Legal
Privacy Policy
Effective date: October 4, 2026 · Last updated: October 4, 2026
1. Overview and scope
This Privacy Policy explains how Shivendra Ananthan Chelliah, the independent developer and operator of Moraea (“Moraea,” “we,” “us,” or “our”), collects, uses, shares, retains, and protects personal information. It applies to:
- The Moraea website at moraea.app (and the legacy caltrakplus.app address, which redirects there), including the marketing pages, any waitlist signup surfaces that may be available from time to time, signed unsubscribe and exit-survey pages, and this policy (the “Site”); and
- The Moraea mobile application for iOS and its home-screen widgets (the “App”), a calorie and nutrition tracker for adults working toward nutrition or weight goals, with an optional medication-tracking add-on for people who choose to record a prescribed medication such as a GLP-1.
Together, the Site and the App are the “Services.” This policy describes our practices; please read it before using the Services. If you do not agree with it, please do not use the Services.
Moraea is a personal tracking tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a “covered entity” or “business associate” under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Some information you enter may nonetheless qualify as health data or “consumer health data” under other laws; see Sections 5 and 15.
2. Who we are and how to contact us
The person responsible for your personal information (the data controller, data user, or business where those legal terms apply) is:
Shivendra Ananthan Chelliah (operating as Moraea), an independent developer based in Malaysia.
Email: developer@rainfroglabs.com
For any privacy question, request, or complaint, contact us at the email above. The developer is the privacy contact, and the person in charge of the protection of personal information, for the Services. We have not appointed a separate data protection officer. If we appoint a data protection officer or a regional representative (see Section 15), we will publish their contact details here.
This policy is available in English, Malay, Spanish, and German; use the language picker at the top of the page to switch. The App is available in English, Spanish, and German. Our shorter Malaysian personal-data notice in Bahasa Malaysia is at moraea.app/privacy-ms. We prepare each translation to say the same thing as the English text. If a translation seems unclear or differs from the English, contact us and we will correct it.
3. Our privacy approach at a glance
Moraea is designed to keep your most sensitive information on your own device wherever possible:
- Your food, water, weight, medication-dose, side-effect, and chat logs are stored on your device, not on our servers.
- To restore your setup when you sign in again, we back up your nutrition plan and the minimum setup details used to calculate it (Section 4.4) to your account. This backup contains no food logs, weight history, medication records, side effects, or chats.
- Other data we hold on our servers (your account, subscription status, security and abuse-prevention records, and legacy Friends/Circle records created by older app versions) is described in Section 4 and kept to what each feature needs.
- AI features send only the content needed for the result you ask for, through our relay, to the AI and search providers named in Section 9. The App tells you before this happens.
- Privacy-minimized usage analytics and crash reporting are separate controls shown during onboarding. Both start enabled, and you can switch either one off before continuing or later in Profile. They do not include the contents of your logs, chats, or photos.
- We do not sell your personal information or consumer health data, we do not show ads, and we do not use or share your information for cross-context behavioral advertising or targeted advertising.
- We do not use Apple Health (HealthKit) data for advertising or marketing, and we do not share it with third parties.
4. Information we collect
4.1 Information you provide on the Site (waitlist and email)
- Email address. If you joined (or later join) the Moraea waitlist, we collect the email address you submit and store it in normalized form (trimmed and lowercased) so we can manage signups consistently and email you: launch and availability notices, occasional Moraea product updates, occasional requests for your feedback, and occasional news about other apps we develop. The Site primarily drives App Store downloads; waitlist signup may not always be shown, but emails already collected, and any future waitlist submissions, continue to be processed as described here. Every such email includes a way to unsubscribe, and unsubscribing stops all of these emails. We do not ask for your name, health information, or payment details on the Site, and we never rent, sell, or share your email with other companies for their own marketing. Emails are sent through our email delivery provider (see Section 9).
- Product-feedback email (opt-in offered by older app versions). The current App does not offer an in-app feedback-email opt-in. Older app versions let signed-in users opt in to product-feedback emails by entering an email address. If you opted in through an older version, we continue to honor that consent until you revoke it. We use that address only for occasional product research, including a short exit survey if you later turn off App Store auto-renew or your subscription expires. Every feedback email includes an unsubscribe link; unsubscribing, emailing us, or deleting your account revokes this consent. We do not use your Apple Sign-In email for this purpose without your opt-in.
- Exit-survey responses. If you opted into feedback email and later cancel renewals (or your subscription expires), we may email a signed link to a short survey on the Site. The survey asks why you left and one follow-up based on that reason (for example, a price range you would consider, features you wanted, or which app you switched to). We store your selected reason, the follow-up answer, and any optional short note you submit, together with a reference to the survey send and your account identifier, so we can improve Moraea. Please do not include medical details, photos, or other sensitive health information. Links are signed so only the intended recipient can submit, and the survey API is rate-limited.
4.2 Information collected automatically on the Site
When you visit the Site or submit a form, our hosting and analytics providers may process limited technical information, including:
- Pages viewed and approximate visit timing
- Referring URL or link that brought you to the Site
- Browser type, device type, operating system, and language
- IP address and similar network identifiers in server and platform logs
To reduce abuse of the waitlist form, our server temporarily uses your IP address, and the email you submit, in short-lived in-memory rate limiters. These counters are held only transiently in server memory, are not written to our database, and are not kept as a permanent record.
4.3 Information stored on your device in the App
Your tracking data stays on your device. We do not receive this content on our servers except where a feature described below requires it. On-device data includes:
- Food and nutrition logs: meals and their estimated calories, macronutrients, fiber, sugar, and sodium; meal photos you attach; saved favorite meals; and an estimated nutrition rating for each meal. Entries may be created by typing, photo, barcode scan, voice dictation, chat with Moraea AI, or relogging a favorite or recent meal.
- Water and weight logs, and the progress views built from them.
- Optional medication records, only if you turn on medication tracking: the medication, the dose and schedule you enter from your existing prescription, administration route, injection site, optional notes, injection-site pain, skipped doses, side effects and their severity, and related measurements you choose to record (such as weight, waist, fasting glucose, or blood pressure). You can also generate a “Dose log summary” PDF on your device.
- Your conversations with Moraea AI, the in-app AI food assistant, including recipes it suggests and any recipe photos it shows.
- Profile and plan details: name (optional), sex, height, birth date, current and goal weight, activity level, weight goal and pace, dietary preference, measurement units, language and appearance choices, membership-card style, reminder settings, and your nutrition targets.
Depending on your iOS backup settings, Apple may include local App data in an encrypted device or iCloud backup. Those backups are controlled by Apple and your Apple Account settings, not stored on Moraea servers, and may persist until you delete the applicable backup.
Home-screen widgets, if you add them, read a limited snapshot of on-device data through an App Group on your device; that widget data is not sent to our servers. Earlier app versions let you add a profile photo; the current App no longer shows or uploads one, and any photo previously added stays on your device until you delete the App or your account.
4.4 Account information and nutrition-plan backup
You sign in during onboarding, before your plan is prepared. Sign-in is required to use the App and its online features. The current App offers Sign in with Apple.
- Sign in with Apple. Apple provides an identity token and, depending on your choices, your name (the first time) and either your email address or a private Apple relay email. We may use the name to prefill your profile if it is empty.
- Legacy passwordless email. Some earlier releases offered email sign-in with a short-lived one-time code. Supabase stores the normalized address as the account credential and Resend delivers the code; a non-persistent Cloudflare Turnstile challenge helps prevent automated abuse and may process your IP address, device/browser signals, and a short-lived challenge token. We do not receive a password.
Supabase exchanges your credential for a session stored in the device Keychain. The server account includes a random user identifier, the associated email or Apple relay email, and the account creation date (used, for example, to decide whether a new account is eligible for the introductory Moraea AI session). We use your authentication email only to create, secure, and communicate about your account. Server-side, identity is derived from the signed session token rather than an account identifier supplied in a request.
Nutrition-plan backup. When you finish (or partly complete) nutrition setup, and whenever you edit your plan, the App saves a backup to your account so it can be restored when you sign in again, including on a new device. The backup contains only: your name (if entered), sex, height, birth date, current and goal weight, activity level, weight goal and pace, dietary preference, measurement units, membership-card style, whether setup is complete, and your calorie, protein, carbohydrate, fat, fiber, sugar, sodium, and water targets. It does not contain food, water, or weight logs, medication or dose information, side effects, photos, or chats. Only you can read it (owner-only access controls), and it is deleted with your account. If you sign in to an existing account and choose to build a new plan instead of restoring the saved one, the new plan replaces the saved backup when you finish setup.
4.5 Moraea AI, the AI food assistant
When you use Moraea AI, your device sends a request to our relay (a Supabase Edge Function), which forwards it through the Vercel AI Gateway to third-party AI and search providers so they can estimate the nutritional content of your meal, answer your nutrition question, or suggest a recipe. Each request may include:
- The message you type (or the text produced by on-device voice dictation) and any meal photo you attach
- Recent messages from the same conversation, including short notes describing estimates or recipes Moraea AI showed earlier, so it can revise them
- Names of your frequent meals from the last 30 days (meal names only, not full nutrition values or photos)
- Your local time, reply-style preference, and App language
- A compact nutrition-plan snapshot: your goal direction, saved dietary preference, nutrition and water targets, today’s logged totals, and the amounts remaining. This snapshot does not contain your name, weight, body measurements, medication, dose, notes, or Apple Health samples.
Routing is server-controlled and may change. In the current App, text and photo requests are handled by OpenAI, with Google as a fallback if OpenAI is unavailable. To look up published nutrition facts (for example, for branded or restaurant foods), the model may send a short search query to Perplexity. When Moraea AI suggests a recipe, it may send a short query (the dish name) to Exa to find a matching recipe photo. Search queries are generated by the model from your request and are not meant to include your identity. Older app versions may use earlier routes, including Google as primary and OpenAI or Anthropic as a fallback.
Recipe photos. If a recipe card shows a photo, the App downloads that image directly from the publisher’s website and credits and links the source. Like any web request, that website receives your IP address, request time, and basic device information. The App sends no cookies with these requests and does not send any of your Moraea data to the publisher.
The first time you open the chat, the App asks you to acknowledge an in-app notice that your messages and photos leave your device for AI processing. We do not store meal text, photos, or chat replies in our database; they are processed to return your result, and your chat history is kept on your device. We do not use your requests to train our own AI models, and we mark gateway requests so providers may not use them for training. Providers may still retain request content for a limited period for abuse monitoring, security, or legal compliance under their applicable terms.
4.6 Progress AI insights
If you use Progress AI insights, the App sends a small weekly aggregate snapshot to our relay, which forwards it through the Vercel AI Gateway to OpenAI, with Google as a fallback. The snapshot may include your starting, current, and goal weight and progress toward that goal; weekly protein, hydration, and calorie averages and targets; the number of days you logged meals and water; and the number of weigh-ins in the last 30 days. We do not send food names, medication or dose entries, side-effect notes, chat text, photos, or Apple Health samples for this feature, and we do not store the snapshot in our database.
4.7 Daily AI breakdowns
If you use a daily AI breakdown (shown in the App as a day score), the App sends an allowlisted snapshot for the selected date to our relay and then through the Vercel AI Gateway to OpenAI, with Google as a fallback. It may include the date; counts of meals, water entries, weigh-ins, doses, and side effects logged that day; the highest side-effect severity; nutrition and hydration totals and targets; and an optional current weight. It does not include food or medication names, notes, photos, exact event times, chat text, or Apple Health samples. The snapshot is not stored in our database; the result is cached on your device.
Progress and Daily AI are switched on once you accept the current Terms and this Privacy Policy in the App, and run only when the Progress tab or a day summary requests a result. You can switch off Progress and Daily AI on their own with the “Moraea insights” switch under Profile → Moraea AI, or turn off all future AI processing with the “AI processing” switch under Profile → Moraea AI → Privacy choices. You can turn either back on in the same place.
4.8 Legacy Friends/Circle data (older app versions)
Friends/Circle is not available in the current App. We keep its authenticated server endpoints temporarily so people using an already-released older version do not lose the feature without notice. If you used Friends/Circle in an older version, we may continue to process the following on our servers, linked to your account:
- Your community profile: a display name you choose and a cosmetic profile-card style.
- Weekly activity signals (Friends): for each week, the number of days (0 to 7) on which you hit your protein target, hit your hydration target, and logged food, plus current streak lengths.
- Activity-feed events and interactions (Friends): events such as closing your weekly anchors or logging food, and the cheers and nudges you send to or receive from buddies.
- Your buddy graph (Friends): the buddy relationships you form and the invite codes you create or redeem.
- Circle membership and pact (Circle): membership in a private circle of two to five people that you joined by invitation or were matched into as a “crew”; your chosen weekly focus and target number of days; whether the pact is paused; a yes/no completion for each date; weekly roll-ups; and the invite codes you create or redeem.
- Circle support signals: the predefined support signals, responses, and reactions circle members exchange, and any anonymous daily contribution to an aggregate community count. There is no free-text field in any of these.
- Crew matching and safety: if you asked to be matched into a crew, a queue record holding your display name, chosen focus, target days, and coarse cadence, time-zone, and language buckets; plus any block you place and any report you submit (a predefined reason only) so we can moderate.
We do not share your food names, calories, macros, weight, medication, doses, side effects, meal photos, chat text, or any other free-text content with buddies or circle members. The only free-text you choose is your display name. Circle daily completion statuses are pruned after 35 days and support signals after 7 days; the remaining records are deleted when you delete your account.
4.9 Apple Health (HealthKit)
Only if you grant permission, the App reads certain values from Apple Health (such as weight, steps, and active energy) and can write food, water, and weight entries back to Apple Health. HealthKit data moves between Moraea and Apple Health on your device under Apple’s policies. We never send HealthKit samples to our servers, AI providers, or analytics providers, never use HealthKit data for advertising or marketing, never sell it, and never share it with third parties.
4.10 Subscriptions, purchases, and App Store notifications
Moraea Pro subscriptions and the one-time Moraea Pro Lifetime purchase are sold and processed by Apple through the App Store. We never receive your payment card details. To unlock and verify paid features, we use:
- RevenueCat: a subscription-management provider that receives a pseudonymous account identifier (your Supabase user ID) and App Store purchase and trial lifecycle information (such as product, entitlement status, renewals, expirations, cancellations, one-time purchases, and refunds). We do not send RevenueCat your name, email, health logs, meal data, chat content, or photos.
- Our server entitlement record: which plan you have, whether it is active, its expiry where applicable, and Apple-provided transaction identifiers. It is created and updated from Apple’s signed App Store Server Notifications and, for purchases made before that link existed, from a signed App Store transaction the App sends for verification. Purchases carry your random app account identifier (not your Apple ID) so we can link them to your account. We also record which account has claimed a given original transaction, so one purchase cannot be reused across accounts. We use these records only to decide whether paid features should be available and to prevent misuse.
If you redeem a promotional offer code, redemption happens entirely through Apple’s system flow. We never receive or store the code itself; we only learn of the resulting entitlement.
4.11 Security, abuse-prevention, and service-limit data
To keep the Services secure, enforce fair-use limits, and prevent abuse of our paid AI features, our backend records limited operational data:
- Service-limit counters: per-account counts of AI requests (Moraea AI, Progress AI, and Daily AI), used to enforce daily quotas, and a count of the free introductory Moraea AI submissions used by a new account.
- Rate-limit and abuse counters: short-window request counters keyed to your account and, for some endpoints, to a network identifier, used to throttle and block abusive traffic.
- Security event logs: records of security-relevant events (for example, a blocked request). These contain only a function name, an event type, a short non-identifying detail, a truncated or redacted account reference, and a truncated IP-address prefix. They do not contain your name, email, tokens, request bodies, health data, or message content.
4.12 Usage analytics (user-controlled; on by default)
The App’s usage-analytics control is shown during onboarding and starts enabled. You may switch it off before continuing or at any time under Profile → Data & account → Device & privacy. When enabled, PostHog receives product-usage events such as coarse feature actions, app version, device and OS details, installation age, subscription funnel stage, goal direction, and broad treatment-stage category (for example, “no medication” or “maintenance,” never a medication name or dose), tied to an app-generated random device identifier. It does not receive your name, email, Apple ID, account identifier, food or nutrition values, weight values, medication or dose values, side-effect details, chat text, photos, or HealthKit samples. We disable session replay, automatic screen and tap capture, surveys, and person profiles. As with any internet request, PostHog receives your IP address when events are sent and may use it to derive an approximate location.
4.13 Crash and error reports (user-controlled; on by default)
The separate crash-and-error-reports control is also shown during onboarding, starts enabled, and can be switched off before continuing or later in Profile. When enabled, PostHog Error Tracking receives stack traces, exception types, app build version, and device model and OS. Reports do not include health data or chat content, and properties are sanitized before they are sent. Symbol files uploaded at build time contain our code, not your data.
4.14 Reminders and notifications
Reminders you turn on (for meals, hydration, weight, and, if you track medication, doses on the schedule you entered) are scheduled locally on your device using iOS notifications. We do not operate a push server for these reminders and do not collect a device push token.
4.15 Camera, photos, microphone, speech, and barcodes
With your permission, the App may access:
- Camera and photo library: to capture or attach meal photos and to scan product barcodes.
- Microphone and speech recognition: so you can describe a meal out loud. Speech recognition is configured to run on your device; the text stays on your device unless you send it to Moraea AI.
When you scan a barcode, the numeric barcode is sent directly from the App to Open Food Facts to look up the product. Open Food Facts and its hosting providers may receive technical data such as your IP address and request time. The barcode is not sent to our servers.
4.16 Feedback and support emails you send us
“Request feature” and “Report issue” in the App open your own email app with a pre-filled message that may include your app version. If you send it, or email us directly, we receive your email address and whatever you choose to include. We use it to respond, fix problems, and improve Moraea. Please avoid sending health details we do not need.
5. Consumer health and sensitive data
Some information you enter (such as weight, body measurements, meals and meal photos, dietary preference, medication, doses, and side effects) relates to your health. It is treated as “sensitive,” “special category,” or “consumer health” data under laws such as the EU and UK GDPR, Malaysia’s PDPA, the California Consumer Privacy Act, other U.S. state privacy laws, and the Washington My Health My Data Act.
- We minimize this data on our servers by keeping logs on your device. The only health-related details stored on our servers are the nutrition-plan backup in Section 4.4 (for example, height, weight, and goal weight).
- Health-related content leaves your device for AI processing only when an AI feature needs it. Moraea AI requires your acknowledgment before the first message or photo is sent. Progress and Daily AI send only the aggregate snapshots in Sections 4.6 and 4.7, after you accept the current Terms and this policy. You can withdraw permission for future AI processing at any time in Profile → Moraea AI → Privacy choices.
- While usage analytics is on, PostHog receives your goal direction and a broad treatment-stage category (Section 4.12), never a medication name, dose, or logged value.
- We do not use health or other sensitive data to infer characteristics about you for advertising, we do not sell it, and we do not share it for advertising.
Our Consumer Health Data Privacy Notice sets out in one place the categories of consumer health data we collect and share, why we collect it, where it comes from, who receives it, and how to exercise your rights over it under the Washington, Nevada, Connecticut, and similar consumer health data laws.
6. How we use information
We use personal information to:
- Operate the App: store and display your logs, calculate nutrition targets, back up and restore your nutrition plan, generate Dose log summary PDFs, schedule reminders, and provide the features you use.
- Provide Moraea AI: estimate the nutrition of meals you describe or photograph, answer nutrition questions, and suggest recipes with photos.
- Provide Progress and Daily AI: summarize your own aggregate tracking numbers when you use those features.
- Support older Friends/Circle clients: temporarily keep compatibility services running for already-released versions.
- Operate subscriptions: verify your entitlement, unlock paid features, and manage the introductory Moraea AI session.
- Secure the Services and enforce limits: detect, prevent, and respond to abuse, fraud, and security incidents, and enforce fair-use quotas and rate limits.
- Communicate with you: send waitlist, launch, and occasional product emails described in Section 4.1, opt-in product-research and exit-survey emails, and replies to your messages. You can unsubscribe from non-essential emails at any time.
- Improve and protect the Services: use privacy-minimized analytics and diagnostic reports while their controls are enabled.
- Comply with law: meet legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
We do not use your information for advertising and we do not sell your personal information. If we want to use personal information for a new purpose that is not compatible with these, we will tell you first and, where required, ask for your consent.
7. Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Explicit consent (Art. 9(2)(a) GDPR) for health data we or our processors handle off your device: content you send to Moraea AI, Progress and Daily AI snapshots, and the health-related details in your nutrition-plan backup. You give it through the in-app disclosures and acceptance steps for those features and can withdraw it at any time (Section 14).
- Consent (Art. 6(1)(a)) for waitlist, product-update, feedback, and other-app emails; opt-in exit surveys; and Apple Health access and device permissions.
- Performance of a contract (Art. 6(1)(b)) to provide the App and the features you request, including your account, plan backup and restore, AI features, subscriptions, and temporary support for Friends/Circle in older versions.
- Legitimate interests (Art. 6(1)(f)) to secure the Services, prevent abuse and fraud, enforce fair-use limits, operate the Site, and process privacy-minimized usage and diagnostic telemetry while its controls are enabled. You may object to this processing, and the App lets you switch telemetry off.
- Legal obligation (Art. 6(1)(c)) where processing is required to comply with law, for example tax or breach-notification duties.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Providing account details is needed to use the App; other information is optional, but some features will not work without it.
8. AI features and automated processing
Moraea AI, Progress AI, and Daily AI are AI systems. When you use them, you are interacting with AI, not a person, and their replies, estimates, ratings, scores, recipes, and summaries are generated automatically. These features:
- run only after the applicable in-app disclosure or acceptance described in Sections 4.5 to 4.7, and only when you use the relevant feature;
- receive only the inputs listed in Sections 4.5 to 4.7;
- produce estimates and informational summaries, not decisions that have legal or similarly significant effects on you;
- are advisory only; you can edit, accept, or ignore any output; and
- are not medical advice, diagnosis, or treatment, and never calculate, recommend, or change a medication dose.
We do not use these features to profile you for advertising, we do not use your requests to train our own AI models, and we do not make solely automated decisions about you that have legal or similarly significant effects within the meaning of Article 22 of the GDPR or comparable laws. Your access to paid features depends on your App Store purchase status, not on any assessment of you. The nutrition targets the App calculates on your device use standard formulas from the details you enter, and you can change them at any time.
11. International data transfers
Moraea is operated from Malaysia and is available in many countries. Our database and server functions are hosted by Supabase in South Korea (Seoul region). Our other providers, including Apple, RevenueCat, Vercel, OpenAI, Google, Perplexity, Exa, Anthropic, PostHog, Resend, Cloudflare, and Open Food Facts, may store or process information in the United States, the European Union, and other countries. These countries may have data-protection laws different from those where you live.
Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we and our providers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss-recognized equivalents, or, where a provider is certified, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. For transfers out of Malaysia, we take the steps the PDPA requires so the data receives a comparable level of protection. You may contact us for more information about these safeguards.
12. Data retention
We keep personal information only as long as needed for the purposes described here, then delete or anonymize it.
- On-device App data: kept until you delete it in the App, delete your account, or delete the App.
- Account and nutrition-plan backup: kept while your account exists and deleted through in-app account deletion.
- Legacy Friends/Circle records: kept until you delete your account, except that Circle daily completion statuses are pruned after 35 days and support signals after 7 days.
- Subscription and entitlement records: kept while your account exists and deleted when you delete your account, together with the related RevenueCat subscriber record. Apple keeps its own purchase records under Apple’s policies.
- Service-limit and rate-limit counters: per-account counters are deleted with your account; short-window network counters expire automatically.
- Security event logs: kept for about 90 days and then deleted.
- AI requests and results: not stored in our database. AI and search providers may keep inputs for a limited period under their API or enterprise terms for abuse monitoring, security, or legal compliance. Chat history and AI results stay on your device until you delete them or your account.
- Analytics and crash data (PostHog): kept under our configuration (currently up to 7 years) unless deleted earlier at your request. Turning a control off stops future collection; you may separately ask us to delete data already collected.
- Waitlist email: kept while we continue to send the emails described in Section 4.1, and deleted or suppressed when you unsubscribe or ask us to delete it. We keep a suppression record only if needed to honor your unsubscribe.
- Feedback-email consent and exit-survey records: kept until you unsubscribe, ask us to erase them, or delete your account.
- Support emails: kept as long as needed to resolve your request and for a reasonable period afterwards for follow-up.
- Server, hosting, and analytics logs: kept under our providers’ standard schedules for security, debugging, and aggregate measurement.
We may keep limited records longer where the law requires it or to establish, exercise, or defend legal claims.
13. Security and breach notification
We use reasonable administrative, technical, and organizational measures to protect personal information, including:
- HTTPS/TLS encryption in transit and Apple platform encryption for on-device data
- Storing your session token in the device Keychain
- Server-only database credentials, row-level security, owner-only access to your plan backup, and least-privilege access on our backend
- Input validation, rate limiting, and abuse protections on our APIs
- Security headers such as a Content Security Policy, HSTS, and frame protections on the Site
- Sanitizing telemetry before it is sent, and disabling session replay, automatic capture, and person profiles in PostHog
No method of transmission or storage is completely secure. If a personal-data breach affects you, we will notify you and the relevant authorities where and as required by law, including within the GDPR’s 72-hour timeline and U.S. state breach-notice laws. Where Malaysia’s PDPA applies and a notifiable breach occurs, we will notify the Personal Data Protection Commissioner as soon as practicable and no later than 72 hours after becoming aware of it, and notify affected people without unnecessary delay and no later than seven days after notifying the Commissioner. Where the U.S. FTC Health Breach Notification Rule or a similar consumer-health breach law applies, we will also give the notices it requires to affected individuals, regulators, and, when required, the media. If you believe your interaction with us is no longer secure, please contact us promptly.
14. Your rights and choices
Depending on where you live, you may have some or all of these rights:
- Know whether we process your data and access a copy of it
- Correct inaccurate or incomplete information
- Delete your information
- Receive a portable copy of information you provided
- Withdraw consent where processing relies on consent
- Object to or restrict certain processing
- Opt out of any “sale,” “sharing,” targeted advertising, or profiling (we do none of these), and limit use of sensitive data
- Learn which third parties receive your data (see Section 9)
- Appeal a decision we make about your request
- Lodge a complaint with your data protection authority
How to exercise your rights. Email developer@rainfroglabs.com and tell us what you are asking for. Because most of your data is stored only on your device, we may not hold it; your device copy is already in your control. We may need to verify your identity (for example, by asking you to email from your account address or to confirm details from the App) before responding. You may use an authorized agent where the law allows. We respond within the time the law requires (generally within one month in the EEA and UK, 21 days in Malaysia, and 45 days in U.S. states, extendable where the law permits), and we will not discriminate against you for exercising your rights. If we decline your request, we will explain why and how to appeal; you may appeal by replying to our response, and we will answer the appeal within the time the law requires.
Account deletion.You can delete your account in the App under Profile → Data & account. Deletion erases your on-device data and deletes your server-side records: your authentication record, nutrition-plan backup, subscription-entitlement and transaction-claim records, the associated RevenueCat subscriber record, service-limit and rate-limit counters, feedback-email consent, exit-survey records, and any legacy Friends/Circle profile and connections. It also clears your session, AI choices, and on-device AI caches. Deleting your account does not cancel an App Store subscription (manage that in iOS Settings), does not remove data you previously wrote to Apple Health, and does not automatically erase analytics or crash data already collected; email us to request deletion of that data or of a waitlist email.
In-app choices.You can switch analytics and crash reports on or off under Profile → Data & account → Device & privacy; switch off Progress and Daily AI with “Moraea insights” under Profile → Moraea AI; turn off all future AI processing under Profile → Moraea AI → Privacy choices; control Apple Health, camera, photos, microphone, speech, and notification permissions in iOS Settings; and unsubscribe from non-essential emails using the link in those emails. Withdrawing a choice does not undo processing already completed; you may ask us to delete provider-held data that can reasonably be linked to your requests.
15. Region-specific disclosures
European Economic Area, United Kingdom, and Switzerland
The EU GDPR, the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection apply when you use the Services from these places. Sections 7, 8, 11, and 14 describe our legal bases, automated processing, transfers, and your rights. We have not yet appointed a representative in the EU or the UK under Article 27 of the GDPR; until we do, please contact us directly at the email above. You may complain to us first, and we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to a supervisory authority, for example your local EU data protection authority (in Germany, the authority for your federal state; in Spain, the Agencia Española de Protección de Datos), the UK Information Commissioner’s Office, or the Swiss Federal Data Protection and Information Commissioner.
California
In the past 12 months we have collected these categories of personal information: identifiers (such as email address, account identifier, and IP address); personal characteristics (such as sex and age from your birth date, in your plan backup); commercial information (subscription and entitlement status); internet or other electronic network activity (pages viewed and user-controlled analytics events); approximate geolocation (derived from IP address by our analytics providers); other information you provide (support messages and optional survey answers); and sensitive personal information (health information you choose to enter or send to AI features, and account login credentials). Sources, purposes, and recipients are described in Sections 4, 6, and 9; retention periods are in Section 12. We do not sell or share personal information for cross-context behavioral advertising, have not done so in the past 12 months, and do not knowingly sell or share the personal information of consumers under 16. We use sensitive personal information only to provide the Services you request and for other purposes the law permits, so the right to limit its use does not require further action. California residents may exercise their rights to know, delete, correct, and opt out by emailing us; even where a statutory threshold does not apply to us, we will honor these requests where reasonably possible. Under California’s “Shine the Light” law, we do not share personal information with third parties for their own direct marketing.
Washington, Nevada, Connecticut, and other consumer health data laws
The Washington My Health My Data Act, Nevada’s consumer health data law, Connecticut’s consumer health data provisions, and similar laws regulate “consumer health data.” Where these laws apply, we collect and share consumer health data only as necessary to provide a feature you request or with the consent the law requires; we do not sell it; we do not use geofences around health-care locations; and we restrict access to it. You may access, delete, and withdraw consent for your consumer health data, and ask for a list of the third parties and affiliates with which it has been shared, by emailing developer@rainfroglabs.com. Our separate Consumer Health Data Privacy Notice gives the full disclosures these laws require.
Other U.S. states
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) may have rights to confirm, access, correct, delete, and obtain a portable copy of their personal data; to opt out of targeted advertising, sale, and certain profiling; to obtain a list of the third parties that received their data (see Section 9); and to appeal a denied request. We process sensitive data only with consent where required and only as necessary to provide the features you request. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. If we deny your appeal, you may contact your state attorney general.
Canada
We obtain consent appropriate to the sensitivity of the information, limit collection to what is necessary, and let you access and correct your personal information and withdraw consent by contacting us. The developer named in Section 2 is responsible for the protection of personal information, including under Quebec’s Law 25. Quebec residents may also request data portability and information about automated processing. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d’accès à l’information.
Australia and New Zealand
We handle personal information in line with the Australian Privacy Principles and the New Zealand Privacy Act 2020, including limits on the use and disclosure of health information. We do not use automated decision-making that significantly affects your rights or interests; the AI features in Section 8 produce estimates you can edit or ignore. Send a privacy complaint to the contact email with the subject “Privacy complaint”; we will respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner or the New Zealand Office of the Privacy Commissioner.
Malaysia
We are based in Malaysia. Under the Personal Data Protection Act 2010 (as amended in 2024), we process personal data with your consent (and explicit consent for sensitive personal data such as health data) for the purposes in this policy, give notice in English and Bahasa Malaysia, keep data accurate, secure, and no longer than necessary, and honor requests to access or correct your data, withdraw consent, stop direct-marketing use, and transmit your data to another controller (data portability) where technically feasible. Contact us at the email above for PDPA matters. You may also contact the Personal Data Protection Department (Jabatan Perlindungan Data Peribadi).
Brazil, India, and other countries
Brazil’s LGPD, India’s Digital Personal Data Protection Act, Singapore’s PDPA, Japan’s APPI, South Korea’s PIPA, and other laws may give you rights to confirm processing, access, correct, delete, or port your data, withdraw consent, nominate someone to exercise your rights, and complain to your national authority (for example, Brazil’s ANPD or India’s Data Protection Board). You can exercise any right available to you, and raise any grievance, by emailing us; we will respond within the time your local law requires.
16. Children's privacy
The Services are intended for adults aged 18 and older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
17. Apple platform disclosures
Moraea is distributed through the Apple App Store and follows Apple’s requirements:
- Sign in with Apple data (identity token, and the name and email or relay email you allow) is used to create and secure your account and is not used for marketing without your separate opt-in.
- HealthKit data is used only to provide app features on your device, is never used for advertising or marketing, is never sold, and is never shared with third parties, AI providers, or our analytics providers.
- Third-party AI. The App tells you, before anything is sent, that Moraea AI shares your messages and photos with third-party AI providers, and asks for your permission. The providers are named in Section 9.
- App Store purchases are handled by Apple; we never receive your payment details.
- The App does not track you as defined by Apple’s App Tracking Transparency framework. Our App Privacy details on the App Store are kept consistent with this policy.
18. Third-party links and services
The Services may link to or rely on third-party websites and services, including recipe publishers linked from recipe cards, whose privacy practices are governed by their own policies, not this one. We encourage you to review the policies of Apple, RevenueCat, Supabase, Vercel, OpenAI, Google, Perplexity, Exa, Anthropic, PostHog, Resend, Cloudflare, and Open Food Facts.
19. Changes to this policy
We may update this Privacy Policy as our Services, providers, or the law change. We will revise the “Last updated” date above and, for material changes, give notice in the App or on the Site before the change takes effect and ask for your consent again where the law requires it. A change will not reduce your rights, or apply a new purpose to data already collected, without the notice or choice required by law. We update the English, Malay, Spanish, and German versions together. This policy is a notice of our practices, not a contract.
20. Contact us
If you have questions about this Privacy Policy or our privacy practices, contact:
Shivendra Ananthan Chelliah
Moraea
Email: developer@rainfroglabs.com