Privacy Policy

The short version: we collect what we need to make OrderFit work, we never sell your data, and you're always in control.

Last updated: April 26, 2026

The TL;DR

• We collect your account info, dietary preferences, meal history, and (only if you let us) your location.

• We use it to personalize your meal recommendations and make the app work — nothing more.

• Your meal queries go to AI providers (OpenAI / Google) to generate suggestions, then come back to you.

• We never sell your data, and you can delete everything from inside the app at any time.

What we collect (and why)

We only collect what we need to make OrderFit work for you. Nothing more.

Your account

Email and name (and optionally an avatar) so you can sign in and sync your preferences across devices. If you sign in with Apple, we get the email Apple gives us — which may be a private relay address if you choose.

Your profile

Dietary preferences (halal, gluten-free, vegan, etc.), fitness goals (cutting, bulking, maintaining, GLP-1), allergies, height, weight, age, and activity level. This is what makes recommendations actually personalized.

Your meal history

Every meal we generate for you is saved so you can re-find favorites and so we can avoid repeating suggestions. You can delete individual meals or your full history at any time.

Your location (only if you allow it)

If you grant location permission, we use your coordinates to find nearby restaurants. We don't store your precise location history — we use it in real time to surface restaurants and discard it after the request.

Munch chat history

When you chat with Munch, our AI food guide, we store your messages so the conversation stays coherent. Chats are deleted on close for privacy unless you explicitly save them.

Subscription status

If you subscribe, we record your subscription state (active / trial / canceled) so we know what to show you. The actual payment is handled entirely by Apple — we never see your card.

Device & usage info

iOS version, device model, app version, language, and basic event analytics (screens viewed, features used) — to fix bugs and understand what works. No browser fingerprinting, no creepy stuff.

Push notification token

If you enable push notifications, Apple gives us a token so we can send you smart reminders (like a nearby healthy meal at lunchtime). You can turn this off in iPhone Settings any time.

App Tracking Transparency (ATT)

If you say yes when we ask permission to track, we send anonymous attribution data to our marketing partners so we know which ad campaigns work. If you say no, we don't track. Either way, the app works the same.

How we use it

Exactly what you'd expect — make OrderFit work. Specifically:

  • Generate meal recommendations that match your goals and dietary needs
  • Show you nearby restaurants based on your location
  • Sync your preferences and meal history across devices
  • Improve the app, fix bugs, and understand what users find useful
  • Send relevant push notifications (if you've opted in)
  • Manage your subscription
  • Respond to support requests

We will never sell your data, share it for unrelated marketing, or use it to train third-party AI models on your personal information.

How AI processing works

OrderFit uses AI to generate personalized meal recommendations. When you ask the app for a meal:

  • Your dietary preferences, goals, and the restaurant menu are sent to our AI providers (currently OpenAI and Google Gemini) as anonymous queries — no name or email attached.
  • The AI generates a suggested meal with estimated macros and calories.
  • The result comes back to your device.

OpenAI and Google process these requests under their own terms (with our enterprise data agreements that prevent them from training models on our queries). We don't send them anything you wouldn't want a stranger to see — no email, no name, no ID.

Where your data lives

Your data is stored on Supabase (an enterprise-grade database provider) with encryption at rest and in transit. Servers are in the United States. We use industry-standard security (HTTPS, encrypted databases, hashed passwords, scoped access tokens stored in iOS Keychain).

Third-party services we use

These are the only outside services that touch your data:

Apple

Sign-In, App Store, push notifications

Supabase

Database & authentication

Adapty

Subscription management

OpenAI

AI meal generation

Google Gemini

AI meal generation (backup)

Singular

Marketing attribution (only if you allow tracking)

Each of these has its own privacy policy. We've reviewed them and we use the most privacy-respecting plans available.

Your rights — you're in control

You can always:

  • See your data — everything we have about you is visible in the app under Profile → Settings.
  • Export your data — request a copy of all your data by emailing us. We'll send it within 30 days.
  • Delete your data — Profile → Settings → Delete Account. This permanently removes everything: your account, profile, meal history, chat logs, all of it. There's no recovery.
  • Turn off tracking — iPhone Settings → Privacy & Security → Tracking → toggle OrderFit off.
  • Turn off location — iPhone Settings → Privacy & Security → Location Services → OrderFit.
  • Turn off notifications — iPhone Settings → Notifications → OrderFit.

If you're in the EU/EEA or UK (GDPR)

You have additional rights under the GDPR: the right to access, rectify, erase, restrict processing, object to processing, and data portability. To exercise any of these, email us. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

If you're in California (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete it, and the right to opt out of any "sale" of personal information. We don't sell personal information, but if you'd like a formal disclosure, email us.

Children's privacy

OrderFit is rated 4+ on the App Store but it's intended for users 13 and older. We don't knowingly collect personal information from children under 13. If you're a parent and you believe your child has signed up, email us and we'll delete the account immediately.

Data retention

  • Active account data: kept while your account is active.
  • Account data after deletion request: removed within 30 days (longer only if required by law).
  • Server logs: retained for 30 days for debugging, then deleted.
  • Anonymized analytics: kept for up to 24 months for product analysis.

Security

We take security seriously. All connections use HTTPS, all stored data is encrypted at rest, authentication tokens live in the iOS Keychain (encrypted by the operating system), and we limit internal access to data on a need-to-know basis. Despite our best efforts, no system is 100% secure — if you ever notice anything suspicious, please email us.

Changes to this policy

If we update this policy in any meaningful way, we'll let you know in the app or via email. Continuing to use OrderFit after a change means you accept the updated policy. The "Last updated" date at the top will always reflect the most recent change.

Contact us

Questions, concerns, or requests about your data? Email us at support@orderfit.app. We answer every message — usually within a couple of days.