Mellowpan Privacy Policy
This Privacy Policy describes how we collect, use, share, and delete personal information when you use Mellowpan. It is written for App Store launch and should match the shipped product. If something in the app conflicts with this policy, contact us and we will correct the mismatch.
1. Who this policy covers
This policy applies to people who download or use Mellowpan, create an account, join a household, use guest intake features, subscribe, publish public content, or contact support.
Mellowpan is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact support@wytun.com and we will delete it.
2. Information we collect
Account and profile
- Email address and authentication identifiers (via Supabase Auth)
- Display name and profile details you choose to provide
- Household membership, roles, invitations, and join-link activity
Household and food preferences
- Allergies, excluded foods, dietary patterns, cuisine preferences
- Food goals and foods you choose to favor or limit (for example purine-conscious planning, lower saturated fat, more fiber, less sodium)
- Concrete clinician-directed food rules you enter as foods to leave out (for example “avoid grapefruit”), not structured medical diagnoses
- Portion / planning defaults, pantry and grocery items, meal plans, cooking progress
- Managed household people you add (including children or dependents you represent)
Mellowpan does not intentionally collect a structured medical-condition profile (such as diabetes, gout, or kidney disease). You may still voluntarily type sensitive details into free-text requests; those requests can be processed by our AI provider under the AI section below and are not promoted into a durable condition profile.
User content
- Recipes, notes, photos, captions, imports, public profile fields, and public Discover posts or likes
- Voice input when you use dictation (processed to text for your request)
- Prompts and free-text requests you send for AI-assisted planning or recipe work
Purchases
- Subscription and entitlement state via Apple In-App Purchase and RevenueCat (we receive purchase/entitlement metadata; Apple processes payment)
Device, diagnostics, and support
- Device and app technical data needed to run the service
- Crash and error diagnostics via Sentry (configured to avoid sending prompts, allergies, emails, or other sensitive content by default)
- Operational metrics for our Azure-hosted generation worker (Azure Monitor)
- Messages you send to support@wytun.com
- Push notification tokens if you enable notifications
- Report, block, screening, moderation, enforcement, appeal, and safety-notice records when you use public-content safety tools, including the limited contact and work-identification details needed for an intellectual-property report
We do not sell your personal information.
3. How we use information
We use information to:
- create and secure your account and household
- generate and adapt meal plans, recipes, grocery lists, and related suggestions
- filter suggestions against allergies and exclusions you provide
- operate Discover, likes, and other features you use
- screen public captions, profile fields, and photos for objectionable content before publication, investigate reports, enforce the Community Guidelines, and process appeals
- process subscriptions and restore purchases
- provide support, security, fraud prevention, and abuse moderation
- improve reliability (crash diagnosis and limited product analytics)
- comply with law and enforce our Terms
4. AI processing (hosted by Microsoft)
Mellowpan uses AI models hosted by Microsoft to interpret requests and create personalized questions, meal-planning suggestions, and recipes. The specific underlying model may change over time; Microsoft remains the processor.
When you allow AI processing, we may send your request and relevant household food context (such as preferences, allergies or exclusions you provide, pantry/inventory context, and related notes needed for the task) to Microsoft to generate a response.
According to Microsoft’s published Microsoft Foundry data-privacy documentation (re-validated at launch time, and re-validated whenever the underlying model changes):
- prompts and completions are not used to train foundation models
- your content is not made available to other Azure customers or to the model provider’s own public consumer product as the processor
- Microsoft may operate abuse monitoring, which can include automated review and, for some flagged content, human review by authorized Microsoft employees
- ordinary chat/completions are processed to fulfill the request; our production deployments may use Global deployment types, which means prompts/responses may be processed in more than one geography where the model is available
You can withdraw AI permission in Settings where offered. After withdrawal, we stop sending future AI-backed requests. Some features require AI and will be unavailable without permission.
AI output can be wrong or incomplete. See our Terms of Use for health, allergy, and accuracy limitations.
Public-content safety screening (Microsoft Azure AI Content Safety)
Before a public caption, profile field, or user photo is published, Mellowpan applies deterministic checks and sends the relevant text or image to Microsoft Azure AI Content Safety for abuse screening. Microsoft processes that submission to provide the screening service. A clear deterministic prohibition is rejected; uncertain results, higher-severity results, and provider errors remain private and may enter human review instead of becoming public. Screening is not perfect and does not replace user reports, blocks, or server-side enforcement.
The founding operator of Wytun LLC reviews reports and uncertain screening cases in Mellowpan's protected Administration area. The operator may see the minimum content and evidence needed to make a safety decision. We do not retain raw Azure responses as a permanent content archive, and we do not put raw report text, submitted media, signed media URLs, or provider payloads in routine analytics or crash logs.
5. Who we share information with
We share information with processors that help us run Mellowpan, including:
| Processor | Role |
|---|---|
| Supabase | Authentication, database, storage, edge functions |
| Microsoft Azure | Hosting for generation workers, AI model inference, and Azure AI Content Safety screening of public text and images |
| Apple | App distribution, push notifications, In-App Purchases |
| RevenueCat | Subscription entitlement management |
| Sentry | Crash/error reporting (privacy-scrubbed) |
| TheMealDB (catalog) | Source of curated/reference recipe catalog content where used |
| YouTube Data API (recipe import) | Reads public video metadata and descriptions only when a user imports a YouTube link; transient metadata is discarded after preview/import processing |
| Cloudflare | Delivery of public Privacy, Terms, Community Guidelines, Support, invite-link, and Apple association pages; edge request metadata may be processed under Cloudflare's provider controls |
| Wikimedia Commons (image lookup) | Optional public image lookup for dish illustrations; search terms and public asset requests may reach Wikimedia, while per-file rights and attribution remain subject to the checked-in source registry |
We may also share information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale of Wytun LLC (with notice where required).
Public content you choose to publish (for example Discover posts) is visible to other users according to the feature settings, subject to moderation state and server-enforced blocks. Reports and moderation decisions are handled by Wytun's founding operator; reporter identity and internal review notes are not disclosed to the reported user.
6. Households and multi-party data
Mellowpan is built for households. If you add another person:
- information you enter about them may be used to plan shared meals
- for AI prompts, we aim to minimize what is sent (for example prefer allergies/exclusions over narrative health notes for managed people, and exclude pending invitees until they accept)
- an adult account holder is responsible for having appropriate authority before entering a child’s or dependent’s information
Members with accounts can update their own preferences after joining.
7. Retention
We keep information while your account is active and as needed to provide the Service.
After account deletion, we delete or anonymize personal data from live systems, subject to limited retention:
| Record type | Retention |
|---|---|
| Billing / Apple / RevenueCat transaction records | As required by Apple, tax, and accounting rules |
| Security / fraud logs | About 90 days (longer only for an open investigation) |
| Moderation reports, decisions, appeals, events, and bounded evidence | About 180 days after a case is closed |
| Removed content kept as moderation evidence | About 90 days after removal (or 180 days while tied to an open case or appeal) |
| Azure Content Safety screening metadata | Only as long as needed for the public-version, active-case, or repeat-abuse purpose, then deleted or aggregated within the bounded moderation window; raw provider responses are not retained as a permanent archive |
| Generation prompts after deletion | Deleted promptly (target within 30 days; backups within rolling backup window, typically ≤ 35 days) |
| Sentry diagnostics | Per Sentry plan retention; scrubbed at ingest |
| Minimal analytics events | Up to 12 months; linked rows are deleted with the account and ordinary review uses privacy-suppressed aggregates |
8. Account deletion
If you create an account, you can start account deletion from inside the app (Settings → Delete account).
- Deleting an owner account deletes every household that account owns and all data
scoped to those households, even if other accepted members remain.
- Other members' Mellowpan accounts remain active, but they lose access to the
deleted household and its shared plans, recipes, groceries, inventory, posts, photos, and other household data. They can use another household or receive a new empty household if they have no other membership. Deleted data and premium access are not transferred.
- Your public posts and related public content are fully deleted (not left as “Deleted User” stubs).
- Moderation records do not prevent deletion: reporter and target account links are cleared where required, and only the minimum case, appeal, audit, or evidence data is retained for its stated limited period. Retained evidence is private and is not a public profile or content archive.
- Deleting your Mellowpan account does not automatically cancel an Apple subscription; use Apple’s subscription management to cancel billing.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Contact support@wytun.com to make a request.
You can:
- edit profile and food preferences in the app
- withdraw AI permission where offered
- control notification, camera, microphone, and photo permissions in system Settings
- delete your account in-app from Settings
- report or block public content/users where those controls are offered
We do not sell personal information and do not use App Tracking Transparency “tracking” as Apple defines it for cross-app advertising unless we change the product and update this policy.
We do not use public posts, profile fields, photos, likes, reports, or moderation records for behavioral advertising. Mellowpan is not an advertising service.
10. Security
We use industry-standard safeguards such as encryption in transit (TLS), access controls, and processor security features. No method of transmission or storage is 100% secure.
11. International users
We may process and store information in the United States and other countries where our processors operate. Our initial App Store availability focuses on the United States, Canada, Mexico, Central America, and selected Spanish-language Latin American countries. Broader EU distribution may require additional notices later.
12. Changes
We may update this Privacy Policy. We will change the effective date and, for material changes, provide additional notice in the app or by email when appropriate. Continued use after an update means you acknowledge the revised policy.
13. Contact
Wytun LLC Email: support@wytun.com
For privacy questions, account deletion help, or safety reports, use the same address.