Privacy Policy
Last updated: date
1. Who is responsible for your data
The controller responsible for processing your personal data is:
Full legal name
Address, Germany
Email: your@email.com
2. What data we collect
Account data
- Your email address, used to create your account and send you a secure sign-in link.
Health and body data (special category — Art. 9 GDPR)
- Age, sex, height, weight
- Activity level, training frequency, sport, average daily steps
- Your goal (cut, maintain, or gain weight)
- Food preferences, dislikes, dietary style, and any allergies you tell us about
We only collect this because it is required to calculate your nutrition plan. We ask for your explicit consent before processing it, and you can withdraw that consent at any time.
Plan and usage data
- Your calculated calorie and macronutrient targets
- Your generated meal plan and plan documents
- Messages you exchange with the AI coach
- Whether your plan has been paid for, and your next check-in date
Payment data
Payments are processed by Stripe. We do not receive or store your card details — these go directly to Stripe. We only receive confirmation of whether a payment succeeded.
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Contract performance (Art. 6(1)(b)) |
| Calculating your nutrition plan from your body and health data | Your explicit consent (Art. 9(2)(a)) |
| Generating your meal plan and plan document | Contract performance (Art. 6(1)(b)) |
| Answering your questions via the AI coach | Contract performance (Art. 6(1)(b)) |
| Processing payment | Contract performance (Art. 6(1)(b)) |
| Meeting tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
4. Who we share it with
We use a small number of processors to run the service. Each only receives what it needs:
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, server functions | Account, health, plan, and chat data |
| Anthropic | AI generation of meal plans, plan text, and coach replies | Your plan figures and preferences; your chat messages |
| Stripe | Payment processing | Email and payment details (card data goes directly to Stripe) |
| Netlify | Website hosting | Technical connection data (e.g. IP address in server logs) |
Some of these providers are based outside the EU. Where data is transferred internationally, it is done on the basis of the European Commission's Standard Contractual Clauses or an equivalent safeguard. Confirm current transfer mechanisms with each provider before publishing.
We do not sell your data, and we do not use it for advertising.
5. How long we keep it
- Account and plan data: for as long as your account exists, so you can return to your plans.
- After deletion: removed from our active systems, subject to any backup rotation period.
- Payment and invoice records: retained as required by German tax law — generally up to 10 years — even if you delete your account.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time, without affecting processing already carried out
- Lodge a complaint with a supervisory authority
To exercise any of these, email your@email.com. You can also complain to your local data protection authority — in Germany, the authority for your federal state (Landesdatenschutzbehörde).
7. AI processing
Your meal plan, plan text, and coach replies are generated using Anthropic's Claude models. To do this, your plan figures and stated preferences are sent to Anthropic for processing. Your name and email are not required for this and are not included in those requests where avoidable. Automated generation is used to produce your plan content; it does not make decisions producing legal effects about you.
8. Cookies and tracking
We do not use advertising or analytics cookies. Signing in stores a session token in your browser so you stay logged in — this is strictly necessary for the service to function and is not used for tracking.
9. Security
Data is transmitted over encrypted connections (HTTPS) and stored with access controls so that each account can only reach its own plans. Payment card details never touch our systems. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.
10. Children
Set Point is available only to adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the service changes. The date at the top reflects the most recent revision.