Mealzy
Pricing Log in

Privacy Policy

Last updated: May 2026

1. Who we are

Mealzy ("we", "us", "our") is an AI-powered meal planning service available at mealzy.org. If you have questions about this policy, contact us at support@mealzy.org.

2. What data we collect

  • Account data: Your name, email address, and a hashed (bcrypt) version of your password when you register.
  • Profile data: Dietary preferences, health goals, budget, and activity level you enter during onboarding — stored locally in your browser (localStorage).
  • Meal plan data: Plans you generate are stored locally in your browser. We do not transmit your meal plan content to our servers beyond what is required to call the AI API.
  • Usage data: A count of how many meal plans you have generated in the current 30-day window, tracked by IP address on our server. This resets automatically.
  • Payment data: Processed entirely by Stripe. We never see or store your card number. We receive a Stripe customer ID and subscription status.

3. How we use your data

  • To provide and personalise the meal planning service.
  • To enforce the free plan limit (3 meal plans per 30-day rolling period).
  • To manage your Pro subscription via Stripe.
  • To respond to support enquiries.
  • We do not sell your data to third parties. We do not use your data for advertising.

4. Third-party services

  • Anthropic: Your meal preferences are sent to the Anthropic API to generate meal plans. Anthropic's data use is governed by their privacy policy.
  • Stripe: Handles all payment processing. See Stripe's privacy policy.
  • Render: Our hosting provider. Your data transits their infrastructure. See Render's privacy policy.

5. Cookies and local storage

We use a server-side session cookie solely to keep you logged in. We store your profile data, meal history, and preferences in your browser's localStorage — this data never leaves your device except when explicitly used to generate a meal plan.

6. Data retention

Account data (name, email, hashed password) is retained until you delete your account. Usage counters (IP-based, plan count) reset every 30 days automatically. Stripe subscription data is retained as long as you have an active or historical subscription, per Stripe's own retention policies.

7. Your rights

  • You may request a copy of the personal data we hold about you.
  • You may request deletion of your account and associated data at any time by emailing support@mealzy.org.
  • You may clear all locally stored data at any time through your browser settings.
  • If you are in the EEA or UK, you have rights under GDPR/UK GDPR including access, rectification, erasure, and objection.

8. Security

Passwords are hashed with bcrypt before storage. All traffic is served over HTTPS. We do not log or store the content of your meal plans on our servers.

9. Children

Mealzy is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date above. For material changes we will notify you by email if we hold your address.

Mealzy
Privacy Policy Privacy Terms Contact Pricing

© 2026 Mealzy. All rights reserved.