Effective date: 24 August 2026
Platify Pty Ltd ACN 697 195 163 ("we", "us", "our", or "Platify") operates the Platify nutrition coaching platform (the "Service"). We are committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains what personal information we collect, how we use and disclose it, and the choices you have regarding your information. By using the Service, you consent to the practices described in this Policy.
This Policy should be read together with our Terms & Conditions and Cookie Policy.
We collect personal information in several ways, depending on how you interact with the Service. Under APP 3 (Collection of solicited personal information), we only collect information that is reasonably necessary for, or directly related to, our functions and activities.
Account Information
When you create an account via Google OAuth or email registration, we collect:
Profile & Health Information
When you set up your nutrition profile, we collect:
Assessment Responses
When you complete the Platify nutrition assessment (Blueprint), we collect your answers to assessment questions, your score and tier classification, and any personal notes you choose to provide.
Contact Information
When you use our contact form, we collect your name, email address, message content, and any file attachments you provide (images or PDFs, up to 25 MB).
Payment Information
If you subscribe through our website, your payment details (card number, billing address) are collected and processed directly by Stripe. We do not store your full payment card details. We receive and store your Stripe customer ID, subscription status, and billing period information. If you subscribe through the Apple App Store or Google Play, your payment details are collected and processed by Apple or Google, not by us or Stripe.
Food Logging & Tracking
When you use our meal tracking features, we collect:
Preferences & Feedback
We collect your ingredient substitution preferences, recipe ratings and favourites, and responses to coaching interventions (accepted, dismissed, or snoozed).
When you use the Service, we may automatically collect:
We may receive information about you from third-party services:
In accordance with APP 6 (Use or disclosure of personal information), we use your personal information only for the purposes for which it was collected, or for directly related purposes you would reasonably expect. Specifically, we use your information to:
Provide the Service
Manage Your Account
Improve the Service
Communicate With You
Legal & Safety
We recognise that some of the information we collect — including your weight, height, dietary requirements, health goals, meal tracking data, and assessment responses — may be considered sensitive information under the Privacy Act 1988 (Cth).
In accordance with APP 3.3, we only collect sensitive information with your consent. By providing this information through the Service, you consent to its collection and use for the purposes described in this Policy. Specifically:
We do not use your health and nutrition data for advertising purposes or sell it to third parties. Your health data is never shared in identifiable form with business partners.
Connecting Apple Health is optional. If you connect it, Platify reads one thing: your body weight. We do not read steps, workouts, heart rate, or any other health information.
Platify also writes the weigh-ins you log in the app back to Apple Health, so your weight history stays in one place. We only write weigh-ins you recorded yourself.
A weight read from Apple Health is used for the same purposes as a weight you type in: to work out your targets, show your trend, and estimate your energy use. We never use Apple Health data for advertising or marketing, we never sell it, and we do not store it in iCloud.
You can change or withdraw the Apple Health permission at any time in the Health app, under Sharing. That stops all further reading and writing. Weigh-ins that already synced stay in your Platify history: deleting one in the Health app stops it syncing again, but it does not remove the copy Platify has already recorded. To have that copy removed, use the rights described in section 9.
Platify uses artificial intelligence to provide its core features. We want you to understand how your data is processed by AI systems:
Your dietary preferences, goals, macro targets, and exclusions are sent to our AI meal generation service to create personalised recipes and meal plans. All AI-generated recipes undergo human review before being made available.
Your assessment question responses and score are processed by AI to generate your personalised nutrition blueprint, including recommendations and coaching strategies.
The coaching agent analyses your meal tracking data, adherence patterns, and progress to generate personalised nudges, coaching messages, and target adjustments.
If you photograph a product nutrition label (the "Scan label" feature in the app), the photo is sent to an automated recognition service to read the nutrition information. We keep the values read from it, such as product name, nutrition numbers and any allergen statements.
We delete the photo once we have read it. We keep it in two cases: when the label could not be read, and when the product needs checking by our team before it is shown to other users. A photo we keep is stored under a randomly generated address. Deleting your account deletes it, and that is currently the only way to remove it.
Allergen information read from a label is treated as an estimate and may be reviewed by our team before it is shown to other users.
If you build a recipe from a photo of a meal, the photo is sent to the same recognition service to read the ingredients. We keep the photo with the recipe you save, together with what the service proposed and what you changed, so we can improve how well meals are read. Meal photos are never added to the shared food database.
We do not use either kind of photo to identify you, and we do not show your photos to other people using the app. Our team may review photos, and the values read from them, to check quality and to improve how well photos are read. A photo we keep is stored under a randomly generated address that we do not publish and that cannot be guessed. That address is the only thing that keeps it private, so anyone who obtains it can open the photo. It can appear in our server logs, which are handled by the providers listed in section 6.
You can remove a meal photo by deleting the recipe it belongs to. Deleting your account removes your meal photos. If you start a recipe from a photo and never save it, we remove that photo after 30 days.
Our AI features are powered by Google Gemini. When your data is processed by these services, it is subject to their respective privacy policies and data processing terms. We send only the minimum information required to provide the feature (e.g., dietary preferences for meal generation, not your full account profile).
Our Help Centre includes a chat assistant that answers questions about using the app, your account, and billing. You can use it without an account. Chat messages you send are processed by Google Gemini (our LLM provider, located in the United States) to generate answers from our published help articles and legal documents, and chat conversations may be reviewed and stored so we can improve our help content. Before a message is sent to the LLM provider, we automatically replace pattern-detectable personal details (email addresses, phone numbers, payment card numbers, and Medicare or tax file number formats) with placeholders; the original text stays only with us.
Anonymous chat conversations are deleted after 90 days. If you ask to talk to a human, we create a support request containing your recent chat transcript and, for anonymous users, the contact email you provide. Support requests are kept as business records, with contact details and transcripts removed after 180 days for anonymous requests; requests linked to a signed-in account follow the account data lifecycle in Section 8. Support requests are emailed to our support inbox via Resend (our email provider, located in the United States). When our Telegram alert channel is enabled, a short summary of the request (never the transcript or your contact email) is also sent to Telegram, a messaging service that may process data outside Australia.
In accordance with APP 8 (Cross-border disclosure of personal information), we inform you that some of our service providers are located outside Australia. Your personal information may be transferred to and processed in:
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information. Our third-party providers maintain industry-standard security certifications and data processing agreements.
We also disclose personal information to PostHog (product analytics and funnel measurement), which processes it in the European Union, and to Branch (marketing measurement), which processes it in the United States. The safeguards described above apply to both.
By using the Service, you acknowledge and consent to the transfer of your personal information to these countries.
In accordance with APP 11.2, we retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Active Accounts
While your account is active, we retain all information necessary to provide the Service, including your profile, meal plans, tracking history, preferences, and user events.
Account Deletion
When you request account deletion, we will:
Photos
Meal photos are kept for as long as the recipe they belong to exists. Deleting a recipe removes its photo, and deleting your account removes your meal photos. A photo from a recipe you started but never saved is removed after 30 days. Label-scan photos are deleted once they have been read. We keep them only when the label could not be read or the product needs checking by our team, and deleting your account removes those. See section 5.4.
Anonymised Data
Anonymised, aggregated data that cannot identify you may be retained indefinitely for research, analytics, and service improvement purposes.
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights regarding your personal information:
Right of Access (APP 12)
You have the right to request access to the personal information we hold about you. We will respond to your request within 30 days. In most cases, access will be provided free of charge, though we may charge a reasonable fee for providing the information in a specific format.
Right of Correction (APP 13)
You have the right to request that we correct any personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to correction requests within 30 days.
Right to Delete
You may request deletion of your account and associated personal information at any time by contacting us at legal@platify.com.au. Deletion is subject to the retention periods described in Section 8.
Right to Opt Out of Marketing
You may opt out of marketing communications at any time by using the unsubscribe link in any marketing email, or by contacting us. Your preference will be updated promptly.
Right to Withdraw Consent
Where we rely on your consent to process personal information (such as sensitive health data), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawing consent for health data processing may affect our ability to provide certain features of the Service.
To exercise any of these rights, please contact us at legal@platify.com.au. We may need to verify your identity before processing your request.
In accordance with APP 11.1, we take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:
While we take reasonable precautions, no method of electronic storage or transmission over the internet is 100% secure. We cannot guarantee absolute security of your personal information.
The Service is not intended for persons under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18 without appropriate consent, we will take steps to delete that information promptly.
If you believe a child under 18 has provided us with personal information, please contact us at legal@platify.com.au.
We may update this Privacy Policy from time to time to reflect changes to our practices, the Service, or legal requirements. If we make material changes, we will notify you by:
We encourage you to review this Policy periodically. Your continued use of the Service after any changes take effect constitutes your acceptance of the revised Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
We will respond to your enquiry within 30 days in accordance with the Australian Privacy Principles.
In accordance with APP 1.4, if you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may lodge a complaint with us at legal@platify.com.au. We will:
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
This section applies if you are located in the European Economic Area (EEA) or the United Kingdom when you use the Service. It supplements, rather than replaces, the rights described in Section 9, and sets out the additional information the General Data Protection Regulation (GDPR) and the UK GDPR require.
Legal Basis for Processing
We process your personal information under these legal bases:
International Transfers
The service providers listed in Section 6.1 process data outside the EEA and UK, mostly in the United States and Australia. Where we transfer your personal information to these countries, we rely on Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or the provider's own equivalent data protection terms.
Your GDPR Rights
In addition to the rights described in Section 9 (access, correction, deletion, and withdrawing consent), which apply to you under the GDPR as well, you have the right to:
To exercise any of these rights, contact us at legal@platify.com.au. We will respond within one month, as required by the GDPR; if a request is complex, we may extend this by up to two further months and will tell you why.