Privacy policy
The short version
- There is no account. We never ask for your name, your email or a password.
- Your meal plans, shopping lists, favourites and preferences live on your device, not on our servers.
- To write your plan, the app sends your food preferences — and nothing that identifies you — to OpenAI.
- Subscriptions are handled by Apple. We never see your card details.
- No advertising, no tracking across other apps or websites, and nothing sold to anyone.
- Delete the app and everything it stored on your device goes with it.
1. Who we are
Meal Planner is an iPhone and iPad app that plans a week of breakfasts, lunches and dinners around a food budget you set. This policy explains exactly what the app does with information, in plain language, and it is deliberately specific rather than hedged.
The data controller for the purposes of the UK GDPR and EU GDPR is Meal Planner, contactable at privacy@mealplanner.app. Where this policy says “we”, it means that controller. Where it says “you”, it means the person using the app.
2. What we do not collect
The app has no sign-up screen, and that is not an oversight. It was built so that it never needs to know who you are. We do not collect, ask for, or receive:
- Your name, email address, phone number or postal address
- Any password, because there is no account to protect
- Your location, at any level of precision
- Your contacts, calendar, photos, microphone or camera
- Health, fitness or medical data, including anything from Apple Health
- Advertising identifiers (the IDFA), and we never ask for tracking permission
- Any information about your activity in other apps or on other websites
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. There is no advertising in the app.
3. What stays on your device
Nearly everything the app knows about you is stored only in the app’s own private database on your device, using Apple’s SwiftData. We have no copy of it and no way to read it. That includes:
- Your preferences: weekly food budget, how many people you cook for, which days you cook, which meals you want planned, how long you are willing to cook, your diet type, ingredients you avoid, ingredients you like, the shops you use, and the staples already in your cupboard.
- Your plans: every generated week, including each meal’s title, description, ingredients, quantities, steps, estimated price and cooking time.
- Your shopping lists and which items you have ticked off.
- Your favourites — the meals you hearted.
- The meal photos generated for your plans, cached on the device so the app works without a connection.
Because this data never leaves the device, deleting the app deletes it. There is no server-side copy to request, export or erase.
4. What leaves your device, and why
Writing a week of meals is the one thing the app cannot do on its own. When you generate or regenerate a plan, or swap a single meal, the app sends a request to OpenAI containing the details it needs to make the plan fit you:
| What is sent | Example | Why |
|---|---|---|
| Weekly food budget | 120 | So the week is priced to fit it |
| Number of people | 2 | So portions and prices are right |
| Days and meals wanted | Mon–Fri, dinner only | So nothing is planned for days you don’t cook |
| Cooking time preference | 15 min | So no recipe outruns your evening |
| Diet type | Vegetarian | So the meals are ones you eat |
| Ingredients to avoid | peanuts, shellfish | So they are kept out of the plan |
| Favourite ingredients | chicken, feta, oats | So more of the week is food you like |
| Shops you selected | Aldi, Trader Joe’s | So price estimates are realistic |
| Week start date | 2026-08-17 | So the days line up with your calendar week |
| A short description of each dish | “pan-seared salmon…” | To generate the photo shown for that meal |
That is the complete list. No name, no email, no account number, no device identifier and no advertising identifier is attached to these requests. As far as OpenAI is concerned, the request is an anonymous set of food preferences.
Note the one thing worth thinking about before you type it: ingredients you avoid can imply health information. If you list an allergy or an intolerance, that fact travels with the request. It is not linked to your identity, but if you would rather it were not sent at all, leave the field empty and filter meals yourself.
5. Who processes data for us
Three companies are involved, and only these three.
OpenAI
OpenAI, L.L.C. generates the meal plans (using its text models) and the meal photographs (using its image models). It acts as our data processor under its API terms, which state that data submitted through the API is not used to train its models. OpenAI may retain API request data for a limited period for abuse monitoring before deleting it — up to 30 days under its current policy. See openai.com/policies/privacy-policy.
Apple
Apple distributes the app and processes every payment. Apple decides what it tells us about a purchase — we receive confirmation that a subscription is active, never your payment details. Apple’s own handling of your Apple Account is covered by Apple’s privacy policy, not by this one.
Superwall
Superwall, Inc. shows the subscription screen and records whether it was shown, dismissed or purchased from, so we can tell whether the screen works. To do that its SDK receives an anonymous app-install identifier it generates itself, plus technical details of the device and app: model, operating system version, app version, language and region. It does not receive your meal plans, your preferences, your name or your email. See superwall.com/privacy.
6. Purchases and subscriptions
Meal Planner is sold as a subscription through the App Store. Payment is taken by Apple using the payment method on your Apple Account. We never see, store or have access to your card number, and we cannot charge you directly.
Managing or cancelling a subscription is done in your Apple Account settings, not in the app, and cancelling takes effect at the end of the period you have already paid for. Refunds are handled by Apple through reportaproblem.apple.com.
7. Diagnostics and crash reports
The app contains no analytics SDK beyond the subscription-screen telemetry described above. It does not log what you cook, when you open it, or what you search for.
Separately, Apple may send us crash reports and aggregate, anonymised usage statistics through App Store Connect — but only if you have turned on “Share With App Developers” in Settings › Privacy & Security › Analytics & Improvements. That switch is yours, it is off unless you turned it on, and what we get back is counts and stack traces, not individuals.
8. Why we are allowed to do this (GDPR)
- Generating your meal plan — performance of a contract (Article 6(1)(b)). You asked for a plan; sending your preferences is how one gets made. Without it the app has no function.
- Processing your subscription — performance of a contract (Article 6(1)(b)), and compliance with tax and accounting duties (Article 6(1)(c)) for records Apple keeps on our behalf.
- Subscription-screen telemetry — legitimate interests (Article 6(1)(f)): knowing whether the purchase screen works, using an identifier that is not linked to you personally.
- Crash reports — your consent, given to Apple through the analytics switch described above (Article 6(1)(a)), which you can withdraw at any time.
We do not carry out automated decision-making that produces legal effects, and we do not profile you for advertising. The app generates food suggestions; it does not make decisions about you.
9. How long anything is kept
- On your device: for as long as you keep the app. Old plans stay until you delete them; deleting the app removes everything at once.
- At OpenAI: request data may be retained for a limited abuse-monitoring window — up to 30 days under its current API policy — and is then deleted. It is not used to train models.
- At Superwall: paywall and subscription events, tied to an anonymous install identifier, for as long as the account is active, in line with its own retention policy.
- At Apple: purchase records for as long as Apple’s terms and tax law require.
10. Your rights and how to use them
If you are in the UK, the EU or another region with comparable law, you have the right to access your personal data, correct it, have it erased, restrict or object to its processing, receive it in a portable form, and complain to a supervisory authority. In California you have the rights to know, delete, correct and opt out of sale or sharing — and there is nothing to opt out of, because we do neither.
In practice, the honest answer for most of these is that you can exercise them yourself, immediately:
- Access and portability: everything we hold about you is on your device, in the app, in front of you.
- Correction: change any preference in Preferences and regenerate the plan.
- Erasure: delete a plan in the app, or delete the app to erase all of it at once.
- Objection: stop generating plans and nothing further is sent anywhere.
Because we hold no account and no identifier for you, we usually cannot find your data on request — there is nothing on our side to look up, and we will not ask you for identifying documents in order to invent a link that does not exist. If you still want to make a request, or complain about how the app handles data, write to privacy@mealplanner.app and we will respond within one month. You may also complain to your national data protection authority; in the UK that is the Information Commissioner’s Office.
11. Children
Meal Planner is meant for the person doing the food shopping, and it is not directed at children. We do not knowingly collect personal information from children under 13 (or under 16 where local law sets that age). Since the app collects no identifying information from anyone, we have no way to detect a child user; if you believe a child has been asked for information they should not have been, contact us and we will look into it.
12. International transfers
OpenAI, Apple and Superwall are US companies, so generating a plan involves sending your food preferences outside the UK and the EEA. Those transfers rely on the standard contractual clauses in each provider’s data processing terms, and where applicable on the provider’s certification under the EU–US and UK–US Data Privacy Framework.
13. Security
Requests to OpenAI are made over HTTPS. Your app database sits inside the app sandbox, protected by iOS and by your device passcode or biometrics. Meal photos are stored as ordinary files inside that sandbox.
No system is perfect, and the honest framing is this: the strongest protection here is architectural rather than procedural. There is no central database of users to breach, because we never built one.
14. Changes to this policy
If the app starts doing something materially different with data — a new processor, a new category of information, an account system — we will update this page and change the date at the top. Significant changes will also be flagged in the app itself. The date at the top always tells you which version you are reading.
15. Contact
Questions, requests or corrections about privacy: privacy@mealplanner.app. Anything else about the app: support@mealplanner.app. We read both.