Privacy Policy
We take your privacy seriously. This policy explains what personal data we collect, how it is used, and what rights you have under the EU General Data Protection Regulation (GDPR), which applies in Norway through the EEA Agreement.
1. Data controller
The controller of your personal data is Sveum Design (sveumdesign.no), the developer of Ketocat. Contact: post@sveumdesign.no.
2. What we collect
Ketocat collects the following categories of personal data:
- Account details: Name and email address at registration.
- Health data (special category, GDPR Art. 9): Weight, waist measurement and body fat percentage · food and drink log with calories and macronutrients · workouts with type, duration, intensity and calories burned · fasting periods · menstruation days if you choose to log them · self-reported energy, fullness and mood on a 1–5 scale · notes you write on measurements and workouts. All of this is voluntary, and you can leave it out.
- Settings and goals: Diet type and carb limit, weight goal, waist goal, target date, activity level, gender, age, height, time zone and language.
- Content you create: Custom foods, recipes and favourites.
- Activity data: Points, streak, daily missions, weekly challenges, purchases in the KP shop and scores in the mini-games.
- Messages: If you connect to a coach, the messages between you are stored.
- Subscription: Status, currency and the last four digits of your card. The card number itself is never stored by us – see section 6.
- Technical data: Signing in to the coach portal creates a session record that includes IP address and browser type, and which is deleted when the session expires. The app itself uses a sign-in token with no IP logging.
- Marketing source: If you arrived via an ad or a link, the source (for example "facebook" or "google") is stored with your account so we can see which marketing works.
We use no tracking cookies, and no third-party analytics tools on our websites.
3. Age limit
Ketocat is for users who are 18 or older. The service is not directed at minors, and we do not knowingly collect personal data from anyone under 18. At registration the user confirms that they meet the age requirement. If we become aware that a minor has created an account, the account and its data will be deleted.
4. Legal basis for processing
- Contract (Art. 6(1)(b)): Delivering the service you signed up for, including subscription and payment.
- Explicit consent (Art. 9(2)(a)): All processing of health data. You give this consent actively at registration and can withdraw it at any time by deleting your account, which deletes the health data immediately.
- Separate consent (Art. 6(1)(a)): Sharing a registration signal with Meta for ad measurement. This is a separate, optional checkbox at registration and does not affect your access to the service. See section 6.
- Legitimate interest (Art. 6(1)(f)): Security, debugging, operational monitoring and measuring which marketing works. We have assessed that this does not override your rights, not least because the visitor statistics cannot be linked to you as a person.
5. Purposes
- Providing and operating the food log, measurements and progress views.
- Calculating calorie needs and macronutrients, and showing patterns in your own numbers.
- Gamification features (points, missions, rewards, mini-games).
- Sending email you have asked for or need: verification code, password link, weekly report and reminders.
- Passing messages between you and a coach you have chosen to connect with.
- Secure authentication and account protection.
- Measuring which marketing leads to registrations.
6. Sharing with third parties
We never sell your data, and your health data is never shared for marketing. The following parties are nevertheless involved:
- Hosting: The service runs on Deploi (deploi.no) on servers in Norway. All your health data is therefore stored in Norway and never leaves the EEA. The provider processes data on our behalf under a data processing agreement and has no right to use it for its own purposes.
- Stripe (payment): For subscriptions, Stripe handles card details and invoicing. Your card number never passes through our servers and is never stored by us. Stripe receives your email address and the amount.
- Email: Verification codes, password links and weekly reports are sent directly from our own server in Norway – no external email service is involved. The weekly report contains health data (days under your carb limit, average calories, workouts and weight change), and you can turn it off under Settings.
- Meta (Facebook) – only with your consent: If you tick the marketing consent box at registration, we send Meta a signal that a registration happened. It contains your email address in encrypted (hashed) form, your IP address and your browser type. The purpose is to measure whether our ads work. No health data is sent. Without consent, nothing is sent. You can withdraw the consent by contacting us.
- Strava – only if you connect it: If you connect Strava, we import your workouts from there. We send no data about you to Strava beyond what the connection itself requires.
- Withings – only if you connect it: If you connect a Withings scale, we import weight and body fat percentage from there. We send no health data to Withings.
- Coach – only if you connect to one: If you enter a coach code, that coach can see your weight measurements, food log, workouts and fasts, and can send you messages. Menstruation data is never shared with coaches. You can break the connection at any time under Settings, and access ends immediately.
- Food databases: When you search for food, your browser contacts matvaretabellen.no directly, and we fetch data from Open Food Facts and USDA through our own servers. They receive only the search term, never who is searching or what you log. In the direct connection to matvaretabellen.no your IP address will be visible to them, as it is to any website you visit.
7. Transfers outside the EEA
Your health data is stored in Norway and is never transferred outside the EEA.
Two services do process other data outside the EEA: Stripe (payment) and – if you have given marketing consent – Meta. Both are US companies certified under the EU–US Data Privacy Framework, which the European Commission has assessed as providing an adequate level of protection.
8. Retention and deletion
- Account and health data: Kept for as long as your account is active. If you delete your account, everything is removed from the service immediately – food log, measurements, workouts, fasts, menstruation data, messages and points. This cannot be undone. See the note on backups below.
- Abandoned accounts: If you never confirmed your email address, or more than 90 days have passed since your trial expired without a subscription and without activity, we send a warning by email. Deletion then happens manually, at the earliest 14 days after the warning. Paying users are never deleted this way.
- Landing page statistics: Stored in aggregate form and cannot be linked to you as a person. See section 9.
- Server logs: Technical error messages. They contain no health data.
- Backups: The server is backed up daily so the service can be restored after a failure. Backups are kept for 10 days and then deleted automatically. If you delete your account, the data is removed from the live service immediately, but it may remain in a backup for up to 10 more days. Backups are used only to restore the service after a fault, and deleted data is never brought back into the service.
9. Cookies and tracking
Ketocat uses a minimum of cookies and local storage:
- localStorage (necessary): The app stores your sign-in token and a local copy of settings, today's log and points in your browser, so the app is fast and works offline. This lives on your own device. It is cleared when you sign out or delete your account, and you can clear it yourself at any time through your browser settings.
- Session cookie (necessary): Used by the coach portal and to protect against forged form submissions. Contains no health data.
- Landing page counter (necessary, no cookies): We count visits to the front page, along with which ad source or referring website (for example a search engine or social media domain) the visit came from, to measure whether our marketing works. We also store the browser's user-agent string (technical information about browser and device) to separate real visits from bots and crawlers in the statistics. To count unique visitors rather than just page loads, we compute a one-way, salted hash of the IP address and user agent, which rotates daily — the IP address itself is never stored, and the hash cannot be used to identify you or follow you across days. We store only the domain name of sources, not the full link you came from, and none of this identifies you as a person. If you register an account via such a link, the source is stored with your account for the same purpose.
10. Your rights
You have the following rights, and can exercise them at any time free of charge:
- Access (Art. 15): Request a copy of all the data we hold about you.
- Rectification (Art. 16): Correct inaccurate data. Most of it you can change yourself in the app.
- Erasure (Art. 17, "the right to be forgotten"): Delete your account under Settings → Account, or contact us.
- Restriction (Art. 18): Ask us to pause processing while an objection is being handled.
- Data portability (Art. 20): Download all your data as JSON under Settings → Export data.
- Objection (Art. 21): Object to processing based on legitimate interest, such as the marketing measurement.
- Withdraw consent: Delete your account to withdraw consent to processing of health data. The marketing consent can be withdrawn separately by contacting us, without losing access to the service.
- Complaint: You can complain to the Norwegian Data Protection Authority, Datatilsynet, if you believe we process your data unlawfully. If you live in another EEA country, you may also complain to your local supervisory authority.
11. Automated decision-making
We make no automated decisions with legal or similarly significant effects on you, and we do no profiling in the sense of GDPR Art. 22. The app calculates calorie needs and shows patterns in your own numbers, but this is information for you – not decisions about you.
12. Security
All traffic is encrypted over HTTPS. Passwords are stored as bcrypt hashes and cannot be read back. Sign-in tokens can be revoked, and all tokens are revoked automatically when you change your password. Sign-in attempts are rate limited. We update server software and dependencies regularly.
Your health data is stored unencrypted in the database, protected by access control at the server and database level. We are considering field-level encryption as a further measure.
13. Changes to this policy
For significant changes, active users are notified by email at least 14 days in advance. The current version is always available at ketocat.com/privacy.