Privacy policy
Last updated: October 2026
Sorloo helps you organise meals, groceries and exercise. To do so we process personal data, some of which is health data. This page explains what we collect, why, and your rights.
Controller
[Company name], [address], registration [number]. Data protection contact: rgpd@sorloo.com.
Data we process
Account data (name, email, hashed password); profile data (food preferences, budget, time, equipment, availability); health data (age, sex, height, weight, measurements, goal, allergies, pregnancy, declared medical situations, household members you add); usage data (plans, logged meals, water, workouts, assistant conversations). Payment data is handled by Stripe only.
Legal basis
Health data is processed only with your explicit consent (GDPR art. 9.2.a), which you can withdraw at any time from your account. Other data is processed to provide the service and to meet legal obligations.
Security
Health data is stored separately and encrypted with AES-256-GCM using a key that never leaves our servers. All traffic uses HTTPS.
Processors
Vercel (hosting, EU region), MongoDB Atlas (database, EU region), Stripe (payments), Anthropic (AI assistant, only the data needed for each request, without your name or email), Hostinger (emails), Unsplash and Pexels (recipe photos, no personal data; Unsplash photos load from their servers). Transfers outside the EU rely on standard contractual clauses.
Retention
Data is kept while your account is active; inactive accounts are deleted after 3 years with prior notice. Billing records are kept 10 years.
Your rights
Access, rectification, export (JSON download from your account), consent withdrawal and one-click deletion of your account and data. Contact rgpd@sorloo.com; you may also complain to your data protection authority.
Disclaimer
Sorloo is a wellness and organisation app, not medical advice.