Privacy Policy
Last updated September 30, 2026
This policy explains how RegimePlan handles personal data: what we collect, why, where it's kept, who else handles it, and the rights you have over it. It covers the RegimePlan website, the dashboard that nutrition practices use, and the client app their clients use.
1. Who we are
RegimePlan is operated by Youakeem Studio, a sole proprietorship (enskild firma) based in Sweden ("we", "us"). For anything in this policy, email business@youakeem.com.
2. Our role and your practice's
RegimePlan is used by nutrition practices to work with their clients, so personal data reaches us in two ways:
- For practice staff accounts, billing and our website, we decide how the data is used, so we are its controller.
- When a practice uses RegimePlan with its clients, the practice decides what to collect and why. The practice is the controller, and we process the data on its behalf as its processor, under the data processing terms in our Terms of Service.
If you are a client of a practice, your practice is the first place to go with questions or requests about your data. We help practices answer them, and you can also write to us.
3. What we collect
About practice staff
- Account details: name, email address, phone number (verified with a one-time code), an optional profile photo, and your password, which we store only as a hash.
- Practice details: the practice's name, web address, logo and colours, and the payment methods you show your clients, such as a wallet number or an IBAN.
- Your WhatsApp connection, if you connect one: the number and the WhatsApp account identifiers.
- What you create: meal plans, dishes, templates, notes about clients, and your conversations with Plan Copilot.
- Billing: your practice's offering and subscription periods, your credit balance and its history, and your payments. Card payments are made on Dodo Payments' checkout, so we never see or store card details.
- Instapay payments: the receipt you upload, and what our own servers read from it with text recognition: the amount, the time, the transfer note, and the payer's name and Instapay address as the receipt shows them. We also receive the bank's notice of each transfer to our account, with its amount, time and reference and the payer's name as the bank shows it, and use it to confirm your payment. None of this is sent to an AI provider.
About a practice's clients
We hold this on behalf of the practice:
- Account details: name, email address, phone number (verified with a one-time code), preferred language, and a password stored only as a hash.
- The intake: date of birth, sex, height, weight, body fat estimate, target weight, activity, goals, food preferences, allergies and intolerances, and health conditions such as diabetes, pregnancy or a history of eating disorders. It also covers eating habits and daily routine, approaches tried before (which can include weight-loss medication), and notes. From these, RegimePlan calculates energy needs and macro targets.
- Meal plans the practice publishes, and meal logs: what was eaten or skipped, descriptions, meal photos, scanned barcodes and nutrition estimates.
- Progress check-ins: weight, body measurements, notes and progress photos.
- Files the client uploads, such as lab results, other documents and payment proofs, and the packages the client buys from the practice with their payment status.
- The practice's own notes about the client.
- WhatsApp messages between the client and the practice, with their attachments and the record of the client's consent (when it was given or withdrawn, the notice shown, and who recorded a withdrawal), if the practice connects WhatsApp and the client agreed to it.
Technical data
- For each signed-in session: the IP address, the browser and device type, and when the session expires.
- Logs and performance data: which pages and API addresses were requested, when, how long they took and whether they worked, including the IP address and browser type. We don't log the content of requests.
- A record of each AI feature use: the feature, the AI model, its cost and its result. We don't store the instructions and data sent to the AI model, but we keep Plan Copilot conversations so the practice can come back to them.
4. Why we use it, and our legal bases
For the data we control, the legal bases below come from the EU General Data Protection Regulation (GDPR):
- Providing RegimePlan to your practice and taking payment for your offering and for credit: the performance of our contract with you (Article 6(1)(b)).
- Keeping RegimePlan secure and working, which covers verifying phone numbers, preventing abuse, and finding and fixing errors: our legitimate interest in running a safe and reliable service (Article 6(1)(f)).
- Sending you service emails, such as password resets and notices about your account or these policies: our contract with you, and our legitimate interest in keeping you informed.
- Keeping accounting records: our legal obligations (Article 6(1)(c)).
For client data, the practice decides the purposes and needs its own legal basis. Health data is a special category of personal data, so a practice usually needs the client's explicit consent to process it. We use client data only to provide RegimePlan to the practice.
We don't sell personal data, and we don't use it for advertising or to train AI models.
5. AI features
Some features send data to AI models to produce a result. The requests go through OpenRouter, which passes them to models run by Google and OpenAI. Each feature sends only what it needs:
- Plan Copilot receives the client's name, age, sex, height, weight, goals, activity, allergies and intolerances, food preferences, health conditions, eating habits and routine, the client's notes, the coach notes the practice chose to share with Plan Copilot, recent weigh-ins, the client's current package, the meal plan and the conversation. When it searches the web, the search query it writes goes to a search provider.
- Dictation sends the recording to be turned into text. The recording is not stored.
- Meal option suggestions receive the meal plan and the client's allergies, intolerances and food preferences.
- Meal estimates in the client app receive the meal photo, the description and the client's answers, or a photo of a food label.
- Dish import, ingredient details and dish photos receive the practice's recipes and catalog, with no client data.
Lab results, documents, progress photos and payment receipts are never sent to an AI model. AI results are suggestions, and no decision with legal or similarly significant effects is made about anyone automatically.
The nutrition values read from a food label are shared with every practice, so a product only needs to be read once. The label photo itself is kept only so we can check a reading, and it's never shown to other practices or clients.
6. Who we share data with
We use these service providers to run RegimePlan. They process data for us under contracts that limit how they can use it:
- Neon: our database, in Frankfurt, Germany.
- Hetzner: the servers that run our API and our dish and ingredient search, in Nuremberg, Germany. The search holds catalog data only, never client data.
- Cloudflare: file storage, our domain names, and an automated check against bots during phone verification.
- Vercel: hosting for the website, the dashboard and the client app.
- Axiom: logs and performance data.
- Resend: emails such as invitations, password resets and notices that a meal plan was published.
- Akedly: phone verification codes. It receives the phone number and the IP address of the device asking for the code.
- OpenRouter, and through it Google, OpenAI and a web search provider: the AI features described in section 5.
- Meta: WhatsApp messages between a practice and its clients, when the practice connects its WhatsApp number.
Two services handle data under their own privacy policies rather than on our behalf:
- Dodo Payments sells credit paid by card as the merchant of record. It receives the buyer's name, email address and payment details, and processes the payment as the seller. Instapay payments don't go through Dodo.
- Open Food Facts, an open food database: when a client scans a barcode, the client app looks the product up there directly, so Open Food Facts receives the barcode and the phone's IP address. We send it nothing else.
To price credit in Egyptian pounds, our servers get the day's exchange rate from Open Exchange Rates. We send it no personal data.
We may also disclose data when the law requires it, or to protect the rights and safety of people using RegimePlan. If RegimePlan is transferred to a new owner, the data goes with it under this policy, and we'll tell you before that happens.
7. Where the data is stored
Our database and API servers are in Germany. Some of our providers are based in, or process data in, countries outside the EU and EEA, including the United States and Egypt. When data goes to one of them, the transfer relies on an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework, for providers certified under it) or on the Commission's standard contractual clauses.
8. How long we keep it
- Account and practice data is kept while the account is open. When a practice asks us to close its account, we delete the practice's data and its clients' data within one month, apart from the records the law requires us to keep.
- When a practice asks us to delete one client's data, we do so within one month.
- Records of payments, for offerings and for credit, are kept as long as accounting law requires, currently seven years in Sweden.
- A bank notice of an incoming Instapay transfer that no payment matches is deleted after 30 days.
- WhatsApp messages and their attachments are deleted automatically after 365 days.
- A file deleted or replaced in RegimePlan is removed from storage. Uploads that were never attached to anything are removed automatically, and imported PDFs once the import is finished or discarded.
- Staff sessions expire after 7 days. Client sessions last up to 90 days and renew while the client keeps using the app.
- Logs are kept for a limited time and deleted automatically.
- Deleted data can remain in our backups for up to 30 days before the backups are overwritten.
9. Security
- All traffic to and from RegimePlan is encrypted (HTTPS), and our providers encrypt stored data.
- On top of that, we encrypt progress photos, documents and payment proofs with a key specific to each client, and the Instapay receipts practices upload, WhatsApp attachments and WhatsApp connection credentials with separate keys. Other data, including meal photos, relies on our providers' encryption.
- Passwords are stored only as hashes.
- A practice's data can be seen by the staff of that practice. Clients see their own data in the client app.
- We don't look at a practice's data in the normal course of running RegimePlan. We may access an account when you ask us for help, to investigate a security issue or a fault, or when the law requires it. When we sign in as a user to do that, the session is recorded.
10. Your rights
Under the GDPR, you can ask us to:
- give you a copy of your personal data;
- correct data that's wrong;
- delete your data;
- restrict or object to how we use it;
- send your data to you, or to another service, in a machine-readable format.
Where we rely on your consent, you can withdraw it at any time. A client can turn off WhatsApp messages from their practice at any time in the Profile tab of the practice's app, ask their practice to stop them, or write to us. Only the client can turn them back on, in the app.
To use these rights, email business@youakeem.com. We answer within one month. If you're a client of a practice, we'll pass your request to the practice and help it answer, because it decides about your data.
You can also complain to a data protection authority: in Sweden, the Swedish Authority for Privacy Protection (imy.se), or the authority where you live or work. If you're in Egypt, Law No. 151 of 2020 on the Protection of Personal Data also gives you rights over your data, and you can use them by writing to us.
11. Cookies and storage on your device
RegimePlan uses only cookies it needs to work: one that keeps you signed in, one that remembers your language, and a few that remember a choice you made, such as keeping the dashboard sidebar open. We don't use analytics or advertising cookies, so we don't show a cookie banner.
- The client app keeps a copy of the client's plan, logs and photos on the phone, so it works without a connection. The copy is deleted when the client signs out.
- The dashboard keeps a copy of your Plan Copilot conversations in the browser, and deletes it when you sign out.
- The client app uses the camera only when you take a meal photo or scan a barcode. The dashboard uses the microphone only when you dictate to Plan Copilot.
12. Children
Staff accounts are for adults. A practice can accept clients from the age of 13. For a client under 18, the practice must have a parent's or guardian's consent where the law requires it.
13. Changes to this policy
When we change this policy, we update the date at the top. If a change affects how we use your data in an important way, we'll tell you by email or in RegimePlan before it applies.
14. Contact
Youakeem Studio, Sweden: business@youakeem.com