Skip to main content
Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and how you stay in control under the GDPR.

Last updated 30 July 2026

1. Who is responsible for your data

Anti-Diet Club (the controller) operates this website and its member area. For any privacy question or to exercise your rights, write to antidietclub2304@gmail.com. This page is maintained by the Anti-Diet Club team and describes our current practices.

2. Data we process

CategoryExamplesPurposeLegal basis
AccountEmail, display name, password hash, sign in providerCreate and secure your accountContract (Art. 6(1)(b))
MembershipPlan, subscription status, roleGive access to Premium featuresContract
Journal and check insFree text entries, mood, energy, emotions, photos you uploadProvide the private journal you asked forExplicit consent (Art. 9(2)(a))
MessagesMessages you exchange with the teamAnswer and support youContract / consent
TechnicalIP address, browser type, security and error logsKeep the service available and secureLegitimate interest (Art. 6(1)(f))
CookiesSession and consent preferencesSign you in, remember your choicesStrictly necessary / consent

Journal entries, emotions and anything you write about food, your body or your health can reveal health data. We treat that as special category data under Article 9: it is stored for you alone, is never sold, never used for advertising and never used to train external AI models.

3. Children

The service is not intended for people under 16. If we learn that an account belongs to a child under 16 without parental authorisation, we delete it.

4. AI companion

When you use the AI companion, the messages of that conversation are sent to our AI provider to generate a reply. We do not send your journal entries, your email or your account identifiers with them, and we do not use these conversations to train models. The companion is educational support, not clinical care.

5. Processors and transfers

  • Hosting and application delivery, for serving the website.
  • Managed database, authentication and file storage, for your account and content, hosted in the European Union where the region is configurable.
  • AI inference provider, for the AI companion replies only.
  • Email delivery, for account emails such as confirmation and password reset.

Each processor acts on our documented instructions under a data processing agreement. Where a transfer outside the EEA is unavoidable, it relies on the European Commission Standard Contractual Clauses.

6. Retention

  • Account and membership data: for as long as your account exists, then deleted.
  • Journal entries, check ins and uploaded photos: until you delete them or delete your account.
  • Messages: up to 3 years after the last exchange.
  • Security and error logs: up to 12 months.

7. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent at any time without affecting past processing. You can also lodge a complaint with your national supervisory authority (in France, the CNIL).

We answer requests within one month. Two of these rights are automated below, so you do not have to wait for us.

8. Security

Access to your data is enforced row by row in the database, so one member can never read another member's journal or messages. Uploaded photos live in a private bucket reachable only through short lived signed links. See our security practices for details, and our cookie policy for tracking choices.

9. Breach notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we inform affected members without undue delay when the risk is high.

10. Changes

We update this notice when our practices change and always publish the date of the latest version at the top of this page.

SOS, gratuit