1. Introduction
Meal7 ("we", "our", or "us") is a meal planning app: it helps you plan your week, keep your recipes, build a grocery list, and track nutrition. Recipes can be imported from a URL or images, generated with AI from ingredients or a dish description, or written by you. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
By using Meal7, you agree to the practices described in this policy.
2. Information We Collect
Account information. When you sign in with Google or Apple, we receive your name and email address from the provider. When you use the app as a guest, we assign an anonymous user ID tied to your device.
Usage data. We store the recipes you generate and save, your meal plans, and your coin and Premium transaction history. The ingredients or description you type are used to produce the recipe and are not stored. If you set a price for an ingredient or save how you convert its unit or name, we store that alongside your chosen currency.
Device information. We collect a device identifier to manage the new user bonus and prevent abuse.
Usage analytics. We record a fixed set of events describing how the app is used, so we can tell what features people use, where they get stuck, and what to fix or build next. These fall into three groups: opening a main screen (the app itself, meal plan, grocery list, settings, or the coins or Premium paywall); the outcome of a feature — generating, saving, or importing a recipe; estimating ingredient prices; meal plan autofill; calculating nutrition; converting a grocery item's unit; clearing the grocery list — each recording success or failure and, where relevant, how long it took; and purchases, recorded as completed or failed. Each event carries your account ID, an analytics identifier generated randomly on your device, the app version, the platform, your device's language, and Premium status at the time.
It does not include what you type. The ingredients and descriptions you enter, your recipes, and your meal plan contents are never sent to our analytics provider. When something fails we record a short error code, never the error message itself.
Purchase information. In-app purchases are processed through the Apple App Store or Google Play Store. We receive transaction identifiers to credit coins to your account and to activate Premium. For the Premium subscription we also record when the current period ends and whether it was renewed, cancelled, or refunded, so the app knows whether your access is still active.
3. How We Use Your Information
- To provide and improve the recipe generation service
- To manage your account, coins balance, and purchase history
- To unlock Premium features and keep track of whether your Premium access is still active
- To display your profile name and email within the app
- To prevent fraud and abuse of the coin system
- To fulfill in-app purchase transactions
- To understand how the app is used in aggregate — how many people return, which features are used, and where people run into problems — so we can decide what to fix and build next
We do not sell your personal information to third parties, and Meal7 shows no advertising of any kind. We do not build advertising profiles about you, and your recipes, your meal plans, and the things you type are never sent to any analytics service.
4. Third-Party Services
Meal7 uses the following third-party services:
- Supabase — database, authentication, and backend infrastructure
- Google (Gemini API) — recipe generation and import, nutrition estimation, meal plan autofill, and ingredient price estimation
- Together AI — recipe image generation
- RevenueCat — in-app purchase management
- Mixpanel — usage analytics
- Google Sign-In / Apple Sign-In — optional account authentication
Each service operates under its own privacy policy.
5. Data Shared With AI Services
Meal7 creates recipes and images using third-party AI services. We ask for your permission inside the app before anything is sent to them for the first time, and you can decline.
This is exactly what each service receives:
- Google (Gemini API) — the ingredients or dish description you type, plus your dietary restrictions, allergies, servings, available tools, time limit, and difficulty. When you import a recipe, it receives the URL or photos you import from. When you ask for a nutrition estimate, it receives the recipe name, ingredients, and servings you entered. For meal plan autofill it receives no recipe text at all: only each recipe's internal ID, its meal type, its nutrition figures, and the nutrition goals you set for the week. When you ask us to estimate ingredient prices, it receives the names and units of the ingredients you haven't priced yet, any prices you've already entered yourself (used only for scale and consistency, not copied as-is), your chosen currency, and the region you optionally type in.
- Together AI — an image description generated from your recipe. Your own typed text is not sent to Together AI.
Your name, email address, and account details are never sent to either service. Requests are made from our servers, so these providers do not receive your device identifier or IP address.
How each provider handles the data it receives is governed by its own terms: see the Gemini API terms and the Together AI privacy policy.
6. Where Your Data Is Processed
Your account, recipes, meal plans, and purchase records are stored on Supabase servers in the United States. Our usage analytics are processed by Mixpanel, also in the United States.
If you use Meal7 from the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your country. Each of these providers is certified under the EU–US Data Privacy Framework and its UK and Swiss extensions, and relies on Standard Contractual Clauses in addition.
7. Data Retention
We retain your data for as long as your account is active. Your profile, your saved recipe list, and your meal plans are kept until you delete them, and are removed when you delete your account.
Two things outlive your account:
- Recipes you generated stay in the shared recipe catalogue that all users can browse, because other people may have saved them or added them to a meal plan. The link back to you is removed, so they are no longer connected to your identity.
- Purchase records are retained for accounting and for handling refund disputes.
- Analytics events stay in our analytics system, held against the account ID and analytics identifier they were recorded with rather than against your name or email. They are what tells us whether people kept using the app over time, and deleting them retroactively would rewrite that history. If you want yours removed, ask us and we will delete them.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Delete your account and associated data from within the app (Profile → Settings → Delete Account)
- Request a copy of your data by contacting us
- Ask us to delete your analytics events in Mixpanel — they are not removed automatically when you delete your account
9. Children's Privacy
Meal7 is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Security
We use industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, and secure token-based authentication. However, no method of transmission over the internet is 100% secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at: