Privacy Policy
EatChowdy (“Chowdy”, “we”, “our”, or “us”) is a meal planning app for iPhone operated by Froth Labs LLC. This policy explains exactly what the app collects, where each piece of it goes, and what you can do about it.
1. Summary
This table is the same disclosure that appears on the App Store listing. The sections below explain each row.
| Category | What it is | Linked to you |
|---|---|---|
| Contact info | Name, email address | Yes |
| Health | Health conditions you choose to tell Chef about | Yes |
| Coarse location | An optional ZIP or postal code you type in | Yes |
| Purchases | Subscription and purchase history | Yes |
| Photos | Recipe, receipt, and pantry photos you take or choose | Yes |
| Other user content | Meal plans, recipes, pantry, grocery lists, preferences, and your conversations with Chef | Yes |
| Identifiers | Your account ID, and a notification token per device | Yes |
| Diagnostics | Crash reports and performance traces | No |
None of it is used to track you. Chowdy contains no advertising, attribution, or product-analytics SDK, never requests the iOS advertising identifier (IDFA), shows no ads, and shares nothing with data brokers. See section 7.
2. What we collect
Account information
When you sign in with Apple or Google, we receive your name and email address from that provider and store them on your profile. We never see or store a password. If you use Apple’s Hide My Email, what we store is Apple’s private relay address, not your real one. We do not collect phone numbers.
Meal planning and recipe content
- Meal plans and the individual meal slots in them, including ones you skip.
- Recipes you save, fork, import, create, or rate, plus your notes and personal tags.
- Pantry items and grocery lists.
- Preferences: meals per day, cooking skill, cooking rhythm, plan length, dietary restrictions, disliked ingredients, weekly grocery budget, shopping style, preferred store, and time zone.
- Your calorie target and macro split, if you set one.
- Your conversations with Chef, the in-app assistant — the messages you send, its replies, and a running summary of the thread.
If you use the calorie calculator, the age, biological sex, height, weight, activity level, and goal you enter are used to run the calculation on your device only. Those figures are never transmitted or stored — only the calorie target the calculator produces is saved to your profile.
Health conditions
If you tell Chef about a health condition — a medical restriction, an allergy, something you are managing through diet — it is stored on your profile so plans and suggestions can account for it, and it is included in the context sent to our AI provider when Chef answers you. This is the most sensitive thing the app holds. You can view, edit, or clear it at any time from the Profile tab, and deleting your account removes it.
Photos
Chowdy uses your camera and photo library in three places, all optional:
- Importing a recipe from a photo. The images you pick (up to three) are downscaled on your device and sent to our servers so an AI model can read the recipe out of them.
- Adding a photo to a recipe. The image is compressed and uploaded to our storage provider, and the resulting URL is saved on that recipe.
- Scanning a receipt or a photo of your pantry. A Pro feature: the images you pick (up to three) are downscaled on your device and sent to our servers so an AI model can read the items out of them. The photos themselves are never stored — only the item names, quantities, and units the model reads are saved, as pantry entries you review and confirm before anything is written.
Please note: recipe photos are stored in a bucket that is readable by anyone who has the exact file URL. The URLs are long and unguessable, only you can write to your own folder, and the app has no feed, no profiles, and no way to browse anyone else’s photos — but the files themselves are not behind a login. Don’t put anything in a recipe photo you would not want reachable by link.
Location
Chowdy never asks for location permission and cannot read your device’s location. It has no GPS access at all. What it does collect is an optional ZIP or postal code you type in yourself, used to find grocery stores near you. You can leave it blank, and you can remove it later.
Subscription
Subscriptions are purchased through Apple’s App Store. Our subscription provider records your purchase and renewal status against your Chowdy account ID so the app knows what you have access to. We never receive or store card numbers or any other payment instrument — Apple handles the transaction end to end.
Notifications
If you allow notifications, the app stores a push notification token on your profile. That token identifies a specific device, so it counts as a device identifier. It is used only to send you meal and plan reminders — never for advertising — and it is cleared when you sign out.
Diagnostics
We collect crash reports and performance traces to keep the app stable. This data is not linked to your identity — we do not attach your user ID, email, or any other account information to it.
What stays on your device
Your sign-in tokens are held in the iOS Keychain, and cached plan and recipe data (so the app works offline) is stored locally. Neither is transmitted to us.
What we never collect
- Device location, precise or coarse, from the operating system.
- Contacts, calendars, HealthKit data, microphone, or motion data.
- Payment card or bank details.
- The advertising identifier (IDFA).
- Your browsing or search activity in other apps or on the web.
3. How we use it
- To run the app: build and store your plans, lists, and recipes.
- To personalize suggestions — Chef adapts to what you actually cook, skip, and rate over time.
- To build a grocery cart at a connected retailer, when you ask it to.
- To manage your subscription entitlement.
- To send notifications you have opted into.
- To diagnose crashes and fix performance problems.
We do not sell your personal information, we do not share it with advertisers, and we do not use it to build advertising profiles.
4. Who we share it with
We use the following service providers. Each is contractually restricted to processing your data on our behalf, for the purpose listed.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage | Your account and all meal planning content, including photos |
| Amazon Web Services | Application servers and Amazon Bedrock, which runs the AI models behind Chef | Your messages to Chef, your plan context and preferences (including health conditions), and photos from recipe import and pantry scanning |
| Sentry | Crash and performance monitoring | Crash reports and performance traces, with no account identity |
| RevenueCat | Subscription management | Your account ID and purchase history |
| Kroger | Optional grocery integration — only if you connect a Kroger account | Product search terms from your grocery list, a store location, and the items you add to your cart |
| Apple, Google | Sign-in; Apple also handles all payments | Your name and email address, from the provider you choose |
We may also disclose information if required by law, or to protect the rights, safety, or property of our users or ourselves.
5. AI processing
Chef runs on Claude models hosted in our own Amazon Bedrock account. When you send Chef a message, what leaves your device is that message, a summary of the conversation so far, and the parts of your profile relevant to the request — your preferences, dietary restrictions, and your health conditions. Recipe photos you import are sent the same way, for the model to read.
Your data is not used to train AI models. Bedrock does not use inference inputs or outputs for model training, and neither do we.
Chef’s suggestions can be wrong. Please check ingredients against your own allergies and restrictions before you cook or buy — see our Terms of Service for the full disclaimer.
6. Retention and deletion
- We keep your account and meal planning data for as long as your account exists.
- Internal audit logs of changes are kept for 90 days, then deleted.
- When you delete your account, your personal data is removed from our systems within 30 days, except where we are required to keep something by law.
7. Tracking and advertising
Chowdy does not track you. Specifically, and as of the version described by this policy:
- There is no advertising SDK, no attribution SDK, and no third-party product-analytics SDK in the app.
- The app never requests the iOS advertising identifier and shows no App Tracking Transparency prompt, because it has nothing to ask for.
- Crash and performance monitoring is diagnostics, not cross-app tracking, and carries no account identity.
- We have no data-broker relationships. Data sent to a grocery retailer goes there because you asked for a cart, and for no other reason.
8. Your rights and choices
- Delete your account. Profile tab → Delete Account. This removes your account and personal data from our systems; it does not cancel an App Store subscription, which you manage in your Apple Account settings.
- Export your data. Profile tab → Export my recipes gives you your saved recipes and meal plans, including your notes and ratings, as a text file. For a copy of everything else we hold about you — your profile, grocery lists, store preferences, and your Chef conversations and learned preferences — email us and we will send it to you.
- Correct or remove specific information. Preferences, dietary restrictions, health conditions, ZIP code, and photos can all be edited or cleared in the app at any time.
- Turn things off. Notifications, the grocery integration, and the optional ZIP code are all opt-in, and can be revoked without losing the rest of the app.
Depending on where you live, you may have additional rights over your personal data — including access, correction, deletion, portability, and the right to object to processing. Email us at privacy@eatchowdy.com and we will action it.
9. Security
Data is encrypted in transit with TLS. Our database enforces row-level security, so one account cannot read another’s rows, and API access requires a signed token tied to your session. Sign-in tokens are stored in the iOS Keychain. No system is perfectly secure and we cannot guarantee absolute security, but these are the measures in place.
10. Children
Chowdy is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
11. Changes to this policy
We will update this page when what we collect changes, and update the “Last updated” date above. If a change is material we will say so in the app. Continuing to use Chowdy after a change takes effect means you accept the updated policy.
12. Contact
Froth Labs LLC
privacy@eatchowdy.com
eatchowdy.com
© 2026 Froth Labs LLC. All rights reserved.