Legal

Privacy Policy

How we collect, use, and protect your information.

Last updated September 24, 2026

1. Introduction

This Privacy Policy explains how MealMath ("MealMath," "we," "us," or "our") collects, uses, shares, and protects information when you use the MealMath mobile app, website, and related services (the "Service"). It should be read together with our Terms of Service.

By using the Service, you agree to the practices described here. If you do not agree, do not use the Service.

2. Information we collect

Account information. When you create an account, we collect your email address, and — if you sign in with Google — your Google display name and profile photo. We also store your device timezone.

Profile, body, and goal data. To build meal plans, you provide information such as your body weight and height, sex, activity level, dietary type, allergens and restrictions, nutrition goals (e.g. maintain, lose, or gain weight), target macros, budget, preferred stores, and planning preferences.

Apple Health data. If you grant permission, the Service reads metrics from Apple Health, including active energy burned, body mass (weight), body fat percentage, lean mass, and dietary intake logged by other apps. Most of this is used on your device to estimate your energy needs. Your body-weight readings are synced to your account on our servers to power weight trends and adaptive estimates; other Apple Health readings remain on your device unless you choose to log them. You can revoke Health access at any time in your device settings.

Content you create. We store content you create or submit, including custom foods, food overrides (price and nutrition corrections), recipes, saved meal plans, preferences, and feedback. When you scan a barcode or submit a food, we may process and store the associated barcode and nutrition images.

Usage, device, and diagnostic data. We collect a device push notification token (so we can send reminders you enable), and crash and diagnostic data through Google Firebase Crashlytics, which includes your account identifier and email together with error reports, to help us fix problems. We also use Google Analytics for Firebase to understand how the app is used: it records app events (for example, that a meal plan was generated or a meal was logged) and basic device information against a random app-instance identifier. We do not link these events to your account, collect your device advertising identifier, or use them for advertising.

We do not use third-party advertising networks or cross-app tracking SDKs.

3. How we use your information

We use your information to:

•Provide the Service — generate cost-optimized meal plans, compute calorie and macro targets, estimate your energy needs (TDEE), and track progress;

•Maintain your account, sync your data across devices, and provide offline access;

•Send notifications and reminders you have enabled;

•Diagnose crashes, prevent abuse, and keep the Service secure; and

•Improve and develop the Service, including the features described in "Deidentified and aggregated data" below.

4. Foods you submit to the shared catalog

Your custom foods, food overrides, plans, and preferences are private to your account and are not shown to other users.

However, if you choose to submit a food for review, you are asking us to add it to our shared, publicly readable food catalog. If accepted, the food data — and limited submission metadata, which may include an identifier associated with your submission — becomes available to all users of the Service. Do not submit a food for review unless you are comfortable with it being public.

5. Deidentified and aggregated data

We may create deidentified and aggregated data from your information and your use of the Service — data that no longer identifies you. We may use this deidentified and aggregated data for any lawful purpose, including research, analytics, and the development, training, and improvement of machine-learning models, datasets, features, and new products and services.

Because this data does not identify you, it is not subject to deletion or to the restrictions that apply to personal data. This is consistent with the content license in our Terms of Service.

6. How we share information

We do not sell your personal information. We share it only with service providers who process data on our behalf, and only as needed to run the Service:

•Google (Firebase and Google Cloud) — hosts our authentication, database (Firestore), file storage, and crash reporting (Crashlytics), and app usage analytics (Google Analytics for Firebase). Your account data, stored content, uploaded images, and diagnostic data reside in Google Cloud.

•Google Cloud AI (Vertex AI) — used to generate embeddings for food catalog data to improve search; we do not send your personal profile or health data for this purpose.

•Expo — issues and delivers the push notification tokens used to send reminders.

We may also disclose information if required by law, to protect our rights or users’ safety, or in connection with a merger, acquisition, or sale of assets. Grocery and nutrition data we ingest from sources such as retailer sites and the USDA database is collected server-side and does not involve sharing your personal information.

7. Data retention

We retain your information for as long as your account is active or as needed to provide the Service. When you request deletion, we delete or de-identify your personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Deidentified, aggregated, and previously published catalog data, and routine backups, may persist as described above.

8. Your rights and choices

Depending on where you live (for example, under GDPR or the CCPA/CPRA), you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. You will not be discriminated against for exercising these rights.

To exercise any of these rights, or to request deletion of your account and associated personal data, contact us at support@mealmath.ai. You can also control certain data directly: revoke Apple Health access in your device settings, and disable push notifications in your device or app settings.

9. Children

The Service is not directed to children under 16 (or the age of digital consent in your jurisdiction), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

10. Security

We use industry-standard safeguards, including the security controls provided by Google Cloud and access rules that restrict your data to your account. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. International data transfers

We are based in the United States and process data there and in other countries where our service providers operate. If you use the Service from outside these regions, you understand your information may be transferred to and processed in countries whose data-protection laws may differ from your own.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect means you accept the revised policy.

13. Contact

Questions about this Privacy Policy or your data? Reach us at support@mealmath.ai. [GOVERNING_JURISDICTION — e.g. State of California, USA] law governs this policy, consistent with our Terms of Service.

See also our Terms of Service.