Privacy Policy
Last updated: 8 September 2026
Emperor Technologies LLC, a California limited liability company ("Company", "mymealT", "we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy ("Policy") describes how we collect, use, store, share, transfer, and otherwise process your personal data when you use our website, mobile application, or other products and services (collectively, the "Services"), and explains your rights under applicable law.
This Policy should be read together with our Terms and Conditions. By using the Services or providing your personal data, you acknowledge you have read and understood this Policy. Depending on where you live, different laws apply: US residents should read Section 16A (US Privacy Rights); Indian residents are covered by the provisions implementing India's Digital Personal Data Protection Act, 2023 ("DPDPA"), the Information Technology Act, 2000, and rules thereunder.
1. Definitions
- "Personal Data" / "Personal Information" means any data about an identifiable individual, as defined under applicable law (including the DPDPA and US state privacy laws).
- "Data Fiduciary" / "Controller" means Emperor Technologies LLC, which determines the purpose and means of processing.
- "Data Principal" / "Consumer" means the individual to whom the Personal Data relates.
- "Processing" means any operation performed on Personal Data, automated or not, including collection, storage, use, disclosure, sharing, transfer, adaptation, restriction, erasure, or destruction.
- "Consent" means a freely given, specific, informed, unambiguous indication of agreement through a clear affirmative action.
- "Sensitive Personal Data" means data revealing physical, physiological, or mental health information, and other categories treated as sensitive under applicable law.
- "Services" means the website, mobile application, and any products or features offered by mymealT.
- "Third-Party Service Provider" means any third party engaged to provide services in connection with the Services.
2. Personal Data We Collect
2.1 Information You Provide
- Phone number — used to create and verify your account via OTP. We do not use it for marketing.
- Profile information — name, date of birth, height, weight, and fitness goals, provided voluntarily to personalise calorie targets.
- Meal logs — foods, photographs, and nutritional data you record.
- Restaurant menu photographs — if you use the Eat Out feature, photographs of restaurant menus you scan. These are processed transiently to extract menu text (dish names, prices, and nutrition estimates) and are not permanently stored; the extracted menu content is added to a shared restaurant database that is not linked to your identity.
- Messages — feedback, enquiries, or communications you send us.
- Any other Personal Data you voluntarily provide.
2.2 Information Collected Automatically
- Device identifiers, including your Firebase Cloud Messaging token, for push notifications.
- IP address, browser type, operating system, device information, and similar technical data.
- Usage data, crash reports, and analytics via Firebase Crashlytics and Google Analytics, to fix bugs and improve the app. These do not intentionally include personally identifiable information.
- Location — if you grant location permission and use location-based features (such as finding nearby restaurants, restaurant check-ins, or associating a scanned menu with a restaurant), your device's precise location is used to serve that request. We do not keep a history of your movements: coordinates are used transiently and retained at most briefly for processing (see Section 11); only restaurant locations are stored durably. Location is never used for advertising or shared for marketing.
- Cookies and similar technologies, as described in Section 10.
2.3 Health and Wellness Data
Subject to your explicit Consent and device permissions, we read step count, weight, and other metrics from Apple Health / Google Fit. This data is stored on your device and our servers solely to power in-app trends, progress tracking, and personalised insights — it is never sold or shared for advertising or marketing. We treat it as Sensitive Personal Data and process it only as described in Section 9.
3. Sources of Personal Data
3.1 We collect Personal Data (a) directly from you (account creation/verification, profile setup, meal logging, granting health-app permissions, contacting us); (b) automatically (cookies, SDKs, analytics, crash-reporting) as you use the Services; and (c) from third parties where you connect services such as Apple Health or Google Fit, subject to device permissions.
3.2 You may decline to provide certain Personal Data, though this may limit features. Where required by law, we process Personal Data only with your Consent or another lawful basis.
4. How We Use Your Personal Data
4.1 We process Personal Data only for legitimate purposes connected with providing and improving the Services, including to:
- create, verify, and manage your account (including via OTP);
- provide, operate, and improve the Services, including personalising calorie targets, recommendations, and health insights;
- record and analyse meal logs and health/wellness data for in-app trends and progress tracking;
- process meal photographs using AI to identify foods and estimate nutrition (photographs processed for this purpose are not used to train AI models);
- send service-related communications (verification, streak reminders, weekly summaries — you can disable push notifications in device settings);
- respond to enquiries, feedback, and support requests;
- monitor and improve performance, security, and reliability;
- detect, investigate, and prevent fraud or misuse; and
- comply with applicable law and lawful requests.
We do not sell your Personal Data. We do not use your meal logs or health/wellness data for advertising or marketing.
5. Sharing of Personal Data
5.1 We do not sell, rent, or trade your Personal Data. We share it only where necessary to provide the Services, where you consent, or where permitted or required by law:
- Service Providers — trusted Third-Party Service Providers who help operate the Services (Section 6), limited to what their role requires.
- Legal and Regulatory Authorities — to comply with law, court orders, or lawful government requests.
- Business Transfers — in a merger, acquisition, or sale of assets, subject to applicable law and safeguards.
- With Your Consent — to any party you authorise.
We require recipients to process Personal Data only for the shared purpose, keep it confidential, and apply appropriate security.
6. Third-Party Service Providers
6.1 We currently engage the following categories, each processing Personal Data only as necessary:
- Heroku (Salesforce) — cloud infrastructure, application hosting, and database services.
- Twilio — OTP SMS delivery for account verification (your phone number is shared solely for this).
- Cloudinary — storage and delivery of meal photographs.
- Anthropic — AI analysis of meal and restaurant-menu photographs to identify foods and estimate nutrition, and generation of eating-out suggestions (processed transiently; not used to train AI models).
- Google Maps Platform (Places API) — restaurant discovery for location-based features. When you search for nearby restaurants, coordinates for that request are sent to Google to identify restaurants around you; Google's own privacy policy applies to its processing.
- Google Firebase — push notifications, crash reporting (Crashlytics), and analytics.
- Google Analytics — aggregated usage and performance information (not intentionally used to collect PII).
6.2 We may add, replace, or remove providers as our needs evolve; any new provider will process Personal Data only as described here. Our Services may link to third-party websites we do not control; review their policies separately.
7. Cross-Border Transfer of Personal Data
7.1 We are a US company and some Third-Party Service Providers process data on servers outside your country, including in the United States. For Indian residents: Section 16 of the DPDPA permits transfer of Personal Data outside India except to jurisdictions restricted by the Central Government; we do not currently transfer to any restricted jurisdiction.
7.2 Independent of what applicable law strictly requires, we seek reasonable contractual and technical safeguards from providers processing Personal Data across borders so it continues to be handled consistently with this Policy. By using the Services, you acknowledge your Personal Data may be processed outside your country as described.
8. Your Rights and Control Over Your Personal Data
Subject to applicable law, you may:
- access information about how your Personal Data is processed;
- request correction, completion, updating, or erasure;
- withdraw Consent at any time (Section 18); withdrawal does not affect prior lawful processing;
- seek grievance redressal (Section 17); and
- delete your account via Settings → Delete Account; data is then handled per Section 11 (Retention).
8.1 We may require identity verification before acting on a request and may decline or limit a request where permitted by law (e.g. where it would adversely affect another person's rights or where retention is legally required).
8.2 Right to Nominate (India). Under Section 14 of the DPDPA, you may nominate another individual to exercise your rights in the event of death or incapacity, by contacting us (Section 18).
8.3 US residents: additional rights are described in Section 16A.
9. Sensitive Personal Data and Explicit Consent
Certain data (weight, height, step count, and other health/wellness metrics) may be Sensitive Personal Data. We process it only on the basis of your explicit Consent, obtained when you grant the relevant device/app permission. You may withdraw Consent by revoking the permission in device settings or deleting your account; this may limit features that depend on that data. We do not share Sensitive Personal Data for marketing or advertising.
10. Cookies and Similar Tracking Technologies
Our mobile application does not use browser cookies; it relies on the device identifiers, SDKs, and analytics tools in Section 2.2. Our website may use cookies and similar technologies to keep you signed in, remember preferences, and understand aggregate usage (e.g. Google Analytics). You can control cookies through your browser; disabling them may affect website functionality but not the mobile application.
11. Retention of Personal Data
We retain account data while your account is active. If you delete your account, your Personal Data is removed within 30 days, unless a longer period is required or permitted by law. Meal logs and health metrics are deleted immediately on account deletion, subject to any legal retention requirement. Coordinates attached to a menu-scan request are retained for at most 14 days as part of scan-processing records and then deleted. Restaurant and menu content contributed through menu scans (dish names, prices, nutrition estimates, and restaurant locations) is retained in our shared restaurant database in a form not linked to your identity, and survives account deletion. We may retain anonymised, aggregated statistics that do not identify you indefinitely.
12. Security of Personal Data
12.1 We implement reasonable technical, organisational, and administrative measures to protect Personal Data, including:
- all data transmitted over encrypted HTTPS connections;
- passwords and authentication tokens hashed before storage;
- OTP codes hashed using PBKDF2 before storage.
12.2 You are responsible for keeping your login credentials confidential and notifying us of unauthorised use. No transmission or storage method is completely secure. If we become aware of a Personal Data breach requiring notification under applicable law, we will take appropriate steps, including notifying affected users and authorities where required.
13. Children's Privacy and Use on Behalf of Another Person
13.1 The Services are not directed to or intended for children under 18. We do not knowingly process a child's Personal Data without verifiable parental/guardian consent where required by law. If we learn we have inadvertently collected a child's Personal Data without required consent, we will take reasonable steps to delete it or otherwise comply with law.
13.2 If you use the Services on behalf of another individual (e.g. as a parent/guardian), you represent you are authorised to provide that individual's Personal Data under this Policy.
14. Marketing Communications and Opt-Out
We may send service-related communications necessary to operate the Services (verification, security notices) — these are not marketing and cannot be opted out of while your account is active. Where you have consented, we may send push notifications (streak reminders, weekly summaries); disable them anytime in device settings. We do not use your phone number for marketing and do not sell Personal Data for advertising. If we introduce promotional communications, you will be able to opt out via the unsubscribe instructions or by contacting us.
15. Changes to This Policy
We may update this Policy to reflect changes in our practices, the Services, or applicable law. We will notify you of material changes via push notification, in-app notice, or other method required by law. The "Last Updated" date reflects the most recent revision. Continued use after a revised Policy takes effect constitutes acceptance, to the extent permitted by law.
16. Governing Law and Jurisdiction
16.1 For US residents, this Policy and any dispute regarding our processing of your Personal Data are governed by the laws of the State of California, United States, and the courts located in California have jurisdiction, subject to any non-waivable rights under your state's law.
16.2 For Indian residents, this Policy is governed by the laws of India, and, subject to applicable law, the courts at Hyderabad, Telangana, India have jurisdiction over disputes concerning our processing of your Personal Data.
16A. US Privacy Rights (CCPA / CPRA and similar state laws)
16A.1 Categories collected. In the past 12 months we have collected: identifiers (phone number, device identifiers, IP address); customer records (name, height, weight); health/wellness information (with consent); internet/usage activity; and inferences for personalisation. Sources and purposes are described in Sections 2–4.
16A.2 No sale or sharing. We do not sell your Personal Information and do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding 12 months, including for consumers under 16.
16A.3 Your rights. Subject to applicable law, US residents may request to: know/access the Personal Information we collect and how it is used; delete it; correct it; and be free from discrimination for exercising these rights.
16A.4 How to exercise. Submit a request via our contact form or info@mymealt.com. We will verify your identity before responding. You may use an authorised agent; we may require proof of authorisation.
16A.5 Shine the Light (California). We do not disclose Personal Information to third parties for their direct-marketing purposes.
17. Grievance Officer (India)
If you have questions, concerns, or grievances regarding this Policy or our processing of your Personal Data, you may contact our Grievance Officer, appointed in accordance with applicable Indian law:
Email: info@mymealt.com (please include "Grievance" in the subject line).
The Grievance Officer will address your grievance within any timelines applicable law prescribes.
18. Contact Us
Questions about this Policy? Send us a message or email us at info@mymealt.com.