Privacy

Version 1.9 · 8 September 2026

What MenuFit stores

Your profile may include a weight goal, diet style, medical conditions, allergies or intolerances, likes, dislikes, health and price priorities, recent context, locale, currency, and free-text notes. Medical-condition, allergy, intolerance, and note entries may contain sensitive health-related information; do not enter unrelated sensitive information. Medical conditions are stored but are not automatically converted into treatment or filtering rules. Your profile, package purchases, menu-credit activity, in-app notification records, referral attribution, and active menu access are retained to provide the service, prevent duplicate notifications, measure service performance, and meet accounting obligations. My places keeps up to 12 of your most recently viewed venue menu links; repeat visits move the same link to the top, and older links are replaced automatically. Saved items keeps a server-derived dish snapshot and its menu source with your account until you remove the item or delete the account. Raw menu sources are deleted when processing reaches a terminal state. For uploaded menus, MenuFit retains an exact-byte SHA-256 digest and normalized analysis, but not the raw file, so an identical upload is not analyzed again. For public menu URLs, MenuFit retains a shared, non-profile snapshot and checks it hourly. Menu analyses, personalization results, translations, recommendations, visual assets, and saved visit context are retained without automatic time-based deletion. Unchanged dishes reuse their translations and visuals across menu revisions. The 24-hour menu-access entitlement is separate from data retention; account and explicit deletion controls still apply.

How data is used

MenuFit uses the saved profile to personalize menu recommendations. Saved items are not copied into profile likes or dislikes and do not change recommendation ranking in this version. Relevant profile fields and menu content are sent to the configured AI provider only to perform the requested analysis, recommendation, translation, or visualization. MenuFit does not use generated dish images as allergen evidence. OAuth credentials and Stripe webhook secrets are kept server-side and are not sent to the AI provider.

QR menu partner attribution

When you choose MenuFit through a registered partner's link or button, MenuFit stores a first-party signed partner-attribution cookie and measures an aggregate funnel using a random visit identifier. MenuFit may attribute a verified signup, completed personalization, checkout, payment, refund, or dispute to the most recent valid provider visit. Raw partner events are deleted after 13 months; purchase attribution is retained with the corresponding purchase record. Partner dashboards show only aggregate funnel, venue, and revenue totals. MenuFit does not share email addresses, profiles, allergies, preferences, free-text notes, or individual recommendations with QR menu partners. Raw IP addresses and full user-agent strings are not stored in partner events.

Your choices

You may update your profile and remove saved items. Contact the MenuFit operator for account access or deletion requests; financial ledger records may need to be retained where required by law. A venue or source owner may request removal of a public menu wrapper through support.