Draft — pending legal review. This page is not final.

Privacy Policy

Effective [EFFECTIVE DATE] · Policy version 2026-09

This policy explains what the A1cMealPrep app collects, why, who helps us handle it, and what you can do about it. We've tried to keep it short and plain.

The short version

  • You need an account to use the app. You make it with Apple or Google, after the sample plan and the subscription offer, whether or not you subscribe.
  • Your health answers, plans and shopping list stay on your phone unless you turn on "Plan with my health info". Without it, we receive only your sign-in, your consent choices and your settings (household size, budget, time per meal, cooking style, region and units), so you don't answer those again on a new phone.
  • We send a small brief to our AI provider, with no name in it, only if you turn on "Share with our AI provider".
  • The app counts how it's used, anonymously, for everyone from the first launch: no answers, no health information, no account or device ID, and an ID that's gone when the app closes. Only if you turn on "Help improve the app" is your usage linked to your account ID.
  • No ads. No cross-app tracking. We don't sell your data. Your health data is never used for ads and never stored in iCloud.
  • You can change your choices or delete your account in the app: Me → Privacy & data.

Who we are

A1cMealPrep is an iPhone app published by Nodogames, LLC ("Nodogames", "we", "us"), [LEGAL ADDRESS OF NODOGAMES, LLC]. Nodogames is a United States company. We decide why and how your personal data is used. Under the GDPR and UK GDPR, that makes us the "controller".

Our privacy officer, who is also the person in charge of protecting personal information under Quebec law, is [PRIVACY OFFICER NAME]. You can reach them at support@a1cmealprep.com.

Our representative in the EU, the UK and Switzerland, if the law requires one: [EU / UK / SWISS REPRESENTATIVE, IF REQUIRED].

A1cMealPrep is for adults with prediabetes or type 2 diabetes who don't use insulin, and the people who cook for them. We aren't a doctor, a hospital or a health plan, and HIPAA doesn't apply to us.

What we collect, and when

Your answers and the sample plan stay on your phone while you set up the app. Then everyone signs in, with Apple or with Google, after the subscription offer, whether or not they subscribe. What we receive after that depends on your choices. Without "Plan with my health info", your health answers, food style, plans and shopping list stay on your phone, your plans are built there, and we receive only your sign-in, your consent choices and your settings. With it on, we also keep a copy of your answers, your recent plans (whether our servers or your phone built them), your shopping list, ratings and favourites, so you can sign in on another phone and pick up where you left off.

DataWhat it includesWhen it leaves your phone
Your health answers and food choices Your condition (prediabetes, type 2 without insulin, or cooking for someone who has it), the types of medicine you tell us about, your goals, allergies, carb range, foods you don't eat and food style (for example vegetarian, halal or kosher). This is health information. Food style can also reveal religious beliefs, and foods you don't eat can hint at health or belief, so we treat them the same way. Before you sign in: never. Without the health consent: never. With "Plan with my health info" on: we store them on our servers.
Your settings Household size, meals per day, weekly budget, time per meal, cooking style, country, state or province, currency, and units (including the unit for blood sugar numbers; we never receive a reading). These aren't health information. When you sign in, and whenever you change one, whether or not "Plan with my health info" is on.
Your sign-in With Sign in with Apple: an ID that Apple gives us for you, and your email address if you choose to share it (it may be Apple's private relay address). We don't ask Apple for your name. When you sign in, we also keep an encrypted Sign in with Apple token, so that we can revoke it with Apple when you delete your account.
With Sign in with Google: an ID that Google gives us for you, and the basic profile Google shares with every app you sign in to with it: your email address, your name and a link to your profile picture. Our login provider keeps them with your account. The app shows your name in the Me tab and doesn't use the picture. We never see your Google password, and we don't ask for access to anything else in your Google Account.
When you sign in.
Plans, shopping list, ratings and favourites Your recent plans: the days you planned, the recipes in each meal, servings, the budget, time and carb range the week was built with, meals you pin or swap, and the prep tasks you tick. Your shopping list: its items and amounts (including ones you edit or add yourself), what you tick and your pantry check. Your ratings (liked, OK or disliked, with optional tags) and your favourite recipes. A plan built for your carb range and a list without your allergens are health-related, so they follow your health consent. Only when "Plan with my health info" is on. Otherwise they stay on your phone.
Your consent choices Which of the three choices you turned on or off, when, and which version of this policy you saw. When you sign in, and whenever you change one.
Subscription and purchases Apple takes payment, and we never see your card. Our subscription provider, RevenueCat, receives your purchase receipt and a user ID (your account ID once you've signed in, and a random ID before that; a purchase made before you sign in moves to your account when you do). It tells the app and our server whether you have an active subscription. When you see prices, buy, restore, or the app checks your subscription.
Anonymous usage counts Simple events about what you do in the app: which setup screen you're on (by its position, never what it asks), that you saw or closed the subscription offer, started a trial, subscribed or restored a purchase, started, cancelled or finished signing in with Apple or Google, built a plan, swapped or pinned a meal, built, copied or shared the shopping list, or viewed, added or rated a recipe. Each event comes with the app version, the iOS version (for example 26), the country your phone's region is set to, and a random ID that the app makes when it starts and keeps only in memory, so it's gone when the app closes. There's no account ID, no device or advertising ID, and nothing is stored on your phone for it. Events never contain your answers or any health information. Our analytics provider is set to discard IP addresses, not to look up your location from them, and not to build a profile from these events. From the first time you open the app, in small batches, whatever you choose. A batch that can't be sent is dropped. While "Help improve the app" is on and you're signed in, these anonymous counts stop and the usage data below is sent instead.
Usage data linked to your account The same events, sent with your account ID (a random code from our login provider, not your email or name) instead of the per-launch ID. Our analytics tool adds the app version, iOS version and device model, and keeps a random ID of its own on your phone. We never send your email, name or answers, and we never link the anonymous counts from before you signed in to your account. No session recordings, no screen tracking, no advertising ID. [TO CONFIRM: the analytics tool's built-in properties] Only if you turn on "Help improve the app", and only once you've signed in. Turn it off in Me → Privacy & data, log out or delete your account, and the app goes back to anonymous counts.
Recipe requests to our AI provider A short brief with the meal type, carb range, time limit, food style, allergies and foods you don't eat. Never your name, email, account ID, medicines or condition. See Our AI provider. Only if you turn on "Share with our AI provider".
Technical data Our server keeps a log line for each request: the time, the endpoint, the result and how long it took. It doesn't log request bodies or query strings, which could contain health information. Our hosting providers see your IP address when the app connects, and we use it for rate limiting and security. Our login provider may keep sign-in security records, including IP addresses. [TO CONFIRM: what Supabase Auth and Railway keep, and for how long] Whenever the app connects to our servers, including to refresh the recipe library, which sends nothing about you.
Support messages Your email address and what you write to us. When you email us.

What we don't collect. We don't ask for your name (Google shares it if you sign in with Google). We don't collect your contacts, photos, precise location, blood sugar readings or Apple Health data. The app fills in your country and state from your phone's region settings, and doesn't use GPS. We don't use the advertising ID, and the app doesn't show Apple's tracking prompt because it doesn't track you.

Reminders. The trial reminder and prep reminders are scheduled on your phone. We don't run a push notification server and we don't receive your device's notification token.

This website has no cookies, no analytics and no third-party scripts, fonts or embeds. Our host keeps ordinary server logs.

Why we use it, and our legal basis

If you're in the European Economic Area, the UK or Switzerland, the law asks us to name a legal basis for each use of your data. Health information is a special category under GDPR Article 9. We only process it on the basis of your explicit consent under Article 9(2)(a).

What we doDataLegal basis
Build your plans, swaps and recipes on our servers Your answers Your explicit consent to "Plan with my health info": GDPR Article 6(1)(a) and Article 9(2)(a), and the same under UK GDPR.
Keep your account and your settings Sign-in details from Apple or Google, consent choices, settings Contract: providing the app you asked for (Article 6(1)(b)).
Save your answers, plans, shopping list, ratings and favourites to your account Your health answers and food choices, plans, shopping list, ratings, favourites Your explicit consent to "Plan with my health info": Article 6(1)(a) and Article 9(2)(a), and the same under UK GDPR.
Run subscriptions and check whether you have one Purchase data, user ID Contract (Article 6(1)(b)).
Ask our AI provider to write recipes The recipe brief Your explicit consent to "Share with our AI provider" (Article 6(1)(a) and Article 9(2)(a)).
Count how the app is used, anonymously Anonymous usage counts We don't think these counts are personal data: they carry no account, device or lasting ID, and nothing is stored on your phone for them. To the extent they are, our legitimate interest in seeing where people get stuck so we can fix it (Article 6(1)(f)). [TO CONFIRM: see the note for the lawyer below]
Understand how you use the app, linked to your account Usage data linked to your account Your explicit consent to "Help improve the app" (Article 6(1)(a), and Article 9(2)(a) because using a diabetes app can itself say something about your health), which is also the consent that the ePrivacy rules require.
Keep the service secure, stop abuse, fix faults, answer support Technical data, support messages Our legitimate interests in a secure, working service (Article 6(1)(f)). You can object.
Keep a record of your consents, meet tax and accounting rules, handle legal claims Consent log, purchase records Legal obligation and legitimate interests (Article 6(1)(c) and (f)). For health information, the establishment or defence of legal claims (Article 9(2)(f)).

Note for the lawyer: anonymous counting without consent in the EU and UK

Remove this box before publishing. What the app does, and what we'd like you to confirm:

  • What happens. From the first launch, in every market including the EU, EEA, UK and Switzerland, the app sends the anonymous usage counts above without asking, and there's no switch to stop them. It stores nothing on the device and reads nothing from it for this: the ID is random, kept in memory, and new on every launch; there are no cookies and the connection keeps no cache. The analytics provider (PostHog, US) discards IPs, does no location lookup and makes no person profile. The events never contain answers or health information.
  • ePrivacy Article 5(3) and UK PECR regulation 6. The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) treat software on a device that makes it send information as "gaining access", even when nothing is stored. If that applies, the only exemption is "strictly necessary", which analytics usually isn't. Some regulators allow audience measurement without consent under conditions (for example the CNIL's exemption: first-party, anonymous statistics only, no cross-app tracking, limited retention, and people are told and can object). The UK Data (Use and Access) Act 2025 adds a PECR exception for statistical analytics where people get clear information and a simple way to object. Our anonymous path has no way to object. Do we need one (for example a "Send anonymous usage counts" switch), in which countries, and is this policy enough information?
  • GDPR. Are per-launch events with no lasting ID personal data (they single out one app launch for its duration)? If they are, is legitimate interest (Article 6(1)(f)) sound here, given the app is for people with diabetes? We don't think the anonymous counts are health data, because they can't be tied to a person.
  • Elsewhere. Quebec Law 25 section 8.1 (technology that can identify, locate or profile must be off by default) and Washington's My Health My Data Act (is this "deidentified data"?).
  • The linked path. Is the "Help improve the app" wording in the app explicit enough for Article 9(2)(a) and for Washington's consent rules? Deleting an account doesn't yet delete the person and their events in PostHog; they stay until PostHog's retention period ends unless we delete them by hand.

We don't use your data to make decisions that have legal or similarly significant effects on you. The planner builds meal suggestions from rules and our recipe library. You can change any of them.

We never use your data for advertising, and we never sell it.

Your three choices

The app asks for these just before you sign in. They all start off, and you can change each one at any time in Me → Privacy & data.

  • Plan with my health info (needed to save your answers and plans to your account). Lets us store your condition, medication, carb range and other health answers, your food style and foods you don't eat, your recent plans, your shopping list, ratings and favourites on our servers, so they come back when you sign in on another phone, and so our servers can build your plans. If you turn it off, we stop syncing them and delete from our servers your health answers, food style, foods you don't eat, plans, shopping list, ratings and favourites. Your settings and consent choices stay with your account. Everything stays on your phone, and the app keeps working there. Turning it off also turns off "Share with our AI provider".
  • Share with our AI provider. Lets us send a brief to our AI provider to write a new recipe. See Our AI provider. It needs the first choice to be on.
  • Help improve the app. Links how you use the app to your account ID once you've signed in, so we can see what to improve. Without it, the app still sends the anonymous usage counts described above, which aren't linked to you. Turning it off, logging out or deleting your account goes back to anonymous counts, and what was counted anonymously before you signed in is never linked to you.

Taking back a consent doesn't affect what we did before you took it back. You can use the app without any of these: you still sign in, but your health answers, plans and shopping list stay on your phone and we keep only your sign-in, your settings and these choices.

Our AI provider

The recipes in the app are written by an AI model (Claude, from Anthropic) and then checked automatically. Nutrition, cost and allergens are calculated from food data, not written by the AI. The recipe library is written ahead of time and doesn't use anyone's personal data.

When you turn on "Share with our AI provider", and a plan has a gap that no recipe in the library fits, we may ask Anthropic to write one new recipe for that gap. The request contains:

  • the meal type, such as dinner;
  • your carb range and time limit for that meal;
  • your food style;
  • your allergies and the foods you don't eat.

It never contains your name, email, account ID, medicines, condition or location. Anthropic acts as our processor. It may only use the request to write the recipe and send it back. [TO CONFIRM: Anthropic's retention period for API requests, and that it doesn't use them to train its models]

With the consent off, nothing about you goes to Anthropic, and your plans still come from the recipe library.

Illustrations of recipes and ingredients are made by AI image models through fal. They are made once and never use your data. fal receives descriptions of dishes and ingredients only.

Who we share it with

We share data only with companies that help us run the app, under contracts that limit what they can do with it. We don't sell your data or share it for advertising.

CompanyWhat it does for usWhat it receivesWhere
Apple Sign in with Apple, the App Store and payments. Apple decides how it uses your Apple Account and payment data under its own privacy policy. Your sign-in and purchases. United States and other countries
Google Sign in with Google, if you choose it. Google decides how it uses your Google Account data under its own privacy policy. That you signed in to A1cMealPrep with your Google Account. United States and other countries
Supabase Our database and login service. Your account ID, email, consent choices and settings (with Google, also your name and profile picture link), and, with consent, your health answers, plans, shopping list, ratings and favourites. United States (US East)
Railway Runs our API server. Your requests as they pass through, and our log lines. [TO CONFIRM: region]
Anthropic Writes new recipes, only with your consent. The recipe brief described above. United States
RevenueCat Runs subscriptions and tells us if you have one. Purchase receipts, a user ID and subscription status. United States
PostHog Usage analytics: anonymous counts from everyone, and usage linked to your account only with your consent. Anonymous usage events; with "Help improve the app" on, usage events with your account ID. No health data, email or name. PostHog Cloud US
fal Makes recipe and ingredient illustrations. Text descriptions of dishes. No user data. United States
Cloudflare Domain name service for a1cmealprep.com, and forwarding of email sent to support@a1cmealprep.com. [TO CONFIRM: mail provider] Emails you send to us. Global network

We may also disclose data when the law requires it, to protect people's safety or our rights, or as part of a sale or merger of our business. If that happens, this policy's protections continue to apply to your data, and we'll tell you first.

Transfers to other countries

Our servers and most of our providers are in the United States. If you live in the European Economic Area, the UK or Switzerland, your data is therefore transferred to the United States.

The law lets us do that only with safeguards. In general terms, we rely on the EU-US Data Privacy Framework, and its UK and Swiss extensions, where a provider is certified under it. Where it isn't, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum for UK data, in our contracts with the provider. We also limit what we send and encrypt data in transit. [TO CONFIRM which mechanism applies to each of Supabase, Railway, Anthropic, RevenueCat, PostHog, Apple, Google and fal]

You can ask us for a copy of the safeguards we rely on, at support@a1cmealprep.com.

If you live in Quebec, your data also leaves Quebec. We assess the privacy risks of that before it happens. [TO CONFIRM: privacy impact assessment completed]

How long we keep it

  • On your phone: until you log out, delete your account in the app, or delete the app. Logging out removes your plan, shopping list and answers from the phone.
  • Account data on our servers (profile and settings, plans, shopping list, ratings, favourites, consent log, login record including what Apple or Google shared, and stored Sign in with Apple token): until you delete your account. We keep only your 8 most recent plans; older ones are deleted when you save a new one. Your health answers, plans, shopping list, ratings and favourites are also deleted as soon as you turn off "Plan with my health info". When you delete it, we delete these from our database right away. Backups that still hold them are overwritten on our provider's normal schedule. [TO CONFIRM: backup period]
  • Purchase records: Apple and RevenueCat keep subscription and purchase records for as long as they need for accounting, fraud prevention and legal reasons. [TO CONFIRM: whether we ask RevenueCat to delete the customer record when an account is deleted]
  • Usage data (anonymous counts, and usage linked to your account): [TO CONFIRM: retention period set in PostHog]. When you turn off "Help improve the app" or delete your account, the app stops sending usage linked to you at once. What was already sent under your account ID stays until that period ends; email us to have it deleted sooner. [TO CONFIRM: whether account deletion should also delete the person in PostHog (it doesn't today)]
  • Server logs: [TO CONFIRM: log retention at Railway].
  • Support emails: while we help you, and for a limited time afterwards. [TO CONFIRM: period]

We may keep some data longer where the law requires it, or to deal with a legal claim.

Your rights

Whatever country you live in, you can:

  • Get a copy of the personal data we hold about you.
  • Correct it. You can edit your answers yourself in the Me tab.
  • Delete it. In the app, go to Me → Privacy & data → Delete my account. This removes your plans, shopping list, ratings, favourites, settings and health info from our servers and from your phone. It doesn't cancel your subscription. Apple bills it, so cancel it first in Settings → Apple Account → Subscriptions.
  • Take back a consent at any time, in Me → Privacy & data.
  • Take your data with you. Ask us and we'll send your data in a common, machine-readable format.
  • Ask us to limit how we use your data, or object to uses based on our legitimate interests.
  • Complain to a regulator (see Where you live).

To use a right that the app doesn't cover, email support@a1cmealprep.com. Tell us the email address you signed in with (with Apple it may be a relay address) so we can find your account. We may ask you to confirm it's you, so we don't hand your data to someone else.

We reply within 30 days. Some laws let us take up to 45 more days for complex requests, and we'll tell you if we do. There's no charge, unless a request is clearly unfounded or excessive.

Children

A1cMealPrep is for adults. You must be 18 or older, or the age of majority where you live, to use it. We don't knowingly collect data from anyone younger. If you think a child has an account, email us and we'll delete it.

Where you live

European Economic Area, UK and Switzerland

The legal bases are above, and Nodogames is the controller. You have the rights in the section above, and you can complain to your local data protection authority. In the UK, that's the Information Commissioner's Office. In Switzerland, it's the Federal Data Protection and Information Commissioner. Our representative, if the law requires one, is named at the top of this page.

Canada

We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, Law 25. We ask for express consent for health information, in separate choices you can take back. Every choice starts off. The app does count use anonymously for everyone, with no account or device ID and nothing kept on your phone; linking your usage to your account is a separate choice that starts off. You can ask for a copy of your data in a common format. Our privacy officer is named above. You can complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information. [TO CONFIRM: French version of this policy for Quebec]

United States

Depending on your state, including California, Colorado, Connecticut, Texas, Virginia and others, you may have the rights of access, correction, deletion, portability, and opting out of sale, targeted advertising and profiling. We give these rights to everyone in the United States. We don't sell personal information, we don't share it for cross-context behavioural advertising, and we don't use it for targeted advertising. We collect health information as "sensitive" information only with your consent, and only to give you the app you asked for.

If we turn down a request, you can appeal by replying to our answer with "Appeal" in the subject line. We answer within 45 days. If you still disagree, you can contact your state attorney general.

Washington, Nevada and Connecticut have extra rules for consumer health data. See our Consumer Health Data Privacy Policy.

Security

  • Data moves between the app and our servers over encrypted connections, and our database provider encrypts stored data.
  • You sign in with Apple or Google, so we never hold a password.
  • Our database is closed to the public. Only our server can read it, and it checks who you are on every request.
  • We don't log request bodies or query strings, and we limit who at Nodogames can see data.
  • The app doesn't use iCloud to sync or store your data, and it keeps its data on your phone in a place that's left out of iCloud and computer backups. If you replace your phone, sign in again: with "Plan with my health info" on, your answers, plans and shopping list come back; without it, your settings and consent choices come back and you answer the health questions again.

No system is completely secure, so we can't promise that nothing will ever go wrong.

If something goes wrong

If a security incident affects your data, we'll investigate quickly, contain it, and tell the people and regulators the law says we must. In practice that means telling regulators in the EU and UK within 72 hours where the law asks for it, following the US Federal Trade Commission's Health Breach Notification Rule (no more than 60 days) and state laws, and telling Quebec's Commission d'accès à l'information and affected people where there's a risk of serious injury. We'll tell you using the email on your account or a message in the app, and we'll say what happened, what data was involved and what you can do.

Changes to this policy

When we change this policy, we'll update the date and version at the top. If a change affects how we use your health information, we'll ask for your consent again in the app before we apply it.

Contact us

Nodogames, LLC
[LEGAL ADDRESS OF NODOGAMES, LLC]
Privacy officer: [PRIVACY OFFICER NAME]
Email: support@a1cmealprep.com