Privacy Policy

Last updated: 20 July 2026 · Applies to Ketocat (ketocat.com) and Ketokatten (ketokatten.no)

We take your privacy seriously. This policy explains what personal data we collect, how it is used, and what rights you have under the EU General Data Protection Regulation (GDPR), which applies in Norway through the EEA Agreement.

1. Data controller

The controller of your personal data is Sveum Design (sveumdesign.no), the developer of Ketocat. Contact: post@sveumdesign.no.

2. What we collect

Ketocat collects the following categories of personal data:

We use no tracking cookies, and no third-party analytics tools on our websites.

3. Age limit

Ketocat is for users who are 18 or older. The service is not directed at minors, and we do not knowingly collect personal data from anyone under 18. At registration the user confirms that they meet the age requirement. If we become aware that a minor has created an account, the account and its data will be deleted.

4. Legal basis for processing

5. Purposes

6. Sharing with third parties

We never sell your data, and your health data is never shared for marketing. The following parties are nevertheless involved:

7. Transfers outside the EEA

Your health data is stored in Norway and is never transferred outside the EEA.

Two services do process other data outside the EEA: Stripe (payment) and – if you have given marketing consent – Meta. Both are US companies certified under the EU–US Data Privacy Framework, which the European Commission has assessed as providing an adequate level of protection.

8. Retention and deletion

9. Cookies and tracking

Ketocat uses a minimum of cookies and local storage:

10. Your rights

You have the following rights, and can exercise them at any time free of charge:

11. Automated decision-making

We make no automated decisions with legal or similarly significant effects on you, and we do no profiling in the sense of GDPR Art. 22. The app calculates calorie needs and shows patterns in your own numbers, but this is information for you – not decisions about you.

12. Security

All traffic is encrypted over HTTPS. Passwords are stored as bcrypt hashes and cannot be read back. Sign-in tokens can be revoked, and all tokens are revoked automatically when you change your password. Sign-in attempts are rate limited. We update server software and dependencies regularly.

Your health data is stored unencrypted in the database, protected by access control at the server and database level. We are considering field-level encryption as a further measure.

13. Changes to this policy

For significant changes, active users are notified by email at least 14 days in advance. The current version is always available at ketocat.com/privacy.

Contact us about privacy
Email: post@sveumdesign.no
We reply within 3 working days.