Privacy Policy — Mibo
Last updated: August 7, 2026
1. Who we are
The Mibo mobile app (the “App”) is published by:
- Publisher: Rémi Dutot, sole trader (French entreprise individuelle / micro-entreprise)
- Address: 2 Impasse du Maine Poirier, 17360 La Clotte, France
- Registration number: SIRET 834 715 534 00022
- Contact / data controller: mibo@solis-apps.com
The publisher is the data controller for the personal data described in this document, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the “GDPR”).
2. How the App works, briefly
Mibo generates a weekly meal plan from preferences you provide during an onboarding flow (preferred store, weekly budget, household size, diet, declared allergies, disliked ingredients, meal style, kitchen equipment, number of dinners per week). There is no traditional account creation (no email/password): the App uses an anonymous Supabase session — a unique technical identifier generated automatically on install, with no sign-up or identity verification.
3. Data we collect
| Category | Detail | Source |
|---|---|---|
| Meal preferences | First name, preferred store, weekly budget, household size, diet, declared allergies, disliked ingredients, meal style, kitchen equipment owned, dinners per week, maximum prep time | Entered by you during onboarding, editable in “Preferences” |
| Meal history | Recipes already served, with date | Generated automatically by app usage (used to avoid repeating a recipe too soon) |
| Content you send us | Message and optional contact email in the “Feedback” form | Entered by you, at your initiative |
| Anonymous identifiers | Supabase anonymous session identifier, RevenueCat user identifier | Generated automatically, contains no civil identity data |
| Subscription data | Premium subscription status, in-app purchase history | Provided by Apple App Store / Google Play via RevenueCat — we never receive your payment card details, which are handled exclusively by Apple/Google |
| Technical and crash data | Error reports, IP address, device and OS information | Collected automatically by our error-tracking tool (Sentry) |
| Usage and analytics data | Screens viewed, product events (e.g. plan generated, recipe swapped) | Collected automatically by our analytics tool (PostHog) — session replay and autocapture are disabled |
| Advertising and attribution identifiers | IDFV (iOS) / Android ID, advertising identifier if authorized, install data | Collected automatically by our marketing attribution partners (Tenjin, Firebase/Google Ads) — subject to your consent, see section 8 |
We do not collect any health data within the meaning of Article 9 of the GDPR: the allergies and diets you declare are used solely to filter recipes and are never analyzed or used for medical purposes. See the disclaimer in section 11.
4. Why we process this data (purposes and legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Generate and display your meal plan, shopping list, manage your preferences | Performance of a contract (Art. 6(1)(b)) |
| Manage your Premium subscription via Apple/Google | Performance of a contract (Art. 6(1)(b)) |
| Respond to messages sent via the feedback form | Performance of a contract / legitimate interest in providing support (Art. 6(1)(b)/(f)) |
| Fix bugs, ensure the security and stability of the App (Sentry) | Legitimate interest (Art. 6(1)(f)) |
| Measure aggregate product usage to improve the App (PostHog) | Legitimate interest (Art. 6(1)(f)), limited to what is strictly necessary |
| Measure advertising campaign effectiveness and attribute installs to a campaign (Tenjin, Firebase/Google Ads) | Consent (Art. 6(1)(a)) — required under the ePrivacy Directive wherever an identifier is read from or stored on your device for non-strictly-necessary purposes |
| Comply with our legal obligations | Legal obligation (Art. 6(1)(c)) |
5. Who we share your data with (processors)
We do not sell personal data. Some data is shared with technical service providers, each acting as a processor under Article 28 of the GDPR, strictly for the purposes listed above:
| Provider | Role | Data location |
|---|---|---|
| Supabase | Database, anonymous authentication, recipe image storage | European Union (Ireland) |
| PostHog | Product usage analytics | European Union |
| Sentry | Error tracking and diagnostics | European Union (Germany) |
| RevenueCat | Subscription and in-app purchase management | United States |
| Tenjin | Install attribution to marketing campaigns | United States |
| Google / Firebase | Advertising conversion measurement (Google Ads) | United States |
| Apple Inc. / Google LLC | Subscription payment processing via the stores | United States |
6. International data transfers
RevenueCat, Tenjin, Google/Firebase and Apple are US-based companies that may process data outside the European Union. These transfers rely, depending on the provider, on:
- the provider's certification under the EU-US Data Privacy Framework, where applicable; and/or
- Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR).
The publisher reviews the safeguards applicable to each provider periodically, as certification statuses and contractual arrangements change over time. You may request details of the safeguards applicable to a given provider by writing to mibo@solis-apps.com.
7. Retention period
- Preferences and meal history: kept for as long as you use the App, until you exercise your right to erasure (section 9) or durably uninstall the App.
- Recent meal history: the last 14 days are actively used to avoid suggesting the same recipe too soon. No automatic purge policy currently applies to older history, which remains stored until you delete it.
- Feedback messages: kept until your request is handled, then for 12 months, unless deleted earlier via “Delete my data”.
- Diagnostic data (Sentry): kept per Sentry's retention policy, typically 90 days.
- Attribution/advertising data: kept per each partner's own retention policy (Tenjin, Google).
8. Your choices about advertising tracking (ATT and Android equivalent)
On iOS, the App asks for your permission via Apple's system-level “App Tracking Transparency” prompt before any tracking activity used for advertising attribution. You can review or change this choice at any time in your phone Settings > Privacy & Security > Tracking, or in Mibo > Settings > Tracking status (ATT).
If you decline, the App continues to work normally; only advertising attribution features are disabled or limited to non-individualized data.
9. Your rights
Under Articles 15 to 22 of the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of your data;
- Right to rectification: correct inaccurate data — available directly in Preferences for your meal preferences;
- Right to erasure: delete your data — available directly in Settings > Delete my data, which erases all your server-side preferences, meal history and feedback messages, then returns you to onboarding;
- Right to restriction of processing;
- Right to object, in particular to processing based on legitimate interest (section 4);
- Right to data portability for data you provided to us;
- Right to withdraw consent at any time for processing that relies on it (section 8), without affecting the lawfulness of processing carried out before withdrawal;
- Right to set directives on the fate of your data after your death (French law, Art. 85 of the Loi Informatique et Libertés), for users in France.
To exercise these rights (other than in-app deletion), contact mibo@solis-apps.com. You may also lodge a complaint with your national data protection authority in the EU (e.g. the CNIL in France — www.cnil.fr), or the supervisory authority of your country of residence.
10. Security
Your data is protected by strict database-level access rules (Supabase Row Level Security): each anonymous session can only read, modify or delete its own data. Communications between the App and our servers are encrypted (TLS).
11. Important disclaimer — allergies and diet
Recipe filtering by allergen and diet is performed automatically based on information you declare and data in the recipe catalog. It is not medical advice nor an absolute guarantee that a recipe is free of a given allergen. Always check the ingredient list yourself before consuming a recipe, especially in case of severe allergies.
To the extent permitted by applicable law, the publisher is not liable for any allergic reaction, health incident, or damage resulting from incorrect or incomplete food information.
12. Children
The App is not directed at individuals under 16. If you are between 13 and 16 (depending on the digital age of consent set by your EU country of residence), use of the App requires parental consent.
13. Users located outside the European Union
Since the App is distributed worldwide via the App Store and Google Play, the principles in this document (GDPR) are applied as our baseline standard of processing for all users. If you reside outside the EU, additional local regulations may grant you different or additional rights (for example, the California Consumer Privacy Act for California residents). This document does not detail those local regimes; to exercise a right specific to your jurisdiction, contact mibo@solis-apps.com.
14. Changes to this policy
This policy may be updated to reflect changes to the App or to applicable law. The “last updated” date at the top of this document reflects the latest revision. You will be notified in-app of any material change.
15. Contact
For any question about this policy or your personal data: mibo@solis-apps.com. No Data Protection Officer (DPO) has been appointed to date, as appointing one is not mandatory given the scale and nature of the Publisher's processing activities.