MeuMenu Ler em português

Privacy Policy

MeuMenu Privacy Policy

Health data has its own policy. The nutrition analysis of your meals involves sensitive personal data, and everything specific to it — how we ask for consent, what the meal history stores, how to withdraw and erase — lives in the Health Data Policy. Read both: this policy is the general map; that one is the fine detail of what matters most.

This document explains, in plain language, what data MeuMenu collects, what we use it for, who we share it with, and what you can demand from us. We are a Brazilian company, so this policy is built on Brazil's General Data Protection Law (Law 13,709/2018 — LGPD) and written to be compatible with the European GDPR. The rules of the service itself — plans, billing, cancellation — live in the Terms of Use.

This policy is available in English (MeuMenu) and Portuguese (MeuMenu). Both versions say the same thing.

1. Who controls your data

MeuMenu is a product of OxeTech. The entity that decides what happens to your data — the controller — is:

The e-mail above receives every request and question about personal data, and that is where we answer from. We are a small company, but we do not rely on the small-business DPO exemption available under Brazilian regulation: MeuMenu processes sensitive health data with artificial intelligence, so we appointed a DPO anyway.

You may also complain directly to Brazil's data protection authority (ANPD) at gov.br/anpd.

2. Where this policy applies

At launch, the service is offered in Brazil and the United States. If you are in a jurisdiction that grants you additional rights (such as the GDPR, in the European Union), we honor equivalent requests through the same channel and within the same deadline as in section 10.

3. What we collect and why

We collect only what the app needs to work. The table shows each item, its purpose, and the legal basis under the LGPD and the GDPR.

Data Purpose Legal basis (LGPD / GDPR)
E-mail address Identify you, let you sign in, confirm the address via a verification code, and send notices about your account and subscription. There is no social login — we receive no data from social networks. Performance of contract — LGPD art. 7(V) / GDPR art. 6(1)(b)
Password (stored only as a hash) Verify that it is you signing in. The password itself is never stored and is never readable by us: we keep only a cryptographic hash, which cannot be reversed into the original password. Performance of contract — LGPD art. 7(V) / GDPR art. 6(1)(b)
Versioned consent records (date, version of the text accepted, and the IP address of the act) Prove that each consent existed, when it was given, and over which text — an obligation of anyone processing personal data (LGPD art. 8 §2; GDPR art. 7(1)). Accountability / legitimate interest — LGPD art. 7(IX) / GDPR art. 6(1)(f)
Usage events (analysis counts, tokens consumed, and cost — never any photo content) Enforce your plan limits, control AI costs, and detect abuse. Performance of contract and legitimate interest — LGPD art. 7(V) and (IX) / GDPR art. 6(1)(b) and (f)
Store subscription identifiers (pseudonymous codes provided by Apple and Google) Know which plan you have and unlock paid features. Payment happens entirely inside the App Store or Google Play — we never receive or store card numbers. Performance of contract — LGPD art. 7(V) / GDPR art. 6(1)(b)
Menu photo (transient — see section 5) Extract the dishes from the menu and, when you ask, generate an illustrative image of each dish. Performance of contract — LGPD art. 7(V) / GDPR art. 6(1)(b)
Photo of your plated meal + manual inputs (plate size or portion weight, if you provide them; transient — see section 5) Estimate the portion weight and nutrients (calories, protein, carbohydrates, fat, fiber, and sodium). This is inferred health data. Specific, highlighted consent — LGPD art. 11(I) / GDPR art. 9(2)(a). Details in the Health Data Policy
Meal history (only if you switch the opt-in on — see section 6) Store your analyses on the server so you can follow your eating over time. Specific, highlighted consent — LGPD art. 11(I) / GDPR art. 9(2)(a)
IP address and server access logs Keep the records required by Brazilian law, investigate abuse, and protect the service. Legal obligation — Brazilian Internet Framework (Marco Civil), art. 15, with LGPD art. 7(II) / GDPR art. 6(1)(c) and (f)

We do not ask for national ID numbers, phone numbers, home addresses, body weight, height, or medical records. If that ever changes, we will tell you first, as described in section 15.

4. The journey of your photo

This is the most important part of this policy. When you photograph a menu or a plate:

  1. The photo leaves your device over an encrypted connection (HTTPS) to our server (a VPS located in Brazil).
  2. The server processes the image in memory only — it is never written to disk and we keep no copy.
  3. The image and the analysis instructions go to the Gemini API, operated by Google LLC — a paid service, contracted under the Gemini API Data Processing Addendum (DPA). Google acts as our processor: it processes on our behalf and under our instructions.
  4. The result comes back to the app and the image is discarded from our server's memory.

What Google may keep. Under the paid Gemini API terms, Google does not use your content to train its models. Google may, however, retain limited logs of prompts and responses for a short period, for security and abuse detection, as set out in the DPA and Google's own policies. We would prefer that to be zero; since it is not, we say so in plain sight.

What we never send to Google: your e-mail, your password or its hash, your subscription data, and your meal history. The request carries no name, no e-mail, and no identifier of your account — to Google, it comes from MeuMenu's account, not from you. The photo file itself, however, may contain metadata recorded by your device (such as capture location and time); if that concerns you, turn off location tagging in your camera before shooting.

AI-generated images. When the app generates a picture of a dish from the menu, that picture is labeled as AI-generated and carries the SynthID watermark, embedded by Google. The image is illustrative: the actual dish the restaurant serves may differ.

Estimates are estimates. Nutrition values are approximate, produced by AI from an image. They do not replace official food labeling or the guidance of a health professional. You can enter the plate size or the portion weight to improve the estimate; by default, the AI estimates on its own.

Photograph with care. Since the image leaves your device, avoid framing anything unrelated to food: other people's faces, documents, screens, badges.

5. What we do not retain

Worth repeating outside the table: we do not store menu or plate photos. We process them in memory, send them to Google for analysis, and discard them. If you do not switch the meal history on (section 6), the analysis result is not kept on the server either.

In the legacy web app, the gallery of generated images lives in the browser's local storage, on your device — the server keeps no copy of it. If you clear your browser data, that gallery is gone, and we cannot recover it, because it was never with us.

6. Meal history is opt-in — and withdrawing means erasing

The meal history starts switched off. It only comes into existence if you turn on its dedicated toggle inside the app:

The full detail — exactly what the history contains, timelines, and the effects of withdrawal — is in the Health Data Policy.

7. What does not exist in MeuMenu

If any item on this list ever changes, this section gets rewritten first and you get notified beforehand (section 15).

8. Who we share data with

This is the complete list. There are no others:

9. International data transfers

Google LLC processes the data described in section 4 in the United States. That transfer happens under the Gemini API Data Processing Addendum, which incorporates contractual data-protection safeguards; under the LGPD, it rests on article 33 (contractual guarantees of an equivalent level of protection, in the standard-clause format of ANPD Resolution 19/2024).

For people in the European Union, once the service is enabled there, the mutual adequacy recognition between the European Union and Brazil additionally supports the data flow between the two jurisdictions, on top of the DPA's contractual safeguards for the leg in the United States.

If we change AI provider or processing country, we will update this policy and notify you first (section 15).

10. Your rights and how to exercise them

Free of charge and with no justification required, you can:

Deadline: 15 calendar days. That is the deadline in LGPD article 19 — the shortest among the privacy regimes that reach us — and we apply it to every request, from anyone, in any country. If a request is complex and needs more time, we say so within those 15 days, with the reason.

How to ask: through the app's own screens where a button exists for the request (account deletion and meal history already have one), or by e-mail at suporte@oxetech.cloud. We may ask you to confirm your identity first — that protects you, so nobody can request your data in your place.

11. How long we keep each thing

Category Period Why
Menu and plate photos Not retained. Processed in memory and discarded right after. We do not need them once the analysis is done.
Server access logs (IP, date, and time) 6 months. Retention period required by Brazil's Marco Civil, art. 15.
E-mail, password hash, and usage events While the account exists. Erased when the account is deleted; backup copies are purged within up to 6 months (section 12). Needed to operate the account.
Meal history (opt-in) While your consent is active. Erased when you withdraw or delete the account; backups within up to 6 months. It only exists because of your consent.
Versioned consent records While the account exists. After deletion, only a cryptographic proof (HMAC) remains — one that does not contain your e-mail and cannot be reversed into it. Proof that the consent and the deletion happened.
Subscription and tax records Up to 5 years after the fact, depersonalized when the account is deleted. Tax obligations and defense in any billing dispute.

12. Deleting your account

You can delete your account through two paths: inside the app itself, in the account area, or through the deletion page on our website — useful if you have already uninstalled the app.

What happens when you delete:

Deleting the account does not cancel the subscription. The subscription is a contract between you and Apple or Google and can only be canceled in the App Store or Google Play settings. Cancel it there — before or after deleting the account — so you do not keep being charged.

13. Children and teenagers

MeuMenu is not directed at children under 13, and we direct no content at that audience. Sign-up asks only for an e-mail and a password and does not verify age — we count on you and on parents and guardians to respect the limit. If we learn that an account was created by a child under 13, we delete the account and the associated data, at no charge and without needing a request. If you are a parent or guardian and believe a child created an account, write to suporte@oxetech.cloud.

Teenagers between 13 and 18 should use the app with the knowledge and supervision of a parent or guardian.

14. Security

What actually exists, today:

No system is invulnerable, and we will not claim otherwise. If a security incident poses a relevant risk to you, we follow LGPD article 48: we notify the authority (ANPD) and you, saying which data was affected, the risks involved, and what we have already done.

15. Changes to this policy

If you disagree with a new version, you can close your account at no cost (section 12). Previous versions are available on request.

16. Contact

Questions about your data: suporte@oxetech.cloud. Our Data Protection Officer, OXETECH TECNOLOGIA LTDA, answers for these requests within OXETECH TECNOLOGIA LTDA. You may also contact Brazil's data protection authority (ANPD) at gov.br/anpd.