Mellowpan Privacy Policy

Effective date
August 9, 2026
Operator
Wytun LLC (“Wytun,” “we,” “us”)
Product
Mellowpan mobile app (including Share Extension, widget, and Apple Watch companion where available)
Contact
support@wytun.com

This Privacy Policy describes how we collect, use, share, and delete personal information when you use Mellowpan. It is written for App Store launch and should match the shipped product. If something in the app conflicts with this policy, contact us and we will correct the mismatch.

1. Who this policy covers

This policy applies to people who download or use Mellowpan, create an account, join a household, use guest intake features, subscribe, publish public content, or contact support.

Mellowpan is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact support@wytun.com and we will delete it.

2. Information we collect

Account and profile

Household and food preferences

Mellowpan does not intentionally collect a structured medical-condition profile (such as diabetes, gout, or kidney disease). You may still voluntarily type sensitive details into free-text requests; those requests can be processed by our AI provider under the AI section below and are not promoted into a durable condition profile.

User content

Purchases

Device, diagnostics, and support

We do not sell your personal information.

3. How we use information

We use information to:

4. AI processing (hosted by Microsoft)

Mellowpan uses AI models hosted by Microsoft to interpret requests and create personalized questions, meal-planning suggestions, and recipes. The specific underlying model may change over time; Microsoft remains the processor.

When you allow AI processing, we may send your request and relevant household food context (such as preferences, allergies or exclusions you provide, pantry/inventory context, and related notes needed for the task) to Microsoft to generate a response.

According to Microsoft’s published Microsoft Foundry data-privacy documentation (re-validated at launch time, and re-validated whenever the underlying model changes):

You can withdraw AI permission in Settings where offered. After withdrawal, we stop sending future AI-backed requests. Some features require AI and will be unavailable without permission.

AI output can be wrong or incomplete. See our Terms of Use for health, allergy, and accuracy limitations.

Public-content safety screening (Microsoft Azure AI Content Safety)

Before a public caption, profile field, or user photo is published, Mellowpan applies deterministic checks and sends the relevant text or image to Microsoft Azure AI Content Safety for abuse screening. Microsoft processes that submission to provide the screening service. A clear deterministic prohibition is rejected; uncertain results, higher-severity results, and provider errors remain private and may enter human review instead of becoming public. Screening is not perfect and does not replace user reports, blocks, or server-side enforcement.

The founding operator of Wytun LLC reviews reports and uncertain screening cases in Mellowpan's protected Administration area. The operator may see the minimum content and evidence needed to make a safety decision. We do not retain raw Azure responses as a permanent content archive, and we do not put raw report text, submitted media, signed media URLs, or provider payloads in routine analytics or crash logs.

5. Who we share information with

We share information with processors that help us run Mellowpan, including:

ProcessorRole
SupabaseAuthentication, database, storage, edge functions
Microsoft AzureHosting for generation workers, AI model inference, and Azure AI Content Safety screening of public text and images
AppleApp distribution, push notifications, In-App Purchases
RevenueCatSubscription entitlement management
SentryCrash/error reporting (privacy-scrubbed)
TheMealDB (catalog)Source of curated/reference recipe catalog content where used
YouTube Data API (recipe import)Reads public video metadata and descriptions only when a user imports a YouTube link; transient metadata is discarded after preview/import processing
CloudflareDelivery of public Privacy, Terms, Community Guidelines, Support, invite-link, and Apple association pages; edge request metadata may be processed under Cloudflare's provider controls
Wikimedia Commons (image lookup)Optional public image lookup for dish illustrations; search terms and public asset requests may reach Wikimedia, while per-file rights and attribution remain subject to the checked-in source registry

We may also share information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale of Wytun LLC (with notice where required).

Public content you choose to publish (for example Discover posts) is visible to other users according to the feature settings, subject to moderation state and server-enforced blocks. Reports and moderation decisions are handled by Wytun's founding operator; reporter identity and internal review notes are not disclosed to the reported user.

6. Households and multi-party data

Mellowpan is built for households. If you add another person:

Members with accounts can update their own preferences after joining.

7. Retention

We keep information while your account is active and as needed to provide the Service.

After account deletion, we delete or anonymize personal data from live systems, subject to limited retention:

Record typeRetention
Billing / Apple / RevenueCat transaction recordsAs required by Apple, tax, and accounting rules
Security / fraud logsAbout 90 days (longer only for an open investigation)
Moderation reports, decisions, appeals, events, and bounded evidenceAbout 180 days after a case is closed
Removed content kept as moderation evidenceAbout 90 days after removal (or 180 days while tied to an open case or appeal)
Azure Content Safety screening metadataOnly as long as needed for the public-version, active-case, or repeat-abuse purpose, then deleted or aggregated within the bounded moderation window; raw provider responses are not retained as a permanent archive
Generation prompts after deletionDeleted promptly (target within 30 days; backups within rolling backup window, typically ≤ 35 days)
Sentry diagnosticsPer Sentry plan retention; scrubbed at ingest
Minimal analytics eventsUp to 12 months; linked rows are deleted with the account and ordinary review uses privacy-suppressed aggregates

8. Account deletion

If you create an account, you can start account deletion from inside the app (Settings → Delete account).

scoped to those households, even if other accepted members remain.

deleted household and its shared plans, recipes, groceries, inventory, posts, photos, and other household data. They can use another household or receive a new empty household if they have no other membership. Deleted data and premium access are not transferred.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Contact support@wytun.com to make a request.

You can:

We do not sell personal information and do not use App Tracking Transparency “tracking” as Apple defines it for cross-app advertising unless we change the product and update this policy.

We do not use public posts, profile fields, photos, likes, reports, or moderation records for behavioral advertising. Mellowpan is not an advertising service.

10. Security

We use industry-standard safeguards such as encryption in transit (TLS), access controls, and processor security features. No method of transmission or storage is 100% secure.

11. International users

We may process and store information in the United States and other countries where our processors operate. Our initial App Store availability focuses on the United States, Canada, Mexico, Central America, and selected Spanish-language Latin American countries. Broader EU distribution may require additional notices later.

12. Changes

We may update this Privacy Policy. We will change the effective date and, for material changes, provide additional notice in the app or by email when appropriate. Continued use after an update means you acknowledge the revised policy.

13. Contact

Wytun LLC Email: support@wytun.com

For privacy questions, account deletion help, or safety reports, use the same address.