PRIVACY POLICY
Effective as of July 08, 2026
Last updated September 10, 2026
MealLens Inc. (doing business as MealVue) ("MealLens", "MealVue", "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy ("Policy") describes how we may collect, use, or disclose your information in the course of your use of our products, applications, services, and website (collectively, the "Services"), and describes the types of information we may collect from you or that you may provide to us when you access or use our services.
This Policy may change from time to time.
Reading this Policy will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, do not download, register with, or use our Services. By downloading, registering with, or using our Services, you indicate that you understand, accept, and consent to the practices described in this Policy.
If you have any questions, please contact our Privacy Officer.
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE USE YOUR INFORMATION?
- WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
- HOW DO WE DISCLOSE AND SHARE INFORMATION?
- DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
- COMMUNITY AND USER CONTENT
- IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
1. WHAT INFORMATION DO WE COLLECT?
User Consent: By providing personal information during account creation and implementation of our Services, you agree to the terms of this Policy and you freely and expressly consent to the collection, use, and disclosure of your personal information in accordance with this Policy.
Types of Information We Collect: We collect different types of information that is reasonably required to provide our Services and to help us provide, improve, and personalize our services. Our collection of personal information is limited to that which is reasonably required to provide our Services.
How We Collect Information About You: We collect information from users through a variety of methods, both directly and automatically, depending on how you interact with our applications or website and the Services you request.
The table below describes the categories of information that we may collect, a description of the information, and the source of the information. We aim to be as complete and transparent about our information collection practices as possible.
| Category | Description | Source |
|---|---|---|
| Account Information | Your name, e-mail address, username, password (which we store only in hashed form), and the public community username you choose. | You |
| Profile and Food Data | Your dietary preferences, food allergies and dietary restrictions, preferred cuisines, default serving size, and the country you select in Settings. Food Data may include sensitive personal information when it indicates or allows someone to infer a health condition (for example a celiac or food-allergy restriction) or religious beliefs (for example a Halal, Kosher, or Jain dietary preference). |
You |
| Kitchen and Shopping Data | The food inventory you enter or scan (item, quantity, storage location, expiry date); your shopping list; your acquisition history, meaning what entered your kitchen, when, and how it arrived (barcode, receipt or photo scan, or manual entry) and whether it came from your shopping list; your meal plans, cooking history and saved recipes; the food-consumption decisions you record in the daily check-in (used, skipped, or muted items); and recipes you import from web pages you choose. This is a record of what you buy and use, built from your own entries and scans. We never ask for or store payment-card details. When you scan a receipt, the store name and prices printed on it are part of the photograph we process and are shown to you on the review screen, but only the item names and quantities you confirm are saved to your account. |
You |
| Photographs and Scans | Photographs you take, or choose from your photo library, of your fridge, pantry, groceries, receipts, and cooked dishes, so that we can recognise ingredients, read receipts, and identify dishes; the barcodes you scan (barcodes are decoded on your device and only the number is sent to us); and photographs you attach to your recipes or community posts. | You |
| Voice Input | If you choose to add items or search by voice, the audio is converted to text by your device platform's speech service (Apple or Google) and the resulting transcript is used to fill in the field you were dictating into. Hands-free cooking commands ("next", "repeat", and similar) are recognised entirely on your device; that audio is not transmitted to us or to anyone else and is not stored. | You |
| AI Interaction Data | The text you type to our AI features (for example, the Fantasy Chef recipe chat and the in-app AI Assistant), the AI-generated recipes you save, and a per-account record of which AI features you used, when, and the processing cost to us (see Section 5). | You, and automatically |
| Sign-in Provider Data | If you choose to sign in with Apple or Google, we receive the name and e-mail address (or, for Apple, the private relay address you choose to share) that the provider shares with us, and we store them with your account. The provider's account identifier is contained in the sign-in token we verify but is not retained. | You and third-party sources |
| Website Data | Our marketing website (mealvue.com) does not use analytics or advertising cookies; it stores only display preferences (such as theme and language) in your browser. The hosting and content-delivery providers for the website may keep standard server logs, such as your IP address, the pages requested, the time of the request, and your browser type. | Third party sources |
| Technical and Usage Data | Our servers automatically collect service-related, diagnostic, usage, and performance information when you access or use our Services. We record such information in log files. Depending on how you interact with us, this may include, for example, your login information, time zone setting, operating system and platform, device hardware details, the app's network user-agent string, usage details (such as which features you use and the searches you run), your IP address, and device event information (for example, system activity, error and crash reports, and hardware settings such as memory and screen size). | Third party sources |
| Communications | Information about you that you give us by communicating with us by phone, e-mail, via our website, via social media, or otherwise. | You |
| Statistical or Aggregated Information | Non-personal information that does not directly or indirectly reveal your identity or directly relate to an identifiable individual. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. Statistical or aggregated data does not, by itself, permit the identification of individual persons. | Third party sources |
| Device Data | Information about the phone or tablet you use to access the Services. Depending on the device, this may include information such as your IP address or proxy server, device and application identification numbers (including an app-installation identifier used for crash reporting), hardware model, operating system and version, and system configuration information. | Third party sources |
| Mobile Device Data | Information such as mobile device identifiers (an operating-system build identifier and an app-installation identifier), device model and manufacturer, operating system name and version, system configuration (time zone, locale, memory), app version and build number, and IP address. We may also collect information about the features of our applications you accessed. When you create a guest account (without registering), the app sends your device's brand, model, name, type, manufacturer, operating-system name and version, app version and build, time zone, locale, total memory, whether it is a physical device, and an operating-system build identifier. We store the brand, model, platform, operating-system version, and build identifier with the guest account; the rest is written to our server logs only. The guest account's display name is built from your device's brand and model plus its platform and operating-system version (for example "Guest (Apple iPhone 15) ios 18.0"). |
Third party sources |
| Mobile Device Access | We may request access or permission to certain features of your mobile device, including your mobile device's camera (to scan barcodes and take photographs), microphone and speech recognition (for voice input and hands-free cooking commands, as described above), and photo library (to choose existing photographs). We do not request access to your location, contacts, calendar, or Bluetooth. If you wish to change our access or permissions, you may do so in your device settings. | You |
| Location-related Data | We do not collect GPS location, and we do not derive your location from your IP address. The only location-related information held on your account is the country you select yourself in Settings and, unless you switch off "Timezone Sharing" (which is on by default), your device's time zone, which our recipe recommendations use to tell what time of day it is for you. In-app reminders are scheduled on your device using its own clock. If you continue as a guest, the app also sends your device's time zone and language/region setting once at sign-in; these are written to our server logs but are not stored in your account. | You |
Information That We Collect Automatically
Website. Our marketing website (mealvue.com) does not currently use analytics or advertising cookies or other tracking technologies; it stores only your display preferences (such as theme and language) in your browser. The hosting and content-delivery providers for the website may keep standard server logs (IP address, pages requested, time of the request, and browser type). If we introduce cookies or analytics on the website in future, we will update this Policy and, where required, ask for your consent first.
App. Usage information collected automatically when you use the App includes a device identifier, an app-installation identifier, the settings and preferences you choose in the Services (such as time zone, locale, and country), the features you use and the searches you run, and your IP address. We do not use third-party analytics or advertising SDKs in the App.
Derived Information: From your Kitchen and Shopping Data we derive habits such as how often you re-buy or use up a particular item and how often you shop. We also record which restock suggestions we showed you, whether you accepted or dismissed each one, and the information we used to rank them. We use this to improve the suggestions we make to you, and we retain it so that we can improve our suggestion models over time.
Google API Services Data: We may also collect information received from Google API Services. Our use will adhere to the Google API Services User Data Policy, including the Limited Use Requirements.
2. HOW DO WE USE YOUR INFORMATION?
In general, personal information you submit to us is used either to respond to requests that you make, or to aid us in serving you better. The table below describes how we may use your information, the type of information, and the manner(s) in which it is used. Our use of personal information is limited to the purposes described in this Policy.
| Use | Type of Information | Basis |
|---|---|---|
| To create and secure your account for our services. | Account Information; Sign-in Provider Data | Performance of the requested Services. |
| To provide the core features of the Services: tracking your food inventory and expiry dates, searching and scaling recipes, planning meals, and keeping your shopping list. | Profile and Food Data; Kitchen and Shopping Data; Photographs and Scans; Voice Input | Performance of the requested Services. |
| To provide AI-powered features: recognising ingredients in photographs, reading receipts, identifying dishes and generating recipes, importing recipes from web pages you choose, extracting items from text you type, paste, or dictate when adding to your inventory, matching scanned or typed item names to our ingredient catalogue, narrating recipe steps aloud, and answering questions through the AI Assistant and Fantasy Chef. | Photographs and Scans; AI Interaction Data; the names of items identified from your scans and the text you enter into an AI feature (Profile and Food Data saved on your account does not reach AI features) | Performance of the requested Services; your consent, where sensitive information is involved. |
| To make suggestions and recommendations to you about recipes to cook and items to restock, and to retain the outcomes of those suggestions so that we can improve the models that produce them. | Kitchen and Shopping Data; Profile and Food Data; Derived Information | Necessary for our legitimate interests (to develop our services and grow our business). |
| To operate the community: display your public profile and the content you publish, enforce our community rules, and act on reports, blocks, and bans. | Account Information; content you publish (see Section 6) | Performance of the requested Services; necessary for our legitimate interests (to keep the community safe). |
| To manage our relationship with you, which may include: providing our services to you; administering your account with us; notifying you about changes to our terms and privacy policy. | Account Information; Communications | Performance of the requested Services. Necessary to comply with a legal obligation. Necessary for our legitimate interests (and to keep our records updated and study how you use our Services). |
| To administer and protect our business and services (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data), to protect the Services (for example, rate-limiting sign-in and account-creation attempts by IP address), and to attribute and limit usage of AI-powered features, including across guest sessions on the same device. | Account Information; Technical and Usage Data; Device Data; Mobile Device Data | Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and abuse). Necessary to comply with a legal obligation. |
| To manage the cost of our AI features: recording, per account, which AI features were used, when, and what they cost us, so that we can apply fair-use limits. | AI Interaction Data | Necessary for our legitimate interests (to run our business sustainably). |
| To diagnose problems and improve the App's features and recommendations, using crash and error reports, a small sample of performance traces and masked session replays (via Sentry), and in-app usage data (for example which suggestions you open or cook). We do not use third-party analytics or advertising SDKs. | Technical and Usage Data; Communications; Statistical or Aggregated Information | Necessary for our legitimate interests (to keep the Services working and improve them). |
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
If you are located in the European Union (EU) or United Kingdom (UK), this section applies to you.
The EU General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your information. There are several different legal bases for processing your information under the GDPR. The applicable bases depend on how we process your information and for what purpose.
We may rely on the following legal bases to process your personal information:
- Consent: We may process your information if you have freely and unambiguously given us your informed consent to use your personal information for a specific purpose. You can withdraw your consent at any time.
- Performance of a Contract: We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests: We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Analyze how our services are used so that we can improve them to engage and retain users; and
- Diagnose problems or prevent fraudulent activities.
- Legal Obligations: We may process your information when we believe it is necessary to comply with our legal obligations, such as cooperating with a law enforcement body or regulatory agency, exercising or defending our legal rights, or disclosing your information as evidence in litigation in which we are involved.
- Vital Interests: We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as in situations involving potential threats to the safety of any person.
If you are located in Canada, this section applies to you.
We may process your information if you have given us express consent to use your personal information for a specific purpose, or in situations where your consent can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way;
- For investigations and fraud detection and prevention;
- For business transactions provided certain conditions are met;
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim;
- For identifying injured, ill, or deceased persons and communicating with next of kin;
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse;
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province;
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records;
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced;
- If the collection is solely for journalistic, artistic, or literary purposes;
- If the information is publicly available and is specified by the regulations; and
- For approved research or statistics projects subject to ethics oversight and confidentiality commitments. We may disclose de-identified information for such projects.
4. HOW DO WE DISCLOSE AND SHARE INFORMATION?
We may disclose the personal information collected from you with individuals or organizations who are our service providers, advisors or consultants when necessary to provide the requested Services. We may disclose aggregated data and information that does not identify any individual, without restriction.
We may disclose personal information that we collect or you provide as described in this Policy:
- To our current and future business partners, subsidiaries, and affiliates.
- In accordance with applicable law in the context of a business transaction such as the purchase, sale or other acquisition, or disposition of our organization in whole or in part, a merger or amalgamation, or a financing, leasing or licensing, both for the purpose of evaluating the transaction and carrying out the transaction if finalized.
- In accordance with applicable law, to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our organization's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our customers and users is among the assets transferred.
- To contractors, service providers, and other trusted third parties who help us operate, improve, and optimize our services (e.g., analytics providers or search engines), and are contractually required to keep your information confidential, use it only for the purposes we specify, and handle it in accordance with the terms outlined in this Policy.
- To fulfill the purpose for which you provide it.
- For any other purpose disclosed by us when you provide the information.
- With your consent.
Vendors, Consultants, and Other Third-Party Service Providers: We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
Third-Party Service Providers: The table below describes the categories of third parties that we may engage, as well as a non-exhaustive list of specific third parties.
| Type of Third-Party Service Provider | Description | Third Party (as applicable) |
|---|---|---|
| AI Platforms | Providers that provide AI tools necessary for the purposes outlined in this Policy. See Section 5 for what each feature sends. | OpenRouter — the service through which most of our requests to AI language and vision models are routed. It receives the food photographs, receipt images, dish photographs, and text you submit to our AI features, and forwards them to the model provider — currently OpenAI, Google Gemini, and Anthropic Claude models and, for web-page recipe import, an open-weight model hosted by a provider chosen by OpenRouter. Where recipe generation uses web-search grounding (on by default), the dish name, cuisine, appearance description, and the ingredients identified in your photograph (not the photograph itself) are sent with OpenRouter's web-search option enabled, and OpenRouter performs the search through its own search provider. United States. OpenAI — called directly for ingredient and dish matching (text embeddings of item names identified from your scans or typed lists, and of dish descriptions), for spoken recipe narration (the text of each recipe step is converted to speech), and by the AI Assistant to search our help documentation (a text embedding of your question). United States. Replicate — generates the illustrative dish image for recipes created by Fantasy Chef, from the generated recipe text. United States. Apple and Google speech services — when you add items or search by voice, the audio and transcript are processed by your device platform's speech service. |
| Cloud Hosting and Infrastructure | Providers that host our platform, store data, and deliver computing, networking, and security infrastructure necessary for the operation of our Services. | Amazon Web Services (AWS) — EC2, RDS (database), S3, CloudFront, Systems Manager, and Simple Email Service (SES). Hosts the application servers, the AI Assistant, Fantasy Chef, and all user account data. United States (us-east-1 / us-east-2). Images are delivered through Amazon CloudFront, a content-delivery network that may cache copies at edge locations outside the United States. DigitalOcean — hosts our receipt-photo analysis service (United States) and our marketing website (Canada). Fridge and pantry photographs are sent to our AWS-hosted application server, not to DigitalOcean. Cloudflare — authoritative DNS for mealvue.com. Visits to the marketing website (www.mealvue.com) are routed through Cloudflare's proxy network; App and API traffic is not proxied through Cloudflare. Expo (Expo Application Services / EAS Update) — hosting and delivery of over-the-air application updates. |
| Payment Processors | Providers that process subscription fees, billing information, and payment transactions. | None at present. All features of the App are currently free and no payment information is collected. If and when we introduce paid subscriptions, purchases will be processed by Apple through the App Store, using RevenueCat, a subscription-management provider that would receive your app user ID and purchase/entitlement status (but not your payment-card details, which Apple handles), and we will update this Policy before doing so. |
| Performance Monitoring Tools | Providers that assist us in understanding usage patterns, monitoring system performance, diagnosing technical issues, and improving our Services. | Sentry (Functional Software, Inc.) — crash reporting, error and performance monitoring, and mobile session replay: a random sample of about 10% of app sessions, plus any session in which an error occurs, is recorded with all on-screen text, images, and graphics masked. United States. Expo (EAS Update) — each time the App launches and checks for an update, Expo receives the platform, the App's runtime version and current update identifiers, a random per-install identifier that is not linked to your account, and, only if the previous launch crashed, a short error message. |
| User Account Registration and Authentication Services | Providers that assist with managing user authentication, access control, and security verification. | Apple — Sign in with Apple. Google — Google Sign-In. Amazon Web Services (Amazon SES) — delivery of password-reset and account-related emails. Apart from the optional Sign in with Apple and Sign in with Google options, which are used to verify your identity and share your name and e-mail address with us at sign-in, no third-party identity or authentication platform is used: your account, credentials, and sessions are created and managed by MealLens on its own servers. |
| Customer Support and Communication | Providers that facilitate customer support, ticketing, live chat, email communications, and notifications. | Zoho Corporation (Zoho Mail) — hosts our support@mealvue.com mailbox and therefore receives any correspondence users send to us. Canadian data centre. Amazon Web Services (Amazon SES) — outbound transactional email (password resets, account-deletion notices). MealLens does not use a third-party helpdesk, ticketing, live-chat, or marketing-email platform. User support is provided by e-mail (support@mealvue.com), by phone (+1 647 830 7080), and through our website (mealvue.com), as listed in the App's Help & Support screen. The in-app AI Assistant is an AI feature operated by MealLens and is described in Section 5; it is not a support channel. In-app reminders are scheduled locally on your device rather than sent from our servers. We do not collect push tokens and we do not use a third-party push-messaging platform. |
| Websites You Ask Us to Import From | When you paste a link to a recipe, our server retrieves that web page on your behalf. | The operator of the website you name sees a request originating from our infrastructure, not from your device. If the page does not carry usable structured recipe markup (schema.org Recipe data), the page's main text (up to about 12,000 characters, with scripts, navigation, and forms stripped) is sent to OpenRouter to extract the recipe. We do not fetch pages behind logins and we reject certain sites we cannot read reliably. |
| Legal, Compliance, and Security | Third parties that support compliance efforts, auditing, fraud prevention, data protection, and legal obligations. | Our external legal counsel, accountants, and other professional advisers, engaged on a confidential basis. Amazon Web Services — security and access-control infrastructure (IAM, VPC security groups, Systems Manager; also listed under Cloud Hosting and Infrastructure above). Apple and Google — platform-level application review and fraud/abuse controls. Content moderation, profanity filtering, age self-certification (you confirm you are 18 or older; we do not verify your age), and abuse prevention are performed in-house by MealLens. No third-party moderation, compliance, or security-audit vendor is currently engaged. |
Public Areas and Other Users: When you share personal information (for example, by posting comments, contributions, or other content to the Services) or otherwise interact with public areas of the Services, such personal information may be viewed by all users and may be publicly made available outside the Services in perpetuity. Other users can see your community username (or, if you have not chosen one, your account username, which for Apple or Google sign-ins is derived from the part of your e-mail address before the @), your post count, your follower and following counts and lists, and the posts, comments, recipes, and photographs you publish. Other users can interact with you by commenting on or replying to your posts and comments and by following you; these interactions are public, and the App has no private messaging. Section 6 describes the community in detail. The Apple and Google sign-in integrations receive only what is needed to sign you in; we do not send information about your activity within the Services to Apple or Google through them. Please note that we do not control, and are not responsible for, other uses of your personal information by your sign-in provider. We recommend that you review their privacy policy to understand how they collect, use, and share your personal information.
Disclosing Information without Consent: There are some circumstances where we may disclose personal information without consent. Such circumstances include where we:
- are permitted or required by law, including by order of a court or tribunal;
- believe, upon reasonable grounds, that it is necessary to protect the safety of an identifiable person or group;
- believe it is necessary to establish or collect fees;
- believe it necessary to permit us to provide approved services, pursue or investigate available remedies (including legal remedies through a civil or criminal court process), or limit any damages that we may have or are likely to sustain;
- believe the information is public; and
- are otherwise permitted by law.
We may disclose personal information when required to by law, for instance in response to a court order, subpoena, search warrant, government investigation, or other legally valid inquiry or request. We may also disclose personal information where permitted by law, such as to our lawyers, accountants, auditors, and agents in order to enforce or protect our legal rights, or to law enforcement agencies in an emergency or in connection with activities that we believe to be unlawful.
Where obliged or permitted to disclose information without consent, we will not disclose more information than is required. We retain the right to use de-identified or aggregated information in any way that it determines appropriate.
Withdrawing Consent: Where you have provided your consent to the collection, use, and transfer of your personal information, you may have the legal right to withdraw your consent under certain circumstances. You may withdraw your consent at any time by contacting the Privacy Officer listed below. Reminder notifications can be turned off in the App's Settings or in your device settings. We currently send only transactional e-mails (password-reset codes and account-deletion notices), which are necessary to operate your account and do not carry an unsubscribe link.
Please note that if you withdraw your consent we may not be able to provide you with a particular product or service. We will explain the impact to you at the time to help you with your decision.
5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Policy govern your use of the AI Products within our Services.
Use of AI Technologies
We provide the AI Products through third-party service providers ("AI Service Providers"), namely OpenRouter (which routes our requests to OpenAI, Google Gemini, and Anthropic Claude models), OpenAI, Replicate, and the speech-recognition services of Apple and Google. As outlined in this Policy, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.
Our AI Products
Our AI Products are designed for the following functions:
- Ingredient recognition — identifying the food items in a photograph of your fridge, pantry, or groceries (photograph → OpenRouter).
- Receipt reading — extracting the purchased items from a photograph of a grocery receipt (photograph → OpenRouter).
- Dish identification and recipe generation — identifying a cooked dish from a photograph (photograph → OpenRouter, which names and describes the dish). If you then choose to have a recipe written — an option offered whether or not we already have a matching recipe — the dish name, that description, the cuisine, and the ingredients the model saw in the photograph (not the photograph itself) are sent to OpenRouter, which may use web search to look up how the dish is made.
- Recipe import — extracting a recipe from a web page you paste a link to, when the page has no structured recipe markup (page text → OpenRouter).
- Fantasy Chef — a conversational chef that invents fusion recipes from the preferences you type into the chat (conversation text → OpenRouter), and illustrates the saved recipe with a generated image (recipe text → Replicate).
- Spoken recipe narration — reading recipe steps aloud in a natural voice (recipe step text → OpenAI text-to-speech). Recipe text is not personal to you; the audio is cached and reused for all users of that recipe.
- Ingredient matching — matching the names of scanned or typed items to our ingredient catalogue (item names and search terms → OpenAI text embeddings).
- Grocery list parsing — turning a free-text or dictated list of groceries into inventory items (the text you enter → OpenRouter).
- AI Assistant — answering questions about how to use the app from our own documentation. The text of your question is sent to OpenAI (to convert it into a search vector so we can find the relevant documentation) and, when matching documentation is found, to OpenRouter together with those documentation excerpts to generate the answer.
How We Process Your Data Using AI
When you use our AI Products (for example, when you submit food photographs, ingredients, or other food data for ingredient recognition, recipe suggestions, or similar features) the inputs you provide, the outputs generated, and related information may be shared with and processed by our AI Service Providers to deliver those features. We process this information in accordance with this Policy and our agreements with these providers, which are intended to limit their use of the information to providing the AI features to us. You can review each AI Service Provider's applicable terms and policies to understand how they handle your information.
Sensitive information and AI. The dietary preferences, food allergies, and dietary restrictions saved in your profile are used by our own systems to filter and rank recipes (recipe browsing and Chef AI recommendations); they are not sent to AI Service Providers. However, information that you choose to type into an AI conversation — for example, telling Fantasy Chef that you are vegetarian or allergic to nuts — is sent to the AI Service Provider as part of the request, and may include information that reveals, or allows someone to infer, a health condition. Please share only what you are comfortable sharing in an AI conversation.
Our own recommendations. Our recipe recommendations ("Chef AI") and restock suggestions are produced by our own systems using your Kitchen and Shopping Data and Profile and Food Data. No AI Service Provider is involved in producing them.
AI usage records. For most AI requests (recipe generation, dish and fridge/pantry photo recognition, recipe import from a web page, adding items by voice or free text, scanned-label matching, recipe narration, and Fantasy Chef — not receipt scanning or the AI Assistant) we record, against your account and your device identifier, which feature was used, when, which provider and model handled it, the amount of processing involved, its cost to us, whether it succeeded, and the plan your account was on. We do not store the content of your request in this record. We use these records to manage our costs and to apply fair-use limits, including across guest sessions on the same device.
AI Assistant question log. The questions you ask the in-app AI Assistant are retained so that we can find gaps in our own documentation. This log contains the question text, the date and time it was asked, which app it came from, whether relevant documentation was found, which documentation section matched best, and whether an answer was given; it does not contain your name, account, device, or network identifier, and we do not link it to you. Anything you type into a question is stored as part of the question text, so please do not include personal information in questions to the AI Assistant. Because the log holds no identifier, we cannot tell which entries are yours; unless you can give us the exact wording and approximate time of a question, individual entries cannot be located or deleted on request.
6. COMMUNITY AND USER CONTENT
The App includes a community where you can share recipes, publish posts, comment, and follow other users. Participation is optional. Before you can publish a community post or comment you must confirm that you are at least 18 years old and agree to our Terms of Use. Recipes you create in the Meals tab are reviewed by our staff before they become visible to other users.
What is public. Your community username, your post count, your follower and following counts and lists, and everything you publish — posts, comments, recipes, and any photographs you attach — are visible to every user of the App (except users you have blocked or who have blocked you) and may be copied or shared outside the Services by others. Recipe ratings you give are shown only as part of a recipe's overall star average and rating count, never attributed to you. Your name, e-mail address, dietary preferences, allergies, inventory, and shopping data are not shown in the community. If you have not yet chosen a community username, your account username is shown instead; for accounts created with Apple or Google sign-in that username is derived from the part of your e-mail address before the @.
Following. Following another user is public: the people you follow, the people who follow you, and the resulting counts are shown on profiles.
Moderation. When you submit a post title, post body, or comment, it is checked against a list of banned words and rejected if one is found, and any HTML formatting is stripped (or, for articles, limited to a safe set of tags) before it is stored. Any user can report a post or another user's profile, and can block another user so that neither of you sees the other's content. Content that receives reports from three different users is hidden automatically pending our review. We may remove content, and may suspend or permanently ban an account from the community, where our Terms of Use or community rules are breached. Reports are kept indefinitely (with the reporter's identity removed if they delete their account); a block record is removed when you unblock the person or when either account is deleted; a ban record is removed when the ban is lifted or the banned account is deleted.
When you delete your account. Your posts and comments remain in the community but are attributed to "Deleted user" rather than to you, so that conversations other people took part in stay intact. The photograph attached to each of your community posts is removed from our storage (a photograph you replaced before deletion, or uploaded but never attached to a post, is not tracked and is not removed). Your follows, saves, ratings, and community memberships are deleted.
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
Storing Your Information: Our application servers and database are located in the United States; our marketing website and support mailbox are hosted in Canada. When we use cloud-based infrastructure provided by third party service providers, personal information may be transferred to or accessed from outside of Canada. We may also process, store, and transfer information, including personal information, in and to a foreign country, with different privacy laws that may or may not be as comprehensive as Canadian law. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that country may be able to obtain access to your personal information through the laws of the foreign country.
You are welcome to contact us to obtain further information about our policies regarding service providers outside of Canada by contacting the Privacy Officer listed below.
By providing your personal information during account creation and use of our Services, you freely and expressly consent to this transfer, storage, or processing of your information.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Policy and applicable Canadian laws.
European Commission's Standard Contractual Clauses: We use third-party service providers, such as hosting providers and technology partners to provide the software, networking, infrastructure and other services required to provide our services. These third-party service providers may process or store information, including personal information, on servers outside of the EEA, UK, and Switzerland. We rely on adequacy, if sent to Canada, and the EU-US Data Privacy Framework ("DPF"), the UK Extension to the EU-US DPF, the Swiss-US DPF, or standard contractual clauses ("SCCs"), if sent to the US or onward to other countries to ensure that information, including personal information, is lawfully transferred under European data protection laws. Our SCCs can be provided upon request. We have implemented similar appropriate safeguards with our third-party service providers and partners.
European Data Protection Rights: If you reside in the European Union (EU) or if your data is processed in connection with any European business we may have now or in the future, the following additional provisions will apply to our use of your information, including personal information.
MealLens as a Data Controller: For the purposes of the GDPR, MealLens may act as a data controller of any personal data collected from or about you when we are:
- collecting information from you to set up and administer the Services and your use of our products, services, website, and applications;
- monitoring usage information of our website and applications;
- managing your contact and other related information to send services and other communications to you; and
- responding to a support or general inquiry.
Lawful Basis for Processing: There are a number of different legal bases for processing personal data under the GDPR. Which one is applicable will depend on precisely how we are processing your personal data and for what purpose. Most commonly, we will process your personal data:
- where it is necessary for the performance of the Services, and in order to take steps at your request prior to entering into an agreement for the use of our Services;
- where it is necessary for the purposes of pursuing our legitimate interests;
- in order to comply with a legal obligation to which we are subject; or
- with your consent, which is freely and expressly given by you when you provide us with your personal information during account creation and use of our Services.
Where we are processing your personal data for the purposes of pursuing our legitimate interests, those interests include providing you with our products, services, website, and applications, features, services, or information you request, improving the quality of our services, website, and applications, for our own marketing purposes, and to investigate and prevent fraud. We will not use your personal data for these purposes when our own interests are overridden by the impact on your interests, rights and freedoms.
Transferring Personal Data to Countries Outside of the EEA: Where we transfer your personal data to countries that are outside the EEA we will ensure that it is protected and transferred in a manner consistent with legal requirements applicable to the personal data concerned. This can be done in a number of different ways, for example: the country to which we send the personal data may have been assessed by the European Commission as providing an "adequate" level of protection for personal data; the recipient may have signed a contract based on standard contractual clauses approved by the European Commission.
Data Retention: We will only keep your personal data for as long as required for the purposes set out in this Policy or as required to comply with any legal obligations to which we are subject.
Further details can be provided upon request to the Privacy Officer listed below.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
Retention of Information: We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including for as long as you maintain an account with us and for any additional period required to comply with our legal obligations (such as tax, accounting, or other legal requirements), resolve disputes or enforce agreements, unless a longer retention period is otherwise required or permitted by law.
In practice:
- Your account and everything in it (profile, inventory, shopping list, acquisition history, meal plans, saved recipes, photographs) is kept while your account exists.
- Deleting your account starts a seven-day grace period during which you can restore it by replying to the confirmation e-mail we send you; a member of our team then restores it manually. After seven days the account is permanently deleted, together with your profile, inventory, shopping list, acquisition history, meal plans, saved recipes, and devices.
- Guest accounts expire automatically twenty-four hours after they are created; the account and its data are then deleted by an automatic clean-up that runs once the account is forty-eight hours old. Guest accounts that delete themselves are deleted immediately, with no grace period.
- What remains after deletion. Recipes you created and community posts or comments you published are kept but detached from you (shown as "Deleted user"), and the photograph attached to each of your community posts is removed (see Section 6). Our AI-usage cost records are kept with the link to your account removed (the device identifier is retained). Moderation records (reports you filed and moderation actions) are kept with your identity removed.
- AI Assistant questions are retained in anonymous form to improve our documentation (see Section 5).
- Error reports and session recordings held by our monitoring provider are kept for a limited period under that provider's retention settings and then deleted.
- Backups. Our database provider takes automated backups of our database, which are retained for a short period (currently up to seven days) for disaster recovery and are not used for any other purpose. Residual copies may persist in backups for that period after deletion.
Disposal of Information: When we no longer need your personal information, we will destroy, erase, or anonymize the information, in accordance with best privacy practices.
Anonymization of Information: Under some circumstances we may anonymize your personal information so that it can no longer be associated with you. We reserve the right to use such anonymized or de-identified data for any legitimate business purpose without further notice to you or your consent.
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
Data Protection Measures: We implement appropriate and reasonable technical, organizational, and contractual safeguards designed to protect the security of any personal information we may use, store, process, or share with third-party service providers. We use physical, electronic, and administrative measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. This includes entering into data processing agreements or equivalent contractual agreements and ensuring adequate security and data protection procedures are in place to maintain a level of protection consistent with this Policy and applicable international data protection requirements.
Security Measures: Information that we collect is stored on servers using standard physical, technical and organizational security procedures and practices appropriate to the nature of the information in an effort to protect information from unauthorized access, destruction, use, modification, or disclosure. Information travelling between the App and our servers, including photographs, is encrypted in transit (TLS). Passwords are stored only in hashed form, and your sign-in token is kept in your device's secure keychain. Access is further restricted to those of employees and trusted third parties that require access to the information in order to provide our products, services, or website.
The safety and security of your information also depends on you. Where we have given you (or you have chosen) a password for access to our Services, you are responsible for keeping it confidential.
No electronic transmission over the Internet or information storage technology is completely secure. Although we do our best to protect your personal information, we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment. We are not responsible for circumvention of any privacy settings or security measures in the Services.
In case of a breach of security safeguards (being the loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a breach of or failure to establish security safeguards) involving your personal information under our control, and if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to you, including, physical, financial, or reputational harm, we will notify:
- you;
- any regulatory authority as appropriate; and
- any other organization or government institution that can reduce the risk or mitigate the harm from the breach.
Further, we will keep a record of all breaches in accordance with our legal obligations.
Third-Party Services: Our Services may provide links to third-party websites or resources, over which we have no control. Your use of our Services means that you acknowledge and agree that we are not responsible for the content or information contained on third-party services. When you follow such links, you are no longer protected by this Policy. We encourage you to read the privacy statements or other disclaimers on third-party websites.
We cannot and do not guarantee, represent, or warrant that the content or information contained in such third-party websites and resources is accurate, legal, non-infringing, or inoffensive.
We do not guarantee that such websites or resources will not contain viruses or other malicious code or will not otherwise affect your computer. By using our Services to search for or link to a third-party website, you agree and understand that we shall not be responsible or liable, directly or indirectly, for any damages or losses caused or alleged to be caused by or in connection with your use of, or reliance on, our Services to obtain search results or to link to a third-party website.
For absolute clarity, MealLens is hereby indemnified from any damage arising from the use of links to third-party websites or resources. We claim such indemnification to the fullest extent that the law permits.
10. DO WE COLLECT INFORMATION FROM MINORS?
Our services are not intended for use by individuals under the age of 18, and we do not knowingly collect or sell personal information from children under 18. If you are a parent or guardian and suspect that your child has provided us with personal information, please contact the Privacy Officer listed below so that we can take all necessary steps to remove the information from our databases.
By using the Services, you represent that you are at least 18 or the equivalent age as specified by law in your jurisdiction. If we learn that personal information from users less than 18 years of age or the equivalent age as specified by law in your jurisdiction has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records.
11. WHAT ARE YOUR PRIVACY RIGHTS?
Your Rights Under the GDPR: Under the GDPR you have a number of rights in relation to your personal data. We respect and honor these rights and will help you to exercise them insofar as we are able. These rights are not absolute. In some cases they will not apply to you, or to the particular use that we are making of your data, and there are exceptions (for example if we have to process the data to comply with our own legal obligations) but if that is the case we will let you know.
At any time, you have the right to:
- request access to or a copy of any personal data which we hold about you;
- rectification of your personal data, if you consider that the information we are holding is inaccurate;
- ask us to delete your personal data, if you consider that we do not have the right to hold it;
- withdraw consent to our processing of your personal data (to the extent such processing is based on previously obtained consent);
- ask us to stop or start sending you marketing messages;
- restrict processing of your personal data;
- data portability (moving some of your personal data elsewhere) in certain circumstances;
- object to your personal data being processed in certain circumstances; and
- not be subject to a decision based on automated processing and to have safeguards put in place if you are being profiled based on your personal data.
Any request from you for access to or a copy of your personal data must be in writing and we will endeavor to respond within a reasonable period and in any event within one month in compliance with European data protection legislation. We will comply with our legal obligations as regards your rights as a data subject. Please be advised that certain data is required to operate your account and provide you with our products, services, website, and applications, and if you seek to withdraw consent you may be disabling our ability to manage your accounts and as a result your accounts may be terminated. We aim to ensure that the information we hold about you is accurate at all times. To assist us in ensuring that your information is up to date, please let us know if any of your personal details change by contacting our Privacy Officer listed below.
If a decision that produces legal or similarly significant effects is made solely by automated means, we will inform you, explain the main factors, and offer a simple way to request human review.
In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting our Privacy Officer listed below. We will consider and act upon any request in accordance with applicable data protection laws within a reasonable period and, in any event, within one month in compliance with European data protection legislation.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State National Data Protection Authority or UK Data Protection Authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Account Information
You can review your account information and your preferences, and update your preferences, from Settings in the App. To change the e-mail address or name on your account, contact us at support@mealvue.com; passwords can be reset from the sign-in screen. You can delete your account from within the App at any time: open Settings, tap your name to open My Profile, then under Manage Account tap Delete Account and confirm with your password (or by typing "delete my account" if you signed in with Apple or Google).
Upon receiving your request to terminate your account, we will deactivate or delete your account and information from our active databases as described in Section 8. After your account is deleted we retain a limited set of information: records of which AI features were used and what they cost us (with your account link removed and only the device identifier kept), moderation records, and recipes, community posts, and comments you published, with your name removed. We may also retain information where needed to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms, and/or comply with applicable legal requirements.
If you have questions or comments about your privacy rights, you may contact our Privacy Officer listed below.
12. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.
13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. More information is provided below.
Categories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, IP address, email address, and account name | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information | YES |
| C. Protected classification characteristics under state or federal law | Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | YES, limited — we do not ask for gender, age, date of birth, or race, but the optional dietary preferences and food allergies you choose (for example Halal, Kosher, Celiac, or specific allergens) may reveal religious or health-related characteristics |
| D. Commercial information | Transaction information, purchase history, financial details, and payment information | YES |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements | YES |
| G. Geolocation data | Device location | NO |
| H. Audio, electronic, sensory, or similar information | Images and audio, video or call recordings created in connection with our business activities | YES — images only (photographs you submit). We do not collect audio: when you use voice input, your device's speech recogniser converts your speech to text and we receive only the text |
| I. Professional or employment-related information | Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | NO |
| J. Education Information | Student records and directory information | NO |
| K. Inferences drawn from collected personal information | Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual's preferences and characteristics | YES |
| L. Sensitive personal Information | Account login information, health-related dietary data (such as allergies or celiac restrictions), and dietary preferences that may reveal religious beliefs (such as Halal or Kosher) | YES |
We only collect sensitive personal information, as defined by applicable privacy laws, for the purposes allowed by law or with your consent. Sensitive personal information may be used, or disclosed to a service provider or contractor, for additional, specified purposes. You may have the right to limit the use or disclosure of your sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
We will use and retain the collected personal information as needed to provide the Services or for:
- Category A - As long as the user has an account with us
- Category B - As long as the user has an account with us
- Category C - As long as the user has an account with us
- Category D - As long as the user has an account with us
- Category F - As long as the user has an account with us
- Category H - As long as the user has an account with us
- Category K - As long as the user has an account with us
- Category L - As long as the user has an account with us
In each case "as long as the user has an account with us" includes the seven-day deletion grace period. After deletion we keep AI-usage cost records (account link removed, device identifier retained), moderation records, and recipes, community posts, and comments the user published, with the author's name removed; residual copies may persist in backups for a short period (see Section 8).
Will Your Information Be Shared with Anyone Else?
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider.
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:
- Category A. Identifiers
- Category D. Commercial information (the contents of receipts you scan, which are processed by our AI Service Provider)
- Category F. Internet or other electronic network activity (app usage, crash and error diagnostics sent to our monitoring provider, and search terms sent to our AI Service Provider for ingredient matching)
- Category H. Audio, electronic, visual, and similar information (photographs you submit)
- Category L. Sensitive personal information (only where you include it in an AI conversation, as described in Section 5)
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:
- Right to know whether or not we are processing your personal data.
- Right to access your personal data.
- Right to correct inaccuracies in your personal data.
- Right to request the deletion of your personal data.
- Right to obtain a copy of the personal data you previously shared with us.
- Right to non-discrimination for exercising your rights.
- Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California's privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling").
Depending upon the state where you live, you may also have the following rights:
- Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota).
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland).
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon).
- Right to obtain a list of third parties to which we have sold personal data (as permitted by applicable law, including the privacy law in Connecticut).
- Right to review, understand, question, and depending on where you live, correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Connecticut and Minnesota).
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California).
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida).
How to Exercise Your Rights
To exercise these rights, you can contact our Privacy Officer listed below.
Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws.
Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.
If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.
Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by contacting our Privacy Officer. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light" Law
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to our Privacy Officer.
14. DO WE MAKE UPDATES TO THIS NOTICE?
We may update this Privacy Policy from time to time. You are responsible for periodically visiting our website and this Policy to check for any changes. All substantial changes made to this Policy will be notified on the website, at our sole discretion, and will take effect immediately. Your continued access and use of our Services, applications, or website following any changes to this Policy constitutes acceptance of the Policy in effect at the time of use. Your continued use of our services will signify that you consent to the collection, use, and disclosure of your personal information in accordance with the Policy in effect at the time of use.
Legal Disclaimer: Depending on the products, services, or use of our applications or website, your choices may include the following:
- Cookie Settings and Preferences: Our website does not currently set analytics or advertising cookies (see Section 1). You can block cookies generally by activating the settings in your internet browser.
- Marketing E-mails: We currently send only service e-mails needed to operate your account (password-reset codes and account-deletion notices), which do not include an unsubscribe option. We do not send promotional e-mails today; if we do in future, each will include an "unsubscribe" link so you can opt out at any time, and you can also opt out by contacting our Privacy Officer.
- Canada's Anti-Spam Legislation (CASL): We are committed to complying with Canada's Anti-Spam Legislation. We only send commercial electronic messages to individuals who have provided either express consent or implied consent, as defined under CASL. We take appropriate measures to ensure our communications are clear, respectful, and fully compliant with CASL requirements.
- Opt-Outs: You may contact us to opt-out of the use or sharing of your personal information, including for marketing or advertising purposes, and/or the provision of your personal information to our business partners for such purposes.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email our Privacy Officer at support@mealvue.com, call us at +1 (647) 830-7080, or contact us by post at:
MealLens Inc. Attn: Privacy Officer 1402 Rushwood Cres. LaSalle, Ontario N9H 2B2 Canada