This Privacy Policy explains how Realvore collects, uses, shares, and protects personal data when you useRealvore. It also explains your choices and rights.
1. Who we are
The controller for personal data is ShiftC Ltd. Registered address: 66 Paul Street, London, EC2A 4NA, United Kingdom. You can contact us about privacy matters at [email protected] or general questions at [email protected].
2. Information we collect
We collect and process the following categories of information:
- Account data: name, email address, sign-in details, household membership, account settings, and preferences.
- Household and content data: recipes, meal plans, shopping lists, pantry or ingredient data, comments, messages, ratings, tags, allergens, nutrition-related inputs, and other content you add.
- Usage and device data: pages viewed, actions taken, feature usage, approximate location derived from IP address, browser, device, operating system, and app version.
- Logs and diagnostics: IP address, timestamps, errors, crash reports, performance data, and security or abuse signals.
- Communications: support requests, contact messages, feedback, and related correspondence.
- Cookie and analytics data: cookie consent choices, necessary cookies, and optional analytics data where enabled. See our Cookie Policy.
3. How we use information
- Provide, maintain, secure, and improve the service.
- Set up accounts, households, preferences, recipes, meal plans, shopping lists, and related features.
- Respond to support requests, contact messages, and user feedback.
- Monitor performance, debug issues, prevent abuse, and protect the reliability and security of the service.
- Measure product usage where optional analytics are accepted.
- Develop and operate optional AI-assisted features where available.
- Comply with legal obligations and enforce our Terms of Service.
4. Legal bases for UK and EEA users
Where UK or EEA data protection law applies, we rely on the following legal bases, mapped to the purpose of processing:
- Account and service delivery: performance of a contract.
- Security and error monitoring: legitimate interests in protecting the reliability and security of the service.
- Optional analytics: consent, which you can withdraw at any time. See our Cookie Policy.
- Legal compliance: compliance with a legal obligation.
- Health-related data (such as allergens or nutrition-related inputs you choose to add), where applicable: your explicit consent, as the applicable condition for processing special category data under Article 9 of the UK GDPR.
5. Sharing and disclosure
We do not sell personal data. We may share personal data with:
- Service providers: vendors that help provide hosting, analytics, feature flags, AI-assisted features, communications, support, security, and error monitoring.
- Legal and safety recipients: regulators, authorities, advisers, or other parties where needed to comply with law, enforce terms, protect rights, investigate abuse, or protect users and systems.
- Business transfer recipients: parties involved in a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate protections.
6. Vendors and subprocessors
We use the following providers to operate the service:
- Cloud hosting and infrastructure: we share personal data with a UK-based provider that stores, secures, backs up, and delivers the Service on our behalf.
- LaunchDarkly (feature flags): rollouts and configuration. See LaunchDarkly Privacy.
- Heap Analytics (optional product analytics): usage measurement where accepted. See Heap Privacy.
- Sentry (error monitoring): error and performance monitoring. See Sentry Privacy.
- OpenAI (optional AI features): may provide models that power AI-assisted functionality where enabled. See OpenAI Privacy.
- Google Cloud Vertex AI (optional AI features): may provide Gemini models that power AI-assisted functionality where enabled. See Google Privacy.
- Anthropic (optional AI features): may provide Claude models that power AI-assisted functionality where enabled. See Anthropic Privacy.
7. Cookies and similar technologies
We and our providers use cookies, SDKs, local storage, and similar technologies for authentication, preferences, security, analytics, and reliability. Optional analytics are controlled through cookie preferences. Some necessary features may not function without essential cookies.
8. Data retention
We retain personal data for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and operate backups. We retain the following categories of data for the periods below:
- Product analytics: up to 6 months.
- Error and crash reports: up to 30 days.
- Application logs: up to approximately 6 months.
- Backups: up to 3 months.
- Account data after deletion: retained for 90 days after deletion to allow account recovery, after which personal information (name, email, and free-text content) is anonymized. Non-identifying billing and subscription records (transaction IDs, amounts, dates) are retained for accounting and legal purposes.
You may delete content you create, such as recipes and meal plans, from within the app where deletion features are available.
9. Security
We use administrative, technical, and organisational measures designed to protect personal data, including encryption at rest for our database and backups. No transmission or storage system is completely secure, so we cannot guarantee absolute security.
10. International transfers
Our hosting infrastructure is UK-based, so most personal data does not leave the UK. However, some of the providers listed in Section 6 process personal data outside the UK:
- Google Cloud Vertex AI and Anthropic (optional AI features): processed in the EU (Belgium). Transfers from the UK to the EEA are covered by the UK’s data protection adequacy regulations, so no additional contractual safeguard is required.
- OpenAI (optional AI features): processed in the United States. We rely on the EU Standard Contractual Clauses, as amended by the UK International Data Transfer Addendum, as the transfer safeguard.
- LaunchDarkly (feature flags) and Sentry (error monitoring): may process data in the United States. These providers primarily rely on their Data Privacy Framework certifications for transfers from the UK, with the EU Standard Contractual Clauses and UK International Data Transfer Addendum applying as a contractual fallback.
- Heap Analytics (optional product analytics): may process data outside the UK. We rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum as the transfer safeguard.
For details on the specific safeguard relied on for a particular transfer, contact us at [email protected].
11. Your rights
Depending on your location, you may have rights to access, correct, erase, restrict, object to, or export your personal data, and to withdraw consent where processing is based on consent. To exercise rights, contact [email protected]. We may need to verify your request before responding.
If UK data protection law applies, you may also complain to the UK Information Commissioner’s Office. See how to complain to the ICO.
12. Children’s privacy
Realvore is not directed to children and we do not knowingly collect personal data from children under 13 or the age of digital consent in their country. If you believe a child has provided personal data, contact us so we can review and delete it where required.
13. Food, nutrition, and AI information
Some content may relate to recipes, ingredients, nutrition, allergies, or AI-assisted suggestions. This information is subject to our Disclaimer.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the effective date. For material changes, we may provide additional notice.