Privacy

Privacy Policy

Version 2026-07-26 · Effective when published

1. Controller and contact

The controller for the processing described here is:

Johanna Hoppe, operating MealWise
Baccumer Str. 19
49808 Lingen (Ems)
Germany

Email: mealwise-support@withoutcookies.dedyn.io
Telephone: +49 1567 9508182

2. Scope and status

This notice covers the MealWise website and the MealWise iOS app. The website is publicly available; the app and selected backend functions are still in pre-release or closed testing unless the App Store shows them as available. A feature described below processes data only when the user actually uses or enables it. Linked third-party websites provide their own privacy information.

3. Website processing

Hosting and security logs

Netlify, Inc. delivers and protects the website on MealWise’s behalf. In doing so, Netlify receives the IP address, request date and time, requested URL, response status, referrer where transmitted, browser and device information, and security-related request data. The purpose is to provide, secure and troubleshoot the website. The legal basis is Art. 6(1)(f) GDPR; the legitimate interests are reliable delivery, abuse prevention and IT security. Netlify deploy artifacts in the current account are retained for up to 30 days. The exact production retention of CDN, function and security logs, Netlify’s subprocessor chain and the applicable transfer safeguards remain release-verification items.

No website tracking or advertising cookies

MealWise does not use browser analytics, advertising pixels, external fonts, Netlify Analytics or Netlify Forms on this website. The website code does not set cookies or use local storage for tracking. Under the current implementation, no consent banner is needed because the site does not store or access non-essential information on the visitor’s device. If this changes, MealWise will update this notice and obtain consent where § 25 TDDDG requires it.

Waitlist

When a visitor submits the waitlist form, the email address, the fixed source label “waitlist-website” and membership of the public “MealWise Waitlist” list are sent directly from the browser to Loops, operated by Astrodon Corporation in the United States. Loops also receives ordinary request data such as the IP address and request time. MealWise uses the address only for the requested waitlist confirmation, early-access and launch messages. The legal basis is consent under Art. 6(1)(a) GDPR and, for electronic marketing, the visitor’s prior express consent under § 7(2)(2) UWG. Consent is voluntary and can be withdrawn at any time through the preference/unsubscribe link in each marketing email or by contacting MealWise; withdrawal does not affect prior lawful processing. The production Loops form must have double opt-in enabled so a new address remains pending and receives no marketing until the owner confirms it. Pending addresses must be removed under the retention rule in section 7. The double-opt-in account setting, DPA, subprocessors and transfer safeguards remain mandatory pre-launch checks.

Blog, calculators and publishing

The blog feed is loaded from a first-party Netlify Function. Public editorial articles may be supplied by Outrank to an authenticated publishing endpoint and stored in Netlify Blobs. This publishing flow is intended for public article data, not visitor or MealWise account data. Serving-size and ingredient-cost calculators run in the browser; their entries are not transmitted or retained by MealWise.

Contact

The contact page creates a draft in the visitor’s own email application. The website does not submit or store the entered name, reply address or message. If the visitor sends the email, the sender’s and MealWise’s email providers process and retain it for handling the request. The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries and otherwise Art. 6(1)(f) GDPR for support and correspondence.

External links

A request to Apple, UserJot or X occurs only after the visitor selects the respective external link. MealWise adds no account identifier, email address, prompt or recipe to these links. The destination provider then receives ordinary request data under its own notice.

4. App processing

Account and authentication

Supabase Auth processes the email address, internal user identifier, provider identity, session and security metadata for email one-time-code, Sign in with Apple and Google Sign-In. Resend delivers authentication email and retains sent-email data for 30 days under its standard service. Cloudflare Turnstile processes network and device signals when enabled for bot and abuse prevention. The legal bases are Art. 6(1)(b) GDPR for account access and Art. 6(1)(f) GDPR for authentication security and abuse prevention.

Profile, streak and reminder preferences

Default servings, country and currency are stored on the device and synchronized to the signed-in user’s protected Supabase profile. The profile can also store the optional reminder-email choice, the server-recorded time of the latest choice and the wording version. Only the current streak count is mirrored to the account; activity dates, the weekly recap archive and local notification schedule remain on the device. The legal basis for account preferences is Art. 6(1)(b) GDPR. Reminder-email consent records are processed under Art. 6(1)(a) and Art. 7(1) GDPR.

Recipe generation and AI providers

Before the first recipe request leaves the device, the app asks the user to affirmatively allow processing of the submitted request by MealWise's Supabase Edge Functions, OpenRouter and its selected inference provider. The request can include dietary or allergy information; without this permission MealWise cannot generate a recipe. The choice is stored only on the device and can be withdrawn in Settings. When a user submits a recipe request, Supabase Edge Functions transmit the request and, for refinement or regeneration, the current recipe context to OpenRouter and a selected inference provider. The response contains AI-generated recipe, price and nutrition estimates. MealWise does not intentionally insert prompts or recipe bodies into its generation-attempt tables, analytics or application logs. The request asks OpenRouter to deny data collection and to use a zero-data-retention-eligible route; the selected route and upstream provider policy must nevertheless be verified for the production release.

Local recipes, widgets and notifications

Accepted recipes, original requests, refinement history, nutrition estimates, streak details, weekly recaps, queued offline requests, widget snapshots and local reminder settings are stored on the device. Queued requests remain in memory and disappear when the app terminates. Apple device backups may include app data according to the user’s Apple settings. Home and Lock Screen widgets may display a local recipe summary; iOS controls Lock Screen visibility. Local notifications use Apple’s on-device notification system and no push token or push provider. These functions do not transmit their content to MealWise unless the user submits a generation request or enables cloud sync.

Optional Pro cloud sync

If the feature is presented in the app and an eligible Pro user explicitly enables it, authenticated Supabase functions store validated recipe copies in a Turso database hosted in AWS Ireland for cross-device access. Stored fields include recipe content, nutrition estimates, recipe identifiers, timestamps and the server-side account association required to isolate each user. Original requests and refinement history are excluded. The legal basis is Art. 6(1)(b) GDPR because this processing is required to provide the user-requested sync feature. Public activation remains conditional on completion of the retention/deletion acceptance described in section 7.

Subscriptions

Apple processes App Store purchases and payment data. RevenueCat receives an app-user identifier based on the Supabase account and processes Apple transaction and entitlement information to determine the active plan. MealWise stores only the derived plan, lifecycle timestamps and limited event identifiers needed for idempotency and reconciliation. MealWise does not receive full card details. The legal bases are Art. 6(1)(b) GDPR and, for records that must be kept by law, Art. 6(1)(c) GDPR.

Product analytics and diagnostics

MealWise configures PostHog’s US service only after the user actively allows optional pseudonymous product analytics in the app. Before that choice, the SDK is not initialized and no PostHog device identifier, lifecycle, screen, error or product event is sent. The prompt names PostHog, its purpose and exclusions, offers refusal, and Settings provides withdrawal at any time. After consent, PostHog receives a randomly generated device-level identifier and allow-listed product, reliability and error events, including feature state, categorical outcome, duration bucket, model, token counts and estimated AI cost. Session replay, autocapture, network capture, text and image capture are disabled. MealWise is designed not to add prompts, recipes, email addresses, OTPs, access tokens, purchase receipts, raw webhook bodies, an IP-address event property or Supabase user UUIDs. As with every direct internet request, PostHog nevertheless receives source network data needed to accept and secure the HTTPS connection; GeoIP enrichment is disabled by MealWise. Withdrawing stops future SDK collection and clears local identity metadata; it does not retroactively erase provider-side events, which remain subject to the provider’s retention. The legal basis is consent under Art. 6(1)(a) GDPR and, where required, § 25 TDDDG. Apple may separately provide diagnostics under the user’s device and App Store settings.

Speech input

Voice input uses Apple Speech and AVFoundation after the user grants microphone and speech-recognition permission. Recognition may occur on the device or through Apple services depending on device, locale and availability. MealWise does not intentionally retain raw audio or send it to analytics. The transcript stays in the request editor and follows the recipe-generation flow only after the user submits it. The legal basis for the submitted request is Art. 6(1)(b) GDPR.

Optional reminder emails

If a user actively enables reminder emails, MealWise sends the account email address and inactive-day count to Loops, operated by Astrodon Corporation in the United States. The setting is off by default and is not required to use MealWise. The legal basis is consent under Art. 6(1)(a) GDPR. Consent can be withdrawn in Settings or through the unsubscribe link in each reminder email; withdrawal does not affect prior lawful processing. No prompt or recipe is sent to Loops.

Feedback portal

The app and website link to the external MealWise portal on UserJot without adding account or recipe data. If opened, UserJot receives ordinary request data and processes any feedback, vote, comment or contact detail the visitor chooses to submit. Users must not submit passwords, one-time codes, access tokens, full purchase receipts or sensitive recipe/account content. UserJot’s role, hosting, retention, deletion and transfer terms remain release-verification items.

5. Recipients and international transfers

Depending on the feature used, recipients can include Netlify, Supabase, Resend, Cloudflare, OpenRouter and its selected inference provider, PostHog, RevenueCat, Turso, Loops (for a waitlist submission or opted-in reminder email), Apple, Google and UserJot. Outrank supplies public editorial content but is not intended to receive visitor or app-account data from MealWise. Several providers are established in or can process data in the United States or another country outside the EEA. Where the GDPR requires a transfer mechanism, MealWise must use an applicable adequacy decision, including the EU–US Data Privacy Framework for a certified recipient, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. A copy or description of the applicable safeguard can be requested using the contact details above. Provider DPAs, subprocessors, locations and certification status must be checked against the production accounts before public app release.

6. Required and optional data

Authentication data and a recipe request are required for account-bound recipe generation. Without them, MealWise cannot authenticate the user or produce a requested recipe. Voice input, reminder emails, feedback, analytics consent where introduced, and Pro cloud sync are optional. Declining an optional feature does not prevent basic account use.

7. Retention and deletion

  • Local app data: until the user deletes the item, clears app storage or uninstalls the app, subject to Apple backup behavior.
  • Account and profile: for the life of the account; deleted through the in-app account-deletion flow unless a limited record must be retained by law.
  • Generation-attempt metadata: 35 days. Prompts and generated recipe bodies are not intentionally stored in this table.
  • RevenueCat webhook event identifiers: 90 days. Current derived plan state remains while the account exists.
  • Deletion challenges: valid for ten minutes and normally removed by the hourly cleanup within approximately 70 minutes.
  • Cron run details: 7 days.
  • Resend authentication emails: 30 days under the standard provider service.
  • Waitlist: a pending, unconfirmed address must be deleted after 30 days. A confirmed address is kept until consent is withdrawn or, if earlier, 30 days after the waitlist/launch-email purpose ends. MealWise must verify the corresponding Loops cleanup workflow and provider backup behavior before public collection.
  • Reminder-email consent and scheduling metadata: while the account exists; removed with account deletion. Loops contact deletion and backup behavior must be verified before public activation.
  • Cloud recipes: while sync is enabled and the account is eligible; after Pro ends, read-only for 30 days and then scheduled for deletion unless Pro is restored. The automated cleanup is not yet enabled for public use and must pass acceptance before this feature is publicly activated.
  • RevenueCat customer: the account-deletion function requests deletion before deleting the Supabase account. Apple transaction records are controlled by Apple and deleting MealWise does not cancel a subscription.
  • PostHog events: subject to the production project’s configured retention. A fixed production period and consent-or-disable decision remain mandatory before public availability in Germany. Identifier-free aggregate finance and AI-cost events cannot be linked back to an account.
  • Website deploys: up to 30 days in the current Netlify account. Netlify’s CDN, function and security-log period must be confirmed before launch.
  • Public blog articles: until replaced or deleted by the operator. They are intended not to contain visitor or MealWise account data.

Backups can persist for a limited additional period. Tax and accounting records are retained only for the periods required by applicable law.

8. Automated processing

AI systems create recipe suggestions, and automated systems apply authentication, entitlement, quota, rate and abuse controls. MealWise does not use solely automated processing to make decisions that produce legal or similarly significant effects within Art. 22 GDPR. A blocked request can be retried later or raised with support.

9. Account and data deletion

The in-app flow verifies a fresh email code, requests deletion of Turso cloud recipes and the RevenueCat customer, then deletes the Supabase Auth account and cascading application records. It clears local session and widget state. A provider failure keeps the account available so deletion can be retried. Deleting the account or app does not cancel an Apple subscription; subscription management remains available through Apple. Local recipes can be deleted individually or by removing app data.

10. Rights

Subject to the statutory conditions, data subjects have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and withdrawal of consent at any time (Art. 7(3)). In particular, a user may object at any time, on grounds relating to their situation, to processing based on Art. 6(1)(f) GDPR. Direct marketing based on consent stops after withdrawal. Identity verification may be required. Requests can be sent to the controller using the contact details above.

Users may complain to any competent supervisory authority. The authority for the controller’s establishment is:

Der Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Contact and complaint information

11. Children

MealWise is not directed to children under 16 and accounts are intended for users aged 16 or older. Users below the age of legal majority need any consent of a parent or guardian required by the law applicable to them, particularly for paid subscriptions. Storefront-specific age, contract-capacity and privacy requirements must be reviewed before distribution in each territory.

12. Security

Measures include encrypted transport, authenticated backend access, row-level database controls, server-side entitlement checks, request limits, bot protection, bounded data schemas and secrets kept out of the public app and repository where appropriate. No internet service can guarantee absolute security.

13. Changes

MealWise will update this notice when providers, purposes, features, retention periods or legal requirements change. Material changes will be communicated where required. The version date above identifies the applicable text.

14. Release verification and official sources

This notice records the implemented and closed-test data flows as of the version date. Before public collection or app release, qualified legal review is still required, together with Loops double-opt-in/cleanup acceptance, the provider agreement/transfer checks, fixed production retention periods, PostHog consent-or-disable decision, cloud-deletion acceptance, App Store privacy-label reconciliation and territory review identified above. This is not a guarantee of legal compliance.

Key official sources: GDPR · § 7 UWG · § 25 TDDDG · Apple App Review Guidelines.