Privacy Policy
Chowdy is a meal planning app for iPhone operated by Froth Labs LLC (“we”, “our”, or “us”). This policy explains exactly what the app collects, where each piece of it goes, and what you can do about it.
1. Summary
This table is the same disclosure that appears on the App Store listing. The sections below explain each row.
| Category | What it is | Linked to you |
|---|---|---|
| Contact info | Name, email address | Yes |
| Health | Health conditions you choose to tell Chef about | Yes |
| Coarse location | An optional ZIP or postal code you type in | Yes |
| Purchases | Subscription and purchase history | Yes |
| Photos | Recipe, receipt, and pantry photos you take or choose | Yes |
| Other user content | Meal plans, recipes, pantry, grocery lists, preferences, and your conversations with Chef | Yes |
| Identifiers | Your account ID, and a notification token per device | Yes |
| Diagnostics | Crash reports and performance traces | No |
None of it is used to track you. Chowdy contains no advertising, attribution, or product-analytics SDK, never requests the iOS advertising identifier (IDFA), shows no ads, and shares nothing with data brokers. See section 7.
2. What we collect
Account information
When you sign in with Apple or Google, we receive your name and email address from that provider and store them on your profile. We never see or store a password. If you use Apple’s Hide My Email, what we store is Apple’s private relay address, not your real one. We do not collect phone numbers.
Meal planning and recipe content
- Meal plans and the individual meal slots in them, including ones you skip.
- Recipes you save, fork, import, create, or rate, plus your notes and personal tags.
- Pantry items and grocery lists.
- Preferences: meals per day, cooking skill, cooking rhythm, plan length, dietary restrictions, disliked ingredients, weekly grocery budget, shopping style, preferred store, and time zone.
- Your calorie target and macro split, if you set one.
- Your conversations with Chef, the in-app assistant — the messages you send, its replies, and a running summary of the thread.
If you use the calorie calculator, the age, biological sex, height, weight, activity level, and goal you enter are used to run the calculation on your device only. Those figures are never transmitted or stored — only the calorie target the calculator produces is saved to your profile.
Health conditions
If you tell Chef about a health condition — a medical restriction, an allergy, something you are managing through diet — it is stored on your profile so plans and suggestions can account for it, and it is included in the context sent to our AI provider when Chef answers you. This is the most sensitive thing the app holds. You can view, edit, or clear it at any time from the Profile tab, and deleting your account removes it.
Health conditions are optional, and we hold them only because you chose to enter them. We use them for one purpose — tailoring your own plans and Chef’s answers to you. We do not sell them, share them for advertising, use them to build a profile of you for anyone else, or use them to make decisions about you outside the app. Clearing the field withdraws that permission; nothing else in the app stops working.
Photos
Chowdy uses your camera and photo library in three places, all optional:
- Importing a recipe from a photo. The images you pick (up to three) are downscaled on your device and sent to our servers so an AI model can read the recipe out of them.
- Adding a photo to a recipe. The image is compressed and uploaded to our storage provider, and the resulting URL is saved on that recipe.
- Scanning a receipt or a photo of your pantry. A Pro feature: the images you pick (up to three) are downscaled on your device and sent to our servers so an AI model can read the items out of them. The photos themselves are never stored — only the item names, quantities, and units the model reads are saved, as pantry entries you review and confirm before anything is written.
Recipe photos are private. They are not publicly accessible, and only your account can add, view, or remove them. To show you a photo, the app requests a temporary link — only your account can request one for your photos, and each link expires after about an hour. The app has no feed, no public profiles, and no way to browse anyone else’s photos.
Location
Chowdy never asks for location permission and cannot read your device’s location. It has no GPS access at all. What it does collect is an optional ZIP or postal code you type in yourself, used to find grocery stores near you. You can leave it blank, and you can remove it later.
Subscription
Subscriptions are purchased through Apple’s App Store. Our subscription provider records your purchase and renewal status against your Chowdy account ID so the app knows what you have access to. We never receive or store card numbers or any other payment instrument — Apple handles the transaction end to end.
Notifications
If you allow notifications, the app stores a push notification token on your profile. That token identifies a specific device, so it counts as a device identifier. It is used only to send you meal and plan reminders — never for advertising — and it is cleared when you sign out.
Diagnostics
We collect crash reports and performance traces to keep the app stable. This data is not linked to your identity — we do not attach your user ID, email, or any other account information to it.
What stays on your device
Your sign-in tokens are held in the iOS Keychain, and cached plan and recipe data (so the app works offline) is stored locally. Neither is transmitted to us.
What we never collect
- Device location, precise or coarse, from the operating system.
- Contacts, calendars, HealthKit data, microphone, or motion data.
- Payment card or bank details.
- The advertising identifier (IDFA).
- Your browsing or search activity in other apps or on the web.
3. How we use it
- To run the app: build and store your plans, lists, and recipes.
- To personalize suggestions — Chef adapts to what you actually cook, skip, and rate over time.
- To build a grocery cart at a connected retailer, when you ask it to.
- To manage your subscription entitlement.
- To send notifications you have opted into.
- To diagnose crashes and fix performance problems.
We do not sell your personal information, we do not share it with advertisers, and we do not use it to build advertising profiles.
4. Who we share it with
We use the following service providers. Each is contractually restricted to processing your data on our behalf, for the purpose listed.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage | Your account and all meal planning content, including photos |
| Amazon Web Services | Application servers and Amazon Bedrock, which runs the AI models behind Chef | Your messages to Chef, your plan context and preferences (including health conditions), and photos from recipe import and pantry scanning |
| Sentry | Crash and performance monitoring | Crash reports and performance traces, with no account identity |
| RevenueCat | Subscription management | Your account ID and purchase history |
| Kroger | Optional grocery integration — only if you connect a Kroger account | Product search terms from your grocery list, a store location, and the items you add to your cart |
| Apple, Google | Sign-in; Apple also handles all payments | Your name and email address, from the provider you choose |
We may also disclose information if required by law, or to protect the rights, safety, or property of our users or ourselves.
5. AI processing
Chef is powered by a third-party large language model that we access through Amazon Bedrock, a service of Amazon Web Services. Amazon processes your data on our behalf and under our instructions, and does not share it with the model’s developer. When you send Chef a message, what leaves your device is that message, a summary of the conversation so far, and the parts of your profile relevant to the request — your preferences, dietary restrictions, and your health conditions. Recipe photos you import are sent the same way, for the model to read.
Your data is not used to train AI models. Amazon Bedrock does not use customer inputs or outputs for model training, and neither do we.
Chef’s suggestions can be wrong. Please check ingredients against your own allergies and restrictions before you cook or buy — see our Terms of Service for the full disclaimer.
6. Retention and deletion
- We keep your account and meal planning data for as long as your account exists.
- Internal audit logs of changes are kept for 90 days, then deleted.
- When you delete your account, your personal data is removed from our live systems immediately and from routine backups within 30 days, except where we are required to keep something by law.
- Crash reports held by our diagnostics provider carry no account identity and expire on that provider’s standard retention schedule.
7. Tracking and advertising
Chowdy does not track you. Specifically, and as of the version described by this policy:
- There is no advertising SDK, no attribution SDK, and no third-party product-analytics SDK in the app.
- The app never requests the iOS advertising identifier and shows no App Tracking Transparency prompt, because it has nothing to ask for.
- Crash and performance monitoring is diagnostics, not cross-app tracking, and carries no account identity.
- We have no data-broker relationships. Data sent to a grocery retailer goes there because you asked for a cart, and for no other reason.
8. Your rights and choices
- Delete your account. Profile tab → Delete Account. This removes your account and personal data from our systems; it does not cancel an App Store subscription, which you manage in your Apple Account settings.
- Export your data. Profile tab → Export my recipes gives you your saved recipes and meal plans, including your notes and ratings, as a text file. For a copy of everything else we hold about you — your profile, grocery lists, store preferences, and your Chef conversations and learned preferences — email us and we will send it to you. This does not include your Apple or Kroger sign-in credentials (returning a live login token would be unsafe) or internal rate-limit counters.
- Correct or remove specific information. Preferences, dietary restrictions, health conditions, ZIP code, and photos can all be edited or cleared in the app at any time.
- Turn things off. Notifications, the grocery integration, and the optional ZIP code are all opt-in, and can be revoked without losing the rest of the app.
Depending on where you live, you may have additional rights over your personal data — including access, correction, deletion, portability, and the right to object to or restrict processing. Email us at privacy@eatchowdy.com. We will confirm it is you, respond within 30 days, and never charge for a request or treat you differently for making one.
United States state privacy laws
If you live in California or another state with a consumer privacy law: we do not sell your personal information, we do not share it for cross-context behavioral advertising, and we have not done either in the past twelve months. Health conditions are “sensitive personal information” under those laws. We use them only to provide the service you asked for, which is why there is no separate “limit the use of my sensitive information” control — there is no secondary use to limit. The categories we collect, why, and who receives them are set out in sections 1 to 4. You may use an authorized agent to make a request, and you may appeal a decision by replying to our response.
In states with consumer health data laws, such as Washington and Nevada, the health conditions, dietary restrictions, and nutrition targets you enter are consumer health data. Everything this policy says about them applies: we collect them only from you and with your consent, use them only to run the app for you, disclose them only to the service providers in section 4 that process them on our behalf, and delete them when you clear the field or delete your account.
Europe and the United Kingdom
Froth Labs LLC is the controller of your data. We process account and meal planning data because it is necessary to provide the service you signed up for; we process health conditions on the basis of your explicit consent, which you give by entering them and withdraw by clearing them; and we process crash diagnostics on the basis of our legitimate interest in keeping the app working. You also have the right to complain to your local data protection authority.
9. Where your data is processed
Chowdy is operated from the United States, and your data is stored and processed there, including by the service providers in section 4. If you use the app from another country, your data is transferred to the United States, whose privacy laws may differ from those where you live. Where the law requires a transfer mechanism, we rely on the data protection terms those providers offer, including standard contractual clauses.
10. Security
Data is encrypted in transit with TLS. Our database enforces row-level security, so one account cannot read another’s rows, and API access requires a signed token tied to your session. Sign-in tokens are stored in the iOS Keychain. No system is perfectly secure and we cannot guarantee absolute security, but these are the measures in place.
11. Children
Chowdy is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
12. Changes to this policy
We will update this page when what we collect changes, and update the “Last updated” date above. If a change is material we will say so in the app. Continuing to use Chowdy after a change takes effect means you accept the updated policy.
13. Contact
Froth Labs LLC
privacy@eatchowdy.com
eatchowdy.com
© 2026 Froth Labs LLC. All rights reserved.
