Privacy Policy

Last updated: October 6, 2026

MenuIQ, LLC — A Delaware Limited Liability Company


Introduction

MenuIQ, LLC ("MenuIQ," "we," "us," or "our") operates a digital menu platform with AI-powered allergen identification and a consumer mobile application, MenuIQ AI. This Privacy Policy explains how we collect, use, share, and protect your information when you use the MenuIQ platform, website, mobile applications, and related services (collectively, the "Service").

MenuIQ is a digital menu and dining-discovery platform — not an ordering or delivery service. We do not fulfill food orders or track delivery logistics. We do process subscription payments (through Apple and Stripe, depending on platform), and the MenuIQ AI app collects health-related dietary information you choose to provide so it can personalize your results. This policy describes those practices in detail.

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

This policy covers three audiences, and not every section applies to you:

  • Restaurant Operators — businesses that create accounts to build and publish digital menus.

  • Menu Browsers — anyone who views a published restaurant menu on the web or by QR code.

  • MenuIQ AI App Users — people who use our consumer mobile app to discover restaurants, scan and translate menus, and get a Personal Fit Score.

1. Information We Collect

1.1 Restaurant Operator Information (Account Holders)

When you create a Restaurant Operator account, we collect:

Account Information: Email address, password (stored as a bcrypt hash — we never store passwords in plain text), and restaurant name and contact details.

Menu Content: Menu item names, descriptions, ingredients, pricing, and images you upload, including Allergen Information (both AI-generated suggestions and your manual edits).

Subscription and Billing: Web subscriptions are processed by Stripe. We receive transaction confirmations, subscription status, and billing history. We never receive or store your full credit card number, CVV, or banking credentials.

Usage Data: Login timestamps, features used, menu edits, AI scan requests, and account activity.

Communications: Any messages you send to our support team.

1.2 Website Visitors (menuiq.ai, including restaurant pages and maps)

You can browse our website without an account. When you do, our servers and our network provider (Cloudflare) receive standard technical information: IP address, device and browser type, pages viewed, and referring page, used to run and secure the site. Cloudflare Web Analytics also measures page views and page performance for us; it uses no cookies. Cloudflare tells us the approximate area of your IP address, which we use to center the map and load restaurants for the area shown; we don't keep it on our servers.

Stored on your device: the website keeps some things in your browser's storage so they work next time, such as your display theme and language, the restaurant pages you viewed recently, the menus you've opened for free and when (to count your free menus), any dietary presets you save, the approximate map location, a cache of nearby restaurants, and your share-card settings. These stay in your browser, and you can clear them in your browser settings. The dietary and allergy preferences you pick on restaurant pages and maps are used in your browser to filter what you see and are not sent to us.

We don't collect your name or email on the website unless you sign in or contact us.

1.3 MenuIQ AI App Information

The MenuIQ AI mobile app is live. You can use core features as a guest; some data below is collected only if you create an account, and certain items are not linked to your identity in guest mode. Depending on the features you use, we collect:

Account & Identifiers: If you sign in, your email and display name/handle via Apple Sign-In or Google Sign-In, plus internal identifiers (a user ID, your sign-in provider ID, a hashed email, and any referral code).

Health & Dietary Profile (Sensitive — see Section 1.4): The allergens, dietary preferences, wellness goals, pregnancy mode status, and related health conditions or cross-contamination sensitivities you choose to provide. We use this to generate your Personal Fit Score and to flag items to avoid. This information is stored on our servers, linked to your account, and used as context when we analyze menus (see Section 3).

Menu Scans & Content: Photos, PDFs, or links of menus you submit; the dishes and details we extract from them; your saved/"hearted" items; and menus you share.

Profile Photo (optional): If you add a profile photo, we screen it for inappropriate content using Google Cloud Vision before storing it.

Personal Fit Score: A computer-generated estimate, produced by our automated models, of how well a restaurant or dish aligns with your profile (see Sections 3 and 4).

Location: With your permission: precise location used on your device to show the map and nearby results; scan-time coordinates (approximately 11 meters) sent to our servers to identify the restaurant you're at; and coarse profile location (approximately 1 km) for features such as showing people near you. We send an approximate location only to the services that help us find restaurants (see Section 3), never for advertising. You can decline location access; some discovery features will be limited.

Contacts (optional): If you choose to find friends, email addresses from your address book are hashed (SHA-256) on your device before transmission and used only to match existing MenuIQ users. We do not store your raw contacts.

Purchases: Subscription tier and status. On iOS, subscriptions are processed through Apple In-App Purchase and managed via RevenueCat; on the web, through Stripe.

Usage & Diagnostics: Scan counts and interaction counts; and crash/error diagnostics (with authentication details stripped) via Sentry in production.

1.4 Sensitive Health Information — How We Handle It

The allergen, dietary, pregnancy, and health-condition data you provide in the MenuIQ AI app is sensitive personal information (health-related data) under the CCPA/CPRA, GDPR, and most state privacy laws. We handle it with enhanced protections:

  • We ask for your consent in the app before we use this information, and you can withdraw it at any time in Settings → Privacy. If you don't agree, you can still scan and translate menus without personalization.

  • We collect only what you choose to provide, and use it solely to personalize your results — generating your Personal Fit Score, flagging items to avoid (including in pregnancy mode), and tailoring menu analysis.

  • To analyze a menu against your needs, the relevant dietary context is sent together with the menu to our AI provider, Google (Gemini API), for processing (see Section 3).

  • This data is stored on our servers and linked to your account so your profile and Fit Scores persist across devices and sessions.

  • We never sell this data, never share it for advertising or cross-context behavioral advertising, and never use it for marketing.

  • You can view, edit, or delete your health and dietary profile at any time in the app, or by emailing [email protected]. See Section 7.

1.5 Content You Make Public

If you make a list public, share a menu, follow people, or fill in your profile, what you choose to make public — your display name, handle, profile photo, profile badges, list titles and notes, recommended dishes, and the restaurants you include — can be seen by anyone who views it, including people without a MenuIQ account. We ask search engines not to index profiles and lists. The allergen, dietary, and pregnancy settings you use for your own scans and fit are private and are never shown to anyone else. Profile badges are separate: they appear only if you choose to show them on your profile, and they can reveal health information — for example an allergy, celiac, or pregnancy — so add only what you're comfortable sharing. Lists are private unless you choose to make them public. You can remove badges, make a list private or delete it, or delete your profile at any time; copies others have already seen or saved may remain.

1.6 Information About Restaurants

To build restaurant pages, we collect information that restaurants publish — menus, websites, and allergen information — and basic place details such as name, address, and cuisine. This is business information, though it can include names that appear on a public menu. If you contact us, through our Contact page or by email, to ask about MenuIQ for Restaurants or to correct or remove a restaurant page, we keep your message and contact details to answer you and handle the request. If a MenuIQ user invites a restaurant to join, we use the restaurant's email address to send that invitation. We keep a record of it so we don't email the same address more than once every 30 days. If the restaurant unsubscribes, we keep its address on a do-not-email list so we never email it again.

2. How We Use Your Information

2.1 Service Delivery. To operate the Service: menu management and publishing for Operators; menu browsing; and, in the app, restaurant discovery, the Personal Fit Score, menu scanning, translation, pregnancy-mode flagging, saving/sharing, and social features (following others, recommendations).

2.2 AI Menu Analysis & Personalization. We use AI to (a) identify potential allergens and dietary attributes in menu text and images, and (b) generate your Personal Fit Score by comparing menu data against your dietary/health profile. See Section 4.

2.3 Translation. In the app, we use AI to translate menus and describe dishes.

2.4 Analytics and Improvement. In the MenuIQ AI app we record a small set of product events (for example, that a scan started or finished, or that a purchase completed) to understand how the app is used and to improve features, performance, and reliability (see Mixpanel in Section 3). These events are linked to an internal account number or a random device ID, never to your name or email. We do not use them for advertising or to build advertising profiles.

2.5 Communications. Transactional messages (account verification, password resets, subscription confirmations, material changes to our Terms or this policy). We do not send marketing emails without your opt-in consent. If you invite a restaurant to MenuIQ, we email them on your behalf without including your name or email.

2.6 Safety, Security, and Legal Compliance. To protect the Service and users, prevent fraud and abuse, comply with law, and enforce our Terms.

3. How We Share Your Information

We do not sell your personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising. We share information only with service providers who process data on our behalf under contractual restrictions, and as described below.

Google LLC — Gemini API (AI Processing). Menu text and images you submit, together with the dietary context needed to analyze them, are sent to Google's Gemini models for real-time analysis (allergen/dietary identification, Fit Score inputs, translation, dish descriptions). Google processes this data as our service provider, under Google's paid API terms, solely to provide the analysis. Under those terms, Google does not use the data we send to train its models.

OpenRouter, Inc. (AI Routing). Our requests to Google's models pass through OpenRouter, which routes each request to Google's own servers and returns the result. OpenRouter acts as our service provider. Our account is set so that requests go only to providers that do not store or train on the data they receive, and only to Google. See OpenRouter's Privacy Policy.

Google LLC — Cloud Vision API (Image Moderation). If you upload a profile photo, it is screened by Google's Cloud Vision API for inappropriate content before it is stored. Google processes the image as our service provider for this purpose only; we use this to keep the community safe, not to identify you.

Payment & subscription sub-processors. When you purchase a subscription, we share what is needed to process and manage it. We never receive or store your full payment card number — card data is handled directly by the processor.

  • Stripe, Inc. (web payments) — processes your name, email, billing address, the last four digits and card type of your payment method, and your IP address for fraud prevention. See Stripe's Privacy Policy.

  • Apple Inc. (iOS in-app purchases) — Apple processes your payment under its own terms; we receive only a transaction identifier and subscription status, never your payment details. See https://www.apple.com/legal/privacy/.

  • RevenueCat, Inc. (subscription management) — validates App Store receipts and manages your subscription entitlement; receives purchase/receipt data, an app-specific user identifier, and device/platform information. See https://www.revenuecat.com/privacy/.

Apple / Google (Sign-In). If you choose to sign in, your provider authenticates you and shares basic profile data (email, name) with us.

Railway (Cloud Hosting) and Cloudflare (Network & Content Delivery). Account and application data, including profile photos, is hosted on Railway. Menu photos and PDFs you upload for a scan are held on our servers only while the scan runs, then deleted. Cloudflare carries traffic to our website and app, delivers their content, and, through Cloudflare Web Analytics (which uses no cookies), measures page views and performance on our website.

Mixpanel, Inc. (Product Analytics). The MenuIQ AI app (not our website) sends Mixpanel a limited set of product events: app opens, onboarding completed, restaurants opened, scans started, completed, or failed (scan type, a rough count of dishes found, and a failure category), paywall views, purchases and restores (the plan and billing period), recommendations added, and menus shared (how they were shared). Each event carries the platform, app version, and your plan. Events are linked to an internal account number when you are signed in, or a random device ID when you are not. Mixpanel also receives standard technical request information, including the raw browser user-agent. We never send Mixpanel your allergen, dietary, or pregnancy selections, menu or dish content, which restaurants you view, your location, your email, handle, or contacts, or anything you type. Mixpanel is set to use no cookies, no IP-based location, and no session recording. Mixpanel keeps this data for up to 5 years; to have yours deleted sooner, email [email protected]. See Mixpanel's Privacy Policy.

Resend (email delivery). Sends our account and service emails — for example sign-in and password emails, receipts, and invitations you ask us to send. Resend receives the recipient's email address and the email's content.

Google Places, OpenStreetMap, and Photon (finding restaurants). We use Google's Places service and OpenStreetMap-based services (the Overpass API and the Photon search service run by komoot) to find restaurants and their basic details. When you search for a place or scan a menu, your search words and an approximate location may be sent to these services so they can return nearby restaurants.

Google Fonts (share cards). When you make a share card, your browser loads its fonts from Google, which receives your IP address and browser information when it does.

OpenFreeMap (maps). When you view a map, your browser requests map images from our map provider, which receives your IP address and the area you're viewing.

Sentry (Diagnostics). Crash and error diagnostics in production, configured not to send personal information and with authentication details stripped.

We may also disclose information if required by law or valid legal process; to protect our rights, users' safety, or the public; or in connection with a merger, acquisition, or sale of assets (in which case your information remains subject to this policy or a successor policy at least as protective).

4. Artificial Intelligence and Automated Decision-Making (ADMT)

4.1 Two AI Functions

(a) Menu & allergen analysis. We analyze menu text and images to identify potential allergens and dietary attributes. For Operators, this produces suggestions you review and edit before publishing. In the app, it powers scanning and translation.

(b) Personal Fit Score. We use automated models to generate a score estimating how well a restaurant or dish aligns with the dietary preferences and restrictions in your profile. This is automated processing/profiling of your personal information, including sensitive health-related data.

4.2 AI Limitations

AI output — including allergen identification and the Personal Fit Score — is advisory only and may be inaccurate, incomplete, or outdated. It can miss allergens, mis-flag allergens, and cannot account for cross-contamination, hidden ingredients, recipe changes, or day-to-day kitchen variation. It is a starting point, not a verified determination and not medical, nutritional, dietary, or allergen-safety advice. Always confirm directly with the restaurant before ordering, especially for allergies, intolerances, medical dietary needs, or pregnancy. See our Terms of Service.

4.3 AI Training

We do not sell your data to train third-party models, and we do not use your health/dietary profile to train models. Google processes the menu content and context we send under its paid API terms, which do not allow Google to use that data to train its models, and our AI routing provider is set to use only providers that do not store or train on it (see Section 3). We may use de-identified, aggregated patterns to improve our own Service.

4.4 ADMT Disclosure (CCPA/CPRA and similar laws)

  • Business purpose: To identify potential allergens/dietary attributes in menus, and to generate a Personal Fit Score that helps you discover restaurants and dishes that may fit your dietary needs.

  • Data processed: Menu names, descriptions, ingredients, and images; and, for the Fit Score, the allergen/dietary/pregnancy/wellness profile you provide.

  • Logic: Automated pattern-matching and scoring of menu data against your stated profile and against known allergen/ingredient profiles.

  • Output: Allergen/dietary tags and a Personal Fit Score — estimates and suggestions, not guarantees or verified facts, and not decisions that produce legal or similarly significant effects about you.

  • Your choices and rights: Providing a profile is optional; you can edit or delete it at any time, and you can use the app without a Fit Score. You may request human review of, or more information about, an automated result by emailing [email protected]. Where required, we obtain your consent before processing sensitive data for personalization, and you may withdraw it. We honor applicable opt-out/limitation rights for automated decision-making and sensitive data (see Section 7).

5. Data Retention

Data Type

Retention Period

Reason

Restaurant Operator account data

Duration of account + 30 days after deletion request

Service delivery and account recovery

Menu content and Allergen Information

Duration of active subscription; deleted when subscription ends

Service delivery

App account & profile (incl. dietary/health profile)

Until you delete it or close your account

Personalization; user-controlled

Menu scans, extracted items, AI results & Fit Score history

Scanned dishes and AI results: deleted 30 days after the scan. The scan record (including its Fit Score): deleted 32 days after the scan. Uploaded menu photos and PDFs: deleted when the scan finishes.

Service delivery; history

Hashed contacts (find-friends)

Not retained after matching

Privacy-forward; matching only

Payment/transaction records (Stripe / Apple via RevenueCat)

7 years

Tax and legal compliance

App usage analytics (Mixpanel)

Up to 5 years; deleted sooner on request

Service improvement

Precise location (scan-time)

Stored with the scan record and deleted with it, 32 days after the scan

Restaurant identification; re-checking a scanned menu

Diagnostics (Sentry)

Kept for the retention period set in our diagnostics service, then deleted automatically

Stability and debugging

IP addresses

Kept in server and security logs only as long as our hosting and network providers keep those logs, then deleted

Security and fraud prevention

Support communications

2 years

Issue resolution

Restaurant invitation records

Unclaimed invitations: 30 days after they're sent, to limit invitations to one per address every 30 days. Accepted invitations: indefinitely

Sending the invitation; limiting repeat emails

Unsubscribed email addresses (do-not-email list)

Indefinitely

So we never email that address again

When data is deleted, it is removed from active systems within 30 days; backups may persist up to 90 days before automatic deletion.

6. Data Security

We use industry-standard technical and organizational measures: TLS 1.2+ in transit; bcrypt password hashing with salt; on-device SHA-256 hashing of contacts before transmission; and access controls that limit who can reach personal data. No system is perfectly secure, and we cannot guarantee absolute security; you are responsible for safeguarding your account credentials.

7. Your Privacy Rights

7.1 All Users

You may access, correct, delete, and (for Operators) port your personal information. In the MenuIQ AI app, you can view, edit, and delete your dietary/health profile directly in Settings. To exercise rights, email [email protected] with "Privacy Rights Request" in the subject line. We respond within 30 days (45 for complex requests, with notice).

7.2 California Residents (CCPA/CPRA)

You have the rights to Know, Delete, Correct, Opt-Out of Sale/Sharing (we do neither), Limit Use of Sensitive Personal Information, and Non-Discrimination. Because we process your dietary/health profile on our servers to provide personalization, your right to limit the use of sensitive personal information is honored through an actual control: you may delete your profile or contact us to limit its use to providing the core Service (you may lose personalization, such as the Fit Score).

Categories of personal information collected in the past 12 months:

Category

Collected

Business Purpose

Identifiers (email, name, device/user IDs)

Yes

Accounts, app functionality

Commercial information (subscription, billing)

Yes

Subscription management

Internet/app activity (browsing, usage)

Yes

Service improvement

Geolocation (precise + coarse, app)

Yes — with permission

Restaurant identification; nearby features

Professional information (restaurant details)

Yes — Operators

Service delivery

Sensitive personal information (allergen/dietary/pregnancy/health data; precise geolocation)

Yes — app users who provide it

Personalized results and Fit Score

User content (menu photos/scans, profile photo, shared items)

Yes — app users

Scanning, analysis, content moderation

Inferences (your Personal Fit Scores and the dishes flagged for you)

Yes — app users who add a profile

Personalized results

We have not sold or shared personal information for cross-context behavioral advertising, and do not intend to.

We do not sell or share the personal information of consumers under 16. We verify requests by confirming you control the email address on your account. You may use an authorized agent; we may ask for your signed permission and ask you to verify your identity with us directly.

7.3 Other U.S. States (including Virginia, Colorado, Connecticut, Oregon, and Texas)

You have rights to access, correct, delete, and get a copy of your personal data, and to opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects (we do none of these). We process sensitive data — including allergen, dietary, pregnancy, and health information and precise location — only with your consent, which you can withdraw at any time in Settings. To exercise these rights, email [email protected]. If we decline your request, you can appeal by replying to our decision or emailing [email protected] with "Appeal" in the subject. We'll respond within the time your state's law requires, and if you disagree with the result, we'll tell you how to contact your state Attorney General.

7.4 European Residents (GDPR/UK GDPR)

Lawful bases: contract (providing the Service), legitimate interests (analytics, security — balanced against your rights), and consent (marketing; non-essential cookies; and your explicit consent, given in the app before you add it, for health-related dietary and pregnancy information under Article 9). You have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, the right to lodge a complaint with your supervisory authority, and the right to human review of automated decisions (Article 22) — relevant to the Personal Fit Score. Your information is processed in the United States. Where required, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses.

7.5 Washington and Nevada Consumer Health Data

The allergen, dietary, pregnancy, and health-condition information you provide is "consumer health data" under the Washington My Health My Data Act and Nevada law. We collect and share it only with your consent, use it only to provide the features you request, and never sell it. You may withdraw consent and request deletion at any time in Settings or at [email protected]. See our Consumer Health Data Privacy Policy for the full disclosure.

8. Cookie Policy

Essential cookies (your sign-in session) are always active. The cookies we set are: "menuiq_session" (keeps you signed in) and "miq_si" (a marker with no personal information that tells our website you're signed in on this browser, so it can link you to the app). We also use your browser's local storage to remember settings on your device, as described in Section 1.2. You can clear it in your browser settings. We do not currently use analytics or marketing/advertising cookies (the app's product analytics, described in Section 3, use no cookies). If we add them, we will update this policy first; analytics cookies will be opt-in for EU/EEA users and opt-out for US users, managed through a consent banner and a "Cookie Settings" link, and for EU/EEA users no non-essential cookies will be set before consent, with "Accept All" and "Reject Non-Essential" equally prominent. You can also manage cookies in your browser.

9. We Don't Sell or Share Your Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. If that ever changes, we will update this policy first and give you a simple way to opt out, including by honoring Global Privacy Control signals.

10. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If we learn we have, we will delete it promptly. Contact [email protected] with concerns.

11. Changes to This Privacy Policy

We may update this policy. For material changes, we will provide notice by email (to Operators) or a prominent in-Service notice at least 30 days before the changes take effect, and update the "Last updated" date. Continued use after the effective date constitutes acceptance. We review this policy at least every 12 months, as the CCPA requires. If a change would let us use your health information in a new way, we'll ask for your consent first.

12. Contact Us

Email: [email protected] ("Privacy Rights Request" in the subject for data requests) Mail: MenuIQ, LLC, 367 St Marks Ave #1116, Brooklyn, NY 11238 Response time: within 30 days (45 for complex requests, with notice).