Privacy policy
Last updated: 15 September 2026
This policy describes what happens to data when you use the MenuBuddy iPhone app and this website. It is written to be read, not clicked through.
Who is responsible
The data controller is Szymon Dziedzic (ChochoApps), the author of MenuBuddy. Contact: the form on the Contact page. We answer data requests within 30 days at the latest.
The short version
- We do not sell data and we show no advertising.
- Your name, avatar, scan history and favourites stay on your phone.
- Menu photos are not stored by us — they pass through our server to the model that reads them, and are gone.
- This website uses no cookies and no analytics.
What we process and why
| Data | Purpose | Where it goes | How long |
|---|---|---|---|
| Account identifier (uid) and sign-in method (Apple / Google) | Tying the starter pack and the Pro plan to a person, not a phone | Firebase Authentication (Google Ireland Ltd.) | Until you delete the account |
| Usage counters and plan status | Enforcing the free pack and the subscription | Cloud Firestore, region europe-central2 (Warsaw) | Until you delete the account |
| Menu photo | Reading and translating the menu | Cloud Functions → OpenAI (processor) | Not stored by us. OpenAI may retain it for up to 30 days for abuse monitoring and does not train on it |
| Food profile: allergens, diet, likes and dislikes, language | Scoring dishes for you and writing sentences for the waiter | Your phone (persistently) + the body of a single model request | Nothing is kept on the server |
| Recording of the waiter (up to 15 s) | Transcription and translation | Cloud Functions → OpenAI | Not stored |
| Text to be read aloud | Speech synthesis with a better voice | OpenAI or ElevenLabs, depending on the voice you choose | Not stored |
| Technical events: successful scan, dish count, response time, crashes | Knowing whether the app works | Firebase Analytics and Crashlytics, Cloud Logging | Logs 30 days |
| Purchase proof (signed store receipt) | Turning on the Pro plan after verification | Apple / Google → our server | Until you delete the account |
| Contact form: name, email, message | Answering your message | Netlify (this site's host) | Up to 24 months |
What we deliberately do not collect
No content reaches analytics: not dish names, not the restaurant's name, not your allergens, not the menu photo. We know a scan succeeded and that it found, say, 24 dishes — we do not know which. We collect no location, no contacts and no advertising identifiers.
Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)) — account, limits, scanning, phrasebook, subscription handling.
- Consent (Art. 9(2)(a)) — allergy information is health data. You provide it voluntarily so the app can warn you. Withdraw consent by clearing the allergens in your profile; the app then stops scoring dishes against them.
- Legitimate interest (Art. 6(1)(f)) — service security, abuse detection and basic technical telemetry.
Processors
- Google Ireland Ltd. — Firebase: sign-in, the limits database, cloud functions, analytics and crash reports. Data region: europe-central2 (Warsaw).
- OpenAI Ireland Ltd. — reading the menu, writing sentences, transcription and speech. Under the API terms, API data is not used to train models.
- ElevenLabs Inc. (USA) — only if you choose the ElevenLabs voice. Transfer based on standard contractual clauses.
- Apple Inc. and Google Ireland Ltd. — payments and purchase verification.
- Netlify Inc. (USA) — hosting this site and receiving the contact form.
We neither sell data nor share it for marketing.
Children
MenuBuddy is not directed at children under 13 and we do not knowingly collect their data. The app is rated 4+ on the App Store, but a store account is created by an adult.
Your rights
You have the right of access, rectification, erasure, restriction, portability and objection. The short paths:
- Delete the account and all server-side data — in the app: Profile → Narrator voice and settings → Delete account. It works immediately and needs no email to us.
- Delete data from the phone — Profile → Start over, or uninstall the app.
- Anything else — through the form on the Contact page.
You may also lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw) or with the authority in your own country.
Security
Traffic between the app and the server is encrypted (TLS). The model key never sits in the app — it lives in a server-side secret manager and is rotatable. Every paid call requires a signed-in account and is subject to per-account limits.
Dish photos from Wikimedia Commons
If you ask for a photo of a dish, the app sends the dish name alone to the public Wikimedia Commons API, straight from your phone. None of your data is attached. This happens only when you tap — never automatically.
Changes
If we change this policy we change the date at the top, and for significant changes we say so in the app. Earlier versions are available on request.