Famenu - Privacy Policy

Effective date: 2026-08-28 Last updated: 2026-08-28

Famenu is a meal-planning app for families: you tell it who eats at your table and what they can't eat, and it plans your week, writes your shopping list, and helps you cook.

This policy explains exactly what we store, why, and who else sees it. It is written to be read, not to be survived.


1. Who is responsible

Famenu, Switzerland. Contact: support@famenu.ch

We are the data controller for the information described below.

2. The short version

3. What we collect, and why

3.1 Account

DataWhy
Email addressIdentifies your account, sign-in, and account emails (verification, password reset)
Preferred name (optional)So the app can greet you
Sign-in method (email, Google, Apple)To sign you in

If you sign in with Google or Apple, we receive your email address and, where you allow it, your name from that provider. We never receive your password.

3.2 Your household

This is the heart of the app, and the most sensitive part:

DataWhy
Number of adults; children's age brackets and optional first namesPortion sizes, and age-appropriate cooking (e.g. under-1 weaning rules)
Allergies - household-wide and per childSafety. These are treated as hard constraints and are checked on every recipe
Dietary restrictions (e.g. vegetarian, lactose-free)To generate food you will actually eat
Foods to avoidSame, for preferences rather than safety
Country and region (typed by you, never from device location)Seasonal produce, local ingredients, currency for cost estimates
Cooking days, meals to plan, time budget, kitchen equipmentTo shape the weekly plan
Pantry contents, fridge ingredients you enterShopping lists and "cook with what I have"

Allergy information is health-related data. We use it for one purpose: keeping those ingredients out of your recipes. We do not use it for profiling, and we do not sell or share it.

What other members of your household can see. Anyone who joins with your invite code shares the household: they can see and edit the whole profile above (including children's names and allergies), the weekly plans, the shopping list and the pantry. They cannot see your personal recipe notes. Only invite people you mean to share all of that with; removing someone means removing them from the household.

3.3 Your use of the app

DataWhy
Weekly plans, generated recipes, batch-cooking sessionsThe service itself
Favourites, ratings, "cooked it" countsTo learn what your household likes
Personal recipe notesYours alone - see §5
Shopping-list ticksTo keep your list in sync across your household
Recipe generation counts, chef-assistant question counts, and daily counters for imports, batch-cooking builds, plan adjustments, problem reports, household joins and grocery sendsTo enforce free-plan limits and to cap abuse of the paid features
Problem reports you send about a recipe: your text, the recipe it concerns, and which household sent itTo fix the recipe. The report and the recipe document are also given to the AI to pre-sort it (§4.1); your household's diets and allergens are looked up at that moment so the AI can judge an allergen claim, and are not stored on the report. Reports are deleted with your account
Grocery ordering (optional): the retailer you chose, whether you prefer organic products, and, for each list you send, the retailer, the outcome, item counts and an estimated totalTo open your shopping list at your retailer and to know whether the feature works. No product names are stored by us; see §4.5 for what the retailer itself receives
Notification preferences and device push tokenTo send the weekly planning reminder you asked for. The reminder may name next week's dishes if you enabled the preview
Your household's invite codeSo a partner or family member can join your household
Subscription status, trial dates, creditsTo know which plan you are on
When you send a list to a shop (Coop, Migros, ...): counts and a total for each send, and, when a send or sign-in fails, a technical trace of the attempt (which step ran, how long it took, the shop's error code, the page path)To see how often sending works and to fix it when it does not. Never the products, your searches, your basket or anything you type on the shop's site. Traces are kept in our logs for 30 days

3.4 What we do not collect

No device location. No contacts. No photos from your device. No advertising identifiers. No behavioural analytics. No crash-reporting SDK. No social-media trackers.

4. Who processes your data

We use a small number of processors, all under contract:

ProcessorWhat they handleWhere
Google (Firebase) - authentication, database, functions, file storage, push notificationsAll of the data aboveData stored in the EU (multi-region eur3; functions and images in Zürich, europe-west6)
OpenAI and Anthropic (AI model providers)Recipe generation, the chef assistant, recipe import (the text or photo you import) and the pre-sorting of problem reports - see §4.1. Which of the two is active is a deployment setting; both are bound by the same limitsProcessed at the provider's infrastructure, under their business terms (no training on our data; inputs may be retained briefly for abuse monitoring)
Google Cloud Vertex AIGenerates the photo for a recipe from its title, description and ingredient names - nothing about youGoogle's global endpoint, which may process the request outside the EU
AlgoliaLibrary search: the words you type in the search box and, for recipes you imported, their titles and ingredient names so you can find them. Search analytics are switched offAlgolia's infrastructure
Apple / GoogleSign-in, push delivery, and the device's own speech recognition if you use voice inputPer their own policies
RevenueCatSubscription status: which plan you bought, when it renews or ends, and the store's anonymous transaction identifiers. Payment itself is handled by Apple or Google; we never see your card or billing addressUnited States (EU-US Data Privacy Framework)
Your grocery retailer (Coop, Migros, Super U, Intermarché, ... - only if you use grocery ordering)Not a processor of ours: an independent controller you sign in to yourself. See §4.5Per their own policies

4.1 What the AI actually receives

When Famenu generates recipes, it sends the AI your household's cooking context: allergens, dietary restrictions, foods to avoid, children's age brackets, number of eaters, country, language, equipment, time budget, and the titles of dishes you have had recently or rated.

It does not send your name, your email, your account identifier, or your children's names. The AI receives "2 adults, one child aged 1–4, allergic to peanuts" - not who you are.

Your personal recipe notes are never sent to the AI, in any form.

When you import a recipe, the text you paste, the page you link, or the photo you take is sent to the AI to be transcribed into a recipe. When you report a problem with a recipe, your report text and the recipe are sent to the AI to be pre-sorted for us, together with your household's diets and allergens so it can judge an allergen claim. Both are one-off requests; nothing about you travels with them.

Training. We do not train any model on your data, and we do not sell it. Our AI providers process what we send them to return a recipe or an answer, under their own commercial terms for business customers.

Anonymous sharing setting. Settings contains an option to share your highest-rated recipes anonymously. It is stored with your account but not yet used - no recipe of yours is shared with anyone today. If we turn it on, we will say so in the app first, and only recipes (which carry no personal data) would ever be involved.

4.2 The chef assistant

Questions you ask the chef assistant are sent to the AI together with your household's cooking constraints (allergens, diets, children's age brackets) so the answer is safe for your table. The question and the answer are not stored - no conversation history is kept on our servers; only a counter of how many questions you have asked, to enforce plan limits. Whatever you type into that box does travel to the AI provider, so treat it as you would any chat box: it is for cooking questions.

4.3 Recipe photos are shared between households

To keep costs (and energy use) down, Famenu photographs a dish, not a household. When two households are served the same dish, they see the same photograph: the app keeps an index of "what is on the plate" (the dish title and its main ingredients, with seasonings ignored) and reuses an existing picture instead of generating a new one.

That index contains no account identifiers and no personal data - it maps a dish fingerprint to an image, nothing more. Your recipes, notes and household profile are never shared with other households.

4.4 Voice input

If you use the microphone to ask the chef assistant a question, the audio is handled by your device's own speech-recognition service (Apple or Google). Depending on your device and its settings, that service may process the audio on their servers under their privacy policy. We receive only the resulting text, and only for as long as it takes to answer.

4.5 Grocery ordering

If you connect a grocery retailer, the retailer's own website opens inside the app and you sign in to it yourself: your retailer password never passes through Famenu, and we never see or store it. To fill your basket, the app searches the retailer's site for the ingredient names on your shopping list - so the retailer receives those names, your device's network address, and whatever its own site collects, under its own privacy policy. The retailer session stays on your device only and is wiped when you sign out of Famenu or delete your account.

5. Your notes are private

Notes you attach to a recipe are visible only to you. They are stored in a record only your account can read, not shared with other members of your household, not used to train anything, and not sent to the AI.

6. Legal bases (GDPR / Swiss nFADP)

Where we process allergy data (health-related), we do so because you have explicitly provided it to obtain a service that depends on it.

7. Children

Famenu is used by adults planning family meals. Children do not have accounts and never interact with the app. A parent may record a child's age bracket, an optional first name, allergies and disliked foods - the minimum needed to cook safely for them. This information is deleted with your household.

8. How long we keep things

We keep your data while your account exists. When you delete your account (Settings → Delete account), we delete:

Deletion is immediate and cannot be undone. Before deleting, the app asks you to sign in again, so a phone left unlocked cannot delete your account in two taps.

A few things deliberately survive, because none of them identifies you:

If you are not the last member of your household, the household and its shared content stay with the remaining members - that is their data too; recipes you imported for the household lose your identifier and stay with them.

Technical logs on our infrastructure are kept for 30 days; they carry event names, counts and a hashed account identifier, never allergen names next to an identifier. Backups held by our infrastructure providers may retain copies for a short period before expiring.

9. Your rights

You can access, correct, export, restrict or delete your data, object to processing, and lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your national authority).

Most of these you can do yourself in the app: your household profile, dietary information and contact details are all editable in Settings, and account deletion is one tap. For anything else, write to us at support@famenu.ch and we will respond within 30 days.

10. International transfers

Your data is stored in the EU. Some processors (the AI providers, the photo generator's global endpoint, and Algolia) may process data outside the EU/Switzerland under standard contractual clauses or an equivalent safeguard.

11. Security

Access to your data is enforced by server-side security rules that run on our infrastructure, not in the app: a signed-in user can read and write only their own records and those of the household they belong to, and the recipe catalogue is read-only to everyone. Recipe generation, account deletion and household joins run as server functions, so a modified client cannot bypass those checks. Traffic is encrypted in transit; data is encrypted at rest by our infrastructure provider. API keys and secrets are held in a managed secret store, never in the app.

12. Changes

If we change this policy materially, we will tell you in the app before the change takes effect. The "last updated" date above always reflects the current version.


Draft prepared from the application's actual data flows on 2026-08-13. It is not legal advice; have a qualified lawyer review it before public release, particularly the sections covering children's and health-related data.