Privacy Policy

    Last updated: 4 April 2026

    CraveShift (“we”, “us”, or “our”) is operated by the CraveShift team at University College Cork, Ireland. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CraveShift mobile application and website at craveshift.org.

    We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Irish data protection law.

    1. Data We Collect

    Account information

    When you create a CraveShift account, we collect your email address and any profile information you voluntarily provide (such as a display name).

    Usage data

    We collect data about how you interact with the app, including features used, session duration, craving logs, and Smart Pairing selections. This data is used to improve the app and personalise your experience.

    Food scan data

    When you scan a food item, we process the image or barcode to retrieve nutritional and ingredient information. Scan data may be stored to power features such as your Craving History and Food Freedom Score.

    Device and technical data

    We may collect device identifiers, operating system version, app version, and crash reports to maintain app stability and security.

    Website analytics

    Our website uses privacy-respecting analytics to understand aggregate traffic patterns (pages visited, referral sources). We do not use cookies for advertising or cross-site tracking.

    2. How We Use Your Data

    • To provide, maintain, and improve the CraveShift app and website
    • To personalise your craving management experience
    • To send transactional emails (e.g. account verification, password reset)
    • To communicate product updates if you have opted in
    • To analyse aggregate usage patterns and improve our science-backed features
    • To comply with legal obligations

    We do not sell your personal data to third parties.

    3. Legal Basis for Processing (GDPR)

    We process your personal data under the following legal bases:

    • Contract performance — processing necessary to provide the CraveShift service you have signed up for.
    • Legitimate interests — improving our app, maintaining security, and preventing fraud.
    • Consent — for optional communications such as marketing emails; you may withdraw consent at any time.
    • Legal obligation — where required by applicable law.

    4. Data Sharing

    We share your data only with trusted third-party service providers that help us operate the app (such as cloud infrastructure, analytics, and customer support tools). These providers are contractually required to protect your data and may not use it for their own purposes.

    We may disclose your data if required to do so by law or in response to valid legal processes.

    5. Data Retention

    We retain your personal data for as long as your account is active or as necessary to provide our services. You may request deletion of your account and associated data at any time (see Section 7).

    6. Data Security

    We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. All data is transmitted over HTTPS. We review our security practices regularly.

    7. Your Rights Under GDPR

    If you are located in the European Economic Area, you have the following rights:

    • Right of access — request a copy of the personal data we hold about you.
    • Right to rectification — request correction of inaccurate data.
    • Right to erasure — request deletion of your data (“right to be forgotten”).
    • Right to restriction — request that we limit how we process your data.
    • Right to data portability — receive your data in a structured, machine-readable format.
    • Right to object — object to processing based on legitimate interests.
    • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

    To exercise any of these rights, contact us at craveshiftsupport.netlify.app. We will respond within 30 days.

    You also have the right to lodge a complaint with the Data Protection Commission of Ireland if you believe your data has been processed unlawfully.

    8. Cookies

    The CraveShift website uses only essential cookies necessary for the site to function. We do not use advertising cookies or third-party tracking cookies. Analytics, where used, are privacy-respecting and cookieless or use first-party data only.

    9. Children’s Privacy

    CraveShift is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

    10. Changes to This Policy

    We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

    11. Contact Us

    For any questions about this Privacy Policy or your personal data, please contact us via our support page.

    CraveShift
    University College Cork, Ireland
    craveshift.org