English▾
  • Nederlands
  • English
  • Français
  • Deutsch
  • Español

Tayb — Privacy Policy

2 September 2026

Who we are

Tayb ("we", "us", "our") is a health and nutrition platform that offers personalised meal plans, recipes, shopping lists and wellness information.

Tayb is commercially operated by Drink 18 VOF. That company determines the purposes and means of the processing of your personal data and is therefore the data controller within the meaning of Article 4(7) GDPR.

Data controller: Name: Drink 18 VOF Legal form: General partnership (vennootschap onder firma) Address: Drink 18, 2140 Antwerpen, Belgium Company number: 0760.812.768 VAT number: BE0760812768 Register of legal entities: RPR Antwerpen, afdeling Antwerpen Email: [email protected] Country: Belgium


What data we collect

2.1 Data you provide yourself

During registration:

  • Email address
  • First and last name
  • Password (stored encrypted; we never see your password in readable form)
  • Date of birth (for age verification and nutritional calculations)

During profile setup (onboarding):

  • Gender (male/female — used for nutritional calculations, not for identity)
  • Weight, height and optional waist circumference
  • Activity level (how active you are in daily life)
  • Life stage (e.g. pregnancy, breastfeeding, menopause — see section 5)
  • Primary health goal (e.g. weight loss, more energy, balance)
  • Dietary preferences (e.g. vegetarian, vegan, halal, kosher)
  • Allergies (EU top-14 allergens)
  • Ingredient preferences (dislikes)
  • Fitness level and workout schedule
  • Household size and maximum cooking time
  • Fasting preferences (Islamic fasting, intermittent fasting, or none)

Optionally, if you choose to:

  • Phone number
  • Address details (street, postcode, city, country)
  • Profile photo
  • Bio/description

2.2 Data collected automatically

When using the app:

  • IP address and user agent (browser type/device) upon login
  • Device information (name, type, platform: iOS/Android)
  • Session data (for security purposes)
  • Push notification tokens (if you enable notifications)

When starting a trial:

  • Device ID (to prevent trial abuse)
  • Normalised email address (to prevent alias abuse)

When you join the referral programme (accepting the programme terms):

  • Date, language choice, version number and a checksum (hash) of the exact terms text you were shown
  • A pseudonymised verification code (keyed hash, HMAC) derived from your IP address — for this acceptance record we do not store your IP address as a readable field, and the IP address cannot be read back from the code. The code is linked to your account and therefore remains personal data
  • Browser/device info (user agent), app version and platform

2.3 Data you actively track

  • Daily water intake
  • Body measurements over time (weight, waist circumference)
  • Fasting log (completion, energy and hunger levels, reason for breaking)
  • Meal completion and shopping list ticking

2.4 Location data

We request permission for your location once (via your operating system) in order to:

  • Calculate prayer times for Islamic fasting (fajr/maghrib)
  • Set your time zone correctly
  • Offer seasonal ingredients

Your location is stored with limited precision (~11 metres) and is only used for Tayb features such as prayer times and seasonal ingredients. We do not sell or share your location with third parties outside our processors.

You can also manually select a city instead of using GPS. We do not continuously track your location.


How we collect this data

Method Explanation
Registration form Email, name, password, date of birth
Onboarding steps 6 steps in which you set up your profile, goals and preferences
App settings Changes to profile, preferences and privacy settings
Automatically during use IP address, device info, session data (for security)
Manual tracking Water intake, body measurements, fasting log
External login services Apple Sign-In or Google Sign-In (if you choose this)
Payment providers Subscription status via Stripe (web); in-app purchases via App Store/Play Store with RevenueCat once the app is in the stores

Why we use your data

Purpose Which data Legal basis
Create and manage account Email, name, password or social login credentials Performance of contract (Art. 6(1)(b))
Generate personalised meal plans Weight, height, activity level, goals, allergies, life stage data where relevant Consent (Art. 6(1)(a)) + explicit consent for special categories (Art. 9(2)(a))
Support food safety Allergies, dietary restrictions, preferences Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a))
Provide fasting and religion-related features Fasting preferences, observances, prayer time settings, relevant life stage data Consent (Art. 6(1)(a)) + explicit consent for special categories insofar as these reveal religion or health (Art. 9(2)(a))
Track progress Body measurements, water intake, logs, history Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a))
Display safety warnings Weight, age, life stage, allergies, BMI or derived signals Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a))
Process subscription and payments Subscription status, payment provider ID, billing details Performance of contract (Art. 6(1)(b)) and, where legally required, legal obligation (Art. 6(1)(c))
Prevent trial abuse and combat fraud Device ID, normalised email address, IP address, subscription history Legitimate interest (Art. 6(1)(f))
Secure your account IP address, session information, MFA credentials, login history Legitimate interest (Art. 6(1)(f))
Send functional emails Email address, name, account status Performance of contract (Art. 6(1)(b))
Marketing communications Email address, name Consent (Art. 6(1)(a))
Push notifications Push token, device information, notification preferences Consent (Art. 6(1)(a))
Customer support Ticket content, account details, communication history Performance of contract (Art. 6(1)(b))
Error tracking and app stability Error reports, technical logs, device info Legitimate interest (Art. 6(1)(f))
Calculate prayer or fasting times Location or manually chosen place, time zone, calculation preferences Consent (Art. 6(1)(a)); if the chosen feature may reveal religious belief, also explicit consent (Art. 9(2)(a))
Legal obligations Audit logs, financial data, tax records Legal obligation (Art. 6(1)(c))
Referral programme: recording your acceptance of the programme terms Acceptance date, terms version and checksum of the text shown, language choice, pseudonymised IP verification code, user agent, app version, platform Performance of contract (Art. 6(1)(b)); for the evidence details (IP code, user agent) legitimate interest (Art. 6(1)(f): proof and fraud prevention)
Referral programme: abuse checks and review of rewards Number and status of invited accounts, aggregated device counts, review decisions (outcome, time, reason) Legitimate interest (Art. 6(1)(f)); a final refusal only happens after human review — see the programme terms
Referral programme: showing progress to the person who invited you Your first name with the initial of your last name (e.g. "Jan D."), your registration date and whether you already count Performance of contract (Art. 6(1)(b)): whoever invited you must be able to follow their progress. We never show your full last name, email address or other details to other users
Friends programme: showing your invitation to whoever opens your link Your first name with the first letter of your last name (e.g. "Jan D.") — visible to anyone who opens your invitation link, even without an account Performance of contract (Art. 6(1)(b)): you share your invitation link yourself; the recipient only sees this masked name, never your full last name or other data

Health and religious data — special attention

Health data

Tayb may process data considered as health data under the GDPR. This may include:

  • body weight, height, waist circumference and other body measurements;
  • health and nutritional goals or preferences that may reveal something about your health;
  • allergies and certain dietary restrictions;
  • life stage information such as pregnancy, breastfeeding or menopause;
  • activity level, calorie and hydration goals;
  • fasting and progress data insofar as these have a health dimension.

We only process such data for features where it is reasonably necessary, such as personalisation, safety warnings, allergy filtering and progress tracking.

Religious data

If you activate certain fasting or prayer time features, we may process data that could reveal your religious beliefs, such as:

  • Ramadan or other observance settings;
  • prayer time calculation preferences;
  • certain dietary settings such as halal or comparable religion-sensitive preferences, insofar as they may reveal religious belief in the context of your use.

We only process this data if you actively use or enable those features.

Legal basis and consent

For these special categories we use as a general rule:

  • Art. 6(1)(a) GDPR as the ordinary legal basis; and
  • Art. 9(2)(a) GDPR as the exception for special categories, based on your explicit consent.

We request this consent separately from the general terms and conditions, through clear choices in the app. Consent is not assumed from the mere fact that you enter data; we request an active confirmation.

You can withdraw your consent at any time via Settings → Privacy & Data. Once you do so, we will stop the relevant processing for the future, unless another valid legal basis still exists for a limited part. The consequence may be that certain personalised features are no longer available. You can then still use Tayb for browsing, recipes, the encyclopaedia and other basic features.

No medical advice

Tayb is a wellness and lifestyle app. The app supports personalised meal planning, bodyweight planning, shopping lists, fasting support and similar features. Tayb is not a medical device and does not provide medical diagnosis, treatment, monitoring or therapeutic advice.

Our information and suggestions are intended as general information about nutrition, exercise and wellbeing. Warnings such as "consult a doctor" or "discuss this with your midwife" are aids and not a substitute for professional medical advice.

If you have health complaints, serious allergies, are pregnant, breastfeeding, taking medication or have other medical questions, always contact a doctor or other qualified healthcare provider.


Sharing with third parties

We never sell your personal data to third parties. We only share your data with service providers and processors that help us provide the Service, and only for the purposes described in this policy.

We share data with the following categories of processors:

Payment processors

Processor Purpose Shared data Country
Stripe Web payments and invoicing Email address, user ID, subscription tier, amount; name, billing address and VAT number are provided by you directly to Stripe Ireland (EU); possible transfer to the US under the EU-US Data Privacy Framework or SCCs
RevenueCat In-app purchases (iOS/Android) — not yet active: enabled at launch in the App Store and Play Store; we will update this policy then App user ID, transaction ID, product ID US

Authentication providers

Processor Purpose Shared data Country
Apple Sign in with Apple Apple user ID, email US/Ireland
Google Sign in with Google Google user ID, email, name US/Ireland

Communication services

Processor Purpose Shared data Country
SendGrid (Twilio) Email delivery Email address, name, email content US
Expo Push Service (Expo, Inc.) and Firebase Cloud Messaging (Google) Push notifications Device tokens, notification content US/Ireland

Hosting, network & storage

Processor Purpose Shared data Country
Hetzner Server hosting (databases and APIs) All data (encrypted) Germany (EU)
Cloudflare Network and security layer for all traffic (proxy, firewall, access control for our admin panel), hosting of the website and the web version of the app, and file storage (R2) IP address and request data with every request; profile photos in storage Storage: EU jurisdiction; traffic: global network, with SCCs/DPF for any transfer

Error tracking

Processor Purpose Shared data Country
Sentry (Functional Software, Inc.) Error tracking Error reports, user ID (no name/email), device info EU region (Frankfurt)

Analytics

Processor Purpose Shared data Country
PostHog (PostHog, Inc. — Cloud EU) App usage analysis, only with your consent User ID and predefined usage events (which features you use); no automatic capture of screens or input EU data centre (Frankfurt)

Analytics is off by default and is only enabled if you choose so in Settings → Privacy. PostHog processes this data solely on our instructions.

We conclude data processing agreements with these processors in accordance with GDPR Article 28 (see implementation checklist); a processor that is not yet active (RevenueCat) is only enabled once that has been done.


International transfers

Our primary infrastructure is located in the EU. However, some of our service providers may process or make data accessible from countries outside the European Economic Area, including the United States.

When this occurs, we ensure a valid transfer mechanism under Chapter V of the GDPR, for example:

  • an adequacy decision where available and applicable for the recipient concerned;
  • standard contractual clauses (SCCs); or
  • another legally permitted safeguard.

Which safeguard applies depends on the specific provider and service at the time of use. We verify this before launch and review it when providers or legislation change.


Retention periods

Data type Retention period Explanation
Account data Until deletion + 30-day grace period After deletion: 30-day recovery period, then permanently deleted
Profile data Until account deletion Deleted upon account deletion
Body measurements (time series) 180 days or until deletion Trend analysis; automatically cleaned up after 180 days
Fasting logs 180 days or until deletion Seasonal tracking (Ramadan cycle)
Water intake logs 180 days or until deletion Daily tracking, automatically cleaned up
Meal plans 90 days or until deletion Meal planning, automatically cleaned up after 90 days
Shopping lists 180 days or until deletion Price comparison and purchase history; automatically cleaned up after 180 days
Login history 180 days Security monitoring, automatically cleaned up
Session data Until logout or expiry Automatically cleaned up
Audit logs 2 years, anonymised upon account deletion Security and compliance purposes
Email delivery logs 1 year Error tracking and delivery tracking
Support tickets 2 years after closure Customer service
Payment data 7 years (statutory accounting obligation) Tax obligations
Trial abuse data 1 year Fraud prevention
Marketing consent history Minimum 5 years Burden of proof for consent
Referral programme terms acceptance (date, version, language, text checksum) For as long as you participate, until your account is deleted Proof of your acceptance (contract/evidence records); deleted together with your account
Evidence details of that acceptance (pseudonymised IP verification code + key version, user agent, app version, platform) 2 years, then automatically deleted Fraud prevention; data minimisation — the acceptance itself remains provable without these details
Referral programme review history (flagged rewards: outcome, time, reason) Until account deletion Accountability for decisions about rewards

After deletion of your account:

  • Your personal data is permanently deleted within 30 days
  • Audit logs are anonymised (your user ID is replaced by a non-traceable code)
  • Financial data is retained as long as the law requires (7 years)

Security

We take appropriate technical and organisational measures to protect your data, including but not limited to:

  • encryption of data in transit and, where appropriate, at rest;
  • secure storage of authentication credentials using modern hashing and encryption standards;
  • pseudonymisation where possible: for the referral programme's acceptance record we store no readable IP address, only a pseudonymised verification code (keyed hash); that code remains personal data and is covered by this policy;
  • role-based access control and logging of sensitive access;
  • session security, rate limiting and anti-abuse measures;
  • backups, monitoring and error tracking; and
  • incident response and data deletion procedures.

No system is entirely risk-free, but we regularly evaluate our security and strive to minimise risks as much as possible.


Your rights

Under the GDPR you have the following rights:

Right How to exercise
Access — You may request which data we hold about you In the app: Settings → Privacy → "Export your data". Or email [email protected]
Rectification — You may have inaccurate data corrected In the app: Settings → Account / Profile
Erasure — You may request deletion of your data In the app: Settings → Account → "Delete account". We delete your data after a 30-day recovery period
Restriction — You may request temporary restriction of processing Email [email protected]
Data portability — You may request your data in a portable format In the app: Settings → Privacy → "Export your data" (JSON format)
Objection — You may object to processing based on legitimate interest Email [email protected]
Withdraw consent — You may withdraw previously given consent In the app: Settings → Privacy & Data → manage per consent type (health data, allergies, health goals, fasting, progress, analytics)

Filing a complaint

If you believe we are not processing your data correctly, you can file a complaint with a supervisory authority:

  • Belgium (our establishment): Data Protection Authority (GBA) — www.gegevensbeschermingsautoriteit.be
  • The Netherlands: Dutch Data Protection Authority (AP) — www.autoriteitpersoonsgegevens.nl

You always have the right to file a complaint with the supervisory authority of your own EU member state. We appreciate it if you contact us first at [email protected] so we have the opportunity to address your question or complaint.


Account deletion

You can delete your account at any time via the app:

  1. Go to Settings → Account → Delete account
  2. Confirm via a 4-step process (including password verification)
  3. Your account is deactivated immediately
  4. After 30 days all data is permanently deleted
  5. Within those 30 days you can recover your account by logging in again

Upon deletion the following data is erased:

  • Profile and personal information
  • Health and preference settings
  • Meal plans and history
  • Favourite recipes and ingredients
  • Push notification tokens and sessions

Audit logs are anonymised (not deleted) in order to meet our security and legal obligations.


Contact details

For questions about this privacy policy or about the processing of your data:

Email: [email protected] Post: Drink 18 VOF, Drink 18, 2140 Antwerpen, Belgium

We aim to respond to requests regarding your privacy rights within 30 days, in accordance with the GDPR.


Minors

Tayb is intended for users aged 18 and over. This age requirement is a product policy of Tayb and not a statement that the GDPR itself always requires a minimum age of 18.

We do not knowingly collect data from persons under 18 years of age. If we reasonably determine that someone under 18 has created an account, we may block or delete the account and erase or anonymise the personal data involved, to the extent permitted by law.

Please contact us at [email protected] if you suspect that a minor has registered.


Changes to this policy

We may update this privacy policy from time to time, for example when new features are added or legislation changes.

In the event of material changes:

  • We will send a notification via the app or by email
  • We will state the date of the last modification at the top of this document
  • We will give you the opportunity to review the changes

Last modified: 2 September 2026


Push notifications, analytics and error tracking

Push notifications

If you enable push notifications, you will receive alerts about:

  • Security warnings (new login, password change)
  • Subscription events (renewal, cancellation, payment issue)
  • Fasting reminders (suhoor/iftar, if you enable this)

You can disable push notifications at any time via Settings → Notifications in the app, or via your phone's settings.

Analytics

We use PostHog (PostHog Cloud, EU data centre in Frankfurt) to understand how the app is used (e.g. which features are popular, where users get stuck). Analytics is off by default. If you enable it via Settings → Privacy, we send predefined usage events together with your user ID to PostHog; there is no automatic capture of screens or entered text. PostHog processes this data as a processor on our instructions (GDPR Art. 28). You can disable analytics again at any time via Settings → Privacy.

Error tracking (Sentry)

We use Sentry (EU region, Frankfurt) to detect and fix technical errors in the app. This involves sending error reports, device information and your user ID (not your name or email) to Sentry. We actively filter personal data from error reports.


Payment information

We do not process credit card numbers or other card details. Payments are handled by:

  • Stripe (for web payments)
  • Apple App Store and Google Play Store (for in-app purchases, via RevenueCat — once the app is in the stores)

From these parties we only receive the status of your subscription (active, expired, etc.) and a reference number. For the privacy policies of these parties, we refer you to their own documentation.

Exception: partner programme. If you take part in our partner programme and are entitled to a payout, we store your IBAN and tax number. These details are kept encrypted, used only for the payout and the statutory administration, and not shared with the payment processors above.


Location and prayer times

If you use Islamic fasting, we may request your location to calculate prayer times (fajr and maghrib). This works as follows:

  • We request permission once via your operating system
  • You can also manually select a city (without GPS)
  • Your GPS coordinates are stored with limited precision (4 decimal places, ~11 metres) as a privacy-by-design measure
  • We only use your location for Tayb features (prayer times, seasonal ingredients, time zone) — not for advertising or tracking
  • We do not sell or share your location with third parties outside our processors
  • You can change your location at any time in the settings

Your location is stored in our database (EU) to repeat the calculation without asking you again. You can change or delete your location at any time in the app settings.


Cookies and tracking (web version)

The admin interface of Tayb (used exclusively internally by our team) uses functional cookies for:

  • Session management (staying logged in)
  • CSRF protection

We do not use tracking cookies or advertising cookies. No third-party cookies are placed. Functional cookies do not require consent under the ePrivacy Directive.


This privacy policy applies to the Tayb mobile app (iOS and Android) and associated services.

Last update: 19 July 2026

Tayb Ingredients Recipes Workouts Pricing FAQ Waitlist Privacy policy Terms Legal information
Language
  • Nederlands
  • English
  • Français
  • Deutsch
  • Español

Tayb does not provide medical advice. The information on this site never replaces the advice of a doctor or dietitian.

Tayb · © 2026 M. Bouchikhi