Privacy Policy
Last updated August 28, 2026
Who we are
Suppr is a household meal-planning app. This policy explains what we collect, why, and what choices you have. If you have questions, email [email protected].
What we collect
- Account data: your name, email, and a hashed password. We never store your password in plain text.
- Profile data: any avatar image you upload, your chosen theme, and your taste profile (dietary preferences, allergens, disliked foods, favorite cuisines).
- Household data: the household name you create or join, its invite code, and your membership.
- Pantry and recipe data: ingredients you add to your pantry and recipes you create. Dinner-vote sessions are tied to your account so the household can see who voted for what.
- Technical data: standard request logs (IP address, user agent, timestamps) for security and debugging. We do not run first-party product analytics.
- Advertising identifiers: in the iOS app, our ad provider (Google AdMob) may access a device advertising identifier (IDFA), approximate location derived from an IP address, ad-view and interaction data, and limited performance or crash diagnostics to show, measure, and improve ads. Use of the IDFA for cross-app tracking only happens if you allow it through the system tracking prompt (see "Advertising and tracking" below).
- Subscription data: if you use Suppr Pro, Apple and RevenueCat process purchase history, subscription status, product, renewal, and entitlement information. Suppr links that entitlement to a random, app-specific billing identifier so Pro works across your signed-in devices. That identifier is not your sequential database ID. We do not receive or store your card or bank details.
How we use it
Your account, household, pantry, recipe, and vote data is used solely to operate the app: signing you in, syncing your household, suggesting and filtering recipes by your taste profile, running votes, and protecting against abuse. We do not sell your personal data. We do not build our own advertising profiles; ad personalization, if any, is performed by Google AdMob under its own policies.
Suppr does not automatically cache Spoonacular search, suggestion, or detail responses for reuse. If you explicitly save, add, plan, or log a Spoonacular recipe, Suppr stores only the recipe ID, title, and image URL needed for that feature; it does not store the full provider response. To reduce repeat calls to TheMealDB, Suppr uses bounded, in-memory API caches. TheMealDB pantry-match results are used for up to 30 minutes; generic inspiration and recipe-detail content may be used for up to 24 hours. These caches do not contain your email or Suppr account ID, are not written to Suppr's database, and disappear when the API process restarts or entries are evicted.
Advertising and tracking
The free version of the iOS app shows banner ads served by Google AdMob. On iOS 14.5+ we present Apple's App Tracking Transparency prompt before any tracking. If you decline, AdMob serves non-personalized ads and does not use your advertising identifier to track you across apps; you can still use Suppr normally. You can change this anytime in iOS Settings → Privacy & Security → Tracking. AdMob's handling of ad data is governed by Google's privacy policy.
Third parties
- Spoonacular provides pantry-matched recipe suggestions and recipe search. We send ingredient names from your pantry, recipe search terms, and the effective diet and allergen/intolerance filters selected by you or your household. We do not send your email address or Suppr account ID to Spoonacular.
- TheMealDB provides pantry suggestions, recipe search, cuisine browsing, and recipe details. Depending on the feature you use, we send pantry ingredient names, recipe search terms, a selected cuisine/area, or a MealDB recipe ID. Suppr applies dietary, allergen, and disliked-food filtering to MealDB results on our server; those preferences are not sent to TheMealDB. We do not send your email address or Suppr account ID to TheMealDB.
- Recipe image providers include Spoonacular, TheMealDB, and Unsplash fallback images. When the app displays one of these images, that provider may receive ordinary request metadata such as your IP address and user agent. Suppr does not allow household members to embed images from arbitrary external hosts.
- Open Food Facts resolves a scanned grocery barcode to a product name. We send only the barcode number, not personal data.
- Google AdMob serves ads in the iOS app (see above).
- RevenueCat validates App Store purchases, maintains Suppr Pro entitlement status, prevents purchase fraud, and provides subscription reporting. It receives a random, app-specific billing identifier and Apple purchase information, but not your Suppr email, sequential database ID, or payment-card details.
- Google AdSense may serve display ads on the website version, using cookies for frequency capping and measurement.
- Instacart (via Impact Radius) builds a shoppable cart when you tap "Shop with Instacart." We send the names of the ingredients you chose to shop and the recipe title to Instacart to find matching products. No personal identifiers are sent. Suppr may earn a commission on resulting purchases; your price is unaffected.
- Walmart (via Impact Radius) tracks affiliate clicks when you tap a "Shop at Walmart" link. The link carries a tracking token but no personal identifiers from us. Suppr may earn a commission on resulting purchases; your price is unaffected.
- Sign in with Apple is offered as a sign-in option. If you use it, Apple gives us a verified identifier and only the name and email you approve (which may be a private relay address). We use it solely to create or access your account.
- Resend delivers transactional email (such as password resets). It receives your email address only to send that message.
Data retention and your rights
You can edit or delete your account at any time from the Profile screen. Account deletion permanently removes your user record, taste profile, avatar, and personal access to household data. Shared household records needed by remaining members may remain without being attributed to your deleted account. Deleting a Suppr account does not cancel an Apple subscription; manage or cancel it in your Apple Account subscription settings. We otherwise keep account data only while the account exists, plus short-lived security logs and records a provider must retain for fraud prevention, accounting, or legal compliance. Email us if you need a copy of your data.
Children
Suppr is not directed at children under 13. We do not knowingly collect data from children under 13. If we learn we have, we will delete it.
Changes
We'll update this policy as the app evolves. Material changes will be reflected in the "Last updated" date and announced in the app.