Privacy at Fuda.
Your household's food restrictions are sensitive information. Here is exactly what we collect, why, and the rules we hold ourselves to. The short version first, the full version below.
The short version (seven promises)
- Your restrictions are health-level data and we treat them that way. We ask your explicit permission before storing them, and you can withdraw it at any time.
- We collect only what changes your answers. Nothing else.
- We never sell your data. To anyone, for anything.
- No advertising, no ad tracking, no profiles built for anyone but you.
- Children never have accounts. A parent records a child's restrictions, and a parent can remove them.
- Delete your account and everything personal is gone within 30 days.
- Everything is stored in the EU.
1.Who we are
Fuda (“we”, “us”) is a food decision service based in the Netherlands. We are the controller for the personal data described here. Contact: privacy@fuda.app.
Unresolved before publication: Legal entity name, registration number, address. Counsel to confirm which entity is the controller, and to update this section when the corporate structure changes. The controller must be stated accurately at all times.
2.What we collect, and why each thing
We collect nothing that does not change your answers.
- Account: your email address, to sign you in and to tell you the things we promise to tell you (like a price change, before it happens).
- Your household's restrictions: allergies, intolerances, medical diets, religious food rules, and things people simply avoid, per person. This is the heart of Fuda and the most sensitive thing we hold. See section 3.
- Household setup: who is in the household (a name or nickname and whether someone is an adult or child), portions, preferences such as time, budget and taste. Children are people in your household, never account holders.
- Pantry and shopping data: what you tell us is in the house and what's on your list, so we can use what you have before recommending spending.
- Decision history: what you accepted, changed or rejected, so your answers get better. Used for your household only; never to build a profile for anyone else.
- Approximate location: city-level, to show shops and restaurants near you. We do not store precise GPS coordinates.
- Technical basics: browser type and language, for localization; your market and language choice (a cookie); strictly necessary session cookies.
3.Your restrictions are special-category data
Food restrictions can reveal health information (an allergy, coeliac disease, a medical diet) and religious belief (halal, kosher and other rules). Under the GDPR these are special categories of personal data. We therefore:
- ask your explicit consent before storing any restriction, separately from the general terms;
- let you withdraw that consent at any time in the app, which removes the restrictions;
- never use restriction data for anything except checking food for your household;
- never share it with anyone, except the processors in section 6 who store it encrypted on our behalf and are contractually forbidden from using it.
A restriction you record for another adult in your household should be recorded with their knowledge. Restrictions for children are recorded by a parent or guardian, who can view and remove them at any time.
Unresolved before publication: PRODUCT BUILD ITEM, not text: the explicit-consent step must exist in onboarding before this section is published. A separate, unticked, plainly-worded consent at the moment restrictions are first entered, and a withdrawal control in the app that removes them.
4.What we will never do
- Sell or rent your data. To anyone, for anything, ever.
- Show you advertising or share your data with advertisers.
- Build profiles of you for third parties.
- Use your restriction data for research, marketing, or model training outside providing your own answers, without asking you first, explicitly and separately.
5.Legal bases
- Explicit consent (Art. 9(2)(a)) for your household's restrictions and any other special-category data.
- Contract (Art. 6(1)(b)) for account, household setup, pantry, lists and decision history: the service you signed up for.
- Consent (Art. 6(1)(a)) for analytics cookies.
- Legitimate interest (Art. 6(1)(f)) only for security, error logging and abuse prevention. We do not rely on legitimate interest for anything involving your restrictions.
6.Where your data lives, and who processes it
All personal data is stored in the European Union.
| Processor | What it does | Personal data | Region |
|---|---|---|---|
| Supabase | Database and sign-in | Yes, encrypted | EU (Frankfurt) |
| Vercel | Hosting | Technical request data | EU routing |
| Sentry | Error reports | Anonymized | EU |
| Google Analytics | Site usage, only with your consent | Pseudonymized usage data | See note below |
Unresolved before publication: Google Analytics: current data-transfer status and safeguards, to be stated accurately by counsel. Merchant of Record row to be added from M7 (payments, VAT, invoices; they are controller for payment data).
Restaurant and venue information (Thuisbezorgd, Uber Eats, Google Maps via SerpAPI, OpenStreetMap) flows to us as public menu and venue data; none of your personal data flows to them.
We will update this table whenever a processor changes, and the “last updated” date with it.
7.How long we keep things
As long as your account is active. Delete your account (Settings > Account > Delete account) and all personal data is permanently removed within 30 days. Withdraw consent for restrictions without deleting the account, and the restrictions are removed while the rest stays.
Unresolved before publication: Backup roll-off period, in days, after deletion. Engineering to confirm.
8.Your rights
Access, correction, erasure, portability (a machine-readable export), restriction, objection, and withdrawal of consent at any time without affecting what happened before. Exercise any of them in the app or via privacy@fuda.app; we respond within one month. You can always complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
10.If something goes wrong
If a data breach ever affects your personal data, we notify the Autoriteit Persoonsgegevens within 72 hours where required, and we tell you directly if there is any meaningful risk to you, in plain language, including what happened and what we are doing.
11.Changes to this policy
We change this page only when reality changes, we date every version, and for any change that matters (new processor, new purpose, new data) we tell account holders by email before it takes effect. Old versions remain available on request.
12.Contact
privacy@fuda.app. A person answers, within a month at the outside, usually much faster.
Version 2 · 23 August 2026 · previous versions on request