Overview & Data Controller
This Privacy Policy explains how DietsBinder (“we”, “us”, or “our”) collects, uses, protects, and discloses personal information when you visit our website at dietsbinder.com, complete our lifestyle assessment at /assessment, or create an account via email login or Google OAuth.
DietsBinder provides personalized nutritional guidance, habit coaching, and meal blueprints tailored to your daily schedule. For any questions regarding your personal data or this policy, our Data Controller can be contacted directly at [email protected].
Information We Collect
We only collect personal information necessary to build your personalized meal binder, verify your identity, and provide customer assistance:
- Assessment & Lifestyle Information: When you complete our 3-minute intake, you may provide your name, age, biological sex, height, weight, daily routine (wake time, sleep time, meal times, hydration, exercise frequency), food preferences, and self-reported wellness goals or concerns (such as PCOS, thyroid function, or digestive issues).
- Authentication & Account Information: If you sign in via email, we collect your email address and generate temporary, disposable 6-digit verification codes. If you authenticate with Google, we receive identity tokens as detailed in Section 3.
- Technical & Session Data: We maintain minimal server logs including request timestamps, IP addresses for security auditing and rate limiting, and temporary cryptographic state tokens to ensure safe authentication.
Google User Data & Limited Use Disclosure
DietsBinder allows users to sign in conveniently and securely using Google OAuth 2.0 (“Sign in with Google”). We request only the minimal standard OpenID scopes: openid, email, and profile.
What We Receive from Google
- Google Email Address: Used as your unique account identifier and for sending necessary service communications.
- Name (Given Name / Full Name): Used to personalize your diet binder greeting and meal plan documents.
- Google Subject Identifier (
sub): A secure, unique alphanumeric identifier assigned by Google to associate your session with your saved assessments.
Google API Services User Data Policy Compliance
DietsBinder's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements:
- No Sale: We do not sell, license, or trade Google user data to third parties, data brokers, or advertising networks.
- No Advertising Use: We do not use or transfer Google user data for serving advertisements, retargeting, or building interest profiles.
- No AI Model Training: We do not use Google user data to train, fine-tune, or develop generalized machine learning or artificial intelligence models.
- Strict Human Access Limits: Human personnel do not inspect Google user data unless you provide explicit consent to investigate a specific technical support issue, or when strictly required by applicable law or security emergencies.
How We Use Your Information
We use the collected information exclusively for legitimate service operations:
- Personalizing Meal Blueprints: Aligning meal timing, portions, and real grocery food suggestions to your specific daily timetable.
- Account Management & Session Continuity: Storing your completed assessment so you can revisit, adjust, and view your custom binder without losing progress.
- Transactional Communications: Sending requested login verification codes, account recovery links, and essential service updates.
- Security & Fraud Prevention: Preventing automated abuse, brute-force login attempts, and unauthorized access to parked assessments.
Wellness & Sensitive Information Safeguards
We recognize that dietary preferences and health goals (such as weight management or metabolic wellness) are sensitive. We want to be entirely clear on how this data is treated:
- Your answers are used strictly to customize the timing and structure of your meal binder.
- DietsBinder is a lifestyle and habit coaching platform, not a medical or clinical provider. Your responses are not treated as medical records and are not shared with healthcare networks, insurance carriers, or pharmaceutical companies.
- We do not monetize your health information in any manner.
Third-Party Infrastructure Providers
We do not sell personal data. We only share information with reputable infrastructure partners under strict confidentiality agreements to deliver the service:
- Hosting & Database: Dedicated, secure cloud servers and hosted PostgreSQL databases with isolated access controls and encrypted storage.
- Email Delivery (Resend): Used exclusively to deliver one-time login verification codes directly to your inbox.
- Google Identity Services: Used strictly for OAuth 2.0 authentication when you choose “Continue with Google.”
Data Retention & How to Delete Your Data
We retain personal data only as long as your account remains active or as needed to provide your meal blueprint. Incomplete or unauthenticated intake sessions are automatically purged after 24 hours.
Your Right to Complete Erasure
You have the right to request the permanent deletion of your account, assessment records, and personal profile at any time.
To request deletion, simply email [email protected] from your registered email address with the subject line “Data Deletion Request”.
We will confirm receipt and permanently delete all your associated records from our active database within 30 days.
Your Privacy Rights
Regardless of your geographical location, DietsBinder provides clear privacy rights in line with modern data protection regulations (including GDPR and CCPA principles):
- Right to Access: You can request a copy of all personal data held in your profile.
- Right to Rectification: You can request correction of inaccurate or outdated information.
- Right to Erasure: You can request permanent removal of your data as described above.
- Right to Withdraw Consent: You may revoke Google OAuth permissions at any time via your Google Account Security Settings.
Data Security
We employ rigorous technical safeguards, including HTTPS (TLS) encryption for all data in transit, strict database credential separation, secure server-side session cookies, and cryptographic hashing for email login tokens. However, no internet transmission is 100% immune; we encourage you to protect your device and login credentials.
Contact Us
If you have questions, feedback, or concerns regarding this Privacy Policy or our compliance with Google API policies, please reach out to us: