August 24, 2026

Privacy Policy

How Munch Manager collects, uses, stores, and protects personal data.

1. Who this policy covers

This Privacy Policy explains how Munch Manager handles personal data when you use the app, website, PWA, and related services.

Munch Manager support at hello@munchmanager.com is the primary contact for privacy questions and requests.

2. Personal data we collect

We collect the data needed to provide a shared meal planning service.

  • Account data, such as your name, email address, profile image, Clerk user identifier, approval status, and last seen time.
  • Group data, such as group names, invite codes, membership, roles, and active group settings.
  • Meal planning content, such as recipes, ingredients, pantry items, shopping lists, weekly slots, ratings, public recipe copies, uploaded images, notes, and ingredient requests.
  • Munchie companion data, such as its name, time zone, XP, crumbs, care statistics, evolution stage, rewards, cosmetics, favorites, achievements, and quest progress.
  • Feedback data, including the free-text message you submit and the account linked to it.
  • Email and in-app messaging data, such as announcements, notification content, intended audience, read status, recipient email addresses, and delivery status.
  • Billing and subscription data, such as Stripe customer and subscription identifiers, plan price, subscription status, billing owner, and current billing-period dates.
  • Device and app data, such as language, theme, default portions, install state, offline cache state, queued offline changes, and push notification subscription details.
  • Technical service data, such as logs, request metadata, rate-limit counters, and security events needed to operate and protect the service. Optional product analytics data, such as pseudonymous user IDs and feature events, is collected only after you accept optional analytics.
  • AI usage data, such as the feature used, model and euro pricing version, token counts, estimated euro cost, request status, and user or household attribution. We do not store prompts, images, audio, source URLs, or generated content in AI usage records.

3. How we use personal data

We use personal data to operate, secure, improve, and support Munch Manager.

  • Authenticate users and verify access through Clerk and Convex.
  • Show real-time shared planning data to the right group members.
  • Store uploaded recipe and pantry images through Cloudflare R2.
  • Operate Munchie, calculate care statistics and rewards, and keep cosmetic, achievement, and quest progress.
  • Generate optional AI features such as recipe imports, pantry scans, translations, and meal suggestions.
  • Review feedback and respond to support needs.
  • Send in-app messages, push notifications when you opt in, and service emails. You can opt out of non-essential email in Settings.
  • Prevent abuse, investigate errors, apply rate limits, and maintain audit logs.
  • Measure product usage with PostHog EU Cloud only if you accept optional analytics.
  • Diagnose client-side errors and performance with sanitized Sentry monitoring only after analytics consent.
  • Process billing, subscriptions, and legally required accounting records when paid plans are enabled.

4. Legal bases

Where the GDPR applies, we process personal data because it is necessary to provide the service you request, because we have legitimate interests in securing the app, because we must comply with legal obligations, or because you have given consent for optional features such as push notifications and product analytics.

Optional PostHog analytics and client-side Sentry monitoring rely on your consent. Necessary security monitoring and service communications rely on our legitimate interests or the performance of our agreement, as applicable. You can disable non-essential email notifications in Settings.

5. Service providers

Munch Manager relies on specialist providers to run the service. These providers process data only as needed to provide their services.

  • Clerk for authentication and user identity.
  • Convex for application data storage, server functions, and real-time sync.
  • Cloudflare R2 for image upload and storage.
  • Vercel for website and app hosting, content delivery, and request handling.
  • Stripe for payment processing, subscription management, tax calculation, and invoices.
  • PostHog EU Cloud for optional product analytics events after analytics consent.
  • Sentry for sanitized error and performance monitoring, consent-gated on the client.
  • Resend for delivery of account and service emails.
  • Google Gemini or similar AI providers for optional AI-assisted features.
  • Web Push services provided by your browser vendor for push notifications.
  • Open Food Facts as a source for public ingredient catalogue data.

6. Cookies, local storage, and offline data

Munch Manager uses necessary browser storage for authentication, security, preferences, PWA behavior, offline access, and queued offline changes. The analytics consent choice is also stored locally so the app can remember it.

Optional PostHog analytics and client-side Sentry monitoring are off by default. If you accept them, PostHog uses localStorage for a pseudonymous analytics identity and sends explicit product events. PostHog automatic interaction capture, exception capture, and session recording remain disabled.

When Sentry is configured and you accept optional analytics, it sends sanitized client error and performance data through Munch Manager's /monitoring endpoint. Sentry session replay is disabled. If you later opt out, Munch Manager stops both client services, resets the PostHog identity, and clears related PostHog client storage where available.

LocalStorage and similar browser storage are treated like cookies for optional analytics consent purposes. The app does not use advertising cookies.

If you clear browser storage, offline data and local preferences on that device may be removed.

7. Sharing

Your group content is shared with members of the same group. Public recipes you choose to publish are available to anyone on the internet, can be indexed by search engines, and can be copied by Munch Manager users into their own groups.

Uploaded images are served from public Cloudflare R2 URLs and should not be treated as protected by group authentication. Someone who obtains an image's exact URL may be able to access it outside Munch Manager. Do not upload sensitive images.

We do not sell personal data. We may disclose data when required by law, to protect the service, or during a business transfer subject to appropriate safeguards.

8. Retention

We keep account and app data for as long as needed to provide Munch Manager, meet legal obligations, resolve disputes, prevent abuse, and maintain backups.

We retain billing and accounting records for 10 years where required by law.

To prevent repeat free trials, we retain a SHA-256 hash of your normalized email address indefinitely, including after account deletion. The stored trial marker does not contain the email address itself.

Detailed AI usage records are retained for 90 days. Monthly AI usage counters are retained for 13 months. Lifetime trial counters are retained to enforce the one-time trial allowance.

Deleted content may remain in backups or logs for a limited period before it is removed according to normal retention practices.

9. International transfers

Some providers may process data outside your country. Where required, transfers rely on appropriate safeguards such as contractual protections and provider compliance measures.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data. You may also withdraw consent for optional features such as push notifications and product analytics.

You can download data linked to your account or permanently delete your account from the Account page. For other privacy requests, email hello@munchmanager.com.

11. Children

Munch Manager is intended for general household and group meal planning. It is not directed to children who are too young to consent to online services under applicable law.

12. Changes

We may update this Privacy Policy as the app, providers, or legal requirements change. The latest version will always be available on this page.