1. Overview & Our Commitment
This Privacy Policy explains how MealPlanner ("we", "us", or "the app") collects, uses, stores, and protects personal, nutritional, and account information when you install and interact with the MealPlanner mobile application.
MealPlanner is designed around data minimization: we only collect the minimum information strictly required to calculate your personalized nutritional targets, track your food intake and meal plans, and facilitate secure synchronization between your devices.
Audited Implementation Fact: MealPlanner does NOT sell your personal data. We do not incorporate third-party advertising networks, third-party analytics trackers, or third-party behavioral profiling tools into the application.
2. Information Collected by Account Type
A. Guest Usage (No Registration Required)
You can use MealPlanner fully as a Guest without providing your name, email address, or creating a password. When using the app as a guest:
- All food diary entries, custom recipes, meal plans, and biometric measurements are stored locally on your device in an isolated SQLite database.
- No personal credentials are transmitted to or stored on remote cloud servers.
B. Email & Password Accounts
If you register a permanent account using email and password, we collect:
- Email Address: Used strictly for account identification, session authentication, and data synchronization.
- Display Name (Optional): Used to personalize your dashboard inside the app.
- Password: Your password is never stored in plaintext. On our backend, passwords are derived using the industry-standard PBKDF2-HMAC-SHA256 algorithm with 10,000 iterations and a cryptographically random, per-user 16-byte salt before storage.
C. Google Sign-In Accounts
If you choose to authenticate via Google Sign-In, MealPlanner uses the official Google Sign-In SDK:
- We receive and verify a secure Google ID token (issued by
accounts.google.com) containing your verified email address, Google account identifier (sub claim), and profile name.
- We never have access to or store your Google account password.
- Google Sign-In accounts are isolated and cannot be accessed via direct password login.
3. Health, Nutrition & User-Generated Content
To provide accurate dietary recommendations and tracking, users may enter health and lifestyle data into MealPlanner:
| Data Type |
Specific Attributes Collected |
Primary Purpose |
| Profile & Biometrics |
Age (13–120), biological sex/gender, height, current weight, target weight, activity level |
Calculate basal metabolic rate (BMR), total daily energy expenditure (TDEE), and daily macronutrient targets. |
| Food Diary & Nutrition |
Food items logged, serving quantities, meal categories (breakfast, lunch, dinner, snack), consumption timestamps, water intake |
Track daily caloric and nutrient intake against personalized health targets. |
| Meal Plans & Custom Content |
Generated meal schedules, custom recipes created by the user, saved favorites |
Organize weekly meal planning and cooking workflows. |
| Shopping List & Pantry |
Grocery shopping list items, pantry stock items, check-off statuses |
Help users purchase and track cooking ingredients. |
| Progress & Measurements |
Periodic body weight check-ins and body circumference measurements |
Graph physical progress over time toward user-defined health goals. |
User Ownership: All custom recipes, logged foods, and meal plans are user-owned data. You maintain complete control over your content and can wipe or export it at any time.
4. Subscriptions & Google Play Billing
MealPlanner offers optional recurring subscriptions for premium features (MealPlanner Premium Monthly and MealPlanner Premium Annual):
- All purchases and recurring subscriptions are processed exclusively through Google Play In-App Billing (via the official
in_app_purchase package).
- No Financial Data Collection: MealPlanner does NOT collect, receive, process, or store credit card numbers, debit card numbers, bank account details, or billing addresses.
- Google LLC handles all payment processing and billing transactions. MealPlanner receives only an anonymized purchase token and active entitlement confirmation from Google Play.
5. How Your Data is Stored & Protected
We implement balanced, audited security controls across each layer of the application:
A. Local Device Storage
- Application Database: Nutrition logs, meal plans, custom recipes, and profile data are stored locally in an application-sandboxed SQLite database (managed via Drift).
- Session Credentials: Authentication tokens (JSON Web Tokens and refresh tokens) are encrypted on your device using
FlutterSecureStorage (utilizing Android Keystore and EncryptedSharedPreferences).
B. Network Transport & Cloud Synchronization
- Transport Encryption: All communication between the MealPlanner mobile app and our backend synchronization server occurs strictly over authenticated HTTPS / TLS connections. Cleartext HTTP is never permitted in production.
- Authentication: Cloud sync requests require a signed, short-lived HS256 JSON Web Token (JWT) transmitted via the HTTP
Authorization: Bearer header.
- Accurate Security Statement: Cloud synchronization utilizes transport-layer encryption (HTTPS/TLS) and authenticated database isolation. We do not make false claims of end-to-end encryption (E2EE) or universal hardware-backed encryption.
6. Third-Party Services & Advertising SDK Policy
MealPlanner maintains a clean, private software architecture:
- No Advertising SDKs: There are no advertising SDKs integrated into MealPlanner (no Google AdMob, no Unity Ads, no AppLovin, etc.). You will never see third-party banner ads, video interstitials, or ad tracking inside the app.
- No Third-Party Analytics Trackers: MealPlanner does not include Google Analytics, Firebase Analytics, Facebook SDK, Adjust, AppsFlyer, or other behavioral telemetry trackers.
- No Third-Party Crash Reporting SDKs: We do not embed external crash analytics tools (such as Sentry or Firebase Crashlytics).
- Integrated Third-Party SDKs: The only third-party SDKs present are:
- Google Sign-In SDK (
google_sign_in): For users who choose to log in with their Google account.
- Google Play In-App Billing SDK (
in_app_purchase): For managing subscription purchases through Google Play.
7. Children's Privacy
MealPlanner is intended for users aged 13 and older.
We do not knowingly collect personal or health information from children under 13. If you believe a child under 13 has provided personal data to MealPlanner, please contact us via our developer support channel so we can promptly delete the account and associated records.
8. Data Retention & Your Right to Deletion
You have full ownership and control over your data in MealPlanner:
In-App Account Deletion (Instant & Permanent)
You can permanently delete your account and all associated data at any time from within the mobile app:
- Open MealPlanner and navigate to Settings.
- In the ACCOUNT section, tap Delete Account & Data.
- Confirm the deletion dialog.
Upon confirmation, the app performs a complete wipe:
- Your user profile, food diaries, weight history, meal plans, custom recipes, pantry items, and shopping lists are deleted from the local database.
- Your authenticated cloud records, sync mutations, and refresh tokens are permanently deleted from our server database in an atomic transaction.
- All secure authentication sessions are cleared from your device.
Guest Data Wipe
For Guest users, tapping Delete Account & Data in Settings immediately wipes all local database records and guest session tokens from your device without contacting remote servers.
Deletion Requests Without App Access
If you uninstalled the application or cannot access your mobile device, you can submit an account deletion request by visiting our Account & Data Deletion Page or contacting developer support.
Google Play Subscription Notice: Deleting your account inside MealPlanner does not cancel recurring subscriptions billed by Google Play. You must cancel active subscriptions in the Google Play Store app > Payments & Subscriptions > Subscriptions.
9. Contact & Support
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact the developer via:
- Email: developer.spectralab@gmail.com
- Google Play Store: You may also reach us through the official developer contact details published on the MealPlanner Google Play Store page.