Sorloo

Privacy policy

Last updated: October 2026

Sorloo helps you organise meals, groceries and exercise. To do so we process personal data, some of which is health data. This page explains what we collect, why, and your rights.

Controller

[Company name], [address], registration [number]. Data protection contact: rgpd@sorloo.com.

Data we process

Account data (name, email, hashed password); profile data (food preferences, budget, time, equipment, availability); health data (age, sex, height, weight, measurements, goal, allergies, pregnancy, declared medical situations, household members you add); usage data (plans, logged meals, water, workouts, assistant conversations). Payment data is handled by Stripe only.

Legal basis

Health data is processed only with your explicit consent (GDPR art. 9.2.a), which you can withdraw at any time from your account. Other data is processed to provide the service and to meet legal obligations.

Security

Health data is stored separately and encrypted with AES-256-GCM using a key that never leaves our servers. All traffic uses HTTPS.

Processors

Vercel (hosting, EU region), MongoDB Atlas (database, EU region), Stripe (payments), Anthropic (AI assistant, only the data needed for each request, without your name or email), Hostinger (emails), Unsplash and Pexels (recipe photos, no personal data; Unsplash photos load from their servers). Transfers outside the EU rely on standard contractual clauses.

Retention

Data is kept while your account is active; inactive accounts are deleted after 3 years with prior notice. Billing records are kept 10 years.

Your rights

Access, rectification, export (JSON download from your account), consent withdrawal and one-click deletion of your account and data. Contact rgpd@sorloo.com; you may also complain to your data protection authority.

Disclaimer

Sorloo is a wellness and organisation app, not medical advice.