Read the detailPhotos and AI processingYou choose the photos and notes. The app asks before the first AI request.
Before AI processing runs for the first time, SelfMosaic asks permission to send the selected kitchen photos and optional notes, reviewed ingredient lists, or selected meal text for an optional serving reference to Microsoft Azure OpenAI. For each live ingredient-scan or meal-plan request, SelfMosaic's backend derives a stable SHA-256 pseudonym from the internal viewer ID and sends that pseudonym to Azure OpenAI as a safety identifier for abuse detection. It contains no email, username, device ID, or raw SelfMosaic viewer ID and is not used for advertising or cross-app tracking. SelfMosaic does not use your kitchen photos, prompts, or saved meals to train SelfMosaic models.
Read the detailWhat SelfMosaic storesMeal requests, saved meals, account or session state, and the minimum context needed to run and support the service.
Saved meals keep the meal idea and its photo-read or reviewed ingredient list. SelfMosaic also keeps your current AI permission, basic diagnostics, support details you send, and the session or account identifiers needed to run, troubleshoot, export, or delete your data. Saved meals stay on this device when SelfMosaic says it saved locally. When session or account saving is available, saved meals can instead attach to that supported session or signed-in account. A saved meal may keep a metadata-stripped thumbnail in the device cache; it is never uploaded or backed up and disappears with the meal, the app, or an operating-system cleanup. SelfMosaic creates a stable, random pseudonymous device identifier and keeps it in local app storage. The app sends that identifier when it creates or recovers a preview or account viewer, when you submit a waitlist or support request, when you report an AI result, during purchase or restore safety checks, and—only after optional analytics consent—when it records an App Store or Product Hunt link opening. SelfMosaic stores the waitlist copy for abuse control; for a link-opening receipt, the server immediately replaces the received identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic uses the identifier for app continuity, request and billing integrity, abuse prevention, security, support, and consented product analytics—not advertising or cross-app tracking. The app also sends and stores the device timezone so dated meals and account activity use the expected local day. Sign-in is optional. If you choose Apple, Google, or an email sign-in method, Clerk and the identity provider may send SelfMosaic an account or user identifier, email address, and name when the provider supplies them. SelfMosaic uses the identifier for authentication and account continuity, and uses a supplied name or email for account display, a one-time transactional account welcome email after the first verified account setup, requested contact, support, export, and deletion. The welcome email is a service message, not a marketing subscription. Billing entitlement is connected through viewer, account, and store identifiers—not your name or email. None of these details is used for advertising or cross-app tracking.
Read the detailProviders and locationsSelfMosaic operates from India. Selected providers process data in the United States.
SelfMosaic is operated from India. Outside providers support hosting, storage, AI food reasoning, optional sign-in, diagnostics, support email, optional analytics, and subscription billing. Some of those providers process data in the United States, so your information may be processed outside your country. Contact privacy@selfmosaic.app with questions about international transfers.
Read the detailAnalytics, email, and billingNo ad tracking. Optional analytics is consent-based; crash diagnostics stay on without raw kitchen photos.
Website analytics are off unless consent controls are available and enabled. Optional in-app product analytics stay off until you turn them on from Privacy in the app. If you choose to join the launch waitlist, SelfMosaic sends and stores the email address you enter, the app-scoped pseudonymous device identifier, the page or placement where you joined, a sanitized referrer path, and available UTM campaign values. SelfMosaic uses the email to send the launch update you requested, the device identifier to limit waitlist abuse, and the source details to understand which SelfMosaic launch surfaces work. Separately, after optional analytics consent, opening an App Store or Product Hunt link sends the device identifier and source details to create a launch-link receipt; the server immediately replaces that identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic does not share this information with advertising networks or use it for cross-app tracking. If you enable optional analytics, SelfMosaic's sanitized product events can include the current plan tier, a subscription package or product identifier, purchase or restore step and outcome, active-entitlement count, server-sync state, and a bounded failure category. PostHog receives those consented events, and Sentry can include the same consented event as a breadcrumb if a later diagnostic report is sent. These events contain no full payment-card data, store receipt, transaction token, or order reference and are used to understand subscription-flow reliability, not for advertising or cross-app tracking. Resend handles the one-time transactional account welcome, requested waitlist and launch updates, and support email delivery. Apple processes iOS payments and Google Play processes Android payments. When separately enabled, signed-in website checkout is processed by Paddle as merchant of record. RevenueCat carries the account-bound entitlement between those providers and SelfMosaic using details such as a pseudonymous App User ID, product, store, entitlement, expiration, cancellation, or refund status. SelfMosaic does not receive or store full payment-card data.