Privacy Policy
Last updated: September 9, 2026
TimeToEat stores account and body-measurement data to provide wellness estimates and approved manager connections. Read this policy before submitting data. If you do not agree to the necessary processing, do not create an account or use the wellness features. You can still exercise your privacy rights without accepting new terms.
1. Operator and contact
The operator's legal name and contact address have not yet been published for this deployment.
Contact support@timetoeat.one for privacy, security, support and rights requests.
Privacy information is incomplete. Do not submit personal data until the operator and infrastructure details below are published. Production registration and new consent are disabled while these details are missing.
2. What is collected and why
- Account: name, email, optional phone, password hash, role, verification status and timestamps, used to operate and secure your account.
- Wellness profile: birthdate and sex if provided, habits, goals, height, weight, activity factor, optional skinfolds and circumferences, blood pressure and pulse. These inputs and dated measurement history support calculations and progress review.
- Connections: manager and client identifiers, request dates and connection status, used to control sharing.
- Manager profiles and applications: name, contact information, professional title, description and optional image URL. Applications are emailed to the support mailbox for manual review. Do not include client or medical records in an application.
- Consent and security: policy version, acceptance and withdrawal dates, adult confirmation, session version, short-lived login-code hashes and rate-limit counters.
- Support: messages and email correspondence you choose to send. Avoid unnecessary health details.
Wellness data can reveal information about health. We use explicit consent for this processing. Basic account processing is necessary to provide the requested service; proportionate security and abuse prevention serve our legitimate interests. We process information to comply with applicable legal obligations where required. No advertising, sale of personal data or model-training purpose is part of this application.
3. How and where data is stored
Account, profile, measurement, connection and consent records are stored as structured rows in a server-side MySQL-compatible database. Passwords are stored as salted bcrypt hashes, not readable passwords. New one-time login codes are stored as keyed hashes. The application server can read your profile and measurements to calculate and display results; this is not end-to-end encrypted storage.
Access is authenticated and checked against the current account and role. An active manager connection permits the manager to view your results and add measurements, goals and habits. Pending and archived connections do not permit access to body measurements. Administrators have access for service administration. Disconnect in Account settings to end a manager's access. This cannot recall copies that a manager previously downloaded or recorded independently.
- Application/database hosting: Not yet published. Region: Not yet published.
- Email provider: Not yet published. Region: Not yet published.
Infrastructure providers process service data, and email providers process recipients, message content and delivery information. The application sends transactional login, setup, account and support messages over an encrypted SMTP connection. Providers may retain their own operational records. We do not claim a particular hosting country, encryption-at-rest configuration, backup schedule or international-transfer safeguard unless it is confirmed for the deployment. Before introducing an international transfer requiring safeguards, the operator must identify and implement an applicable legal mechanism and update this notice.
4. Your browser, cookies and external images
An essential HTTP-only cookie keeps you signed in for up to seven days. It uses SameSite protection and is marked Secure in production. Changing a password, deleting an account or withdrawing consent invalidates previous sessions.
Unsubmitted quiz answers and progress are stored in this tab's session storage so you can move between steps. They are cleared when you complete or reset the quiz, or normally when you close the tab; browser session restoration may preserve them. The application does not currently set advertising or behavioural-tracking cookies.
Loading an external manager image can disclose your IP address to that image host. Avoid sensitive image URLs. The application applies a no-referrer policy. Downloaded exports remain on your device under your control.
5. Retention and deletion
- Account data and measurement history remain in the application database until you delete the account. Withdrawal separately erases measurements, birthdate, sex, goals and habits and archives manager connections while keeping basic account access.
- Login codes stop working at expiry or after use. Normal login/reset codes expire after three minutes; welcome and email-change links can last up to 24 hours. An hourly cleanup task removes expired/used codes and expired abuse counters. If cleanup fails, expired codes remain unusable until cleanup resumes.
- Abuse counters use keyed hashes of IP addresses and submitted email identities; raw values are not stored in these counters. Counters expire after 15 minutes and are removed by cleanup.
- A privacy completion receipt contains a random reference, action type and completion time, without an account ID, name, address, message or measurement data. Receipts are purged after 90 days by the hourly task.
- Infrastructure log retention: Not yet published. Application error logs omit raw query strings and database/SMTP exception payloads.
- Backup retention: Not yet published. Account deletion acts on the application database; it does not instantly remove copies in infrastructure backups, support mailboxes or independent manager records. Contact support about those copies and any applicable retention duty.
6. Your choices and rights
In Account settings you can download your data as JSON directly to your device, withdraw wellness consent, disconnect a manager or permanently delete your account. Withdrawal and deletion require a recent sign-in and confirmation. Erasure cannot be undone; download a copy first if wanted. Withdrawal does not affect the lawfulness of earlier consent-based processing.
You may also request access, correction, deletion, portability, restriction or objection where applicable by emailing support. We may need proportionate verification of identity. Where GDPR applies, requests must normally be addressed within one month; any permitted extension and its reason must be communicated. You may complain to the data-protection authority in your place of residence, work or alleged infringement. No agreement to these terms waives these rights.
7. Limits and changes
This service is for adults aged 18 or older. Calculations are informational wellness estimates, not medical diagnosis, treatment or emergency monitoring. No internet service can guarantee absolute security. The User Agreement explains permitted use and liability limits; it does not remove data-protection obligations or rights that cannot be waived.
Material changes to consent-based processing require a new, explicit choice before the affected features can be used. The app records the accepted policy version. You may refuse and export or delete your existing data.