MealLoop Privacy Policy
Last updated: 12 August 2026
This page is an English translation provided for convenience. In the event of any discrepancy or dispute, the French version is the authoritative text and prevails.
MealLoop is a family meal-planning app. This policy explains what data is collected, why, where it is hosted, how long it is kept, and how to exercise your rights. It covers the mobile app, the web app (app.getmealloop.app) and this presentation website.
The terms of use and the community-space rules complement this text: they can be read on this page and in the app (Settings > About > Legal information).
1. Who we are
MealLoop is a family meal-planning application, developed and operated in a personal capacity (no registered company) by William Albert, domiciled in the canton of Vaud, Switzerland.
This policy covers every way of accessing the service, in its three forms:
- The mobile app (Android).
- The web app, usable from a browser at app.getmealloop.app — the same service, the same account and the same data as the mobile app.
- The presentation website getmealloop.app, purely informational, which requires no account.
For any question about your personal data, you can contact us at: contact@getmealloop.app.
2. What data we collect
MealLoop is designed for family use: almost all the data you enter serves directly to make the app work (meal catalog, agenda, shopping lists), not to profile you.
2.1 Account data
- Email address (sign-in identifier).
- Password — never stored in plain text: it is hashed by the authentication service (Supabase Auth); MealLoop itself never has access to it.
- Display name (freely chosen, visible to the other members of your households).
2.2 Household data
- Household name, invite code, list of members and their role (household owner / member).
- Household settings: shopping day and frequency, display units, aisle order.
2.3 Culinary content you create
- Meals and recipes: name, description, ingredients, prices, steps, utensils, preparation times, difficulty.
- Personal ratings: your appreciation (1 to 5 stars) and your opinion on a recipe's difficulty, tied to your own profile within the household.
- Allergens and dietary attributes declared on a recipe (e.g. vegetarian, vegan, contains tree nuts) — data that regulations may classify as sensitive (health-related): it is only used for display within your household and is never shared outside of it.
- Photos you choose to add to a recipe or a step — voluntary upload only, compressed on your device before upload.
- Video links (e.g. YouTube) you attach to a recipe — only the link is stored, never the video itself.
2.4 Planning and shopping
- Planned meals agenda, cooking history (dates, number of times).
- Generated shopping lists and the declared stock of your pantry.
2.5 History and change log
Who, within your household, changed what and when on a meal or recipe — visible only to the members of that household, and used for the undo feature.
2.6 Reminders and notifications
If you enable a reminder, the meal time and lead time are stored to schedule a local notification on your device. This mechanism does not go through any third-party push notification service or external server.
2.7 Settings stored on your device
Some settings that only frame how things are displayed are stored solely on the device or browser you are using, and are never sent to the server: the chosen language (French/English), the light/dark theme, the temperature unit, the first day shown in the agenda and the shopping list display options. On the mobile app they are stored in the app's local preferences; on the web app and on this site, in the browser's local storage (see section 11).
2.8 Community space (optional)
If — and only if — you choose to publish in the community space, the following data becomes public, visible to other MealLoop users:
- The community nickname you choose (distinct from your display name within the household) and, where applicable, your public profile.
- The frozen copy of the recipes you publish.
- Your reviews of published recipes: the star rating, the optional comment you write, your community nickname, the date and the version of the recipe concerned. A review is public by nature; do not write anything in it that you would not want visible to everyone. Ratings are also used in aggregate for recipe rankings and the "recipe of the week", "recipe of the month" and "best recipes of all time" listings.
- The reports you submit, and the moderation data arising from them.
None of this data is published automatically: by default, nothing from your household leaves it. Recipes you save (set aside for later), by contrast, remain private: that list is visible only to you and feeds no public counter. The full rules for this space (moderation, reporting, appeals) appear in Part 3 of the terms of use.
2.9 Error reports and diagnostics
To fix failures, the app automatically sends a technical report when an error occurs (Sentry service, see section 5). This report contains the error message and its stack trace, the device or browser type, the system version and the MealLoop version, plus a technical identifier linking several errors to the same session. It contains neither the content of your recipes, nor your agenda, nor your shopping lists, nor your password. These reports are used exclusively for service stability.
2.10 Image recognition and translation features
- Receipt scanning and importing a recipe from a photo — the image you choose is sent to the Gemini API (Google) to extract structured text from it, only on your explicit action.
- Translation of community recipes — when a recipe is published in the community space, its title, ingredients and steps are sent to the Google Cloud Translation API to be translated into the app's other language. This only concerns content you have voluntarily made public.
- Product label scanning — this feature runs entirely on your device: no image and no text is sent to any server.
2.11 What we do not collect
- No location data.
- No payment data (the app is free, with no in-app purchases to date).
- No advertising identifier, no ad network, no audience-measurement or behavioural analytics tool — neither in the app nor on this site.
- No profiling for commercial purposes, no resale of data.
3. Why we use this data
- To provide the service: catalog, agenda, automatic generation of shopping lists, pantry tracking.
- To personalise meal suggestions (ratings, cooking frequency, recency, categories).
- To manage your account and access security (authentication).
- To warn you when a recipe that was already planned or used to generate a shopping list has been modified since.
- To schedule, if you enable it, a local reminder before a meal or a preparation step.
- To publish, if you ask for it, a recipe or a review in the community space, and to make that content readable in both languages of the app.
- To ensure the security of the service, moderate the community space and prevent abuse.
- To diagnose and fix app failures (error reports, see 2.9).
4. Legal basis for processing
- Performance of the contract between you and MealLoop when you create an account, for most of the data above.
- Consent, for strictly optional features: reminders/notifications, adding photos, publishing and commenting in the community space, sending an image to a recognition feature.
- Legitimate interest, for service security, moderation, abuse prevention and technical diagnostics.
- Legal obligation, where applicable, for retaining moderation data or responding to a request from an authority.
5. Who this data is shared with
MealLoop does not sell, rent or trade any data. The service does, however, rely on technical providers ("processors" under the FADP and the GDPR), which process certain data on our behalf and under our instructions. The complete list, current as of this version, is as follows:
- Supabase Inc. (AWS hosting) — database, authentication, photo storage, server functions. Covers almost all of the data in section 2. Processed in Ireland (EU/EEA), eu-west-1 region.
- Sentry (Functional Software, Inc.) — error reports and technical diagnostics (data described in 2.9). Processed in the European Union (Germany).
- Google (Google Ireland Ltd. / Google LLC) — "Sign in with Google", if you choose this sign-in method: your email address and Google account name. Processed in the EU and the United States.
- Google LLC — Gemini API — text extraction from a receipt or recipe photo: the image you submit to this feature. Processed in the United States.
- Google LLC — Cloud Translation API — translation of recipes published in the community space: title, ingredients and steps of your public recipes only. Processed in the United States.
- Cloudflare, Inc. — delivery and hosting of this site and of the web app: technical connection logs (IP address, browser type). Global network, nearest point of presence.
- BunnyWay d.d. (fonts.bunny.net) and jsDelivr — delivery of the fonts and of a display library used by this site and the web app: IP address, simply as a result of the request.
Clarifications:
- No data is sold, rented, or used for advertising purposes, either by MealLoop or by these providers in the course of their work for MealLoop.
- No sharing with any third party outside this list, except where legally required (e.g. a court order).
- A household's data is visible only to the members of that household (strict technical isolation at the database level — see section 9).
- Providers handling public content (translation) never receive private content from your household.
- This list may change; any substantial modification is announced in accordance with section 13.
6. Data transfers outside Switzerland
The main hosting (Supabase) is located in Ireland, and error reports (Sentry) are processed in Germany: two member states of the European Union and the European Economic Area (EEA). These transfers are covered by the mutual adequacy recognition between Switzerland and the EU/EEA — these countries are on the list of countries with adequate protection maintained by the Swiss Federal Council (Annex 1 of the Swiss Data Protection Ordinance) — so no additional safeguard is required for them.
Certain ancillary processing activities do, however, involve a transfer to the United States: Google sign-in, the image recognition and translation features (Google LLC), and the technical delivery of the site and the web app (Cloudflare, Inc.). These transfers are framed by the recognised safeguard mechanisms: these providers are certified under the Data Privacy Framework (including its Swiss component, the Swiss–U.S. DPF) and/or apply the European Commission's standard contractual clauses.
7. Retention period
- Active account: your data is kept as long as your account and your households exist.
- Trash (deleted meals/recipes): kept for 7 days, then automatically and permanently purged.
- Change log: the 50 most recent entries per meal are kept; older ones are purged automatically.
- Household deletion: immediate and irreversible cascade over all of that household's data, at the initiative of a household owner.
- Individual account deletion: available self-service in the app (Settings > My account), immediate and irreversible, or by email if you no longer have access to the app — see the dedicated page. If you are the sole owner of a household, governance is transferred to the other members; if you are its last member, the household and its data are deleted along with your account.
- Community publications and reviews: kept as long as you do not remove them. You can delete a published recipe or a review at any time. Deleting your account removes your publications. Your reviews, however, are anonymized rather than deleted: the link to your account, your nickname and the text of your comment are erased permanently, but the star rating is kept as an isolated number that is no longer attached to any person and continues to count towards the recipe's average. The reason is that deleting those ratings would retroactively change the ranking of recipes published by other users, who have nothing to do with your departure.
- Error reports (Sentry): kept for a limited period set by the service configuration (at most 90 days as of this version), then automatically deleted.
- Community moderation data: reports and the audit log of moderation actions are kept for a limited and justified period, then deleted or anonymised. They are only accessible to the moderation team.
8. Your rights
In accordance with the Swiss Data Protection Act (FADP) and, where applicable, the GDPR if you reside in the European Union, you have the following rights:
- Right of access — obtain a copy of the data concerning you.
- Right to rectification — correct inaccurate data (possible directly in the app for almost all fields).
- Right to erasure — request the deletion of your account and personal data.
- Right to portability — receive your data in a structured format.
- Right to object and to restrict processing, in the cases provided for by law.
The right of access and the right to portability can be exercised directly in the app (Settings > My account > Export my data). The right to erasure likewise (Settings > My account > Delete my account), or by email if you no longer have access to the app — see how to proceed. For any other right, contact us at the address given in section 1.
9. Security
- Strict per-household data isolation at the database level (PostgreSQL Row-Level Security).
- Encrypted connections (HTTPS) at all times between the app and the servers.
- Passwords hashed, never stored or transmitted in plain text.
- Photos hosted in a private storage space, accessible only via signed links with a limited lifetime (1 hour).
- The app only embeds the public "anon" key, never an admin key.
10. Permissions requested by the app
On the mobile app:
- Camera / photo gallery — only if you add a photo, scan a receipt or a product label. Optional.
- Notifications — only if you enable a reminder. Optional.
On the web app, no system permission is requested: the features that rely on the device camera and on local reminders are not offered there. Choosing a photo from your disk goes through the browser's file picker, which only grants access to the file you designate.
11. Cookies, local storage and trackers
MealLoop sets no advertising cookie and uses no tracker or audience-measurement tool, neither in the mobile app, nor on the app.getmealloop.app web app, nor on this site. No consent banner is therefore required: nothing is stored that is not strictly necessary to the functionality you requested.
What is actually stored:
- Mobile app — the display settings described in 2.7, in the app's local preferences, and a session token to keep you signed in.
- Web app — in your browser's local storage (localStorage): the sign-in session token, the language, the theme and the display settings described in 2.7. These items are technical and strictly necessary; they allow no cross-site tracking. You can clear them at any time by clearing the site's data in your browser — you will then be signed out.
- This presentation website — only the light/dark theme you chose and the fact that the language-change suggestion has already been shown. No account, no cookie, no personal data.
Finally, displaying this site and the web app loads fonts from fonts.bunny.net and an image display library from cdn.jsdelivr.net. These services set no cookie and perform no advertising tracking, but do technically receive your IP address simply as a result of the request (see section 5).
12. Use by minors
MealLoop is an app for family use. A minor may be invited into a household by a parent or guardian, who remains responsible for the creation and management of their account.
13. Changes to this policy
This policy may evolve along with the app. Any substantial change will be announced to you before it takes effect.
14. Contact and complaints
For any question or complaint about your data, contact us at contact@getmealloop.app. You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or with the competent authority of your country of residence if you are in the European Union.