Privacy Policy

Last Updated: December 1, 2025

Introduction

CorgInc, ("CorgInc," "we," "our," or "us"), operates the website corgeat.com (the "Website") referred to as the "Services."

This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our meal planning and grocery management platform. Our Services help users plan meals, manage ingredients, create shopping lists, and track nutrition and costs.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our practices, please do not use our Services.

Data Controller & Contact Information

Data Controller:
CorgInc
60 rue Francois 1er
75008 Paris, France

Privacy Contact: contact@corgeat.com

Supervisory Authority (EU Users): Users in the European Union have the right to lodge a complaint with their local data protection authority. A list of supervisory authorities can be found at: https://edpb.europa.eu/about-edpb/board/members_en

Scope of Processing

This Privacy Policy applies to:

  • Registered Users: Individuals who create an account to access personalized features
  • Anonymous/Guest Users: Individuals who use limited features without creating an account
  • Platform Coverage: Our Website, mobile applications (iOS and Android), and any API services we provide

Data We Collect

Account & Identity Data

When you create an account, we collect:

Data Type Purpose Required
Email addressAccount identification, communication, password recoveryYes
UsernameProfile identificationYes
PasswordAccount security (stored in hashed form only)Yes
Profile informationPersonalization (name, profile picture)No

Health, Nutrition & Body Data

To provide personalized meal planning, we may collect:

Data Type Purpose Required
Height and weightCalculating calorie needs and nutritional goalsOptional
Age and genderPersonalizing nutritional recommendationsOptional
Dietary preferencesFiltering meals (vegan, gluten-free, allergies, etc.)Optional
Activity levelAdjusting calorie recommendationsOptional
Nutritional logsTracking daily intake and progressUser-entered
Meal plansOrganizing weekly/daily mealsUser-created
Grocery listsManaging shopping itemsUser-created

Important: Health and nutrition data are used solely to provide and improve our meal planning services. We do not sell this data or use it for advertising purposes.

Payment & Subscription Data

For premium subscriptions, we collect:

Data Type Purpose Storage
Subscription statusDetermining feature accessOur servers
Transaction identifiersOrder tracking and supportOur servers
Billing datesSubscription managementOur servers
Payment method detailsProcessing paymentsThird-party processors only

Note: We do not store complete credit card numbers, bank account details, or other sensitive payment information on our servers. All payment processing is handled by secure third-party payment processors (Apple App Store, Google Play Store, Stripe).

Technical & Usage Data

We automatically collect:

Data Type Purpose
IP addressSecurity, fraud prevention, approximate location for content
Browser type and versionOptimizing website display
Operating systemApp compatibility and optimization
Device identifiersAnalytics, crash reporting
App versionSupport and debugging
TimezoneDisplaying correct times for meal planning
Access timestampsService analytics and security
Crash and diagnostic logsImproving app stability

Automatically Collected Data

Data Type Purpose Control
CookiesSession management, preferences, analyticsCookie settings
Analytics dataUnderstanding usage patternsPrivacy settings
Location data (if enabled)Local store pricing, nearby recipesDevice permissions

Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience. Categories include:

Essential Cookies

Required for basic functionality such as authentication and security. These cannot be disabled.

Cookie Purpose Duration
Session cookieMaintains login stateSession
CSRF tokenSecurity protection1 year

Analytics Cookies

Help us understand how users interact with our Services. You may opt out of these.

Provider Purpose More Information
PostHogProduct analytics and user behaviorPostHog Privacy Policy

Error Monitoring

Used to identify and fix technical issues.

Provider Purpose More Information
SentryError tracking and diagnosticsSentry Privacy Policy

Managing Cookies

You can manage cookie preferences through:

  • Our cookie consent banner (displayed on first visit)
  • Your browser settings (instructions vary by browser)
  • Device settings for mobile applications

Note: Disabling essential cookies may prevent certain features from functioning properly.

Purpose of Processing

We process your personal data for the following purposes:

Purpose Description Legal Basis
Service OperationProviding meal planning, grocery lists, and recipe featuresContract performance
Account ManagementCreating and maintaining your accountContract performance
PersonalizationCustomizing meal recommendations based on preferencesConsent / Legitimate interest
Analytics & ImprovementUnderstanding usage patterns to improve ServicesLegitimate interest
Customer SupportResponding to inquiries and resolving issuesContract performance
Security & Fraud PreventionProtecting accounts and detecting abuseLegitimate interest
Marketing CommunicationsSending newsletters and promotional content (with consent)Consent
Legal ComplianceMeeting legal obligationsLegal obligation

Third-Party Services

We work with trusted third-party service providers to operate our Services:

Analytics & Performance

Provider Purpose Privacy Policy
PostHogProduct analyticshttps://posthog.com/privacy

Error Monitoring

Provider Purpose Privacy Policy
SentryCrash reporting and diagnosticshttps://sentry.io/privacy/

Payment Processing

Provider Purpose Privacy Policy
Apple App StoreiOS subscription paymentshttps://www.apple.com/privacy/
Google Play StoreAndroid subscription paymentshttps://policies.google.com/privacy
Stripe (if applicable)Web payment processinghttps://stripe.com/privacy

Cloud Infrastructure

Provider Purpose Privacy Policy
VercelData storage and processinghttps://vercel.com/legal/privacy-policy

Data Sharing

We Do Not Sell Your Personal Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

When We Share Data

We may share your information in the following circumstances:

Circumstance Details
Service ProvidersThird parties that help us operate our Services (hosting, analytics, payment processing) under strict contractual obligations
Legal RequirementsWhen required by law, court order, or government request
Protection of RightsTo protect our rights, privacy, safety, or property, or that of our users
Business TransfersIn connection with a merger, acquisition, or sale of assets (you will be notified of any change in ownership)
With Your ConsentWhen you explicitly authorize us to share information

International Data Transfers

Our Services may involve transferring your data to countries outside your residence, including the United States and other jurisdictions.

Safeguards for International Transfers

When transferring data internationally, we implement appropriate safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms for data transfers
  • Data Privacy Framework: For transfers to certified US companies
  • Adequacy Decisions: Transfers to countries recognized by the EU as providing adequate protection

By using our Services, you consent to the transfer of your information to countries that may have different data protection standards than your country of residence.

Data Retention

We retain your personal data only as long as necessary for the purposes described in this Privacy Policy.

Data Category Retention Period
Account dataUntil account deletion + 30 days for backup removal
Health/nutrition dataUntil account deletion or upon request
Transaction records7 years (for tax and legal compliance)
Analytics data26 months (aggregated/anonymized)
Support communications3 years after resolution
Server logs90 days

Data Deletion

When you delete your account:

  • Personal data is permanently deleted within 30 days
  • Anonymized/aggregated data may be retained for analytics
  • Some data may be retained if required by law

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Right Description
AccessRequest a copy of your personal data
CorrectionRequest correction of inaccurate data
DeletionRequest deletion of your data ("right to be forgotten")
RestrictionRequest limitation of processing
PortabilityReceive your data in a portable format
ObjectionObject to processing based on legitimate interests
Withdraw ConsentWithdraw previously given consent at any time
Lodge ComplaintFile a complaint with your local data protection authority

Exercising Your Rights

To exercise any of these rights:

  1. In-App: Visit Settings > Privacy > Data Management
  2. Email: Contact contact@corgeat.com
  3. Account Deletion: Settings > Account > Delete Account

We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing certain requests.

California Residents (CCPA/CPRA)

California residents have additional rights including:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

We do not sell personal information as defined under California law.

Children's Privacy

Our Services are not intended for children under the age of 16 (or 13 in the United States).

Our Commitments

  • We do not knowingly collect personal information from children under the applicable age
  • If we discover that a child has provided personal information without proper consent, we will delete it promptly
  • Parents or guardians who believe their child has provided us with personal information should contact us immediately

Parental Rights

If you are a parent or guardian and believe your child has provided personal information to us, please contact us at contact@corgeat.com. We will:

  1. Verify your identity as the child's parent/guardian
  2. Provide access to the child's data upon request
  3. Delete the child's account and associated data

Security Measures

We implement industry-standard security measures to protect your personal data:

Technical Safeguards

  • Encryption in Transit: All data transmitted between your device and our servers uses TLS/SSL encryption
  • Encryption at Rest: Sensitive data stored on our servers is encrypted
  • Password Security: Passwords are hashed using secure algorithms (never stored in plain text)
  • Access Controls: Strict access controls limit employee access to personal data
  • Regular Audits: Security practices are regularly reviewed and updated

Your Responsibilities

To help protect your account:

  • Use a strong, unique password
  • Enable two-factor authentication if available
  • Do not share your login credentials
  • Log out when using shared devices

Security Incidents

In the event of a data breach affecting your personal information, we will:

  • Notify you as required by applicable law
  • Notify relevant supervisory authorities where required
  • Take immediate steps to mitigate the impact

No system is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. You use our Services at your own risk.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

How We Notify You

  • Material Changes: We will notify you via email and/or prominent notice within our Services before changes take effect
  • Minor Changes: Updates will be posted on this page with an updated "Last Updated" date

Your Acceptance

Your continued use of our Services after any changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, please stop using our Services and delete your account.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

CorgInc

Email: contact@corgeat.com

Mailing Address:
60 rue Francois 1er
75008 Paris, France

Response Time: We aim to respond to all privacy-related inquiries within 30 days.

Additional Information by Region

European Economic Area (EEA), UK & Switzerland

  • Data Controller: CorgInc, 60 rue Francois 1er, 75008 Paris, France
  • Supervisory Authority: CNIL (Commission Nationale de l'Informatique et des Libertes)
  • Legal Basis: See "Legal Basis for Processing" section

California, USA

  • Categories of personal information collected: See "Data We Collect" section
  • Business purposes: See "Purpose of Processing" section
  • We do not sell personal information
  • Contact for CCPA requests: contact@corgeat.com

This Privacy Policy was last updated on December 1, 2025.

2025 CorgInc. All rights reserved.