Privacy policy

Version 1.2 · updated 2026-09-26

This is an English translation for your convenience. The Lithuanian version is the legally binding one; if they differ, the Lithuanian text applies.

Draft: the company details are still being added, and a lawyer is reviewing the text. We don't collect any data that isn't described here.

In short

  • Without an account (the website, calculators, the quiz) everything stays on your device only – we can't see it.
  • With an account (the app, invite-only for now) your plan, food diary and weight are stored encrypted on our server in the EU – only with your explicit consent, so that you can see them on all your devices.
  • We never send your health quiz answers (conditions, the eating and sleep questionnaires, pregnancy) anywhere – not even if you have an account.
  • No advertising, no ad pixels and no visitor tracking.
  • We only get your email address if you join the waitlist yourself or write to us.
  • When you scan a barcode, only the code number is sent to Open Food Facts.

Who we are

Data controller: Travel Solutions Inc., MB, company code 306998943, registered office [to be added]. Email for privacy questions: labas@dumpli.app. We process health data (a special category) only for account holders and only with their explicit consent, but not on a large scale, so we have not appointed a data protection officer for now.

What stays on your device only

The app calculates and stores your nutrition quiz answers – age, height, weight, health conditions, answers to the eating and sleep questionnaires, pregnancy – and calculator data only in your browser or on your phone. Meal and progress photos also stay on your device only. None of this is sent to our servers – not even if you have an account.

Without an account, your food diary, weight and plans also stay on your device only. You can delete them yourself: in the app, “Me” → “Delete all my data”, or by clearing the site data in your browser or deleting the app.

Your account: what is stored on our server

For now the app opens by invitation, and it works with an account. When you create an account, you give your explicit consent in a separate tick box (GDPR Art. 9(2)(a)) for us to store your app record: your plan settings (goal, calorie and protein targets, allergies, dietary choices and, if the quiz recommended talking to a doctor first, that flag, so that we don't show numbers on another device either), your food diary, water, movement, sleep, weight, saved recipes, shopping list and your family members' allergies.

  • The record is stored encrypted (AES-256) on our server in Germany (Hetzner). We don't store your password – only its hash (scrypt), from which the password can't be recovered.
  • The encryption key is kept on the same server, so this protects against stolen disks or copies, but not against us – we're telling you this openly. We don't read your record unless you ask us for help.
  • Your login is kept in a secure cookie (180 days). We don't store IP addresses.
  • You can withdraw your consent at any time: “Me” → “Delete account”. Your account and record are deleted from the server immediately; they disappear from backups within 14 days.
  • You can download all the data we hold at any time: “Me” → “Download everything we store”.

What we process and why

What data we process, why and for how long
DataPurposeLegal basisHow long
Email address and consent record (waitlist)To tell you about the launch and important newsYour consent (GDPR Art. 6(1)(a))Until you unsubscribe; 12 months after launch we'll ask whether you want to stay, and delete the addresses of those who don't reply
Account: email address, password hash, time of consents, invitation codeLogging in, password resetContract (GDPR Art. 6(1)(b))As long as you have an account; deleted immediately when you delete it
App record (health data, see above)So your data is on all your devices and isn't lost if you lose your phoneExplicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a))As long as you have an account; up to 14 days in backups
Messages sent through the “Report or suggest” form (text, page, and your name and email if you choose)To fix mistakes, improve Dumpli and reply; to publish a recipe you sent, if you allowed itLegitimate interest in improving the service; for publishing a recipe – your consent12 months after the issue is resolved; published recipes – for as long as they are published
Your emails to us (email address, content)To reply and resolve a question or complaintLegitimate interest in replying; for complaints – a legal obligation12 months after the issue is resolved; complaints – 3 years
Technical server records (errors; we don't keep a log of visitor requests)Keeping the website running and secureLegitimate interest (GDPR Art. 6(1)(f))Overwritten automatically; the log size is limited

Giving your email address is optional – Dumpli works exactly the same without it. We store waitlist email addresses on our own server in the EU (Hetzner) – only the email address, the time of consent and the page where you signed up, with no IP address and no quiz answers. We use Google Search Console only for summary information about how the website appears in search – it tells us nothing about individual visitors.

When Dumpli Plus arrives in the apps, payments will be handled by Apple (App Store) or Google (Google Play) as separate data controllers. We will receive only what is needed to switch on Plus, and we will keep accounting records for as long as the law requires. We will update this section before we start selling.

Barcode lookup

When you look up a product by its barcode, the app contacts the open product database Open Food Facts (France, EU). Only the code number is sent. As when visiting any website, their server sees your IP address. Open Food Facts is an independent data controller, not our processor.

Who receives data

  • Cloudflare, Inc. – domain name system (DNS) (data processor). Data may be transferred to the USA under the EU-US Data Privacy Framework and standard contractual clauses.
  • Zoho Corporation B.V. – our mailbox (data processor); data is stored in an EU data centre. This is where the emails you write to us end up.
  • Hetzner Online GmbH (Germany) – the server that runs the website and the app and stores the waitlist, accounts and messages (data processor, EU data centre).
  • Email sending service – to be added when we start sending emails.
  • Apple and Google – only if you buy Plus in their stores (separate controllers).

We don't pass data to anyone else, and we never sell it.

Cookies and device storage

We don't use advertising, analytics or tracking cookies. The only cookie is the login cookie, if you have an account. Fonts are loaded from our own website, not from third parties. Your device stores only the data without which the features you use wouldn't work (quiz answers, the app's food diary, photos, working offline). That's why we don't show a cookie banner. If we ever wanted to add visitor statistics, we would first describe it here and ask you.

Automated decisions

The quiz and the calculator give suggestions calculated on your device using publicly described formulas. We make no automated decisions with legal or similarly significant effects, and we don't build profiles for advertising.

Age

Dumpli is meant for adults (18+). Teenagers should discuss a meal plan with their parents and a doctor. We only accept people aged 18 or over on the waitlist.

Your rights

You can ask to access your data, correct it, delete it, restrict its processing, object to processing, receive it in a portable format, and withdraw your consent at any time (every email has an unsubscribe link). Write to labas@dumpli.app – we'll reply within a month, free of charge. We'll check your identity only when it's really necessary.

If you think your rights have been violated, you can contact VDAI (the State Data Protection Inspectorate of Lithuania; L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, vdai.lrv.lt) or the supervisory authority in your own EU country. We'd be grateful if you wrote to us first.

Security

The website works only over a secure connection (HTTPS), with security headers and without third-party scripts. We collect as little as possible. Account records are encrypted, passwords are stored only as hashes, and the number of password-guessing attempts is limited. Data on your device is only as secure as the device itself – use a screen lock.

Changes

Every version has a number and a date. We'll tell waitlist members about significant changes by email in advance. See also the terms of use.