Privacy Policy
1. Controller and contact
The controller for the processing described here is:
Johanna Hoppe, operating MealWise
Baccumer Str. 19
49808 Lingen (Ems)
Germany
Email: mealwise-support@withoutcookies.dedyn.io
Telephone: +49 1567 9508182
2. Scope and status
This notice covers the MealWise website and the MealWise iOS app. The website is publicly available; the app and selected backend functions are still in pre-release or closed testing unless the App Store shows them as available. A feature described below processes data only when the user actually uses or enables it. Linked third-party websites provide their own privacy information.
3. Website processing
Hosting and security logs
Netlify, Inc. delivers and protects the website on MealWise’s behalf. In doing so, Netlify receives the IP address, request date and time, requested URL, response status, referrer where transmitted, browser and device information, and security-related request data. The purpose is to provide, secure and troubleshoot the website. The legal basis is Art. 6(1)(f) GDPR; the legitimate interests are reliable delivery, abuse prevention and IT security. Netlify deploy artifacts in the current account are retained for up to 30 days. The exact production retention of CDN, function and security logs, Netlify’s subprocessor chain and the applicable transfer safeguards remain release-verification items.
No website tracking or advertising cookies
MealWise does not use browser analytics, advertising pixels, external fonts, Netlify Analytics or Netlify Forms on this website. The website code does not set cookies or use local storage for tracking. Under the current implementation, no consent banner is needed because the site does not store or access non-essential information on the visitor’s device. If this changes, MealWise will update this notice and obtain consent where § 25 TDDDG requires it.
Blog, calculators and publishing
MealWise editorial articles are bundled and served as first-party static website pages. Serving-size and ingredient-cost calculators run in the browser; their entries are not transmitted or retained by MealWise.
Contact
The contact page creates a draft in the visitor’s own email application. The website does not submit or store the entered name, reply address or message. If the visitor sends the email, the sender’s and MealWise’s email providers process and retain it for handling the request. The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries and otherwise Art. 6(1)(f) GDPR for support and correspondence.
External links
A request to Apple, UserJot or X occurs only after the visitor selects the respective external link. MealWise adds no account identifier, email address, prompt or recipe to these links. The destination provider then receives ordinary request data under its own notice.
4. App processing
Account and authentication
Supabase Auth processes the email address, internal user identifier, provider identity, session and security metadata for email one-time-code, Sign in with Apple and Google Sign-In. Resend delivers authentication email and retains sent-email data for 30 days under its standard service. Cloudflare Turnstile processes network and device signals when enabled for bot and abuse prevention. The legal bases are Art. 6(1)(b) GDPR for account access and Art. 6(1)(f) GDPR for authentication security and abuse prevention.
Profile, streak and reminder preferences
Default servings, country and currency are stored on the device and synchronized to the signed-in user’s protected Supabase profile. The profile can also store the optional reminder-email choice, the server-recorded time of the latest choice and the wording version. Only the current streak count is mirrored to the account; activity dates, the weekly recap archive and local notification schedule remain on the device. The legal basis for account preferences is Art. 6(1)(b) GDPR. Reminder-email consent records are processed under Art. 6(1)(a) and Art. 7(1) GDPR.
Recipe generation and AI providers
Before the first recipe request leaves the device, the app asks the user to affirmatively allow processing of the submitted request by MealWise's Supabase Edge Functions, OpenRouter and its selected inference provider. The request can include dietary or allergy information; without this permission MealWise cannot generate a recipe. The choice is stored only on the device and can be withdrawn in Settings. When a user submits a recipe request, Supabase Edge Functions transmit the request and, for refinement or regeneration, the current recipe context to OpenRouter and a selected inference provider. The response contains AI-generated recipe, price and nutrition estimates. MealWise does not intentionally insert prompts or recipe bodies into its generation-attempt tables, analytics or application logs. The request asks OpenRouter to deny data collection and to use a zero-data-retention-eligible route; the selected route and upstream provider policy must nevertheless be verified for the production release.
Local recipes, widgets and notifications
Accepted recipes, original requests, refinement history, nutrition estimates, streak details, weekly recaps, queued offline requests, widget snapshots and local reminder settings are stored on the device. Queued requests remain in memory and disappear when the app terminates. Apple device backups may include app data according to the user’s Apple settings. Home and Lock Screen widgets may display a local recipe summary; iOS controls Lock Screen visibility. Local notifications use Apple’s on-device notification system and no push token or push provider. These functions do not transmit their content to MealWise unless the user submits a generation request or enables cloud sync.
Optional Pro cloud sync
If the feature is presented in the app and an eligible Pro user explicitly enables it, authenticated Supabase functions store validated recipe copies in a Turso database hosted in AWS Ireland for cross-device access. Stored fields include recipe content, nutrition estimates, recipe identifiers, timestamps and the server-side account association required to isolate each user. Original requests and refinement history are excluded. The legal basis is Art. 6(1)(b) GDPR because this processing is required to provide the user-requested sync feature. Public activation remains conditional on completion of the retention/deletion acceptance described in section 7.
Subscriptions
Apple processes App Store purchases and payment data. RevenueCat receives an app-user identifier based on the Supabase account and processes Apple transaction and entitlement information to determine the active plan. MealWise stores only the derived plan, lifecycle timestamps and limited event identifiers needed for idempotency and reconciliation. MealWise does not receive full card details. The legal bases are Art. 6(1)(b) GDPR and, for records that must be kept by law, Art. 6(1)(c) GDPR.
Product analytics and diagnostics
MealWise configures PostHog’s US service and Aptabase’s EU service only after the user actively allows optional product analytics in the app. Before that choice, neither SDK is initialized. The prompt names both providers, offers refusal, and Settings provides withdrawal at any time. The legal basis is consent under Art. 6(1)(a) GDPR and, where required, § 25 TDDDG.
PostHog receives a randomly generated device-level identifier and allow-listed product, reliability and error events, including feature state, categorical outcome, duration bucket, model, token counts and estimated AI cost. Session replay, autocapture, network capture, text and image capture are disabled. MealWise is designed not to add prompts, recipes, email addresses, OTPs, access tokens, purchase receipts, raw webhook bodies, an IP-address event property or Supabase user UUIDs. As with every direct internet request, PostHog nevertheless receives source network data needed to accept and secure the HTTPS connection; GeoIP enrichment is disabled by MealWise.
Aptabase receives only a fixed analytics schema: app start; authentication completion outcome; plan category; recipe-generation start, success, local completion, re-edit, failure and cancellation; onboarding start, fixed screen reached, account setup complete and completion; plus paywall view, fixed page, source, plan selection, purchase start, purchase outcome and dismissal. A successful recipe-generation or re-edit event includes a whole-second duration so MealWise can calculate an aggregate average. Each Aptabase event also contains its time, a short-lived random session identifier, app version and build, operating-system name and version, locale, device model, Aptabase SDK version and whether the app was built in Debug mode. MealWise does not send an account identifier, durable device identifier, prompt, recipe, text input, email address, OTP, receipt or screen recording to Aptabase. Aptabase receives source network data needed to accept and secure its HTTPS connection.
Withdrawing consent stops future SDK collection and clears local analytics identity metadata where applicable. It does not retroactively erase provider-side events already sent, which remain subject to each provider’s configured retention. Apple may separately provide diagnostics under the user’s device and App Store settings.
Speech input
Voice input uses Apple Speech and AVFoundation after the user grants microphone and speech-recognition permission. Recognition may occur on the device or through Apple services depending on device, locale and availability. MealWise does not intentionally retain raw audio or send it to analytics. The transcript stays in the request editor and follows the recipe-generation flow only after the user submits it. The legal basis for the submitted request is Art. 6(1)(b) GDPR.
Optional reminder emails
If a user actively enables reminder emails, MealWise sends the account email address and inactive-day count to Loops, operated by Astrodon Corporation in the United States. The setting is off by default and is not required to use MealWise. The legal basis is consent under Art. 6(1)(a) GDPR. Consent can be withdrawn in Settings or through the unsubscribe link in each reminder email; withdrawal does not affect prior lawful processing. No prompt or recipe is sent to Loops.
Feedback portal
The app and website link to the external MealWise portal on UserJot without adding account or recipe data. If opened, UserJot receives ordinary request data and processes any feedback, vote, comment or contact detail the visitor chooses to submit. Users must not submit passwords, one-time codes, access tokens, full purchase receipts or sensitive recipe/account content. UserJot’s role, hosting, retention, deletion and transfer terms remain release-verification items.
5. Recipients and international transfers
Depending on the feature used, recipients can include Netlify, Supabase, Resend, Cloudflare, OpenRouter and its selected inference provider, PostHog, RevenueCat, Turso, Loops, Apple, Google and UserJot. Several providers are established in or can process data in the United States or another country outside the EEA. Where the GDPR requires a transfer mechanism, MealWise must use an applicable adequacy decision, including the EU–US Data Privacy Framework for a certified recipient, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. A copy or description of the applicable safeguard can be requested using the contact details above. Provider DPAs, subprocessors, locations and certification status must be checked against the production accounts before public app release.
6. Required and optional data
Authentication data and a recipe request are required for account-bound recipe generation. Without them, MealWise cannot authenticate the user or produce a requested recipe. Voice input, reminder emails, feedback, analytics consent where introduced, and Pro cloud sync are optional. Declining an optional feature does not prevent basic account use.
7. Retention and deletion
- Local app data: until the user deletes the item, clears app storage or uninstalls the app, subject to Apple backup behavior.
- Account and profile: for the life of the account; deleted through the in-app account-deletion flow unless a limited record must be retained by law.
- Generation-attempt metadata: 35 days. Prompts and generated recipe bodies are not intentionally stored in this table.
- RevenueCat webhook event identifiers: 90 days. Current derived plan state remains while the account exists.
- Deletion challenges: valid for ten minutes and normally removed by the hourly cleanup within approximately 70 minutes.
- Cron run details: 7 days.
- Resend authentication emails: 30 days under the standard provider service.
- Reminder-email consent and scheduling metadata: while the account exists; removed with account deletion. Loops contact deletion and backup behavior must be verified before public activation.
- Cloud recipes: while sync is enabled and the account is eligible; after Pro ends, read-only for 30 days and then scheduled for deletion unless Pro is restored. The automated cleanup is not yet enabled for public use and must pass acceptance before this feature is publicly activated.
- RevenueCat customer: the account-deletion function requests deletion before deleting the Supabase account. Apple transaction records are controlled by Apple and deleting MealWise does not cancel a subscription.
- PostHog and Aptabase events: subject to each production project’s configured retention. A fixed production period, provider deletion process and final consent review remain mandatory before public availability in Germany. Aptabase events are designed for aggregate/session funnel analysis and contain no MealWise account identifier.
- Website deploys: up to 30 days in the current Netlify account. Netlify’s CDN, function and security-log period must be confirmed before launch.
- Public blog articles: until replaced or deleted by the operator. They are intended not to contain visitor or MealWise account data.
Backups can persist for a limited additional period. Tax and accounting records are retained only for the periods required by applicable law.
8. Automated processing
AI systems create recipe suggestions, and automated systems apply authentication, entitlement, quota, rate and abuse controls. MealWise does not use solely automated processing to make decisions that produce legal or similarly significant effects within Art. 22 GDPR. A blocked request can be retried later or raised with support.
9. Account and data deletion
The in-app flow verifies a fresh email code, requests deletion of Turso cloud recipes and the RevenueCat customer, then deletes the Supabase Auth account and cascading application records. It clears local session and widget state. A provider failure keeps the account available so deletion can be retried. Deleting the account or app does not cancel an Apple subscription; subscription management remains available through Apple. Local recipes can be deleted individually or by removing app data.
10. Rights
Subject to the statutory conditions, data subjects have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and withdrawal of consent at any time (Art. 7(3)). In particular, a user may object at any time, on grounds relating to their situation, to processing based on Art. 6(1)(f) GDPR. Direct marketing based on consent stops after withdrawal. Identity verification may be required. Requests can be sent to the controller using the contact details above.
Users may complain to any competent supervisory authority. The authority for the controller’s establishment is:
Der Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Contact and complaint information
11. Children
MealWise is not directed to children under 16 and accounts are intended for users aged 16 or older. Users below the age of legal majority need any consent of a parent or guardian required by the law applicable to them, particularly for paid subscriptions. Storefront-specific age, contract-capacity and privacy requirements must be reviewed before distribution in each territory.
12. Security
Measures include encrypted transport, authenticated backend access, row-level database controls, server-side entitlement checks, request limits, bot protection, bounded data schemas and secrets kept out of the public app and repository where appropriate. No internet service can guarantee absolute security.
13. Changes
MealWise will update this notice when providers, purposes, features, retention periods or legal requirements change. Material changes will be communicated where required. The version date above identifies the applicable text.
14. Release verification and official sources
This notice records the implemented and closed-test data flows as of the version date. Before public app release, qualified legal review is still required, together with the provider agreement, subprocessor and transfer checks, fixed production retention and deletion procedures for PostHog and Aptabase, cloud-deletion acceptance, App Store privacy-label reconciliation and territory review identified above. This is not a guarantee of legal compliance.
Key official sources: GDPR · § 25 TDDDG · Apple App Review Guidelines.
For related information, see about MealWise, our plans and pricing, the Imprint, or contact MealWise.