Privacy Policy
Last updated: 26 March 2026
1. Data we collect
Spoon & Plan collects the following information to provide and improve our service:
- Profile information — your name, email address, and household size provided during account creation.
- Dietary and allergy data — dietary preferences, allergies, and allergy severity. This is special category data under GDPR Article 9 and is only collected with your explicit consent.
- Meal preferences — cuisine preferences, disliked ingredients, and favourite recipes you save within the app.
- Photos — recipe photos you scan are stored securely in Cloudflare R2 and linked to your account.
- Anonymous usage analytics — aggregated, non-personally-identifiable data such as feature usage frequency to help us improve the app experience.
2. Data we do NOT sell
We do not sell, rent, or trade your personal data to third parties. Your information is used solely to operate and improve Spoon & Plan.
3. AI data processing
Spoon & Plan uses AI services (Anthropic Claude) to generate personalised meal plans and extract recipes from photos. Your dietary preferences and household information are sent to our AI provider to create recipes tailored to you. This processing only occurs with your explicit consent (Apple Guideline 5.1.2(i)).
No personal data is retained by the AI provider beyond the immediate request. Your data is not used to train AI models.
4. UK DPA & GDPR compliance
Spoon & Plan is operated by Raines Digital Ltd from the United Kingdom and complies with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). You have the right to access, rectify, or erase your personal data at any time. To exercise these rights, contact us at the email address listed below.
5. Account deletion
You may delete your account and all associated data at any time from the Settings screen within the app, or by contacting our support team. Upon deletion, all personal data is permanently and immediately removed from our systems, including stored photos.
6. Data processors
We use the following third-party processors:
- Supabase — authentication, database hosting, and server-side functions (EU region).
- Cloudflare — image storage (R2), content delivery, and DNS.
- Anthropic — AI meal plan generation and recipe extraction.
- RevenueCat — subscription billing and in-app purchase management. No payment card details are stored by Spoon & Plan directly.
- Sentry — crash reporting (no PII collected).
- PostHog — anonymous usage analytics. Aggregated, non-personally-identifiable data only. No names, emails, or meal content.
- Expo — push notifications. Receives your push token and device information to deliver reminders. You can opt out in your device settings.
- OpenAI — AI meal generation (fallback provider). The same dietary preferences and household data may be processed if the primary provider is temporarily unavailable. Same data minimisation principles apply.
- Google AI (Gemini) — AI meal generation fallback and food photo generation. No personal data is included in image generation prompts.
7. AI-generated content disclaimer
Spoon & Plan uses artificial intelligence to generate meal plans, recipes, and shopping lists. While we validate AI output against your declared allergies, AI-generated content may occasionally contain errors. Always use your own judgement when preparing food, particularly regarding allergens and ingredient safety.
8. No medical or nutritional advice
Spoon & Plan does not provide medical, nutritional, or dietary advice. Content within the app is for informational purposes only and is not a substitute for professional guidance. Consult a qualified healthcare professional before making significant changes to your diet.
9. Children's data
Spoon & Plan accounts are for adults (16+) only. The “household kids” field is a count used for portion sizing — we do not collect individual data about children.
10. Contact
If you have any questions about this privacy policy, please contact us at:
Raines Digital Ltd, United Kingdom