Mangello
Back

Last updated August 2026

Privacy Policy

1. Who we are

Mangello is a grocery and recipe app for iPhone and the web. This policy explains what data the app collects, why, who processes it, and how to delete it. Contact details for privacy requests are listed on our App Store listing.

2. Data we collect

  • Account data. Your email address and password (stored hashed by our authentication provider), plus the date your account was created.
  • Profile data. Display name, emoji, and an optional profile photo you upload.
  • Scan data. Photos you take or choose for a grocery scan are sent to our server and on to our AI provider for analysis. We do not store the photo itself; we store only a per-day/per-month scan counter for your account so we can enforce your scan allowance.
  • Recipe and voice input. Text you type or dictate (recipe searches, ingredient lists) is sent to our server and AI provider to generate a result. Speech is converted to text by Apple's on-device/system speech recognition; we receive only the resulting text.
  • Subscription data. If you subscribe, Apple processes the payment. We and our subscription provider receive a purchase/entitlement record tied to an anonymous subscriber id matched to your account. We never receive your payment card details.

3. Data kept only on your device

Your grocery lists, pantry items, family members, locally saved recipes and reminders are kept in the app on your device and are not uploaded to our servers. Deleting the app removes them.

4. Publicly visible information

Profile photos are stored in a publicly readable storage bucket: anyone who has the direct file URL can view the image, so please do not upload anything you consider private. Your email address is never shown to anyone else. Mangello does not currently include a public feed, comments or any other way for users to see each other's content.

5. How we use your data

We use your data only to operate the app: to sign you in, to show your profile, to produce scan and recipe results, to enforce your scan allowance and subscription status, and to fix bugs. We do not sell your personal information, we do not use it for advertising, and we do not use third-party advertising or cross-app tracking SDKs.

6. Third parties who process data

  • Supabase (via Lovable Cloud) — hosts our database, authentication and file storage.
  • Lovable AI Gateway / Google Gemini — processes scan images and recipe prompts to generate results.
  • RevenueCat and Apple — process and validate App Store subscription purchases.

These providers act on our behalf under their own security and privacy commitments. We share only what is needed for the feature you used. Before your first AI request the app asks for your explicit permission to send content to the AI provider; if you decline, scans and AI recipes stay switched off and the rest of the app keeps working.

7. Device permissions

  • Camera / Photos — used only when you start a grocery scan or pick a profile photo. Images are used for that action alone.
  • Microphone / Speech recognition — used only while you hold or start voice capture, to turn speech into grocery items.
  • Notifications — used only for reminders you create.

Every permission is optional. If you decline, the related feature falls back to manual typing or entry and the rest of the app keeps working.

8. Retention and deletion

Account, profile and scan-count data are retained while your account exists. You can permanently delete your account at any time from You → Danger zone → Delete my account. Deletion runs on our server: it removes every file you uploaded (profile photo, recipe media) through the storage service, then deletes your account, profile and scan counters. It is immediate and irreversible. Deleting your account does not cancel an App Store subscription — cancel that in Settings → Apple Account → Subscriptions. Purchase records held by Apple and our subscription provider are retained by them for their own legal and accounting obligations.

9. Security

Data is transmitted over HTTPS and stored with per-user access rules so one account cannot read another account's private data. Files in public buckets are readable by URL by design (see section 4). No system is perfectly secure, but we apply industry-standard measures.

10. Children

Mangello is not directed at children under 13 and we do not knowingly collect their personal information. Contact us if you believe a child has created an account and we will delete it.

11. Your rights and contact

You can access and correct your profile in the app, and delete all of your data from the Profile page. For any other privacy request, use the support contact published on our App Store listing; we aim to respond within 30 days. If we change this policy we will update the date at the top of this page.