Privacy
The short version: Fed keeps your email address and the weeks it planned for you. Health details like allergies are used only if you say yes, and stay in your browser. Nothing is sold and nothing is shared for advertising.
Fed is run by T-StartUps, based in the Netherlands. Questions or requests: getfedapp@proton.me.
KVK registration is in progress. The registered name, address, chamber-of-commerce and VAT numbers will be added here once they're issued.
On what basis
Everything below is stored on one of four legal bases. Your account, plans and payments are kept because we can't run the service you asked for without them — performance of a contract. Usage counts and the abuse checks on generation and feedback limits are our legitimate interest in keeping Fed working and affordable for everyone, weighed against your privacy — which is why they're built to identify as little as possible. Payment records are kept as long as they are because Dutch tax law requires it — a legal obligation. Health information — allergies and intolerances, and the body details in the portion step — is used only with your explicit consent, which you give in a separate pop-up, only when you choose to enter that information, and can withdraw at any time (see “Health information” below). Where Google sign-in shares more with us, that's your own choice to use it.
What is stored, and why
- Your email address
- So you can sign in and so we can reach you about your account. If you signed in with Google we also receive your name and profile picture.
- Your password
- Only ever as an Argon2 hash. The password itself is never written down anywhere, which is also why nobody here can tell you what it is if you forget it.
- Your saved weeks
- If you're signed in: the weeks Fed planned for you — the dishes, the shopping list and, if you used the portion step, the daily calorie and protein target worked out from your details. This is what makes a plan appear on your other device. Your diet choices, allergies, body details and any note you typed stay in your browser. They're sent to Fed's server when a week is planned, and aren't saved in Fed's database.
- A count of weeks generated
- A timestamp per generation, so the free allowance can be enforced. Before you have an account this is tied to a random identifier stored in your browser, not to you.
- Your likes, dislikes and notes on dishes
- If you're signed in, your “More like this” and “Not again” choices and any notes you write on a recipe, so they follow you to your other devices. Without an account they stay in your browser only.
- Feedback you send
- Your message, the page you were on, your account if you're signed in, and an email address only if you choose to give one. A one-way code made from your network address is kept with it, only to stop one network sending more than ten messages a day. It's also forwarded straight to the inbox of whoever runs Fed, so it's read promptly.
- Usage counts
- How many times things happen each day — for example, how often cooking mode is opened, a shopping list is shared, or someone reaches a given step of building a week. If a link brought you here, which site it was, as just its domain ("reddit.com"), never the full link or the page you were on. Only the date, the kind of event, that domain where it applies, and a number are stored. No account, device, address or cookie is attached, so none of it can be traced back to you.
- Payments
- If you buy access, we store which plan you bought, the amount, and Mollie's payment reference. Card and bank details never reach Fed — those go straight to Mollie, our payment provider.
What is not stored
- No card numbers, IBANs or bank credentials.
- No advertising or tracking cookies, and no analytics profile.
- Nothing is sold or handed to advertisers. There is no such deal.
Health information
Allergies and intolerances (nuts, dairy, gluten, egg, fish) and the body details in the portion step (weight, height, age, sex, activity, goal) are information about your health. Fed only uses them if you say yes when it asks for your explicit consent, in a separate pop-up that appears when you try to add an allergy or use the portion option. Until you do, those stay locked. Choices like vegetarian or no pork aren't health information, but they get the same care, because they can hint at beliefs.
When you agree:
- They're sent to Fed's server to plan and price your week. Your allergies and body details stay in your browser and aren't saved in Fed's database.
- For a freshly written week, your allergies and a daily calorie and protein target worked out from your body details go to Fed's AI writer, Anthropic, in the USA. Your weight, height, age, name and email do not.
- If you're signed in, the weeks Fed saves for you include that calorie target, so a week can show whether it feeds you enough.
- Anything you type in the notes box goes to the AI writer exactly as written. Keep health details to the boxes, where Fed can actually filter for them.
To withdraw, tap “Withdraw” under the allergy list or the portion option. That clears your allergy ticks and body details from this device and Fed stops using them straight away — which also means it stops filtering for allergies, and says so. To remove saved weeks that hold the calorie target, use “Delete my saved weeks” or delete your account, both on the Account page.
Who else sees it
Four companies process data on Fed's behalf, and only to do their job:
- Railway — Fed runs on Railway's servers, which hold the database with everything under “What is stored”. Railway is a US company and processes data in the United States, so this is a transfer outside the EU. It relies on the EU–US Data Privacy Framework, which the European Commission recognises as adequate, and on standard contractual clauses.
- Anthropic — when you ask for a freshly generated week, your budget, diet and allergy choices, cuisine choices, a daily calorie and protein target if you used the portion step, and anything you typed in the notes box are sent so a plan can be written. Your name, email address, weight, height and age are not. Anthropic is based in the United States, so this is a transfer outside the EU; it happens under the standard contractual clauses the European Commission has approved for exactly this.
- Mollie — handles payments and sees what a payment provider must see.
- Google — only if you choose to sign in with Google.
Freshly written weeks are written by an AI model. Each dish it writes is labelled “AI-written” on its card, and marked as AI-generated in the data behind it.
How long it is kept
Your account and its data stay until you delete them, which you can do yourself on the Account page. Delete it and everything attached — weeks, likes and notes, savings history, feedback and price corrections you sent — goes with it. Some things don't wait for that, and are deleted automatically:
- The one-way network codes used to stop abuse: after 30 days.
- The record that a freshly written week was made, for the free allowance: after about a year.
- Price corrections you send: after 90 days, which is how long they count.
- Feedback: after a year. Reports on a recipe: six months after they've been dealt with.
- Server error logs: after 90 days.
Payment records are the exception: Dutch tax law requires the seller to keep them for seven years. When you delete your account they stay, but detached from you — what remains is a payment reference, a plan, an amount and dates, with nothing that says who paid.
Your rights
Under the GDPR you can ask us to:
- send you a copy of your data (access) — “Download my data” on the Account page, a plain JSON file
- correct it if it's wrong (rectification)
- delete it (erasure) — “Delete my account” on the Account page, which works straight away
- hand you your data in a portable format, to take elsewhere (portability) — the same download
- pause processing while a request like this is being sorted out (restriction)
- stop processing done on the legitimate-interest basis above (objection) — for example, if you'd rather not be counted in usage stats
- withdraw your consent to using health information (withdrawal) — tap “Withdraw” in the app, any time, and it stops straight away
We have to respond within a month. Email the address above. You can also complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.
Age
Fed is for people aged 16 and over. If you think someone younger has made an account, email us and we'll delete it.
Cookies
Only four things are stored in your browser, and all are necessary for Fed to work: a sign-in cookie; a cookie remembering whether you use Fed in English or Dutch; a small amount of local storage holding your preferences (including light or dark appearance, and whether you've agreed to Fed using health information), your current week and your ticked-off shopping items; and, once you've opened Fed, a copy of the app itself so it opens without signal. There is nothing to consent to because there is nothing optional being collected.
Last updated: 19 September 2026.