Privacy Policy for MealQ
Last Updated: October 4, 2026
Introduction
MealQ ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the MealQ mobile and desktop application.
Information We Collect
Account Information
- Username and email address — Required for account creation; email is used for verification and account recovery
- Display name — Optional name shown to household members
- Password — Stored securely using industry-standard hashing (bcrypt)
- Google account identifier and email — If you choose to sign in with Google, we receive your Google account ID and email address from Google
- Registration code or household invite code — Used during account creation when provided
User-Generated Content
- Meal information — Meal names, descriptions, recipes, ingredients, and tags
- Meal plans — Your scheduled meals for specific dates and meal types
- Shopping lists — Items you add to your shopping lists, including quantities and categories
- Household data — Household names and membership information
- Images — Photos you upload for your meals, stored in Cloudflare R2 storage
- Day tags and notes — Tags and notes you create for specific days
- User preferences — Notification settings and other app preferences
Device and Technical Information
- Device tokens — Apple Push Notification service (APNs) and Firebase Cloud Messaging (Android) tokens for push notifications (optional, only if you enable notifications)
- IP address and User-Agent — Collected during registration and login for security and rate-limiting purposes; not stored long-term
- Local storage data — Cached data stored on your device for offline functionality
Subscription Information
- Subscription tier and status — Free trial, active, cancelled, or expired
- Purchase records — Google Play purchase tokens or Apple App Store transaction identifiers, used to verify and manage your subscription
- Subscription dates — Trial start/end dates and billing period information
Usage Information
- AI usage counts — How many times you use an optional AI feature each day, so we can apply fair-use limits
- Feature usage events — Records of actions you take in the app (for example, creating a meal, adding a shopping list item, or starting a session), associated with your account and household and used to understand and improve MealQ. See "Analytics" below
- Authentication session tokens — For maintaining your login state
How We Use Your Information
We use your information to:
- Provide core functionality — Enable meal planning, shopping list management, and recipe organization
- Enable collaboration — Share meal plans and shopping lists with household members in real time
- Provide offline access — Cache data locally on your device for offline use
- Send notifications — Alert you to shopping list changes (only if you enable notifications)
- Maintain security — Authenticate your identity and protect your account
- Send transactional emails — Email verification and password reset messages
- Manage subscriptions — Verify and process Apple App Store and Google Play purchases
- Import recipes — Fetch a recipe page or read recipe text you provide, and turn it into a draft meal for you to review
- Power optional AI features — If AI features are enabled for your account, suggest a store section for new shopping items and, when a recipe page has no structured data, extract the recipe from its text
- Improve the app — Understand which features are used, so we can fix problems and prioritize improvements
Data Storage and Security
Cloud Storage
- Your account data is stored securely on Cloudflare's infrastructure using D1 databases
- All data transmission uses HTTPS encryption
- Passwords are hashed using bcrypt and never stored in plain text
Local Storage
- Data is cached on your device using secure localStorage for offline functionality
- Cached data automatically expires after 14 days
- You can clear cached data at any time through the app
Authentication
- We use session tokens for authentication
- Tokens expire after a set period
- You can log out at any time to invalidate your session
Data Sharing and Third Parties
Third-Party Services
We integrate with the following third-party services:
- Recipe websites — When you import a recipe from a link, our servers fetch that public web page on your behalf. We do not send your account information to the site.
- TypeSafe AI — If AI shopping categorization is enabled for your account, the name of a newly added shopping item and the names of the categories on that list are sent to TypeSafe AI to suggest a store section. No account details are sent. See TypeSafe AI's privacy policy on its website.
- Cloudflare — Our API, database, image storage and AI processing (Workers AI) are hosted on Cloudflare. See Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/
- Resend — We use Resend to send transactional emails (verification and password reset). Your email address is transmitted to Resend solely for delivery of these messages. See Resend's privacy policy at https://resend.com/legal/privacy-policy
- Google — If you sign in with Google or purchase a subscription through Google Play, Google processes that request. We receive your Google account ID and email, or purchase tokens and subscription status, to manage your account and access. We also use Firebase Cloud Messaging to deliver push notifications on Android. See Google's privacy policy at https://policies.google.com/privacy
- Apple — If you purchase a subscription through the App Store, Apple processes the purchase. We receive transaction identifiers and subscription status from Apple to manage your access, and use the Apple Push Notification service to deliver push notifications on iOS. See Apple's privacy policy at https://www.apple.com/legal/privacy/
No Selling of Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Analytics
MealQ records feature usage events (such as which features you use and when) on our own Cloudflare infrastructure. These events are linked to your account and household and are used only to operate and improve MealQ. We do not use third-party analytics SDKs or advertising networks, we do not use your data for advertising, and we do not track you across other companies' apps or websites.
AI Features
MealQ has two optional AI features. You can manage them in Settings, and neither is used to advertise to you.
- Shopping item categorization — When you add a shopping item without a category, MealQ may send the item name and your list's category names to TypeSafe AI, which suggests a store section. Your household's own past choices are used first, and if the service is unavailable or unsure the item is simply left uncategorized.
- AI recipe import — When you import a recipe from a link or pasted text and the page has no structured recipe data, MealQ sends the page text or the text you pasted to a language model running on Cloudflare Workers AI to extract the recipe. You review the draft before anything is saved.
We removed AI meal suggestions, which sent household meals and preferences to a language model, and the Spoonacular and TheMealDB recipe search, so that data is no longer sent anywhere.
Household Access Tokens
If you create a household access token, anyone holding it can read your household's meal plan (limited to the meal types you choose, with or without notes) until it expires or you revoke it in Settings. Tokens are read-only, and only a hash of each token is stored.
Your Rights and Choices
You have the right to:
- Access your data — View all data associated with your account
- Update your information — Edit your profile, meals, shopping lists, and preferences at any time
- Delete your data — Request deletion of your account and associated data
- Export your data — Request a copy of your data in a portable format by emailing us
- Control notifications — Enable or disable push notifications at any time
- Manage household access — Control who can access your shared meal plans and shopping lists
- Manage your subscription — Cancel or modify your subscription at any time through the App Store (Settings, then your name, then Subscriptions) or the Google Play Store
Data Retention
- Active accounts — Data is retained as long as your account is active
- Cached data — Local cache expires after 14 days of inactivity
- Deleted accounts — Upon account deletion, your data will be permanently removed from our servers within 30 days
- Logs — Server logs are retained for security purposes for a limited time period
Household Data Sharing
When you join or create a household:
- Household members can view shared meal plans and shopping lists
- Changes are synced in real time to all household members
- You control which households you join and can leave at any time
- Household administrators can manage member roles and permissions
- Only members of your household can view your shared data
Push Notifications
If you enable push notifications:
- We store device tokens to send notifications
- Notifications are sent only for shopping list changes
- You can control notification frequency and preferences in Settings → Notifications
- You can disable notifications at any time in Settings
- Uninstalling the app automatically stops notifications
Email Communications
If you provide an email address:
- We send a verification email when you register or request re-verification
- We send password reset emails when you request them
- We send transactional notifications related to your subscription (e.g., subscription changes from Apple or Google Play)
- We do not send marketing or promotional emails
Subscriptions
If you subscribe to MealQ Premium:
- Subscriptions are purchased and managed through the Apple App Store or Google Play, depending on your device
- We receive purchase verification data (transaction identifiers or purchase tokens, subscription state) to grant access
- Billing is handled entirely by Apple or Google; we do not store payment card information
- You can cancel your subscription at any time through the App Store or Google Play Store
Children's Privacy
MealQ is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Updating the "Last Updated" date at the top of this policy
- Displaying a notice within the app
Your continued use of MealQ after changes are posted constitutes acceptance of the updated policy.
Data Security Measures
We implement appropriate technical and organizational security measures, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing (bcrypt)
- Role-based access control
- Regular security updates
- Rate limiting on authentication endpoints
Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us at:
Email: mealq.support@plantolive.app Website: https://mealq.plantolive.app (see also Support)
Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the data and the context:
- Contract performance — Processing necessary to provide the service you requested
- Consent — When you explicitly agree (e.g., enabling push notifications)
- Legitimate interests — For security, fraud prevention, and service improvement
You have additional rights under GDPR, including the right to object to processing, request data portability, and lodge a complaint with your supervisory authority.
California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it
- Request deletion of your personal information
- Opt-out of the sale of personal information (note: we do not sell personal information)
- Non-discrimination for exercising your privacy rights
By using MealQ, you acknowledge that you have read and understood this Privacy Policy.