Fuelist: AI Meal Planner · iOS
Privacy Policy
Last updated: August 26, 2026 · Operated by AlyraLabs LLC · Available in the United States
The short version
Fuelist collects what it needs to build your meal plans and run your account. We do not sell your personal information and we do not use it for advertising. You can delete your account from inside the app at any time.
This policy explains how Fuelist: AI Meal Planner (“Fuelist,” “we,” “us”), an iPhone app operated by AlyraLabs LLC, handles the information you share. It is written in plain language rather than dense legal terms.
A note on nutrition and health. Fuelist provides general nutrition and meal-planning information. Your goals, measurements and dietary details are sensitive, health-related information, but they are not medical records or clinical data. Fuelist is not a healthcare provider, and its plans, estimates and guidance are not a substitute for professional medical or dietary advice.
If you are a Washington or Nevada resident, see also our Consumer Health Data Privacy Policy, which describes additional rights you have over this information.
2. What Fuelist does
Fuelist creates personalized meal plans, recipes, nutrition estimates, shopping lists, pantry information, food-product information and cooking guidance. You create an account, complete onboarding, receive a generated plan, manage your recipes and shopping lists, can scan food barcodes, and can subscribe to Fuelist Pro.
3. What Fuelist collects
3.1 Account and contact information
- Email address
- Display name
- Your account ID (a UUID that identifies your account)
- Account and email-verification status
- Authentication session information
- Whether transactional emails, such as verification or password reset, were sent or delivered
Password sign-in is handled by Supabase. AlyraLabs never receives or stores your readable password.
3.2 Profile, wellness and nutrition information
Depending on what you choose to provide:
- Age and biological sex
- Height, current weight, target weight
- Activity level
- Weight, fitness, wellness and nutrition goals
- Calculated daily calorie and macronutrient targets
- Custom calorie, protein, carbohydrate and fat targets
- Dietary style and any custom diet description
- Food allergies and other dietary restrictions
- Foods you dislike and meals you reject
- Favorite cuisines
- Meal frequency, snack and dessert preferences
- Cooking-time and batch-cooking preferences
- Plan duration
- Grocery budget level and optional custom weekly budget
- Pantry staples and custom pantry items
You provide this voluntarily so Fuelist can personalize your plans. This is sensitive, health-related information and we treat it accordingly. Your age is used to calculate your targets and is stored only on your device; it is not sent to our servers.
3.3 Content you create or the app generates
- Meal plans, plan dates and durations
- Recipe names, meal types and scheduled days
- Recipe ingredients, amounts, units, instructions, servings, tags and preparation times
- Nutrition estimates — calories, protein, carbohydrates, fat, fiber
- Favorite recipes, rejected meals, and meals you create yourself
- Shopping-list items and their checked status
- Pantry items and scanned grocery products
- Generated price estimates and package guidance
- Generated dish and ingredient image descriptions
- Referral source and promo codes
- Streak and app-progress information
- Reminder preferences and times
3.4 What you tell the chef
Fuelist lets you describe how you like to eat in your own words, either in the chef chat or when requesting a single meal. Here is exactly what happens to that text:
- It is sent to our AI provider to fulfil the request.
- The conversation is saved on your device so that closing the sheet does not erase it. It is stored in your device's local app storage, is reset at the start of each new day, and is never sent to our servers or to another device. Deleting the app removes it.
- What the chef learns from it is saved to your profile and synced. Fuelist distils your conversation into short preference notes — the styles you like, meals you want included, and things to avoid — and these are stored with your account so future plans can follow them. You can view and clear them in the app.
We cannot promise our infrastructure providers retain nothing for any period; their own processing and retention terms apply.
3.5 Photos and camera
You can optionally choose or capture a profile photo. It is stored on your device and synchronized to a private storage bucket connected to your account.
You can also add or replace the photo on a meal, and attach a photo to a meal you create yourself. These images are stored in a separate private storage bucket connected to your account and are visible only to you. They are deleted when you delete the meal, and when you delete your account.
Camera access is also used to scan grocery-product barcodes. Fuelist does not use facial recognition and does not continuously record the camera. Camera frames are processed for scanning and are not saved. The resulting barcode number is sent to Open Food Facts to retrieve product information. You can decline camera access and still use the rest of the app.
3.6 Purchase and subscription information
Purchases are processed by Apple and managed through RevenueCat. Fuelist may process:
- Your RevenueCat App User ID, which is your Fuelist account UUID
- Apple transaction and receipt information
- Product and package identifiers, and whether you chose monthly or yearly
- Trial eligibility and status
- Purchase dates, subscription status, renewal status
- Cancellation, expiration and billing-issue events
- Refund information, price and currency
- Restore-purchase activity and promo access status
Apple processes the actual payment. AlyraLabs never receives your card or bank details. RevenueCat may send subscription lifecycle events to your PostHog profile so we can measure trials, purchases, renewals and cancellations.
3.7 Product analytics
Fuelist uses PostHog. The app sends a deliberately limited set of custom events: onboarding started, steps viewed and completed; account creation and authentication; plan generation started, completed or failed, with duration and requested length; paywall viewed and package selected; purchase started, completed, cancelled or failed; recipe opened; meal swapped; shopping mode started; shopping-list item checked.
PostHog is identified by your account UUID. Fuelist does not send PostHog your email address, name, food or recipe names, body measurements, onboarding answers, allergy details, or anything you typed to the chef. Session replay, screen capture, element-interaction capture, automatic lifecycle events, surveys and feature flags are all disabled.
PostHog and other technical providers may still process limited technical information such as IP address, approximate region inferred from it, device type, OS version, app version, timestamps and network metadata.
3.8 Notifications
Fuelist asks for notification permission only when needed. Reminders are scheduled locally on your device using Apple's notification system — Fuelist does not use a push-notification provider and no reminder content leaves your phone. Preferences are stored with your local profile settings.
3.9 Food and product lookup
Ingredient and nutrition queries are sent through our servers to USDA FoodData Central. Scanned barcodes are sent to Open Food Facts. Product names and purchase units are sent through our servers to OpenAI to generate package explanations and price ranges. Price estimates are calibrated against published average US retail prices from the U.S. Bureau of Labor Statistics; no information about you is sent there.
Common ingredient, food, image and product results are stored in shared caches so the same public information is not generated repeatedly. These entries contain food data, not your account information.
4. How you sign in
You can create an account with an email address and password, with Sign in with Apple, or with Sign in with Google.
With Apple or Google we receive only your email address and your name. We never receive your password, and we request no other data from those accounts — no contacts, calendar, files or fitness data.
If you use Apple's Hide My Email, Apple gives us a private relay address instead of your real one. Fuelist works normally with it.
You can revoke access at any time in your Google account permissions or in Settings → Apple ID → Sign in with Apple. Revoking access does not by itself delete your Fuelist account — use account deletion in the app for that.
5. Where your information lives
| Information | Where it is kept |
|---|---|
| Your profile, goals, measurements, restrictions and preferences | Your device, and synced to your account in the cloud |
| Your active meal plan, its meals, and its shopping list | Your device, and synced to your account in the cloud |
| Up to five recent plans | Your device only. Older plans are removed from our servers on each sync |
| Profile photo | Your device, and a private cloud bucket |
| Meal photos you add | Your device, and a private cloud bucket |
| Chef chat conversation | Your device only, reset each day |
| Preference notes distilled from the chef chat | Your device, and synced to your account |
| Scanned grocery products in your pantry | Your device only |
| Your age | Your device only |
| Notification preferences and scheduled reminders | Your device only |
| Appearance and unit preferences, AI usage counters, cached nutrition and images | Your device only |
7. Service providers
| Provider | What they do |
|---|---|
| Supabase | Authentication, database, private photo storage, cloud sync, server-side functions, account deletion, AI usage limits, security |
| OpenAI | Meal-plan and recipe generation, chef requests, meal and ingredient image generation, package explanations and price ranges. Information sent for planning may include age, biological sex, height, weight, goals, activity level, nutrition targets, diet preferences, allergies, restrictions, disliked foods, cooking preferences, plan length and budget |
| Apple | Sign in with Apple including Hide My Email, app distribution, TestFlight, in-app purchases, subscription billing, refunds and subscription management |
| Sign in with Google, via Google's official iOS SDK and its supporting libraries. Google provides only the name and email of the account you select | |
| RevenueCat | Subscription products and offerings, trial eligibility, purchasing and restoring, receipt validation, entitlement access, subscription analytics, and sending subscription events to PostHog |
| PostHog | Product analytics, onboarding and paywall measurement, subscription lifecycle analysis |
| Resend | Verification, password-reset, email-change and other transactional account emails |
| USDA FoodData Central | Ingredient and nutrition data lookup |
| Open Food Facts | Barcode, brand, product image and nutrition lookup |
| U.S. Bureau of Labor Statistics | Published national average retail food prices, used to calibrate cost estimates. No information about you is sent |
8. What Fuelist does not collect
- Precise GPS location
- Address-book contacts
- Microphone or audio recordings
- Apple HealthKit records
- Motion or fitness-sensor records
- Government identification numbers
- Payment-card or bank-account numbers
- Advertising identifiers for targeted advertising
- Biometric face templates
- Cross-app browsing history
Providers may still infer approximate location from IP addresses for security and analytics.
9. How information is used
- Create and manage your account, and help you recover it
- Personalize meal plans and recipes
- Calculate nutrition targets and estimates
- Respect your allergies and dietary restrictions
- Create shopping lists and pantry recommendations
- Provide food and barcode information, images and buying guidance
- Synchronize your information across your devices
- Process and restore subscriptions and determine Pro access
- Provide reminders
- Measure onboarding and feature performance
- Diagnose failures, prevent abuse and enforce AI usage limits
- Maintain security
- Respond to support and privacy requests
- Meet legal, tax, accounting and platform obligations
10. Selling, advertising & tracking
AlyraLabs does not sell your personal information. Fuelist displays no third-party advertising and does not use your information for cross-app behavioral advertising. PostHog is used for first-party product analytics. RevenueCat and PostHog are linked for subscription analytics, not advertising. If this ever changes we will update this policy and any applicable consent flows first.
Fuelist's settings screen links to our Instagram and TikTok profiles. If you follow one, you leave Fuelist and that platform's own privacy policy applies. We embed no tracking code from them, and they receive nothing about you unless you tap through.
11. Security & breach notification
Your data is stored on your device and in Supabase-hosted infrastructure in the United States. Access to your account's rows is restricted at the database level so that one account cannot read another's. AlyraLabs uses reasonable administrative, technical and organizational safeguards. No transmission or storage system can be guaranteed completely secure.
If we discover a breach affecting your identifiable health information, we will notify you without unreasonable delay and no later than 60 days after discovery, and will notify the Federal Trade Commission as required by its Health Breach Notification Rule.
12. Retention & deletion
California law requires us to tell you how long we keep each kind of information, or the criteria we use to decide. Ours:
| Information | How long we keep it |
|---|---|
| Account identifiers (email, name, account ID) | While your account is active. Deleted when you delete your account |
| Profile, goals, measurements, restrictions, preference notes | While your account is active. Deleted when you delete your account |
| Your active meal plan, its meals and shopping list | Until replaced by a new plan, or your account is deleted |
| Older plans | Removed from our servers on the next sync. Up to five stay on your device until you delete them or remove the app |
| Profile and meal photos | Until you remove them, or your account is deleted |
| Chef chat conversation | Device only. Reset at the start of each day |
| Scanned pantry products, age, notification settings, cached data | Device only. Until you clear them or remove the app |
| AI usage counters | Per day, for rate limiting. Deleted with your account |
| Product analytics events | Retained by PostHog under their retention schedule, keyed to your account ID |
| Purchase and subscription records | Retained by Apple and RevenueCat under their own tax, accounting and audit obligations, which continue after you delete your Fuelist account |
| Recipes added to the shared collection | Kept indefinitely. They contain nothing identifying you |
You can delete your account from inside the app. Doing so deletes your authentication account, synchronized profile, plans, plan meals, shopping items, AI usage records, your private profile photo, and any meal photos you added — both the stored image files and the records pointing to them. Fuelist also clears local plans, profile settings and scheduled notifications during a successful deletion. If any part of the deletion cannot be completed, the whole deletion is stopped and reported to you rather than partially applied.
Recipes already added to the shared collection are not removed, because they carry nothing identifying you and other people's plans may reference them.
Deleting your Fuelist account does not cancel an Apple subscription — manage that through Apple. Apple, RevenueCat, PostHog, email and infrastructure providers may retain limited transaction, analytics, security, backup or legal records under their own obligations.
13. Your privacy choices
You can contact AlyraLabs to:
- Request access to your personal information
- Correct inaccurate information
- Request deletion
- Ask for a portable copy where applicable
- Object to or restrict certain processing where applicable
You can also, at any time, withdraw permissions in iOS Settings, disable notifications, remove or replace your profile and meal photos, clear your saved preference notes, and manage or cancel subscriptions through Apple.
Depending on where you live, you may have rights to know what personal information we hold, to correct it, to delete it, to receive a portable copy, and to opt out of its sale or of targeted advertising. These rights exist under the California Consumer Privacy Act as amended by the CPRA, and under comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states.
California: categories we collect
California law asks businesses to describe personal information using its own defined categories. Mapped to ours:
| Statutory category | Do we collect it? | What it is, for Fuelist |
|---|---|---|
| Identifiers | Yes | Name, email address, account ID, IP address |
| Customer records (Cal. Civ. Code §1798.80(e)) | Yes | Name, and physical characteristics — height and weight |
| Protected classification characteristics | Yes | Age and biological sex, used only to calculate your nutrition targets |
| Commercial information | Yes | Subscription purchased, trial status, renewals, cancellations, refunds |
| Internet or network activity | Yes | In-app events such as plans generated and recipes opened; device and app version |
| Geolocation data | Limited | Approximate region inferred from IP address by our providers. No GPS |
| Sensory or audiovisual information | Yes | Profile photo and any meal photos you add. No audio |
| Inferences | Yes | Calculated calorie and macro targets, and preference notes distilled from what you tell the chef |
| Sensitive personal information | Yes | Health information: measurements, goals, dietary restrictions and food allergies |
| Biometric information | No | — |
| Professional or employment information | No | — |
| Education information | No | — |
We collect all of it directly from you, or generate it from what you provide. We do not buy personal information or obtain it from data brokers. It is used for the purposes in section 9, and disclosed only to the providers in section 7.
California law also treats health information as sensitive personal information. We use yours only to provide the service you asked for — calculating your targets and building your plans — and never to infer characteristics about you, so no separate right to limit its use applies. You can still delete it at any time.
Washington and Nevada residents have additional rights over consumer health data, described in our Consumer Health Data Privacy Policy.
To exercise a right, email contact@alyralabs.com. We will acknowledge within 10 business days and respond substantively within 45 days, and will tell you if we need a further 45 days. We will not discriminate against you for exercising a right.
14. Automated decisions
Fuelist generates meal plans automatically from the goals and preferences you provide, using third-party AI models. These are suggestions about food. They produce no legal effect and nothing similarly significant, and you are never profiled for any decision about credit, employment, insurance or access to a service. You can change or ignore any plan Fuelist produces.
15. Children
Fuelist is not directed to children, and AlyraLabs does not knowingly collect personal information from anyone under 16. If we learn that such information has been collected, we will take appropriate steps to delete it.
16. Changes to this policy
AlyraLabs may update this policy. When we do, we will change the “Last updated” date at the top of this page, and we will communicate material changes through the app, the website, or another reasonable method.
17. Contact us
AlyraLabs LLC
67 Spring Hill Road, Annandale, NJ 08801, United States
Privacy and app support: contact@alyralabs.com