Privacy policy
What is collected, why, for how long, with whom, and how to take back control.
Last updated: September 3, 2026
The data controller
The data controller is ZEPRAUG & CO, Société par actions simplifiée (SAS), whose registered office is at 173 rue de Courcelles, 75017 Paris, France.
No data protection officer is appointed: the appointment is required neither for an organization of this size nor for this kind of processing. Requests are handled by Louis Langevin, président.
Requests about your data are handled at contact@zepraug.com.
The principle
Zemiam processes what it takes to estimate a plate and keep a journal. Nothing is shared or sold to third parties, and everything can be deleted at any time. No health data leaves for advertising purposes: not the food journal, not meal photos, not weight, not measurements, not steps.
One thing does leave for that purpose, named below with its recipient: the device's advertising identifier, together with the fact that the app was installed, opened, and that a subscription was bought. That is what makes it possible to know which ads bring people to Zemiam. It can be refused, and refusing removes no feature.
The site itself sets no cookie, calls no third-party script, and does not measure its own traffic. There is therefore no banner to accept: there is nothing to consent to. Fonts are served from this domain rather than from a remote font service, which avoids a connection to a third party on first load.
The app, on the other hand, can measure its own usage, and only if the person agrees: the question is asked at sign-up, through an unchecked box, and withdraws in one step from the Profile tab. The detail is further down.
What is processed, and what for
| Purpose | Legal basis | Data | Retention |
|---|---|---|---|
| Account and sign-in | Performance of the contract | Email address, sign-in provider identifier | Life of the account, then 12 months of inactivity |
| Goal calculation | Performance of the contract, and explicit consent for health data | Sex, year of birth, height, weight, activity level, goal | Life of the account |
| Food journal and meal photos | Performance of the contract | Meal descriptions, quantities, macronutrients, photos | Life of the account |
| AI analysis of a photo or a description | Consent, logged with a timestamp in the profile | The photo or text sent to the model | The time of the call, no retention by the provider |
| Steps and activity data | Consent, via Apple Health on iOS or Health Connect on Android | Step count, weight | Life of the account |
| Weigh-ins and measurements | Explicit consent | Weight, waist measurement, and other entered measurements | Life of the account |
| Service emails | Performance of the contract | Email address, message delivery status | Life of the account, delivery events purged after 90 days |
| Promotional messages | Consent, an unchecked and separate box | Email address | Until withdrawn, 3 years at most with no interaction |
| Suppression list | Compliance with the right to object | Email address and the reason for the refusal | 3 years after the last contact |
| Shopping list from recipes | Performance of the contract | Checked recipes, number of people, items checked in store: on the device only. Sharing is the person's own action toward the app they choose | On the device, until the person clears it; no copy at Zemiam |
| Rate-limiting of analyses | Legitimate interest, protecting the service from automated use | Account identifier, call counter | 24 hours |
| Billing records | Legal obligation | Accounting records produced by the store | 10 years |
| Advertising measurement | Consent, refusable with no effect on the app | Device advertising identifier, an anonymous identifier assigned by Meta, app install and open, subscription purchase | Until consent is withdrawn |
| Usage measurement | Consent, an unchecked and separate box, withdrawable in the app | Account identifier, screens opened, sign-up steps, the method and calorie total of a logged meal, an analysis result, a paywall view and a subscription, the number of recipes and items on a shopping list and the app it was shared to | Until withdrawn or until the account is deleted, 13 months at most |
Creating an account carries no marketing consent. Consent boxes are unchecked, separate from the terms of use, and separate from one another.
AI analysis
Estimating a photo or a description requires sending that photo or text to a model provider. This only happens after explicit consent, separate from creating the account, and it can be withdrawn at any time from the profile.
The estimation provider called is Gemini, from Google. It is the only one, and no other model receives a photo or a description. The choice of provider is fixed when the server starts: it does not change from one call to the next, and a change requires a deployment, at which point this page is updated.
Google is established outside the European Union and the United Kingdom. Sending a photo or a description is therefore a transfer under UK GDPR as well as under the EU GDPR. For the EU, this transfer is covered by Google's data processing addendum for products where Google acts as a processor, whose full text is public at that address, and its transfers rely on Google's certification to the EU-U.S. Data Privacy Framework, checkable on its public register. For the UK, the equivalent basis is the UK Extension to that same framework, known as the “UK-US Data Bridge”, in force since 12 October 2023, where the recipient participates in it (checkable on the same register), and otherwise the UK's International Data Transfer Addendum.
The photo is sent only for the duration of the call, and it is not used to train a model. That sentence holds under one specific condition, stated rather than implied: the call goes through the paid plan of the Gemini API, the only one whose terms forbid Google from using submitted content to improve its products. The free plan allows the opposite, human review included, and it is not the one used here.
Dictating a meal
Saying what's on the plate sends the microphone's sound, for the length of a sentence, to Deepgram, which writes it down. This only happens after a consent separate from the analysis one, asked on the first dictation, and it can be withdrawn at any time from the profile. The written sentence comes back into the app as if it had been typed, then follows the path of a description: it goes to Google for the estimate, under the terms of the previous paragraph.
The entry point called is the one Deepgram reserves for the European Union, and every call carries the option that keeps the sound out of its model improvement program: the sound is kept only for as long as it takes to write it, neither on the phone, nor at Zemiam, nor at Deepgram beyond processing. Deepgram is established in the United States, and this transfer is covered by a data processing agreement including the European Commission's standard contractual clauses.
Meal photos
Photos are stored in a folder specific to each account, and only that account can write to it or delete a file from it. Reading a file requires no authentication: it requires the file's exact address, which carries the account's identifier and the timestamp of the shot, and which is published nowhere.
This setting is under review, with the goal of moving storage to signed access. This page will be updated the day that happens.
Health and activity data
Step count and weight can be imported from Apple Health on iOS or Health Connect on Android, after authorization given inside the system. This data serves only the calculation of goals. Access is read-only: Zemiam never writes to Apple Health or Health Connect.
It is never used for advertising, never sold, never transferred, and never disclosed to a data broker. Apple forbids it, and that prohibition is repeated here because it is worth being able to read.
Whether weight, measurements, and food intake qualify as health data under the stricter EU and UK rules for special category data is under review. In the meantime, this data is processed on the basis of explicit consent, the more demanding of the two regimes.
Consumer health data (United States)
A few U.S. states regulate consumer health data as its own category, separate from general privacy law, and some give consumers a private right to sue. Washington State's My Health My Data Act is the most documented example. What follows states facts about how Zemiam works, not a conclusion about compliance with any specific state law.
The data Zemiam processes that could be read as consumer health data includes weight, body measurements, step count, and food intake. All of it is processed on the basis of explicit consent, described above, which can be withdrawn at any time. None of it is sold. None of it is disclosed to a data broker. None of it is used for advertising: the advertising measurement described below receives none of it. It can be exported and deleted at any time, as described in the rights section further down.
Emails
Zemiam's messages carry no tracking pixel. Opening a message is not measured, and click tracking is turned off at the sending provider.
Service messages, which accompany how the account works, are sent with no prior consent because they are part of the contract. Promotional messages require a box checked on purpose, and every send carries a free unsubscribe link.
An address that has opted out of sends is kept on a suppression list. This may seem counterintuitive: it is the only way to honor the refusal, since erasing the address would make it possible to re-add it later.
Recipients
| Recipient | Role | Location of processing |
|---|---|---|
| Supabase | Database, authentication, and photo storage | European Union, region eu-west-1 |
| Vercel Inc. | Hosting for the site and the app's server routes | United States, with edge execution in Europe |
| Resend | Sending service emails | European Union, region eu-west-1 |
| Google (Gemini) | Model provider for analyzing photos and descriptions | Outside the European Union |
| Deepgram, Inc. | Writing down a dictated meal, for the length of a sentence | European Union, entry point api.eu.deepgram.com; company established in the United States |
| RevenueCat | Technical management of subscriptions | United States |
| PostHog | Measuring app usage | European Union, Frankfurt region |
| Apple and Google | Sale and billing of the subscription, app distribution | Under the terms of each store |
| Meta Platforms Ireland | Advertising measurement, only if tracking is accepted | Ireland, with transfers to the United States |
All of them are processors except the last: they process on Zemiam's behalf and have no right to reuse what they receive. Meta processes for its own purposes, which is exactly why its case gets the section below, and why it can be refused.
No data is disclosed to a third party outside this list, except under a lawful request from a judicial authority.
Advertising measurement
Zemiam shows no ads. The app buys some, on Facebook and Instagram, and tries to learn which ones bring people who stay. That is the only purpose of what follows.
A component provided by Meta is built into the app. When tracking is accepted, it sends the device's advertising identifier, an anonymous identifier Meta assigns to this install, the fact that the app was installed and then opened, and the fact that a subscription was purchased. Nothing else.
What never reaches Meta, whatever the setting: the food journal, meal photos, weight, measurements, steps, age, sex, goals, email address, and name. No health data, no data that identifies you by name. This data is never sold, transferred, or disclosed to data brokers, and it is never used for credit-worthiness or lending decisions. The list of what is sent is closed by the one above it: the component is never called anywhere else in the code.
None of this leaves without explicit consent. It is asked at sign-up, through an unchecked box, separate from the one for AI analysis and the one for emails. Until it is given, Meta's component is present but closed: it reads no identifier and logs no event.
Withdrawing is as simple as agreeing, and it lives in the app: Profile tab, Ad measurement section. It takes effect immediately, on iPhone as on Android, with no need to go through system settings. Refusing removes no feature of Zemiam and changes nothing about what the app does.
On iPhone, a system window asks its own question on first launch, in addition. It comes from an Apple requirement and does not replace the consent above: its answer changes under Settings, Privacy & Security, then Tracking. On Android, the advertising identifier is removed under Settings, Google, then Ads. A refusal set at either of these places is enough to close everything, including the app's own setting.
Usage measurement
Fixing the app requires knowing where it falls short: which screens are opened, at which step of a flow people stop, by which method a meal is logged, whether an analysis succeeded. That is the only purpose of what follows.
When measurement is accepted, a component provided by PostHog sends, under the account's identifier, the screens opened, the sign-up steps, the method and calorie total of a logged meal, an analysis result, whether a barcode was found, a paywall view, and a subscription. PostHog hosts this data in the European Union, Frankfurt region, on Zemiam's behalf, and has no right to reuse it.
What never leaves, whatever the setting: the food journal, meal photos, weight, measurements, steps, age, sex, goals, email address, and name. No advertising identifier either. The only figure that travels is the calorie total of a logged entry.
This information is neither shared nor sold to third parties. It serves Zemiam and nobody else: no ad network, no data broker, no matching against another service.
Nothing leaves without explicit consent. It is asked at sign-up, through an unchecked box, separate from the other three. Until it is given, the component is not even started.
Withdrawal and deletion are possible at any time: Profile tab, Usage measurement section. Withdrawal takes effect immediately and removes no feature. Deleting the account also erases what was measured, events included, and a written request to contact@zepraug.com gets the same erasure without deleting the account.
How long
Retention periods are in the treatments table. Two points add to it.
- When an account is deleted, the data leaves immediately. Encrypted backups of the database keep a copy for seven days, then that copy disappears on its own.
- Accounting records tied to a subscription are kept for 10 years, because accounting law requires it. They contain no food journal.
Your rights, and the path for each
Everyone has a right of access, rectification, erasure, restriction, objection, and portability, as well as the right to withdraw consent at any time. Here is where each one lives.
- Delete the account and its data. In the app: Profile tab, Account section, Delete account. Deletion is immediate and removes the journal, the photos, the profile, the goals, the weigh-ins, the steps, and the favorites. Without the app, the account deletion page describes the path by email and lists what remains.
- Erase only the journal. Same screen, Erase journal line. The account, profile, and goals stay in place.
- Take your data with you. Same screen, Export my data line. The export is a file readable by another application.
- Withdraw a consent. Consent to AI analysis, to health data, to promotional messages, to advertising measurement, and to usage measurement each withdraw separately from the profile. Withdrawing does not undo what was done before it.
- Write instead, if you would rather not use the app. A request sent to contact@zepraug.com is handled within one month at most, extendable by two months for a complex request, in which case the extension and its reason are announced within the first month.
Complain to a regulator
If a response is unsatisfactory, or absent after the one-month period, a complaint can be filed with a data protection authority.
In the European Union, with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at www.cnil.fr.
In the United Kingdom, with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom, or at ico.org.uk.
Automated decisions
The estimate produced by the model is an aid to data entry. It produces no legal effect and is not an automated decision within the meaning of Article 22 of the GDPR or its UK equivalent. It can be corrected, and it can be deleted.
Minors
The service is for people who meet the minimum age described in the terms of use. Below that age, the consent of whoever holds parental responsibility is required, and Zemiam has no reliable way to collect it.
Security
Exchanges with the service are encrypted in transit. The database enforces row-level isolation by account: a request can only read the data of the account that sends it. Administrative keys never travel through the app.
Changes
This policy may evolve, in particular if a processor changes or if photo storage moves to signed access. The revision date at the top of the page is the reference, and a substantial change is announced in the app before it takes effect.
Version in force since September 3, 2026.