Privacy Policy

Last updated: 17 July 2026

This Privacy Policy explains what information the Mealfy mobile app (“Mealfy”, “the app”, “we”, “us”) collects, how we use it, and the choices you have. By using Mealfy you agree to the practices described here.

Who we are

Mealfy is a menu-scanning app that lets you photograph a restaurant menu and turns it into structured, translated text. The app and its backend are operated by the Mealfy team. If you have any questions about this policy or your data, contact us at [email protected].

Information we collect

Account information

Mealfy does not use passwords. If you sign in with your email, we collect your email address and send you a one-time code to confirm it. The code is valid only for a short time and is used solely to sign you in.

If you sign in with Apple or Google, that provider shares your email address along with your name and profile picture, if available, so we can create or match your account. This information is read once, at sign-in, and stored with your account; the app does not let you edit it. Authentication happens on the provider’s side — we never see your Apple or Google credentials. If you choose “Hide My Email” when signing in with Apple, we only receive the forwarding address Apple generates for you, not your real email.

Menu photos and scans

When you scan a menu, the app uploads the photo you take to our servers for processing. The photo and the extracted menu (dish names, prices, categories, translations) are saved to your account so you can view your history, favorites, and past scans.

You can delete your account at any time — this removes all of your data, including your photos and extracted menus, from our servers.

Location

If you grant location permission, the app records the approximate coordinates of where a scan was taken and stores them with that scan (for example, to place it on a map and remember where you found a menu). Location is used only while you are using the app (“When In Use”). You can decline this permission or turn it off at any time in iOS Settings — the app still works without it.

Diagnostics and crash reports

To keep the app stable, we collect crash reports and error diagnostics (such as error type, affected screen or request path, and device/OS information). These reports are used only to diagnose and fix problems. They do not include your menu photos.

AI processing records

Every menu scan is recorded in our AI tracing system, which stores the input and output of each AI request — including the menu photo and the text extracted from it. We use these records to measure and improve recognition accuracy, debug incorrect results, and improve the app. This system is self-hosted on our own servers: these records are not sent to any third-party analytics or monitoring provider.

How your information is used

We do not sell your personal data, and we do not use it for advertising.

Third-party services

To provide the app, some data is shared with the following service providers, who process it only on our behalf:

Payments

Mealfy does not currently process payments or offer paid subscriptions. If this changes, we will update this policy before any paid features are introduced.

Data retention

We keep your account information, scans, and saved menus for as long as your account exists. Crash and diagnostic reports are retained only as long as needed to investigate and resolve issues. When you delete your account, we delete the personal data associated with it, except where we are required to keep certain records by law.

Where your data is stored

Your account data, menu photos, saved scans, AI processing records, and crash diagnostics are stored on servers we operate, located in the European Union. Our backend, AI tracing, and error monitoring (GlitchTip) are all self-hosted on this infrastructure, so this data is not shared with any third-party analytics or hosting provider.

The one exception is menu photo processing: when you scan a menu, the photo is sent to OpenAI, which may process it on servers outside the EU (including the United States). Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the transfer mechanisms offered by that provider.

Your rights and choices

Depending on where you live, you may have additional rights under laws such as the GDPR (EU/EEA) or the CCPA (California), including the right to access, correct, delete, or export your data. To exercise any of these rights, contact us at the email above.

Children

Mealfy is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS/TLS). Because sign-in is passwordless, there is no password of yours for us to store or for an attacker to steal. No method of transmission or storage is completely secure, but we work to protect your information against unauthorized access.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. We encourage you to review this page from time to time for any changes.

Contact

Questions about this policy or your data? Email us at [email protected].