This Privacy Policy explains how M-Malik, operated by Mansoor Ahmed Malik ("we", "us", or "our"), collects, uses, and protects your information when you use the Thali mobile application (the "App"). We are the data controller for your personal data.
Contact: thali@m-malik.com
1. Who this applies to
This policy applies to everyone who uses Thali, and includes specific rights for users in the European Economic Area (EEA), the United Kingdom, and California.
Thali is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
2. What data we collect
| Category | Examples | Why we collect it |
|---|---|---|
| Account data | Your name and email address, and either a password (stored hashed by our auth provider — we never see it in plain text) or your Sign in with Apple / Google details (the name and email you choose to share). With Sign in with Apple we also keep a token that lets us revoke Apple sign-in when you delete your account | To create and secure your account |
| Profile / health-related data | Age, sex, height, weight, activity level, dietary goals | To calculate your calorie and macro targets |
| Food & meal data | Meals you log, dishes, portions, cooking preferences | To provide the core tracking feature |
| Profile photo (optional) | A picture you choose for your profile | To show on your profile. It is stored in our file storage and can be viewed by anyone with its direct link, so only use a photo you are comfortable sharing. You can remove it at any time |
| Launch waitlist (website, optional) | The email address you enter in “Notify me” on thali.m-malik.com | To send you one email when Thali is available. It is emailed to our team inbox and kept in a private list on our web host; it is never sold or shared, and we don’t add you to any newsletter |
| Service logs | Server request logs and error messages generated when the App talks to our backend | To keep the App working, secure, and to fix bugs |
We do not collect your precise location, contacts, or browsing history. The App contains no analytics or advertising trackers.
Cookies and local storage
In the App: Thali does not use cookies or tracking technologies. It stores a small amount of data on your device only to function: your sign-in session (stored encrypted on iOS/Android) and your app settings (such as your units preference). This on-device data is removed when you sign out or uninstall the App.
On this website: thali.m-malik.com uses Google Analytics to understand how visitors find and use the site. Analytics cookies (_ga, _ga_*) are set only if you choose “Accept all” in our cookie banner. Choosing “Essential only” means Google Analytics is never loaded and no analytics cookies are set at all. We use no advertising or cross-site tracking cookies, and we do not use website analytics to identify you. Your choice is remembered in your browser’s local storage — clear your site data to be asked again.
3. Health-related data and your explicit consent
Body metrics (weight, height) and the calorie/nutrition data you track may qualify as health data (“special category data”) under GDPR Article 9.
We only process this data on the basis of your explicit consent, which you give during onboarding. You can withdraw consent at any time by deleting your account (§9), which stops all processing of this data.
4. Third parties we share data with
Calorie and nutrition estimates are calculated by our own system from our food database. We use the following third-party “processors” who handle data on our behalf under data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, hosting | United States |
| Apple | App distribution, Sign in with Apple | United States / global |
| Expo / EAS | App builds and app updates | United States |
If you choose Sign in with Google, Google handles that sign-in under its own privacy policy and shares your name and email with us.
We do not sell your personal data and we do not share it for advertising.
5. International data transfers
Our providers are located in the United States. When your data is transferred outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with each provider’s own safeguards, to protect it.
6. Legal bases for processing (GDPR)
| Data | Legal basis |
|---|---|
| Account, food logs, app functionality | Performance of a contract (providing the App you signed up for) |
| Health-related data (weight, calorie tracking) | Explicit consent (Art. 9(2)(a)) |
| Service logs, security, fraud prevention | Legitimate interests (keeping the App secure and working) |
7. Automated decision-making
We do not make automated decisions that produce legal or similarly significant effects about you. Your calorie and macro targets are calculated from the details you enter, using a standard formula, and you can change them at any time.
8. How long we keep data
We keep your data while your account is active. If you delete your account, your personal data and profile photo are deleted promptly after your request is processed; we keep only a minimal deletion record (an anonymous identifier and date, no personal data) to prove the deletion happened, and any records we must retain by law.
Waitlist emails are kept until we send the launch email, then deleted within 30 days. Email thali@m-malik.com any time to be removed sooner.
Copies of deleted data may remain in encrypted backups for a limited period before being automatically overwritten. Backup copies are not used for any other purpose and are securely deleted in accordance with our backup retention schedule.
9. How we protect your data
- Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider.
- Your sign-in session is stored encrypted on your device (hardware-backed keystore).
- Access is restricted by row-level security so you can only ever access your own data.
- Passwords are hashed; we never store them in plain text.
- We follow the principle of least privilege for administrative access.
No system is perfectly secure. While we use industry-standard measures, we cannot guarantee absolute security. In the event of a personal data breach that risks your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR.
10. Your rights
Everyone can exercise their rights directly in the App: edit your data (Profile → Personal Info), export a full copy (Profile → Download my data), and permanently delete your account and all data (Profile → Delete account).
If you are in the EEA/UK, you also have the right to: access, rectification, erasure, restriction, data portability, objection, and to withdraw consent. You may lodge a complaint with your local supervisory authority (in the UK, the ICO at ico.org.uk).
If you are in California (CCPA/CPRA), you have the right to know, delete, correct, and to opt out of sale/sharing — note we do not sell or share personal information. We will not discriminate against you for exercising your rights.
To exercise any right, email thali@m-malik.com. We respond within 30 days (GDPR) or 45 days (CCPA).
11. Changes to this policy
We may update this policy. If we add features that use your data in new ways, we will update this policy before they go live. Material changes will be notified in-app or by email. The “Last updated” date at the top reflects the current version.
12. Contact
Questions or requests: thali@m-malik.comData controller:
M-Malik
Operated by Mansoor Ahmed Malik
Pakistan