Tayb — Privacy Policy
2 September 2026
Who we are
Tayb ("we", "us", "our") is a health and nutrition platform that offers personalised meal plans, recipes, shopping lists and wellness information.
Tayb is commercially operated by Drink 18 VOF. That company determines the purposes and means of the processing of your personal data and is therefore the data controller within the meaning of Article 4(7) GDPR.
Data controller: Name: Drink 18 VOF Legal form: General partnership (vennootschap onder firma) Address: Drink 18, 2140 Antwerpen, Belgium Company number: 0760.812.768 VAT number: BE0760812768 Register of legal entities: RPR Antwerpen, afdeling Antwerpen Email: [email protected] Country: Belgium
What data we collect
2.1 Data you provide yourself
During registration:
- Email address
- First and last name
- Password (stored encrypted; we never see your password in readable form)
- Date of birth (for age verification and nutritional calculations)
During profile setup (onboarding):
- Gender (male/female — used for nutritional calculations, not for identity)
- Weight, height and optional waist circumference
- Activity level (how active you are in daily life)
- Life stage (e.g. pregnancy, breastfeeding, menopause — see section 5)
- Primary health goal (e.g. weight loss, more energy, balance)
- Dietary preferences (e.g. vegetarian, vegan, halal, kosher)
- Allergies (EU top-14 allergens)
- Ingredient preferences (dislikes)
- Fitness level and workout schedule
- Household size and maximum cooking time
- Fasting preferences (Islamic fasting, intermittent fasting, or none)
Optionally, if you choose to:
- Phone number
- Address details (street, postcode, city, country)
- Profile photo
- Bio/description
2.2 Data collected automatically
When using the app:
- IP address and user agent (browser type/device) upon login
- Device information (name, type, platform: iOS/Android)
- Session data (for security purposes)
- Push notification tokens (if you enable notifications)
When starting a trial:
- Device ID (to prevent trial abuse)
- Normalised email address (to prevent alias abuse)
When you join the referral programme (accepting the programme terms):
- Date, language choice, version number and a checksum (hash) of the exact terms text you were shown
- A pseudonymised verification code (keyed hash, HMAC) derived from your IP address — for this acceptance record we do not store your IP address as a readable field, and the IP address cannot be read back from the code. The code is linked to your account and therefore remains personal data
- Browser/device info (user agent), app version and platform
2.3 Data you actively track
- Daily water intake
- Body measurements over time (weight, waist circumference)
- Fasting log (completion, energy and hunger levels, reason for breaking)
- Meal completion and shopping list ticking
2.4 Location data
We request permission for your location once (via your operating system) in order to:
- Calculate prayer times for Islamic fasting (fajr/maghrib)
- Set your time zone correctly
- Offer seasonal ingredients
Your location is stored with limited precision (~11 metres) and is only used for Tayb features such as prayer times and seasonal ingredients. We do not sell or share your location with third parties outside our processors.
You can also manually select a city instead of using GPS. We do not continuously track your location.
How we collect this data
| Method | Explanation |
|---|---|
| Registration form | Email, name, password, date of birth |
| Onboarding steps | 6 steps in which you set up your profile, goals and preferences |
| App settings | Changes to profile, preferences and privacy settings |
| Automatically during use | IP address, device info, session data (for security) |
| Manual tracking | Water intake, body measurements, fasting log |
| External login services | Apple Sign-In or Google Sign-In (if you choose this) |
| Payment providers | Subscription status via Stripe (web); in-app purchases via App Store/Play Store with RevenueCat once the app is in the stores |
Why we use your data
| Purpose | Which data | Legal basis |
|---|---|---|
| Create and manage account | Email, name, password or social login credentials | Performance of contract (Art. 6(1)(b)) |
| Generate personalised meal plans | Weight, height, activity level, goals, allergies, life stage data where relevant | Consent (Art. 6(1)(a)) + explicit consent for special categories (Art. 9(2)(a)) |
| Support food safety | Allergies, dietary restrictions, preferences | Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a)) |
| Provide fasting and religion-related features | Fasting preferences, observances, prayer time settings, relevant life stage data | Consent (Art. 6(1)(a)) + explicit consent for special categories insofar as these reveal religion or health (Art. 9(2)(a)) |
| Track progress | Body measurements, water intake, logs, history | Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a)) |
| Display safety warnings | Weight, age, life stage, allergies, BMI or derived signals | Consent (Art. 6(1)(a)) + explicit consent for health data (Art. 9(2)(a)) |
| Process subscription and payments | Subscription status, payment provider ID, billing details | Performance of contract (Art. 6(1)(b)) and, where legally required, legal obligation (Art. 6(1)(c)) |
| Prevent trial abuse and combat fraud | Device ID, normalised email address, IP address, subscription history | Legitimate interest (Art. 6(1)(f)) |
| Secure your account | IP address, session information, MFA credentials, login history | Legitimate interest (Art. 6(1)(f)) |
| Send functional emails | Email address, name, account status | Performance of contract (Art. 6(1)(b)) |
| Marketing communications | Email address, name | Consent (Art. 6(1)(a)) |
| Push notifications | Push token, device information, notification preferences | Consent (Art. 6(1)(a)) |
| Customer support | Ticket content, account details, communication history | Performance of contract (Art. 6(1)(b)) |
| Error tracking and app stability | Error reports, technical logs, device info | Legitimate interest (Art. 6(1)(f)) |
| Calculate prayer or fasting times | Location or manually chosen place, time zone, calculation preferences | Consent (Art. 6(1)(a)); if the chosen feature may reveal religious belief, also explicit consent (Art. 9(2)(a)) |
| Legal obligations | Audit logs, financial data, tax records | Legal obligation (Art. 6(1)(c)) |
| Referral programme: recording your acceptance of the programme terms | Acceptance date, terms version and checksum of the text shown, language choice, pseudonymised IP verification code, user agent, app version, platform | Performance of contract (Art. 6(1)(b)); for the evidence details (IP code, user agent) legitimate interest (Art. 6(1)(f): proof and fraud prevention) |
| Referral programme: abuse checks and review of rewards | Number and status of invited accounts, aggregated device counts, review decisions (outcome, time, reason) | Legitimate interest (Art. 6(1)(f)); a final refusal only happens after human review — see the programme terms |
| Referral programme: showing progress to the person who invited you | Your first name with the initial of your last name (e.g. "Jan D."), your registration date and whether you already count | Performance of contract (Art. 6(1)(b)): whoever invited you must be able to follow their progress. We never show your full last name, email address or other details to other users |
| Friends programme: showing your invitation to whoever opens your link | Your first name with the first letter of your last name (e.g. "Jan D.") — visible to anyone who opens your invitation link, even without an account | Performance of contract (Art. 6(1)(b)): you share your invitation link yourself; the recipient only sees this masked name, never your full last name or other data |
Health and religious data — special attention
Health data
Tayb may process data considered as health data under the GDPR. This may include:
- body weight, height, waist circumference and other body measurements;
- health and nutritional goals or preferences that may reveal something about your health;
- allergies and certain dietary restrictions;
- life stage information such as pregnancy, breastfeeding or menopause;
- activity level, calorie and hydration goals;
- fasting and progress data insofar as these have a health dimension.
We only process such data for features where it is reasonably necessary, such as personalisation, safety warnings, allergy filtering and progress tracking.
Religious data
If you activate certain fasting or prayer time features, we may process data that could reveal your religious beliefs, such as:
- Ramadan or other observance settings;
- prayer time calculation preferences;
- certain dietary settings such as halal or comparable religion-sensitive preferences, insofar as they may reveal religious belief in the context of your use.
We only process this data if you actively use or enable those features.
Legal basis and consent
For these special categories we use as a general rule:
- Art. 6(1)(a) GDPR as the ordinary legal basis; and
- Art. 9(2)(a) GDPR as the exception for special categories, based on your explicit consent.
We request this consent separately from the general terms and conditions, through clear choices in the app. Consent is not assumed from the mere fact that you enter data; we request an active confirmation.
You can withdraw your consent at any time via Settings → Privacy & Data. Once you do so, we will stop the relevant processing for the future, unless another valid legal basis still exists for a limited part. The consequence may be that certain personalised features are no longer available. You can then still use Tayb for browsing, recipes, the encyclopaedia and other basic features.
No medical advice
Tayb is a wellness and lifestyle app. The app supports personalised meal planning, bodyweight planning, shopping lists, fasting support and similar features. Tayb is not a medical device and does not provide medical diagnosis, treatment, monitoring or therapeutic advice.
Our information and suggestions are intended as general information about nutrition, exercise and wellbeing. Warnings such as "consult a doctor" or "discuss this with your midwife" are aids and not a substitute for professional medical advice.
If you have health complaints, serious allergies, are pregnant, breastfeeding, taking medication or have other medical questions, always contact a doctor or other qualified healthcare provider.
Sharing with third parties
We never sell your personal data to third parties. We only share your data with service providers and processors that help us provide the Service, and only for the purposes described in this policy.
We share data with the following categories of processors:
Payment processors
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| Stripe | Web payments and invoicing | Email address, user ID, subscription tier, amount; name, billing address and VAT number are provided by you directly to Stripe | Ireland (EU); possible transfer to the US under the EU-US Data Privacy Framework or SCCs |
| RevenueCat | In-app purchases (iOS/Android) — not yet active: enabled at launch in the App Store and Play Store; we will update this policy then | App user ID, transaction ID, product ID | US |
Authentication providers
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| Apple | Sign in with Apple | Apple user ID, email | US/Ireland |
| Sign in with Google | Google user ID, email, name | US/Ireland |
Communication services
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| SendGrid (Twilio) | Email delivery | Email address, name, email content | US |
| Expo Push Service (Expo, Inc.) and Firebase Cloud Messaging (Google) | Push notifications | Device tokens, notification content | US/Ireland |
Hosting, network & storage
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| Hetzner | Server hosting (databases and APIs) | All data (encrypted) | Germany (EU) |
| Cloudflare | Network and security layer for all traffic (proxy, firewall, access control for our admin panel), hosting of the website and the web version of the app, and file storage (R2) | IP address and request data with every request; profile photos in storage | Storage: EU jurisdiction; traffic: global network, with SCCs/DPF for any transfer |
Error tracking
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| Sentry (Functional Software, Inc.) | Error tracking | Error reports, user ID (no name/email), device info | EU region (Frankfurt) |
Analytics
| Processor | Purpose | Shared data | Country |
|---|---|---|---|
| PostHog (PostHog, Inc. — Cloud EU) | App usage analysis, only with your consent | User ID and predefined usage events (which features you use); no automatic capture of screens or input | EU data centre (Frankfurt) |
Analytics is off by default and is only enabled if you choose so in Settings → Privacy. PostHog processes this data solely on our instructions.
We conclude data processing agreements with these processors in accordance with GDPR Article 28 (see implementation checklist); a processor that is not yet active (RevenueCat) is only enabled once that has been done.
International transfers
Our primary infrastructure is located in the EU. However, some of our service providers may process or make data accessible from countries outside the European Economic Area, including the United States.
When this occurs, we ensure a valid transfer mechanism under Chapter V of the GDPR, for example:
- an adequacy decision where available and applicable for the recipient concerned;
- standard contractual clauses (SCCs); or
- another legally permitted safeguard.
Which safeguard applies depends on the specific provider and service at the time of use. We verify this before launch and review it when providers or legislation change.
Retention periods
| Data type | Retention period | Explanation |
|---|---|---|
| Account data | Until deletion + 30-day grace period | After deletion: 30-day recovery period, then permanently deleted |
| Profile data | Until account deletion | Deleted upon account deletion |
| Body measurements (time series) | 180 days or until deletion | Trend analysis; automatically cleaned up after 180 days |
| Fasting logs | 180 days or until deletion | Seasonal tracking (Ramadan cycle) |
| Water intake logs | 180 days or until deletion | Daily tracking, automatically cleaned up |
| Meal plans | 90 days or until deletion | Meal planning, automatically cleaned up after 90 days |
| Shopping lists | 180 days or until deletion | Price comparison and purchase history; automatically cleaned up after 180 days |
| Login history | 180 days | Security monitoring, automatically cleaned up |
| Session data | Until logout or expiry | Automatically cleaned up |
| Audit logs | 2 years, anonymised upon account deletion | Security and compliance purposes |
| Email delivery logs | 1 year | Error tracking and delivery tracking |
| Support tickets | 2 years after closure | Customer service |
| Payment data | 7 years (statutory accounting obligation) | Tax obligations |
| Trial abuse data | 1 year | Fraud prevention |
| Marketing consent history | Minimum 5 years | Burden of proof for consent |
| Referral programme terms acceptance (date, version, language, text checksum) | For as long as you participate, until your account is deleted | Proof of your acceptance (contract/evidence records); deleted together with your account |
| Evidence details of that acceptance (pseudonymised IP verification code + key version, user agent, app version, platform) | 2 years, then automatically deleted | Fraud prevention; data minimisation — the acceptance itself remains provable without these details |
| Referral programme review history (flagged rewards: outcome, time, reason) | Until account deletion | Accountability for decisions about rewards |
After deletion of your account:
- Your personal data is permanently deleted within 30 days
- Audit logs are anonymised (your user ID is replaced by a non-traceable code)
- Financial data is retained as long as the law requires (7 years)
Security
We take appropriate technical and organisational measures to protect your data, including but not limited to:
- encryption of data in transit and, where appropriate, at rest;
- secure storage of authentication credentials using modern hashing and encryption standards;
- pseudonymisation where possible: for the referral programme's acceptance record we store no readable IP address, only a pseudonymised verification code (keyed hash); that code remains personal data and is covered by this policy;
- role-based access control and logging of sensitive access;
- session security, rate limiting and anti-abuse measures;
- backups, monitoring and error tracking; and
- incident response and data deletion procedures.
No system is entirely risk-free, but we regularly evaluate our security and strive to minimise risks as much as possible.
Your rights
Under the GDPR you have the following rights:
| Right | How to exercise |
|---|---|
| Access — You may request which data we hold about you | In the app: Settings → Privacy → "Export your data". Or email [email protected] |
| Rectification — You may have inaccurate data corrected | In the app: Settings → Account / Profile |
| Erasure — You may request deletion of your data | In the app: Settings → Account → "Delete account". We delete your data after a 30-day recovery period |
| Restriction — You may request temporary restriction of processing | Email [email protected] |
| Data portability — You may request your data in a portable format | In the app: Settings → Privacy → "Export your data" (JSON format) |
| Objection — You may object to processing based on legitimate interest | Email [email protected] |
| Withdraw consent — You may withdraw previously given consent | In the app: Settings → Privacy & Data → manage per consent type (health data, allergies, health goals, fasting, progress, analytics) |
Filing a complaint
If you believe we are not processing your data correctly, you can file a complaint with a supervisory authority:
- Belgium (our establishment): Data Protection Authority (GBA) — www.gegevensbeschermingsautoriteit.be
- The Netherlands: Dutch Data Protection Authority (AP) — www.autoriteitpersoonsgegevens.nl
You always have the right to file a complaint with the supervisory authority of your own EU member state. We appreciate it if you contact us first at [email protected] so we have the opportunity to address your question or complaint.
Account deletion
You can delete your account at any time via the app:
- Go to Settings → Account → Delete account
- Confirm via a 4-step process (including password verification)
- Your account is deactivated immediately
- After 30 days all data is permanently deleted
- Within those 30 days you can recover your account by logging in again
Upon deletion the following data is erased:
- Profile and personal information
- Health and preference settings
- Meal plans and history
- Favourite recipes and ingredients
- Push notification tokens and sessions
Audit logs are anonymised (not deleted) in order to meet our security and legal obligations.
Contact details
For questions about this privacy policy or about the processing of your data:
Email: [email protected] Post: Drink 18 VOF, Drink 18, 2140 Antwerpen, Belgium
We aim to respond to requests regarding your privacy rights within 30 days, in accordance with the GDPR.
Minors
Tayb is intended for users aged 18 and over. This age requirement is a product policy of Tayb and not a statement that the GDPR itself always requires a minimum age of 18.
We do not knowingly collect data from persons under 18 years of age. If we reasonably determine that someone under 18 has created an account, we may block or delete the account and erase or anonymise the personal data involved, to the extent permitted by law.
Please contact us at [email protected] if you suspect that a minor has registered.
Changes to this policy
We may update this privacy policy from time to time, for example when new features are added or legislation changes.
In the event of material changes:
- We will send a notification via the app or by email
- We will state the date of the last modification at the top of this document
- We will give you the opportunity to review the changes
Last modified: 2 September 2026
Push notifications, analytics and error tracking
Push notifications
If you enable push notifications, you will receive alerts about:
- Security warnings (new login, password change)
- Subscription events (renewal, cancellation, payment issue)
- Fasting reminders (suhoor/iftar, if you enable this)
You can disable push notifications at any time via Settings → Notifications in the app, or via your phone's settings.
Analytics
We use PostHog (PostHog Cloud, EU data centre in Frankfurt) to understand how the app is used (e.g. which features are popular, where users get stuck). Analytics is off by default. If you enable it via Settings → Privacy, we send predefined usage events together with your user ID to PostHog; there is no automatic capture of screens or entered text. PostHog processes this data as a processor on our instructions (GDPR Art. 28). You can disable analytics again at any time via Settings → Privacy.
Error tracking (Sentry)
We use Sentry (EU region, Frankfurt) to detect and fix technical errors in the app. This involves sending error reports, device information and your user ID (not your name or email) to Sentry. We actively filter personal data from error reports.
Payment information
We do not process credit card numbers or other card details. Payments are handled by:
- Stripe (for web payments)
- Apple App Store and Google Play Store (for in-app purchases, via RevenueCat — once the app is in the stores)
From these parties we only receive the status of your subscription (active, expired, etc.) and a reference number. For the privacy policies of these parties, we refer you to their own documentation.
Exception: partner programme. If you take part in our partner programme and are entitled to a payout, we store your IBAN and tax number. These details are kept encrypted, used only for the payout and the statutory administration, and not shared with the payment processors above.
Location and prayer times
If you use Islamic fasting, we may request your location to calculate prayer times (fajr and maghrib). This works as follows:
- We request permission once via your operating system
- You can also manually select a city (without GPS)
- Your GPS coordinates are stored with limited precision (4 decimal places, ~11 metres) as a privacy-by-design measure
- We only use your location for Tayb features (prayer times, seasonal ingredients, time zone) — not for advertising or tracking
- We do not sell or share your location with third parties outside our processors
- You can change your location at any time in the settings
Your location is stored in our database (EU) to repeat the calculation without asking you again. You can change or delete your location at any time in the app settings.
Cookies and tracking (web version)
The admin interface of Tayb (used exclusively internally by our team) uses functional cookies for:
- Session management (staying logged in)
- CSRF protection
We do not use tracking cookies or advertising cookies. No third-party cookies are placed. Functional cookies do not require consent under the ePrivacy Directive.
This privacy policy applies to the Tayb mobile app (iOS and Android) and associated services.
Last update: 19 July 2026