Winning Meals Privacy Policy
Privacy Policy
Last updated: June 28, 2026
Winning Meals is a beta app. This policy describes the current web app, iPhone/iPad wrapper, and optional server-backed features. We will update it before adding new analytics, billing, grocery checkout, iCloud sync, or broad account-sharing features.
Summary
Winning Meals is local-first. Recipes, pantry foods, meal plans, fitness profile inputs, coach-client notes, scan images, and backups stay on your device or browser unless you choose to export, import, paste, upload, scan, use optional account sync, or call a server-backed lookup feature.
Winning Meals does not currently require an account, sell personal data, run ads, or provide active iCloud sync. Optional Supabase account sync may be enabled for beta testing so users can move app data between devices after signing in.
Information Stored Locally
The app can store these items locally in your browser or native app container:
- Saved recipes, ingredients, instructions, tags, collections, notes, ratings, source links, and cooked dates.
- Uploaded recipe scans or pantry photos when saved with a recipe or pantry workflow.
- Weekly meal-plan assignments, grocery-list state, pantry foods, and reviewed quantities.
- Fitness profile inputs, editable macro targets, and coach workspace records.
- Storage preferences, local beta-interest entries, and aggregate local evidence counters.
Clearing browser data, using private browsing, deleting the app, or changing devices can remove or hide local data. Export a JSON backup before clearing data, switching devices, or reinstalling.
User-Controlled Exports And Imports
You can export local recipe backups and aggregate evidence files. Recipe backups can include saved recipes and the local fitness profile. Evidence exports are designed to contain aggregate usage and AI cost counters only, not recipe text, grocery items, profile details, names, emails, or payment details.
Scanning, OCR, And Photos
Winning Meals uses OCR to help read recipe cards, screenshots, food labels, barcodes, and pantry photos selected by you. In the web app, OCR runs in the browser through Tesseract.js. The iOS wrapper asks for camera or photo library access only when you choose a scanning or import workflow.
Server-Backed Features
Some optional features call Winning Meals server routes so private API keys stay out of the browser and iOS bundle. Gemini-backed cleanup and meal-planning features send only the recipe, pantry, goal, and grocery details needed for the requested action. USDA lookup sends a food query. Open Food Facts lookup sends a barcode. Recipe URL import sends a URL that you provide.
Review AI-generated results, nutrition estimates, product suggestions, and imported recipe drafts before saving, cooking, shopping, or using them for nutrition planning.
Grocery And Shopping Integrations
The current app can prepare grocery-list payloads and exports. Winning Meals does not silently place grocery orders, store grocery account tokens locally, or imply a grocery-provider partnership before approval.
Nutrition And Health
Nutrition and macro tools are planning aids, not medical advice. Macro targets are estimates and remain editable. Ask a qualified professional about weight loss, medical diets, pregnancy, minors, allergies, diabetes, kidney disease, heart disease, eating disorder concerns, or other clinical situations.
Account Sync And Cloud Storage
Optional Supabase account sync can send recipes, pantry items, meal-plan slots, coach clients, settings, and scan metadata needed to sync your account across devices. Account sync is not required to use the app locally. The current MVP does not provide active iCloud sync.
Data Deletion
You can delete saved recipes, pantry items, coach clients, and other local records inside the app. You can also remove local data by clearing browser data or deleting the app. If optional account sync is enabled, server-side account export and deletion are handled through support during beta until self-service account controls are built and reviewed.
Children
Winning Meals is not designed for children under 13. Do not knowingly submit children's personal information without a reviewed child-safety, consent, and privacy process.
Security
Server-only API keys stay in server-side secret stores. Keys should not be placed in the app bundle, screenshots, docs, Git history, support messages, Linear issues, or GitHub issues.
Contact
For beta support, account data requests, or privacy questions, use the support path published at winningmeals.com/support.html.