Privacy Policy — Kaji Meals
What the Kaji Meals app collects, why, how long we keep it, and what you can ask us to do about it.
Visiting kaji.studio itself? Read the website privacy policy →
Who we are
Kaji Studio makes the Kaji Meals app. For everything described here we are the data controller, meaning we decide what is collected and why. Our full identification and contact address are at the bottom of this page.
This policy covers the app. Reading it on kaji.studio is a visit to our website, which collects its own small handful of things and has its own policy, linked above.
If you want to exercise any of the rights described below, or you simply want to know what we hold about you, use the privacy contact address at the bottom of this page. It goes to a separate inbox from general support so that a request cannot get lost behind a pile of feature suggestions. We answer within one month, which is the deadline the GDPR sets us.
The short version
We would rather not hold your data. The app works offline on your device, and your content reaches our servers only if you choose a cloud workspace. We sell a subscription, not your information.
- We do not sell or rent personal data, and we never have.
- We do not use advertising networks, and there are no advertising or tracking cookies anywhere.
- The app contains no analytics and no crash reporting. We do not know which screens you open or how long you spend in them.
- Everything we store on our own servers is hosted in the European Union.
Your account and your workspace
Kaji Meals needs an account, but it does not need your content. When you set up your workspace you choose between keeping it on this device and syncing it to the cloud. Choose local, and your meals, plans and photos stay on your phone — they are never uploaded, and the only thing we hold is the account itself. Choose cloud, and we store the following so your content survives a lost phone and reaches your other devices.
Choosing a local workspace is not the same as us holding nothing, and we would rather say so plainly than let the word local imply more than it should. Your account itself always lives on our servers, because that is what lets you sign in on a new phone. So does a record of the workspace you own — its name and the fact that you own it — even when nothing inside it ever leaves your device.
| What | Local workspace | Cloud workspace |
|---|---|---|
| Account: email address, name, password hash, sign-in timestamps | On our servers | On our servers |
| Profile: avatar colour, eating type, nutrition display preferences, language | On our servers | On our servers |
| Licence tier (free or paid) | On our servers | On our servers |
| Workspace record: its name, that you own it, who its members are | On our servers | On our servers |
| Meals, recipes, ingredients, plans, shopping lists, categories | Your device only — never uploaded | On our servers |
| Nutrition targets | Your device only — never uploaded | On our servers |
| Meal photos | Your device only — never uploaded | On our servers |
A paid subscription does not change what we store. It unlocks cloud sync and sharing, so in practice a paid user is more likely to have chosen a cloud workspace — but the columns above are decided by that choice, not by what you pay.
With a cloud workspace, this is what we hold and why.
| What | Why | Basis |
|---|---|---|
| Email address, name and password | To create the account, sign you in and let you reset your password. Passwords are stored as a hash by our authentication provider; we never see the password itself. | Performing our contract with you |
| Your meals, recipes, ingredients, plans, shopping lists and categories | This is the content of the app. It is stored so it survives a lost phone and reaches your other devices. | Performing our contract with you |
| Nutrition targets and per-person settings | So the app can show you progress against the goals you set. | Performing our contract with you |
| Workspace membership and role | So the right people can see a shared workspace, and so we know who may change what. | Performing our contract with you |
| Language preference | So the app opens in the language you chose, on every device. | Performing our contract with you |
If you share a workspace, the people in it can see the content of that workspace. That is the point of sharing, but it is worth being explicit: a shared meal plan is visible to everyone in the workspace, along with the name on your account.
Meal photos
If you add a photo to a meal, it is uploaded to our storage in the European Union and stored under a path built from two random identifiers — one for your workspace, one for the meal. The link is long and unguessable, and it is not listed anywhere: someone would need the exact address to reach the image.
We should be precise about what that does and does not mean. The file is served without requiring a login, so anyone you deliberately give the link to can open it, and that is what will make sharing a meal possible later. It is not encrypted in a way that hides it from us, and we can access it to run the service. It is not indexed by search engines.
Deleting a meal, or deleting your account, removes the photos that belong to it. The database record goes immediately; the image file itself is reclaimed by a job that runs every night, because storage cannot be cleared in the same operation as the database. So a deleted photo can persist for up to a day before the file is gone. The same job removes any photo whose meal no longer exists, so an interrupted delete does not leave a file stranded.
When you contact support
There are two support forms in the app, and they collect different things because one of them is reachable without signing in. We use what they send to answer you, and for nothing else. The basis is performing our contract with you and our legitimate interest in providing support — not consent, because you asked us for help and we should not need permission to reply.
- Report a problem (signed in)
- The subject and message you type, the category you pick, and diagnostics: your app version, your platform and version, your device name, your user id, your workspace id, your licence status and your account email address. Your account email is used as the reply address; we ignore any address the app might otherwise send, so a reply can only ever go to the account itself.
- Trouble signing in (signed out)
- The email address, subject and message you type, plus your app version, your platform and version, and your device name. Because you are not signed in, we cannot confirm the address belongs to you, and we treat what you tell us as an unverified claim. We will ask you to prove ownership before changing anything on an account.
The signed-out form additionally stores two things whose only purpose is to stop the form being abused as a way of sending mail through us: an identifier the app generates once and keeps in your device's secure storage, used to allow one message per device per day; and a SHA-256 hash of your IP address, used to allow three per day from the same address. We do not store the IP address itself. Because the hash is unsalted we treat it as pseudonymous rather than anonymous — it identifies less than an IP address, but not nothing. Our basis for both is our legitimate interest in keeping the service usable. The limits only look back one day, but we keep both for seven days so that a burst of abuse can still be looked into. After that both are deleted, while the message itself follows the twelve-month rule below.
Support messages are deleted twelve months after they are sent: in our database automatically and without exception, and in our support inbox by hand on the same schedule. A mailbox runs no cleanup job of its own, and we would rather say that than imply an automation that is not there.
Subscriptions and payment
Kaji Meals sells subscriptions through the App Store and Google Play. We never see your card details, your billing address or your payment method — the store handles the payment and tells us only whether an entitlement is active.
We use RevenueCat to manage those entitlements. It receives an anonymous identifier for your install, the subscription events the store sends, and your platform. It tells us whether you are on the free or paid tier, which is what unlocks the paid features. Apple and Google process this outside the EU under their own privacy policies and the European Commission's standard contractual clauses.
Who else processes your data
We use a small number of providers to run the service. They act on our instructions under a data processing agreement, and none of them may use your data for their own purposes.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication and photo storage — the account and workspace content described above | Ireland (EU) |
| Resend | Delivering support mail and account emails | EU |
| RevenueCat | Subscription entitlements | United States, under standard contractual clauses |
| Apple, Google | App distribution and payment processing | United States, under standard contractual clauses |
Our website is hosted by Vercel. It plays no part in the app, and the website policy linked at the top of this page covers it.
How long we keep things
- Your account and its content
- Until you delete your account. Deletion is available in the app's settings and removes your account, your content and your photos, with photo files reclaimed by the nightly job described above.
- Support messages
- Twelve months from the day you send them. The database record goes automatically; the mail in our support inbox we delete by hand on the same schedule.
- Device identifier and IP hash
- Stored only by the signed-out support form. Seven days from the day you send the message, then deleted automatically; the message itself is kept for the twelve months above.
- Deleted content
- When you delete a meal or a plan it disappears immediately, but a marker is kept for thirty days so that a device which was offline learns about the deletion instead of resurrecting it. After thirty days the row is removed for good.
- Workspace invitations
- An invitation code works for fifteen minutes and then stops. The record that it was created is kept for a further seven days, so a failed invite can still be looked into, and is then deleted.
Your rights
Under the GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for your data in a portable form. You can also object to any processing we base on legitimate interest, and we will stop unless we have a compelling reason not to.
You do not need our help to delete your account — it is in the app's settings, and it removes your content and photos along with it. For anything else, write to the privacy contact address at the bottom of this page.
If you think we have handled your data badly, we would rather hear it from you first, but you have every right to complain to a supervisory authority instead. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD); if you live elsewhere in the EU, you may complain to your own country's authority.
Children
Kaji Meals is not aimed at children and we do not knowingly create accounts for anyone under 16. If you believe a child has an account with us, tell us and we will delete it.
Changes to this policy
When we change what we collect, we change this page in the same release, and the date at the top moves. If a change materially affects you — a new processor, a new purpose, a longer retention period — we will tell you in the app rather than relying on you to re-read this page.