Privacy Policy
Last updated: June 2026
Supperly ("we", "us", "our") is a meal-planning app. This policy explains what data we collect, why, and how you can control it.
1. What we collect
- Account data: email address and (if you use Google Sign-In) your Google account ID and display name. We never store your Google password.
- Recipes: recipe titles, ingredients, instructions, and images you import or enter manually. Images are stored in Cloudflare R2.
- Meal plans and grocery lists: the meal plans and shopping lists you create inside the app.
- Usage analytics: anonymised event data (e.g. "recipe imported", "grocery list generated") collected via PostHog. These events do not include the content of your recipes. You can opt out by contacting us.
- Error data: technical error information (stack traces, request context) used to fix bugs.
2. How we use your data
- To provide the app's core features (recipe storage, planning, shopping lists).
- To improve the product using aggregated, anonymised analytics.
- To send transactional notifications if you opt in (e.g. household invite accepted).
3. Data sharing
We do not sell your data. We share it only with the following sub-processors:
- Neon (database hosting) — your recipes, meals, and account data.
- Cloudflare R2 (image storage) — recipe images you import.
- PostHog (analytics) — anonymised usage events.
- Google Gemini (AI enhancement) — recipe text is sent to Google's Gemini API to clean, structure, and translate imported recipes.
- Google (authentication) — only if you use Google Sign-In.
- Fly.io (API hosting) — processes all API requests.
4. Data retention
Your account data and recipes are retained until you delete your account. Analytics events are retained for 12 months. You can request deletion at any time (see Contact below).
5. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your data. To exercise these rights, contact us.
6. Security
Passwords are hashed with Argon2id. All data is transmitted over HTTPS. Refresh tokens are stored hashed and rotated on each use.
7. Children
Supperly is not directed at children under 13. We do not knowingly collect data from children.
8. Changes
We will update this policy when we add new data types or change how we use existing ones. The "last updated" date above will reflect any changes.
9. Contact
Questions or requests: mealtime890@gmail.com