Legal document

Privacy Policy

Last updated: 16 September 2026  ·  Version 2.1

Snack Me Up decides what you cook. To do that well it needs to know your allergies, your kitchen and what you ate recently. This document says plainly what data we collect, why, who processes it for us, how long we keep it and how you can delete it.
  1. Data controller
  2. Data we collect
  3. Why, and on what legal basis
  4. Artificial intelligence
  5. Voice, photos, location, notifications
  6. Third-party services
  7. Sensitive data
  8. How long we keep data
  9. Deleting your account
  10. Your rights (GDPR)
  11. Advertising and tracking
  12. Security
  13. Children
  14. Changes to this Policy

Data controller

The controller of your personal data is Jarosław Przezdziecki, Poland, the maker of Snack Me Up (“we”, “the app”).

Contact for anything related to your data: support@snack-me-up.com. We reply within 30 days at the latest.

We process data under Regulation (EU) 2016/679 (GDPR) and Polish data protection law. This Policy covers the Snack Me Up mobile app for iOS and Android and the pages at snack-me-up.com and jarekprzez-smu.github.io/snackmeup-web.

Data we collect

We collect only what the app needs to work. There are no ads, so we do not build a profile of you for anyone but you.

CategoryWhat exactlySource
Account Email address, chef name (optional), sign-in provider (Apple, Google or email), account identifier. You can also use the app without creating an account — we then create an anonymous technical account with no email address. You, at sign-in or first launch
Device anchor A hash of an identifier that lets us recognise the same device: on Android the system app identifier, on iOS a random identifier stored in the device keychain. Used only to count the free monthly generation allowance and to merge an anonymous account into the account you later sign in to. It does not identify you by name and it is not an advertising identifier. Device
Culinary profile Allergies and dietary exclusions, disliked ingredients, diet type, kitchen equipment, favourite cuisines, skill level, budget, default servings, language, country or region. In Meal Prep also household members: a label (e.g. “Anna”, “kids”), portion multiplier, their exclusions and diet. You, during setup and in settings
Activity in the app Recipes generated, cooked, skipped and rated, favourites, views, pantry, shopping lists, meal plans, cooking statistics, the craving you type or dictate in Cravings mode. Your actions in the app
Product photos In Kitchen Hero you can photograph your fridge or groceries. The photo is sent to the AI model to recognise ingredients and is not stored by us — only the list of recognised ingredients remains. You, voluntarily
Subscription RevenueCat subscriber identifier, status (free, trial, Premium), start, renewal and expiry dates, purchase platform. We never see your card details — payment is handled entirely by Apple or Google. Apple / Google via RevenueCat
Notifications Device push token and platform — only if you grant the system permission. Used for reminders about planned cooking and a ready Meal Prep plan. Device, with your consent
Technical data App version, operating system, request timestamps, IP address in short-lived infrastructure logs, AI usage counters (not linked to a user), error records. Automatically
Usage analytics Events describing the path through the app only: which setup step was shown, opening the sign-in screen and its outcome (method and error code — never your password), leaving the waiting screen before a recipe is ready. Each event carries a random installation identifier, a session identifier, the platform, app version, language and a timestamp. We use no third-party analytics SDKs — events go only to our own infrastructure. They contain no recipe text, no cravings, no photos and nothing from your cooking profile. Automatically, while you use the app

We do not collect: precise GPS location (see section 5), contacts, advertising identifiers, data from other apps, or any health data beyond what you yourself enter in your culinary profile.

Why, and on what legal basis

PurposeDataLegal basis (GDPR)
Generating and selecting recipes tailored to youculinary profile, activity, craving, product photoscontract — Art. 6(1)(b); for allergies and diet your explicit consent — Art. 9(2)(a)
Avoiding repetition (Anti-Monotony Engine)history of generated, cooked and skipped dishescontract — Art. 6(1)(b)
Running your account, sign-in, merging an anonymous accountaccount, device anchorcontract — Art. 6(1)(b)
Enforcing the free allowance and preventing abusedevice anchor, generation counters, technical datalegitimate interest — Art. 6(1)(f)
Managing the Premium subscription and free trialsubscription datacontract — Art. 6(1)(b)
Push remindersnotification tokenconsent — Art. 6(1)(a)
Adapting ingredient availability to your regioncountry or regioncontract — Art. 6(1)(b); consent for a one-off location read
Security, error diagnostics, AI cost controltechnical datalegitimate interest — Art. 6(1)(f)
Seeing which setup or sign-in step people stop at, and fixing those placesusage analyticslegitimate interest — Art. 6(1)(f)
Answering your messages and handling your rightsemail, message contentlegal obligation — Art. 6(1)(c); legitimate interest

We make no decisions with legal effect on you by solely automated means. Recipe selection is automated, but its only effect is a dinner suggestion.

Artificial intelligence

Recipes, meal plans, dish images and ingredient recognition from photos are generated by the Google Gemini AI model, which we use through Google's paid API.

What reaches the model

We send only what a recipe needs: your preferences, allergies and exclusions, equipment, the titles of dishes you ate recently, your craving, the number of servings, your region and — in Kitchen Hero — the product photo. We do not send your email address, account identifier or subscription data.

What Google does not do

Under the paid Gemini API terms, Google does not use submitted content to train its models and does not retain it beyond what is needed to serve the request and legally required abuse monitoring. Details: Gemini API Terms.

Automatically generated content

Recipes and plans are generated automatically and may contain mistakes — in quantities, timings and, exceptionally, ingredients. We treat the allergies in your profile as a hard constraint and verify the output, but no system offers a 100% guarantee. Always check product labels. Snack Me Up is not medical or dietary advice and is not a medical device.

Shared catalogue

A generated recipe (title, ingredients, steps, macros, image) goes into the app's shared recipe catalogue without any of your personal data and may be suggested to other users with similar preferences. Dish images are AI-generated and shared between users as a cache; they contain no personal data.

Voice, photos, location, notifications

Each permission below is optional. The app works without them and you can revoke consent in your system settings.

Third-party services

We rely on providers without whom the app could not run. Each processes data on our behalf, or as an independent controller for its own service (payments, sign-in).

ProviderRoleWherePolicy
Supabasedatabase, authentication, dish image storage, server functionsEU (Frankfurt)supabase.com/privacy
Google (Gemini API)generating recipes, plans and dish images, recognising ingredientsUSA / globalpolicies.google.com/privacy
Google (Sign in with Google, Google Play)sign-in, app distribution, payments on AndroidUSA / globalas above
Apple (Sign in with Apple, App Store, speech recognition)sign-in, distribution, payments on iOS, speech-to-textUSA / globalapple.com/legal/privacy
RevenueCatverifying and syncing subscription statusUSArevenuecat.com/privacy
Expo (EAS)delivering push notificationsUSAexpo.dev/privacy
GitHubhosting this pageUSAgithub.com — privacy

Transfers outside the European Economic Area. US providers process data under the European Commission's adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses. Your database and account stay in the European Union.

We do not sell personal data and do not share it with anyone for marketing purposes.

Sensitive data

Allergies, intolerances and diet type (e.g. vegan, keto) may be health data under Article 9 GDPR. We process them:

You can withdraw consent at any time by removing these entries from your profile — the app will then generate recipes without those constraints.

How long we keep data

Deleting your account

You can delete your account yourself in the app: Profile → Delete account. The operation is immediate and irreversible. We then delete the sign-in account and all data linked to it: profile, allergies, equipment, household members, activity history, ratings, favourites, pantry, shopping lists, meal plans, statistics, generation jobs and notification tokens.

The only things we do not delete are contents no longer linked to you: anonymous recipes and dish images in the shared catalogue and aggregated AI usage counters. Cancel an active subscription separately in App Store or Google Play settings — deleting the account does not cancel it.

If you cannot sign in to the app, write to support@snack-me-up.com — we will delete the account manually after verifying that you own it.

Your rights (GDPR)

You have the right to:

Send requests to support@snack-me-up.com from the address linked to your account. We reply within 30 days; in complex cases we may extend this by a further 60 days and will tell you if so.

Advertising and tracking

Snack Me Up shows no ads, contains no third-party advertising or analytics SDKs, and does not track you across other apps or websites. We do not use the advertising identifier (IDFA / GAID). The app is funded solely by subscriptions.

From version 1.0.1 we measure our own, anonymous usage analytics, described in section 2: we want to know which setup or sign-in step people stop at. The events never leave our infrastructure, are not combined with any advertising profile, and are neither sold nor shared with anyone.

If we ever add a third-party analytics or error-monitoring tool, we will update this document before enabling it and — where the law requires — ask for your consent.

Security

Data in transit is encrypted (TLS). Database access is governed by rules that let each user read and change only their own rows; the server functions that generate content verify identity and entitlements before every call. Keys to external services live in an encrypted secret store, never in the app on your phone. Only the data controller has administrative access.

Children

The app is intended for people aged 16 or over. We do not knowingly collect data from younger users. If you believe a child under that age has created an account, write to us and we will delete it.

Changes to this Policy

We will announce material changes in the app or by email before they take effect. The current version and date are always at the top of this page. The previous version (1.0, June 2025) did not cover anonymous accounts, the device anchor, speech recognition, product photos, notifications or the shared recipe catalogue — this version describes those mechanisms explicitly.

Questions: support@snack-me-up.com