Munchi
Privacy Policy
Last updated 25 August 2026
Munchi works by looking at photos of your fridge. This page explains exactly what that means for your data: what we collect, who processes it, how long we keep it, and how to delete all of it.
The short version. Your fridge photos are sent to Google Gemini to identify ingredients, then stored so your pantry works. We do not sell your data, we do not use it for advertising, and you can delete everything from inside the app at any time. Your dietary restrictions and allergies are treated as sensitive and are used only to filter recipes.
Who we are
Munchi is made by Ilium Studio (“we”). For privacy questions, contact [SUPPORT EMAIL — confirm before launch]. Our registered details are [LEGAL ENTITY AND ADDRESS — confirm before launch].
What we collect
Photos of your food
When you scan your fridge, the app captures a photo using your camera or one you select from your photo library. The image is uploaded to our backend and sent to Google Gemini, which identifies the food in it. We store the resulting ingredient list, and we store the image itself so your pantry cards can show it.
We only access the camera or photo library when you start a scan or pick an image. We do not scan your photo library in the background and we do not read photos you have not chosen.
Your pantry and cooking activity
Ingredients and their estimated freshness, recipes suggested to you, recipes you cooked, your shopping list, and the food-waste savings the app calculates from that activity.
Your preferences, including allergies
Diet, cuisines, cooking time, household size, goals, and any allergies or ingredients you tell us to avoid. Allergy and dietary information can reveal health or religious characteristics, so we treat it as sensitive personal data. It is used solely to filter and rank recipes. It is never used for advertising or profiling and is never sold.
Account information
The app can be used without an account, identified only by a random device identifier. If you create an account, our authentication provider processes your email address, or the identifier returned by Sign in with Apple or Google if you use those.
Purchase information
Subscription status, renewal dates, and transaction identifiers, received from our subscriptions provider and from Apple or Google. We never receive your full payment card details. Payment is handled entirely by Apple or Google.
Device and diagnostic data
A generated device identifier, app version, platform, and basic error and performance logs used to keep the app working.
Why we use it
- To identify food from your photos and build your pantry.
- To suggest recipes that fit what you have, your diet, and your allergies.
- To keep your data in sync and restore it if you reinstall.
- To manage your subscription and entitlements.
- To diagnose crashes and improve reliability.
Where the law requires a legal basis, we rely on performance of our contract with you for the core features, your explicit consent for sensitive allergy and dietary data, and our legitimate interest in keeping the service secure and working.
Who processes your data
We use the following processors. Each receives only what it needs to do its job.
- Google (Gemini) — receives your fridge photos to identify ingredients.
- Convex — our backend and database, stores your pantry, preferences, and images.
- Spoonacular — supplies recipe content. It receives ingredient and filter terms, not your identity.
- Clerk — handles sign-in if you create an account.
- RevenueCat — manages subscription status.
- Apple and Google — process payment and app distribution under their own privacy policies.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.
How long we keep it
Your pantry, preferences, and images are kept while your account or device record is active, so the app works when you come back. Cached recipe search results expire automatically after 30 days. Diagnostic logs are kept for a short operational period. [CONFIRM EXACT RETENTION PERIODS BEFORE LAUNCH]
Deleting your data
You can delete everything from inside the app, in Settings. Deletion removes your pantry, preferences, recipes, shopping list, cooking history, and the stored fridge photos themselves. It is immediate and it is not reversible.
If you cannot access the app, email [SUPPORT EMAIL] from the address on your account and we will delete it for you.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data, to withdraw consent, to object to or restrict processing, and not to be discriminated against for exercising these rights. Contact us to exercise any of them. If you are in the UK or EEA you may also complain to your local supervisory authority.
Children
Munchi is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
International transfers
Our processors may handle data outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
Security
Data is encrypted in transit. Access to production systems is limited. No system is perfectly secure, so we cannot guarantee absolute security.
Changes
If we make a material change we will update the date at the top of this page and, where the change is significant, notify you in the app.