Legal · Effective May 1, 2026 · GDPR + CCPA compliant

Privacy Policy.

What we collect, why, who we share it with, and the buttons that put you in charge.

v1.0Last updated · May 1, 2026Reading time · ~8 minQuestions? privacy@foodgenie.app

The short version

TL;DR · 6 things to know
  • We collect what we need to make FoodGenie work — recipes, plans, dietary profile, conversations.
  • We don't sell your data. Ever. No advertising data brokers.
  • We share with sub-processors who help us run the service (Anthropic / Neon / Vercel). DPAs signed.
  • LLM providers are contractually prohibited from training on your data.
  • You can download, correct, or delete everything. Open Settings → Privacy →
  • GDPR + CCPA compliant. EU/CA residents have full rights.

Last updated · May 1, 2026 · v1.0

§ Section 01

1. What We Collect

✦ Plain English

We collect only what we need to run the service — things you give us directly (like recipes and your email), plus standard technical data like your IP address.

We collect information you provide directly (name, email, password, recipes, inventory), information generated by your use of the service (meal plans, search history, Genie conversations), and standard technical data (IP address, browser type, device identifiers).

§ Section 02

2. How We Use Your Data

✦ Plain English

We use your data to run FoodGenie and power features like the Genie and recipe parsing. We don't use it for advertising — ever.

We use your data to provide and improve FoodGenie, send transactional emails (account confirmation, password reset), and power AI features like recipe parsing and the Genie assistant. We do not use your data for advertising.

§ Section 03

3. AI and LLM Processing

✦ Plain English

When you use the Genie or import a recipe, your input goes to an AI provider (Anthropic Claude). They're contractually prohibited from training on it. Outputs may be cached for performance.

When you import a recipe or ask the Genie a question, your input is sent to an AI provider (currently Anthropic Claude). We do not permit these providers to use your data for model training under our agreements. Outputs may be cached for performance. See our sub-processor list for current providers.

§ Section 04

4. Data Sharing

✦ Plain English

We don't sell your data. We only share it with the sub-processors that help us run the service — all of them have signed Data Processing Agreements.

We do not sell your personal data. We share data only with sub-processors necessary to operate the service: Neon (database hosting), Vercel (web hosting), Resend (email), Anthropic (AI), and Stripe (billing). All are bound by data processing agreements.

§ Section 4a

5. Household Data

✦ Plain English

In a household, other members can see shared recipes, inventory, and plans. You control your access and can leave any time from Settings.

When you join a household, other members can see shared recipes, inventory, and meal plans. Household owners can manage member access. You can leave a household at any time from Settings.

§ Section 05

6. Data Retention

✦ Plain English

We keep your data as long as your account is active. Delete your account from Settings and we'll erase your personal data within 30 days.

We retain your data for as long as your account is active. You can delete your account from Settings, which will delete your personal data within 30 days (it may persist in encrypted backups for up to 30 additional days). Some data may be retained longer for legal compliance.

§ Section 06

7. Your Rights

✦ Plain English

You can access, correct, export, or delete your data from Settings → Privacy. For anything more complex, email privacy@foodgenie.app.

Depending on your location, you may have rights to access, correct, export, or delete your personal data under GDPR, CCPA, and other applicable laws. You can exercise most rights directly from Settings → Privacy. For other requests, contact privacy@foodgenie.app. We respond within 30 days.

§ Section 07

8. Cookies and Tracking

✦ Plain English

We use session cookies for login and localStorage for theme preferences. No third-party tracking cookies, no advertising pixels.

We use session cookies for authentication and localStorage for theme preferences. We do not use third-party tracking cookies or advertising pixels.

§ Section 08

9. Security

✦ Plain English

We use HTTPS, bcrypt password hashing, and encrypted database connections. No system is 100% secure — please use a strong, unique password.

We use industry-standard security practices including HTTPS, bcrypt password hashing, and encrypted database connections. Report security concerns to security@foodgenie.app. No system is completely secure; please use a strong, unique password and enable two-factor authentication where available.

§ Section 09

10. Children's Privacy

✦ Plain English

FoodGenie isn't for children under 13. Child profiles on Household plans are managed by an adult account holder, not standalone accounts.

FoodGenie is not directed at children under 13 as standalone account holders. Child profiles on Family/Household plans are managed by the adult account holder and are not independent accounts. If you believe a child has provided us personal data outside this structure, contact privacy@foodgenie.app and we will delete it promptly.

§ Section 10

11. Changes to This Policy

✦ Plain English

We'll email you and post an in-app notice at least 30 days before any material changes take effect.

We will notify you of material changes via email or in-app notice at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.

§ Section 11

12. Contact

✦ Plain English

For privacy questions or to exercise a right, email privacy@foodgenie.app. For security concerns, email security@foodgenie.app.

For privacy questions or to exercise your data rights, email privacy@foodgenie.app. For security concerns, email security@foodgenie.app. For DPA/DPO inquiries, email dpo@foodgenie.app.

§ Sub-processors

Who we share data with

FoodGenie shares limited data with the third-party services below so we can run the product. All have signed Data Processing Agreements prohibiting independent use of your data. We update this list within 30 days of any change.

Sub-processorWhat they doWhat they seeRegionDPA
Vercel, Inc.Web hosting + CDNIP address, request metadata, cached pagesUnited StatesView ↗
Neon Inc.Database (PostgreSQL hosting)All stored account data (recipes, inventory, plans, household)United States · EU (regional replicas)View ↗
Anthropic PBCAI (recipe parsing + Genie chat)Submitted recipe text, chat promptsUnited StatesView ↗
Resend Inc.Transactional emailEmail address, name, message contentUnited StatesView ↗
Stripe, Inc.Subscription billingBilling email, plan, last-4 of payment method (not card number)United StatesView ↗

Last updated: 2026-05-23. Notify of changes: privacy@foodgenie.app.

Privacy questions? Email privacy@foodgenie.app. For security concerns, email security@foodgenie.app.