Mealyo
Back to home

Privacy Policy

How we handle your data — transparent, GDPR-compliant, and only as much as needed.

Last updated: June 2026

Note: Mealyo is a project of Enactus Mannheim e. V., registered in Germany. The association is the controller under the GDPR. The legally binding version of this policy is the German one, available at /datenschutz. For all data-related questions you can reach us directly at team@mealyo.de.

1. Controller

Enactus Mannheim e. V., P4 9, 68161 Mannheim, Germany. The current board members are listed at enactus-mannheim.com/impressum. Direct contact for the Mealyo team: team@mealyo.de.

2. Minimum age

Mealyo is intended for users aged 16 and over. If you are younger, you may only use Mealyo with the consent of your parent or guardian. If we learn that we have collected personal data from a child under 16 without that consent, we will delete it without delay. If you believe we may have data about a child, please contact us at team@mealyo.de.

3. What we process

This policy covers both the website (mealyo.de) and the mobile app.

  • Account data — email address, display name, profile picture (when logging in with Google or Apple), birthday (optional), internal user ID.
  • Preferences — diet, allergies, dislikes, and optionally height, weight, activity level and goals. Always optional, editable any time.
  • Content — your inventory, shopping lists, weekly plans, cooking history, recipes. Stored under your user ID and only accessible to you and any household members you invite.
  • Receipt scans & AI — receipt images are sent to our servers to be parsed by AI (see section on OpenAI below). We retain receipts only as long as needed for processing.
  • Server log files — our hosting provider (Google Cloud, Firebase App Hosting, region europe-west4) logs IP address, timestamp, requested URL and HTTP status, user-agent and referrer. Logs are kept for up to 30 days and used only for operations, error analysis and abuse prevention. Legal basis: Art. 6(1)(f) GDPR.
  • Waitlist — name and email saved in a Google Sheet, used only to notify you once at launch. You can opt out any time by replying to our confirmation email. Legal basis: Art. 6(1)(a) GDPR (consent).

4. Processors and third-party services

We use the following providers under data processing agreements (Art. 28 GDPR) where applicable:

  • Firebase (Google Ireland Limited) — Authentication, Cloud Firestore (EU, europe-west), Storage, Cloud Functions and App Check.
  • RevenueCat (USA) — subscription management. Receives a pseudonymous user ID and subscription status. No payment data.
  • PostHog — pseudonymous product analytics. No cross-app tracking, no advertising IDs. Can be disabled in app settings.
  • OpenAI (USA) — receipt parsing, recipe generation, translations. We send only the data required for the feature, never your name, email or profile. Training is disabled for our requests.
  • Google Mobile Ads (AdMob) — only in the free tier. Uses device/advertising IDs. iOS asks for your tracking consent (App Tracking Transparency). Mealyo Pro and Family disable ads entirely.
  • Google Sign-In / Sign in with Apple — used only for login; we receive only the minimum required info.
  • Google Fonts — Poppins is self-hosted via next/font. No live request to Google when the page loads.
  • Userjot— in-app feedback. When you submit feedback we send the text you wrote and a pseudonymous user ID; we don't pass your name or email unless you voluntarily include them in the message. See userjot.com/privacy.

5. Use of artificial intelligence

Mealyo uses AI models for several features, including receipt parsing, translations, recipe and weekly-plan suggestions, and structuring recipes you enter yourself. AI-assisted features are labelled inside the app.

How the data flow works:AI requests always go through our backend, never directly from the app to the AI provider. We send only the content needed for the specific feature — e.g. the text of a receipt or the title and ingredients of a recipe. Your name, email, profile or other identifying data are not transmitted. The AI's response comes back through our backend and is stored in your account.

AI-generated content may be incorrect or out of date (so-called "hallucinations") and is not a substitute for professional nutritional or medical advice. Please double-check allergy and nutrition information before relying on it. We disable training on our data with our AI providers (see section 4 — OpenAI).

6. Transfers to third countries (especially the USA)

Some of our processors are based in or transfer data to the USA (notably OpenAI, RevenueCat, and parts of Google's services). The USA is not automatically considered a country with an adequate level of data protection. We rely on the following safeguards for these transfers:

  • EU-US Data Privacy Framework (DPF) — the European Commission has decided that DPF-certified US companies provide an adequate level of protection. The list of certified companies is at dataprivacyframework.gov.
  • EU Standard Contractual Clauses (SCC) under Art. 46 (2)(c) GDPR as an additional contractual safeguard.
  • Technical and organisational measures such as encryption, minimisation, and pseudonymisation.

Despite these safeguards, we cannot rule out that US authorities may access personal data and that data subject rights may not be enforceable in the same way.

7. Cookies and local storage

Strictly necessary (no consent required):we store your theme, preferred language, and your cookie choice itself in your browser's local storage. These are required to operate the site (§ 25(2)(2) TTDSG).

Only with your consent:if you click "Accept" in the cookie banner, we additionally load PostHog (see 5.3), which sets cookies and local-storage entries for pseudonymous usage analytics. The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TTDSG. You can withdraw your consent at any time; this does not affect the lawfulness of processing done before the withdrawal.

Current status: No choice yet

The mobile app stores login tokens and caches in the OS-protected app sandbox.

8. Push notifications

With your permission, Mealyo sends reminders for items expiring soon or planned meals. You can disable them any time in your device settings.

9. Retention

We retain personal data only as long as your account is active or legal retention obligations apply. You can delete your account any time from the in-app settings — this irreversibly removes your inventory, shopping lists, plans and recipes.

10. Your rights

Under the GDPR you have the rights of:

  • access (Art. 15)
  • rectification (Art. 16)
  • erasure (Art. 17)
  • restriction (Art. 18)
  • data portability (Art. 20)
  • objection (Art. 21)
  • lodging a complaint with a supervisory authority (Art. 77)

To exercise any of these rights, just email us at team@mealyo.de.

11. Competent supervisory authority

If you believe that the processing of your personal data violates the GDPR, you can lodge a complaint with our competent supervisory authority:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany

Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Web: baden-wuerttemberg.datenschutz.de

You may also contact any other EU data protection authority, in particular the one in the EU member state where you live.

12. Security

All connections between the app, website and our servers are TLS-encrypted. Data within Firebase is additionally encrypted at rest. Access to personal data is limited to the small Mealyo team members who need it to do their job.

13. Changes

We update this policy when our services, processors or applicable laws change. The latest version is always available on this page; the date above shows the last update.

This English text is provided for convenience. The legally binding version is the German one at /datenschutz.