Privacy Policy
Last updated: July 13, 2026
This Privacy Policy explains how Soroff ("we", "us"), operated from Norway, collects and uses your personal data when you use the Soroff app and soroff.com (the "Service"). We process personal data in accordance with the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
1. Data we collect
- Account data: email address and a hashed password when you register.
- Profile data: information you enter to calculate your calorie plan — such as weight, goal weight, activity level, and timeframe.
- Meal data: meals you log, including names, nutrition values, timestamps, and meal photos you choose to save.
- Photos for AI analysis: when you use AI food scanning, the photo you take is sent to our servers and to our AI provider to estimate nutrition values.
- Purchase status: whether you have an active Soroff Pro subscription. Payment itself is handled entirely by Apple — we never see your payment card or billing details.
- Technical data: basic logs necessary to operate and secure the Service.
We do not collect your precise location, contacts, or advertising identifiers, and we do not show ads.
2. Why we process your data (legal bases)
- To provide the Service (contract, GDPR Art. 6(1)(b)): accounts, meal logging, calorie plans, AI analysis, subscriptions.
- Health-related data you enter (explicit consent, GDPR Art. 9(2)(a)): weight and dietary data are processed only to provide the app's features to you.
- To secure and improve the Service (legitimate interest, GDPR Art. 6(1)(f)).
- To comply with legal obligations (GDPR Art. 6(1)(c)).
3. Who we share data with
We do not sell your personal data. We share data only with processors needed to run the Service:
- Supabase — database, authentication, and file storage for accounts, meals, and photos.
- AI provider (Anthropic) — receives meal photos you submit for analysis, solely to return nutrition estimates.
- Apple — processes all payments and subscription management under Apple's own privacy policy.
Where processors are located outside the EU/EEA, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
4. How long we keep data
We keep your data for as long as your account exists. If you delete your account (Settings → Delete account in the app), your account, profile, meals, and photos are permanently deleted from our systems. Backups are purged on a rolling basis shortly thereafter.
5. Your rights
Under the GDPR you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; and to withdraw consent at any time. You can exercise most of these directly in the app, or by contacting us. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or your local supervisory authority.
6. Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored hashed. Access to production data is restricted. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.
7. Children
The Service is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
8. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always available at soroff.com/privacy. If changes are material, we will notify you in the app.
9. Contact
Data controller: Soroff (Norway). Questions or requests: support@soroff.com