Privacy Policy
Last updated: March 2026
What's For Dinner (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you use our website and services (collectively, the “Service”).
1. Information We Collect
Information you provide
- Account information: Email address and password (or Google OAuth credentials) when you create an account.
- Meal preferences: Dietary restrictions, allergies, household size, budget range, cooking skill level, cuisine preferences, and preferred cooking time — provided during onboarding.
- Payment information: Billing details processed securely through Lemon Squeezy. We do not store your credit card number, CVV, or full billing details on our servers.
- Communications: Any emails or messages you send to our support address.
Information collected automatically
- Usage data: Pages visited, features used, and general interaction patterns, collected via Vercel Analytics (privacy-focused, no personal data tracking).
- Device information: Browser type, operating system, and screen size for responsive design optimization.
- Device fingerprint: A non-identifying hash used solely to enforce free plan limits (one free plan per device). This fingerprint cannot be used to identify you personally.
2. How We Use Your Information
- Generate meal plans: Your preferences are sent to our AI provider to create personalized weekly meal plans tailored to your dietary needs, budget, and household.
- Deliver plans by email: Your email address is used to send weekly meal plans and important account updates (such as subscription confirmations and billing notifications).
- Process payments: Billing information is shared with Lemon Squeezy to process subscription payments.
- Improve the Service: Aggregated, anonymized usage data helps us understand how people use the Service and where to make improvements.
- Prevent abuse: Device fingerprints and rate limiting help prevent misuse of free plan features.
We do not sell, rent, or trade your personal information with third parties for marketing purposes. We will never send you unsolicited promotional emails beyond what is directly related to the Service.
3. Third-Party Services
We use the following third-party services to operate the Service. Each processes only the minimum data necessary:
- Supabase (database and authentication) — stores your account, preferences, and generated meal plans. Hosted on AWS with encryption at rest.
- Lemon Squeezy (payment processing) — handles subscription billing, invoicing, and tax compliance. See Lemon Squeezy's Privacy Policy.
- Anthropic (Claude AI) — processes your meal preferences to generate personalized plans. Preferences are sent as structured prompts; no personal identifiers (name, email) are included in AI requests.
- Resend (email delivery) — sends your weekly meal plans and transactional emails. See Resend's Privacy Policy.
- Vercel (hosting and analytics) — hosts the website and provides privacy-focused analytics without cookies or personal data collection. See Vercel's Privacy Policy.
4. Cookies and Local Storage
We use essential cookies for authentication and language preferences. We also use browser local storage to cache your free meal plan for immediate display. No third-party tracking cookies are used. We do not use advertising cookies or retargeting pixels.
5. Data Retention
- Active accounts: Your data is retained for as long as your account is active and you have a subscription.
- Cancelled subscriptions: Account data is retained for 90 days after cancellation in case you resubscribe, then automatically deleted.
- Meal plan history: Past meal plans are retained for the duration of your subscription. Up to 5 previous weeks are accessible from your dashboard.
- Deletion requests: Upon request, all your data is permanently deleted within 30 days.
6. Data Security
We take reasonable measures to protect your information, including:
- All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
- Database access is restricted through row-level security policies — you can only access your own data.
- Payment processing is handled entirely by Lemon Squeezy; we never see or store your full payment details.
- Authentication tokens are stored securely using HTTP-only cookies.
7. Your Rights
You have the right to:
- Access your data: View your preferences, meal plan history, and account information from your dashboard.
- Update your data: Modify your meal preferences, email address, or other account details at any time.
- Delete your data: Request complete deletion of your account and all associated data by emailing us.
- Export your data: Request a copy of your personal data in a portable format.
- Withdraw consent: Unsubscribe from email communications at any time (note: transactional emails related to your subscription may still be sent).
To exercise any of these rights, email us at our contact form. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
9. International Data Transfers
Your data may be processed and stored in the United States through our hosting and service providers. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or by posting a prominent notice on the Service at least 30 days before changes take effect. The “Last updated” date at the top of this page indicates the most recent revision.
11. Contact
Questions or concerns about this Privacy Policy? Email us at our contact form.