Dietista Personal · Information and help
Privacy Policy
1. Responsible and contact
The controller for Dietista Personal's processing is Luis Eduardo Rodríguez Ayuso, NIF 47201597P, Calle Loma de los Riscos, 81, puerta 2, Torremolinos (Málaga), 29620, Spain. Contact for privacy and exercising rights: support@edosoft.app; you may also send a written request to the address above. The owner states that appointing a data protection officer does not apply; this assessment must be validated against the actual processing.
2. Data and sources
When you sign in with Google or Apple, the app receives account data supplied by the provider, such as identifier, name and email. It processes the data you enter: profile image, biography, age, gender, height, weight, physical activity, goals, target weight and dietary preferences or restrictions. It stores weight history, progress, and the plans, recipes, collections and shopping lists you use or customise. It calculates BMI and a calorie target from the profile.
Integrated services may also process installation and notification identifiers, usage events and technical diagnostics. The Android code incorporates Crashlytics, and both platforms integrate Remote Config to check app status; actual collection and production configuration remain to be verified. The store handles payment and the app checks purchase status. Do not enter unnecessary health information in free-text fields or support messages.
3. Purposes and legal bases
The following map identifies the bases corresponding to each purpose; it does not mean that the necessary consent or controls are already implemented.
| Purpose and data | Legal basis and status |
|---|---|
| Create and maintain the account; authenticate access and manage the requested content. | Performance of a contract, Article 6(1)(b) GDPR, for necessary data. Optional features and sensitive content require a separate assessment. |
| Personalise plans, calculate BMI and calories, record weight and progress; body profile and restrictions revealing health information. | Consent, Article 6(1)(a), and explicit consent, Article 9(2)(a) GDPR, for health data. No specific mechanism has been found; accepting terms does not replace it. |
| Measure usage with Firebase Analytics; events and identifiers. | Consent, Article 6(1)(a) GDPR, separate from the account and health data. A dialogue exists; its information and withdrawal controls need correction. |
| Manage Premium and answer contractual enquiries; purchase status and communications. | Performance of a contract or steps requested before entering into a contract, Article 6(1)(b). For privacy rights and specific legal obligations, Article 6(1)(c). |
| Send notifications through Firebase Cloud Messaging; installation identifier and messages. | For necessary service notices, Article 6(1)(b), depending on their content. Optional notices require consent; system permission does not by itself authorise marketing. Campaigns and configuration must be confirmed. |
| Check operational status with Firebase Remote Config; installation identifiers. | Article 6(1)(b) for configuration necessary to provide the service. Its necessity, data minimisation and actual configuration must be verified; use for personalisation or experiments with other purposes has not been established. |
| Crash diagnostics, access logs and service protection. | The basis remains to be documented according to the data and purpose: any legitimate interest (6(1)(f)) requires a balancing assessment and data minimisation; optional collection or non-essential access to the device requires the applicable consent. No verified legal basis is attributed to Crashlytics. |
| Retain information required by specific legal obligations. | Article 6(1)(c), with the applicable law, categories and period still to be identified. This does not justify retaining the nutritional profile indefinitely. |
4. Health data and your choices
Weight, its changes, BMI and certain restrictions may reveal health information. In the reviewed service there is no evidence of healthcare provision allowing reliance on the healthcare exception in Article 9(2)(h). Explicit, informed and demonstrable consent is needed for purposes that process health data, separate from terms, privacy, analytics and marketing. Existing analytics consent does not cover these data.
You may request withdrawal of consent and cessation of the associated processing via support@edosoft.app or by post. Withdrawal does not affect prior lawfulness where consent was valid. Without processing the body profile, recommendations dependent on it cannot be offered; features available without these data must be specified in the app. Publishing this policy does not obtain your consent or remedy its absence.
5. Automated recommendations
The reviewed logic combines weight, height, age, gender, activity and goal to estimate daily energy; it uses weight and height for BMI and filters plans by calories and preferences. The result influences suggested plans and may be incorrect or unsuitable for your situation. You can view and customise plans; there is no evidence of individual review by a healthcare professional.
No decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR have been identified. This conclusion needs review if recommendations, restrictions or consequences change. You may request information and challenge your data or the recommendations through the privacy channels. See the nutritional scope.
6. Providers and recipients
| Service | Function and data | Outstanding information |
|---|---|---|
| Firebase Authentication (Google) | Authentication and account identifiers; Google or Apple according to the chosen sign-in method. | Contracting entity, each party's roles, applicable terms and location. |
| Firebase Analytics (Google) | Usage measurement and identifiers following the analytics choice. | Actual events, advertising and sharing options, retention and entity. |
| Firebase Cloud Messaging (Google) | Notification delivery and installation tokens. | Messages, user association, expiry and entity. |
| Firebase Crashlytics, integrated on Android | Crash diagnostics, subject to verification of activity. | Data sent, controls, active platforms, retention and entity. |
| Firebase Remote Config (Google), integrated on Android and iOS | Check app status; installation identifiers used by the SDK. | Configuration, entity, region, retention and identifier removal. |
| MongoDB Atlas | Database for profiles, plans, weight and progress, according to the infrastructure declared by the owner. | Contracted entity, cluster region, subprocessors and terms. |
| Backblaze, S3-compatible storage | Images and thumbnails, according to the infrastructure declared by the owner. | Entity, contracted product, storage region and retention. S3 compatibility does not identify Amazon as the provider. |
| Cloudflare | Handles access to the backend API, as confirmed by the owner. | Specific product, configuration, processed data and logs, entity and applicable regions. This does not establish that it hosts the website. |
| Railway, Spring backend | Processing the profile and content requested by the app; hosting in Europe confirmed by the owner. | Specific region and country, contracting entity, subprocessors, backups and support access. ‘Europe’ does not by itself establish that all processing takes place in the EEA. |
| App Store and Google Play | Purchase and subscription management according to the chosen store. | Entities and data exchanged in production. |
Authorities may receive data when a specific legal obligation requires it. The email and website providers, and the specific Cloudflare products contracted for the API, remain to be confirmed. The identified technologies do not by themselves establish data processing agreements, European locations, anonymisation, specific encryption or certifications.
7. International transfers
The owner confirms that the Railway backend is in Europe; the specific country or region has not been identified, nor have the locations, subprocessors and access arrangements of the other providers. It is therefore not claimed that all data remain in the EU or that a specific safeguard exists. Before finalising this policy, the countries, recipients and mechanism applicable to each transfer must be identified: an adequacy decision or safeguards under Article 46 GDPR, with the corresponding assessments and measures. You may request information and a copy of the applicable safeguards from the controller.
8. Conservation and disposal
The profile, weight history and progress are stored for the features described. An effective retention schedule covering inactivity purges, logs, backups, SDKs and images has not been confirmed; this information must be completed. The current account deletion process does not support a claim that all associated data are deleted.
A legal obligation or defence of claims can justify retention only of the necessary data and for the identified applicable period. Where blocking under Article 32 LOPDGDD applies, these data must be excluded from ordinary use until destruction. Neither that procedure nor an operational deletion timeframe has been verified. See account and data deletion.
9. Rights, withdrawal of consent and complaints
You may request access, rectification, erasure, restriction, objection and portability where applicable; you may also withdraw consent and exercise applicable rights relating to automated decisions. Write to support@edosoft.app or to the controller's address, specifying the right and the account email. Do not send passwords or identity documents by default; if there are reasonable doubts about identity, proportionate additional information may be requested.
As a general rule, requests are handled free of charge and without undue delay. The statutory response period is one month from receipt; it may be extended by two further months due to complexity or the number of requests, with notification within the first month. This is a statutory response period, not a promise to purge all copies within thirty days. If your right is not addressed, you may complain to the Spanish Data Protection Agency.
10. Minors and website privacy
Dietista Personal is intended exclusively for adults aged 18 or over, according to the audience confirmed by the owner. It is not offered to minors. The reviewed code still accepts ages from 1 to 120: controls must be corrected and any existing minors' accounts reviewed. If you identify a minor's account, contact the controller to review its processing and any appropriate deletion. This policy does not establish that age controls are already implemented.
This website serves public information. The language selector uses local resources and keeps the choice in page memory; the reviewed code does not incorporate analytics or its own cookies. Logs and technologies added by production hosting remain to be confirmed. See cookies and similar technologies.