Mealyn · Privacy Policy
Your meal diary is private by default.
This policy explains what Mealyn collects, why we collect it, and how to contact us about privacy questions or account deletion.
Information We Collect
- Account information for your chosen login method: email; Apple user identifier and name/email supplied by Apple (including a private relay address); phone number and verification records where phone sign-in is supported; and display name, bio, avatar, account region and session tokens. We do not receive your Apple password.
- Receipts you upload and merchant, items, dates, amounts, currency and linked records you confirm or enter; and AI results. Conceal full card numbers, identity documents and unrelated personal information.
- Feedback text, optional screenshots, and the account identifier, app version, platform and language needed to handle it. Support personnel can review this content; check screenshots before submitting.
- Meal journal content you add, including meal photos, captions, meal type, timestamps, and time zones.
- Social content you choose to share, including Activity text, selected meal photos, structured meal or restaurant messages, audience choices, restaurant context, and optional expense or party-size details.
- Location context you provide or select, such as a restaurant reference and the canonical city attached to a private meal. On supported iPhones, Mealyn may read photo-owned location metadata exposed by the selected Photos asset, or GPS embedded in the selected image, to find that city and nearby restaurants, as described below.
- Safety and relationship information such as friend requests, blocks, reports, bounded report evidence, and operator actions.
- Photo upload metadata such as file type, file size, upload state, and storage object identifiers.
- Push notification registration information such as an app installation identifier, platform, environment, and device token.
- App compatibility information linked to the signed-in account: a random app-installation identifier, iOS version, non-user-assigned hardware-model identifier, Mealyn version and build, and coarse server-recorded first- and last-seen times.
- Service-region, entitlement, subscription, purchase-verification, and feature-usage information needed to run account features.
- App and service diagnostics such as device type, IP address, request timing, and error logs.
Camera, Photos, and Device Permissions
Camera and photo access support meal, receipt and other images, avatars and feedback screenshots you choose to capture or upload. We access only photos you select or permit. Notification permission supports enabled reminders and service messages. Manage these permissions in iOS Settings.
Mealyn may use location information in selected photos to identify a city on your device and support nearby restaurant search. Exact coordinates are kept in protected app-local storage, excluded from backup and account sync, and are not sent to Mealyn's servers or embedded in processed uploads. When you use nearby restaurant search, the map provider receives the query text and search-center location.
How We Use Information
- To create and secure your account.
- To save, display, sync, and restore your private meal journal.
- To recognize and describe images, perform content safety checks and provide the meal-analysis, receipt-parsing and other AI features you use.
- To store a canonical private meal city produced on your device so Mealyn can summarize cities in your own meal history.
- To deliver the Activity and structured friend shares you choose to send, enforce their audience, and provide related notifications.
- To let another signed-in user find your profile after entering a complete verified Mealyn login email that is enabled for discovery. Mealyn does not return or display an email in social search results and does not support partial email matching.
- To provide service-region routing, account entitlements, App Store subscription verification, and purchase restoration.
- To understand recent iOS, iPhone hardware-family, and Mealyn-build coverage for app compatibility, reliability, customer support, and aggregate release planning.
- To handle feedback, receive reports, apply blocks, review bounded safety evidence, prevent abuse, and troubleshoot support requests.
- To improve app reliability using diagnostics that should not contain submitted social text.
Sharing and Sale
We do not sell your personal information. When another signed-in user enters your complete verified and discoverable Mealyn login email, we may show that user your display profile, including your display name, avatar, and profile bio, subject to account and block rules. We do not show your email address in the result.
Meal journal content remains private unless you choose a sharing action. For the first social release, selected Activity and structured-share content is delivered only through accepted-friend experiences. The receiving user sees only the fields you selected for that share; unrelated journal entries remain private.
If content is reported, authorized support or operations personnel may review the reporter's reason, optional note, and a bounded snapshot of the reported content. Mealyn does not tell the reported user who submitted the report.
Necessary service providers include Alibaba Cloud and AWS (account, content and media hosting; Alibaba Cloud also provides email and phone verification); OpenAI or Alibaba Cloud DashScope (AI processing below); Apple (sign-in, purchases, push and available map search). Each receives information needed for the relevant function.
These providers are allowed to process information only as needed to provide their services to Mealyn. App Store subscription purchases are processed by Apple under Apple's own terms and privacy practices.
We may disclose information if required by law, to protect Mealyn and its users, or to investigate abuse or security issues.
Storage and Security
Mealyn uses authenticated access controls for account data and private media. Meal photos and journal fields are private by default and become visible to another user only when you select an available sharing action and audience.
A device-local photo location candidate is isolated by account, protected while the device is locked, and excluded from device backup and Mealyn account sync. It is used only for your private city assessment and same-device restaurant search; it is not public location proof.
Service Regions and AI Processing
Mainland-China accounts' primary application data is stored with Alibaba Cloud in mainland China; global accounts' primary application data is stored with AWS in the United States. Necessary linked account identifiers and subscription transaction information from both regions are processed in the United States for subscription verification and entitlement management.
Global accounts use OpenAI and mainland-China accounts use Alibaba Cloud DashScope for AI processing. Depending on the feature, inputs include needed images, relevant records and a pseudonymous account safety identifier for recognition, descriptions, meal analysis, receipt parsing and content safety. When you use an available monthly report feature, relevant records, dates, cities and spending summaries are also used for AI summaries. Feedback screenshots, passwords and verification codes are not part of these AI inputs. Provider retention is governed by the relevant service arrangements.
Retention and Deletion
We keep account, journal, receipt and spending, feedback, media, social, entitlement, and diagnostic information for as long as needed to provide Mealyn, maintain security, comply with legal obligations, resolve disputes, and operate backups. When you delete meals or request account deletion, we begin deletion or deactivation work for active service data and may retain limited records where required for security, billing, fraud prevention, or legal compliance.
Mealyn keeps only the latest compatibility snapshot for an app installation. A later signed-in account on the same installation replaces the current account association without retaining account-association history. Account deletion removes snapshots currently owned by that account, and snapshots not reported for more than 180 days are removed from active service storage. Signing out by itself does not delete the latest snapshot.
Deleting a meal removes its device-local photo location candidate on that installation. Deleting your account removes all such candidates owned by that account. Exact photo coordinates are not retained in Mealyn service backups because they are not uploaded.
A submitted safety report may retain a bounded snapshot after the original share becomes unavailable so authorized personnel can review it. Account deletion removes reports and evidence targeting the deleted account and anonymizes reporter identity in any minimally retained safety audit, unless a documented legal obligation requires otherwise.
Your Choices
- You can choose what meal photos and profile information you add.
- You can choose which supported meal, restaurant, photo, expense, and party-size fields to share with friends.
- You can report received social content and block another user in the app.
- You can delete meals in the app when deletion is available for that record.
- You can manage camera and photo library permissions in iOS Settings.
- You can manage App Store subscriptions through your Apple ID subscription settings.
- You can permanently delete your account in Profile, Settings, Delete Account, or email support@mealyn.net for privacy support.
You may also contact support@mealyn.net to request access, a copy, correction or deletion of personal information, withdraw consent or make a complaint. We perform necessary identity checks and handle requests under applicable law. Withdrawing processing necessary for the service may affect continued service, without removing statutory rights.
Children
Mealyn is not intended for children under 14. If you believe a child under 14 has provided personal information, contact us so we can investigate and act under applicable law.
Operator and Contact
Mealyn is operated by Mealyn Team, who is responsible for processing your personal information. For service or privacy questions, contact support@mealyn.net.
Last updated: September 18, 2026