Privacy Policy
ListThisMeal · Last updated 6 October 2026
This policy explains what the ListThisMeal app collects, why, who else sees it, and how to get rid of it. It covers the app, which is used on phones only, and this website, listthismeal.com, which explains the app and how to install it.
Who we are. ListThisMeal is operated from the Philippines by the developer named under “Contact” at the foot of this page, who is the data controller for everything described here. The same address reaches our Data Protection Officer.
1. The short version
- You can use the app without an account. The app then keeps your shopping list in a guest account that has no email, name or password. Signing out of it deletes it, and so does not opening the app for a while — see “How long we keep it” below.
- With an account, your content syncs to our database so it survives a reinstall and reaches your other devices.
- We do not sell your personal information and we do not share it with data brokers.
- You can delete your account and everything in it at any time — in the app, or at listthismeal.com/delete-account.
2. What we collect
Account and profile
- Email address and a password (stored only as a salted hash — we never see it).
- If you sign in with Google: the name, email address and profile photo on your Google account. We copy the photo into our own storage as your profile photo, unless you have already chosen one.
- Username, full name, bio, profile photo and country, if you set them.
- The cuisines you say you love, if you pick them, so the app can show you recipes from them first.
- Your chosen app language, so notifications and emails we compose on the server match the language you read the app in.
- Your plan — free, Pro or Group — its trial and renewal dates, and the reference Google Play gives your purchase. Never your card details.
Content you create
- Recipes, ingredients, steps and recipe photos.
- Shopping lists, pantry quantities and meal plans.
- Collections, bookmarks, and the people you block.
- Reports you file about another person, their recipes or collections.
- Who you follow and who follows you, and the recipes you save, plan and add to your shopping list. Section 3 says which of these other people can see.
- Your conversations with Cartie, the in-app help assistant, and anything you send to support, including photos you attach.
Health, dietary and religious information — sensitive data
Read this one. While you set up your account, and later on Profile → Diet & Health, the app asks about food allergies, health conditions (including an option for pregnancy), diets, and religious dietary rules such as halal and kosher. You choose whether to answer; every one of those questions can be skipped.
Under the EU GDPR (Art. 9) and the Philippine Data Privacy Act of 2012 (§3(l)) this counts as sensitive personal information. We process it only with your explicit consent, which the app asks for on a screen of its own, with its own “I agree”, before your first answer is saved; we record when you agreed and to which wording. We use it for exactly one purpose: filtering and flagging recipes so the app does not put food in front of you that you cannot or will not eat. It is never used for advertising, never shared with an advertiser or an insurer, and never sold. Our Consumer Health Data page says the same in more detail.
You can change or clear these answers in the app at any time, and deleting your account deletes them outright. The filtering is guidance, not a clinical guarantee — always check ingredient labels yourself.
Device and technical data
- Push token — an anonymous device identifier issued by Firebase Cloud Messaging so a notification can reach your phone. Stored against your account, and removed when you sign out or delete the account.
- Which devices you're signed in on — a random identifier the app creates when it is installed, a label such as “Android device”, and when it was last used, so your account can be signed in on one device at a time. You can see and remove them in Settings → Your devices, and they are deleted with your account.
- Approximate location — only if you allow it, and only to work out your country: to put its cuisines first in the recipe filter, to fill in your country when you tap “Use my location” while setting up your profile, and — if your phone already allows it — to show what people in your country are planning this week. We ask only when you tap something that needs it, never at launch. To turn a position into a country your phone asks its own geocoding service (Google's on Android, Apple's on iOS); we keep the country, never your coordinates.
- Microphone audio — only while you are actively using voice search. The audio is handled by your device's own speech recogniser (Apple's or Google's, depending on the phone); we receive only the resulting text and never record or store audio.
- Referral data — if you sign up through someone's referral link we record which account referred you, plus a coarse device signal used solely to detect one person rewarding themselves with several accounts.
- Standard server logs from our hosting providers (IP address, timestamp, user agent), kept for security and abuse investigation. We do not copy them: our database host keeps its own for one day on our current plan, and the others for a short time on their own schedules.
We do not collect your contacts, your photo library beyond the individual images you attach to a recipe, a precise GPS track, or anything you do outside the app.
3. What other people can see
Your shopping list, meal plans, pantry, and your allergy, health and diet answers are never shown to other people — unless you share a plan with a Group (below). These are the things other people can see.
Your profile
- Your username, full name, profile photo, bio and country, and how many people you follow and follow you, can be seen by anyone using the app.
- A private account (Settings → Private account) means people have to ask to follow you and you choose who is let in, and only the people you let in can see who you follow and who follows you. It does not hide your profile details or your counts, and a recipe you made Public stays Public until you change it.
Your recipes and collections
- Each recipe has its own audience, chosen when you save it: Public (anyone using the app), Followers (only people you have let follow you) or Only me. A new recipe starts on Public if your account is public and on Followers if it is private; you can change it before you save, and at any time after.
- A collection is seen by other people only once you publish it.
- People who follow you see the recipes and collections you publish in their Followed feed.
Saving, planning and shopping from somebody else's recipe
- When you save somebody's recipe, they are told, by name.
- When you add somebody's recipe to your meal planner, they are told, by name, and your name appears on that recipe's “Planners” list. The app tells you this before your first add. A recipe Surprise Me picks for you is recorded the same way but notifies nobody.
- When you add a recipe's ingredients to your shopping list, your name appears on that recipe's “Shoppers” list. Nobody is notified.
- If your account is private, other people see you on those lists as “Someone”, but the recipe's creator sees your name.
- A recipe shows how many times it has been saved, planned and shopped, and planned recipes count, without names, towards the “Most planned” list for your country.
- Nothing else about your plan is shared: the day, the meal, the servings and what else is on your list stay in your account.
- Removing the meal or the items later does not remove the record that you added them, because you did. Deleting your account removes it.
- A recipe's creator can turn these notifications off in Settings → Notifications.
Groups
- If you join a Group plan, its members share one meal planner and one shopping list: everyone in the group can see, add, change and remove what is on them, and the app shows who added what. Members are told about changes the group makes.
- The group's owner is told if you have not opened the app for two weeks.
- Leaving the group ends the sharing.
Invitations, blocking and reports
- If you join through somebody's invite link, they see your name in their list of invitations, and when their reward is earned — which happens once you pay the regular price for a plan.
- Blocking somebody hides their recipes, collections and activity from you and ends following both ways. They are not told, and it does not hide your public recipes from them.
- If you report somebody, they are not told who reported them.
Taking something down stops us showing it; it does not recall it. You can make a public recipe private again, delete it, or delete your account, at any time, and it disappears from the app. It cannot reach anybody who already read it, wrote it down, took a screenshot or saved their own copy — no service can do that.
4. Who we share it with
These are the only third parties that ever receive your data, and each gets the minimum it needs to do its job:
| Service | What it receives | Why |
|---|---|---|
| Supabase (AWS, Singapore) | Your account, profile, and all the content and preferences described above | Authentication, database and file storage — our primary backend |
| Cloudflare Pages | Standard web request logs | Hosting and delivering this website |
| Cloudflare Email Routing | Emails you send to support@dcr8ives.com | Passing them on to our support mailbox |
| Google (Gmail) | Emails you send to support and our replies | Our support mailbox |
| Google Sign-In | Only if you choose “Continue with Google”: Google tells us your name, email address and profile photo, and learns that you signed in to ListThisMeal | Signing you in |
| Google Firebase Cloud Messaging | Your device push token and the text of a notification | Delivering push notifications you have opted into |
| Resend | Your email address and the message body | Sending the emails the app sends you: sign-in and password-reset codes, the weekly digest, and replies about a support request |
| OpenAI | The text of a question you type to Cartie, the help assistant — no account identifier, no name, no email | Finding the help article that answers it. Nothing is sent unless you ask Cartie something. |
| OpenAI | What you are about to post for others to see — a recipe's name, description, steps and new photo; your name, username, bio and new profile photo; a collection's name, description and new cover; a group's name — sent without your account or your email. When the thing being checked is your name, username, bio or profile photo, that is what is sent. | Checking it does not break our content rules before it is saved. A recipe kept to you alone is checked too, because it can be shared later. Support messages and reports are never checked. |
| Your phone's geocoding service (Google's on Android) | An approximate position, only when the app needs your country | Turning a location fix into a country name. We keep the country, never your coordinates. |
| Google AdMob | Your IP address, the kind of device and app version, how you interact with an ad, and a per-app ID Google uses to count and protect its ads — never your name or email, and never your phone's advertising ID, which the app does not read | Showing ads on the free plan. Ads are never personalised: they are not chosen from your interests and never follow you between apps. In the European Economic Area, the UK and Switzerland, Google asks for your consent first, and Settings → Ad privacy choices lets you change your answer. |
| Google Play | Your payment details, handled entirely by Google Play | Taking subscription payments. The app never sees your card, e-wallet or bank details. |
We also disclose data where the law requires it, and to investigate abuse, fraud, or a threat to someone's safety.
5. Why we may use it
The law asks us to name the ground for each use. These are ours:
| What we do | On what ground |
|---|---|
| Your account, profile, recipes, lists, plans and syncing them; your plan and its payments; the emails and codes that sign you in; answering you when you ask the help assistant or write to us | Providing the app you signed up for (a contract with you) |
| Your allergies, health conditions, diet and religious food rules | Your explicit consent, which you can withdraw at any time |
| Your location, the microphone for voice search, and push notifications | Your consent, given when you allow it on your phone |
| Ads on the free plan | Our legitimate interest in paying for the free plan; in the European Economic Area, the UK and Switzerland, your consent through Google's prompt |
| The check on what you post, reports, blocking, the device and referral checks, server logs, and keeping a report after the reporter leaves | Our legitimate interest in keeping the app safe and fair for the people who use it |
| The weekly digest email to subscribers | Our legitimate interest in telling subscribers about the app they pay for — every digest has a one-tap unsubscribe |
| Records and answers the law requires of us | A legal obligation |
6. Where your data lives
Our database is hosted in Singapore (AWS ap-southeast-1). The
services listed above may process data in other countries, including the United
States. Where personal data leaves the Philippines, the EEA or the UK it is
transferred under the receiving provider's standard contractual clauses —
for the UK, with the UK's International Data Transfer Addendum. You can ask us
for a copy of these safeguards at the address below.
7. How long we keep it
- Account data and content — until you delete the account.
- Help and support conversations — deleted once they are three years old.
- Deletion removes your profile, recipes, shopping lists, meal plans, preferences, health answers, notifications, follows, referral records, group memberships, push tokens and the record of your consent. It is immediate and irreversible: there is no recovery window, and our database plan keeps no backups to restore you from. If that changes, this page will say how long a deleted account can remain in one.
- What survives a deletion — reports you filed about other people's content are kept for moderation with your identity removed, so that deleting an account cannot erase a moderation record; there is no fixed limit on them yet, and they are used for nothing else. Emails you sent to support stay in our support mailbox until they are three years old. Server logs age out on the providers' own schedules — one day at our database host on our current plan.
- Guest accounts — a guest account (“Try without an account”) is deleted, with everything in it, when you sign out of it, or automatically once the app has not been opened on it for 90 days — 30 days if nothing was ever added to it. Creating an account from it keeps everything instead.
- On your device — some preferences are kept on the phone itself, and uninstalling the app or clearing its storage removes them.
8. Your rights
You may access, correct, export, restrict or delete your personal data, object to processing, and withdraw a consent you have given — including the consent for the health and dietary information above. Most of this is available directly in the app; for anything else write to the address below and we will answer within 30 days. Health information has its own page: Consumer Health Data.
If you are in the Philippines you may complain to the National Privacy Commission; in the EEA or the UK, to your local supervisory authority.
9. Children
ListThisMeal is not directed at children. You must be 16 or older to use ListThisMeal, wherever you live. We do not knowingly collect data from anyone younger. If we learn that someone under 16 has an account, we delete it and everything in it; if you believe we have such an account, contact us.
If you are 16 or 17
- You can use everything in the app. Before you first share something other people can see — your profile, a recipe, a collection — the app reminds you how to stay safe online.
- Keep your home address, phone number, school and other personal details out of your recipes, your bio and your photos.
- Ads in the app are never chosen from what you like or do, for anyone.
- You can ask a parent or someone you trust about anything on this page, and you can delete your account and everything in it at any time.
10. Security
Traffic is encrypted in transit (TLS) and the database is encrypted at rest. Access to your rows is enforced by row-level security inside the database itself, not only by the app. Passwords are stored as salted hashes. No system is perfect, and we will notify you and the relevant authority if a breach affects your personal data.
11. Changes to this policy
If we change how we use your data we will update the date at the top of this page and, for anything material, tell you in the app before the change takes effect.
12. Contact
Dcr8ives — support@dcr8ives.com
Data Protection Officer — the same address, with “Data Protection Officer” in the subject.
To report illegal content, with or without an account, see listthismeal.com/report.
Terms of Service · Consumer Health Data · Delete your account