ListThisMeal Get the app

Privacy Policy

ListThisMeal · Last updated 6 October 2026

This policy explains what the ListThisMeal app collects, why, who else sees it, and how to get rid of it. It covers the app, which is used on phones only, and this website, listthismeal.com, which explains the app and how to install it.

Who we are. ListThisMeal is operated from the Philippines by the developer named under “Contact” at the foot of this page, who is the data controller for everything described here. The same address reaches our Data Protection Officer.

1. The short version

2. What we collect

Account and profile

Content you create

Health, dietary and religious information — sensitive data

Read this one. While you set up your account, and later on Profile → Diet & Health, the app asks about food allergies, health conditions (including an option for pregnancy), diets, and religious dietary rules such as halal and kosher. You choose whether to answer; every one of those questions can be skipped.

Under the EU GDPR (Art. 9) and the Philippine Data Privacy Act of 2012 (§3(l)) this counts as sensitive personal information. We process it only with your explicit consent, which the app asks for on a screen of its own, with its own “I agree”, before your first answer is saved; we record when you agreed and to which wording. We use it for exactly one purpose: filtering and flagging recipes so the app does not put food in front of you that you cannot or will not eat. It is never used for advertising, never shared with an advertiser or an insurer, and never sold. Our Consumer Health Data page says the same in more detail.

You can change or clear these answers in the app at any time, and deleting your account deletes them outright. The filtering is guidance, not a clinical guarantee — always check ingredient labels yourself.

Device and technical data

We do not collect your contacts, your photo library beyond the individual images you attach to a recipe, a precise GPS track, or anything you do outside the app.

3. What other people can see

Your shopping list, meal plans, pantry, and your allergy, health and diet answers are never shown to other people — unless you share a plan with a Group (below). These are the things other people can see.

Your profile

Your recipes and collections

Saving, planning and shopping from somebody else's recipe

Groups

Invitations, blocking and reports

Taking something down stops us showing it; it does not recall it. You can make a public recipe private again, delete it, or delete your account, at any time, and it disappears from the app. It cannot reach anybody who already read it, wrote it down, took a screenshot or saved their own copy — no service can do that.

4. Who we share it with

These are the only third parties that ever receive your data, and each gets the minimum it needs to do its job:

ServiceWhat it receivesWhy
Supabase (AWS, Singapore) Your account, profile, and all the content and preferences described above Authentication, database and file storage — our primary backend
Cloudflare Pages Standard web request logs Hosting and delivering this website
Cloudflare Email Routing Emails you send to support@dcr8ives.com Passing them on to our support mailbox
Google (Gmail) Emails you send to support and our replies Our support mailbox
Google Sign-In Only if you choose “Continue with Google”: Google tells us your name, email address and profile photo, and learns that you signed in to ListThisMeal Signing you in
Google Firebase Cloud Messaging Your device push token and the text of a notification Delivering push notifications you have opted into
Resend Your email address and the message body Sending the emails the app sends you: sign-in and password-reset codes, the weekly digest, and replies about a support request
OpenAI The text of a question you type to Cartie, the help assistant — no account identifier, no name, no email Finding the help article that answers it. Nothing is sent unless you ask Cartie something.
OpenAI What you are about to post for others to see — a recipe's name, description, steps and new photo; your name, username, bio and new profile photo; a collection's name, description and new cover; a group's name — sent without your account or your email. When the thing being checked is your name, username, bio or profile photo, that is what is sent. Checking it does not break our content rules before it is saved. A recipe kept to you alone is checked too, because it can be shared later. Support messages and reports are never checked.
Your phone's geocoding service (Google's on Android) An approximate position, only when the app needs your country Turning a location fix into a country name. We keep the country, never your coordinates.
Google AdMob Your IP address, the kind of device and app version, how you interact with an ad, and a per-app ID Google uses to count and protect its ads — never your name or email, and never your phone's advertising ID, which the app does not read Showing ads on the free plan. Ads are never personalised: they are not chosen from your interests and never follow you between apps. In the European Economic Area, the UK and Switzerland, Google asks for your consent first, and Settings → Ad privacy choices lets you change your answer.
Google Play Your payment details, handled entirely by Google Play Taking subscription payments. The app never sees your card, e-wallet or bank details.

We also disclose data where the law requires it, and to investigate abuse, fraud, or a threat to someone's safety.

5. Why we may use it

The law asks us to name the ground for each use. These are ours:

What we doOn what ground
Your account, profile, recipes, lists, plans and syncing them; your plan and its payments; the emails and codes that sign you in; answering you when you ask the help assistant or write to us Providing the app you signed up for (a contract with you)
Your allergies, health conditions, diet and religious food rules Your explicit consent, which you can withdraw at any time
Your location, the microphone for voice search, and push notifications Your consent, given when you allow it on your phone
Ads on the free plan Our legitimate interest in paying for the free plan; in the European Economic Area, the UK and Switzerland, your consent through Google's prompt
The check on what you post, reports, blocking, the device and referral checks, server logs, and keeping a report after the reporter leaves Our legitimate interest in keeping the app safe and fair for the people who use it
The weekly digest email to subscribers Our legitimate interest in telling subscribers about the app they pay for — every digest has a one-tap unsubscribe
Records and answers the law requires of us A legal obligation

6. Where your data lives

Our database is hosted in Singapore (AWS ap-southeast-1). The services listed above may process data in other countries, including the United States. Where personal data leaves the Philippines, the EEA or the UK it is transferred under the receiving provider's standard contractual clauses — for the UK, with the UK's International Data Transfer Addendum. You can ask us for a copy of these safeguards at the address below.

7. How long we keep it

8. Your rights

You may access, correct, export, restrict or delete your personal data, object to processing, and withdraw a consent you have given — including the consent for the health and dietary information above. Most of this is available directly in the app; for anything else write to the address below and we will answer within 30 days. Health information has its own page: Consumer Health Data.

If you are in the Philippines you may complain to the National Privacy Commission; in the EEA or the UK, to your local supervisory authority.

9. Children

ListThisMeal is not directed at children. You must be 16 or older to use ListThisMeal, wherever you live. We do not knowingly collect data from anyone younger. If we learn that someone under 16 has an account, we delete it and everything in it; if you believe we have such an account, contact us.

If you are 16 or 17

10. Security

Traffic is encrypted in transit (TLS) and the database is encrypted at rest. Access to your rows is enforced by row-level security inside the database itself, not only by the app. Passwords are stored as salted hashes. No system is perfect, and we will notify you and the relevant authority if a breach affects your personal data.

11. Changes to this policy

If we change how we use your data we will update the date at the top of this page and, for anything material, tell you in the app before the change takes effect.

12. Contact

Dcr8ives — support@dcr8ives.com

Data Protection Officer — the same address, with “Data Protection Officer” in the subject.

To report illegal content, with or without an account, see listthismeal.com/report.

Terms of Service · Consumer Health Data · Delete your account