Privacy Policy
Last updated: April 06, 2026
1. Information We Collect
Personal Information
- Account Information: Email address, password (encrypted), and display name
- Dietary Preferences: Food allergies, dietary restrictions, cuisine preferences, and cooking skill level
- Menu Planning Data: Generated menus, recipes, shopping lists, and your feedback on them
- Usage Data: How you interact with the app, feature usage, and error logs
Automatically Collected Information
- Technical Data: IP address, browser type, device information, and session data
- Analytics: Page views, click patterns, and app performance metrics
- Cookies: Session cookies for authentication and functionality
2. How We Use Your Information
- Core Functionality: Generate personalized meal plans, recipes, and shopping lists using AI
- Account Management: Create and maintain your account, authenticate login sessions
- Communication: Send transactional emails (password resets, menu ready notifications)
- Improvement: Analyze usage patterns to improve our AI recommendations and user experience
- Support: Respond to your questions, troubleshoot issues, and provide customer service
- Legal Compliance: Comply with applicable laws and protect against fraud
3. AI and Third-Party Services
OpenAI Integration
We use OpenAI's services to generate meal plans and recipes based on your preferences. Your dietary information is sent to OpenAI for processing, but we:
- Do not include personally identifiable information in AI requests
- Only send dietary preferences, not your name or email
- OpenAI processes this data according to their Privacy Policy
Email Services
We use third-party email services to send transactional emails. Your email address is shared with these services solely for delivery purposes.
4. Data Sharing and Disclosure
We do not sell, rent, or share your personal information with third parties for marketing purposes.
We may share your information only in these limited circumstances:
- Service Providers: Third parties who help us operate the service (hosting, email delivery, analytics)
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfer: If we're acquired or merged, your data may transfer to the new owner
- Safety: To prevent harm to users or the public
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data is encrypted in transit (HTTPS) and at rest
- Access Controls: Limited employee access on a need-to-know basis
- Regular Updates: We keep our systems updated and monitor for vulnerabilities
- Secure Infrastructure: Data is stored on reputable cloud providers with strong security practices
However, no system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Your Rights and Choices
Account Management
- Access: View and update your account information and preferences at any time
- Deletion: Delete your account and associated data from your account settings
- Export: Request a copy of your data (contact us at [email protected])
Communications
- Email Preferences: Control which transactional emails you receive
- Opt-out: You can disable non-essential email notifications in your account settings
Cookies
We use cookies to provide and improve our service. Here's what you need to know:
Necessary Cookies
These cookies are essential for the website to function properly.
- Session Cookie: Keeps you logged in while using MagicMenu
- CSRF Token: Protects against cross-site request forgery attacks
- Cookie Consent: Remembers your cookie preferences (stored in localStorage)
Analytics Cookies (Optional)
These cookies help us understand how visitors use our site.
- Usage Analytics: Anonymous data about page views and feature usage
- Performance Metrics: Helps us identify and fix performance issues
You can accept or decline analytics cookies using the cookie banner. We currently do not use any third-party analytics services.
Managing Your Cookie Preferences
- Cookie Banner: Use the cookie consent banner (appears on first visit) to accept or decline optional cookies
- Browser Settings: You can also control cookies through your browser settings, but this may limit app functionality
- Reset Preferences: Clear your browser's localStorage to reset your cookie preferences
7. Data Retention
- Active Accounts: We retain your data while your account is active
- Deleted Accounts: Data is permanently deleted within 30 days of account deletion
- Legal Requirements: Some data may be retained longer if required by law
- Backups: Data in backups is deleted according to our backup retention schedule (up to 90 days)
8. International Users
MagicMenu is operated from the United States. If you're accessing the service from outside the US, your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
9. Children's Privacy
MagicMenu is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information immediately.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will:
- Post the updated policy on this page with a new "last updated" date
- Notify you via email if you have an account
- For material changes, require re-acceptance of terms
Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
- Email: [email protected]
- Response Time: We aim to respond within 2 business days
California Residents: Under the California Consumer Privacy Act (CCPA), you have additional rights regarding your personal information. Contact us for details about exercising these rights.