Legal

Privacy Policy

1. Scope and data controller

This Privacy Policy explains how Cobalt Cat, a food, nutrition, and body-weight tracking service, processes personal data when you use the application and related services.

Cobalt Cat is operated by Viktor Livar. The operator is the data controller for personal data processed through the service. Privacy questions and requests can be sent to support@cobaltcat.app.

2. Personal data we process

Depending on how you use the service, we process the following categories of information:

  • Account and authentication data: a stable account identifier, email address, display name, profile picture, authentication status, and account or session timestamps.
  • Food and nutrition data: selected products, custom products, portion weights, meal times, daily intake records, calories, macronutrients, favorites, and product ordering.
  • Body-weight data: dated body-weight measurements and your optional target body weight.
  • Day metadata and settings: day labels, label definitions, predefined meal times, nutrient-summary preferences, product-card preferences, and synchronization metadata.
  • Custom product content: product names, nutrient values, images you upload or paste, and image URLs you ask the service to import.
  • Technical data: IP address and request metadata processed by hosting and authentication providers, authentication events, error details, diagnostic information, and security logs needed to operate and protect the service.

Nutrition, food-intake, and body-weight records may constitute data concerning health under applicable law. You choose whether to enter this information.

3. Account credentials and Google sign-in

Account authentication is provided through Amazon Cognito. If you use email and password credentials, Cognito processes the credentials and Cobalt Cat does not receive or store your password in plain text.

If you choose to sign in with Google, Cobalt Cat requests only the OpenID Connect identity scopes needed for authentication: openid, email, and profile. We may receive your Google account identifier, name, email address, email-verification status, and profile picture. We do not receive your Google password and do not request access to Gmail, Google Drive, contacts, calendars, or other Google account content.

Google processes the sign-in interaction under its own privacy terms. You can manage the connection from your Google account as well as request deletion from Cobalt Cat.

4. Local-first storage and guest use

Cobalt Cat is local-first. The application stores product data, intake records, body-weight records, settings, favorites, labels, and synchronization state in IndexedDB on your device. Authentication tokens are stored in local storage, while short-lived login state and PKCE verification data are stored in session storage.

You can use core features without an account. Guest data remains on that browser and is not sent to Cobalt Cat servers unless you later sign in. When you sign in, locally stored guest data may be associated with your account and synchronized so that it is available in later sessions or on other devices.

Clearing site data, using private-browsing cleanup, uninstalling the browser, or losing the device can remove local information that has not synchronized. Logging out removes the local authentication session but does not itself delete locally stored tracking data or server-side account data.

5. Why we process personal data

We process account information and application data to create and maintain your account, provide the features you request, synchronize data, preserve settings, respond to support requests, and perform our agreement with you. Where the GDPR applies, this processing is based on Article 6(1)(b).

Where nutrition or body-weight information qualifies as special-category health data and a special-category condition is required, we rely on your explicit consent under Article 9(2)(a). You may withdraw that consent at any time by contacting us. Withdrawal does not affect earlier lawful processing, but it may require deletion of the relevant records and prevent us from providing features that depend on them.

We process limited technical and security information where necessary for our legitimate interests in securing, troubleshooting, and reliably operating the service under Article 6(1)(f). We may also process information to comply with legal obligations under Article 6(1)(c).

6. How we use and disclose information

We use personal data only to operate, maintain, secure, support, and improve Cobalt Cat, and to comply with applicable law. We do not sell personal data, display advertising, create advertising profiles, or share food-intake or body-weight history with data brokers or advertisers.

We disclose information only to service providers acting on our behalf, when you direct us to do so, when required by law, or when reasonably necessary to protect users, the service, or others from fraud, abuse, security threats, or unlawful activity.

Cobalt Cat does not currently use third-party behavioral analytics or advertising trackers.

7. Service providers and processing locations

Amazon Web Services (AWS) provides authentication, application hosting, content delivery, APIs, serverless processing, databases, file storage, and operational logging. Core server-side account data and uploaded product images are currently stored in the AWS us-east-1 region in Northern Virginia, United States. The public application is delivered through a global content-delivery network.

Google acts as an independent provider when you choose Google sign-in. Google may also receive a browser request when the application displays the profile-picture URL supplied with your Google identity.

These providers process information under their own terms and applicable data-protection obligations. Provider use can involve processing in the United States and other countries in which they operate.

8. Product images and imported image URLs

When you create or edit a custom product, the application resizes and converts the selected image before it is stored. If you provide an image URL, the Cobalt Cat backend downloads the image from that public URL and stores a processed copy.

Stored product images are served from publicly accessible object URLs so that product cards can display them efficiently. They are not presented as a public user gallery, but anyone who obtains an image URL may be able to view the image. Do not upload images containing people, private documents, sensitive information, or content you do not have the right to use.

9. International data transfers

Because the service uses infrastructure in the United States and globally operated providers, personal data may be transferred across national borders. Where personal data subject to the GDPR is transferred outside the European Economic Area and safeguards are required, we rely on applicable provider contractual protections, including the European Commission Standard Contractual Clauses incorporated into the AWS Data Processing Addendum, or another lawful transfer mechanism.

10. Retention

Local data remains in your browser until it is removed by the application, by you through browser controls, or by the browser or device. Synced account data is generally retained while your account remains active and until it is deleted or no longer needed to provide the service.

Temporary staged image imports expire automatically after approximately one day. When a stored custom-product image is replaced, the service attempts to remove the previous image. Operational and security logs are retained according to operational, security, and legal needs.

After a valid deletion request, we delete or anonymize personal data that is no longer required, subject to reasonable technical processing time and any information that must be retained to comply with law, resolve disputes, or protect the service.

11. Browser storage and cookies

The Cobalt Cat web application uses IndexedDB, local storage, and session storage for local-first data, authentication, security, and application state. It does not currently set advertising or analytics cookies.

Amazon Cognito and Google may set necessary authentication or security cookies on their own domains during sign-in and sign-out. Their handling of those cookies is governed by their respective policies.

12. Security

We use reasonable technical and organizational safeguards designed to protect personal data, including encrypted network connections, managed authentication, access-controlled APIs, and encrypted AWS storage. No internet service or storage system can guarantee absolute security.

You are responsible for protecting your device and account access. Contact us promptly if you believe your account or data has been accessed without authorization.

13. Your privacy rights

Depending on applicable law, you may have rights to:

  • request access to your personal data and information about its processing;
  • correct inaccurate or incomplete personal data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests;
  • receive eligible data you provided in a portable, machine-readable form;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with the competent data-protection authority where you live or work, or where you believe a violation occurred.

To exercise a right, email support@cobaltcat.app. We may request information necessary to verify your identity and account ownership. Rights are subject to applicable legal conditions and exceptions.

14. Account and data deletion

Cobalt Cat does not currently provide an in-app account-deletion control. To request deletion of your account and synchronized data, email support@cobaltcat.app, preferably from the email address associated with your account. You may also request a copy of eligible account data through the same address.

Account deletion is permanent once completed. Deleting server-side data does not automatically clear copies stored locally in your browser, so you should also log out and clear Cobalt Cat site data on devices where you no longer want it retained.

15. Children

Cobalt Cat is not intended for children under 16, and children under 16 must not create an account or provide personal data through the service. If we learn that personal data was collected from a child contrary to applicable law, we will take appropriate steps to delete it.

16. Automated decisions

Cobalt Cat does not use personal data to make automated decisions that produce legal or similarly significant effects. Nutrient calculations, summaries, and progress charts are informational outputs based on data recorded in the application.

17. Changes to this policy

We may update this Privacy Policy as the service, providers, or legal requirements change. We will update the effective date and provide additional notice when required for a material change.

18. Contact

Data controller: Viktor Livar. Email: support@cobaltcat.app.