MealLuma Privacy Policy

MealLuma uses OpenAI for Photo recognition and unresolved Photo or Describe nutrition. Requests set store:false; the current Photo path does not save new meal images in MealLuma storage.

What We Collect

If you sign in with Apple, we collect that account identifier plus any Apple email or display name you choose to share. We also store subscription status. We store a device push token only if you opt into a feature that requires server-delivered notifications.

To calculate general tracking references, you may provide profile details such as sex, age, height, weight, goal, activity level, and cuisine preferences. You may also save an optional protein-first display preference. You can edit these details; deleting your account removes them.

We store the resulting meal records you save, including dish and component names, estimated or edited nutrition, meal time, correction memories, and favorite status. These records support your history, streaks, weekly recaps, and trends.

A Photo upload is held in request memory while it is processed. The current synchronous Photo path does not write new meal images to MealLuma storage. If you accept the result, the nutrition record remains in your log without the image.

How Meal Inputs Are Used

For Photo analysis, the meal image and any optional dish hint you enter are uploaded over an encrypted connection and sent to the OpenAI API for food recognition. Recognized components that cannot be resolved from a complete saved correction or a verified catalog match are then sent as text and portion context to OpenAI for nutrition estimation.

For Describe analysis, complete saved corrections and verified catalog matches are resolved on MealLuma's service first. Only unresolved description or component text and portion context are sent to the OpenAI API. Describe does not upload or create a meal photo. The estimate is held temporarily as a draft and added to your saved history only when you accept it.

Both OpenAI meal requests set store:false. MealLuma does not include your MealLuma account identifier, Apple identity or email, profile, weight, goal, activity level, protein-first display preference, meal history, or saved correction state in those provider requests.

Nutrition Label OCR runs on your device. The label values you confirm can be sent to MealLuma to save the meal, but the label image and OCR task are not sent to OpenAI.

For an exact barcode fallback, MealLuma may query Open Food Facts using only the barcode and a service-level request header. No MealLuma account identifier, profile, or meal history is included in that lookup.

When you log a catalog food, MealLuma receives the selected catalog ID, grams, and meal time. Pinned USDA rows are resolved and calculated on MealLuma's service without an OpenAI request. An Open Food Facts catalog ID may trigger the same exact-barcode lookup described above; client-supplied calories, confidence, and provenance are not trusted for this path.

Estimates are produced automatically and are approximate by nature — you can correct any of them.

OpenAI Data Controls

The store:false setting means MealLuma does not opt the response into OpenAI's stored-completion, distillation, or evaluation features; it does not override separate abuse-monitoring retention. OpenAI states that API data is not used to train its models by default, but its abuse-monitoring logs may retain content, including prompts, responses, and images, for up to 30 days unless a different approved data-control arrangement applies.

Retention And Deletion

MealLuma does not retain new Photo uploads in its own storage after the current request finishes. OpenAI's separate abuse-monitoring retention is described above. Typed descriptions and the resulting dish, nutrition, favorite choice, and other saved meal details stay in your log until you delete the meal or your account.

Profile details, correction memories, and cached weekly recaps remain while your account is active unless you edit, clear, or replace them through the app.

When an in-app account-deletion request succeeds, it has completed permanent removal of your photos, meal logs, profile, and account record from our systems. A minimal cryptographic deletion receipt (the deleting session pseudonym and a one-way refresh hash) may remain solely to recover a lost success response; it is usable only during the original 60-day refresh lifetime, is scheduled for automatic deletion at the session's 67-day storage-cleanup mark, and cannot restore the account or access deleted data. If an infrastructure step fails, the account stays disabled and the deletion can resume safely instead of reporting false completion.

Limited pseudonymous product and reliability events expire automatically within 90 days. They are not used for advertising and may remain until that expiry after account deletion.

Your Health Data

Details like your weight, goal, and activity level are used to compute general tracking references and personalize app features. They and the optional protein-first display preference are stored against your MealLuma account, are not sold or used for advertising, and are not included in OpenAI meal requests or Open Food Facts barcode lookups.

Apple Health sync is off by default. If you enable it in Settings and grant permission, MealLuma writes estimated dietary energy, protein, carbohydrate, and fat for your logged meals to Apple Health. MealLuma does not request read access, and you can turn sync off at any time.

No Tracking

MealLuma has no third-party advertising, no tracking SDKs, and does not sell your data. We use your data only to run the service, process purchases, provide support, and prevent abuse.

Contact

Email nora@halehearth.com.