Privacy Policy — Mibo

Last updated: September 21, 2026

1. Who we are

The Mibo mobile app (the “App”) is published by:

The publisher is the data controller for the personal data described in this document, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the “GDPR”) and, for users located in Switzerland, within the meaning of Article 5(j) of the Swiss Federal Act on Data Protection (the “FADP”, see section 13). Details specific to users located in Quebec are set out in section 14.

2. How the App works, briefly

Mibo generates a weekly meal plan from preferences you provide during an onboarding flow (preferred store, weekly budget, household size, diet, declared allergies, disliked ingredients, meal style, kitchen equipment, number of dinners per week). There is no traditional account creation (no email/password): the App uses an anonymous Supabase session — a unique technical identifier generated automatically on install, with no sign-up or identity verification.

3. Data we collect

CategoryDetailSource
Meal preferences First name, country, preferred store, weekly budget, household size, disliked ingredients, meal style, kitchen equipment owned, dinners per week, maximum prep time Entered by you during onboarding, editable in “Preferences”
Allergies and diet Declared allergies, diet (e.g. vegetarian, no pork) Entered by you; kept only on your device, never sent to our servers or service providers
Meal history Recipes already served, with date Generated automatically by app usage (used to avoid repeating a recipe too soon)
Content you send us Message and optional contact email in the “Feedback” form Entered by you, at your initiative
Anonymous identifiers Supabase anonymous session identifier, RevenueCat user identifier Generated automatically, contains no civil identity data
Subscription data Premium subscription status, in-app purchase history Provided by Apple App Store / Google Play via RevenueCat — we never receive your payment card details, which are handled exclusively by Apple/Google
Technical and crash data Error reports, IP address, device and OS information Collected automatically by our error-tracking tool (Sentry)
Usage and analytics data Screens viewed, product events (e.g. plan generated, recipe swapped) Collected by our analytics tool (PostHog) only if you agree — session replay and autocapture are disabled
Advertising and attribution identifiers IDFV (iOS) / Android ID, advertising identifier if authorized, install data Collected automatically by our marketing attribution partners (Tenjin, Firebase/Google Ads) — subject to your consent, see section 8

Your allergies and diet may reveal information about your health or religious beliefs, which is sensitive data (GDPR Art. 9, FADP Art. 5(c), Section 12 of the Quebec private-sector Act). This is why they stay only on your device: recipe selection is computed locally, and this information is never sent to our servers, analytics tools or service providers. The publisher has no access to it. It is erased when you use “Delete my data” or uninstall the App. See also the disclaimer in section 11.

4. Why we process this data (purposes and legal bases)

PurposeLegal basis (GDPR Art. 6)
Generate and display your meal plan, shopping list, manage your preferences Performance of a contract (Art. 6(1)(b))
Manage your Premium subscription via Apple/Google Performance of a contract (Art. 6(1)(b))
Respond to messages sent via the feedback form Performance of a contract / legitimate interest in providing support (Art. 6(1)(b)/(f))
Fix bugs, ensure the security and stability of the App (Sentry) Legitimate interest (Art. 6(1)(f))
Measure aggregate product usage to improve the App (PostHog) Consent (Art. 6(1)(a)), collected in the App and revocable at any time in Settings
Measure advertising campaign effectiveness and attribute installs to a campaign (Tenjin, Firebase/Google Ads) Consent (Art. 6(1)(a)) — required under the ePrivacy Directive wherever an identifier is read from or stored on your device for non-strictly-necessary purposes
Comply with our legal obligations Legal obligation (Art. 6(1)(c))

5. Who we share your data with (processors)

We do not sell personal data. Some data is shared with technical service providers, each acting as a processor under Article 28 of the GDPR, strictly for the purposes listed above:

ProviderRoleData location
SupabaseDatabase, anonymous authentication, recipe image storageEuropean Union (Ireland)
PostHogProduct usage analyticsEuropean Union
SentryError tracking and diagnosticsEuropean Union (Germany)
RevenueCatSubscription and in-app purchase managementUnited States
TenjinInstall attribution to marketing campaignsUnited States
Google / FirebaseAdvertising conversion measurement (Google Ads)United States
Apple Inc. / Google LLCSubscription payment processing via the storesUnited States

Apple and Google, as operators of the App Store and Google Play, process subscription payments as independent controllers rather than as processors.

6. International data transfers

RevenueCat, Tenjin, Google/Firebase and Apple are US-based companies that may process data outside the European Union. These transfers rely on the following safeguards:

The publisher reviews the safeguards applicable to each provider periodically, as certification statuses and contractual arrangements change over time. You may request details of the safeguards applicable to a given provider by writing to mibo@solis-apps.com.

Safeguards applicable to disclosures of data from Switzerland and from Quebec are described in sections 13 and 14.

7. Retention period

8. Your choices about advertising tracking (ATT and Android equivalent)

On iOS, the App asks for your permission via Apple's system-level “App Tracking Transparency” prompt before any tracking activity used for advertising attribution. You can review or change this choice at any time in your phone Settings > Privacy & Security > Tracking, or in Mibo > Settings > Tracking status (ATT).

If you decline, the App continues to work normally; only advertising attribution features are disabled or limited to non-individualized data.

9. Your rights

Under Articles 15 to 22 of the GDPR, you have the following rights over your personal data:

To exercise these rights (other than in-app deletion), contact mibo@solis-apps.com. You may also lodge a complaint with your national data protection authority in the EU (e.g. the CNIL in France — www.cnil.fr), or the supervisory authority of your country of residence. If you reside in Switzerland or Quebec, your rights and the competent authority are set out in section 13 and section 14.

10. Security

Your data is protected by strict database-level access rules (Supabase Row Level Security): each anonymous session can only read, modify or delete its own data. Communications between the App and our servers are encrypted (TLS).

11. Important disclaimer — allergies and diet

Recipe filtering by allergen and diet is performed automatically based on information you declare and data in the recipe catalog. It is not medical advice nor an absolute guarantee that a recipe is free of a given allergen. Always check the ingredient list yourself before consuming a recipe, especially in case of severe allergies.

To the extent permitted by applicable law, the publisher is not liable for any allergic reaction, health incident, or damage resulting from incorrect or incomplete food information.

12. Children

The App is not directed at individuals under 16. If you are between 13 and 16 (depending on the digital age of consent set by your EU country of residence), use of the App requires parental consent. In Switzerland, use of the App by a person aged 13 to 16 likewise requires the consent of their legal representative.

13. Users located in Switzerland (FADP)

If you reside in Switzerland, the processing of your data is also governed by the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”, SR 235.1) and its Ordinance (the “DPO”, SR 235.11), which apply whenever processing has an effect in Switzerland (Art. 3 FADP). This entire document applies to users located in Switzerland; this section clarifies or adapts certain points.

13.1 Controller

The controller is the publisher identified in section 1, established in France, reachable at mibo@solis-apps.com. No representative in Switzerland has been appointed, as the cumulative conditions of Article 14 FADP (large-scale, regular processing involving a high risk to the personality of data subjects) are not met.

13.2 Principles and grounds for justification

The FADP does not require a legal basis for every processing operation; it requires compliance with the principles of lawfulness, good faith, proportionality, purpose limitation, accuracy and security (Arts. 6 and 8 FADP). Where a ground for justification is required (Art. 31 FADP), we rely on the grounds set out in section 4: performance of a contract, our overriding interest, or your consent. The advertising-tracking consent mechanism described in section 8 also applies in Switzerland.

13.3 Disclosure of data abroad

Your data may be disclosed to the recipients listed in section 5, located in the following countries:

13.4 Automated individual decisions

Your meal plan is generated automatically, but this is not an automated individual decision within the meaning of Article 21 FADP: it has no legal effect on you and does not significantly affect you. No other decision of this kind is made about you.

13.5 Your rights

In particular, you have the following rights:

To exercise these rights, write to mibo@solis-apps.com. Since the App works without an account, we may ask you for the information needed to locate the data associated with your anonymous session. If you believe the processing of your data breaches the FADP, you may contact the Federal Data Protection and Information Commissioner (FDPIC)www.edoeb.admin.ch — or bring a claim before the competent civil courts.

14. Users located in Quebec (Law 25)

If you reside in Quebec, the processing of your personal information is also governed by the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as amended by Law 25 (the “Act”). This entire document applies to users located in Quebec; this section clarifies certain points.

14.1 Person in charge of the protection of personal information

In accordance with Section 3.1 of the Act, the person in charge of the protection of personal information is Rémi Dutot, publisher of the App, reachable at mibo@solis-apps.com. Any question, access request or complaint about your personal information may be addressed to him.

14.2 Consent and privacy settings

Your information is collected from you, through the App, for the purposes described in section 4. In accordance with Sections 8.1 and 9.1 of the Act, the App's settings provide the highest level of confidentiality by default:

14.3 Communication outside Quebec

Your personal information is communicated outside Quebec, to the service providers listed in section 5, in the European Union (Ireland, Germany) and the United States. These communications are governed by the contractual commitments and safeguards described in section 6 (Section 17 of the Act).

14.4 Automated decisions

Your meal plan is generated automatically, but no decision based exclusively on automated processing and producing effects on you is made within the meaning of Section 12.1 of the Act.

14.5 Your rights

To exercise these rights, write to mibo@solis-apps.com. In the event of a confidentiality incident presenting a risk of serious injury, we will notify you and the Commission d'accès à l'information (Section 3.5). If you are not satisfied with our response, you may contact the Commission d'accès à l'information du Québec (CAI)www.cai.gouv.qc.ca.

15. Users located in other countries

Since the App is distributed worldwide via the App Store and Google Play, the principles in this document (GDPR) are applied as our baseline standard of processing for all users. If you reside outside the EU, Switzerland and Quebec, additional local regulations may grant you different or additional rights (for example, the California Consumer Privacy Act for California residents). This document does not detail those local regimes; to exercise a right specific to your jurisdiction, contact mibo@solis-apps.com.

16. Changes to this policy

This policy may be updated to reflect changes to the App or to applicable law. The “last updated” date at the top of this document reflects the latest revision. You will be notified in-app of any material change.

17. Contact

For any question about this policy or your personal data: mibo@solis-apps.com. No Data Protection Officer (DPO) has been appointed to date, as appointing one is not mandatory given the scale and nature of the Publisher's processing activities.