Who this policy applies to
This policy applies to the MealManager Android application published by Programmatic Solutions International LLC ("PSI," "we," "our," or "us"). MealManager is intended for adult household organizers. It does not require a PSI account and does not include a PSI-operated cloud synchronization service.
Information stored on the device
Depending on the features used, MealManager can store the following information in the app's private device storage:
- Household and member names, dates of birth, body measurements, pregnancy or lactation status, activity settings, optional DASH/kidney planning goals, clinician-provided nutrient limits and other nutrition overrides, allergies, dietary preferences, and medical notes.
- Pantry, grocery, recipe, meal-plan, participation, cooking-history, feedback, receipt, price, and nutrition-reference records.
- Scan sessions, recognized text, barcodes, candidate metadata, confidence values, and confirmation history.
- Images a user intentionally keeps with a household, member, recipe, or inventory record.
- Encrypted OpenAI and USDA credentials and the address of an optional self-hosted HTTPS provider.
- Limited local response caches for Open Food Facts and USDA FoodData Central.
Medical notes are stored only. MealManager does not interpret them, diagnose a condition, or include them in its built-in OpenAI meal-draft request. Android automatic backup is disabled. Provider credentials are encrypted with a key protected by Android Keystore and are kept separately from the meal-planning database.
Camera, photos, and scan information
Camera permission is requested only after a user chooses to capture a scan. A user can instead import an image through Android's document picker without granting Camera permission.
Bundled Google ML Kit text and barcode recognition processes image input and recognition output on the device. Temporary source images are kept in app-private, no-backup storage during review. They are deleted after confirmation, dismissal, or cancellation. Abandoned temporary scan images are purged after seven days. Recognized text, barcodes, and confirmed records can remain locally after the temporary image is removed.
Pantry and food-appearance scans can offer an unchecked, per-scan option to use a self-hosted image provider configured by the user. If selected, the complete image is sent over HTTPS to that endpoint. If not selected, the image is not sent to the self-hosted endpoint. Users should not submit images containing people or unrelated private information.
Optional network services
MealManager's core household, pantry, recipe, planning, grocery, and history workflows do not require the services below.
Google ML Kit
The app bundles ML Kit text-recognition and barcode-scanning models. Google states that image inputs and recognition results for these features remain on the device. Google also describes limited SDK diagnostics and usage information, which can include device and application information, per-installation identifiers, feature and event metrics, input or output sizes, and error codes. See Google's ML Kit data-disclosure guidance.
Open Food Facts
After a user starts a barcode lookup, the app sends the barcode and an app user agent to the Open Food Facts API. Returned product fields can be cached locally. MealManager does not retain provider product images. Open Food Facts applies its own privacy and service practices. Its database is made available under the Open Database License (ODbL), with individual database contents under the Database Contents License. See the Open Food Facts licensing guidance.
USDA FoodData Central
When a user configures a USDA data.gov API key and starts a search or details request, the app sends the key, entered search term, or selected FoodData Central identifier over HTTPS. Results can be cached locally. FoodData Central data is public-domain data offered under CC0, and MealManager preserves source identifiers. See the FoodData Central API guide.
OpenAI
OpenAI use is optional, requires a user-supplied API key, and begins only when the user explicitly includes configured AI providers in a meal request. MealManager sends derived constraints such as meal type, scheduled time, maximum preparation time, pantry or use-soon signals, currency, and diner count. The built-in request does not send names, dates of birth, photos, medical notes, allergy records, or other household profile fields. Provider output remains an unverified review draft and is subject to deterministic local safety checks and user confirmation.
The request sets store to false. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in, while abuse-monitoring logs can be retained under OpenAI's applicable data controls. See OpenAI API data controls.
Self-hosted provider
A user can configure an HTTPS endpoint that PSI does not operate or control. Meal-generation requests send the same limited derived constraints described above. A scan image is sent only after the separate per-scan option is selected. The endpoint operator controls its server logs, storage, retention, security, and deletion practices. Users should configure only an endpoint they trust.
Recipe-page import
Recipe import requests the specific HTTPS page selected by the user and reads a bounded Schema.org Recipe payload. The destination site receives ordinary network information such as the device's public IP address and applies its own terms and privacy practices.
Export, deletion, and retention
MealManager provides controls to:
- Delete individual households, eligible user-managed recipes, and the isolated sample household.
- Clear stored OpenAI and USDA credentials.
- Confirm, dismiss, or cancel scans and remove their temporary source images.
- Export or import an explicit JSON data set through Android's document picker.
- Use Android's Clear storage control or uninstall the app to remove remaining private app data.
The JSON export excludes provider credentials, provider caches, search indexes, temporary scan paths, and private image attachments. The user selects the destination provider and is responsible for protecting the exported file. Local records remain until the user deletes them, clears app storage, uninstalls the app, or an app-specific retention rule removes them. Information already sent to another service is subject to that service's retention and deletion controls.
Security
MealManager uses Android app-private storage, disables cleartext network traffic and automatic backup, requires HTTPS for direct providers and recipe import, bounds network payloads, and is designed not to log household profiles, credentials, recognized text, images, or medical notes. No security control can guarantee absolute protection. Users should keep Android updated, protect device access, and avoid exporting data to an untrusted location.
Children
MealManager is intended for adult household organizers and is not directed to children. An adult can store a child's profile locally to support portion and nutrition-reference matching. Children should not configure providers, upload images, or use the app independently.
Nutrition, allergy, and food-safety limits
Missing values remain unavailable rather than being inferred. Confirmed allergy and dietary conflicts are hard exclusions, but incomplete product or recipe evidence remains unverified. A photo, scan, provider response, or appearance observation cannot establish that food is safe to eat.
Optional DASH-style support compares measured recipe sodium with a daily planning limit and can prioritize lower-sodium options. Optional kidney-support planning has no default medical target: it affects ranking only when the user enters nutrient limits supplied by a qualified clinician and the recipe contains the required measured values. Needs can differ with condition, laboratory results, medicines, and treatment.
These comparisons and substitution ideas are planning aids only. They are not professional nutrition services or medical advice, and they do not establish that a recipe is appropriate for any person or condition. Users are responsible for reviewing ingredients, labels, portions, substitutions, and clinician guidance.
Advertising, sale, and sharing
MealManager contains no advertising SDK. PSI does not sell MealManager personal information. Information leaves the device only through user-directed exports or the optional provider and page-import actions described in this policy. Platform and provider services apply their own terms and privacy practices.
Changes to this policy
We may update this policy when MealManager's data practices or applicable requirements change. The effective date at the top of this page will identify the current version. The Google Play Data safety declaration and this policy are intended to remain consistent with every distributed version of the app.
Contact
Questions about this policy or information controlled by PSI can be sent to support@psillc.org. PSI cannot delete information held under a user's separate relationship with OpenAI, USDA, a self-hosted provider, a document provider, or an imported recipe website unless PSI controls that service.