Privacy Policy
Last Updated: 24 March 2025
Effective Date: 24 March 2025
Knowledge Collective Ltd ("we", "us", "our", or "Mena AI") operates the Mena AI mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
Company Details:
Knowledge Collective Ltd
167-169 Great Portland Street, 5th Floor
London W1W 5PF
United Kingdom
Contact: team@trymena.ai
By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
1. Information We Collect
1.1 Personal Information
When you create an account or use the App, we may collect:
- Account Information: Name, email address, username, date of birth, gender, and profile avatar.
- Authentication Data: Sign-in credentials via Google Sign-In, Apple Sign-In, or email/password through our authentication provider (Supabase Auth). We do not store your Google or Apple passwords.
1.2 Health and Body Data
To provide personalised nutrition guidance, we collect:
- Body Metrics: Height, current weight, starting weight, target weight, and target date.
- Health Conditions: Any health conditions you choose to disclose, medication status, pregnancy status.
- Activity Data: Activity level, occupation type, and lifestyle information.
1.3 Nutrition and Diet Data
- Meal Logs: Food descriptions, timestamps, nutritional breakdowns (calories, protein, carbohydrates, fat, fibre, sugar), and meal zone classifications.
- Meal Photos: Images of meals you upload for AI-powered analysis.
- Water Intake: Daily water consumption tracking.
- Dietary Preferences: Meals per day, calorie targets, and dietary patterns.
1.4 Fitness and Activity Data (Optional)
If you connect a health data source, we may read:
- Google Fit / Health Connect (Android): Steps, weight, sleep data, total and active calories burned.
- Apple HealthKit (iOS): Steps, sleep, calories, and weight data.
You can disconnect these integrations at any time from the App settings.
1.5 Behavioural and Wellbeing Data
- Daily Check-Ins: Mood, feelings, and self-reported wellbeing data.
- Motivation Factors: Your reasons for using the App and weight loss goals.
1.6 Social and Community Data
- Social Interactions: Group memberships, partnership/buddy connections, activity feed posts, comments, kudos/likes, and follower/following relationships.
- Referrals: Referral codes and referral status.
- Achievements: Badges earned, streak counts, and challenge participation.
1.7 AI Interaction Data
- Chat Messages: Conversations with the AI assistant for nutrition guidance.
- Meal Analysis: Prompts and results from AI-powered meal analysis (both image and text-based).
- AI-Generated Content: Personalised insights, recommendations, and coaching responses.
1.8 Device and Technical Data
- Device Tokens: For delivering push notifications via Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS).
- App Usage: Notification preferences and privacy settings.
- Analytics Data: Usage patterns and events collected via Firebase Analytics and Mixpanel (see Section 4).
1.9 Contact Information (Optional)
If you grant permission, the App may access your device contacts (email addresses only) to help you find friends already using Mena AI. Your full contact list is not stored on our servers.
1.10 Information We Do NOT Collect
- Payment or billing information (the App does not currently process payments)
- Precise GPS location data
- SMS, text message, or call log content
- Browsing history outside the App
2. How We Use Your Information
We use the information we collect to:
- Provide and Maintain the App: Create and manage your account, deliver personalised nutrition plans, track your progress, and enable social features.
- AI-Powered Features: Analyse meal photos and text descriptions to estimate nutritional content, provide personalised meal recommendations, generate daily insights and progress summaries, and power the AI chat assistant.
- Health Tracking: Integrate with Google Fit, Health Connect, or Apple HealthKit to display activity data alongside nutrition tracking.
- Communication: Send push notifications (meal reminders, check-in reminders, social updates, partnership notifications), and respond to your enquiries.
- Social Features: Enable groups, partnerships, activity feeds, challenges, and community interactions.
- Analytics and Improvement: Understand how users interact with the App to improve features, fix issues, and enhance user experience.
- Safety and Security: Detect and prevent fraud, abuse, or security incidents.
3. How We Share Your Information
We do not sell your personal data. We may share information with the following parties:
3.1 Service Providers
- Supabase: Database hosting, authentication, file storage, and serverless functions (based in the EU/US).
- OpenAI: Meal photo and text analysis, AI chat responses, and meal recommendations. Meal images and text descriptions are sent to OpenAI's API for processing.
- Firebase (Google): Analytics, crash reporting (Crashlytics), and push notification delivery.
- Mixpanel: Analytics and event tracking.
- Apple / Google: Authentication via Sign-In with Apple and Google Sign-In.
3.2 Other Users
If you use social features, certain information may be visible to other users based on your privacy settings:
- Profile information (name, username, avatar, bio) if your profile is set to public.
- Activity feed posts, meal photos (if sharing is enabled), streak counts, and achievements (based on your privacy settings).
- Group membership and partnership connections.
3.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
3.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction.
4. Analytics and Tracking
We use the following analytics services:
- Firebase Analytics: Tracks app usage events and user properties to help us understand how the App is used. Data is processed by Google.
- Firebase Crashlytics: Collects crash reports and diagnostic data to help us identify and fix bugs.
- Mixpanel: Tracks user interactions and events for product analytics.
You can limit analytics data collection by adjusting your device settings or contacting us.
5. Data Storage and Security
5.1 Storage
Your data is stored on servers managed by Supabase. Meal photos and profile images are stored in Supabase Storage. AI interactions are processed via OpenAI's API.
5.2 Security Measures
We implement appropriate technical and organisational measures to protect your data, including:
- OAuth 2.0 authentication for Google and Apple Sign-In.
- Encrypted local storage on your device for sensitive data.
- Row-Level Security (RLS) policies on our database to ensure users can only access their own data.
- Secure HTTPS connections for all data transfers.
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Your Privacy Controls
The App provides granular privacy settings, allowing you to control:
- Public Profile: Whether your profile is visible to other users.
- Discoverability: Whether you appear in search results.
- Activity Feed: Whether your activity posts appear in the feed.
- Streak Sharing: Whether your streak is displayed on your profile.
- Achievement Sharing: Whether badges and milestones are auto-posted to the feed.
- Meal Photo Sharing: Whether meal photos are visible in the activity feed.
You can adjust these settings at any time within the App.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
7.1 Under UK GDPR and Data Protection Act 2018
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing of your data for certain purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
7.2 Under EU GDPR
If you are located in the European Economic Area, you have the same rights as listed above under UK GDPR. You also have the right to lodge a complaint with your local data protection authority.
7.3 Under CCPA (California, USA)
If you are a California resident, you have the right to:
- Know what personal information is collected, used, and shared.
- Request deletion of your personal information.
- Opt out of the sale of personal information (we do not sell your data).
- Non-discrimination for exercising your privacy rights.
To exercise any of these rights, please contact us at team@trymena.ai.
8. Account Deletion
You can delete your account at any time through the App:
- Go to Settings > Delete Account.
- Confirm deletion by typing "DELETE".
- Provide a reason for deletion (optional feedback).
Account deletion permanently removes all your data from our servers, including your profile, meal logs, chat history, social connections, and any uploaded images. This action is irreversible.
9. Data Retention
- We retain your personal data for as long as your account is active or as needed to provide you with the App's services.
- If you delete your account, all associated data is permanently deleted.
- Anonymised and aggregated data that cannot identify you may be retained for analytical purposes.
- We may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention).
10. Children's Privacy
The App is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at team@trymena.ai.
11. Third-Party Links
The App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.
12. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those in your jurisdiction. We ensure appropriate safeguards are in place for international transfers in accordance with applicable data protection laws.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the "Last Updated" date at the top. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Knowledge Collective Ltd
167-169 Great Portland Street, 5th Floor
London W1W 5PF
United Kingdom
Email: team@trymena.ai
15. Legal Basis for Processing (UK/EU)
We process your personal data on the following legal bases:
| Legal Basis | Examples |
|---|---|
| Consent | Health data collection, contact access, push notifications, analytics |
| Contract Performance | Account creation, meal tracking, AI features, nutrition plans |
| Legitimate Interests | App improvement, security, fraud prevention, analytics |
| Legal Obligation | Compliance with applicable laws and regulations |
You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.