This Application collects some Personal Data from its Users.
This document can be printed for reference by using the print command in the settings of any browser.
Mathias OVIEVE
5 Rue Hector Malot
69007 Lyon
Owner contact email: contact@momeats.app
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application. Data needed to provide a requested feature is distinguished from optional processing. Product usage analytics is not necessary to provide the User with food guidance or access to their subscription.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application and confirm that they have the third party's consent to provide the Data to the Owner.
This Application may request certain permissions that allow it to access the User's device Data as described below. By default, these permissions must be granted by the User before the respective information can be accessed. Permissions can be revoked at any time in the device settings.
Used for capturing photos of meals, recipes and restaurant menus for AI analysis, and for scanning product barcodes in the Product Search feature.
Used for selecting existing photos from the User's library to send to the AI assistant, recipe scanner or menu scanner, and to share images in the in-app support chat.
Used only when the User starts a voice conversation with the AI Assistant. The Application explains audio sharing before first use and requests the device's microphone permission. The User can mute audio transmission or end the conversation at any time, and revoke microphone permission in device settings. Refusing this permission does not prevent use of the text-based AI Assistant.
MomEats includes AI-powered features that analyze food safety and wellness information personalized to the User's pregnancy. These features are powered by Gemini, developed by Google LLC, and accessed through Firebase AI Logic. This section describes each AI feature, the personal data sent to Google for processing, and how the User's consent is obtained and managed.
The AI Assistant allows the User to ask food-safety questions or photograph a meal to receive personalized guidance based on their trimester and health profile. The following data is transmitted to Google for each request:
In versions offering voice conversations, the User can speak to the AI Assistant and hear AI-generated replies through Gemini Live, accessed through Firebase AI Logic. This is an interaction with AI; the voice does not belong to a human adviser. Google processes:
MomEats uses audio temporarily to transmit speech and play replies; it does not save recordings of either side of the conversation. Text transcripts are saved in Cloud Firestore, linked to the User's account, as part of their private AI conversation history. See voice data retention for storage and deletion details. Google's separate processing and retention practices are described under AI Provider and Data Handling.
Muting stops further microphone audio from being sent. Ending the session, leaving the conversation screen, or putting the Application in the background stops the voice session. The Application does not listen in the background. These actions do not erase data already transmitted or the saved transcript.
The Recipe Scanner allows the User to photograph a printed recipe or provide a URL; AI analyzes the ingredients and suggests pregnancy-safe substitutions. The following data is transmitted to Google for each request:
The Menu Scanner allows the User to photograph a restaurant menu (up to five pages per scan); AI identifies dishes, flags pregnancy-risky items and suggests safer alternatives. The following data is transmitted to Google for each request:
Menu scan results and the original photos are stored in the User's account so they can be reviewed later in the scan history. The User may delete individual scans or all scans at any time from within the Application.
The Food Journal Insights feature analyzes the User's logged meals and wellness check-ins to surface patterns and personalized recommendations. The following data is transmitted to Google when generating insights:
The AI Meal Plan Generation feature creates personalized multi-day meal plans based on the User's dietary profile and pregnancy context. The following data is transmitted to Google for each request:
Generated meal plans and individual recipe details are stored in the User's account. When the User requests a detailed recipe from a generated meal plan, the meal title, summary, main ingredients, serving count, trimester and toxoplasmosis immunity status are transmitted to Google for processing.
The Product Search feature allows the User to search for food products by name or scan a barcode using the device camera. Product information is retrieved from a curated database and the Open Food Facts API. Pregnancy safety is evaluated using a rule-based engine. When rule-based scoring is insufficient, the following data is transmitted to Google for AI-powered safety scoring:
Product search history is stored locally on the User's device.
All AI features are powered by Google LLC (Gemini) through Firebase AI Logic, including Gemini Live for voice conversations. The Application sends AI requests and live audio through the Firebase AI Logic SDK. Processing is not restricted to Europe and may take place in the United States or other countries where Google or its service providers operate.
Under the Gemini API paid-service data terms applicable to MomEats, Google does not use submitted content or generated responses to improve its products or train its AI models. Google may temporarily retain inputs and responses for security, abuse prevention and legal obligations. MomEats' absence of saved audio recordings does not mean that Google provides zero retention.
The AI Assistant may use Google Search to support its answers, including during voice conversations. For this feature, Google retains prompts, supplied context and generated output for 30 days to provide search-supported answers and debug and test the systems supporting this feature. These provider practices are described in the Gemini API Terms.
Firebase Privacy Policy | Google Privacy Policy
Before any personal data is transmitted to Google for the first time, the Application presents the User with an explicit consent prompt that describes which data will be sent and for what purpose. AI features are not activated until the User actively accepts this prompt.
The User may withdraw their consent at any time from the Application's settings. Upon withdrawal, all AI features (AI Assistant including voice conversations, Recipe Scanner, Menu Scanner, Food Journal and Wellness Insights, AI Meal Plan Generation, and Product Search AI scoring) will become unavailable. Withdrawing AI consent does not affect other Application functionality. The in-app withdrawal flow also deletes saved AI conversations, including voice transcripts. It does not automatically erase data already retained by Google under its own processing and retention terms.
To withdraw AI consent or request deletion of data previously processed by Google, Users may contact the Owner at contact@momeats.app.
This section describes the PostHog integration in MomEats versions that include product usage analytics. It concerns the mobile Application; visiting this website does not itself activate the Application's PostHog SDK.
MomEats uses PostHog to understand which features are useful, where Users encounter difficulties, and whether changes improve the Application. The selected events cover app openings, onboarding, navigation, subscription-screen interactions, food searches, barcode lookups, food categories and lists, opening food details, AI requests and reopening AI histories. AI analytics records the feature used, whether a request succeeds, fails or is cancelled, and its duration. Search analytics records the search source, result count and whether a result is opened. These events are not a recording of every tap.
The SDK stores a generated identifier on the device and uses session identifiers to relate events. After sign-in, analytics is linked to a MomEats-specific identifier derived from the account ID; preceding activity on that installation may be associated with the account. These identifiers are pseudonymous, not anonymous. MomEats does not send the User's name or email address in this integration.
Events include timestamps, feature and navigation labels, catalogue category identifiers, request identifiers, result counts, durations and general outcome categories. The SDK also supplies information such as the app version and build, device model, operating system, screen dimensions, language, time zone and network connection type. PostHog receives the IP address used for the connection; the current project does not enable IP anonymization. Approximate location may be derived from the IP address. This integration does not request access to the device's GPS location.
Analytics from development builds, TestFlight testing and production releases is labelled separately. MomEats shares an analytics project with other applications operated by the Owner, with app-specific event labels and account identifiers. This configuration does not intentionally link a MomEats account to accounts in other apps; it does not create separate storage or access permissions for each app.
MomEats does not include search text, product names, scanned barcodes, AI messages or responses, recipe URLs, photos, journal contents, pregnancy trimester, immunity status, allergies or other health profile values in its PostHog events. General feature-use events still relate to use of a pregnancy-focused application and must not be treated as fully anonymous information. Content needed to operate AI and search features is processed separately as described above.
Session replay, automatic screen capture and automatic interaction capture are disabled in this integration. The Owner uses these events for product improvement, not targeted advertising or automated decisions about a User's health or eligibility for the Service.
Optional product analytics is separate from the processing needed to operate the Service and from consent to send content to the AI provider. Its legal basis is the User's consent (Article 6(1)(a) GDPR). Before activating PostHog, the Application offers a separate choice to accept or refuse statistics. Refusing does not remove access to the subscription or other features. No analytics events from before acceptance are saved for later transmission. Acceptance of the Terms, continued use of the Application, or consent to AI processing does not constitute consent to product analytics.
The choice, its date and the version of the consent notice are saved locally on this device to respect the User's preference. Users can withdraw consent in Profile → Privacy → Usage statistics, or review the notice there before enabling statistics again. Withdrawal stops new collection, cancels outstanding analytics requests and clears the SDK's locally queued events and identifiers. Data already transmitted cannot be recalled by this control. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn, and does not automatically erase data held by PostHog; erasure can be requested separately as described below.
Users can contact contact@momeats.app to request access to or erasure of analytics associated with their account, or to exercise the rights described below. Apple's device analytics preference does not control this separate PostHog integration. Signing out resets the SDK's current identity but does not delete events already received by PostHog.
This Application uses the following third-party services that may collect and process Personal Data:
Provides product usage analytics on the Owner's behalf. Data processed includes the events, pseudonymous identifiers, technical information and connection information described in the product usage analytics section. MomEats uses PostHog Cloud in the United States.
PostHog Privacy Policy | PostHog Data Processing Agreement
Used for user account creation and authentication via Apple Sign In or email/password. Data processed: email address, name, unique user identifier.
Used to store user-generated content, preferences and app data. Data processed: account information, meal data, user preferences, journal entries, wellness checks, AI conversations including voice transcripts, recipe analyses, menu scan analyses, generated meal plans, community feature requests and votes, content reports, and the User's blocked users list.
Used to store user-uploaded images sent to the AI assistant, recipe scanner and menu scanner. Data processed: photos and media files.
Powers all AI features in this Application (AI Assistant, Recipe Scanner, Menu Scanner, Food Journal Insights, AI Meal Plan Generation, and Product Search safety scoring), including live voice conversations through Gemini Live. Data sent to Google for processing includes: user questions, microphone audio, voice transcriptions, conversation history, meal photos, recipe photos or URLs, restaurant menu photos, dietary preferences, food allergies and intolerances, trimester of pregnancy, toxoplasmosis immunity status, meal logs, wellness check-in data, and product safety queries. Google returns generated text or audio as appropriate. For processing locations, model training and provider retention, see AI Provider and Data Handling.
AI features are activated only after the User provides explicit consent in-app. See the "AI-Powered Features and Data Processing" section above for full details.
Firebase Privacy Policy | Google Privacy Policy
Used to search food product information by name or barcode in the Product Search feature. Data processed: product name or barcode identifier. Open Food Facts is an open, collaborative database; no personal user data is transmitted to this service.
Used to manage in-app subscriptions and purchases. Data processed: subscription status, purchase history, anonymous user identifiers.
This Application is distributed on the Apple App Store. Apple processes payments for in-app purchases and may collect basic analytics data. Users may opt-out of Apple analytics through device settings.
Used to collect crash reports and diagnostic data to improve app stability. Data processed: crash logs, stack traces, device model and operating system version, Firebase user identifier.
Used to verify that requests to backend services originate from the genuine Application. App Attest generates device attestation tokens; no personally identifiable information is collected through this service.
Used to provide in-app live support chat. Data processed: messages and files shared in the chat, email address (if provided by the User), device type and app version. Crisp IM SARL is a French company; data may be stored within the European Union.
The Application includes a public roadmap where Users may submit feature requests, vote on requests submitted by other Users, and report inappropriate content. Each feature request stores the User's display name, account identifier, the title and description provided, the chosen category, vote count, and the creation and update timestamps.
Feature requests and the author's display name are visible to all other authenticated Users of the Application. Users should not include personal data, sensitive health information, or confidential third-party information in feature request titles or descriptions.
Reports submitted to flag a feature request (reason and reporter identifier) are visible only to the Owner and are used to moderate the public roadmap. The Owner reserves the right to remove or hide feature requests that violate the Terms or applicable law. Users may request the removal of their own feature requests at any time by contacting the Owner at contact@momeats.app.
Automated moderation. Each submitted feature request is automatically processed by a Firebase Cloud Function deployed in Europe (eu-west1) that scans the title and description for obviously problematic content. Feature requests flagged by this filter are soft-hidden pending human review. The automated moderation function processes only the feature request's title, description and author identifier; no data is transmitted to third parties for this purpose.
Blocking another User. Users may block another User from the feature request roadmap. When this happens, the blocked User's account identifier and their display name (cached at the time of blocking so the list remains readable) are stored on the blocking User's own profile. The Application uses this list locally to hide feature requests authored by blocked Users. The blocked users list is not shared with other Users and can be modified from Profile → Blocked users at any time.
User data is stored on Firebase / Google Cloud servers located primarily in the United States. AI processing is performed by Google through Firebase AI Logic, including streamed microphone audio for voice conversations. AI processing may take place in the United States or other countries where Google or its service providers operate; it is not restricted to Europe. For details on which data is sent to Google and how consent is managed, see the "AI-Powered Features and Data Processing" section of this policy. Product usage analytics is transmitted to PostHog Cloud in the United States. Support chat data processed by Crisp may be stored within the European Union.
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of the Data. Where data is transferred outside the EU, the Owner relies on appropriate safeguards such as Standard Contractual Clauses or the service provider's compliance frameworks.
PostHog's published Data Processing Agreement includes Standard Contractual Clauses for relevant international transfers. Users may contact the Owner to obtain information about the safeguards applicable to their data. Accepting these Terms or this policy does not itself provide a legal basis for an international transfer.
This Application offers auto-renewing subscriptions managed through RevenueCat and processed via Apple In-App Purchases. The Owner does not directly collect or store payment card information. All payment processing is handled by Apple.
Subscription status and purchase history are synchronized through RevenueCat to manage access to the Application.
Users may delete their account from the Application's settings or contact the Owner at contact@momeats.app to request erasure of their personal data. Upon receiving a valid request, the Owner will delete the User's account and personal data within 30 days, except where retention is required by law.
The current in-app account deletion process does not automatically erase previously collected PostHog events. Requests to remove associated analytics must also be directed to the Owner at contact@momeats.app. An account identifier may help locate these events; events recorded before sign-in may not be linkable to an account. Uninstalling the Application does not erase data already held by a service provider.
Voice audio and transcripts. MomEats does not retain audio recordings. Text transcripts remain in the User's private AI conversation history until the conversation is deleted, the in-app AI consent withdrawal flow deletes it, or the account is deleted. There is currently no automatic expiry for conversation transcripts. The User can delete conversations from the Application's conversation history. Deleting a conversation in MomEats does not automatically erase Google's separately retained service data; see AI Provider and Data Handling and contact the Owner for requests concerning that data.
Product usage analytics. The current PostHog project reports a plan-based event retention window of seven years, but automatic expiry is not currently enforced. Events therefore remain until deleted; there is no automatic twelve-month deletion in place. Users may request erasure through the contact details above. This provider setting is not a statement that every event is needed for seven years. The Owner must limit retention to what is necessary for the stated purposes.
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to:
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.
Information collected automatically through this Application (or third-party services employed in this Application), which can include device information, interaction data, and other technical details.
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
The means by which the Personal Data of the User is collected and processed.
The service provided by this Application as described in the relative terms (if available) and on this site/application.
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy policy relates solely to this Application, if not stated otherwise within this document.
Latest update: September 13, 2026