Legal · last updated September 2026
Privacy Notice
This controlled pre-production notice describes the data flows implemented in the current Supplove MVP and identifies the remaining production prerequisites.
01Controller status
The final production notice must identify the verified legal entity that operates Supplove as data controller, including its legal name, address and contact details. Those verified controller details are not yet present in this repository and remain a production-release blocker.
Privacy requests can currently be directed to privacy@supplove.app.
02Data processed by the current MVP
- email address, account creation time and timezone
- 18+ attestation timestamp/version
- health-data consent timestamp/version and withdrawal timestamp
- authentication/session and rate-limiting metadata
- supplement plans, including user-entered dose and timing
- supplement intake logs and timestamps
- canonical identity/evidence metadata attached to plan and log records where available
- reference-comparison status and reasons generated from logged data where applicable
- in-app reminder interactions
- minimised internal product analytics events
- technical/security metadata processed by the application and infrastructure providers
03Health-related data and explicit consent
Supplement plans, doses, intake history and user-linked reference-comparison results can reveal or permit inferences about health. Supplove therefore treats these data conservatively as potentially falling within the GDPR rules for data concerning health.
Before health-data tracking features are enabled, the application records a separate explicit consent for processing supplement-plan, intake-log and related reference-comparison data. The consent is separate from accepting the Terms and can be withdrawn from Account & Privacy. Withdrawal disables health-data features; it does not itself delete previously stored data. Account/data deletion is available separately.
04Purposes and legal bases
- account/authentication and core service functionality: GDPR Article 6(1)(b), where processing is necessary to provide the service
- proportionate security, abuse prevention and rate limiting: GDPR Article 6(1)(f), subject to necessity, balancing and minimisation
- health-data processing: explicit consent is implemented as the planned Article 9(2)(a) condition for the current MVP health-data purposes; the final production legal analysis and DPIA must confirm the complete basis and wording
- product analytics: limited to allowlisted events and minimised metadata; supplement names, doses, reference statuses and population attributes are not accepted as generic analytics metadata
05Infrastructure providers and transfers
The current architecture names the following providers:
- Vercel — application hosting
- MongoDB Atlas — database hosting
- Resend — transactional magic-link email delivery
Before production, Supplove must verify the contracting entity, data processing agreement, configured region, subprocessors and any transfers outside the EEA for each provider. Where Chapter V GDPR safeguards are required, the applicable transfer mechanism must be documented. This notice does not claim that all processing is EU-only.
06Retention
Authentication token and rate-limit records use expiry fields and database TTL mechanisms. New internal analytics events are pseudonymised and carry a 90-day expiry timestamp enforced by a database TTL index. Legacy analytics rows may require a separate cleanup before production.
Account, supplement-plan and intake-log records are retained while the account exists unless deletion is requested or another legal requirement applies. A final category-specific production retention schedule, including processor and backup handling, remains required.
07Your data-protection controls and rights
Subject to the conditions and limits in applicable law, GDPR rights can include access, rectification, erasure, restriction, objection and data portability, as well as withdrawal of consent where processing is based on consent.
Authenticated users can download a JSON export from Account & Privacy, withdraw health-data consent, and trigger account/data deletion. The deletion workflow removes the user account, supplement plan, intake logs, outstanding magic-link tokens and analytics records linked to the account. Provider copies and backup lifecycle remain subject to the documented processor/retention configuration that must be completed before production.
You may also contact privacy@supplove.app for privacy requests.
08Analytics minimisation
New analytics writes use a keyed pseudonymous user identifier rather than storing the account email. Client analytics are restricted to an allowlist. Health-content fields such as supplement names, doses, reference/safety statuses, substance identifiers, population attributes and free-text health data are not accepted as generic analytics metadata.
09Complaints
You have the right to lodge a complaint with a competent data protection supervisory authority. For a controller established in Poland, the national supervisory authority is the President of the Personal Data Protection Office (Prezes UODO). The final production notice will contain the verified controller and supervisory-authority contact details applicable to the service.
10Automated reference comparisons
Supplove may calculate informational reference-comparison statuses from logged supplement data. The MVP 2 design does not use those statuses to make decisions that produce legal or similarly significant effects. Missing identity, evidence, population or intake scope must remain explicitly not evaluable rather than being treated as safe.
11Remaining production prerequisites
Before public MVP 2 production, Supplove must still complete the verified controller identity, DPIA, provider/transfer inventory, final retention and backup schedule, legacy analytics cleanup where required, and final exact-runtime legal review documented in the LEGAL-001 project materials.