01. About this policy
This policy is intended to explain how personal information is handled when you visit the Palete website or use the Palete meal planner app. Palete is presented as a meal planner that takes account of your routine, goals, tastes and budget.
The website identifies Meteoric Group in its copyright notice. The full legal name of the organisation responsible for personal data, its address, country of establishment and privacy contact must be confirmed before this policy takes effect.
The app and this website are different services. Data displayed in a promotional screenshot is not information collected from a website visitor.
02. Information and purposes
The current landing page has no account-registration form, meal-entry form or payment form. Its page code does not include analytics or advertising scripts. This does not describe every activity of the hosting or access-control provider, and it does not establish the app’s practices.
The final app policy must identify which of the following categories are actually used, their sources and their purposes:
- Account information: if accounts are offered, the sign-in details and profile fields needed to create, authenticate and manage an account.
- Meal-planning information: any preferences, goals, routines, meal records, shopping lists or budgets entered to create and manage meal plans.
- Support correspondence: any messages and attachments submitted when requesting help.
- Technical information: any device details, error reports, usage events, IP addresses or access logs used to deliver or secure the service.
- Purchase information: if paid features are offered, the subscription or transaction details received from the payment provider.
These are categories to verify, not a declaration that all of them are collected. Required and optional fields, collection methods and the consequences of not providing information must be explained in the final notice.
03. Legal bases
Where applicable law requires a legal basis, it must be identified for each processing purpose. Depending on the actual activity and jurisdiction, this may include providing a requested service, complying with a legal obligation, consent, or a legitimate interest supported by the required assessment.
Opening the website or accepting a privacy policy does not, by itself, provide consent for every use of personal information. Where consent is required, the final policy must explain how it is obtained and withdrawn. The applicable jurisdictions and legal bases are awaiting confirmation.
04. Health and dietary data
Allergies, medical dietary restrictions, body measurements and some nutrition goals can reveal sensitive health information. If Palete processes this information, the final policy must specify exactly what is used, why, the applicable legal basis, who receives it and how long it is kept.
Access to Apple Health, HealthKit or other health services has not been confirmed. Neither has the use of third-party AI to process meal preferences or health information. This draft does not authorise such access or sharing.
07. Retention and deletion
The final policy must state how long each category of information is kept, or the criteria used to determine that period. It must distinguish active account data, support records, security logs, backups and any records that must be retained by law.
Account creation and deletion features have not been confirmed. The final version must provide the actual steps or verified contact for requesting deletion, explain what is deleted, identify any justified exceptions, and describe backup removal times.
Uninstalling an app does not necessarily delete information stored on a server. No server-side deletion process or retention period is promised by this draft.
08. Security
Security measures must be appropriate to the information processed and the risks involved. The final notice should describe confirmed safeguards at a useful level, without disclosing details that would compromise security.
The app’s encryption, access controls, backup protections and incident-response practices have not been verified. This draft makes no claim that a specific security certification or safeguard is in place. No online service can guarantee absolute security.
09. International transfers
Hosting or service providers may process information in countries other than the user’s country. The app’s storage locations, recipients and transfer arrangements must be confirmed.
Where cross-border transfers are subject to legal requirements, the final notice must identify the relevant destinations or recipient information and the applicable safeguards. A general reference to international processing is not a substitute for identifying actual transfer practices.
10. Your rights and choices
Depending on the law that applies and the circumstances, you may have rights to confirm whether your information is processed, access or correct it, request deletion or portability, object to or restrict certain processing, and withdraw consent.
Some laws also provide rights to information about recipients and review of certain decisions based solely on automated processing. Rights may be subject to legal conditions and exceptions. You may also be able to complain to your local data-protection authority.
The final policy must provide a working channel for requests and explain any proportionate identity checks. A verified privacy contact and the app’s available settings are still needed. Please do not send identity documents or health information to an unverified address.
11. Children’s privacy
The intended age group and availability of the app to children have not been confirmed. The final policy must accurately state whether children can use the service and explain any required parental involvement, age controls and safeguards.
No age limit or parental-consent mechanism is established by this draft. If children’s information is processed, the applicable rules must be assessed before release.
12. Changes to this policy
The date above records when this draft was prepared, not when a final policy became effective. A confirmed version should show its effective or revision date and explain how material changes will be communicated.
Where a new data use requires a fresh choice or consent, simply updating this page is not enough. The relevant notice and choice must be provided before that use begins.
13. Contact
A working privacy contact is needed so users can ask questions and exercise their rights. Before publication, confirm the following:
- Responsible organisation
- Full legal entity and address to be confirmed
- Country of establishment
- To be confirmed
- Privacy email
- To be supplied by the operator
This draft does not provide an active privacy-request channel.
