Smart Lifestyle AS (“Smart Lifestyle”, “we”, “us” or “our”) provides the SmartEating mobile application, related websites, waitlist and services (together, “SmartEating”). This Privacy Policy explains how we process personal data when you join our waitlist, create an account or use SmartEating.
1.Who is responsible for your data?
Smart Lifestyle AS is the controller of the personal data described in this policy.
- Legal name: Smart Lifestyle AS
- Organisation number: 829 972 972
- Address: c/o Christoffer Riseng Bølla, Strandvegen 107, 2315 Hamar, Norway
- Email: support@smarteating.ai
- Telephone: +47 45 84 94 84
- Websites: https://smarteating.ai and https://smart.lifestyle
We have not appointed a data protection officer. Privacy questions and requests can be sent to the email address above.
2.Who may use SmartEating?
SmartEating is intended for general consumers aged 18 or older. It is not directed to children, and we do not knowingly allow anyone under 18 to create an account or provide health data. If you believe that a person under 18 has provided us with personal data, contact us so that we can investigate and delete it where appropriate.
3.Personal data we process
The data we process depends on the features you choose to use.
Waitlist and contact data
- Name and email address
- Waitlist status, invitation status and related timestamps
- Messages you send to support and our responses
- Marketing preferences, if you separately choose to receive marketing
Account and identity data
- Name, email address and account identifiers
- Authentication, session and security information
- Language, locale, settings and notification preferences
- Organisation or trainer relationship, where applicable
Passwords and authentication credentials are handled by our authentication provider. We do not receive your password in readable form.
Profile, nutrition and health-related data
When you choose to provide it, this may include:
- Date of birth or age, sex, height, weight, target weight, waist measurements and body-fat information
- Activity level, occupation, goals, dietary pattern, food preferences and exclusions
- Allergies and other food-safety information
- Sleep, smoking and alcohol information
- Food diary entries, meals, quantities, calories, macronutrients and other nutrition information
- Meal plans, recipes, protocols, adherence, energy and progress information
- Journal entries and other information you enter in free-text fields
Some of this information is health data and therefore a special category of personal data under the GDPR.
Connected health and wearable data
If you explicitly connect a supported service, SmartEating may process data such as:
- Steps, active energy, distance, workouts and activity summaries
- Weight, height, body-mass index and body-fat information
- Heart rate, resting heart rate, heart-rate variability and oxygen saturation
- Sleep, readiness and recovery information
This may come from Apple Health or supported wearable providers such as Oura. Availability depends on the version of SmartEating and your device. You decide whether to connect a service and which device permissions to grant.
Content, chat and AI interaction data
- Messages and prompts you send to SmartEating
- AI responses, tool results, generated plans and other output
- Images, documents and other attachments you choose to upload
- Voice transcripts and information generated during voice sessions
- Conversation history and working memory used to maintain context
Do not upload another person’s health information, confidential information or images unless you are legally entitled to do so.
Camera, image and barcode data
If you use meal-photo or barcode features, we may process:
- Meal or food images
- Barcode numbers, product names, brands and food information
- Recognition results and corrections you make
A meal image may be sent to an AI provider for recognition. The recognition endpoint is designed not to retain the original image in the SmartEating food log; the food information you confirm may be saved. An image or document deliberately attached to a chat may be stored with that conversation.
Voice data
If you start a voice session, live audio is transmitted to our voice-AI provider to transcribe your speech and generate a response. Smart Lifestyle does not intend to store raw voice recordings. We may store transcripts that become part of a conversation, session duration, token usage, cost information and security logs.
Subscription and transaction data
- Subscription status, entitlement, product and renewal information
- App Store transaction and purchase identifiers
- Limited information needed to validate, restore and administer access
Apple processes your payment method and billing transaction. We do not receive your full payment-card details.
Trainer-sharing data
If you explicitly link your account to a trainer or coach, SmartEating may share the categories you select, such as profile and goals, adherence, weight trends or engagement information. You can revoke the link from SmartEating. Revocation stops future access but does not automatically delete information the trainer lawfully retained before revocation.
Technical, security and usage data
- IP address, device, operating-system and application-version information
- Request timestamps, error, crash and diagnostic information
- Authentication, audit, fraud-prevention and security events
- Feature usage, AI token consumption and estimated service cost
We do not use health data for advertising, sell personal data or share personal data for cross-context behavioural advertising.
4.Where the data comes from
We receive personal data:
- Directly from you
- From your device and your use of SmartEating
- From Apple Health or a wearable service when you connect it
- From Apple and our subscription-management provider
- From a trainer when you choose to establish a trainer relationship
- From public or licensed food and product databases when SmartEating retrieves nutrition or product information
5.Why we process data and our legal bases
We process personal data only when we have a legal basis.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Manage the waitlist and invitations | Name, email, status | Steps requested before entering a contract; legitimate interests in managing controlled access |
| Create and secure your account | Identity, authentication, device and security data | Performance of our contract; legitimate interests in security and fraud prevention |
| Provide paid SmartEating features | Profile, messages, food logs, plans, settings and subscription status | Performance of our contract |
| Personalise SmartEating using health-related information | Health profile, diary and connected-health data | Your explicit consent under GDPR Articles 6(1)(a) and 9(2)(a) |
| Connect Apple Health, wearables or a trainer | Connected data and selected sharing categories | Your explicit, feature-specific consent |
| Provide AI chat, vision and voice features | Prompts, context, attachments, transcripts and output | Performance of our contract; explicit consent where health data is included |
| Operate, troubleshoot and protect SmartEating | Technical, audit, security and limited usage data | Our legitimate interests in delivering a reliable and secure service |
| Meet accounting, tax, legal and regulatory duties | Transaction, consent and request records | Compliance with legal obligations |
| Send marketing | Email and preferences | Your separate consent, where consent is required |
Providing health data is optional, but SmartEating cannot provide health-based personalisation without it. You may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal, and it may disable the connected or personalised feature.
6.Artificial intelligence
SmartEating uses AI to generate conversational responses, recognise food, produce meal plans and protocols, and explain patterns in the information you provide. Depending on the feature and configuration, relevant prompts and context may include your profile, goals, allergies, dietary preferences, recent food log, connected-health summaries and conversation history.
AI output may be inaccurate, incomplete or unsuitable for you. SmartEating does not use AI to make decisions that produce legal or similarly significant effects about you. See the Terms of Service for important health and safety limitations.
We use service providers to perform AI processing, including OpenAI and Anthropic. Generated recipe imagery may be produced using fal.ai. We configure providers for business/API use and do not permit them to use SmartEating customer content to train general-purpose models unless we clearly disclose a change and obtain any consent legally required.
7.Apple Health and wearable data
Connected-health features are optional. SmartEating requests only the permissions shown by your device, and you can change them in your device or provider settings. We use connected data to provide the feature you requested, such as activity summaries, progress information or personalised wellness guidance.
We do not use Apple Health or wearable health data for advertising, data brokerage, credit, employment, insurance eligibility or unrelated marketing. Disconnecting a source stops new collection. For Oura, revoking consent also requires us to stop processing and delete Oura user data within 72 hours. For other sources, disconnecting does not automatically delete information already imported; you may delete your account or contact us to request deletion.
8.Who receives personal data?
We disclose personal data only as needed to provide, protect and administer SmartEating, when you direct us to share it, or when law requires it. Current or planned recipients include:
| Recipient/category | Purpose |
|---|---|
| Microsoft Azure, primarily Norway East | API, database, storage, security and backup infrastructure |
| Clerk | Authentication, account management and waitlist invitations |
| OpenAI and Anthropic | AI chat, planning, recognition, analysis, voice and related processing |
| RevenueCat and Apple | Subscription administration, purchase validation and App Store billing |
| Mailgun, configured for its EU region | Transactional and consented email |
| Apple Health, Oura and supported connection services | User-requested health and wearable connections |
| fal.ai | Generated recipe and meal-plan imagery |
| Expo/EAS and application-distribution providers | Building, updating and distributing the mobile application |
| Food and product-data providers | Retrieving nutrition, product, barcode or recipe information |
| A trainer or coach selected by you | Categories you explicitly choose to share |
| Professional advisers and authorities | Legal, accounting, security or regulatory requirements |
Providers act under contracts and data-protection terms appropriate to their role. We require providers with access to personal data to protect it to at least the level described in this policy and, where applicable, required by Apple’s rules. We do not give RevenueCat, Mailgun or advertising providers your detailed health profile for their own marketing.
9.International transfers
Our primary application infrastructure is planned for Azure Norway East. Some providers or their subprocessors operate outside Norway or the European Economic Area. Where GDPR requires safeguards, we rely on mechanisms such as an adequacy decision, the European Commission’s Standard Contractual Clauses and supplementary technical and organisational measures.
You may contact us for more information about the safeguards used for a particular transfer.
10.How long we keep data
We aim to apply the following retention periods, subject to implementation and legal-review confirmation:
| Data | Intended retention |
|---|---|
| Waitlist data | Until you are invited, withdraw or are removed; otherwise no longer than 12 months after the last waitlist activity |
| Account, profile, health, diary, chat and generated content | While your account is active and until deletion is completed |
| Active-system data after a verified account-deletion request | Deleted or irreversibly de-identified without undue delay, normally within 30 days |
| Oura user data, if the Oura integration is enabled | Only for the period strictly necessary; deleted within 72 hours after an applicable deletion request or consent revocation, and when required on termination or cancellation |
| Backups | Removed through the backup lifecycle, normally within 90 days |
| Security and audit records | Normally 12 months, unless needed longer for an investigation or legal claim |
| Consent and withdrawal records | As needed to demonstrate compliance and handle legal claims |
| Transaction and accounting records | For the period required by accounting, tax and other applicable law |
Where a connected-provider agreement requires a shorter deletion period, including for Oura data, that shorter period overrides the general active-system and backup periods above.
Providers may retain limited data according to their contracts, legal obligations and documented retention periods. We may retain data longer when required by law, necessary to establish or defend a legal claim, or requested by a competent authority. Where possible, we restrict the data while that need continues.
11.Security
We use technical and organisational safeguards designed to protect personal data, including access controls, encrypted network connections, encryption for selected sensitive database fields, audit logging and production secret management. No system is completely secure. You are responsible for protecting your device, email account and login credentials and for notifying us if you suspect unauthorised access.
12.Your rights
Subject to applicable conditions and exceptions, you may have the right to:
- Obtain confirmation and access to your personal data
- Correct inaccurate or incomplete data
- Request deletion
- Restrict or object to certain processing
- Receive data you provided in a portable format
- Withdraw consent at any time
- Object to direct marketing
- Complain to a supervisory authority
You can manage some data, permissions and connections in SmartEating. You may also use the account export or deletion controls or email support@smarteating.ai. We may need to verify your identity before completing a request. We will respond within the period required by applicable law.
You may complain to the Norwegian Data Protection Authority (Datatilsynet): https://www.datatilsynet.no. If you live elsewhere in the EEA, you may also contact your local supervisory authority.
13.Account deletion
Deleting your account is intended to remove your active SmartEating profile and associated content, subject to the retention exceptions above. It does not cancel an App Store subscription automatically. Cancel the subscription separately through your Apple account to prevent future renewal charges.
Deletion from active systems does not necessarily remove data already and lawfully shared with a trainer, data retained by Apple for transaction administration, or data held in backups until the backup lifecycle expires.
15.Changes to this policy
We may update this policy when SmartEating, our providers or legal requirements change. We will post the updated version and change the “Last updated” date. If a change materially affects your rights or how we use health data, we will provide additional notice and seek new consent where required.
16.Contact us
Questions, complaints and privacy requests can be sent to:
Smart Lifestyle AS
Organisation no. 829 972 972
c/o Christoffer Riseng Bølla
Strandvegen 107
2315 Hamar, Norway
Email: support@smarteating.ai
Telephone: +47 45 84 94 84