Privacy Policy
Effective date: 25 September 2026
Controller: Pensy Group LLC, Tulsa, Oklahoma. Contact: foodoodle@pensygroup.com.
1. The 30-second version
- We collect what you give us: your account, your household, your recipes and scans, and your My Food information.
- Your My Food space is private by default. Planners in your household always see your dietary restrictions. Everything else leaves My Food only when you choose.
- AI features send relevant text and images to OpenAI to do their job. OpenAI doesn't train on that data.
- We don't sell your data. We don't show ads.
- You can export or delete your data in Settings.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email, name, password (hashed), avatar | To sign you in and identify you to your household |
| Household | Household name, members, roles, invitations, settings, themes | To run the shared plan |
| Recipes and meals | Recipes you write, generate, link, or scan; planned meals; votes; ratings; notes | Core functionality |
| Public recipes | A copy of each recipe a planner makes public: its title, picture, ingredients, steps, times, tags and nutrition, the name your household chose to be credited as, and the ratings other households give it (their stars only, as one number per household) | To show it on the public book and let other households add it |
| Reports about a public recipe | The reason and, if given, an email address | To act on the report |
| Oodle cards | Each member's card: their name, an age band derived from their birthday, their restrictions and notes, an optional note and contact; every version's salted fingerprint; each link it was sent as, who it was for, where it was emailed, whether it carries their likes, dislikes and favorite meals, and how often it was opened | To let a member or their manager send the current card to a school, a camp or a host, and turn it off |
| Grocery | Inventory, shopping list, receipts and receipt images | Core functionality |
| My Food | Dietary restrictions, preferences, goals, favorites, ideas, special requests, birthday date and birthday meal, personal plans, AI chats | Personal features and, where you choose, household planning |
| Managed profiles | Name, avatar, optional birthday, restrictions, preferences, favorites, requests, birthday meal for members without accounts (including children, added by a parent or guardian) | To include them in the household plan |
| Images | Recipe photos, scans, receipts, generated images | Scanning and display |
| Device and usage | Browser or app version, platform, push token, IP address, request logs, error reports, background task status | Security, reliability, notifications |
| Support | Messages you send us | To help you |
| Billing | Your household's plan, subscription status, and billing history. Your card details go to Stripe, never to us | To take payment and manage the subscription |
| Referral link | If you arrived through a member's referral link: which member's code it was and when you clicked | So that member is credited and your household gets its discount |
| Referral program | If you apply: your country, your answers to the application, and the version of the Affiliate Agreement you accepted. Then your referral code, daily click counts, the households your link brought, commissions and payouts. Stripe collects the identity, bank and tax details needed to pay you | To review your application, run the program, and pay you |
We don't collect precise location or contacts, and we never see or store your full card number.
3. How we use it
- Run foodoodle: plans, lists, recipes, scanning, notifications, emails you asked for.
- AI features: generate recipes and images, read scans and links, suggest meals, propose plans, answer questions.
- Keep meals safe: check meals against the dietary restrictions in your household.
- Improve suggestions: use favorites and preferences as de-identified signals within your household, unless you turn that off.
- Security and reliability: logs, rate limits, abuse prevention, backups.
- Legal: comply with law and enforce our Terms.
We don't use your data for advertising and we don't sell it.
4. Who sees what inside your household
- Everyone in the household sees the confirmed plan, recipes, the grocery list, votes counts, and member names and avatars.
- Planners also see members' dietary restrictions, submitted special requests, shared birthday meals, vote details, and anything a member sets to "Planners".
- Only you see your private My Food information, unless you change its visibility in Settings → Privacy.
- Managers of a managed profile see that profile's My Food, because they operate it on that member's behalf.
- Your AI chats are never shared with anyone in your household.
- Whoever holds an Oodle card link you sent sees that card — name, age band, restrictions, notes, contact, and their likes, dislikes and favorite meals unless you sent just the rules — until you turn the link off. Never the birthday, never an email, never anyone else in the house.
- A member whose referral link you used sees counts and amounts only: how many households their link brought and what they earned. Never your name, your email, your household, or anything you do in foodoodle.
- Anyone on the internet can see a copy of each recipe a member has made public — the recipe only. Never names, notes, votes, ratings, restrictions or anything from My Food. A public copy is permanent and is not deleted with your household or account; the household name on it is.
5. AI processing
AI features are provided using OpenAI's API. Depending on the feature, we send: recipe text, images of recipes and receipts, member first names, dietary restrictions, preferences and goals you have made visible to planning, your own My Food information for your personal AI, chat messages, and household context such as upcoming meals and inventory. OpenAI does not use API data to train its models and retains it for up to 30 days for abuse monitoring, per its API policies. AI output is stored in foodoodle as recipes, proposals, and messages. You can delete AI chats at any time.
Connected assistants. You can connect your own AI assistant, for example Claude or ChatGPT, to foodoodle from that assistant. When you do, it can see what you can see in the household you choose (the plan, the grocery list, recipes and your own My Food) and, if you allow it, do what you can do there, as you: add to the list, vote, plan meals. What it reads is sent to that assistant's provider under your agreement with them, not ours. It never gets another member's private information, and it can't change who is in your household, what others can see, your payments, or a dietary restriction beyond adding one. Everything it changes shows in your household's activity with its name on it. You can disconnect any assistant at any time in Settings → Account.
6. Service providers
| Provider | What they process | Purpose |
|---|---|---|
| OpenAI | Text and images described above | AI features |
| Resend | Email address, name, email content | Invitations, password resets, digests, support replies |
| Replit (hosting and PostgreSQL) | All application data | Running the service |
| Replit App Storage | Uploaded and generated images | Storing images |
| Expo, Apple, Google | Push tokens, notification text | Push notifications |
| Stripe | Billing name and email, card details, subscription and payment history; for referral affiliates, identity, bank and tax details | Payments, subscriptions, affiliate payouts, and tax reporting |
| No third party. Page events on the marketing site go to our own server, with no cookies and no identifier | Aggregated, anonymous page events | Understanding site traffic |
Providers act on our instructions under contracts that protect your data.
7. Children
Signing up on your own is for people 13 and over (16 where required). A child under 13 uses foodoodle only through a parent or legal guardian in their household, in one of two ways:
- A managed profile. We collect only what the adult enters: a name, optional avatar and birthday, food preferences, restrictions, favorites, requests, and a birthday meal.
- The child's own login. A parent or guardian who plans the household gives the child's profile a login, and the invitation goes to the email address they enter. That step is the parent's consent, and nothing is collected from the child before it. The login adds the child's email address and password, what they do in the household (votes, requests, list items, ratings and notes), and the device and usage data in section 2.
Anyone under 13 has no foodoodle chat, no personal food plans and no connected assistants, so none of the child's own information is sent to an AI provider for those. Household features a child uses, such as scanning a recipe, are processed by the providers in section 6 in the same way as everyone's. We use a child's information only to run their household's foodoodle. We don't sell it or use it for advertising.
A parent or guardian who looks after the child can see and edit the child's profile and food rules at any time, remove the child from the household, and ask us to review or delete the child's information by writing to foodoodle@pensygroup.com. A child's account can also be deleted from its own Settings. The limits above end on the child's 13th birthday. If you believe we hold information about a child without a parent's consent, contact foodoodle@pensygroup.com and we will delete it.
8. Retention
| Data | Kept |
|---|---|
| Account | Until you delete it, then 30 days grace, then deleted |
| Household data | While the household exists; 30 days grace after deletion |
| Your My Food after leaving a household | 30 days, exportable, then deleted |
| Scans and receipt images | 12 months by default (household setting 3–24 months), then images deleted |
| AI chats | Until you delete the thread |
| Logs | 30 days |
| Backups | 30 days, encrypted |
| Email suppression list | Hashed address kept to honour opt-outs |
| Public recipe copies | Permanent, by design: a recipe made public was given to the commons. Not deleted with the household or the account; the household's name on it is removed with the household. Taken down only by us, on a report |
| Reports about a public recipe | Until acted on, then 12 months |
| Billing and referral records | As long as tax and accounting law requires us to keep financial records |
| Referral cookie | 30 days in your browser, removed once your household is created |
| Oodle cards, versions and links | Deleted with the member. The fingerprints on the ledger are permanent by design and meaningless without the card's salt, which is deleted with it |
9. Your rights
Depending on where you live you may have the right to access, correct, export, delete, or restrict use of your data, to object to processing, and to complain to a data protection authority. In foodoodle: Settings → Account → Export my data / Delete account. Or email foodoodle@pensygroup.com. We respond within 30 days.
California residents: we don't sell or share personal information for cross-context advertising. Rights under the CCPA can be exercised through the same channels.
10. Security
Passwords are hashed. Sessions use secure tokens. Data is encrypted in transit and at rest. Images are served through expiring links. Access inside the company is limited to people who need it to run the service. No system is perfectly secure; if there is a breach that affects you we will tell you as the law requires.
11. International transfers
Our providers may process data in the United States and other countries. Where required we use approved safeguards such as standard contractual clauses.
12. Cookies
The web app uses one strictly necessary cookie for your session. If you arrive through a member's referral link, we also set one first-party cookie, fd_ref, for 30 days. It holds the referral code and the time you clicked, and nothing about you or your device, so that the member who sent you is credited and your household gets its discount. It is removed once your household is created. The marketing site sets no other cookies; its analytics are cookieless. We don't use advertising trackers, and nobody promoting foodoodle may place a pixel, script or tracker on our pages.
13. Changes
We'll post updates here with a new effective date and tell you in the app or by email about material changes at least 14 days before they take effect.
14. Contact
foodoodle@pensygroup.com · Tulsa, Oklahoma