Privacy Policy
Last updated: August 22, 2026
MealKal is designed to work on your device. This policy explains what information the app handles and why.
Information stored on your device
Your meal plans, preferences, shopping lists, and cooking history are stored locally on your device. In this version the app does not require an account, and this content is not uploaded to our servers. The one exception is the fridge photo feature described below, which only runs when you choose to use it.
Information we process
To keep the app working and to fix problems, we use PostHog for privacy-respecting analytics and crash reporting that collect anonymous, aggregated usage and diagnostic data. This data is not used to identify you.
We also use AppsFlyer, a mobile measurement partner, to understand how people discover the app and to measure aggregate usage such as installs, active users, and approximate (country- or region-level) location derived from your IP address. To do this, AppsFlyer receives device and usage signals such as a generated AppsFlyer install ID, your device's vendor identifier (IDFV), device and operating-system information, and your IP address. We use this to see which of our own marketing efforts work — it is not used to show you ads inside the app.
Subscriptions are handled by Apple, together with RevenueCat (subscription management) and Superwall (which presents subscription offers). We receive your subscription status (for example, active or expired) but not your payment details, which are managed by Apple.
Recipe, price, and image data is delivered to the app as read-only content. Downloading this content involves standard network requests that may include your device's IP address, as with any internet connection.
App Tracking Transparency (Apple devices)
On Apple devices, iOS will ask for your permission before the app can access your device's advertising identifier (IDFA) for tracking. We show this prompt once, and only after you have entered the app — never during sign-up or checkout.
If you allow it, your IDFA is shared with AppsFlyer to improve the accuracy of install attribution (matching an install to the marketing effort that led to it). If you decline, or take no action, no IDFA is collected. Either way the app works exactly the same: measurement of installs, active users, and country-level location does not depend on the IDFA. You can change this choice at any time in iOS Settings → Privacy & Security → Tracking.
Fridge photo analysis
The app includes an optional feature that lets you take a photo of your fridge or ingredients so the app can suggest what you can cook. This feature runs only when you choose to use it. When you do, the photo is sent over a secure connection to our processing backend (hosted on Supabase) and forwarded to OpenAI, which analyzes the image to identify ingredients and returns the result to the app.
The photo is used only to produce that result. It is processed on the fly and is not stored on our servers after analysis, and it is not used by OpenAI to train their models. We do not use these photos to identify you or to build a profile about you. If you never use this feature, no photo ever leaves your device.
Third-party services we use
We rely on a small number of trusted service providers to operate the app. Each processes only the limited data needed for its function, under its own privacy policy:
- Apple — App Store purchases and subscription billing. See Apple's Privacy Policy.
- RevenueCat — subscription management and status. See RevenueCat's Privacy Policy.
- Superwall — presents subscription offers and paywalls. See Superwall's Privacy Policy.
- PostHog — anonymous analytics and diagnostics. See PostHog's Privacy Policy.
- AppsFlyer — mobile measurement and marketing attribution (installs, active users, campaign attribution). See AppsFlyer's Privacy Policy.
- Supabase — hosts the backend that processes fridge photos. See Supabase's Privacy Policy.
- OpenAI — analyzes fridge photos when you use that feature. See OpenAI's Privacy Policy.
How long we keep data
We keep personal data only as long as needed for the purposes described in this policy.
- On-device content (meal plans, preferences, shopping lists, cooking history) stays on your device until you delete it or uninstall the app.
- Fridge photos are not stored on our servers — they are processed and discarded. OpenAI may retain a copy for a limited period (up to 30 days) to monitor for abuse or misuse, after which it is deleted, in line with OpenAI's policies. The photos are not used to train OpenAI's models.
- Analytics and diagnostic data are kept in aggregated or pseudonymous form for a limited period (up to 12 months) and then deleted or further anonymized.
- Measurement and attribution data processed by AppsFlyer (install and usage signals, device identifiers, IP address) is retained in pseudonymous form for a limited period in line with AppsFlyer's policies, then deleted or anonymized.
- Subscription status is retained by Apple and RevenueCat for as long as your subscription is active and for a limited period afterwards, as required to meet accounting and legal obligations.
Your rights
Depending on where you live, you have rights over your personal data, and we honor them regardless of where you live.
If you are in the EU, EEA, or the UK (GDPR), you have the right to access, correct, delete, or export ("port") your data, to object to or restrict certain processing, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.
If you are in California or another US state with a privacy law (for example CCPA/CPRA), you have the right to know what personal information we collect, to access and delete it, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information, so there is nothing to opt out of — but you may still exercise your other rights.
To exercise any of these rights, email us at [email protected]. We will respond within the timeframe required by applicable law. Because much of your data lives only on your device, you can also exercise many of these rights directly by editing or deleting content in the app, or by uninstalling it.
What we do not do
We do not sell your personal information. We do not show third-party ads inside the app, and we do not build advertising profiles about you or target ads at you. Where we use the advertising identifier — only with your permission — it is solely to measure which of our own marketing efforts led to an app install (attribution), not to advertise to you.
Children
MealKal is not directed to children under 13, and we do not knowingly collect personal information from them.
Your choices
You can control tracking at any time on Apple devices in Settings → Privacy & Security → Tracking. You can stop all data collection by uninstalling the app, which removes locally stored content from your device. You can manage or cancel your subscription in your Apple account settings.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected on this page with a new date.
Contact
Questions about privacy? Email [email protected].