Effective date: July 6, 2026
Privacy Policy
We believe your data is yours. Here is exactly what we collect, why, and how we protect it.
1. Who We Are
Meringue is operated by Everywhen Software LLC. When this policy refers to “we,” “us,” or “our,” it means Everywhen Software LLC. If you have questions about this policy, contact us at hello@lemondroplabs.io.
2. Information We Collect
Account information
Meringue uses Sign in with Google, Sign in with Apple, or an emailed sign-in link or code for authentication. When you connect a Google or Apple account, we receive and store your name, email address, and (for Google) your profile photo URL solely to create and identify your account. If you sign in with an emailed link or code, we store only your email address. If you use Apple’s Hide My Email feature, we store the private relay address Apple provides instead of your personal email. We never receive your Google or Apple password, or any data beyond what is needed to create your account.
Content you create
We store all content you add to the Service on your behalf, including:
- Recipes (title, ingredients, instructions, notes, tags)
- Pantry items and quantities
- Meal plan entries
- Shopping list items
- Recipe photos you upload
- Diet preferences and allergen selections you configure in Settings
This content is linked to your account and is private by default. It becomes visible to other people only when you choose to share it, through household sharing or a share link (both described below). Diet and allergen preferences are stored solely to power the in-app filtering feature; we do not use this information for any other purpose, and we do not share or sell it.
Household sharing
If you create or join a household, some of your content is shared with its members (up to 6 people): the household uses one shared pantry, one shared shopping list, and one shared meal plan, and recipes and cookbooks marked as shared are visible to every member. If you leave a household or are removed from one, your recipes and cookbooks revert to private.
Share links
Creating a share link for a recipe or shopping list makes that page viewable by anyone who has the link, and shared recipe pages may appear in search engines. Removing the share link (or deleting the recipe or list) makes the page unavailable.
Automatically collected data
Like most web services, our servers receive standard technical information when you use the app: IP address, browser type, operating system, and timestamps. We use this data only to operate and debug the Service, not to build profiles or for advertising.
3. How We Use Your Information
We use the information we collect to:
- Create and maintain your account.
- Display your recipes, pantry, meal plan, and shopping list to you.
- Process subscription payments and manage your billing.
- Send transactional emails (account confirmation, subscription receipts, expiry notices).
- Investigate and fix bugs or security issues.
- Comply with legal obligations.
We do not sell your data. We do not use your content to train machine learning models. We do not show you ads.
4. Cookies and Session Storage
Meringue sets a single first-party session cookie named mr_session when you sign in. This cookie contains a signed JWT that identifies your session and expires after 7 days. It is used solely to keep you signed in between page loads; it is not used for tracking or advertising.
With your consent we load Vercel Analytics, a cookieless analytics service that measures aggregate usage (such as page views), and PostHog, which records product usage events (such as saving a recipe or filling a meal plan) tied to your account so we can understand how Meringue is used. Neither uses tracking cookies, pixel trackers, or fingerprinting, and neither is shared with advertisers. We ask for this consent through a notice the first time you visit; your choice is saved in your browser under the meringue_cookie_consent key, and neither runs unless you accept. You can change your choice at any time using the Cookie preferences link in the footer of this page.
We also use Sentry for error monitoring, which runs regardless of the cookie choice above since it is necessary to keep the Service reliable and secure, not for analytics or advertising. Sentry may capture a masked, non-identifying session replay (all text and media are blocked) when an error occurs, and never your email address.
5. Third-Party Services
We use a small number of trusted third-party services to operate Meringue:
- Google OAuth and Sign in with Apple: handle sign-in authentication. Each is governed by its provider’s privacy policy.
- Vercel Analytics: privacy-friendly, cookieless aggregate usage analytics, loaded only after you accept the cookie notice (see Section 4). Governed by Vercel’s privacy policy.
- PostHog: product usage analytics tied to your account, loaded only after you accept the cookie notice (see Section 4). Never receives your email address. Governed by PostHog’s privacy policy.
- Sentry: error monitoring, so we can detect and fix bugs. Runs regardless of the cookie notice since it is a security and reliability function, not analytics. Governed by Sentry’s privacy policy.
- Supabase: hosts our PostgreSQL database where your account data and app content are stored. Servers are located in the US.
- Amazon Web Services (S3 + CloudFront): stores and delivers recipe photos you upload.
- Anthropic: powers AI features such as recipe extraction and nutrition estimation. When you import a recipe, the content you provide is sent to Anthropic’s API to generate results: the text of the recipe or page for URL imports, the photo itself for photo imports, and the video’s captions for video imports. Anthropic does not use your data to train its models. Governed by Anthropic’s privacy policy.
- Resend: delivers transactional email, such as sign-in links and codes, to your email address. Governed by Resend’s privacy policy.
- Upstash: provides short-lived operational storage for security features such as rate limiting, sign-in codes, and duplicate-event protection, which can briefly include your email address. Governed by Upstash’s privacy policy.
- RevenueCat: manages subscription status. Payments are billed by Apple or Google, and we never receive or store your full payment card details; RevenueCat receives your account identifier and purchase events so we can unlock Premium. Governed by RevenueCat’s privacy policy.
Each of these providers has its own privacy policy, and data shared with them is limited to what is necessary to provide the Service.
6. Data Storage and Security
Your data is stored on servers in the United States. We use industry-standard measures to protect your data, including encrypted connections (HTTPS), signed session tokens, and access controls on our database. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security, but we take reasonable precautions to protect your information.
7. Data Retention
We retain your data as long as your account is active. If your subscription lapses, your data is retained for 30 days to allow for resubscription. After 30 days of non-payment, your account and all associated data may be permanently deleted.
Deleting a single recipe moves it to the trash, where you can restore it for 30 days. After 30 days it is permanently removed, along with any photo you uploaded for it.
If you delete your account through the app, your data is permanently removed from our active systems. Backups may retain your data for up to 30 additional days before they are rotated out.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate data.
- Deletion: delete your account (and all associated data) at any time from your account settings, or by emailing us.
- Portability: request an export of your recipe and app data in a machine-readable format.
- Opt-out of marketing: we send very few emails; you can unsubscribe from any non-transactional email using the link in the email.
To exercise any of these rights, email hello@lemondroplabs.io. We will respond within 30 days.
9. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that we have collected information from a child under 13, we will delete it promptly. If you believe we may have information about a child, please contact us.
10. International Users
Meringue is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. By using the Service, you consent to this transfer. We take steps to ensure your data is protected in accordance with this policy regardless of where it is processed.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will notify you by email or through a prominent notice in the app before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the updated policy.
12. Contact
If you have questions or concerns about this Privacy Policy or how we handle your data, please email us at hello@lemondroplabs.io.
Terms of Service · Copyright · · Sign in