Data controller
The controller of your personal data is Jarosław Przezdziecki, Poland, the maker of Snack Me Up (“we”, “the app”).
Contact for anything related to your data: support@snack-me-up.com. We reply within 30 days at the latest.
We process data under Regulation (EU) 2016/679 (GDPR) and Polish data protection law. This Policy covers the Snack Me Up mobile app for iOS and Android and the pages at snack-me-up.com and jarekprzez-smu.github.io/snackmeup-web.
Data we collect
We collect only what the app needs to work. There are no ads, so we do not build a profile of you for anyone but you.
| Category | What exactly | Source |
|---|---|---|
| Account | Email address, chef name (optional), sign-in provider (Apple, Google or email), account identifier. You can also use the app without creating an account — we then create an anonymous technical account with no email address. | You, at sign-in or first launch |
| Device anchor | A hash of an identifier that lets us recognise the same device: on Android the system app identifier, on iOS a random identifier stored in the device keychain. Used only to count the free monthly generation allowance and to merge an anonymous account into the account you later sign in to. It does not identify you by name and it is not an advertising identifier. | Device |
| Culinary profile | Allergies and dietary exclusions, disliked ingredients, diet type, kitchen equipment, favourite cuisines, skill level, budget, default servings, language, country or region. In Meal Prep also household members: a label (e.g. “Anna”, “kids”), portion multiplier, their exclusions and diet. | You, during setup and in settings |
| Activity in the app | Recipes generated, cooked, skipped and rated, favourites, views, pantry, shopping lists, meal plans, cooking statistics, the craving you type or dictate in Cravings mode. | Your actions in the app |
| Product photos | In Kitchen Hero you can photograph your fridge or groceries. The photo is sent to the AI model to recognise ingredients and is not stored by us — only the list of recognised ingredients remains. | You, voluntarily |
| Subscription | RevenueCat subscriber identifier, status (free, trial, Premium), start, renewal and expiry dates, purchase platform. We never see your card details — payment is handled entirely by Apple or Google. | Apple / Google via RevenueCat |
| Notifications | Device push token and platform — only if you grant the system permission. Used for reminders about planned cooking and a ready Meal Prep plan. | Device, with your consent |
| Technical data | App version, operating system, request timestamps, IP address in short-lived infrastructure logs, AI usage counters (not linked to a user), error records. | Automatically |
| Usage analytics | Events describing the path through the app only: which setup step was shown, opening the sign-in screen and its outcome (method and error code — never your password), leaving the waiting screen before a recipe is ready. Each event carries a random installation identifier, a session identifier, the platform, app version, language and a timestamp. We use no third-party analytics SDKs — events go only to our own infrastructure. They contain no recipe text, no cravings, no photos and nothing from your cooking profile. | Automatically, while you use the app |
We do not collect: precise GPS location (see section 5), contacts, advertising identifiers, data from other apps, or any health data beyond what you yourself enter in your culinary profile.
Why, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Generating and selecting recipes tailored to you | culinary profile, activity, craving, product photos | contract — Art. 6(1)(b); for allergies and diet your explicit consent — Art. 9(2)(a) |
| Avoiding repetition (Anti-Monotony Engine) | history of generated, cooked and skipped dishes | contract — Art. 6(1)(b) |
| Running your account, sign-in, merging an anonymous account | account, device anchor | contract — Art. 6(1)(b) |
| Enforcing the free allowance and preventing abuse | device anchor, generation counters, technical data | legitimate interest — Art. 6(1)(f) |
| Managing the Premium subscription and free trial | subscription data | contract — Art. 6(1)(b) |
| Push reminders | notification token | consent — Art. 6(1)(a) |
| Adapting ingredient availability to your region | country or region | contract — Art. 6(1)(b); consent for a one-off location read |
| Security, error diagnostics, AI cost control | technical data | legitimate interest — Art. 6(1)(f) |
| Seeing which setup or sign-in step people stop at, and fixing those places | usage analytics | legitimate interest — Art. 6(1)(f) |
| Answering your messages and handling your rights | email, message content | legal obligation — Art. 6(1)(c); legitimate interest |
We make no decisions with legal effect on you by solely automated means. Recipe selection is automated, but its only effect is a dinner suggestion.
Artificial intelligence
Recipes, meal plans, dish images and ingredient recognition from photos are generated by the Google Gemini AI model, which we use through Google's paid API.
What reaches the model
We send only what a recipe needs: your preferences, allergies and exclusions, equipment, the titles of dishes you ate recently, your craving, the number of servings, your region and — in Kitchen Hero — the product photo. We do not send your email address, account identifier or subscription data.
What Google does not do
Under the paid Gemini API terms, Google does not use submitted content to train its models and does not retain it beyond what is needed to serve the request and legally required abuse monitoring. Details: Gemini API Terms.
Automatically generated content
Shared catalogue
A generated recipe (title, ingredients, steps, macros, image) goes into the app's shared recipe catalogue without any of your personal data and may be suggested to other users with similar preferences. Dish images are AI-generated and shared between users as a cache; they contain no personal data.
Voice, photos, location, notifications
Each permission below is optional. The app works without them and you can revoke consent in your system settings.
- Microphone and speech recognition. In Cravings, Sweet Tooth and Kitchen Hero you can dictate a craving. Speech-to-text is performed by your phone's system service (Apple or Google) under that provider's privacy policy — this may involve sending audio to that provider's servers. We receive text only; we do not record or store audio.
- Camera and photo library. The Kitchen Hero photo is sent to the AI model solely to recognise ingredients and is not stored on our servers.
- Location. During setup you may allow a one-off location read so the app can set your country and region (ingredient availability, local cuisine). We store only the country or region — never coordinates — and we do not track location in the background. You can also enter your region manually.
- Notifications. Only cooking reminders and a ready-plan notice. No marketing pushes.
Third-party services
We rely on providers without whom the app could not run. Each processes data on our behalf, or as an independent controller for its own service (payments, sign-in).
| Provider | Role | Where | Policy |
|---|---|---|---|
| Supabase | database, authentication, dish image storage, server functions | EU (Frankfurt) | supabase.com/privacy |
| Google (Gemini API) | generating recipes, plans and dish images, recognising ingredients | USA / global | policies.google.com/privacy |
| Google (Sign in with Google, Google Play) | sign-in, app distribution, payments on Android | USA / global | as above |
| Apple (Sign in with Apple, App Store, speech recognition) | sign-in, distribution, payments on iOS, speech-to-text | USA / global | apple.com/legal/privacy |
| RevenueCat | verifying and syncing subscription status | USA | revenuecat.com/privacy |
| Expo (EAS) | delivering push notifications | USA | expo.dev/privacy |
| GitHub | hosting this page | USA | github.com — privacy |
Transfers outside the European Economic Area. US providers process data under the European Commission's adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses. Your database and account stay in the European Union.
We do not sell personal data and do not share it with anyone for marketing purposes.
Sensitive data
Allergies, intolerances and diet type (e.g. vegan, keto) may be health data under Article 9 GDPR. We process them:
- only on the basis of your explicit consent, which you give by entering them in your profile;
- only so that recipes and plans are safe and suitable for you;
- with no profiling for other purposes and no sharing with advertisers.
You can withdraw consent at any time by removing these entries from your profile — the app will then generate recipes without those constraints.
How long we keep data
- Account, profile, activity: for as long as the account exists.
- Anonymous account (no sign-in): for as long as you use the app on that device; when you sign in, its data is merged into the target account.
- Free allowance counter tied to the device anchor: counted in monthly cycles and overwritten each month.
- Subscription data: for the subscription term plus the period required for accounting and complaint handling.
- Infrastructure logs (including IP address): up to 30 days.
- Usage analytics: events are kept, but deleting your account clears the account identifier inside them — only the random installation identifier remains, and it points to no person. They hold none of the text you typed.
- Recipes in the shared catalogue: indefinitely, as anonymous content not linked to you.
- Support correspondence: up to 3 years after the case is closed, for potential claims.
Deleting your account
You can delete your account yourself in the app: Profile → Delete account. The operation is immediate and irreversible. We then delete the sign-in account and all data linked to it: profile, allergies, equipment, household members, activity history, ratings, favourites, pantry, shopping lists, meal plans, statistics, generation jobs and notification tokens.
The only things we do not delete are contents no longer linked to you: anonymous recipes and dish images in the shared catalogue and aggregated AI usage counters. Cancel an active subscription separately in App Store or Google Play settings — deleting the account does not cancel it.
If you cannot sign in to the app, write to support@snack-me-up.com — we will delete the account manually after verifying that you own it.
Your rights (GDPR)
You have the right to:
- access — receive a copy of your data;
- rectification — most data can be corrected in your profile settings;
- erasure — in the app, as in section 9;
- restriction of processing and objection to processing based on legitimate interest;
- portability — receive your data in a machine-readable format (JSON);
- withdraw consent at any time, without affecting the lawfulness of earlier processing;
- lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or the supervisory authority in your country of residence.
Send requests to support@snack-me-up.com from the address linked to your account. We reply within 30 days; in complex cases we may extend this by a further 60 days and will tell you if so.
Advertising and tracking
Snack Me Up shows no ads, contains no third-party advertising or analytics SDKs, and does not track you across other apps or websites. We do not use the advertising identifier (IDFA / GAID). The app is funded solely by subscriptions.
From version 1.0.1 we measure our own, anonymous usage analytics, described in section 2: we want to know which setup or sign-in step people stop at. The events never leave our infrastructure, are not combined with any advertising profile, and are neither sold nor shared with anyone.
If we ever add a third-party analytics or error-monitoring tool, we will update this document before enabling it and — where the law requires — ask for your consent.
Security
Data in transit is encrypted (TLS). Database access is governed by rules that let each user read and change only their own rows; the server functions that generate content verify identity and entitlements before every call. Keys to external services live in an encrypted secret store, never in the app on your phone. Only the data controller has administrative access.
Children
The app is intended for people aged 16 or over. We do not knowingly collect data from younger users. If you believe a child under that age has created an account, write to us and we will delete it.
Changes to this Policy
We will announce material changes in the app or by email before they take effect. The current version and date are always at the top of this page. The previous version (1.0, June 2025) did not cover anonymous accounts, the device anchor, speech recognition, product photos, notifications or the shared recipe catalogue — this version describes those mechanisms explicitly.
Questions: support@snack-me-up.com