SelfMosaicFridge, pantry, or counter photo in; practical meal ideas out.

Privacy

Privacy for SelfMosaic.

This notice covers SelfMosaic's kitchen-photo meal flow. It includes selected kitchen photos, optional cooking context, ingredient lists, saved meals, support, billing status, diagnostics, analytics settings, export, and deletion data.

You choose what to send, what to save, and whether to enable optional analytics.

The short version

The parts most people want to know.

SelfMosaic uses the kitchen photos and details you choose to create meal ideas. You can export or delete your data.

At a glance

Your choices stay visible.

  • After you approve, selected kitchen photos are sent to Microsoft Azure OpenAI for the request. Original bytes are not kept on SelfMosaic's servers or used to train SelfMosaic models.
  • Parsed AI results may be kept for up to 24 hours for an exact retry. Saved meals persist only when you choose to save them.
  • There is no advertising or cross-app tracking. Optional analytics stays off until you enable it.
  • SelfMosaic receives subscription status, not your full card details.

How it works

Four useful questions, with detail on demand.

Open a section when you want the provider or processing detail.

Read the detailPhotos and AI processingYou choose the photos and notes. The app asks before the first AI request.

Before AI processing runs for the first time, SelfMosaic asks permission to send the selected kitchen photos and optional notes, reviewed ingredient lists, or selected meal text for an optional serving reference to Microsoft Azure OpenAI. For each live ingredient-scan or meal-plan request, SelfMosaic's backend derives a stable SHA-256 pseudonym from the internal viewer ID and sends that pseudonym to Azure OpenAI as a safety identifier for abuse detection. It contains no email, username, device ID, or raw SelfMosaic viewer ID and is not used for advertising or cross-app tracking. SelfMosaic does not use your kitchen photos, prompts, or saved meals to train SelfMosaic models.

Read the detailWhat SelfMosaic storesMeal requests, saved meals, account or session state, and the minimum context needed to run and support the service.

Saved meals keep the meal idea and its photo-read or reviewed ingredient list. SelfMosaic also keeps your current AI permission, basic diagnostics, support details you send, and the session or account identifiers needed to run, troubleshoot, export, or delete your data. Saved meals stay on this device when SelfMosaic says it saved locally. When session or account saving is available, saved meals can instead attach to that supported session or signed-in account. A saved meal may keep a metadata-stripped thumbnail in the device cache; it is never uploaded or backed up and disappears with the meal, the app, or an operating-system cleanup. SelfMosaic creates a stable, random pseudonymous device identifier and keeps it in local app storage. The app sends that identifier when it creates or recovers a preview or account viewer, when you submit a waitlist or support request, when you report an AI result, during purchase or restore safety checks, and—only after optional analytics consent—when it records an App Store or Product Hunt link opening. SelfMosaic stores the waitlist copy for abuse control; for a link-opening receipt, the server immediately replaces the received identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic uses the identifier for app continuity, request and billing integrity, abuse prevention, security, support, and consented product analytics—not advertising or cross-app tracking. The app also sends and stores the device timezone so dated meals and account activity use the expected local day. Sign-in is optional. If you choose Apple, Google, or an email sign-in method, Clerk and the identity provider may send SelfMosaic an account or user identifier, email address, and name when the provider supplies them. SelfMosaic uses the identifier for authentication and account continuity, and uses a supplied name or email for account display, a one-time transactional account welcome email after the first verified account setup, requested contact, support, export, and deletion. The welcome email is a service message, not a marketing subscription. Billing entitlement is connected through viewer, account, and store identifiers—not your name or email. None of these details is used for advertising or cross-app tracking.

Read the detailProviders and locationsSelfMosaic operates from India. Selected providers process data in the United States.

SelfMosaic is operated from India. Outside providers support hosting, storage, AI food reasoning, optional sign-in, diagnostics, support email, optional analytics, and subscription billing. Some of those providers process data in the United States, so your information may be processed outside your country. Contact privacy@selfmosaic.app with questions about international transfers.

Read the detailAnalytics, email, and billingNo ad tracking. Optional analytics is consent-based; crash diagnostics stay on without raw kitchen photos.

Website analytics are off unless consent controls are available and enabled. Optional in-app product analytics stay off until you turn them on from Privacy in the app. If you choose to join the launch waitlist, SelfMosaic sends and stores the email address you enter, the app-scoped pseudonymous device identifier, the page or placement where you joined, a sanitized referrer path, and available UTM campaign values. SelfMosaic uses the email to send the launch update you requested, the device identifier to limit waitlist abuse, and the source details to understand which SelfMosaic launch surfaces work. Separately, after optional analytics consent, opening an App Store or Product Hunt link sends the device identifier and source details to create a launch-link receipt; the server immediately replaces that identifier with a daily scoped SHA-256 hash before storing the receipt. SelfMosaic does not share this information with advertising networks or use it for cross-app tracking. If you enable optional analytics, SelfMosaic's sanitized product events can include the current plan tier, a subscription package or product identifier, purchase or restore step and outcome, active-entitlement count, server-sync state, and a bounded failure category. PostHog receives those consented events, and Sentry can include the same consented event as a breadcrumb if a later diagnostic report is sent. These events contain no full payment-card data, store receipt, transaction token, or order reference and are used to understand subscription-flow reliability, not for advertising or cross-app tracking. Resend handles the one-time transactional account welcome, requested waitlist and launch updates, and support email delivery. Apple processes iOS payments and Google Play processes Android payments. When separately enabled, signed-in website checkout is processed by Paddle as merchant of record. RevenueCat carries the account-bound entitlement between those providers and SelfMosaic using details such as a pseudonymous App User ID, product, store, entitlement, expiration, cancellation, or refund status. SelfMosaic does not receive or store full payment-card data.

Retention

How long data stays.

These are maximum or normal windows, not promises to keep data for the full period.

At a glance

Retention by outcome

Original kitchen photos
Used for the request you start. Original bytes are not retained on SelfMosaic's servers.
AI retry data
Accessible for 24 hours and normally removed within 25 hours.
Support and AI-result reports
Scheduled for deletion or permanent redaction within 365 days; final cleanup normally finishes within one additional hour.
Email and launch-link records
Email delivery records are normally removed within 90 days plus one hour. Consented launch-link receipts are kept for 90 days and normally removed by the next daily cleanup.
Account deletion
Signs you out immediately; queued server cleanup is designed to finish in about 30 days.
Exports
Downloadable for up to 7 days, or sooner when the export contains expiring AI retry data.
Read exact retention and cleanup detail

For an exact replay, SelfMosaic temporarily stores a random request ID, a SHA-256 input digest, and the parsed ingredient read, meal-plan result, or recipe-visual result content for a 24-hour retry window. If recipe visuals are enabled, the generated image file and storage metadata use the same window and appear in your export while retained. The retry record never contains the original selected photo bytes. It becomes inaccessible after 24 hours and is cleared, including the generated image file, by the next hourly sweep, normally within 25 hours. Support-request content—including text submitted with an AI-result report—is scheduled for deletion or irreversible redaction within 365 days after submission and may be removed earlier. Final cleanup normally completes within one additional hour. SelfMosaic removes bounded email send and delivery-event records once they are older than 90 days through the next hourly sweep, normally within 90 days plus one hour; a record written by an email action already in flight follows the same sweep. When account deletion begins, SelfMosaic may temporarily keep copies of the exact pseudonymous RevenueCat App User ID already carried by restricted deletion, billing-event, webhook, and operator records while it creates a one-way billing-quarantine anchor or removes provider-linked billing data. These deletion-carried copies—including short-lived queued billing callback arguments—have a fixed, non-renewable 30-day recovery/provider-use deadline. After it, they are used only by bounded cleanup to locate and erase old copies; never for anchor creation or retry, provider calls, entitlement reconciliation, logging, or new durable state. Bounded cleanup starts immediately and erases them sooner when they are no longer needed. If scheduled redaction is delayed, physical redaction continues across the next bounded cleanup executions until complete; if anchor setup still fails, only cleanup waiting on that anchor is released. Unrelated export, support, or deletion stalls remain unchanged. The one-way anchor can remain for up to 30 days to quarantine delayed billing events and contains no raw provider identifier. New RevenueCat webhook metadata received later follows a separate lifecycle: it can temporarily include a provider identifier and event details, expires after 24 hours, and is normally removed within 25 hours. After account or preview deletion, viewer-owned server product data follows the deletion workflow and stated retention exceptions. The stable pseudonymous device identifier, device-level appearance and onboarding settings, and the optional analytics choice remain in local app storage. They contain no meal, prompt, or kitchen-photo content. If you use SelfMosaic again, the app may send the same device identifier during a new bootstrap, waitlist or support request, AI-result report, purchase or restore safety check, or consented link-opening receipt; it does not restore the deleted account data. Data exports normally stay downloadable for up to 7 days. When an export contains AI retry content, the whole export expires no later than the earliest included retry record. Each download rechecks identity, ownership, and the deadline; SelfMosaic does not expose a reusable storage link.

Your controls

Export, correct, or delete your data.

Start account deletion from More in the app when you can. Use the public deletion page or privacy inbox if sign-in is blocked, or if you need export, deletion, or data-handling help.

Rights, age, changes, and billing

Use the privacy inbox to ask for access, export, correction, or deletion. You can turn optional analytics off from Privacy in the app.

You must be at least 13 to use SelfMosaic. If local law requires a higher age or guardian permission, that stricter rule applies.

Important policy changes will be shown in the product before they affect you.

Deleting SelfMosaic data does not cancel a subscription. Manage or cancel App Store billing in Apple Subscriptions, Google Play billing in Google Play Subscriptions, or a website purchase from the management link in its Paddle receipt.

Ending a preview is not deletion

Ending a preview removes that session from the current device. It does not delete the preview's server data, and the next preview starts with a new server record. Use Clear my data before ending the preview if you want deletion. If you already ended it, contact the privacy inbox; SelfMosaic can help only where the old record can be securely matched.