Mealkit

Privacy Policy

Effective date: July 27, 2026  ·  Version 2.0

This Privacy Policy explains what information Mealkit collects, how we use it, who we share it with, how long we keep it, and the choices and rights you have. Mealkit is operated by Dina Shadi, doing business as Mealkit ("Mealkit," "we," "us," or "our"). It applies to the Mealkit mobile application and this website. It is part of, and incorporated into, our Terms of Service.

The short version

Contents

1. Scope 2. Information we collect 3. What we do not collect 4. Sensitive information and consent 5. Consumer health data 6. How we use information 7. AI processing 8. How we share information 9. Legal bases (EEA/UK) 10. California disclosures 11. Your rights and choices 12. Data retention 13. Security and data breaches 14. Children and minors 15. International transfers 16. Changes to this policy 17. Contact

1. Scope

This policy covers information we collect through the Mealkit app and this website. It does not cover the practices of Apple or of any third party whose own privacy policy governs their handling of your data, as described in Section 8.

How you accept this policy. Mealkit requires a subscription. Before you start a free trial or subscribe, we show you a screen linking to this policy and to our Terms of Service, stating that starting a trial or subscribing means you agree to them. Tapping that button is your acceptance of this policy and, where we rely on consent, your consent to the processing described here, including the processing of the dietary information covered by Sections 4 and 5. We record the version of this policy in effect at that moment. You can withdraw consent at any time as described in Section 11.

2. Information we collect

2.1 Photos of your kitchen, fridge, counter, or pantry

Mealkit's primary feature lets you photograph the inside of your fridge, your counter, or your pantry so the App can identify food items. When you do this, the image is transmitted to our processing providers, analyzed by automated image recognition and AI to extract a list of likely food items, and then discarded. We do not store the image, we do not build a photo library, and we do not associate the image with you after processing. Only the extracted text list of food items is retained.

Because these photos are taken inside your home, they may incidentally capture things beyond food, including people, faces, children, personal documents, medication stored in a fridge, alcohol, and the interior of your home. We do not want that information, we do not intentionally extract it, and we discard the image after food items are extracted. Please avoid putting people or anything sensitive in frame. We do not perform facial recognition and we do not collect biometric identifiers.

2.2 Receipt images

If you scan a grocery receipt, the image is processed by text recognition and AI to extract food and product lines, and is then discarded on the same basis as Section 2.1. A receipt can contain non-food information such as the store, date, time, payment method, partial card digits, loyalty number, and non-food purchases. We extract food and grocery items only, and we do not retain the other information or the image.

2.3 Barcode scans

When you scan a barcode, we send the product code to a product lookup service to retrieve the product name and description. We retain the resulting item, not the camera image.

2.4 Ingredients and content you enter

Ingredients you type, edits you make to a recognized list, saved and favorited recipes, and notes. This text is sent to our AI processing provider, Anthropic, to generate recipes, and is retained so your kitchen and saved recipes persist between sessions.

2.5 Dietary preferences and restrictions

If you tell the App about dietary preferences or restrictions, including allergies, intolerances, ingredients to avoid, dietary styles such as vegetarian, vegan, halal, kosher, gluten-free, or dairy-free, or filters such as high-protein, we collect and retain those selections and use them to choose which recipes to show you. Depending on what you enter and where you live, this information may qualify as sensitive personal information, special category data, or consumer health data. See Sections 4 and 5.

These fields are taste and convenience preferences and are not a safety mechanism. See Section 8 of our Terms of Service.

2.6 Account information (optional)

Creating an account is optional and is not required to use the App. If you choose to sign in with Apple, we receive a unique Apple identifier and, depending on your Apple ID sharing choices, your name and an email address, which may be Apple's private relay address. We use this to sync your saved recipes, kitchen, and preferences across your devices.

If you do not sign in, we still generate and store an anonymous device or installation identifier so your data persists between sessions. That identifier is personal information under some laws, and you can have it and its associated data deleted under Section 11.

2.7 Usage and diagnostics

We use PostHog to understand how the App is used. This includes in-app events, screen views, feature usage, session information, crash and error reports, and general device metadata such as device model, operating system version, app version, language, and coarse region. We do not use this to build advertising profiles and we do not track you across other companies' apps or websites. On iOS, we will not engage in tracking as defined by Apple without your permission through the App Tracking Transparency prompt, which you may decline at any time in your device Settings.

2.8 Subscription information

Purchases are processed by Apple and managed for us by RevenueCat. We receive subscription and entitlement status, such as which plan you are on and whether a trial or subscription is active, plus an anonymous subscriber identifier. We never receive or store your full payment card details, which are handled entirely by Apple.

2.9 Support and correspondence

If you email us, we keep your message, your email address, and anything you choose to include, so we can respond and keep a record of the request.

3. What we do not collect

4. Sensitive information and your consent

Some of what you may choose to enter, particularly allergies, intolerances, medically motivated dietary restrictions, and religious dietary styles, can reveal information about your health or your religious beliefs. In some places that is treated as sensitive personal information or special category data.

We process this information only with your explicit consent, which you give when you accept this policy and each time you choose to enter such a detail. We use it for one purpose only: to select and filter which recipes we show you. We do not use it for advertising, we do not sell it, we do not use it for profiling that produces legal or similarly significant effects, and we do not share it except with the providers in Section 8 who are needed to operate the App.

You never have to enter it. The App works without any dietary information. You can withdraw consent at any time by removing the entry or deleting your data under Section 11.

5. Consumer health data

Allergy and health-motivated dietary information may qualify as "consumer health data" under laws including Washington's My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act. Where it does, we commit to the following, and this section serves as our consumer health data privacy notice.

6. How we use information

We do not use your personal information for advertising, and we do not make decisions about you by solely automated means that produce legal or similarly significant effects.

7. AI processing

To generate recipes and read images, we send your ingredient text and your scanned images to our third-party AI processing provider, Anthropic. Anthropic acts as our processor and processes the data only on our instructions to return a result to you.

We have configured our AI processing so that your inputs are not used to train the provider's models. The provider may retain inputs briefly for its own security and abuse-monitoring purposes before deleting them, and does not use them for any other purpose.

Please do not enter medical information, government identifiers, financial details, or anything else sensitive into the App. It is not needed to generate a recipe.

8. How we share information

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as follows.

8.1 Service providers

ProviderWhat it processesWhy
AnthropicIngredient text, kitchen and receipt imagesRecognize food and generate recipes
SupabaseAccount data, saved kitchen, recipes, preferencesDatabase, authentication, hosting
RevenueCatSubscription and entitlement statusManage subscriptions and access
ApplePayment, billing, optional Sign in with AppleSell and manage the subscription
PostHogUsage events, crashes, device metadataAnalytics and diagnostics
Product / barcode databaseScanned barcode numbersLook up product names

Each is bound to use the data only to provide their service to us.

8.2 Legal and safety disclosures

We may access, preserve, and disclose information if we believe in good faith it is reasonably necessary to: comply with a law, regulation, subpoena, court order, warrant, or other valid legal process; respond to a lawful government request; enforce our Terms of Service or investigate a potential violation; detect, prevent, or address fraud, security, or technical issues; establish, exercise, or defend a legal claim; or protect the rights, property, or safety of us, our users, or the public. Where we are legally permitted to do so, we will make reasonable efforts to notify you first.

8.3 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your information may be transferred as part of that transaction. We will require the recipient to honor this policy for the information transferred, or give you notice and a choice before your information becomes subject to a materially different policy.

8.4 With your direction

We share information with anyone else only when you ask us to or give us permission.

9. Legal bases for processing (EEA and UK)

PurposeLegal basis
Providing the App, generating recipes, managing your account and subscriptionPerformance of a contract (Art. 6(1)(b))
Dietary, allergy, and religious dietary informationExplicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Analytics, diagnostics, and optional trackingConsent (Art. 6(1)(a))
Security, abuse prevention, service improvement, defending claimsLegitimate interests (Art. 6(1)(f)), balanced against your rights
Retention and disclosure required by lawLegal obligation (Art. 6(1)(c))

Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. The controller is the entity named at the top of this policy.

10. California disclosures

This section is for California residents and describes the categories of personal information we have collected in the preceding 12 months, along with sources, purposes, and recipients. It also serves as our notice at collection.

Category (CCPA)ExamplesSourcePurposeDisclosed to
IdentifiersApple user ID, account ID, anonymous device identifier, emailYou, AppleCreate and operate your account, persist your dataHosting, auth, analytics, subscription providers
Customer recordsName or relay email, if you share itYou, AppleAccount and supportHosting provider
Commercial informationSubscription plan, trial and entitlement status, purchase historyYou, Apple, RevenueCatManage the subscriptionApple, RevenueCat
Internet or network activityApp events, screen views, feature usage, crash logsAutomaticAnalytics, diagnostics, securityAnalytics provider
Visual informationPhotos of fridge, counter, pantry, receipts (transient, then deleted)YouIdentify food itemsAnthropic
Sensitive personal informationAllergies, intolerances, health-motivated or religious dietary restrictionsYouSelect and filter recipes onlyAnthropic, hosting provider
InferencesLikely food preferences derived from your saved recipesDerivedImprove suggestionsHosting provider

We do not sell and do not share (for cross-context behavioral advertising) any category of personal information, including that of anyone we know to be under 16. We use and disclose sensitive personal information only for purposes permitted under the CPRA without a right to limit, namely performing the service you requested; because that is the only way we use it, no action is required to limit it, though you may contact us to confirm. We retain each category as described in Section 12. We do not use your personal information for automated decision-making with legal or similarly significant effects.

11. Your rights and choices

11.1 Deleting your data

If you have an account: Settings → Delete Account in the App.

If you never signed in: you still have a deletion right. Delete the App's data from Settings in the App, or email us at [email protected] with your anonymous identifier, which is shown in the App under Settings, and we will delete the records associated with it.

See the Delete Account page for exactly what is removed and when.

11.2 Rights available to everyone

11.3 Regional rights

California (CCPA/CPRA): the rights to know, access, delete, correct, opt out of sale or sharing (we do neither), limit the use of sensitive personal information (see Section 10), and non-discrimination. You may use an authorized agent with proof of authorization.

Washington, Nevada, Connecticut and other consumer health data laws: the rights in Section 5, including the right to a list of third parties with whom health data was shared, and the right to withdraw consent.

Other US states with comprehensive privacy laws, including Virginia, Colorado, Utah, Texas, Oregon, Montana, and others: rights of access, correction, deletion, portability, opt-out of targeted advertising, sale, and profiling (we do none of these), and the right to appeal a denied request by replying to our decision.

EEA, UK, and Switzerland (GDPR): rights of access, rectification, erasure, restriction, objection, and portability, the right to withdraw consent, and the right to lodge a complaint with your local supervisory authority or the UK ICO.

11.4 Opt-out preference signals

Where required, we treat a recognized opt-out preference signal such as Global Privacy Control as a valid request to opt out of the sale or sharing of personal information. We do neither, but we honor the signal.

11.5 How to make a request

Email [email protected] with the subject line "Privacy Request." We will verify your request, which for account holders normally means confirming control of the email or account, and respond within the time required by applicable law, generally 45 days in the US and one month in the EEA and UK, with an extension where permitted. There is no charge unless a request is manifestly unfounded or excessive.

12. Data retention

DataHow long we keep it
Photos of fridge, counter, pantry, receiptsNot retained. Deleted immediately after food items are extracted.
Extracted and entered ingredients, saved recipes, preferencesWhile your account or anonymous profile is active
Dietary and allergy preferencesUntil you remove them or delete your data
Account and authentication recordsWhile your account is active
Analytics and diagnostic eventsUp to 12 months, then deleted or aggregated so they no longer identify you
Subscription and transaction recordsAs required for support, tax, accounting, and legal purposes, typically up to 7 years
Support emailsUp to 24 months after the request is closed

After you delete. We remove your data from our active production systems within 30 days. Copies may persist in encrypted backups for up to 90 days before they are overwritten on our normal backup rotation, and we do not restore deleted data from backups except as part of a full disaster recovery. We may retain information for longer where required by law, or to resolve a dispute, prevent fraud or abuse, or enforce our agreements, and in that case we retain only what is necessary for that purpose.

13. Security and data breaches

We use industry-standard measures appropriate to the size of our operation, including encryption in transit (TLS), encryption at rest through our infrastructure provider, authentication and row-level access controls so you can only reach your own data, restricted administrative access, and reliance on established providers for hosting, authentication, and payments. We never handle your payment card details.

No system is completely secure. We cannot guarantee absolute security, and you provide information at your own risk. You are responsible for keeping your device and your Apple ID secure.

Breach handling. If a breach affects your personal information, we will investigate, contain it, and notify affected users and the relevant supervisory authorities as and when required by applicable law, including within 72 hours of becoming aware where the GDPR applies.

14. Children and minors

Mealkit is intended for users aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has given us information, email [email protected] and we will delete it promptly.

If you are between 13 and 17, you may use Mealkit only with the involvement and permission of a parent or legal guardian, who should review this policy with you and who consents to your use of the App and to our processing of your information, including the dietary information described in Sections 4 and 5. Where we would knowingly process the personal data of a user under 16 in the EEA or UK, we rely on parental or guardian consent as the legal basis to the extent required by law.

We do not knowingly sell or share the personal information of anyone under 16, and we do not use minors' information for targeted or behavioral advertising.

15. International transfers

We operate from the United States. Your information is processed in the United States and in other countries where our service providers operate, which may have data protection laws different from those in your country. Where required for transfers out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, together with additional measures where necessary. You may request a copy of the relevant safeguards by emailing us.

16. Changes to this policy

We may update this policy from time to time. When we do, we will revise the effective date and version at the top. For material changes we will give you notice in the App or by email before they take effect, and where the change affects our use of sensitive or consumer health data, or where applicable law requires it, we will obtain your consent before applying it to information we already hold.

17. Contact

Questions, privacy requests, or complaints: [email protected].

If you are in the EEA or the UK and are not satisfied with our response, you may lodge a complaint with your local data protection supervisory authority or the UK Information Commissioner's Office.