TinyPlate is built by TinyPlate LLC. This policy explains what we collect, why, and what you can do about it. Plain English, no dark patterns.
The app stores the minimum we need to help you plan safe meals for your child:
We do not collect: photos of your child, location, or contact list. We use an analytics tool (PostHog) to understand how the app is used. See "Who sees the data" below for exactly what it receives, including the one piece of your child's health information that reaches it.
This section is about the tinyplate.app website (this landing site, blog, and the safe-food checker), not the app itself. To understand how people find us and measure whether our ads work, our website uses two kinds of tools.
We use PostHog, Inc. (United States) for privacy-focused analytics: page views, clicks, and aggregate usage. PostHog records technical data such as your IP address, browser type, the page you viewed, and the referring page, and sets first-party cookies to keep a session together. PostHog does not receive your child's name, allergies, or meal data. See posthog.com/privacy.
Our website uses the Meta Pixel and Meta Conversions API (from Meta Platforms, Inc.) so we can measure and optimize the ads we run on Facebook and Instagram. When you visit a page, the Meta Pixel may share with Meta that you viewed a page (and which one), your IP address and browser user-agent, and Meta advertising cookies set in your browser (the _fbp cookie, and _fbc if you arrived from a Facebook or Instagram ad), which act as a device or click identifier.
In addition, if you give us your email on our website (for example, on the safe-food checker's email step or at checkout), our server may send that email to Meta through the Conversions API in hashed (SHA-256) form, along with the same IP address, user-agent, and Meta cookies. Hashing scrambles the email before it leaves our server; Meta uses it only to match the event for ad measurement. We never send your child's name, age, allergies, or any meal or health information to Meta.
We use these tools for advertising measurement and optimization and, where permitted, retargeting. For ad measurement, Meta acts as an independent or joint controller under its own Business Tools terms; how Meta uses data it receives is governed by Meta's Privacy Policy.
The TinyPlate iOS app also uses the Meta SDK so we can measure whether the ads we run on Facebook and Instagram actually bring people to the app. The first time you open the app, iOS asks your permission (the App Tracking Transparency prompt) before we're allowed to use your device's advertising identifier for this. If you decline, we don't collect it, and the app works exactly the same either way. If you allow it, the app shares your device's advertising identifier with Meta, along with app events like starting a free trial or completing a purchase, so we can attribute installs and measure ad performance. We never send your child's name, age, allergies, or any meal or health information to Meta.
These advertising and analytics cookies are optional. You can opt out for this browser using our Do Not Sell or Share My Personal Information control below, and we honor your browser's Global Privacy Control signal as an opt-out. You can also adjust your Meta ad settings at facebook.com/adpreferences/ad_settings or opt out of interest-based ads at optout.aboutads.info (US) or youronlinechoices.eu (EU/UK).
TinyPlate uses AI to build your weekly plans, to adjust a plan when you ask for a swap, and to answer your feeding questions in chat. Here is exactly what that means, because this is the part of the app that touches your child's information most directly.
What we send. Your child's age in months, the allergens you've told us about, their reaction history for those allergens (whether each one has been tolerated, caused a mild or moderate reaction recently, caused a severe reaction, or hasn't been tried yet), your pantry list, which recipes your child has loved or refused, your cuisine preferences, your current week's plan when you ask for a swap, and the text of any question or swap request you type. We send the allergens because that is what stops the AI from suggesting something your child reacts to.
What we don't attach. We never attach your child's name, your child's date of birth, your name, or your email to an AI request. From your saved profile, the only identifying detail the AI gets is an age in months. The allergens go too, as listed above, because they are what keeps the suggestions safe. One exception, and it's in your hands: the questions you type in chat and the swap requests you write are sent to the AI exactly as you typed them. If you type your child's name into the message box, it goes along with it. If you'd rather it didn't, just say "my daughter" or "my son" instead.
Who receives it. Groq, Inc. (United States) and OpenAI, L.L.C. (United States). They process it only to return an answer to us.
What the AI does not decide (for plans). When we build or adjust a plan, allergen and age filtering happen in our database before the AI sees a recipe, so anything containing your child's allergens is already gone. The AI arranges a plan from recipes that are already safe, and it cannot invent a recipe or reach outside that list. Every meal it suggests is a suggestion: you review the plan, you can swap any meal, and nothing reaches your child without you.
Chat is different, and you should know how. The feeding coach in chat is a language model answering in its own words, not picking from a filtered list. We tell it your child's allergens and age and instruct it not to suggest anything unsafe, but it is not bound by the database filter the way the meal planner is. Treat its answers as general guidance, check the in-app safety checker for anything you're unsure about, and check with your pediatrician when it matters.
Preferences. We score which recipes your child tends to love or refuse, based on the reactions you log, and use those scores to bias future suggestions. That is the whole extent of it. We don't build a profile of your child for any other purpose.
TinyPlate is designed for parents and caregivers, not children. Children do not create accounts, upload content, or interact with the app directly. Information about your child is information you provide. You have the right to:
If you are under 13 years of age, do not use this app.
Your data stays as long as your account exists. When you delete your account, your sign-in is destroyed immediately: you're locked out at once and cannot recover the account through the app. Your child, pantry, meal, and allergy records are then held for 30 days before they are permanently purged. That window exists as a safety net, so that if you deleted by mistake you can email contact@tinyplate.app within those 30 days and we can put it back. After the purge, data may persist in Supabase backups for up to 30 more days before those roll off. If you want it gone immediately rather than after the grace window, say so in that email and we'll purge it by hand.
You can, at any time, email contact@tinyplate.app to:
If you're in the EU/UK: you have additional rights under GDPR (rectification, objection, erasure, and the right to withdraw consent). Exercise them via the same email. Our legal basis for running the app is your consent (signing up and acknowledging the disclaimer) and our legitimate interest in providing the service. Our legal basis for advertising and analytics cookies on the website is your consent, which you can withdraw anytime using the controls in "Advertising & analytics." For Meta's advertising tools, Meta acts as an independent or joint controller as described above.
We do not sell your personal information for money. However, the Meta advertising tools on our website (the Meta Pixel and Conversions API) share online identifiers (the _fbp / _fbc cookies), your IP address, and, if you provide it, a hashed email address with Meta for cross-context behavioral advertising. Under the CCPA as amended by the CPRA, that is treated as a "share" (and may be treated as a "sale"). We do not knowingly sell or share the personal information of consumers under 16.
If you are a California resident, you have the right to know what personal information we collect, to access, correct, or delete it, to opt out of its sale or sharing, and not to be discriminated against for exercising these rights.
Do Not Sell or Share My Personal Information — selecting this turns off our advertising tools for this browser. We also honor your browser's Global Privacy Control (GPC) signal automatically. For any other request, email contact@tinyplate.app with "Privacy Request" in the subject line.
We'll update this page when material changes happen. The effective date above will change. If the changes materially affect your rights, we'll notify the email on your account.
Email contact@tinyplate.app. General questions also: admin@tinyplate.app. For data-protection or deletion requests, please include "Privacy Request" in your subject line so we can prioritize.