Last updated August 2026
This Privacy Policy explains how Meal Planner ("we", "us") handles information when you use our website and Android app. The app is offline-first: it works fully without an account, and most of your data stays on your phone. This page covers what changes when you use the optional online features. We do not sell your personal data.
Your meal plans, dietary preferences, allergies, grocery lists, pantry, saved dishes and the in-app health tracker (food log, weight and sleep entries) are stored locally on your phone. We cannot see them unless you sign in and they are part of the backup described below — the day-to-day health tracker entries never leave your device.
An account exists only to back up your data and sync it across devices; every feature works signed out. You can sign in two ways, and both reach the same account when the verified email address matches. With Google Sign-In we receive your name, email address and profile photo URL from Google. With email and password, the credential is held by Google Firebase Authentication, which also sends the confirmation and password-reset emails — we receive only your email address (and your name, if Firebase has one) and never see or store your password. We require the address to be confirmed before an account becomes usable. Either way we then store a backup snapshot of your app data on our servers: your preferences (including diet, allergens, favourite cuisines, household size, units and theme), your body profile (height, weight, age, sex, activity level and goal — "health & fitness" data under Google Play's categories), your week plans including which meals you cooked, your saved dish ratings, and your pantry list. The backup is one snapshot per account, replaced each time your device uploads a newer one, and kept until you delete your account.
When you use AI features (the assistant or recipe generation), your relevant app preferences — such as diet, allergens, country, household size, body goal and favourite cuisines — are sent to our AI provider with that request to personalise the result. This context is used only to answer the request; our request logs keep outcome, model and token counts with a hashed network identifier for abuse prevention, never your messages or your name/email.
We use Google Firebase Analytics to understand which features are valuable, and Google AdMob to show limited ads. Both are consent-gated: where required we ask first, analytics consent is denied by default until you choose, and a premium option removes ads entirely. These services may process device identifiers (such as the advertising ID), IP address, app interactions and diagnostics. We never send your health values, name or email to analytics. We do not show ads during onboarding or cooking.
We use reputable providers for hosting and AI assistance, processing data only as needed to deliver the service. Recipe videos play in the official YouTube embedded player (YouTube's own privacy policy applies during playback). If you share a dish, a copy of that dish's content (never your personal data) is stored on our servers to serve the share link. Some providers process data outside the UK; where they do, we rely on their recognised safeguards for international transfers.
Where UK GDPR applies, we rely on: performance of a contract for the account, backup and AI features you ask for; consent for analytics and personalised advertising; and legitimate interests for keeping the service secure, rate-limited and reliable.
You can use the app without ever signing in, clear locally stored data from the app or Android settings at any time, and withdraw ad/analytics consent in the app. If you have an account you can delete it — and all server-side data with it — in the app (Settings → Delete account & data) for immediate effect, or request account deletion here; web requests are queued and processed manually, usually within 30 days. If you want your data gone but would rather keep the account, see deleting your data. You also have the right to access, correct, restrict or object to our processing and to data portability, and you can complain to your supervisory authority (in the UK, the ICO).
The app is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
Questions or requests? Email support@kivons.com.