This Privacy Policy explains how personal data is collected, used, shared, and protected when you use the FlavorDay mobile application and related services (the "App" and "Services").
If you do not agree with this Privacy Policy, please do not use the App.
1) Who We Are (Controller) and Contact
Controller: Maksim Panaskin (independent developer, sole proprietor) operating under the brand "FlavorDay" / "Excludium".
Contact:
- Name: Maksim Panaskin
- Email: support@excludium.com
Privacy requests:
- Email: support@excludium.com
- Subject line: Privacy Request
We do not currently designate a Data Protection Officer because the scale of processing does not meet GDPR Article 37 thresholds. The contact above is the single point of contact for all privacy matters.
2) Scope
This Privacy Policy applies to:
- the FlavorDay mobile app (iOS and Android) and related backend services hosted by us;
- customer support communications.
It does not apply to third-party services accessed through the App (for example Apple App Store, Google Play, ad networks). Those services are governed by their own privacy policies. Where we engage a third party as a data processor, we identify them in Section 6.
3) Personal Data We Collect
Depending on features used, we may collect the following categories.
A. Data you provide directly
- Account data: email address, given/family name, login provider identifier (Apple user identifier or Google subject identifier).
- Household / planning preferences: number of persons, calorie target, diet type, cooking time, budget level, kitchen styles, dietary restrictions and allergies you choose to enter.
- Pantry, ingredients, shopping list items, saved menus, generated meal plans and related planning content.
- AI inputs and feedback: prompts, ratings, replace/regenerate requests.
- Support communications: messages and details you send to support.
Important: The App is not intended to collect medical records. However, allergy and diet information may be treated as health-related ("special category") data in some jurisdictions (for example Article 9 GDPR). You are not required to enter any allergy or diet information; you may use the App with generic preferences only.
B. Data collected automatically
- Device/app data: device model, OS version, app version, app language, timezone.
- Identifiers: IP address (received whenever the App connects to our backend); resettable advertising identifiers (Android Advertising ID / Apple IDFA) only if rewarded ads are enabled and the platform-level permission is granted.
- Usage data: which screens were viewed, feature usage, session timing, error events.
- Diagnostic data: crashes, error logs, performance events.
- Approximate location derived from IP for fraud / security / regional formatting (for example local currency, regional ingredient names).
C. Payments and subscriptions
Purchases are processed by Apple App Store or Google Play. We do not receive full payment card data. From the platform we receive only the metadata needed for entitlement checks:
- subscription status and start/end dates;
- product identifier (for example
aimenu_premium_monthly); - transaction / purchase identifiers and the original purchase identifier (for renewal tracking).
We process Apple App Store Server Notifications and Google Play Real-Time Developer Notifications to keep entitlement status up to date.
D. Token wallet
To allocate AI generation capacity we maintain an in-app token wallet on our servers, including:
- current token balance;
- transaction history (allocation grants, generation costs, ad refills, refunds, admin adjustments);
- ad-grant records used to enforce daily caps and prevent fraud.
These records are linked to your account identifier and persist for the life of your account; they are deleted when you delete your account (see Section 12).
E. Sign-in provider tokens
When you sign in with Apple, we receive a single-use authorization code from Apple. We exchange this code with Apple for a refresh token, which we store in encrypted form (AES-256-GCM with a server-side key managed via systemd-creds) so that we can call Apple's /auth/revoke endpoint on your behalf when you delete your account, in compliance with App Store Review Guidelines §5.1.1(v). When you sign in with Google, we do not retain Google refresh tokens.
F. Advertising and rewarded ads
If you choose to watch rewarded video ads to earn additional tokens:
- the Google Mobile Ads SDK (AdMob) processes ad interactions, device identifiers and approximate IP-based location for ad delivery, measurement and fraud prevention;
- our backend receives a Server-Side Verification (SSV) callback from Google with a transaction identifier and a signed token, which we verify against Google's published verifier keys before crediting tokens.
G. Diagnostics on your device
The App keeps a small in-memory diagnostic log on the device (capped at ~500 entries) for troubleshooting. This log is not transmitted to our servers automatically. You can view it from Profile -> Logs and copy it to clipboard if you choose to attach it to a support email.
4) How We Use Personal Data
We process personal data to:
- provide and operate the Services and your account;
- generate menus, recipes and shopping lists from your inputs (this involves sending the relevant inputs to our AI sub-processor — see Section 6);
- enforce the token quota that limits AI generation costs;
- process subscriptions and rewarded-ad refills, and prevent abuse of either;
- provide account and customer support;
- maintain security, prevent fraud, and detect automated abuse;
- monitor reliability and improve product quality;
- comply with legal obligations and enforce our Terms.
We do not perform any solely automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. AI-generated menus and shopping lists are informational suggestions and do not by themselves grant or deny access to any service, benefit or right.
We do not use your personal data for behavioural advertising profiling. Rewarded ads (if you opt to watch them) are served by Google's ad network under Google's own targeting logic and are not driven by data we share with Google.
5) Legal Bases (EEA / UK and Similar Regimes)
Where required by law, we rely on:
- Contract necessity (Article 6(1)(b) GDPR): providing the Services you signed up for, including authentication, menu generation, subscription management, and account deletion.
- Consent (Article 6(1)(a) GDPR; Article 9(2)(a) for any health-related categories): rewarded-ad participation, optional collection of allergy / diet data, and any future marketing communications.
- Legitimate interests (Article 6(1)(f) GDPR): service security, abuse and fraud prevention, reliability monitoring, and high-level product analytics. We have weighed these interests against your rights and have implemented safeguards described in Section 10.
- Legal obligation (Article 6(1)(c) GDPR): compliance with applicable laws and lawful requests from authorities.
For users in the United States, we rely on the relevant state-law equivalents (for example a "business purpose" under the CCPA / CPRA).
6) How We Share Personal Data
We do not sell your personal data for monetary consideration. We share data only with the following categories of recipients, all acting as our processors or sub-processors except where noted:
| Recipient | Role | Categories of data shared | Country |
|---|---|---|---|
| Microsoft Azure | Backend hosting (virtual machine, network) | Everything in Section 3 (transit + at rest) | EU (West Europe region) |
| OpenAI, L.L.C. | AI text generation (gpt-5.4-nano / gpt-5-mini) | Menu prompts including diet, restrictions, persons count, region, language | United States |
| Apple Inc. | Sign-in with Apple identity verification, App Store Server API for receipt validation, /auth/revoke on account deletion |
Apple identity token, authorization code, transaction identifiers | United States |
| Google LLC | Sign-in with Google identity verification, Google Play Billing receipt validation | Google identity token, purchase tokens | United States |
| Google LLC (AdMob) | Rewarded video advertising and Server-Side Verification (only if you watch ads) | Advertising identifier, IP, ad interaction events | United States |
| ipapi.co | IP-to-country lookup on first sign-in (cached server-side) | Your IP address (transient) | European Union |
OpenAI has confirmed that data submitted via its API is not used to train OpenAI models by default; we have not opted into any training programmes.
We may also disclose data to: (i) competent authorities where required by law, valid legal process, or to protect rights, property or safety; and (ii) counterparties in a merger, acquisition or asset transfer scenario, with lawful safeguards.
For users in California: as of the date above, we do not "sell" personal information for monetary consideration. The Google Mobile Ads SDK may receive identifiers that California law could classify as a "sharing" of personal information for cross-context behavioural advertising. You can disable rewarded ads simply by not watching them; we do not show rewarded ads automatically. You may also exercise opt-out and other CCPA / CPRA rights via the Privacy Request channel in Section 11.
7) Advertising, Tracking and Your Choices
The App does not run interstitial or banner ads. It offers an optional rewarded video ad that grants extra tokens; you trigger it explicitly. If you do trigger it:
- the Google Mobile Ads SDK is engaged for the duration of the ad;
- on iOS, the SDK respects your App Tracking Transparency choice;
- on Android, the SDK respects your Ad Personalization choice.
You can also:
- reset or limit your advertising identifier in your device settings;
- disable rewarded ads simply by not watching them (your subscription tier is not affected).
8) International Transfers
Our backend is hosted on Microsoft Azure in the European Union (West Europe region). Some processing necessarily takes place outside your country of residence:
- AI generation is performed by OpenAI in the United States;
- Apple and Google identity / billing services are operated in the United States;
- the Google Mobile Ads SDK (when triggered by you) involves transfers to the United States.
Where these transfers leave the EEA / UK, we rely on the European Commission Standard Contractual Clauses (SCCs) and on the EU-U.S. Data Privacy Framework where the recipient is certified, plus supplementary measures such as encryption in transit. You may request a copy of the safeguards applicable to a specific transfer by emailing us at the address in Section 1.
For users in the Russian Federation: we process personal data outside the Russian Federation. By creating an account you provide explicit consent under Federal Law No. 152-FZ to the cross-border processing of your personal data by us and the sub-processors listed in Section 6 for the purposes described in Section 4.
9) Data Retention
We retain personal data only as long as needed for the purposes above:
| Data category | Retention |
|---|---|
| Account, profile, household preferences | Until you delete your account |
| Generated menus, saved menus, shopping lists | Until you delete the item, or until account deletion |
| Token wallet balance and ledger | Until account deletion |
| Refresh tokens (server, hashed) | Until rotation or 30 days, whichever comes first |
| Encrypted Apple sign-in refresh token | Until account deletion or sign-out |
| Server access and application logs | Up to 30 days, then rotated |
| Crash and diagnostic events | Up to 90 days |
| Subscription / billing records | Up to 7 years if needed for tax or accounting |
| In-device diagnostic log | Last ~500 entries on your device only; cleared by reinstall |
| Anti-abuse identity marker (sign-in provider + its opaque subject id) | Kept after account deletion solely to stop the one-time free welcome bonus from being re-claimed by deleting and re-creating an account. Contains no name, email, or usage data. |
Backup copies may persist for a limited period (typically up to 30 days) before being overwritten.
10) Security
We apply administrative, technical and organisational safeguards including:
- TLS for all client-to-server traffic;
- ASP.NET Core Data Protection keys for cookie / token signing, persisted to a permission-restricted directory;
- AES-256-GCM encryption of any sign-in provider refresh tokens stored at rest;
- secrets (database passwords, API keys, Apple
.p8private keys, AES keys) loaded from systemd encrypted credentials, never written to source control or the deploy artifact; - least-privilege OS user for the application process;
- request rate limiting and abuse heuristics on sensitive endpoints (auth, billing, AI generation, ad SSV).
No system can guarantee absolute security. If we become aware of a personal-data breach affecting your data, we will notify you and the competent authority where required by applicable law.
11) Your Rights
Depending on your jurisdiction, you may have rights to:
- access your personal data;
- correction of inaccurate data;
- deletion ("right to be forgotten");
- portability in a structured, commonly used, machine-readable format;
- restriction of, or objection to, certain processing;
- withdrawal of consent (where processing is consent-based) without affecting the lawfulness of prior processing;
- not be subject to solely automated decision-making with legal or similarly significant effects (we do not perform such decision-making — see Section 4);
- lodge a complaint with your supervisory authority (for EU users, your national Data Protection Authority; for UK users, the Information Commissioner's Office).
To submit a request, email support@excludium.com with subject "Privacy Request". We will respond without undue delay and in any event within one month, extendable by a further two months for complex requests as permitted by Article 12(3) GDPR. Identity verification may be required before completing certain requests.
For users in California: you may exercise your CCPA / CPRA rights (right to know, right to delete, right to correct, right to limit use of sensitive personal information, right to opt out of sale or sharing) via the same channel. We do not knowingly sell or share personal information of consumers under 16.
12) Account Deletion
You can request account deletion in three ways:
- In-app:
Profile -> Delete Account - Outside the app (public URL): https://flavorday.excludium.com/api/legal/account-deletion
- By email: support@excludium.com (subject:
Account Deletion Request)
Upon a valid deletion request, we delete or anonymize:
- your account record, profile and household preferences;
- generated menus, saved menus and shopping lists;
- token wallet balance and ledger entries;
- refresh tokens and reviewer access grants;
- ad reward grants and SSV records;
- subscription records (subject to the legal-retention exception below).
When you delete your account through the in-app flow, in addition to wiping your stored data we invoke Apple's REST /auth/revoke endpoint to revoke your Sign-in-with-Apple refresh token (as required by App Store Review Guidelines §5.1.1(v)). For Sign-in-with-Google we drop the federated link locally; Google's own revocation is available in your Google Account settings.
We retain a minimal anti-abuse identity marker — your sign-in provider plus its opaque subject identifier, containing no name, email, or usage data — strictly to stop the one-time free welcome bonus from being re-claimed by deleting and re-creating an account. We may additionally retain a minimal subset of records strictly for: (i) defence of legal claims; (ii) fraud and abuse prevention; (iii) tax or accounting obligations (typically subscription receipts retained up to 7 years). Backups containing your data will be overwritten in the normal backup rotation, typically within 30 days.
13) Diagnostics on Your Device
To help you self-diagnose issues without contacting support, the App keeps a short in-memory diagnostic log on your device, accessible from Profile -> Logs. This log:
- contains app and HTTP-level events (no full URL query strings, no JWT contents — only types and lengths);
- is limited to the most recent ~500 entries;
- is cleared when you reinstall or sign out;
- is not transmitted to our servers; you copy it to clipboard yourself if you choose to share it with support.
14) Push Notifications
If you grant notification permission, the App may schedule local notifications on your device (for example, "your weekly menu is ready"). These notifications are generated and delivered locally; we do not use Apple Push Notification service or Firebase Cloud Messaging for marketing. You can revoke notification permission at any time in your device settings.
15) Children's Privacy
The App is rated and marketed for users aged 17 and older and is not directed to children under 13 (or the equivalent minimum age in your country). By creating an account you confirm that you meet our Terms' minimum-age requirement (Section 2 of the Terms). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@excludium.com and we will review and delete the data.
16) Changes to This Privacy Policy
This Privacy Policy may be updated. The "Last updated" date indicates the latest revision. Material changes will be highlighted in-app and, where required by law, additional notice will be provided. Your continued use of the App after a material change is your acknowledgement of the updated Privacy Policy.
17) Contact
For privacy questions or requests:
- Maksim Panaskin
- support@excludium.com
- Subject:
Privacy Request
Legal notice: this document is a practical product-level privacy notice maintained by an independent developer. It is not a substitute for tailored legal advice. For final commercial launch in regulated markets, an independent review by a licensed attorney is recommended.