mogutto Privacy Notice

Delail LLC (“we”, “us” or “our”) provides the mogutto meal-planning and recipe-generation service (the “Service”). This notice explains how we handle information about people who use the Service.

We are the controller of the personal data described in this notice. Our company details are available on the Delail company website, and privacy enquiries can be sent to [email protected].

Last updated: 23 August 2026

1. Information we collect

We may collect the following information when you enter it, use the Service, connect an external service, contact us or communicate with our servers:

2. Why we use personal data

We use personal data to:

  1. provide meal plans, recipes, shopping lists, chat responses and other Service functions;
  2. create, authenticate and manage accounts;
  3. apply your preferences, allergies, avoided ingredients and dietary goals;
  4. provide paid features, check subscription status and validate purchases;
  5. answer enquiries, complaints and support requests;
  6. prevent misuse, secure the Service and enforce our Terms;
  7. investigate faults, analyse use, produce statistics and improve quality and features; and
  8. provide important service, contract and legal notices.

We do not use your information for third-party advertising, advertising tracking or marketing distribution.

3. Lawful bases and sensitive information for UK users

Where the UK GDPR applies, we rely on the lawful basis appropriate to each activity:

Allergy information, dietary restrictions, health goals and free-text content may reveal health information or other special-category data. Entering these fields is optional. Where special-category processing is based on consent, we request explicit consent before sending the information to an external AI provider.

AI output is not medical or allergy advice, and you must independently check ingredients, labels and authoritative information.

4. External services and AI providers

We use external services only as needed to provide and protect the Service.

Google services

We use Google services for authentication, hosting, storage, logging and optional analytics.

Apple services

We use Apple authentication and App Store services for authentication, in-app purchases, subscription status and purchase validation.

OpenAI API and Gemini API

We use OpenAI API and Gemini API services to generate meal plans, recipes and shopping lists, assist with recipe editing and provide chat responses.

Depending on the function you request, data sent to an AI provider may include household size, allergies or avoided ingredients, dietary goals, preferences, cooking equipment, generation conditions, free-text requests, saved recipes and chat content.

If you enter identifying, confidential or third-party information in a free-text or chat field, that information may be transmitted.

For safety and abuse prevention, OpenAI, the provider of the OpenAI API, may retain prompts and responses for up to 30 days, and Google, the provider of the Gemini API, may retain prompts and responses for 55 days.

5. Your AI consent choices

Before the first AI transmission, the app identifies the external providers, purpose and categories of entered data that may be sent. The consent is off by default and requires an affirmative action.

You can withdraw your consent or consent again at any time in Settings. After withdrawal, new meal-plan, recipe-generation and chat requests that require an external AI transmission are disabled by the server. You can continue to access functions that do not need a new AI transmission.

Withdrawal does not affect the lawfulness of processing completed before withdrawal. Minimal consent and withdrawal records may be retained for accountability and security until you delete your account or they are no longer needed.

6. Server logs and analytics

We use Cloud Logging and Google Analytics for Firebase for operation, security, fault investigation and quality improvement. These services may process IP addresses, timestamps, device and app information, interactions, errors and analytics identifiers.

Technical and analytics data may not be individually deleted immediately when an account is deleted and may remain until the applicable retention period ends.

7. Processors, disclosures and international transfers

We do not sell personal data. We disclose it only with consent, where required by law, to protect a person or property, as part of a business transfer, or to a provider processing it for the purposes described in this notice.

Google, Apple, OpenAI and other service providers may process data in countries outside your country of residence, including the United States. We use access controls, encryption, data minimisation and contractual protections appropriate to the service.

Where UK transfer rules apply, we use an applicable transfer mechanism, such as UK adequacy regulations or contractual safeguards including the UK International Data Transfer Agreement or UK Addendum, as appropriate. Contact us if you need information about the safeguard used for a particular provider.

8. Retention and account deletion

We generally retain account details, settings, saved preferences, meal plans, recipes, chats and shopping lists while your account remains active. Support correspondence is generally retained for three years after the enquiry is closed.

When you delete your account using the in-app function, principal data associated with the account is ordinarily deleted promptly. Technical logs, analytics, crash data, provider-held data, minimal purchase records and information needed for legal obligations, security, fraud prevention, fault investigation or disputes may remain for their applicable retention period.

9. Your rights

Depending on the law that applies, you may have rights to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, receive portable data, object to processing and complain to a supervisory authority.

Where processing is based on consent, you may withdraw that consent at any time. AI and analytics consent can be changed in Settings. Other requests can be sent to [email protected]. We may need to verify your identity and will respond within the period required by applicable law.

UK users may complain to the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you do not have to contact us before contacting the ICO.

10. Security

We use organisational and technical measures designed to prevent unauthorised access, misuse, loss or disclosure, including access controls, encryption in transit, cloud configuration controls, credential management and supplier oversight. If a personal-data breach occurs, we will take the steps required by applicable law.

11. Children

The Service is not directed specifically to children.

12. Changes and contact

We may update this notice when laws, the Service or our data practices change. We will notify you of material changes through the Service or another appropriate method and request consent where required.

For privacy questions, rights requests, complaints or account-deletion support, contact [email protected].

13. Consumer health data

You may voluntarily save allergy information and other health-related meal considerations as meal settings. External AI data-sharing consent is required before entered content is sent to an AI service. You can edit or delete saved settings, and withdrawing AI data-sharing consent disables new AI generation and chat without deleting those settings. Details and U.S. consumer health rights are described in our Consumer Health Data Privacy Policy.