Privacy

What the site knows about you, why, and for how long.

Updated 20 August 2026

In short

This site carries no advertising tracker, no analytics, and passes nothing to anyone for commercial purposes. There is no cookie banner because there is nothing to ask you to accept.

The only data kept is what you enter so the site can weigh your meals rather than somebody else's.

What is stored on the server

Your account: email address, a name if you give one, a hash of your password — never the password itself —, a Google identifier if you sign in that way, your chosen language, and the dates you signed up and confirmed.

Your profile: sex, age, height, weight, activity outside sport, sessions per week, kind of training, quality of starches, appetite and goal. These answers are used for nothing but working out your nutrition targets.

The weeks you compose: the dishes chosen, never the grammes — those are recomputed from your profile, so they follow your measurements when those change.

Your problem reports: your message, the severity you picked, the page concerned, your browser, your screen size and your language.

What never leaves your device

The ticked boxes on the shopping list, the dishes marked cooked and the meals marked eaten stay in your browser's storage. They are never sent to the server, and clearing the site's data erases them for good.

Why this data is processed

The account and the profile are needed for the service you asked for: a menu weighed for you. Without them the site shows the recipes as they were written, and nothing is kept.

Reports are kept in order to fix what people ran into, which is the legitimate interest of keeping the site working.

For how long

Your account, your profile and your weeks are kept as long as the account exists, and erased when it is deleted.

A confirmation link lasts twenty-four hours, a password reset link one hour. After that they are unusable and deleted.

A session lasts thirty days, or until you sign out.

Reports are kept as long as they help fix the problem they describe.

Who else can see it

Nobody. No data is sold, rented, or passed to third parties for commercial purposes.

Three providers are involved technically: o2switch, in France, which hosts the database and sends the mail; Netlify, in the United States, which serves the pages; and Google, if and only if you choose to sign in with a Google account — Google then passes us your address, your name and your identifier.

Netlify being an American company, serving the pages means a transfer outside the European Union. Those pages hold no personal data: your profile never travels through them, it is asked of the French server directly.

Cookies and local storage

Three cookies, no more. The session one keeps you signed in for thirty days; it is unreadable to JavaScript and travels only over HTTPS. A ten-minute one protects the Google sign-in against request forgery. The last one remembers the language you chose.

All three are strictly necessary or a display preference: the rules exempt them from consent, which is why no banner is put in your way.

Your browser's local storage holds your ticked boxes, as described above.

Your rights

You may ask to see the data concerning you, to correct it, to erase it, to receive a copy of it, or to object to its processing.

Write to the address below: your request will be handled within one month. Deleting an account erases the account, the profile and the saved weeks.

If the answer does not satisfy you, you may refer the matter to the Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, 75007 Paris.

Security

Traffic is HTTPS end to end. Passwords are kept as a scrypt hash, never in the clear. The database can only be reached from the server that uses it, never from the internet.

No system is perfectly safe. If you find a flaw, write to us rather than publish it.