1. Who we are and scope
Munchio is a general-wellness food diary operated by Engineers Space LLC (“Munchio,” “we,” “us”). This policy applies to the Munchio mobile app, munchio.app, and support communications.
Engineers Space LLC is responsible for the personal information described here. Munchio is not a healthcare provider, health plan, or medical-record service, and the app is not intended for clinical care.
Additional disclosures about nutrition and related wellness data appear in the Consumer Health Data Privacy Notice.
2. Information we process
- Account and identity information — email address, Supabase account identifiers, authentication method, session and security events, and limited identity-provider information returned by Apple or Google.
- Profile and settings — display name, 18+ confirmation, timezone, unit preferences, app settings, and an optional saved daily energy-reference value. Optional body inputs used to calculate that reference are processed for the calculation and are not saved by Munchio.
- Food and wellness information — food descriptions, meal labels, times, portions, calories, protein, carbohydrates, fat, notes, corrections, custom foods, diary history, summaries, meal suggestions, declared allergens, foods to avoid, and related version history.
- Capture information — a photo, voice recording, or typed description you deliberately submit for an AI-assisted estimate, plus the structured estimate, assumptions, confidence class, corrections, provider/model version, safe outcome codes, and bounded usage and latency metadata.
- Purchase and entitlement information — RevenueCat customer identifier, product, entitlement status, renewal/expiry state, and minimized store-event metadata. Apple or Google processes payment details; Munchio does not store full payment-card numbers.
- Support information — your email address and the messages or attachments you knowingly send to support. Please do not send passwords, one-time codes, tokens, food photos, recordings, or detailed health information to support.
- Technical and operational information — app version, platform, request IDs, timestamps, safe error codes, provider/model versions, latency, bounded cost/usage counts, and security or rate-limit events. Operational logs are designed not to contain raw media, transcripts, prompts, tokens, or unnecessary free text.
Website data
The initial munchio.app website uses no behavioral analytics, advertising pixels, session replay, or non-essential cookies. Cloudflare may process ordinary delivery and security information such as IP address, request headers, requested URL, and timing when it serves the site. The website does not sign users in or read diary data.
3. Capture and AI processing
When you choose Photo, Voice, or typed AI capture, the app sends the selected input through a Munchio server function to OpenAI to create an editable food and nutrition estimate. We do not include your email, display name, Supabase user ID, or unrelated diary history in the capture request.
Munchio does not save raw food photos or voice recordings. They are held in a short-lived device cache and transient server memory only while the requested capture is processed, with cleanup on success, failure, cancellation, timeout, and restart where technically possible.
A voice transcript is not stored as a separate permanent record after finalization. The original typed description is not required after finalization unless you explicitly save it as a note. A validated but unfinished structured capture result may be kept for up to 24 hours so you can recover the review step after a network interruption.
Munchio requests OpenAI processing with application storage disabled where supported. OpenAI states that API data is not used to train its models unless the API customer opts in, but under default API controls customer content may appear in abuse-monitoring logs retained for up to 30 days unless different approved controls apply. See OpenAI API data controls.
4. How we use information
We use information to:
- authenticate you and keep your account secure;
- provide the diary, editable estimates, summaries, meal suggestions, export, deletion, and purchase restoration you request;
- preserve saved nutrition snapshots so historical entries do not silently change when a model or catalog changes;
- enforce account ownership, capture quotas, paid access, dietary exclusions, rate limits, and abuse prevention;
- troubleshoot failures, measure reliability and provider cost without retaining raw media or unnecessary user content; and
- comply with law and enforce the Terms of Service.
Depending on your location, these activities rely on performing our agreement with you or providing a service you requested, your consent, legitimate interests in operating and securing Munchio, and legal obligations. We do not sell personal information or use it for cross-context behavioral advertising.
5. Providers and disclosures
We use the following providers for specific, limited purposes:
- Supabase — authentication, Postgres database, Row Level Security, Edge Functions, and scheduled maintenance. Supabase processes the account, diary, preference, entitlement, capture-result, and operational records described above. See Supabase Privacy.
- OpenAI — transient photo, voice, and typed capture processing, plus bounded inputs for requested summaries and familiar meal suggestions. See OpenAI Privacy Policy.
- RevenueCat — purchase status, entitlement reconciliation, and provider-side customer deletion. It does not need your food diary to perform those tasks. See RevenueCat Privacy.
- Apple and Google — identity services where selected, app distribution, purchases, refunds, and store subscription management under their own privacy policies.
- Resend — delivery of transactional authentication email through Supabase. See Resend Privacy.
- Cloudflare — delivery and security for the static munchio.app website. See Cloudflare Privacy Policy.
We may disclose information when reasonably necessary to comply with law, protect users or the service, investigate fraud or security incidents, or complete a merger, acquisition, financing, or sale of assets subject to appropriate privacy obligations.
6. Retention
- Account, profile, preferences, diary, saved estimates, summaries, and plans are generally retained while your account is active so you can use and export your history.
- Raw food photos and voice recordings are not persisted in Munchio storage. Provider retention is described in section 3.
- Unfinished structured capture results expire after 24 hours.
- A content-free, pseudonymous deletion receipt is removed within 30 days after terminal completion or failure.
- Minimized operational, security, billing, tax, fraud-prevention, and dispute records may be retained as long as reasonably necessary for those purposes or as required by law. Apple, Google, RevenueCat, and payment processors may retain their own transaction records under their policies and legal obligations.
7. Your choices and rights
You can correct diary items and preferences in the app. Under Settings → Privacy & data, you can request an account export and permanently delete your account. If you cannot use the app, follow the Account Deletion page.
Depending on where you live, you may also have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive a portable copy, or appeal a denied request. Contact support@munchio.app. We may need to verify that you control the account before acting on a request. We will not ask for your password, one-time code, access token, food diary, photo, or recording to verify a privacy request.
You may complain to the privacy or data-protection authority where you live. We will not discriminate against you for exercising a privacy right.
8. Security and international processing
Munchio uses access controls, encrypted transport, secret separation, Row Level Security, bounded requests, minimized logs, and ownership-scoped operations. No security measure can guarantee absolute protection.
Engineers Space LLC and its providers may process information in the United States and other countries. Where required, transfers use applicable contractual or legal safeguards. Contact us if you want more information about a transfer relevant to your account.
If a legally reportable breach occurs, we will provide notice to affected users and regulators as required by applicable law.
9. Age and sensitive content
Munchio is intended only for adults aged 18 or older. We do not knowingly offer the service to children. If you believe a person under 18 created an account, contact support so we can investigate and take appropriate action.
Munchio is designed for ordinary food and general-wellness logging. Do not use capture or support channels to submit medical records, government identifiers, payment-card numbers, account credentials, or another person’s sensitive information.
10. Changes and contact
We may update this policy when the product, providers, or law changes. The date above will change, and we will provide additional notice or request consent when required.
Privacy questions and requests: support@munchio.app
Engineers Space LLC
75 E 3rd St
Sheridan, WY 82801
United States