Satio App Privacy Policy
Last updated: June 2026 · Applies to the Satio mobile app. For the waitlist only, see our waitlist privacy notice.
Short version: Satio works for you, not advertisers. We collect only what we need to log your meals and coach you, sensitive health data is only ever used with your explicit consent, we never sell your data, and you can access, export, or delete everything at any time. The detail is below.
1. Who we are & how to reach us
Satio ("we", "us", "our") provides the Satio AI nutrition app and is the data controller for the personal data described in this policy.
- Privacy contact: privacy@satio.app — use this for any privacy question, rights request, or complaint.
- General contact: hello@satio.app
We are not currently required to appoint a Data Protection Officer (DPO). If that changes, we will publish the DPO's contact details here. You can always raise data-protection matters with our privacy contact above, and you have the right to complain to a supervisory authority (see section 10).
2. The personal data we collect, and where it comes from
We collect the following categories of personal data — most of it directly from you as you set up and use the app:
| Category | Examples | Source |
|---|---|---|
| Account & profile | Email, name (optional), age, units, goals and preferences set during onboarding | You |
| Meal data | Photos you take, descriptions, ingredients, and the nutrition estimated from them | You; derived by the app/AI |
| Health & body data (special category — see 4) | Weight, body measurements, blood pressure, blood glucose, menstrual cycle, exercise, sleep | You; or a connected service (e.g. Health Connect) if you enable it |
| Usage & device data | App interactions, settings, and basic device/diagnostic data needed to run the app | Automatically, as you use the app |
| Optional analytics & crash data | Anonymous usage events; crash reports | Automatically — only if you opt in |
Everything optional is off by default and is asked for at the moment you first use the feature. We do not buy personal data about you from third parties.
3. Why we process your data, and our legal basis
We process personal data only for the specific purposes below, and each has a lawful basis under GDPR Article 6 (and Article 9 for health data — see section 4):
| Purpose | Legal basis |
|---|---|
| Create and run your account; log meals; estimate nutrition; provide the coaching features you've asked for | Performance of a contract (Art. 6(1)(b)) |
| Process health & body data; analyse meal photos; personalise coaching | Your explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Keep the service secure and prevent fraud or abuse; fix crashes and improve reliability | Our legitimate interests (Art. 6(1)(f)), or your consent for optional diagnostics |
| Send optional analytics; any non-essential communications | Your consent (Art. 6(1)(a)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not use your data for purposes incompatible with those listed here without telling you first.
4. Health data — special category (GDPR Article 9)
Satio does process special-category (health) data — the weight, blood-pressure, glucose, cycle, exercise, sleep, and meal-derived information you choose to log. This data gets extra protection under GDPR Article 9.
Our condition for processing it is your explicit, informed consent (Article 9(2)(a)), given the first time you use each health feature. Every health feature is off until you turn it on. You can withdraw consent at any time in Settings → Privacy; withdrawal stops future processing without undoing lawful prior processing. Health data is used only to provide your nutrition and coaching features — never for advertising, and never sold.
5. How we handle data — our principles (GDPR Article 5)
- Lawfulness, fairness & transparency: we process data only for the purposes and on the bases set out in this policy.
- Purpose limitation: we use data for those stated purposes and not in ways incompatible with them.
- Data minimisation: we collect only what we need to provide the feature you're using; optional data is off by default.
- Accuracy: you can view and correct your data in the app at any time, and we encourage you to keep it up to date.
- Storage limitation: we keep data only as long as needed for the purpose (see section 9).
- Integrity & confidentiality: we protect data with encryption and access controls (see section 11).
- Accountability: we maintain this policy and our practices to demonstrate compliance, and we'll evolve them as the app grows.
6. Photos, AI, and automated decisions
When you use photo analysis or coaching, the relevant meal photo, your message, and applicable diet/health context are sent to our AI provider to generate a response. We omit your name, email, and account ID from these requests. The provider does not use your data to train its models. You can turn photo analysis off in Settings.
Automated decision-making & profiling. Satio uses AI to estimate nutrition from photos and to generate coaching suggestions, patterns, and reminders. This is informational and advisory only: you remain in control, and you can review, edit, correct, or ignore anything it produces. We do not make automated decisions that produce legal effects or similarly significant effects on you (for example, nothing here determines your access to a legal right, financial product, employment, or essential service). Where we personalise content based on your data, you can turn personalisation off in Settings.
7. Who we share data with (recipients)
We do not sell your data, share it with other Satio users, share it for anyone else's advertising, or use it to train AI models. We do share data with a small number of service providers ("processors") strictly so they can help us run Satio, under contracts (data-processing agreements) that limit how they use it:
- Anthropic (Claude AI) — meal-photo analysis and coaching responses.
- Supabase — secure cloud storage of your account and logged data.
- Google Health Connect — optional sync of activity, sleep, and other metrics you connect.
- Firebase (Google) — optional crash reporting (off by default).
We may also disclose data where we are legally required to (for example, to comply with a valid legal request), or to protect the rights, safety, and security of our users and our service. We do not share identifiable health information publicly.
8. International data transfers
Some of our processors are located outside the EEA/UK — in particular, Anthropic and Google process data in the United States. This means your personal data may be transferred across borders. Where it is, we rely on appropriate safeguards: in particular, the European Commission's Standard Contractual Clauses (SCCs), which are incorporated into our providers' data-processing terms (for example, Anthropic's Commercial Terms and DPA). You can contact us for more detail on the safeguards used.
9. How long we keep your data (retention)
We keep personal data only as long as we need it for the purpose it was collected, then delete it or anonymise it. Concretely:
| Data | Retention | Why |
|---|---|---|
| Account & profile | For the life of your account | To provide the service |
| Meal & health logs | Until you delete them, or your account is deleted | So your history and trends stay available to you |
| Meal photos | 90 days (you can delete sooner) | Short-term, just long enough to log and review |
| Personalisation / learning data | Up to 2 years | To keep coaching relevant; expires if unused |
| Inactive accounts | Deleted after 2 years of inactivity | Storage limitation |
You can delete specific categories or your entire account at any time in Settings → Delete Data, which removes the associated data from our systems.
10. Your rights
Under the GDPR (and similar laws) you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — have your data deleted ("right to be forgotten").
- Restriction — limit how we process your data.
- Portability — receive your data in a portable, machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — at any time, for anything based on consent.
How to exercise your rights
Most rights are built into the app: Settings → Export Data (access & portability) and Settings → Delete Data (erasure), and you can edit your data directly to correct it. You can also delete your data via our public data deletion page. For anything else — or to make a formal request — email privacy@satio.app. We will respond within one month (extendable by up to two further months for complex requests, and we'll tell you if so). We don't charge for this except where a request is manifestly unfounded or excessive.
Complaints
If you're unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to lodge a complaint with a data-protection supervisory authority — in the EU, your national authority (a list is at edpb.europa.eu); in the UK, the Information Commissioner's Office (ICO).
11. Consent
Where we rely on consent, that consent is freely given, specific, informed, and unambiguous, and you give it through a clear affirmative action when you first enable a feature. Withdrawing consent is as easy as giving it — toggle the relevant feature or category off in Settings → Privacy, with no penalty. Withdrawal applies going forward and does not affect processing that was lawful before you withdrew.
12. Security
- On your device: an encrypted local database; optional PIN/biometric lock.
- In transit: HTTPS/TLS for all network calls.
- In the cloud: encrypted at rest, with access restricted to what's needed to run the service.
13. Data breaches
We maintain measures to detect and respond to personal-data breaches. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (GDPR Article 33). Where a breach is likely to result in a high risk to you, we will also inform affected users without undue delay (GDPR Article 34), along with steps you can take.
14. Minimum age
Satio is for users aged 16 and over. Because it involves calorie, weight, and health tracking, we don't allow younger users to create an account and we ask for age during onboarding. We don't knowingly collect data from anyone under 16; if you believe someone under 16 has provided us data, contact us and we'll delete it.
15. Changes to this policy
We may update this policy for new features, legal requirements, or security improvements. We'll notify you in the app and, where required, ask you to re-accept. We won't reduce your privacy protections without clear notice, and we'll update the "last updated" date above.