Privacy policy
For the Sately iOS app and sately.co · last updated 27 August 2026
Sately is a food diary. It holds what you ate, and some numbers about your body that you choose to enter. That is health data, and it is treated as such: it stays in the EU, it is never sold, and nobody looks at it to sell you anything.
The app is in a private, invite-only beta. There is no public signup, no advertising, and no tracking of any kind — no analytics SDK, no third-party trackers, no advertising identifiers.
Since 27 August 2026 the same account can also sign in on sately.co, so a tester sees their favourites and preferences on a laptop as well as on the phone. It is the same account and the same data — signing in on the website creates nothing new. Reading the website without signing in stays exactly as it was: no account, and nothing about you stored.
Who is responsible
Andreas Eenfeldt, a Swedish physician, is the data controller. He runs Sately personally. Questions, or a request to see or delete your data, go to andreas.eenfeldt@gmail.com.
What Sately stores
- Your email address — the only thing you need to sign in. There is no password for ordinary accounts; you get a one-time code by email.
- What you log — the foods and meals you record, the amounts, the time and date, and the calories, protein and satiety score worked out from them.
- Photos of meals, if you use the camera to log. These are stored, in a private folder only your account can open.
- Body measurements you enter — weight, and optionally waist and blood pressure.
- Your settings — targets, height, age, and the food preferences you set during onboarding, including any diets you follow and foods you avoid.
- Favourites and saved meals you create, in the app or on the website.
- Blood test values — only on accounts where that feature is switched on. It is off for beta testers.
Search terms typed into the food search are recorded without any link to your account, to learn which foods people look for. They cannot be traced back to you.
Where it is kept
In a Supabase database hosted on Amazon Web Services in Ireland (eu-west-1). Your diary, your photos and your measurements stay in the European Union. Each account can only read its own rows — this is enforced by the database itself, not by the app.
Who else processes it
Sately uses a small number of services to work. Each one sees only what it needs:
- Supabase — the database, sign-in, and photo storage. EU region, as above.
- Resend — sends your sign-in code. Sees your email address, nothing else.
- Vercel— runs sately.co and the app's API.
- Umami — counts page views on the website, so we can see which pages get read. It sets no cookies, never receives your email address or anything from your account, and what it records is never linked to you. The app has no analytics at all.
- OpenAI and Anthropic— read meal photos to work out what is on the plate, and write the coach's notes. They receive the photo and the relevant part of your diary for that request. Under their API terms this content is not used to train their models.
- Apple— while the app is distributed through TestFlight, Apple collects crash reports and basic usage information from beta builds and shares them with us. That can include your name and email address, and Apple's own TestFlight privacy notice covers it.
Some of these companies are based outside the EU, so some data leaves it. Those transfers rely on the standard data protection terms each provider offers under EU law.
Cookies, and what stays in your browser
Sately sets no cookies. The website keeps two things in your browser's own storage: which country's shelf you chose, and, if you sign in, the token that keeps you signed in. Both stay on your device — clearing your browser data removes them, and signing out removes the token straight away.
Photographs
Meal photos are kept, because the diary shows them back to you and because they help the next reading be more accurate.
Photographs of a blood test report are never stored. The image travels inside the request that reads it and is gone when that request finishes. Only the numbers you then confirm are saved.
Why we are allowed to hold it
Food logs, weight, blood pressure and blood test values are health data under Article 9 of the GDPR. The legal basis is your explicit consent, given when you choose to enter them. You can withdraw it at any time by asking for your account to be deleted, and nothing in the app requires you to enter a measurement you would rather not.
How long it is kept
Until you ask for it to be deleted. Email the address above and the account and everything attached to it — diary, photos, measurements — is removed. There is no waiting period and no copy kept afterwards, beyond ordinary encrypted backups which age out.
Your rights
Under the GDPR you can ask for a copy of your data, have it corrected, have it deleted, or object to it being processed. Ask at the address above. If you think your data has been mishandled you can complain to the Swedish Authority for Privacy Protection, IMY.
What Sately does not do
- No advertising, and no data sold or shared for marketing.
- No advertising identifiers, no tracking pixels, and no profile built about you. The website counts page views — see Umami above — and that is the whole of it.
- No profiling, and no automated decisions with legal effects.
- Not intended for anyone under 18.
Not medical care
Sately is a food diary and a wellness tool. It is not a medical device, it does not diagnose or treat anything, and it is not a substitute for your own doctor.
Changes
If this policy changes in a way that matters, the date at the top moves and beta testers are told by email. Back to sately.co.