Privacy Policy

Effective date: 24 August 2026

1. Introduction

Platify Pty Ltd ACN 697 195 163 ("we", "us", "our", or "Platify") operates the Platify nutrition coaching platform (the "Service"). We are committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy explains what personal information we collect, how we use and disclose it, and the choices you have regarding your information. By using the Service, you consent to the practices described in this Policy.

This Policy should be read together with our Terms & Conditions and Cookie Policy.

2. Information We Collect

We collect personal information in several ways, depending on how you interact with the Service. Under APP 3 (Collection of solicited personal information), we only collect information that is reasonably necessary for, or directly related to, our functions and activities.

2.1 Information You Provide Directly

Account Information

When you create an account via Google OAuth or email registration, we collect:

  • Full name
  • Email address
  • Profile picture (from your Google account, if available)

Profile & Health Information

When you set up your nutrition profile, we collect:

  • Age, gender, height, and weight
  • Target weight and fitness goals (lose weight, build muscle, maintain)
  • Activity level and occupation type
  • Dietary preferences, allergies, and food exclusions
  • Preferred cuisines and meals per day
  • Timezone

Assessment Responses

When you complete the Platify nutrition assessment (Blueprint), we collect your answers to assessment questions, your score and tier classification, and any personal notes you choose to provide.

Contact Information

When you use our contact form, we collect your name, email address, message content, and any file attachments you provide (images or PDFs, up to 25 MB).

Payment Information

If you subscribe through our website, your payment details (card number, billing address) are collected and processed directly by Stripe. We do not store your full payment card details. We receive and store your Stripe customer ID, subscription status, and billing period information. If you subscribe through the Apple App Store or Google Play, your payment details are collected and processed by Apple or Google, not by us or Stripe.

Food Logging & Tracking

When you use our meal tracking features, we collect:

  • Meals marked as eaten or skipped
  • Foods logged manually, via ingredient search, or by photographing a product nutrition label. When you scan a label, the photo is sent to our servers to read the nutrition values. We delete it once we have read it. We keep it only if we could not read it, or if the product needs checking by our team (see section 5.4). The food record we keep stores the read values, not the image.
  • Photos of meals you cook, when you choose to build a recipe from a photo. The photo is sent to our servers to read the ingredients, and we keep it with the recipe you save (see section 5.4).
  • Scanned barcodes (GTIN/EAN codes) where applicable
  • Weight logs and weekly check-in data (weight, energy level, mood, adherence rating, optional notes)
  • Optional progress photos (web only at launch)

Preferences & Feedback

We collect your ingredient substitution preferences, recipe ratings and favourites, and responses to coaching interventions (accepted, dismissed, or snoozed).

2.2 Information Collected Automatically

When you use the Service, we may automatically collect:

  • Usage data: pages visited, features used, ingredient searches, meal plan interactions, and other actions within the Service (recorded as user events)
  • Device information: browser type, operating system, screen resolution, and device identifiers
  • Log data: IP address, access times, and referring URLs
  • Performance data: page load times and application performance metrics

2.3 Information from Third Parties

We may receive information about you from third-party services:

  • Google: name, email, and profile picture when you authenticate via Google OAuth
  • Apple: name (returned on first sign-in only) and email when you authenticate via Sign in with Apple. If you choose "Hide My Email", Apple provides a private relay address (e.g. an `@privaterelay.appleid.com` alias) that forwards email to your real address. We also receive purchase history from Apple In-App Purchase and from Apple's App Store Server Notifications for subscription lifecycle events.
  • Stripe: subscription status and payment confirmation details (web subscription path only)
  • RevenueCat: in-app purchase entitlement state, product identifiers, and subscription expiration dates (mobile subscription path only)
  • Open Food Facts: nutritional data associated with scanned food barcodes (no personal data is sent to Open Food Facts)

3. How We Use Your Information

In accordance with APP 6 (Use or disclosure of personal information), we use your personal information only for the purposes for which it was collected, or for directly related purposes you would reasonably expect. Specifically, we use your information to:

Provide the Service

  • Generate personalised meal plans based on your goals, preferences, and dietary requirements
  • Provide nutrition coaching and assessment results (Nutrition Report)
  • Calculate and display accurate nutritional information
  • Process ingredient substitutions and dietary accommodations
  • Track your meal adherence, weight progress, and coaching milestones

Manage Your Account

  • Authenticate your identity and maintain your session
  • Process subscription payments and manage billing
  • Send transactional communications (account updates, billing confirmations, security alerts)

Improve the Service

  • Analyse usage patterns to improve features and user experience
  • Monitor application performance and fix technical issues
  • Train and improve our AI models and nutritional database accuracy
  • Generate aggregated, anonymised insights about nutrition trends

Communicate With You

  • Respond to your enquiries and support requests
  • Send coaching notifications, nudges, and milestone celebrations
  • Send marketing communications (with your consent, and you may opt out at any time in accordance with the Spam Act 2003 (Cth))

Legal & Safety

  • Comply with legal obligations and enforce our Terms & Conditions
  • Detect, prevent, and address fraud or security issues

4. Health & Nutrition Data

We recognise that some of the information we collect — including your weight, height, dietary requirements, health goals, meal tracking data, and assessment responses — may be considered sensitive information under the Privacy Act 1988 (Cth).

In accordance with APP 3.3, we only collect sensitive information with your consent. By providing this information through the Service, you consent to its collection and use for the purposes described in this Policy. Specifically:

  • Health and nutrition data is used solely to generate personalised meal plans, calculate nutritional targets, track your progress, and provide coaching guidance.
  • Dietary restriction and allergy data is used to ensure generated meal plans and ingredient substitutions are safe and appropriate for your needs.
  • Weight and body measurement data is used to calculate caloric and macronutrient targets, track progress toward your goals, and adjust coaching recommendations.
  • Weekly check-in data (mood, energy, adherence) is used to refine coaching strategies and detect when adjustments to your plan may be beneficial.

We do not use your health and nutrition data for advertising purposes or sell it to third parties. Your health data is never shared in identifiable form with business partners.

4.1 Apple Health

Connecting Apple Health is optional. If you connect it, Platify reads one thing: your body weight. We do not read steps, workouts, heart rate, or any other health information.

Platify also writes the weigh-ins you log in the app back to Apple Health, so your weight history stays in one place. We only write weigh-ins you recorded yourself.

A weight read from Apple Health is used for the same purposes as a weight you type in: to work out your targets, show your trend, and estimate your energy use. We never use Apple Health data for advertising or marketing, we never sell it, and we do not store it in iCloud.

You can change or withdraw the Apple Health permission at any time in the Health app, under Sharing. That stops all further reading and writing. Weigh-ins that already synced stay in your Platify history: deleting one in the Health app stops it syncing again, but it does not remove the copy Platify has already recorded. To have that copy removed, use the rights described in section 9.

5. AI Processing of Your Data

Platify uses artificial intelligence to provide its core features. We want you to understand how your data is processed by AI systems:

5.1 Meal Plan Generation

Your dietary preferences, goals, macro targets, and exclusions are sent to our AI meal generation service to create personalised recipes and meal plans. All AI-generated recipes undergo human review before being made available.

5.2 Nutrition Assessment (Blueprint)

Your assessment question responses and score are processed by AI to generate your personalised nutrition blueprint, including recommendations and coaching strategies.

5.3 Nutrition Coaching Agent

The coaching agent analyses your meal tracking data, adherence patterns, and progress to generate personalised nudges, coaching messages, and target adjustments.

5.4 Photos You Send Us

If you photograph a product nutrition label (the "Scan label" feature in the app), the photo is sent to an automated recognition service to read the nutrition information. We keep the values read from it, such as product name, nutrition numbers and any allergen statements.

We delete the photo once we have read it. We keep it in two cases: when the label could not be read, and when the product needs checking by our team before it is shown to other users. A photo we keep is stored under a randomly generated address. Deleting your account deletes it, and that is currently the only way to remove it.

Allergen information read from a label is treated as an estimate and may be reviewed by our team before it is shown to other users.

If you build a recipe from a photo of a meal, the photo is sent to the same recognition service to read the ingredients. We keep the photo with the recipe you save, together with what the service proposed and what you changed, so we can improve how well meals are read. Meal photos are never added to the shared food database.

We do not use either kind of photo to identify you, and we do not show your photos to other people using the app. Our team may review photos, and the values read from them, to check quality and to improve how well photos are read. A photo we keep is stored under a randomly generated address that we do not publish and that cannot be guessed. That address is the only thing that keeps it private, so anyone who obtains it can open the photo. It can appear in our server logs, which are handled by the providers listed in section 6.

You can remove a meal photo by deleting the recipe it belongs to. Deleting your account removes your meal photos. If you start a recipe from a photo and never save it, we remove that photo after 30 days.

5.5 Third-Party AI Services

Our AI features are powered by Google Gemini. When your data is processed by these services, it is subject to their respective privacy policies and data processing terms. We send only the minimum information required to provide the feature (e.g., dietary preferences for meal generation, not your full account profile).

5.6 Help Chat Conversations

Our Help Centre includes a chat assistant that answers questions about using the app, your account, and billing. You can use it without an account. Chat messages you send are processed by Google Gemini (our LLM provider, located in the United States) to generate answers from our published help articles and legal documents, and chat conversations may be reviewed and stored so we can improve our help content. Before a message is sent to the LLM provider, we automatically replace pattern-detectable personal details (email addresses, phone numbers, payment card numbers, and Medicare or tax file number formats) with placeholders; the original text stays only with us.

Anonymous chat conversations are deleted after 90 days. If you ask to talk to a human, we create a support request containing your recent chat transcript and, for anonymous users, the contact email you provide. Support requests are kept as business records, with contact details and transcripts removed after 180 days for anonymous requests; requests linked to a signed-in account follow the account data lifecycle in Section 8. Support requests are emailed to our support inbox via Resend (our email provider, located in the United States). When our Telegram alert channel is enabled, a short summary of the request (never the transcript or your contact email) is also sent to Telegram, a messaging service that may process data outside Australia.

6. Sharing Your Information

In accordance with APP 6, we do not sell your personal information. We may share your information in the following circumstances:

6.1 Service Providers

We use trusted third-party service providers to operate the Service. These providers are contractually obligated to protect your information and may only use it for the purposes we specify:

ProviderPurposeData Shared
StripePayment processing (web subscriptions)Email, billing details
Apple (Sign in with Apple, In-App Purchase, App Store Server Notifications)Authentication and mobile payment processingName (first sign-in), email or relay address, purchase tokens, subscription state
RevenueCatMobile in-app purchase receipt validation and entitlement managementApple purchase tokens, subscription state, your Platify user ID
Google (OAuth)AuthenticationEmail, name, profile picture
Google (Gemini AI)Meal plan generation, assessments, food recognition, help chat repliesDietary preferences, assessment responses, food descriptions, nutrition-label photos and meal photos, help chat messages (pattern-detectable personal details replaced with placeholders)
Google AnalyticsUsage analyticsAnonymised usage data, page views, events
Microsoft ClaritySession analytics and heatmapsAnonymised session recordings, interaction patterns
ResendEmail deliveryEmail address, name, message content
Telegram (when our alert channel is enabled)Instant support-request alerts to our teamSupport request id, category, one-line summary (never the transcript or your contact email)
Neon (PostgreSQL)Database hostingAll application data (encrypted in transit and at rest)
Upstash (Redis)Session cachingTemporary meal plan data (24-hour TTL)
VercelHosting, file storage, performance monitoringApplication data, recipe images, photos you upload, performance metrics
Expo (push notifications)Mobile push notification delivery (proxy to Apple APNs and Google FCM)Device push token, your Platify user ID, the notification payload
Grafana Cloud (Loki, Tempo)Server-side observability (application logs and request traces)Pino server logs (request IDs, status codes, latency, your Platify user ID when authenticated, and the storage addresses of photos you upload). No payload bodies.
PostHogProduct analytics and funnel measurementPseudonymous device or visitor identifier, your Platify user ID once you are signed in, app and site usage events, the campaign parameters your visit or install arrived with, and subscription events including the amount paid, the currency and the subscription identifier
BranchMarketing measurement (which source led to an app install)Pseudonymous web visitor identifier, a device-scoped install identifier from the app (the identifier for vendors on iOS), campaign parameters, the page you arrived from and the page you landed on

6.2 Anonymised & Aggregated Data

We may share anonymised, aggregated data with business partners, researchers, or other third parties for purposes such as industry research, nutritional trend analysis, and product development. This data is fully de-identified and cannot be used to identify you personally. Examples include aggregated usage statistics, popular cuisine trends, and general nutritional patterns across our user base.

6.3 Legal Requirements

We may disclose your personal information if required to do so by law, regulation, legal process, or enforceable government request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

6.4 Business Transfers

If Platify Pty Ltd is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

7. International Data Transfers

In accordance with APP 8 (Cross-border disclosure of personal information), we inform you that some of our service providers are located outside Australia. Your personal information may be transferred to and processed in:

  • United States: Google (authentication, AI services, analytics), Stripe (payment processing), Vercel (hosting and file storage), Resend (email delivery), Upstash (caching)
  • Australia (ap-southeast-2): Neon PostgreSQL (primary database)

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information. Our third-party providers maintain industry-standard security certifications and data processing agreements.

We also disclose personal information to PostHog (product analytics and funnel measurement), which processes it in the European Union, and to Branch (marketing measurement), which processes it in the United States. The safeguards described above apply to both.

By using the Service, you acknowledge and consent to the transfer of your personal information to these countries.

8. Data Retention

In accordance with APP 11.2, we retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Active Accounts

While your account is active, we retain all information necessary to provide the Service, including your profile, meal plans, tracking history, preferences, and user events.

Account Deletion

When you request account deletion, we will:

  • Promptly delete or de-identify all personal information that is not required to be retained by law
  • Retain records required for legal, tax, or regulatory purposes for the minimum period mandated by applicable law (for example, financial records may be retained for up to 7 years in accordance with the Income Tax Assessment Act 1997 (Cth) and Corporations Act 2001 (Cth))
  • Permanently delete cached data (Redis session data expires automatically after 24 hours)

Photos

Meal photos are kept for as long as the recipe they belong to exists. Deleting a recipe removes its photo, and deleting your account removes your meal photos. A photo from a recipe you started but never saved is removed after 30 days. Label-scan photos are deleted once they have been read. We keep them only when the label could not be read or the product needs checking by our team, and deleting your account removes those. See section 5.4.

Anonymised Data

Anonymised, aggregated data that cannot identify you may be retained indefinitely for research, analytics, and service improvement purposes.

9. Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights regarding your personal information:

Right of Access (APP 12)

You have the right to request access to the personal information we hold about you. We will respond to your request within 30 days. In most cases, access will be provided free of charge, though we may charge a reasonable fee for providing the information in a specific format.

Right of Correction (APP 13)

You have the right to request that we correct any personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to correction requests within 30 days.

Right to Delete

You may request deletion of your account and associated personal information at any time by contacting us at legal@platify.com.au. Deletion is subject to the retention periods described in Section 8.

Right to Opt Out of Marketing

You may opt out of marketing communications at any time by using the unsubscribe link in any marketing email, or by contacting us. Your preference will be updated promptly.

Right to Withdraw Consent

Where we rely on your consent to process personal information (such as sensitive health data), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawing consent for health data processing may affect our ability to provide certain features of the Service.

To exercise any of these rights, please contact us at legal@platify.com.au. We may need to verify your identity before processing your request.

10. Data Security

In accordance with APP 11.1, we take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Encryption at rest: Your data is stored in encrypted databases hosted by Neon (PostgreSQL) with industry-standard encryption
  • Authentication security: Passwords are hashed using bcrypt; OAuth tokens are securely stored and never exposed to client-side code
  • Access controls: Administrative access is restricted to authorised personnel via email whitelist
  • Payment security: for website subscriptions, payment card data is handled exclusively by Stripe, a PCI DSS Level 1 certified payment processor, and we never store your full card details. For app subscriptions, payment card data is handled exclusively by Apple or Google and never reaches us
  • Session management: Sessions use JWT tokens with expiration and secure cookie attributes (HttpOnly, Secure)

While we take reasonable precautions, no method of electronic storage or transmission over the internet is 100% secure. We cannot guarantee absolute security of your personal information.

11. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate and improve the Service. For detailed information about the cookies we use, their purposes, and how to manage your cookie preferences, please refer to our Cookie Policy.

In summary, we use:

  • Essential cookies: Required for authentication and session management (NextAuth session cookie)
  • Analytics cookies: Google Analytics and Microsoft Clarity for understanding how the Service is used
  • Performance cookies: Vercel Speed Insights for monitoring application performance

12. Children's Privacy

The Service is not intended for persons under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18 without appropriate consent, we will take steps to delete that information promptly.

If you believe a child under 18 has provided us with personal information, please contact us at legal@platify.com.au.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, the Service, or legal requirements. If we make material changes, we will notify you by:

  • Posting the updated Policy on this page with a revised effective date;
  • Sending you an email notification (for material changes); or
  • Displaying a notice within the Service.

We encourage you to review this Policy periodically. Your continued use of the Service after any changes take effect constitutes your acceptance of the revised Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:

We will respond to your enquiry within 30 days in accordance with the Australian Privacy Principles.

15. Complaints

In accordance with APP 1.4, if you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may lodge a complaint with us at legal@platify.com.au. We will:

  • Acknowledge your complaint within 7 days;
  • Investigate the matter and provide a written response within 30 days; and
  • Take appropriate action to resolve the complaint where we find it to be justified.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

16. GDPR & UK GDPR (EEA and UK Residents)

This section applies if you are located in the European Economic Area (EEA) or the United Kingdom when you use the Service. It supplements, rather than replaces, the rights described in Section 9, and sets out the additional information the General Data Protection Regulation (GDPR) and the UK GDPR require.

Legal Basis for Processing

We process your personal information under these legal bases:

  • Contract: processing your account, meal plans, food diary, and the other core features you signed up for.
  • Consent: processing health and nutrition data (Section 4), meal and label photos (Section 5.4), and any other sensitive information you choose to provide. You may withdraw this consent at any time as described in Section 9.
  • Legitimate interests: securing the Service, preventing fraud, and improving our features, balanced against your rights and interests.
  • Legal obligation: retaining records where the law requires it, as described in Section 8.

International Transfers

The service providers listed in Section 6.1 process data outside the EEA and UK, mostly in the United States and Australia. Where we transfer your personal information to these countries, we rely on Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or the provider's own equivalent data protection terms.

Your GDPR Rights

In addition to the rights described in Section 9 (access, correction, deletion, and withdrawing consent), which apply to you under the GDPR as well, you have the right to:

  • Restrict how we process your personal information in certain circumstances;
  • Receive a copy of your personal information in a structured, commonly used, machine-readable format (data portability);
  • Object to processing based on our legitimate interests; and
  • Lodge a complaint with your local data protection supervisory authority. UK residents can contact the Information Commissioner's Office at ico.org.uk.

To exercise any of these rights, contact us at legal@platify.com.au. We will respond within one month, as required by the GDPR; if a request is complex, we may extend this by up to two further months and will tell you why.