Privacy Policy
Food My Way is currently in private beta. Most recipe and diary information is stored locally on your device unless you choose to use an enabled cloud-account feature.
Information stored on your device
The app uses browser storage to remember recipes, ingredient swaps, food-diary entries, preferences, and beta-interest information you choose to enter. This information may be erased if you clear browser data, remove the app, or change devices.
Founding list and email choices
If you join the founding list, Food My Way stores your email address, signup source, consent status, and related timestamps so we can send the updates you requested. You can unsubscribe through a link in those emails or contact support. We retain this information until you unsubscribe, request deletion, or it is no longer needed for founding-launch communications.
Cloud accounts
If cloud accounts are enabled and you choose to use one, Food My Way stores your normalized email address, hashed one-time login and session credentials, and related challenge, session, and revision timestamps. Raw login and session credentials are not stored. If you explicitly back up your app data, the cloud snapshot contains only supported Food My Way data, such as recipes, preferences, meal plans, grocery items, and diary entries, and is subject to size limits.
Information you choose to share
When you create a recipe-sharing link, the recipe data is encoded in that link. Anyone who receives the link may be able to read and save the recipe. Do not include confidential, medical, or personally identifying information in recipe names or ingredients.
First-party product analytics
When analytics is enabled, Food My Way records a temporary random session identifier, the page path, and limited events such as recipe generation, saving, planning, installation, checkout starts, and generic error categories. Analytics deliberately excludes recipe names, ingredients, diary entries, email addresses, error messages, and full shared links. The session identifier is kept in session storage and is not an advertising identifier. Product events are intended to be deleted after 90 days.
Service providers
Cloudflare provides hosting, network security, serverless processing, and database infrastructure. Resend delivers passwordless login emails when cloud accounts are enabled and may deliver founding-list updates when that email program is configured. Stripe processes checkout, payment, and transaction information.
If grocery ordering is enabled and you select “Shop ingredients,” Food My Way sends the grocery item names and quantities you selected to Instacart to create a hosted shopping link. Instacart handles the resulting cart, product availability, substitutions, retailer selection, pickup or delivery, payment, and its own account experience under its policies.
Payments
Payment details are collected and processed by Stripe. Food My Way does not store complete payment-card numbers. We retain limited transaction and access records for fulfillment, refunds, disputes, accounting, and legal obligations.
Children
Food My Way is designed for use by adults and families. It is not directed to children under 13, and children should not submit personal information directly to the service.
Health information
Food preferences, recipes, and nutrition entries can be sensitive. The beta is not designed to store medical records, diagnoses, allergy treatment plans, or other protected health information. Do not rely on the app as a substitute for medical advice or emergency care.
Your choices
You can export or remove locally stored information through the app’s controls, or remove it by clearing site data in your browser. When cloud accounts are enabled, the account controls let you export your cloud snapshot or delete the account and its stored snapshot. You can unsubscribe from founding-list emails through the link in those messages or by contacting support.
Security and retention
We use reasonable safeguards appropriate to the service. No electronic system can guarantee absolute security. Local beta data remains until you delete it or your browser removes it. Login challenges expire after 15 minutes and account sessions after 30 days. Product analytics events are deleted after 90 days. Founding-list records are retained as described above. Limited payment, refund, and entitlement records may be retained as needed to provide access, handle refunds and disputes, maintain accounting records, and meet legal obligations.
Changes
We may update this policy as features and vendors change. The effective date above will be revised when material updates are made.
Contact
Privacy questions may be sent to [email protected].