Privacy Policy — the SofiaYuzu app
Last updated: 10 September 2026 · Version 1.0
This policy is about the SofiaYuzu health and food tracker — the app at sofiayuzu.com/app and the same app on the App Store and Google Play. It is complete on its own: everything you need to know about the app is on this page, and you do not have to read anything else to understand it.
If you only read recipes on sofiayuzu.com, or you bought a cookbook, that is a different service with much less data involved, and it has its own policy at sofiayuzu.com/privacy/.
1. Who we are
The app is run by Sofiia Serhiivna Hetman (Гетьман Софія Сергіївна), a private entrepreneur (ФОП) registered in Ukraine, third tax group.
- Record number in the Unified State Register (ЄДР): 2011600000000112030
- Registered address: Microdistrict 2, building 46, Lozova, Kharkiv region, 64606, Ukraine
- Phone: +380 93 118 22 96 — the line takes messages and points you to email.
- Email: admin@sofiayuzu.com — the fast way to reach us; we answer in writing.
We decide what happens to your data, so under the GDPR we are the controller. There is no company, no team and no support department. Two people can reach production data: Sofia, and one technical person who maintains the service — nobody else, and no outsourced support. Sofia is a certified nutritionist and personal trainer, and she reads meal-plan drafts as described in section 8.
Write to admin@sofiayuzu.com about anything on this page. It is the same address for privacy questions, data requests and complaints.
An AI assistant reads that mailbox first and answers routine things — cancelling a web subscription, questions about how the app works — and it says so at the start of every conversation. A person reads everything else, and every request about your data goes to a person. Please do not send us lab results or other health documents by email: put them in the app. If one arrives, we delete the message.
You can write to us in English, German, Spanish, French, Polish, Portuguese, Russian or Ukrainian.
2. The short version
- The app holds health information about you. That is the sensitive part, and sections 3.2 and 4 are about it.
- We do not sell your data, and we do not share it for advertising.
- We do not show ads in the app.
- We never see your card number. Paddle, Apple or Google takes the payment, depending on where you bought.
- AI is used to turn a photo or a sentence into a draft entry you check. It never decides anything about you. We never send it your name, email or account identifier — but a document you upload may have your name printed on it (section 6).
- Your written notes are never sent to the AI provider or to anyone else.
- Reports, charts, streaks and correlations are ordinary arithmetic on your own logs. No AI, and nothing leaves our systems to produce them.
- Our support mailbox is read first by an AI assistant, which tells you so at the start; anything about your data is handled by a person.
- You can export everything and delete everything, at any time, for free.
3. What the app collects
3.1 Your account and your subscription
- Account details: your email address, the name you choose to give, your password (held by Clerk in hashed form — we never see it), your sign-in history, session information and the IP addresses you signed in from.
- Your date of birth, asked once when the account is created. We keep it because we have to be able to show that we checked you are at least 16 (section 14), and because a target calculated from your body data depends on your age.
- The country you are in. We work it out from your IP address, and from the billing country your payment provider gives us. We use it for prices, tax and the consumer rules that apply to you. We do not show it to you in the app, and we do not collect precise location — a country is not a location. If you want to know what we have on record, ask and we will tell you.
- Subscription and trial details: which plan you are on, when your trial or paid period started and ends, whether you cancelled, and the order reference from the shop you bought in.
- About the card, and who charges it. The app is paid from the start; there is no free tier. The 7-day trial requires a card. Where you bought your subscription decides who takes the money and what reaches us:
- On sofiayuzu.com — Paddle's checkout takes your card. What comes back to us is the plan, the dates, whether it is active or cancelled, your billing country and the order reference.
- In the iOS or Android app — Apple or Google takes the payment inside the store. We never see your card, and we do not even see your store account. What reaches us is a server notification from the store: which product, whether it is active, in trial, cancelled or refunded, and the dates.
In no case do we see or store your card number, expiry date or security code.
- App settings: your units, your reminder settings, and which features you have switched on.
- Push tokens: if you turn notifications on, the token your phone or browser gives us, so a notification can reach that device.
- Leaderboard entry, if you join it. The leaderboard lives in the streak window and is off unless you switch it on. When it is on, the top ten are shown to other users, and what they see is the nickname you chose and your points. Nothing else — not your name, not your email, not a single entry from your diary. You can leave at any time and your nickname disappears from the board immediately.
- Consent records: which consents you gave and when, so we can show we asked you properly.
3.2 Your health data
This is what the law calls special category data, and we treat it separately. All of it is optional, and all of it is entered by you:
- Food and drink — what you ate, portions, nutrients.
- Water — what you drank.
- Weight and body measurements.
- Sleep.
- Steps and activity, including numbers read from a screenshot you upload.
- Gym workouts.
- Menstrual cycle data, including period days, spotting, predictions, and — if you switch them on — pregnancy-test and ovulation-test results, discharge and vaginal symptoms.
- Sexual activity, if you use those chips: whether activity happened on a day, and the chips you pick about it. Nothing about partners, and no free-text is required.
- Blood lab results — values, units and reference ranges.
- Mood chips, including ones about low mood, obsessive thoughts and self-criticism.
- Medications and supplements — names, doses, composition.
- Free-text notes you write to yourself, including well-being notes.
- Bowel movement records, if you use that tracker.
- Uploaded files — lab report PDFs and photos of lab forms, and before/after body photos (section 3.3).
Two of these get their own consent. European law treats data about your sex life, and data about reproductive health, as categories of their own — not as a sub-heading of "health". So the consent you give for the tracker does not cover them: they are listed separately on the consent screen that opens the first time you use one of these features, they can be refused without losing anything else, and refusing them leaves the rest of the app working exactly as before.
Your written notes stay with us. Diary notes and well-being notes are never sent to the AI provider or to anyone else. They are stored, encrypted, and used only to show them back to you.
We also calculate things from your logs — calorie and protein targets, charts, streaks, correlations, and the reports the app shows you. See section 7: that is arithmetic, not AI.
3.3 Files you upload
Two kinds of file can be uploaded: lab report PDFs and photos of lab forms, and before/after body photos.
- They are stored in Cloudflare R2, in a bucket with an EU jurisdiction restriction, so the objects stay in the European Union.
- They are encrypted before they are written, and the file name gives nothing away about you.
- Deleting the record in the app deletes the file. When you delete a lab document, a photo, or your whole account, the stored object goes with it in the same operation — it is not left behind.
- We do not run face or body recognition on your photos and we do not build a biometric template from them. Nothing in the app measures or identifies a person from a picture.
- A lab form usually has your name, date of birth and clinic printed on it. If you would rather not store that, type the values in by hand and do not upload the file.
3.4 Technical data
Hosting and security logs from Cloudflare (your IP address, the request, your browser and operating system version), error logs when something breaks, and the anti-abuse check on sign-in forms: our sign-in provider Clerk runs a Cloudflare Turnstile bot check there, which is there to keep bots out.
3.5 What we do not collect
We do not collect precise location. We do not buy data about you from anyone, and we do not receive health information about you from any other source — everything in section 3.2 is what you typed or uploaded yourself. We do not read your device's health app, contacts, calendar or photo library; a photo reaches us only when you pick it.
4. Your consents
We ask for four things when you create your account, as four separate checkboxes. None of them is ticked in advance — you tick what you agree to:
- The terms of use. Required: this is the contract.
- Health data. Required, and here is why we can ask for it: the whole product is a health tracker, so processing what you log is not an extra we bolted on, it is the thing you are buying. What it covers is set out in section 3.2, and you agree that this data is handled by the providers listed in section 9, some of which are in the United States and the United Kingdom, under the safeguards in section 10. You can withdraw it at any time — see below.
- AI features. Optional. Every AI feature has a hand-entry alternative, so the app works fully without it. Refusing costs you nothing.
- Marketing emails. Optional.
Two more consents come later, when they are about to matter:
- The sensitive trackers — cycle and reproductive entries, mood, medications, lab results, body photos, bowel records, sexual activity — ask for their own consent the first time you open one of them, not at sign-up. By then you can see what the feature actually is. Data about your sex life and reproductive health is listed separately there, because the law treats it as a category of its own.
- The meal-plan review asks for its own consent at the moment you request a plan, because that is the one feature that sends anything to Telegram (section 8).
You can withdraw any of these at any time in Profile → Your data → Consents & privacy. Withdrawing is as easy as giving it — the same two taps, in the same place, with no extra questions — and it does not delete your account: the affected features simply stop. Every consent and every withdrawal is logged with its date and the version of the text you saw.
If you withdraw the health-data consent, the tracker cannot do what it exists to do, so it stops. That would leave you paying for something you cannot use, so in that case you can cancel and get money back on the same terms as an ordinary cancellation — we do not make withdrawing a consent worse for you than cancelling. Withdrawal does not undo processing that already happened lawfully before you withdrew.
5. Why we are allowed to process this
| What | Why we may do it |
|---|---|
| Running your account, your trial and your subscription | Performing our contract with you (Art. 6(1)(b) GDPR) |
| Everything you log in the tracker — your health data | Two things at once. Processing it is what the contract you paid for consists of (Art. 6(1)(b)) — a health tracker without health data is not a product. And because it is health data, the law needs a second key on top: your explicit consent (Art. 9(2)(a)). Under Ukrainian law that consent is not a second key but the only one: Article 7 of Law 2297-VI allows data about health and sex life to be processed on your consent and has no "we need it for the contract" route. You can withdraw the consent at any time; section 4 explains what happens then, including your right to a refund |
| Data about your sex life, and reproductive-health data | Your separate explicit consent (Art. 9(2)(a)), asked for on its own. These are categories of their own under Art. 9(1), so the consent above does not cover them |
| Checking that you are at least 16 (your date of birth) | Our legitimate interest in keeping the service away from children, and in being able to show that we checked (Art. 6(1)(f)) |
| Working out which country you are in, from your IP address and from your billing details | Our legitimate interest in showing the right prices and applying the right consumer rules (Art. 6(1)(f)), and a legal obligation for tax (Art. 6(1)(c)) |
| Payment, invoices, tax and accounting records | Performing our contract, and a legal obligation we have (Art. 6(1)(b) and (c)) |
| Hosting, security, anti-abuse and fraud prevention | Our legitimate interest in keeping the service up and safe (Art. 6(1)(f)) |
| Answering your emails and requests | Our legitimate interest in replying to you (Art. 6(1)(f)) |
| Sending photos, documents or text to the AI provider | Your separate consent (Art. 6(1)(a) and, for health data, Art. 9(2)(a)). Every AI feature has a hand-entry alternative, so you can refuse it and keep the whole app |
| Sending a meal-plan draft to Sofia through Telegram | Your separate explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), which is also what makes that transfer lawful under Art. 49(1)(a) |
| Taking your data out of the country you live in (section 10) | Your consent, which is what Ukrainian law requires for a transfer to a country that is not treated as giving adequate protection. Inside the EEA and to the United Kingdom no separate instrument is needed |
| The leaderboard, if you join it | Your consent (Art. 6(1)(a)) — it is off unless you switch it on |
| Marketing emails | Your consent, which you can withdraw at any time |
| Push notifications | Your consent, given on your device |
Do you have to give us this? To have an account you have to accept the terms and give the health-data consent — that is what the service is. The AI consent, the meal-plan review, the leaderboard and marketing are genuinely optional: refuse them and everything else still works.
One difference worth knowing about. European law asks two questions about health data — why you are processing personal data at all, and why you may touch a special category. Ukrainian law asks one, and answers it with a short closed list in which "performing a contract" does not appear. So for us the same tick-box does two different jobs: in the EU it is the special-category exception on top of our contract with you, and in Ukraine it is the entire legal basis. In practice this means one thing to you: withdraw it and the tracker stops, everywhere, with nothing underneath it.
6. AI features
We use an AI model in a small number of places, always to turn something you give us into a draft you then check. AI never runs by itself in the background, and it is never used to make a decision about you.
| What you do | What we send | What comes back |
|---|---|---|
| Describe or dictate a meal | The text you typed (up to 500 characters) | A suggested list of foods with weights and nutrients |
| Photograph a meal or a food label | Up to 4 photos | Suggested dishes, portions and nutrients |
| Upload a lab report, doctor's note or prescription | Page photos, or a PDF of up to 20 pages | The values and the text exactly as printed |
| Photograph a supplement or medicine package | One photo | Product name, dose, composition |
| Type the name of a medicine | The name (up to 80 characters) | Its general pharmacological class |
| Upload a steps or sleep screenshot | One screenshot | The numbers shown in it |
| Photograph a bowel movement | One photo | A suggested type and colour |
| Ask for a monthly meal plan (Max only) | Your calorie and protein targets, your goal, allergies, diet, likes and dislikes, meal times, dates, and our recipe catalogue | A draft month of meals |
| Write to support | Your message, and the earlier messages in that conversation. No health data — we ask you not to send it, and delete it if it arrives | An answer, or a hand-off to a person |
Everything else in the app runs on ordinary code.
About dictation. When you dictate a meal instead of typing it, the speech is turned into text by your own browser or phone, using Apple's or Google's built-in speech service — not by us and not by our AI provider. We receive only the finished text. Which company that is, and what it does with the audio, depends on the device you are using and its settings. If you would rather that did not happen, type instead: the microphone never starts on its own.
We do not send the AI provider your name, your email address or your account identifier. But we do send whatever is visible in a photo you upload. A photograph of a lab form usually has your name, date of birth and clinic printed on it, and we cannot strip that out before the page is read. If you would rather not send it, type the values in by hand.
The AI transcribes; it does not interpret. When it reads a lab report it copies out the values, units and reference ranges exactly as the laboratory printed them, including any high or low marks the laboratory itself printed. It never adds a judgement of its own, and the app never tells you whether a value is good or bad. The app is not a medical device and is not a substitute for medical care.
And it can get it wrong. AI transcription can be incomplete or simply incorrect — a decimal point in the wrong place, a unit misread, a line skipped. Every result is a draft for you to check, and your original document stays the authoritative version. Please compare the numbers against the paper or PDF you uploaded before you rely on them, and never take an app value to a doctor without the original.
Who processes it. Anthropic PBC, United States, acts as our processor under Anthropic's Commercial Terms of Service and Data Processing Addendum. Anthropic does not use what we send to train its models. It deletes inputs and outputs under its published retention policy; where its safety systems flag a request, it may keep them longer.
There is always a manual way. Every AI feature above has a hand-entry alternative — you can type any of it in yourself and never send a photo. The single exception is the monthly meal plan, which exists only as an AI draft read by a person and only on the Max plan; if you do not want that, do not ask for one.
We make no automated decisions about you. Every AI result is a draft you can edit or discard before it is saved, and the meal plan is read by a person before you see it. The rules in Article 22 GDPR on solely automated decision-making therefore do not apply. If that ever changes, we will tell you before it does.
Your choice. You can switch AI features off in Profile → Your data → Consents & privacy.
7. Your reports and charts are not AI
The reports, charts, streaks, correlations and targets the app shows you are calculated arithmetically from your own logs, on our own servers. No AI is involved in producing them, your diary is not sent anywhere to make them, and nobody outside our systems sees them.
8. Your meal plan is read by a person, through Telegram
A monthly meal plan is a Max feature, and it is not released to you automatically. The AI writes a draft and Sofia reads it and approves it before it reaches you. Sofia is a certified nutritionist and personal trainer — a qualification obtained through completed professional nutrition courses. It is a certification, not a state-registered dietitian licence, and her review is a sanity check on the draft, not medical advice.
Here is how that works, in plain terms:
- The draft plan, together with your calorie and protein targets, your goal and your allergy list, is sent to a private chat on Telegram so that Sofia can read it and approve it.
- Your account identifier goes with it — a shortened form of it in the message, and the full identifier inside the approval button. Your name and your email address are not sent.
- Telegram is not our processor. It is a messaging company acting for itself, we have no data processing agreement with it, and the message passes through its servers outside the European Union. We rely on your explicit consent for this, and that is also what makes the transfer lawful.
- What that costs you, stated plainly. There is no adequacy decision for this transfer, no data processing agreement and no standard contractual clauses. So the usual protections are not in place: authorities in the countries the message passes through may be able to reach it, and rights you have under European law may be difficult or impossible to enforce there. That is the specific risk you are consenting to, and it is exactly why this feature is optional and off unless you ask for it.
- How long it stays there. The review chat is cleared on a rolling 30-day schedule, and everything about you is removed from it when you delete your account. Being honest about the limit of that: deleting a message removes it from the chat, and what Telegram keeps on its own servers afterwards is not in our control and not something we can promise you.
- One other thing goes to Telegram, and it is not about you. Sofia gets automatic operational alerts there — how much the AI cost today, that the retention job ran. They contain no health data and no full account identifier.
- If you do not want any of that to happen, do not use the meal-plan feature. Everything else in the app works without it, and no other feature sends anything about you to Telegram.
9. Who else receives your data
We do not sell data and we do not share it for advertising. These are the companies involved in running the app, what each one gets, and whether it acts on our instructions (a processor) or decides for itself (its own controller).
| Company | What it receives | Role |
|---|---|---|
| Cloudflare, Inc. (US, with EU infrastructure) — hosting, the D1 database, R2 file storage, network security | Everything the app stores: your account, your logs, your health data, your uploaded files, plus request logs with your IP address | Processor. Our database is provisioned in Cloudflare's EU region (EEUR); file storage carries an EU jurisdiction restriction |
| Clerk, Inc. (US) — accounts and sign-in, including the Turnstile bot check on the sign-in forms | Your email address, your name if you gave one, your hashed password, sign-in and session history, IP address. No health data | Processor |
| Anthropic PBC (US) — the AI model, in the app and in the assistant that reads our support mailbox | Only what section 6 lists: the text you typed, the photos and documents you chose to send, and the messages you write to support. No name, no email, no account identifier | Processor |
| Paddle.com Market Ltd (UK) — checkout, payments, VAT, invoices, Merchant of Record for purchases on sofiayuzu.com | Your card details, billing address and country, email, what you bought, and the card charged when the trial ends. It sends us back your email, the product, your billing country, the plan and dates, and the order reference | Its own controller for the sale, under its own terms and privacy policy |
| Apple Distribution International Ltd (Ireland) — the seller for purchases made in the iOS app | Your payment details, which product you bought, and your store account — none of which reaches us. It sends us a server notification with the product, the status and the dates | Its own controller for the sale, under Apple's own terms |
| Google — the seller for purchases made in the Android app | The same, through Google Play | Its own controller for the sale, under Google's own terms |
| Brevo (Sendinblue SAS, Paris, France) — transactional email | Your email address and the content of the emails we send you, plus delivery logs | Processor |
| Telegram — the private chat where Sofia reads meal-plan drafts | The draft plan, your targets, your goal, your allergy list and your account identifier, as described in section 8. No name, no email | Its own controller; not our processor, no data processing agreement |
| Google (Firebase Cloud Messaging) — push notifications on Android and the web | Your device push token and the notification text | Processor, under Google's data processing terms |
| Apple Inc. (APNs) — push notifications on iPhone and iPad | Your device push token and the notification text | Processor, under Apple's terms |
| Mozilla — push notifications in Firefox | Your device push token and the notification text | Processor, under Mozilla's terms |
| Open Food Facts (non-profit, France) — barcode lookups | Only the barcode number. The request is made by our server, so your IP address is never visible to them and nothing identifies you | Public database; no personal data is sent |
Some food data comes from Open Food Facts, used under the Open Database License (ODbL), and from the USDA FoodData Central database, which is in the public domain. The app shows the source where that data is used.
Each company marked Processor above works under a written data processing agreement, and every one of them is required by that agreement to provide the same or an equal level of protection for your data as this policy states. We will send you a copy of any of those agreements on request — write to admin@sofiayuzu.com.
Some entries in that table are not processors, and we want to be exact about what that means. Paddle, Apple, Google as sellers, and Telegram act for themselves, under their own terms, and nothing we have signed binds them to this policy. For the three shops that is normal — they are the sellers of record and the law puts its own duties on them. For Telegram it matters more, so section 8 spells out what goes there and what the risk is; nothing reaches Telegram unless you ask for a meal plan.
We may also disclose data if the law requires it, or to establish or defend a legal claim. If that happens we will tell you, unless we are legally forbidden from doing so.
10. Where your data is
We are based in Ukraine. The database and the stored files are provisioned in the European Union. Some of the companies above are outside the EU, so data reaches them there.
- United States — Cloudflare, Clerk, Anthropic, and Google, Apple and Mozilla as push providers. The safeguard is the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), incorporated into each provider's data processing agreement, together with the measures in section 12. For data covered by UK law, the same clauses apply with the UK International Data Transfer Addendum.
- European Union — Brevo (Sendinblue SAS, France) and Apple Distribution International (Ireland). No transfer instrument is needed.
- United Kingdom — Paddle. The UK has an adequacy decision from the European Commission, so no extra instrument is needed.
- Telegram, for the meal-plan review only, as described in section 8. There is no adequacy decision, no data processing agreement and no standard contractual clauses there. It happens on your explicit consent under Art. 49(1)(a) GDPR, only if you ask for a meal plan, and section 8 sets out the specific risk that comes with it.
- If you are in Ukraine, the transfer to the United States rests on two things at once: the Standard Contractual Clauses in each provider's agreement, and your own consent, which is what Ukrainian law requires for a country it does not treat as giving adequate protection. Section 18 sets out what that means for you.
You can ask us for a copy of the clauses and the agreement they sit in — write to admin@sofiayuzu.com. If a copy contains commercial terms that are not about you, we may redact those, and we will say that we have.
11. How long we keep things
| What | How long |
|---|---|
| Your account and all your health data, if you cancel | Fully available to you for 30 days after the subscription ends. From day 30 to day 90 the account is archived — you cannot add to it. On day 90 it is erased. |
| Your account and all your health data, if you just stop using the app without cancelling | After 18 months without signing in we email you a warning. After 24 months without signing in, the account and its data are erased |
| Uploaded lab documents and body photos | Deleted with the record they belong to; otherwise on the same 90-day schedule as the account |
| Subscription and payment records (plan, dates, cancellation, order reference) | For as long as tax and accounting law in Ukraine requires — currently at least 3 years |
| Emails you send us | Up to 24 months |
| The record that you gave — or withdrew — a consent, and when | 3 years after the account closes. It holds no health data, only which consent, which version of the text, and the date. The law puts the burden of proving consent on us, so this one record has to outlive the account. Three years is our own choice, matched to the general limitation period in Ukraine, not a period the law fixes |
| Meal-plan review messages in Telegram | Cleared on a rolling 30-day schedule, and when you delete your account |
| Hosting and security logs at Cloudflare | A short rolling window — currently 7 days on our plan |
| Push tokens | Until you turn notifications off, or the device stops accepting them |
| Log of what was sent to the AI provider | 90 days, then deleted automatically |
| Email delivery logs at Brevo | 1 month |
About backups — the honest version. Our database provider keeps a rolling point-in-time backup that is always on and cannot be switched off, with a window of 30 days. So when you delete something it disappears from the live service straight away and stops being available to anyone, but a copy can still exist inside that backup window until it is overwritten on that fixed schedule. We do not use those backups to bring deleted data back: if we ever had to restore from one, we would re-apply every deletion made in the meantime. That is why we do not tell you deletion is "instant and permanent" — it is instant in the service, and permanent once the window has rolled over.
12. How your data is protected
- Everything travels over encrypted connections (HTTPS/TLS).
- Encryption at rest, precisely. Everything is stored inside Cloudflare's infrastructure, which encrypts data at rest as a platform. On top of that, we encrypt the most revealing fields ourselves, with AES-GCM, before they are written: your free-text notes, your medication and supplement names and doses, your cycle entries, your lab values and labels, and every file you upload. Plain numbers — a weight, a step count, a portion size — are stored as ordinary columns inside that encrypted database. To be exact about the key: encryption uses one key held by the service, not a separate key for each user. We are working towards per-user keys, and we will change this sentence when that is true, not before.
- Responses containing your health data are marked so that browsers and networks do not keep a cached copy on disk.
- Passwords are handled by Clerk and are never visible to us.
- Access to production data is limited to Sofia and one technical person who maintains the service, both under an obligation of confidentiality, both with two-factor authentication on every account involved. There is no team, no outsourced support, and no third-party analytics with access to your health data.
No system is perfectly secure, and we would rather say that plainly than promise otherwise. If a breach happens that is likely to affect your rights, we will notify the relevant supervisory authority and, where the law requires it, you.
If you are in the United States. We are also subject to the Federal Trade Commission's Health Breach Notification Rule (16 CFR Part 318). If unsecured health information about you is acquired or disclosed without authorisation, we will tell you and the FTC without unreasonable delay and in any case within 60 calendar days of discovering it, and we will tell you what happened, what information was involved, what we are doing about it, and what you can do. If 500 or more people in one state or territory are affected, we will also notify prominent media in that area, as the Rule requires.
13. Your rights
Wherever you live, you can ask us to:
- see what we hold about you, and get a copy of it;
- correct anything that is wrong;
- delete your data — there is a Delete account button in the app, and the step-by-step version is at sofiayuzu.com/legal/delete-account/;
- get a portable copy of what you gave us, in a machine-readable file (there is an Export button in the app);
- object to anything we do on the basis of our legitimate interest;
- restrict processing while a dispute is being sorted out;
- withdraw a consent you gave — for health data, for the sensitive trackers, for the AI features, for the meal-plan review, for the leaderboard, for marketing — at any time, without losing your account.
What the export contains. In Profile → Your data → Download my data (JSON) you get a machine-readable file with everything you logged: meals, water, weight and measurements, sleep, steps, workouts, cycle, mood and notes, medications, lab values, bowel records, body photos, goals, settings and streaks. The original PDFs and photos of lab documents are not inside that file — they are large, and you download them one by one from each document. If you want the rest of what we hold about you — the record of which consents you gave, the log of what was sent to the AI provider, your push subscriptions — ask at admin@sofiayuzu.com and we will send it.
These rights work even after your subscription has ended and your account is archived: export and deletion stay available to you throughout.
It is free. We usually answer within a week. Billing disputes and anything complex can take up to two weeks. Requests about your personal data are answered within one month (45 days if you are making a request under Washington State law), and any refund we owe you is paid within 14 days of your notice. If a data request is unusually complex we may need up to two further months, and we will tell you inside the first month if that happens.
To use any of these, write to admin@sofiayuzu.com, or use the Export and Delete account buttons in the app. We may need to confirm that you control the account's email address before we act — that is to stop someone else getting your health data.
14. You must be at least 16
You must be at least 16 to have an app account. The tracker records calorie targets, weight, body photos and cycle data, and we are not willing to put that in front of a child.
We do not knowingly collect data from anyone under 16. We ask for your date of birth before the account is created, and we check it on our side, not only in the browser.
If we find out that an account belongs to someone under 16, we delete the account and everything in it — we do not simply block it and keep the email address — and we refund what was paid.
If somebody else tells us that an account belongs to a child, we do not act on a stranger's word alone. We write to the address on the account, we give 14 days for an answer, and while we wait the account stops accepting new health entries, while reading and export keep working. The full procedure is in section 2 of the App terms.
15. Emails and notifications
- Emails you cannot turn off are the ones we must send to run your account: sign-in and security notices, purchase confirmations, subscription and renewal notices, cancellation confirmations, and answers to your requests. This includes the trial reminder: on day 5 of your 7-day trial we email you with the date the trial ends, the exact amount that will be charged, how often it will be charged after that, and a direct link to cancel.
- Marketing emails only go out if you asked for them, and every one has an unsubscribe link.
- Push notifications are off until you switch them on, and you can switch them off again on your device or in the app. We do not use push for marketing. We do use it, alongside email, to remind you before a yearly subscription renews — the email is the one that counts, the push is a courtesy. Reminder notifications are written so that the text on your lock screen gives nothing away: it says you have a reminder, and the detail is inside the app.
16. Cookies, fonts and analytics in the app
- Necessary only. Inside the app we use cookies and local storage to keep you signed in (Clerk), to remember your settings, and to run the anti-abuse check on sign-in forms (Cloudflare Turnstile, through Clerk). Without them the app cannot work, so there is nothing to consent to.
- Fonts are served from our own domain. Nothing about your visit to the app is sent to Google to display text.
- No analytics in the app, and no advertising SDKs. There is no Google Analytics here, no Meta pixel, no crash-reporting SDK and no third-party analytics of any kind inside the tracker. That is deliberate: an analytics tool that logs which screen you opened would learn that you use a cycle tracker or a mood diary, and we are not sending that to anyone. We count how the app is used with our own counters, on our own servers, in aggregate — never tied to your health entries, and never leaving our systems. We do that on our legitimate interest in knowing whether the product works (Art. 6(1)(f)); the counts are aggregated, and no event name carries anything about your health. Google Analytics runs on the recipe website only, and that site has its own policy.
- YouTube. Recipe videos are embedded on the recipe website, not inside the app.
17. If you are in the United States
Washington State's My Health My Data Act requires a separate policy dealing only with consumer health data. It is here: Consumer Health Data Privacy Policy.
Requests under that law are answered within 45 days, with one possible 45-day extension if the request is complex, and we will tell you if we need it.
We apply the same rules to the consumer health data of Nevada residents under Nevada SB 370.
We do not sell health data, and we do not share it with anyone for advertising.
18. If you are in Ukraine
This section is for people in Ukraine. It adds to the rest of this policy and does not replace it. Where this section and the rest of the policy say different things, this section is the one that applies to you.
Who is responsible. ФОП Sofiia Serhiivna Hetman (Гетьман Софія Сергіївна), record in the Unified State Register of Ukraine (ЄДР) 2011600000000112030, Microdistrict 2, building 46, Lozova, Kharkiv region, 64606, Ukraine, admin@sofiayuzu.com. We are a sole trader registered in Ukraine.
Why we are allowed to hold your health data: because you said yes
In Ukraine, information about your health and your sex life may not be processed at all unless one of a short list of exceptions applies. The only exception that fits a service like ours is your own unambiguous consent. There is no "we need it for the contract" route in that list — so unlike in the European Union, your consent here is not a second lock on top of a contract. It is the whole basis.
What that means for you, plainly:
- we ask for your consent to health data before you enter any of it, with nothing ticked in advance;
- we ask separately again the first time you open one of the sensitive trackers, and the AI features have their own checkbox at sign-up — every one of them has a hand-entry alternative, so you can refuse it and keep the whole app;
- we ask separately again before a meal-plan draft goes to Sofia through Telegram;
- if you withdraw the health-data consent, we stop. There is no fallback basis underneath it that would let us carry on. Your account stays, your data stays until you ask us to delete it, and the tracker stops working — section 4 explains what happens next and what it means for your subscription.
Your account, your subscription and the emails we must send about them run on our contract with you, and our tax records on a legal obligation. Those two do not stop when a consent is withdrawn.
Your data leaves Ukraine, and you are consenting to that
Our database and the files you upload are in the European Union. From there, some of your data reaches companies elsewhere:
| Where | Who | What they get |
|---|---|---|
| United States | Cloudflare, Inc.; Clerk, Inc.; Anthropic PBC; Google, Apple and Mozilla (push) | See section 9 — hosting and storage, sign-in, the AI features, notification delivery |
| United Kingdom | Paddle.com Market Ltd | Checkout, payment, tax, invoice |
| Ireland and France (EU) | Apple Distribution International Ltd; Brevo (Sendinblue SAS) | Store purchases; your email address and the emails we send you |
| Outside all of the above | Telegram | Only a meal-plan draft, and only if you ask for one (section 8) |
Under Ukrainian law some destinations count as giving an adequate level of protection and some do not. The European Union and the United Kingdom are treated as adequate — the United Kingdom because it is a party to Council of Europe Convention 108. The United States is not, and neither is Telegram.
For those two we rely on your consent, and we would rather tell you exactly what you are consenting to than bury it:
- once your data is in the United States, Ukrainian law does not travel with it;
- authorities there may be able to require access to it under their own rules;
- the rights this policy gives you may be harder to enforce there than at home.
There are written contracts in place with Cloudflare, Clerk, Anthropic, Google and Apple — the European Commission's Standard Contractual Clauses, incorporated into each provider's data processing agreement. They are a real protection and we would not use a provider without them. They are not the same thing as Ukrainian law, and we are not going to pretend they are.
If that is not acceptable to you, do not tick the box. The app cannot run without sending data to those companies, so this is an honest dead end rather than a hidden one.
Your rights, and how fast we answer
You can ask us to show you what we hold, correct it, stop processing it, delete it, give you a copy in a machine-readable file, and withdraw any consent you gave. It is free, and you never need an active subscription to use these rights. Write to admin@sofiayuzu.com.
We answer within 30 calendar days, and sooner where we can. If we ever need longer for a genuinely complicated request, we will tell you before the deadline runs out, not after, and we will say why.
We may need to confirm that you control the account's email address before we act. That is the only check we do, and it exists to stop someone else getting your health data.
You must be at least 16
The age limit is 16 here as everywhere else, and section 14 explains why and what we do if we find out otherwise. We do not operate a parental-consent route.
Where to complain
Please tell us first — admin@sofiayuzu.com — because most things are a misunderstanding we can fix the same week. You do not have to, and you can go straight to the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини), ombudsman.gov.ua. You can also go to court where you live. Nothing on this page takes that away.
Language
If you open our site from Ukraine, the Ukrainian version loads by default, and it is never shorter or less detailed than any other version. If you write to us in Ukrainian or Russian, we answer in the same language.
Where the app is not available
We do not offer the app or the cookbooks in Russia, Belarus, Kazakhstan or Uzbekistan, we do not direct our services at those countries, and we do not accept sign-ups or orders from there.
19. Changes to this policy
We update this page when what we do changes — as a rule before the change goes live, not after. Every version carries the date at the top.
If a change matters to you — a new recipient of your data, a new purpose, a change to how long we keep something — we will tell you by email and in the app, and where the law requires it we will ask for your consent again rather than assume it.
20. Complaints
If something here is wrong, or you are unhappy with how we handled a request, please tell us first at admin@sofiayuzu.com. We answer data requests quickly, and most things are a misunderstanding we can fix the same week.
You can also complain to a supervisory authority, and you do not have to talk to us first:
- In the EU: the data protection authority of the country you live in, work in, or where the problem happened.
- In the UK: the Information Commissioner's Office (ICO), ico.org.uk.
- In Ukraine: the Ukrainian Parliament Commissioner for Human Rights (Ombudsman), ombudsman.gov.ua.
- In the United States: your state Attorney General; in Washington State, the Attorney General's office also enforces the My Health My Data Act.
21. Languages
The English text of this page is the one we write and update first.
Where we have published a version in another language, that version is the one that applies to you and you can rely on it. If it differs from the English one, the meaning that is more favourable to you applies. Anything that was more favourable to you in an older translation still applies to what you did while that translation was the published one — we do not get to improve our position by being slow to translate. Once the Ukrainian version is published, it applies to users in Ukraine as Ukrainian law requires.
Today this page is published in English. Translations into German, Spanish, French, Polish, Portuguese, Russian and Ukrainian are being prepared, and each version will show when it was last updated. Until a version in your language is published, the English text applies. If you spot a difference between two versions, write to admin@sofiayuzu.com and we will fix whatever is wrong.
Last updated: 10 September 2026 · ФОП Sofiia Serhiivna Hetman (Гетьман Софія Сергіївна) · ЄДР 2011600000000112030 · Microdistrict 2, building 46, Lozova, Kharkiv region, 64606, Ukraine · admin@sofiayuzu.com