Your recipes, meal plans, shopping lists and fridge contents stay on your iPhone and in your own private iCloud. We cannot see them.
We have no accounts and no sign-up. We never ask for your name, email or phone number inside the app.
The app sends anonymous usage statistics (screen opened, dish saved) that are not tied to you and cannot be traced back to you.
We never see your payment details. Apple handles the subscription.
Food Menu: Plan & Shop (“the app”) is made and operated by NanoPies OÜ, a company registered in Estonia (“we”, “us”). For anything in this policy, write to [email protected].
For the purposes of the EU General Data Protection Regulation (GDPR), NanoPies OÜ is the data controller for the limited data described below.
Everything you create in the app is stored locally on your iPhone:
This data is never uploaded to our servers. Deleting the app from your iPhone deletes this data from the device.
If you are signed in to iCloud, iOS syncs the app’s data to your private iCloud database so you can restore it or use it on another device signed in to the same Apple Account. This is handled entirely by Apple’s infrastructure — we have no access to it and no ability to read it. Apple’s Privacy Policy applies to data held in iCloud. You can turn the sync off in iOS Settings → your name → iCloud.
To understand which parts of the app people actually use, we collect anonymous product analytics through TelemetryDeck (TelemetryDeck GmbH, Germany), a privacy-first analytics service. Its SDK is open source, it uses no cookies and no fingerprinting, and it never stores IP addresses — an IP is used only to derive the country a signal came from and is then discarded.
When something happens in the app, we send a small signal such as shopping.opened, dish.saved or paywall.converted. Each signal carries:
These signals never contain your recipes, ingredients, shopping lists, meal plans, names, contacts, photos, precise location, email address or IP-based profile. We do not use the advertising identifier (IDFA), we do not track you across other apps or websites, and we do not build advertising profiles. The legal basis is our legitimate interest (GDPR Art. 6(1)(f)) in understanding aggregate product usage.
Note: if you have used a version of this policy dated before September 2026, it stated that the app used no analytics. That is no longer accurate — this section describes what the current version of the app actually does.
Access to the app is sold as an auto-renewing subscription with a two-week free trial. The purchase is made through your Apple Account using Apple’s In-App Purchase system.
We never receive or store your card number, billing address or any other payment detail. Apple is the seller of record; its Privacy Policy and Media Services Terms govern the transaction. The app asks StoreKit on your device whether a valid subscription exists and stores only that yes/no answer locally.
The app downloads the built-in cookbook (recipes and their photos) from foodmenu.dev. These requests are read-only: the app asks for content and receives it. It does not send us your dishes, your plans, or anything else you have created.
Like any web server, ours writes standard technical request records — IP address, timestamp, requested path, user agent — which we use to keep the service running and to detect abuse. We keep them for up to 30 days and do not use them to identify individuals.
foodmenu.dev is a static site. It sets no cookies, runs no analytics and contains no third-party trackers. Fonts are served from our own domain, not from a font CDN. The only thing stored in your browser is a localStorage entry remembering which of the six interface languages you picked.
| Provider | What it does | What it receives |
|---|---|---|
| Apple | App distribution, In-App Purchase, iCloud sync | Payment and account data, under Apple’s own policy; your synced data, encrypted in your private iCloud |
| TelemetryDeck GmbH | Anonymous product analytics | The anonymous signals described in section 4 |
| Our hosting provider | Serves the website and the cookbook API | Standard server request records |
The app is a general-audience cooking tool and is not directed at children under 13. We do not knowingly collect personal data from anyone, children included.
Because we hold no account and no identifier that points to you as a person, there is normally nothing for us to look up, export or erase — your data is on your device and in your own iCloud, both of which you control directly.
If you are in the EEA or the UK, you still have the rights to access, rectification, erasure, restriction, objection and portability under the GDPR, and the right to lodge a complaint with your local supervisory authority. If you are in California, you have the rights described by the CCPA/CPRA; note that we do not sell or share personal information as those laws define it. Write to [email protected] and we will help as far as the data allows.
On-device and iCloud data lives for as long as you keep it. Anonymous analytics signals are retained by TelemetryDeck in aggregate form. Server request logs are kept for up to 30 days.
If this policy changes, the updated version will be published at this address with a new effective date. Material changes will also be noted in the app’s release notes.
NanoPies OÜ, Estonia — [email protected]