Privacy notice

Last updated: 4 September 2026

This notice explains what EatWell collects, why, who else handles it, where it goes, how long it is kept, how AI is involved, and what you can ask us to do about it.

It describes EatWell as it actually works during the controlled beta, including the parts that are still being worked on. Where something is not settled yet, it says so instead of rounding it up into a reassurance.

Who is responsible for your data

EatWell is run by Nic Sheen, Weathervane House, LS29 7DP, United Kingdom, who is the data controller for everything described here.

Who this applies to

EatWell is a controlled beta offered to a small group of adults in the United Kingdom. It is not designed or offered for children, and it should not be used to log food on a child's behalf.

There are other things EatWell is not built for. Read EatWell's safety and limits.

What EatWell collects

  • Account and contact details: The email address you sign in with, and the name or profile details you choose to give.
  • Guest and session identifiers: If you try EatWell without registering, an anonymous session identifier ties your entries to that session so you do not lose them.
  • What you log: Meal descriptions in your own words, the estimates produced from them, any corrections you make, usuals and meal plans.
  • Goals and measurements: Calorie and protein goals, and weight or waist measurements, when you choose to supply them.
  • Generated insights: The reflections, patterns and encouragement EatWell produces from your log.
  • Consent and notice records: Which version of this notice you were shown, when, and what you agreed to.
  • Data held in your browser: Sign-in state, your guest identifier, your settings and some caches that keep screens fast. These are described further down.
  • Necessary operational records: Request and error records needed to run and secure the service, sign-in and rate-limiting records, and the email you send to support or privacy.

Why EatWell processes it

  • To sign you in and run the service you are using.
  • To turn what you write about a meal into an estimate, and to produce the reflections you ask for.
  • To keep your history, goals and settings so they are still there next time.
  • To keep EatWell secure, available and fixable when it breaks.
  • To answer your support requests and your data-rights requests.
  • To meet obligations the law places on us.

To be explicit about what does not happen: beta data is not sold, it is not used for advertising, and it is not quietly reused to train an EatWell model.

This is the position EatWell intends to take. It has not yet been through completed legal review, and it will be corrected here if that review changes it.

  • Contract, or steps you have asked for: creating and running your account and providing the core logging and estimate features.
  • Legitimate interests: proportionate security, abuse prevention and reliability work, such as keeping error records, limiting repeated sign-in attempts and diagnosing faults.
  • Legal obligation: where the law requires us to keep or disclose something.
  • Explicit consent: for processing that may reveal information about your health, and for the optional personalised AI reflection.

You can withdraw consent at any time by emailing privacy@simplyeatwell.co.uk. Withdrawing stops any further processing that relies on your consent; it does not make processing that already happened lawfully unlawful.

How AI is involved

Four separate features send data to an AI model, and they send different things.

  • Meal parsing: Sends the meal text you wrote, together with fixed instructions and the current server date and time. Nothing else about you is added to it.
  • Weekly and monthly reflection: Uses aggregate patterns from your log — calorie and protein totals, meal counts and types, weekday and weekend counts, calories by day. It does not send your raw meal text.
  • Positive nudges: Use counts, averages and meal types only. They do not send ingredient-level detail.
  • Smart insight: May use up to seven days of your meal descriptions, shortened and length-capped, with their dates, nutrient figures and daily totals.

No direct account identifier — your account ID, email address or name — is appended to these prompts.

Your calorie and protein goals are not sent to the AI model, and nothing you log is compared with a target. Reflections describe patterns and ranges; they do not score a day or treat a gap as a lapse.

That is not the same as the prompts being anonymous. Meal descriptions, dates, goals and patterns can still identify you or reveal sensitive things about you, so please avoid putting identifying or sensitive facts into a meal description if you would rather they were not processed this way.

Who else handles it, and where

  • Amazon Web Services: Hosts the EatWell application, its database and its operational logs. The current platform runs in the United States.
  • OpenAI: Processes the AI requests described above, and may process them outside the United Kingdom.
  • Amazon SES: Sends your sign-in email.
  • Zoho Mail EU: Handles the human support and privacy mailboxes.

Contractual and international-transfer safeguards with these providers are being finalised before the beta opens. That work is not complete, and putting the paperwork in place does not by itself settle every open question about processing outside the United Kingdom.

How long it is kept

  • Guest sessions and the meals logged in them: Marked in the launch configuration to expire 30 days after your last activity. The actual deletion can happen some time after that mark.
  • Registered account records: Meals, corrections, usuals, plans, measurements, insights and your profile are kept for as long as the account exists, and are removed from live systems after a verified deletion request, apart from anything we are legally required to keep.
  • Essential application logs: 30 days.
  • Support and privacy email: Normally 12 months after the request is closed.
  • Consent and notice evidence: The lifetime of the account plus three years.
  • Protected backups: Rolling backups may still contain deleted records for up to 35 days. They are not restored to give anyone ordinary access to data.

You can delete your account yourself from your Profile page. It asks you to confirm by typing an exact confirmation, and it only proceeds if you signed in within the last 15 minutes, so someone using a session you left open cannot delete your account. Everything listed above is then removed from live systems, apart from anything we are legally required to keep and a minimal record that the deletion happened. If you would rather ask us to do it, email privacy@simplyeatwell.co.uk and we will verify the request and act on it.

Data held in your own browser stays there until the session it belongs to ends, until you clear it, or until your browser or device removes it.

Cookies and device storage

EatWell keeps a small amount of information on your own device. Broadly, it is used for:

  • Signing you in and keeping you signed in
  • Identifying your guest session if you have not registered
  • Remembering the data choice you made, and when
  • Remembering your settings, and caching data so screens load quickly

EatWell does not use advertising cookies, analytics cookies or third-party tracking of any kind. Some of what EatWell stores supports something you asked for; some of it is convenience that is still being assessed, and it is not presented as though it were all strictly necessary.

Cookies and device storage lists every cookie and stored value by name, what it is for, how long it lasts and what stops working if you clear it.

Your controls and your rights

Inside EatWell you can:

  • Edit or delete any individual meal you have logged.
  • Download the account export from your Profile page using “Download my data”.
  • Delete your account and everything stored with it, from the same page.

By emailing privacy@simplyeatwell.co.uk you can ask for access to your data, correction of it, erasure of it, restriction of how it is used, or portability of it, object to processing, or withdraw consent. We may need to confirm who you are before acting on a request.

If you are unhappy with how EatWell has handled your data, you can also complain to the Information Commissioner's Office: make a data protection complaint.

What the AI output is, and is not

Nutrition estimates and reflections are generated using AI. They are approximate, they can be wrong, you can edit or delete them, and they are not medical advice.

Nothing EatWell generates makes a legal or similarly significant decision about you. It is there to help you notice how you eat, not to judge or rank you.

Changes to this notice

EatWell is changing quickly, and this notice will change with it. If a change is material, the date at the top will be updated and, where it matters, the change will be brought to your attention rather than left for you to spot.