Famenu - Privacy Policy
Effective date: 2026-08-28 Last updated: 2026-08-28
Famenu is a meal-planning app for families: you tell it who eats at your table and what they can't eat, and it plans your week, writes your shopping list, and helps you cook.
This policy explains exactly what we store, why, and who else sees it. It is written to be read, not to be survived.
1. Who is responsible
Famenu, Switzerland. Contact: support@famenu.ch
We are the data controller for the information described below.
2. The short version
- We collect what the app needs to plan your meals - your household's composition, dietary needs and cooking preferences - plus your account email.
- We have no analytics, no advertising, no tracking, and no third-party marketing SDKs. The app contains none.
- We never request or read your device's location. Your country and region are things you type, and you can change them.
- Your recipe notes are private to you and are never sent to the AI.
- You can delete your account, and everything in it, from inside the app.
3. What we collect, and why
3.1 Account
| Data | Why |
|---|---|
| Email address | Identifies your account, sign-in, and account emails (verification, password reset) |
| Preferred name (optional) | So the app can greet you |
| Sign-in method (email, Google, Apple) | To sign you in |
If you sign in with Google or Apple, we receive your email address and, where you allow it, your name from that provider. We never receive your password.
3.2 Your household
This is the heart of the app, and the most sensitive part:
| Data | Why |
|---|---|
| Number of adults; children's age brackets and optional first names | Portion sizes, and age-appropriate cooking (e.g. under-1 weaning rules) |
| Allergies - household-wide and per child | Safety. These are treated as hard constraints and are checked on every recipe |
| Dietary restrictions (e.g. vegetarian, lactose-free) | To generate food you will actually eat |
| Foods to avoid | Same, for preferences rather than safety |
| Country and region (typed by you, never from device location) | Seasonal produce, local ingredients, currency for cost estimates |
| Cooking days, meals to plan, time budget, kitchen equipment | To shape the weekly plan |
| Pantry contents, fridge ingredients you enter | Shopping lists and "cook with what I have" |
Allergy information is health-related data. We use it for one purpose: keeping those ingredients out of your recipes. We do not use it for profiling, and we do not sell or share it.
What other members of your household can see. Anyone who joins with your invite code shares the household: they can see and edit the whole profile above (including children's names and allergies), the weekly plans, the shopping list and the pantry. They cannot see your personal recipe notes. Only invite people you mean to share all of that with; removing someone means removing them from the household.
3.3 Your use of the app
| Data | Why |
|---|---|
| Weekly plans, generated recipes, batch-cooking sessions | The service itself |
| Favourites, ratings, "cooked it" counts | To learn what your household likes |
| Personal recipe notes | Yours alone - see §5 |
| Shopping-list ticks | To keep your list in sync across your household |
| Recipe generation counts, chef-assistant question counts, and daily counters for imports, batch-cooking builds, plan adjustments, problem reports, household joins and grocery sends | To enforce free-plan limits and to cap abuse of the paid features |
| Problem reports you send about a recipe: your text, the recipe it concerns, and which household sent it | To fix the recipe. The report and the recipe document are also given to the AI to pre-sort it (§4.1); your household's diets and allergens are looked up at that moment so the AI can judge an allergen claim, and are not stored on the report. Reports are deleted with your account |
| Grocery ordering (optional): the retailer you chose, whether you prefer organic products, and, for each list you send, the retailer, the outcome, item counts and an estimated total | To open your shopping list at your retailer and to know whether the feature works. No product names are stored by us; see §4.5 for what the retailer itself receives |
| Notification preferences and device push token | To send the weekly planning reminder you asked for. The reminder may name next week's dishes if you enabled the preview |
| Your household's invite code | So a partner or family member can join your household |
| Subscription status, trial dates, credits | To know which plan you are on |
| When you send a list to a shop (Coop, Migros, ...): counts and a total for each send, and, when a send or sign-in fails, a technical trace of the attempt (which step ran, how long it took, the shop's error code, the page path) | To see how often sending works and to fix it when it does not. Never the products, your searches, your basket or anything you type on the shop's site. Traces are kept in our logs for 30 days |
3.4 What we do not collect
No device location. No contacts. No photos from your device. No advertising identifiers. No behavioural analytics. No crash-reporting SDK. No social-media trackers.
4. Who processes your data
We use a small number of processors, all under contract:
| Processor | What they handle | Where |
|---|---|---|
| Google (Firebase) - authentication, database, functions, file storage, push notifications | All of the data above | Data stored in the EU (multi-region eur3; functions and images in Zürich, europe-west6) |
| OpenAI and Anthropic (AI model providers) | Recipe generation, the chef assistant, recipe import (the text or photo you import) and the pre-sorting of problem reports - see §4.1. Which of the two is active is a deployment setting; both are bound by the same limits | Processed at the provider's infrastructure, under their business terms (no training on our data; inputs may be retained briefly for abuse monitoring) |
| Google Cloud Vertex AI | Generates the photo for a recipe from its title, description and ingredient names - nothing about you | Google's global endpoint, which may process the request outside the EU |
| Algolia | Library search: the words you type in the search box and, for recipes you imported, their titles and ingredient names so you can find them. Search analytics are switched off | Algolia's infrastructure |
| Apple / Google | Sign-in, push delivery, and the device's own speech recognition if you use voice input | Per their own policies |
| RevenueCat | Subscription status: which plan you bought, when it renews or ends, and the store's anonymous transaction identifiers. Payment itself is handled by Apple or Google; we never see your card or billing address | United States (EU-US Data Privacy Framework) |
| Your grocery retailer (Coop, Migros, Super U, Intermarché, ... - only if you use grocery ordering) | Not a processor of ours: an independent controller you sign in to yourself. See §4.5 | Per their own policies |
4.1 What the AI actually receives
When Famenu generates recipes, it sends the AI your household's cooking context: allergens, dietary restrictions, foods to avoid, children's age brackets, number of eaters, country, language, equipment, time budget, and the titles of dishes you have had recently or rated.
It does not send your name, your email, your account identifier, or your children's names. The AI receives "2 adults, one child aged 1–4, allergic to peanuts" - not who you are.
Your personal recipe notes are never sent to the AI, in any form.
When you import a recipe, the text you paste, the page you link, or the photo you take is sent to the AI to be transcribed into a recipe. When you report a problem with a recipe, your report text and the recipe are sent to the AI to be pre-sorted for us, together with your household's diets and allergens so it can judge an allergen claim. Both are one-off requests; nothing about you travels with them.
Training. We do not train any model on your data, and we do not sell it. Our AI providers process what we send them to return a recipe or an answer, under their own commercial terms for business customers.
Anonymous sharing setting. Settings contains an option to share your highest-rated recipes anonymously. It is stored with your account but not yet used - no recipe of yours is shared with anyone today. If we turn it on, we will say so in the app first, and only recipes (which carry no personal data) would ever be involved.
4.2 The chef assistant
Questions you ask the chef assistant are sent to the AI together with your household's cooking constraints (allergens, diets, children's age brackets) so the answer is safe for your table. The question and the answer are not stored - no conversation history is kept on our servers; only a counter of how many questions you have asked, to enforce plan limits. Whatever you type into that box does travel to the AI provider, so treat it as you would any chat box: it is for cooking questions.
4.3 Recipe photos are shared between households
To keep costs (and energy use) down, Famenu photographs a dish, not a household. When two households are served the same dish, they see the same photograph: the app keeps an index of "what is on the plate" (the dish title and its main ingredients, with seasonings ignored) and reuses an existing picture instead of generating a new one.
That index contains no account identifiers and no personal data - it maps a dish fingerprint to an image, nothing more. Your recipes, notes and household profile are never shared with other households.
4.4 Voice input
If you use the microphone to ask the chef assistant a question, the audio is handled by your device's own speech-recognition service (Apple or Google). Depending on your device and its settings, that service may process the audio on their servers under their privacy policy. We receive only the resulting text, and only for as long as it takes to answer.
4.5 Grocery ordering
If you connect a grocery retailer, the retailer's own website opens inside the app and you sign in to it yourself: your retailer password never passes through Famenu, and we never see or store it. To fill your basket, the app searches the retailer's site for the ingredient names on your shopping list - so the retailer receives those names, your device's network address, and whatever its own site collects, under its own privacy policy. The retailer session stays on your device only and is wiped when you sign out of Famenu or delete your account.
5. Your notes are private
Notes you attach to a recipe are visible only to you. They are stored in a record only your account can read, not shared with other members of your household, not used to train anything, and not sent to the AI.
6. Legal bases (GDPR / Swiss nFADP)
- Performing our contract with you - your account, household profile, plans, shopping lists. Without these the app cannot work.
- Your consent - push notifications, voice input, and any optional sharing setting. You can withdraw consent at any time in Settings.
- Our legitimate interests - keeping the service secure and preventing abuse of generation limits.
Where we process allergy data (health-related), we do so because you have explicitly provided it to obtain a service that depends on it.
7. Children
Famenu is used by adults planning family meals. Children do not have accounts and never interact with the app. A parent may record a child's age bracket, an optional first name, allergies and disliked foods - the minimum needed to cook safely for them. This information is deleted with your household.
8. How long we keep things
We keep your data while your account exists. When you delete your account (Settings → Delete account), we delete:
- your user record, your recipe bookkeeping (favourites, ratings, notes), your problem reports, and every usage counter;
- your membership of the household (the household's invite code is rotated when you leave);
- and, if you are the last member, the household itself with its children, pantry, weekly plans, slots, shopping lists, batch-cooking sessions, problem reports, and the recipes you imported together with their original scans and photos;
- your authentication account.
Deletion is immediate and cannot be undone. Before deleting, the app asks you to sign in again, so a phone left unlocked cannot delete your account in two taps.
A few things deliberately survive, because none of them identifies you:
- generated recipe documents - they carry no account identifier (only an internal household reference that stops resolving once the household is gone), and other members' plans may still reference them;
- the dish→photo index (§4.3), which contains no personal data at all;
- our cost records - the counts of what each request cost us to serve keep their numbers but lose your identifier; monthly totals keyed to you are deleted;
- a hashed trace of your sign-in address (a one-way fingerprint, not the address itself), kept so that a new account on the same address does not receive a second free trial.
If you are not the last member of your household, the household and its shared content stay with the remaining members - that is their data too; recipes you imported for the household lose your identifier and stay with them.
Technical logs on our infrastructure are kept for 30 days; they carry event names, counts and a hashed account identifier, never allergen names next to an identifier. Backups held by our infrastructure providers may retain copies for a short period before expiring.
9. Your rights
You can access, correct, export, restrict or delete your data, object to processing, and lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your national authority).
Most of these you can do yourself in the app: your household profile, dietary information and contact details are all editable in Settings, and account deletion is one tap. For anything else, write to us at support@famenu.ch and we will respond within 30 days.
10. International transfers
Your data is stored in the EU. Some processors (the AI providers, the photo generator's global endpoint, and Algolia) may process data outside the EU/Switzerland under standard contractual clauses or an equivalent safeguard.
11. Security
Access to your data is enforced by server-side security rules that run on our infrastructure, not in the app: a signed-in user can read and write only their own records and those of the household they belong to, and the recipe catalogue is read-only to everyone. Recipe generation, account deletion and household joins run as server functions, so a modified client cannot bypass those checks. Traffic is encrypted in transit; data is encrypted at rest by our infrastructure provider. API keys and secrets are held in a managed secret store, never in the app.
12. Changes
If we change this policy materially, we will tell you in the app before the change takes effect. The "last updated" date above always reflects the current version.
Draft prepared from the application's actual data flows on 2026-08-13. It is not legal advice; have a qualified lawyer review it before public release, particularly the sections covering children's and health-related data.