nativelabs.lt
🥗
Mito

Privacy Policy

Last updated: 2026-05-27

Your privacy matters to us. This policy explains exactly what data Mito collects, why we collect it, and how we protect it. We comply with the EU General Data Protection Regulation (GDPR) and Lithuanian data protection law. Questions? Contact us at mito@nativelabs.lt.

1. Data Controller

The data controller responsible for processing your personal data is NATIVELABS, MB, company code 307599139, registered address Vilniaus g. 110A-28, PabradÄ—, LT-18178 Ĺ venÄŤioniĹł r. ('Company', 'we', 'us').

Contact: mito@nativelabs.lt

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Mito mobile application ('App'). It is governed by the General Data Protection Regulation (GDPR) and the Law on Legal Protection of Personal Data of the Republic of Lithuania.

2. Data We Collect

Account data: email address, name, and authentication tokens collected via Apple Sign In or Google Sign In.

Health & body data: age, gender, height, weight, target weight, activity level, dietary preferences, food allergies and dislikes. This data is considered sensitive (special category) under GDPR and is collected solely to generate personalized meal plans.

Usage data: app interactions, features used, subscription status, and session information.

Weight logs: historical weight entries you voluntarily record in the App.

Device data: device type, operating system version, and app version for technical support purposes.

We do not collect precise location data, contacts, photos, or any data unrelated to nutrition and meal planning.

3. Legal Basis for Processing

Your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)) — for processing health-related data such as weight, height, dietary restrictions, and body metrics.

Contractual necessity (GDPR Art. 6(1)(b)) — to provide the App's core functionality, including generating meal plans and managing your subscription.

Legitimate interests (GDPR Art. 6(1)(f)) — for improving App performance, preventing fraud, and ensuring technical security.

You may withdraw your consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4. How We Use Your Data

To generate personalized AI-powered weekly meal plans and shopping lists based on your profile.

To calculate your nutritional targets (TDEE, macros) and track your progress.

To manage your account, subscription, and billing through Apple App Store or Google Play Store.

To send push notifications (meal reminders, weekly summaries) if you have enabled them.

To improve the App's AI models and overall functionality using anonymized, aggregated data.

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

5. Third-Party Services

Supabase (supabase.com) — database and authentication infrastructure. Data is stored on EU-based servers.

RevenueCat (revenuecat.com) — subscription management. Handles purchase verification and subscription status.

Mixpanel (mixpanel.com) — anonymous product analytics. Used to understand which features are used and to fix bugs. No health data is sent.

Apple App Store / Google Play Store — payment processing. We do not store your payment card details.

Google Sign In / Apple Sign In — authentication providers used to create your account.

Third-party AI providers are covered separately in Section 6 below due to the sensitivity of the data involved.

All third-party processors are bound by data processing agreements and are GDPR-compliant where applicable.

6. AI Service Providers (OpenAI)

To generate your personalized weekly meal plans and shopping lists, we use a third-party AI service: OpenAI, L.L.C. (openai.com). This section explains exactly what is shared, why, and with whom — in line with Apple App Store Review Guidelines 5.1.1(i) and 5.1.2(i) and GDPR transparency requirements.

What data is sent to OpenAI: your goal (lose/maintain/gain weight), gender, age, height, current weight, target weight, activity level, dietary struggles, reported symptoms, food allergies and dislikes, language preference, and your computed calorie/macro targets. We do NOT send your name, email address, authentication tokens, device identifiers, payment information, weight history logs, or any other contact information.

Who receives the data: OpenAI, L.L.C., the operator of the OpenAI API. OpenAI is bound by a Data Processing Addendum (DPA) and contractual obligations of confidentiality and security. Data is transmitted over encrypted HTTPS/TLS connections.

Why we send it: the data is used solely to generate the meal plan, recipes and shopping list that you have explicitly requested. It is not used for advertising, profiling for marketing, or any unrelated purpose.

No model training: per OpenAI's API data usage policy, data submitted via the OpenAI API is not used to train or improve OpenAI's models. The data is processed only to produce the response we requested on your behalf.

Your consent: before any health or profile data is sent to OpenAI, you are shown an explicit in-app consent screen that summarises this section. You must affirmatively agree before any plan is generated. You may withdraw consent at any time by deleting your account (see Section 9). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Cross-border transfer: OpenAI is headquartered in the United States. Personal data transferred to OpenAI is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, as well as supplementary technical and organisational safeguards.

Data retention by OpenAI: API requests may be retained by OpenAI for a limited period (currently up to 30 days) for abuse and misuse monitoring, after which they are deleted (per OpenAI's API data usage policy). Generated meal plans returned to Mito are stored in our Supabase database and are deleted when you delete your account.

7. Data Retention

Your account and profile data is retained for as long as your account is active.

If you delete your account, your personal data will be permanently deleted within 30 days, except where retention is required by law (e.g., financial records retained for 10 years under Lithuanian accounting law).

Anonymized, aggregated usage data may be retained indefinitely for analytical purposes.

8. Data Security

We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), secure authentication via OAuth 2.0, and row-level security on our database.

Access to personal data is restricted to authorized personnel only.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

9. Your Rights (GDPR)

Right of access — you may request a copy of all personal data we hold about you.

Right to rectification — you may correct inaccurate or incomplete data directly in the App settings.

Right to erasure ('right to be forgotten') — you may delete your account and all associated data at any time via App Settings → Account → Delete Account.

Right to restriction — you may request that we limit how we process your data in certain circumstances.

Right to data portability — you may request your data in a machine-readable format.

Right to object — you may object to processing based on legitimate interests.

Right to withdraw consent — for health data processing, you may withdraw consent at any time.

To exercise any of these rights, contact us at mito@nativelabs.lt. We will respond within 30 days.

10. Children's Privacy

Mito is not intended for children under 14 years of age. We do not knowingly collect personal data from children under 14.

Users between 14 and 18 must have parental or guardian consent before using the App.

If we become aware that we have collected data from a child under 14 without parental consent, we will delete that data immediately.

11. Push Notifications

The App may send push notifications for meal reminders, weight logging prompts, and weekly nutrition summaries.

You can enable or disable push notifications at any time via App Settings → Notifications or your device's system settings.

We do not use push notifications for marketing or advertising purposes.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notification or email at least 14 days before taking effect.

Continued use of the App after the effective date of changes constitutes acceptance of the updated Policy.

The current version of this Policy is always available at nativelabs.lt/mito/privacy-policy.

13. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania:

State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) · L. Sapiegos g. 17, LT-10312 Vilnius · ada@ada.lt · www.ada.lt

14. Contact

For any questions or requests regarding this Privacy Policy or your personal data, please contact:

NATIVELABS, MB · Vilnius, Lithuania · mito@nativelabs.lt