Legal
Privacy Policy
Effective date: September 18, 2026
Mealio LLC ("Mealio," "we," "us," or "our") operates the website located at mealio.co and the Mealio mobile application (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
If you have questions about this policy, contact us at contact@mealio.co.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: When you register, we collect your email address and a hashed password.
- Sign in with Google or Apple: If you sign in with Google or Apple, that provider sends us your name, your email address, whether it has verified that address, and an account identifier it assigns for Mealio. Apple lets you share a private relay address instead of your real email, and sends your name only the first time you sign in. We never receive your Google or Apple password.
- Creator application: If you apply to the Creator Partner Program, we collect your display name, phone number (optional), and social media or website links you choose to provide.
- Meal and recipe data: Meal names, ingredients, recipes, photos, and associated store information that you save or publish through the Service.
- Support communications: Any information you provide when contacting us at contact@mealio.co.
- Bug reports: When you submit a bug report through the app or website, we collect the description you write and the diagnostic information described in Section 1.2. Submitting a report is optional and entirely your choice.
1.2 Information Collected Automatically
- Authentication data: Session tokens and device identifiers used to keep you logged in securely.
- Log data: IP addresses, user agent strings, and timestamps associated with authentication events (login, logout, token refresh). These are used for security monitoring and abuse prevention.
- Usage data: Information about how you interact with the Service, including which meals you save and which grocery stores you use. This data is used to calculate creator profit share and improve the Service.
- Diagnostic logs (bug reports): The mobile app keeps a short, temporary record of recent activity in memory on your device. This record is never stored permanently and never transmitted to us unless you choose to submit a bug report. If you do, the recent diagnostic logs are attached to your report and emailed to our support address. To help us reproduce the problem, these logs may include the meals and grocery items involved in a cart action, the store used, and basic device and app information (app version, operating system, and the screen you were on). Before the logs leave your device we automatically remove sensitive values, including your password, login/session tokens, and email address. The logs are used solely to investigate and fix the issue you report.
1.3 Information from Third Parties
- Payment processors: If you subscribe to a paid plan, payment is processed by our third-party payment providers. Subscriptions purchased on the web are processed by Stripe; subscriptions purchased in the mobile app are processed by the Apple App Store or Google Play and managed on our behalf by RevenueCat. We receive a customer identifier and subscription status but do not store your full payment card details.
- Grocery platforms: Mealio interacts with grocery store websites on your behalf to add items to your cart. We do not store your grocery account credentials. Any data exchanged with grocery platforms is used solely to complete the cart action you initiate.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Authenticate your identity and maintain the security of your account;
- Process subscription payments and manage your subscription status;
- Calculate and distribute Creator Partner profit share;
- Send you transactional emails, including login verification codes and account notifications;
- Respond to your support requests;
- Detect, investigate, and prevent fraudulent or unauthorized activity;
- Improve and develop new features for the Service;
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your information for targeted advertising.
3. How We Share Your Information
We may share your information in the following limited circumstances:
- Service providers: We share information with third-party vendors who help us operate the Service, including our hosting provider (Vercel), which also provides the website analytics we use to count visits to pages, our database host (Supabase), the AI provider that reads a creator’s own posts to draft recipes from them (Anthropic), the push notification service that delivers notifications to your phone using a device token and the text of the notification (Expo), payment processors (Stripe, and the Apple App Store and Google Play for in-app purchases), subscription-management provider (RevenueCat), email delivery provider (Resend), and payout provider (Tremendous). These providers are contractually obligated to protect your information and may only use it to provide services to us.
- Legal requirements: We may disclose your information if required to do so by law, court order, or valid governmental request, or to protect the rights, property, or safety of Mealio, our users, or the public.
- Requests from public authorities: When a government agency, court or other public authority asks us for information about a user, we review whether the request is lawful and valid before responding, and we challenge any request we consider unlawful, overly broad or not properly served. Where we must respond, we disclose only the minimum information the request legally requires. We keep a record of every such request, how we responded and the legal basis for that response.
- Business transfers: If Mealio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information becomes subject to a different privacy policy.
- With your consent: We may share your information for any other purpose with your explicit consent.
4. Data Retention
We retain your account information for as long as your account is active or as needed to provide the Service. Authentication log data (IP addresses, user agents) is retained for up to 90 days for security purposes. Meal and recipe data is retained until you delete it or close your account. If you close your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or financial compliance purposes.
5. Data Security
We implement industry-standard technical and organizational security measures to protect your information, including:
- Passwords are hashed and never stored in plain text;
- Authentication tokens are signed with a secret key and expire automatically;
- One-time login codes and device-trust tokens are stored as SHA-256 hashes;
- Session cookies are HTTP-only and not accessible by JavaScript;
- All data in transit is encrypted using TLS/HTTPS;
- Database access is controlled via row-level security policies.
No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Grocery Store Access
To add ingredients to your cart, Mealio interacts with grocery store websites on your behalf. How this works depends on where you shop:
- Connected store accounts (web): You authorize Mealio through the store's own sign-in. Mealio uses that authorization solely to search products and add items to your cart. We never receive your store password.
- Other stores (mobile app): The Mealio app opens the store's website in a secure in-app browser where you log in directly with the retailer. Mealio reads product names and page elements only to locate items and complete the cart additions you initiate. This data is used locally to perform the action and is never transmitted to our servers.
Mealio does not monitor your general browsing activity, track websites unrelated to the Service, read or store the contents of grocery pages beyond what is necessary to fill your cart, or transmit your grocery account credentials to our servers.
7. Creator Platform Connections (YouTube, Instagram and TikTok)
If you are a creator, you may connect a platform account so that Mealio can find recipes you have already published and prepare them for your review. This section describes what that connection allows, and applies in addition to the rest of this policy. Connecting an account is entirely optional. Creators who do not connect one publish to Mealio by hand, and nothing described here happens to them.
- What we access: With your authorization, Mealio reads the list of videos on the YouTube channel you connect, together with each video’s title, description, publication date and thumbnail. If, when you connect, you also allow Mealio to read your captions, then for a video whose description is too short to hold a recipe we also download that video’s captions (its transcript) and read them together with the description. We use these to identify posts that contain recipes and to extract the ingredients and steps from them. To do that, the title, description and any captions we read are sent to our AI provider (Anthropic), which processes them on our behalf to produce the draft. We only ever read the channel you connected.
- What we do with it: An extracted recipe becomes a draft that is shown to you for approval. Nothing extracted from your channel is published on Mealio until you, or an administrator acting on your behalf, approves it. Drafts you decline are not published.
- What we write, and only if you ask: Mealio can add a link to your Mealio recipe page at the end of the description of the video that recipe came from. This is a setting that is off unless you turn it on, it is offered only to creators who have connected a YouTube channel, and it applies only to videos on that channel. We append our link and do not remove or alter anything else in your description. Turning the setting off stops any further changes.
- What we never do: We do not use data obtained from your channel for advertising, we do not sell or transfer it, we do not use it to train machine-learning or AI models, and we do not read, collect or store anything from YouTube beyond what is needed to produce the recipe drafts described above and, where you have enabled it, to append the link.
- Stopping and removing it: You can disconnect the account at any time from your creator settings, which stops all reading immediately. You can also revoke Mealio’s access directly through your Google Account permissions page. On disconnection we delete the access and refresh tokens we hold for that account.
Mealio’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.
Instagram
- What we access: With your authorization, and only for an Instagram professional (Business or Creator) account, Mealio reads your account’s ID, username and account type, and the list of posts on that account together with each post’s caption, media type, link, publication time, media address and, for a video or a carousel, its cover image and the addresses of its items. We use these to identify posts that contain recipes, to extract the ingredients and steps from the caption, and to take the post’s picture as the photo for the recipe. We only ever read the account you connected, and we ask Instagram for read access only.
- What we do with it: The same as for YouTube above. An extracted recipe becomes a draft that is shown to you for approval, and nothing is published on Mealio until you, or an administrator acting on your behalf, approves it. We also copy the picture of the post the recipe came from — the photo itself, or the cover image of a video or a carousel — and save it on Mealio as that recipe’s photo, because the address Instagram gives us expires within hours and would otherwise leave the recipe with a broken picture. We copy no other photos or videos, and never the video file itself. You can change that photo, or clear it, when you review the draft and at any time afterwards from your creator portal. Clearing it takes the picture off the recipe; the copy itself stays in our storage, and is deleted when you delete your Mealio account.
- What we never do: Mealio never posts, comments, sends messages or changes anything on your Instagram account. We do not use data obtained from Instagram for advertising, we do not sell or transfer it, and we do not use it to train machine-learning or AI models.
- Stopping and removing it: You can disconnect Instagram at any time from your creator settings, which stops all reading immediately and deletes the access token we hold. You can also remove Mealio in the Instagram app under Settings, Apps and websites. Your use of Instagram is also governed by the Instagram Terms of Use and Meta Privacy Policy.
TikTok
- What we access: With your authorization, Mealio reads the list of videos on the TikTok account you connect, together with each video’s ID, title, description, duration, cover image, share and embed links and publication time, plus the account’s own ID. We use these to identify videos that contain recipes and to extract the ingredients and steps from them. We only ever read the account you connected, and we ask TikTok for read access only.
- What we do with it: The same as for YouTube and Instagram above: an extracted recipe becomes a draft for your approval, and nothing is published without it.
- What we never do: Mealio never posts, comments or changes anything on your TikTok account. We do not use data obtained from TikTok for advertising, we do not sell or transfer it, and we do not use it to train machine-learning or AI models.
- Stopping and removing it: You can disconnect TikTok at any time from your creator settings, which stops all reading immediately and deletes the access and refresh tokens we hold. You can also remove Mealio in the TikTok app under Settings and privacy, Security and permissions, Manage app permissions.
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to our legal retention obligations.
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your information in certain circumstances.
To exercise any of these rights, contact us at contact@mealio.co. We will respond within 30 days.
How to delete your data
You can do this yourself, at any time, without contacting us. There are two different things you may want, so both are listed.
- Delete your whole Mealio account. Open Account in the app or on the website, choose Delete Account, and type Delete Account to confirm. This immediately and permanently removes your profile (your email address, name and password), your saved meals, any meals you published as a creator, your creator application and creator profile, any Instagram, YouTube or TikTok connection and the access tokens we held for it, who you follow, your remembered devices, any one-time codes, and the photos you uploaded. It cannot be undone. If you pay for Mealio on mealio.co, that subscription is cancelled when you delete your account. A subscription you bought in the app through the App Store or Google Play is not, because only Apple or Google can cancel it: cancel it in your App Store or Google Play subscription settings.
Some records are kept after deletion. None of them contain your email address or name:- Billing records. Your subscription and payment history (dates, amounts, currency and plan) is kept for legal, tax and accounting reasons. Stripe, Apple and Google also keep their own records of your payments under their own privacy policies.
- Anonymous usage records. Which recipes from Discover you saved and when, when you opened the app or website, and your cart runs (the store, how many items were added, whether it worked, and technical details such as the app version). We also keep a short summary of the account: when you signed up, your plan, when you subscribed, which creator’s link you signed up through (if any) and when you deleted it. These records help us count things like how many people keep using Mealio and how creator profit share is paid.
- Our log of emails we sent you, with your email address removed, so it can still be counted.
The billing and usage records are linked only to a random account number, which after deletion no longer connects to your email address, name or anything else that identifies you.
If you were a creator, copies of your recipes that other people saved to their own accounts belong to them and stay there, which can include your creator name and a photo you uploaded. Any photo of yours that someone else’s meal still shows is kept for as long as it does. - Disconnect a linked account and keep your Mealio account. If you connected Instagram, YouTube or TikTok as a creator, open the creator portal, find that connection and choose Disconnect. This deletes the access token we stored for it, so we stop reading anything from that platform. Recipes you already published on Mealio stay; delete them individually, or delete your account, if you want them gone too.
- One thing disconnecting cannot undo. If you asked Mealio to add a link to a YouTube video’s description, that edit is on your video and stays there, and we cannot un-tell anyone who has already read it. You can remove it yourself in YouTube Studio at any time.
- If you cannot sign in, or you want something the steps above do not cover, email contact@mealio.co from the address on the account and we will delete it for you.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at contact@mealio.co.
10. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer. We take steps to ensure that any such transfers comply with applicable data protection requirements.
11. Cookies and Local Storage
We use HTTP-only cookies to maintain your authenticated session on the website. These cookies are strictly necessary for the Service to function and cannot be disabled without logging out. We do not use advertising cookies or third-party tracking cookies. The mobile application stores your authentication tokens in the device's secure storage (the iOS Keychain on iOS, or the Android Keystore on Android).
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new effective date and, where appropriate, by sending an email to the address associated with your account. We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy, please contact us at:
Mealio LLC
1800 Heatherglen Ln
Austin, TX 78758
contact@mealio.co