Privacy Policy
Who runs this
Menu Decoder is operated by PRE-LAUNCH ACTION [OPERATOR LEGAL ENTITY] — the registered business name has not yet been finalized in this policy; until it is, treat privacy@menudecoder.app as the point of contact for anything in this policy, including data-subject requests. For the EU General Data Protection Regulation (GDPR) and UK GDPR, that operator is the data controller for the personal data described below. PRE-LAUNCH ACTION whether an EU representative is required under GDPR Article 27 has not yet been assessed; that assessment is pending before any EU-facing public launch.
What we collect
Menu Decoder is built to need as little of your data as the app's core function allows. Two kinds of data exist:
- Your dietary profile — allergies and their severity, health conditions, medications, religious rules, lifestyle choices, diet programs, and your custom avoid list — is built and saved in your browser or device, using local storage (localStorage/IndexedDB). There is no account and no login. That profile is also sent to our server with every scan you run, so the server can compute your verdicts — see the next section, which corrects a common misconception about "on-device" apps: on-device storage and on-device processing are not the same thing, and Menu Decoder does the first but not the second.
- Saved cards and recipes — anything you choose to save from a scan — stay on your device, the same as your profile, and are not sent anywhere except at the moment you generate or save them (see below).
- Basic technical data inherent to any web request — such as your IP address — passes through our server and hosting infrastructure in the ordinary course of serving the app, the same as any website.
What we send with each scan — read this one
That transmission is processed transiently — held in server memory only for the seconds it takes to analyze the menu and return your results — and is not written to a persistent database. See Retention for the specific exceptions (like operational logs) and their current status. Because allergies, conditions, and medications are treated as a special, more sensitive category of personal data under laws like the GDPR, we ask for your explicit agreement to this per-scan transmission when you first build your profile in Settings. PRE-LAUNCH ACTION confirm that an explicit, separate consent step (distinct from simply filling in the Settings form) is live in the app before relying on this policy for EU/UK users.
Photos are also downscaled and re-encoded on your device before upload, to keep scans fast. In the ordinary case, that re-encoding also strips embedded metadata such as EXIF tags, including any GPS location baked into the original photo file. If that client-side step fails for any reason, the app falls back to sending your original photo file, which may still carry that metadata — if you'd rather not share it, consider stripping it yourself first, or use the paste-text or menu-link option instead.
What we do NOT collect
- No accounts, no sign-up, no passwords built into Menu Decoder itself.
- No analytics or advertising trackers, ad identifiers, or third-party marketing pixels built into the app or website.
- No sale of your data to anyone, for any purpose.
- No cross-app or cross-site advertising tracking of you.
- Your dietary profile is never used to build a marketing or advertising profile of you.
These statements describe what Menu Decoder itself collects. While the app is distributed for testing through Apple's TestFlight, Apple separately collects a tester's email address (to send the invite), device information, and crash/usage diagnostics, in order to operate the TestFlight service — under Apple's own developer and privacy terms, not this policy, and outside our control. If you're testing Menu Decoder via TestFlight, that collection by Apple happens regardless of anything described above.
Lawful basis for processing (GDPR/UK GDPR)
Where GDPR or UK GDPR applies to you, we rely on:
- Consent (Article 6(1)(a)) for building and storing your profile, and — because your profile includes health-related information such as allergies, conditions, and medications — the explicit consent required by Article 9(2)(a) for sending that data with each scan.
- Legitimate interest (Article 6(1)(f)) for the minimum operational logging needed to keep the service running and to guard against abuse, balanced against your rights as described under Retention.
You can withdraw consent at any time by deleting your profile in Settings or clearing your browser's site data. This stops future scans from sending profile data; it does not undo a scan already processed.
Third-party processors
To produce a verdict, a scan's contents are sent to the following third parties. Where we direct exactly what they may do with it, they act as our processors; where noted below, part of that chain is outside our direct control:
- Google Cloud Vision — receives menu photos to run optical character recognition (OCR) and return the text on the page, under Google's own Cloud data-processing terms. PRE-LAUNCH ACTION execute a Data Processing Addendum (DPA) with Google before relying on this path for EU/UK-covered scans.
- Anthropic's API — receives the extracted or pasted menu text and your dietary profile, to parse dishes and, where our own knowledge base doesn't have a confident answer, to infer likely ingredients, under Anthropic's own API terms. PRE-LAUNCH ACTION execute a DPA and/or confirm zero-retention terms with Anthropic before relying on this path for EU/UK-covered scans.
- OpenRouter — used only as a routing fallback if the direct Anthropic path is unavailable. When used, OpenRouter itself selects a downstream model provider to serve the request; we do not currently name or restrict which downstream provider that is, and that provider's own retention and training practices are outside our control. PRE-LAUNCH ACTION name or contractually restrict OpenRouter's downstream provider, or disable this fallback for EU/UK or otherwise health-data-sensitive traffic, before public launch.
- Hosting/infrastructure provider — PRE-LAUNCH ACTION [NAME THE OPERATOR'S HOSTING/CDN PROVIDER HERE]. Whoever runs the server that serves Menu Decoder has the technical access to traffic passing through it, including IP addresses, that any host has to the traffic it carries.
- Apple, Inc. (TestFlight) — during the current testing stage, operates the distribution channel used to install Menu Decoder on testers' devices, and collects tester email, device information, and crash/usage diagnostics for that purpose, independently of Menu Decoder, under Apple's own terms.
None of these processors are paid with, or otherwise given, your data as consideration; none of them are permitted to sell it.
International data transfers
Google, Anthropic, and OpenRouter are U.S. companies. Using them to process a scan means your menu content and profile data — including the health-related parts of it — are transferred to and processed in the United States. Where GDPR/UK GDPR applies, a transfer like this needs an appropriate safeguard, such as Standard Contractual Clauses (SCCs) or, where applicable, the EU-U.S. Data Privacy Framework (DPF). PRE-LAUNCH ACTION confirm and document which safeguard covers each processor listed above before relying on this policy for EU/UK users.
Retention
Per-scan content
Your menu photo/text and profile, sent to produce a scan's verdicts, are held only in server memory for the duration of that request, typically a few seconds, and are not written to a persistent database on our side. PRE-LAUNCH ACTION this describes our own server's intended behavior; it does not describe what each third-party processor above does on its own servers — Google and Anthropic each retain some data under their own, separate terms regardless of ours, and confirming the specifics of each is part of the DPA work noted above.
Operational / abuse-prevention logs
Basic request logs — such as IP address, timestamp, and which endpoint was called, but not your menu content or dietary profile — may be kept briefly to operate the service and guard against abuse. PRE-LAUNCH ACTION a specific retention period for these logs has not yet been finalized; this policy will be updated with an exact figure before public launch.
On-device data
Your profile, saved cards, and saved recipes live in your browser's or device's local storage and persist there until you delete them individually or clear your browser's/device's site data.
Your rights (GDPR/UK GDPR)
If GDPR or UK GDPR applies to you, you have the right to: access the personal data we hold about you, correct inaccurate data, request erasure, request restriction of processing, object to processing carried out on the basis of legitimate interest, receive a copy of data you provided in a portable format, and withdraw consent at any time (without affecting processing already carried out under it). Because we don't operate accounts, most of what falls under "your data" is already directly in your control, in Settings and the Saved tab, for anything stored on your own device. For anything you believe we hold elsewhere — such as an operational log entry — contact privacy@menudecoder.app and we will respond as required by law; because we hold no account identifiers, we may need to ask you to describe the request so we can locate anything relevant. You also have the right to lodge a complaint with your local data protection supervisory authority at any time.
California & other U.S. state privacy rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, and similar laws in a growing number of other U.S. states give you rights that include: the right to know what personal information is collected, the right to delete it, the right to correct it, the right to opt out of its sale or sharing (we do not sell or share personal information for cross-context behavioral advertising — see "What we do NOT collect" above), and the right to non-discrimination for exercising any of these rights. To exercise a right under this section, contact privacy@menudecoder.app. Because we don't operate accounts, we may ask you to describe what you're requesting and confirm the device or browser in question, since we have no other way to verify identity.
Washington consumer health data (My Health My Data Act)
Your allergies, health conditions, and medications qualify as "consumer health data" under Washington State's My Health My Data Act (MHMDA), which applies to data like this regardless of the size of the business handling it. Consistent with MHMDA, we: do not sell your consumer health data; do not share it except with the processors named above, and only to produce your scan results, chef cards, or recipe lookups; and let you withdraw consent and request deletion of your consumer health data at any time, from Settings or by contacting privacy@menudecoder.app.
PRE-LAUNCH ACTION MHMDA requires a separate, standalone consumer health data privacy policy (distinct from this general privacy policy) and a separate, signature-level consent step at the point consumer health data is first collected. This section summarizes our intended practice honestly, but does not by itself satisfy either of those two MHMDA-specific requirements — both are pending before a Washington-facing public launch.
Your choices
- Edit or delete any part of your profile in Settings at any time — this also stops it being sent with future scans.
- Delete individual saved cards or recipes, or clear all of them, from the Saved tab.
- Clearing your browser's or device's site data removes everything Menu Decoder has stored on that device.
- Use "Guest" scanning mode from the Today bar to check a menu without sending any saved profile at all.
Children
Menu Decoder is intended for use by adults managing their own dietary needs, or by adults setting up and managing a profile on behalf of someone in their care, such as a parent building a profile for a food-allergic child. We do not knowingly collect data directly from children under the applicable age of digital consent in their location. Because the app has no accounts and collects no contact information from anyone, we have no account-level record to associate with any user, child or adult; if you believe a child has set up their own profile, the fastest way to remove it is directly on that child's device, in Settings, since that's also where it lives. You can also contact us at privacy@menudecoder.app with any concern.
Changes to this policy
If how Menu Decoder handles data changes, we'll update this page and the "last updated" date above. Because there are no accounts or email addresses on file for the app itself, we have no way to notify you individually — checking back here is the way to stay current.
Contact
Questions about this policy, or any data-subject request under GDPR, CCPA, MHMDA, or similar law, can be sent to privacy@menudecoder.app, the operator of Menu Decoder.