SelfMosaicFridge, pantry, or counter photo in; practical meal ideas out.

Privacy

Privacy for SelfMosaic.

What SelfMosaic stores for kitchen photos, ingredient lists, saved meals, and repeated support issues.

SelfMosaic tells you what it stores before it asks you to trust it.

SelfMosaic privacy

What this notice covers

This notice covers SelfMosaic's kitchen-photo meal flow.

Privacy

Current scope

This notice covers SelfMosaic's kitchen-photo meal flow: selected kitchen photos, optional cooking context, ingredient lists, saved meals, the optional missing-items view, support requests, billing status, diagnostics, analytics settings, export, and deletion data.

SelfMosaicbilling statusprivacy controls

Privacy

What we collect and why

SelfMosaic processes the selected kitchen photos and optional text context you choose for each meal request. It stores ingredient lists used with saved meals, including whether each list was only photo-read or explicitly reviewed, plus support details, the current AI processing permission, diagnostics, and session or account identifiers needed to keep saved meals usable, investigate repeated issues, export or delete account data, and keep the service reliable. Saved meals keep the meal idea. When you save a meal from a photo you selected, SelfMosaic makes a bounded, metadata-stripped thumbnail in the app's on-device cache. That thumbnail is never uploaded to SelfMosaic, is not included in device backups, and may disappear if the operating system clears the cache. Deleting the saved meal (or the app) removes any remaining cached thumbnail.

kitchen photosphoto-read or reviewed ingredientssaved mealssupport

Privacy

Device identifier and timezone

SelfMosaic creates a stable, random pseudonymous device identifier and keeps it in local app storage. The app sends that identifier when it creates or recovers a preview or account viewer, when you submit a waitlist or support request, when you report an AI result, during purchase or restore safety checks, and—only after optional analytics consent—when it records an App Store or Product Hunt link opening. SelfMosaic stores the waitlist copy for abuse control; for a link-opening receipt, the server immediately replaces the received identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic uses the identifier for app continuity, request and billing integrity, abuse prevention, security, support, and consented product analytics—not advertising or cross-app tracking. The app also sends and stores the device timezone so dated meals and account activity use the expected local day.

pseudonymous device IDtimezoneapp and security

Privacy

Optional sign-in details

Sign-in is optional. If you choose Apple, Google, or an email sign-in method, Clerk and the identity provider may send SelfMosaic an account or user identifier, email address, and name when the provider supplies them. SelfMosaic uses the identifier for authentication and account continuity, and uses a supplied name or email for account display, a one-time transactional account welcome email after the first verified account setup, requested contact, support, export, and deletion. The welcome email is a service message, not a marketing subscription. Billing entitlement is connected through viewer, account, and store identifiers—not your name or email. None of these details is used for advertising or cross-app tracking.

optional sign-inname and emailaccount continuity

Privacy

Waitlist and launch measurement

If you choose to join the launch waitlist, SelfMosaic sends and stores the email address you enter, the app-scoped pseudonymous device identifier, the page or placement where you joined, a sanitized referrer path, and available UTM campaign values. SelfMosaic uses the email to send the launch update you requested, the device identifier to limit waitlist abuse, and the source details to understand which SelfMosaic launch surfaces work. Separately, after optional analytics consent, opening an App Store or Product Hunt link sends the device identifier and source details to create a launch-link receipt; the server immediately replaces that identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic does not share this information with advertising networks or use it for cross-app tracking.

optional waitlistlaunch updateconsented measurement

Privacy

AI provider safety identifier

For each live ingredient-scan or meal-plan request, SelfMosaic's backend derives a stable SHA-256 pseudonym from the internal viewer ID and sends that pseudonym to Azure OpenAI as a safety identifier for abuse detection. It contains no email, username, device ID, or raw SelfMosaic viewer ID and is not used for advertising or cross-app tracking.

pseudonymous viewer IDAzure OpenAIabuse detection

Privacy

Optional billing analytics

If you enable optional analytics, SelfMosaic's sanitized product events can include the current plan tier, a subscription package or product identifier, purchase or restore step and outcome, active-entitlement count, server-sync state, and a bounded failure category. PostHog receives those consented events, and Sentry can include the same consented event as a breadcrumb if a later diagnostic report is sent. These events contain no full payment-card data, store receipt, transaction token, or order reference and are used to understand subscription-flow reliability, not for advertising or cross-app tracking.

analytics consentplan and packageno card data

Privacy

Outside services

SelfMosaic is operated by SelfMosaic and uses outside services for hosting, storage, AI food reasoning, crash diagnostics, support requests, account-service and requested launch-email delivery, optional product analytics, and subscription billing. Resend handles the one-time transactional account welcome, requested waitlist and launch updates, and support email delivery. SelfMosaic removes bounded send and delivery-event records once they are older than 90 days through the next hourly sweep, normally within 90 days plus one hour, and removes linkable records earlier through the account-deletion workflow where implemented; a record written by an email action already in flight remains subject to that same bounded sweep. Apple processes iOS subscription payments and Google Play processes Android subscription payments. When signed-in website checkout is available, Paddle acts as merchant of record. RevenueCat carries the account-bound entitlement between those providers and SelfMosaic. SelfMosaic receives only the identifiers and billing state needed to grant and support access, such as a pseudonymous App User ID, product, store, environment, entitlement, expiration, cancellation, or refund status. SelfMosaic does not receive or store full payment-card data. Before AI processing runs for the first time, the app asks permission before selected kitchen photos, optional notes, reviewed ingredient lists, or selected meal text for an optional serving reference are sent for processing. SelfMosaic does not use your kitchen photos, prompts, or saved meals to train SelfMosaic models.

hosting and storageAI processingcrash diagnosticsbilling providersoptional analytics

Privacy

Where your information is processed

SelfMosaic is operated from India, and our service providers process data in the United States (Convex, Clerk, RevenueCat, PostHog, Sentry, Resend, and Microsoft Azure OpenAI, as listed above). Where data about people in the European Economic Area or the United Kingdom is transferred to these providers, the transfers are protected by European Commission–approved Standard Contractual Clauses and, where providers are certified, the EU–U.S. Data Privacy Framework. Kitchen photos are processed for meal generation and are not retained on SelfMosaic's servers; a limited retry record is kept for up to 24 hours. A saved meal can keep a bounded thumbnail in the app's on-device cache; the thumbnail is not backed up and may be cleared by the operating system.

operated from IndiaUS processingStandard Contractual ClausesEU–U.S. Data Privacy Framework

Privacy

Saved meals and missing items

Saved meals stay on this device when SelfMosaic says it saved locally. When session or account saving is available, saved meals can instead attach to that supported session or signed-in account. The optional missing-items view is derived only from saved meals and their missing-items lists.

session or accountsaved mealslocal mode onlyoptional missing-items view

Privacy

Ending a preview is not deletion

Ending a preview removes that session from the current device. It does not delete the preview's server data, and the next preview starts with a new server record. Use Clear my data before ending the preview if you want deletion. Afterward, contact the privacy inbox; help depends on whether SelfMosaic can safely identify the old preview and remains subject to retention, backup, and legal limits.

new previewclear before endingnot automatic deletion

Privacy

Retention, deletion, and export

To prevent a retry from running or counting the same AI action twice, SelfMosaic temporarily stores a random request ID, a SHA-256 input digest, and the parsed ingredient read, meal-plan result, or recipe-visual result content for a 24-hour retry window. If optional recipe-visual generation is enabled, its generated image file and storage metadata use that same window and appear in your export while retained. That retry record never contains the original selected photo bytes. It becomes inaccessible after 24 hours and is cleared, including the generated image file, by the next hourly sweep, normally within 25 hours. Saved meals stay on this device when SelfMosaic says it saved locally. When session or account saving is available, saved meals can instead attach to that supported session or signed-in account. Account deletion signs you out immediately and queued cleanup is designed to finish within about 30 days, depending on background work, backups, support records, and legal duties. After account or preview deletion, viewer-owned server product data follows the deletion workflow and stated retention exceptions. The stable pseudonymous device identifier, device-level appearance and onboarding settings, and the optional analytics choice remain in local app storage. They contain no meal, prompt, or kitchen-photo content. If you use SelfMosaic again, the app may send the same device identifier during a new bootstrap, waitlist or support request, AI-result report, purchase or restore safety check, or consented link-opening receipt; it does not restore the deleted account data. Data exports normally stay downloadable for up to 7 days. If a requested snapshot includes still-retained AI retry content, the whole export expires no later than the earliest included retry record; the app shows the exact deadline. Every download rechecks sign-in, account ownership, and that deadline before returning bytes. SelfMosaic does not expose a reusable storage URL, so the download service refuses the file at the deadline even if physical cleanup needs a retry.

about 30-day deletion windowup to 7-day export windowsession or account24-hour AI retry window

Privacy

Analytics and contact

SelfMosaic is not designed around ad tracking or cross-app tracking. Crash diagnostics stay on so the app can catch breakage without raw kitchen photos in error reports. Website analytics are off unless consent controls are available and enabled. When you enable analytics, launch-link receipts use a daily-scoped pseudonymous identifier and are deleted after 90 days. Optional in-app product analytics stay off until you turn them on from Privacy in the app. Use the privacy inbox for access, correction, export, deletion, or data-handling questions.

no ad trackerscrash diagnosticsprivacy inbox

Requests and controls

If saved meal data looks wrong, include your session context.

The useful detail is whether SelfMosaic said the meal was saved on this device, saved to a session, or saved to a signed-in account. Start account deletion from More inside the app when you can. Use the public deletion page or privacy inbox if sign-in is blocked, or if you need export, correction, or data-handling help.