Last updated: August 14, 2026
LumaMeal ("the App", "we", "us") is a meal-planning app that builds a personalized weekly meal plan, generates a grocery list, estimates nutrition from photos of your meals or pantry, and lets you track what you eat. This policy explains what data the App collects, why, and how it is stored and protected.
LumaMeal does not require your name, email address, or a password to use the App. You are identified only by an anonymous, randomly generated device account. Your meal photos, pantry photos, preferences, and logs are stored securely and are never sold or shared with advertisers.
LumaMeal uses Firebase Anonymous Authentication. On first launch, the App creates an anonymous account consisting of a random identifier (UID) — no email, phone number, name, or password is collected or required. This identifier is used solely to associate your preferences, meal plans, grocery lists, and logs with your device so they can sync and persist across app launches.
To personalize your plan, the setup flow asks you for:
This information is used only to generate and refine your meal plans and grocery lists. It is stored in your Firestore user document and is never used for advertising.
The App stores, under your anonymous account:
This data is stored in Google Firebase (Firestore and Cloud Storage), scoped to your account so that only your own device/account can read or write it.
Meal plans, recipes, ingredient recognition, nutrition estimates, and dish illustrations are generated using Google's Gemini and Imagen models through Firebase AI Logic (Vertex AI). Your setup preferences, pantry/meal photos, and prompts derived from them are sent to Google's AI services solely to generate this content for you. Nutrition estimates are AI-generated approximations and should not be treated as precise medical or clinical measurements — see the Terms of Service for details.
LumaMeal offers optional auto-renewable subscriptions (weekly and monthly, each with a free trial) that unlock full AI-generated plans, recipes, and unlimited regenerations. Payments are processed entirely by Apple through your App Store account — LumaMeal never sees or stores your payment or card details. We use RevenueCat to manage subscription status and entitlements; RevenueCat receives your anonymous app-generated identifier and purchase/transaction data (such as product ID, purchase date, and renewal status) — never your name, email, or card details.
We use the following service providers to operate the App. Each processes data only as needed to provide its service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Storage) | Anonymous account, data storage & sync | Anonymous UID, preferences, plans, logs, cached images |
| Google Firebase AI Logic (Gemini / Imagen via Vertex AI) | Meal plan, recipe, ingredient & nutrition generation | Preferences, prompts, submitted photos |
| RevenueCat | Subscription management | Anonymous UID, purchase/entitlement data |
| Apple (App Store / StoreKit) | Payment processing | Handled entirely by Apple |
These providers are contractually and technically restricted from using your data for their own advertising purposes.
Your data is protected by Firebase security rules that scope every document and file to your own anonymous account — no other user or account can read or write your data. Data is encrypted in transit (HTTPS/TLS) and at rest by Google Cloud/Firebase infrastructure.
LumaMeal is not directed at children and is not intended for use by anyone under 13 (or the applicable minimum age in your country). While the App lets a parent or guardian record a child's age as part of household size for portioning purposes, it does not knowingly collect personal data directly from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your data, or to object to certain processing. Because your account is anonymous, we can only act on such requests when you can identify your account (e.g. via the anonymous ID visible in the App, if applicable) or via the device/App instance itself. Contact us using the details below to exercise these rights.
We may update this policy from time to time. Material changes will be reflected on this page with a new "last updated" date; continued use of the App after a change constitutes acceptance of the revised policy.
Privacy questions or data deletion requests: emirarikan99@gmail.com