Privacy Policy
Last updated: April 25, 2026 Effective date: April 25, 2026
Important: This is a template prepared by an AI assistant. It is not legal advice. Have a Delaware-licensed attorney review before any paid launch or App Store submission, and confirm answers to the App Store App Privacy questionnaire match this policy.
This Privacy Policy describes how MnM Labs Inc. ("MnM Labs", "we", "us", "our") collects, uses, shares, and protects information when you use The Fridge mobile application and related services (the "Service").
By using the Service, you agree to the practices described here. If you do not agree, do not use the Service.
1. Information We Collect
1.1 You provide directly
- Account information — name, email address, and a unique user identifier from Apple Sign In or Google Sign In (we do not receive your Apple/Google password).
- Profile — dietary preferences, allergies, restrictions, household size, skill level, equipment, and similar onboarding data you choose to share.
- Pantry & inventory — items you add, edit, or remove (name, quantity, category, expiry, source).
- Photos — images of food, receipts, and barcodes you submit through the scan feature.
- Voice & audio — when voice mode is active, audio captured by your device's microphone.
- Cooking sessions — recipes you cook, ratings, completion status, timer usage, transcripts of voice conversations.
- Support communications — emails or messages you send us.
1.2 Generated by your use
- Device & technical data — device model, OS version, app version, IP address (truncated), language, and time zone.
- Usage analytics — feature use, screen views, scan counts, voice-session duration, errors and crash reports.
- Diagnostic logs — server-side logs (truncated/redacted) including error stack traces.
1.3 From third parties
- Authentication providers — when you sign in with Apple or Google, we receive a unique ID and (where you allow) name and email.
- Voice provider — when you use voice mode, we may receive transcripts and metadata from the voice-AI provider for the active session.
1.4 What we don't collect
- We don't collect precise location, contacts, photo library at large, calendar, health records, or financial account numbers.
- Apple's App Store handles all payment information; we never see your card or Apple ID password.
- We don't use third-party advertising or tracking SDKs.
2. How We Use Information
We use the information above to:
- Provide and operate the Service (recipe suggestions, voice cooking, pantry tracking, scan recognition).
- Personalize AI responses based on your dietary preferences, pantry, and prior sessions.
- Authenticate you and secure your account.
- Send transactional notifications (timers, session prompts, account messages). We do not send marketing email without consent.
- Diagnose, debug, and improve the Service (crash reports, anonymized analytics).
- Monitor for abuse and enforce our Terms.
- Comply with legal obligations and respond to lawful requests.
We do not sell your personal information. We do not use your User Content to train third-party AI models. We may use de-identified, aggregated data to improve our prompts, knowledge base, and pricing.
3. AI & Generative-Model Processing
Operating the Service requires sending portions of your data to AI providers for inference:
| Data | Sent to | Purpose |
|---|---|---|
| Voice audio + transcripts | ElevenLabs | Real-time speech-to-text, response generation, text-to-speech |
| Voice transcripts + pantry context | OpenAI / Google Gemini | Cooking guidance, recipe planning |
| Photos (food, receipts, barcodes) | Google Gemini | Image recognition (ingredient identification, quantity extraction) |
| Pantry items + dietary profile | OpenAI / Google Gemini | Suggestion generation, substitution logic |
We have configured these providers to: retain data only as needed to deliver the response; not use your inputs or outputs to train their general-purpose models, where the provider supports that setting.
ElevenLabs may retain voice audio for short periods under its standard retention policy. We are evaluating zero-retention agreements.
If you do not consent to this processing, you cannot use the corresponding feature.
4. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact support@mnm.ag and we will delete it.
If you are between 13 and 18, you may use the Service only with parental or legal-guardian consent.
5. Sharing & Disclosure
We share information only as described below.
5.1 Service providers (data processors)
We share information with vendors who process data on our behalf, bound by contract to use it only for the services they provide to us:
| Provider | Purpose | Data category |
|---|---|---|
| Apple | Sign In with Apple, App Store | Auth identifier, purchase records |
| Sign In with Google | Auth identifier | |
| Supabase (PostgreSQL hosting) | Database, storage | Account, pantry, sessions, transcripts |
| Railway | Backend hosting | Server logs, in-flight requests |
| ElevenLabs | Voice AI | Audio, transcripts |
| Google Gemini | Vision + LLM | Photos, prompts |
| OpenAI | LLM | Prompts, transcripts |
| Sentry | Error monitoring | Stack traces, redacted user IDs |
5.2 Legal & safety
We may disclose information if required by law, subpoena, or court order, or to protect the rights, property, or safety of MnM Labs, our users, or others.
5.3 Business transfers
If MnM Labs is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred subject to this Privacy Policy.
5.4 With your consent
We may share information for any other purpose with your explicit consent.
6. Data Retention
| Category | Retention |
|---|---|
| Account & profile | Until you delete your account |
| Pantry, recipes, sessions | Until you delete the data or your account |
| Voice audio | Up to 30 days at the voice provider, then purged; we do not store raw audio long-term |
| Voice transcripts | Stored with the cooking session; deletable |
| Photos (scans) | Processed in-flight; we typically do not retain the raw image after recognition completes |
| Diagnostic & error logs | Up to 90 days |
| Analytics events | Up to 24 months, aggregated |
| Backups | Up to 30 days after deletion in our backups, then purged |
After account deletion, residual data may persist in immutable backups for up to 30 days before automated purge.
7. Your Rights
Depending on where you live, you may have rights under laws including the California Consumer Privacy Act (CCPA/CPRA), the EU and UK General Data Protection Regulation (GDPR), and similar laws.
You may:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Export your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent at any time (this does not affect prior processing).
- Opt out of any "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising).
To exercise rights, email support@mnm.ag from the email address associated with your account, or use in-app delete-account controls. We will respond within 30 days (CCPA) or 30 days extendable to 90 (GDPR).
You may also lodge a complaint with your local data-protection authority.
California "Shine the Light" notice: California residents may request information about disclosures of personal information to third parties for direct-marketing purposes. We do not engage in such disclosures.
8. Security
We use commercially reasonable technical and organizational measures to protect your information, including:
- TLS encryption for data in transit.
- Encryption at rest for our primary database.
- Authentication via Apple/Google identity providers (we never see your password).
- Server-side validation of all auth tokens (JWT/JWKS).
- Rate limiting and abuse detection.
- Access controls limiting employee access to production data.
- Regular security review and dependency monitoring.
No method of transmission or storage is 100% secure. You are responsible for keeping your device and authentication credentials secure.
9. International Transfers
We are based in the United States and our service providers are primarily in the United States, the European Union, and the United Kingdom. By using the Service, you consent to the transfer of your information to and processing in the United States and other jurisdictions, which may have data-protection laws different from your country.
For transfers from the EU/UK to the U.S., we rely on Standard Contractual Clauses or equivalent safeguards where required.
10. Cookies & Tracking
The Service is a native mobile app and does not use cookies, web beacons, or third-party advertising trackers. We do not engage in cross-app or cross-site tracking. The App Tracking Transparency framework does not apply because we do not track for ad purposes.
11. Apple App Privacy Details
Per Apple's requirements, the categories of data the Service collects and how they are linked to your identity are summarized in the App Store listing's "App Privacy" section. The categories below match this Privacy Policy:
| Category | Linked to user | Used for tracking |
|---|---|---|
| Contact info (email) | Yes | No |
| User content (pantry, photos, voice) | Yes | No |
| Identifiers (user ID) | Yes | No |
| Usage data | Yes | No |
| Diagnostics | Yes | No |
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the Service or by email at least 14 days before they take effect. Your continued use after the effective date constitutes acceptance.
13. Contact
For privacy questions, requests, or complaints:
MnM Labs Inc. Delaware, United States support@mnm.ag