Politique de confidentialité pour Mealio
Mealio par Mealio LLC
Politique de confidentialité pour Mealio
Privacy Policy
Effective date: February 22, 2026
Mealio ("we," "us," or "our") operates the Mealio browser extension and the website located at mealio.co (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
If you have questions about this policy, contact us at contact@mealio.co.
- Information We Collect
1.1 Information You Provide Directly
Account information: When you register, we collect your email address and a hashed password.
Creator application: If you apply to the Creator Partner Program, we collect your display name, phone number (optional), and social media or website links you choose to provide.
Meal and recipe data: Meal names, ingredients, recipes, photos, and associated store information that you save or publish through the Service.
Support communications: Any information you provide when contacting us at contact@mealio.co.
1.2 Information Collected Automatically
Authentication data: Session tokens, refresh tokens, and device identifiers used to keep you logged in securely.
Log data: IP addresses, user agent strings, and timestamps associated with authentication events (login, logout, token refresh). These are used for security monitoring and abuse prevention.
Usage data: Information about how you interact with the Service, including which meals you save and which grocery stores you use. This data is used to calculate creator revenue share and improve the Service.
1.3 Information from Third Parties
Payment processors: If you subscribe to a paid plan, payment is processed by our third-party payment provider (Lemon Squeezy). We receive a customer identifier and subscription status but do not store your full payment card details.
Grocery platforms: The extension interacts with grocery store websites on your behalf to add items to your cart. We do not store your grocery account credentials. Any data exchanged with grocery platforms is used solely to complete the cart action you initiate. - How We Use Your Information
We use the information we collect to:
Provide, operate, and maintain the Service;
Authenticate your identity and maintain the security of your account;
Process subscription payments and manage your subscription status;
Calculate and distribute Creator Partner revenue share;
Send you transactional emails, including login verification codes and account notifications;
Respond to your support requests;
Detect, investigate, and prevent fraudulent or unauthorized activity;
Improve and develop new features for the Service;
Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your information for targeted advertising.
- How We Share Your Information
We may share your information in the following limited circumstances:
Service providers: We share information with third-party vendors who help us operate the Service, including our database host (Supabase), payment processor (Lemon Squeezy), email delivery provider (Resend), and payout provider (Tremendous). These providers are contractually obligated to protect your information and may only use it to provide services to us.
Legal requirements: We may disclose your information if required to do so by law, court order, or valid governmental request, or to protect the rights, property, or safety of Mealio, our users, or the public.
Business transfers: If Mealio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information becomes subject to a different privacy policy.
With your consent: We may share your information for any other purpose with your explicit consent.
4. Data Retention
We retain your account information for as long as your account is active or as needed to provide the Service. Authentication log data (IP addresses, user agents) is retained for up to 90 days for security purposes. Meal and recipe data is retained until you delete it or close your account. If you close your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or financial compliance purposes.
- Data Security
We implement industry-standard technical and organizational security measures to protect your information, including:
Passwords are hashed and never stored in plain text;
Authentication tokens are signed with a secret key and expire automatically;
Refresh tokens are stored as SHA-256 hashes in the database;
Session cookies are HTTP-only and not accessible by JavaScript;
All data in transit is encrypted using TLS/HTTPS;
Database access is controlled via row-level security policies.
No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
- Browser Extension Permissions
The Mealio browser extension requests certain permissions to function. Here is what each permission is used for:
Storage: To save your authentication tokens and meal data locally in Chrome's secure storage on your device.
Active Tab: To detect which grocery store website you are currently viewing so the extension can display relevant meals and initiate cart filling.
Tabs: To open the Mealio login page when you choose to sign in, and to communicate between the extension's side panel and the active grocery store tab.
Scripting / Content scripts: To interact with supported grocery store web pages for the sole purpose of automating cart additions on your behalf. Content scripts read product names and button elements on the page to locate items — this data is used only locally to complete the action you initiate and is never transmitted to our servers.
Side Panel: To display the Mealio meal manager in Chrome's built-in side panel alongside the grocery store website.
The extension does not monitor your general browsing history, track websites unrelated to the Service, read or store the contents of grocery pages beyond what is necessary to fill your cart, or transmit your grocery account credentials to our servers.
- Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
Access: Request a copy of the personal information we hold about you.
Correction: Request correction of inaccurate or incomplete information.
Deletion: Request deletion of your personal information, subject to our legal retention obligations.
Portability: Request your data in a machine-readable format.
Objection: Object to processing of your information in certain circumstances.
To exercise any of these rights, contact us at contact@mealio.co. We will respond within 30 days.
- Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at contact@mealio.co. - International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer. We take steps to ensure that any such transfers comply with applicable data protection requirements. - Cookies and Local Storage
We use HTTP-only cookies to maintain your authenticated session on the website. These cookies are strictly necessary for the Service to function and cannot be disabled without logging out. We do not use advertising cookies or third-party tracking cookies. The browser extension uses Chrome's chrome.storage.local API to store your authentication tokens locally on your device. - Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new effective date and, where appropriate, by sending an email to the address associated with your account. We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the revised policy. - Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy, please contact us at:
Mealio
contact@mealio.co