mogutto Privacy Notice
Delail LLC (“we”, “us” or “our”) provides the mogutto meal-planning and recipe-generation service (the “Service”). This notice explains how we handle information about people who use the Service.
We are the controller of the personal data described in this notice. Our company details are available on the Delail company website, and privacy enquiries can be sent to [email protected].
Last updated: 23 August 2026
1. Information we collect
We may collect the following information when you enter it, use the Service, connect an external service, contact us or communicate with our servers:
- Account and authentication data: email address, user ID, display name, profile details and information supplied by an authentication provider.
- Food preferences and potentially health-related data: household size, allergies, ingredients to avoid, disliked foods, preferences, dietary goals, dietary restrictions, cooking equipment and free-text requests.
- Content created or stored in the Service: generation conditions and history, meal plans, recipes, ingredients, instructions, shopping lists, saved preferences, chat messages and AI responses.
- Subscription and purchase data: subscription status, product information, transaction identifiers and information about purchases, renewals, cancellations and refunds.
- Support data: email address, enquiry content, correspondence and information needed to verify your identity.
- Technical data: IP address, device, operating-system and app information, timestamps, interactions, errors, crashes, analytics identifiers and other technical logs.
2. Why we use personal data
We use personal data to:
- provide meal plans, recipes, shopping lists, chat responses and other Service functions;
- create, authenticate and manage accounts;
- apply your preferences, allergies, avoided ingredients and dietary goals;
- provide paid features, check subscription status and validate purchases;
- answer enquiries, complaints and support requests;
- prevent misuse, secure the Service and enforce our Terms;
- investigate faults, analyse use, produce statistics and improve quality and features; and
- provide important service, contract and legal notices.
We do not use your information for third-party advertising, advertising tracking or marketing distribution.
3. Lawful bases and sensitive information for UK users
Where the UK GDPR applies, we rely on the lawful basis appropriate to each activity:
- Contract: to create and manage your account, provide requested Service functions and administer a subscription.
- Consent: to send entered content to an external AI provider and to collect optional analytics data.
- Legitimate interests: to secure and operate the Service, prevent misuse, diagnose faults, provide support and improve the Service, where those interests are not overridden by your rights.
- Legal obligation: where processing is necessary to comply with applicable law.
Allergy information, dietary restrictions, health goals and free-text content may reveal health information or other special-category data. Entering these fields is optional. Where special-category processing is based on consent, we request explicit consent before sending the information to an external AI provider.
AI output is not medical or allergy advice, and you must independently check ingredients, labels and authoritative information.
4. External services and AI providers
We use external services only as needed to provide and protect the Service.
Google services
We use Google services for authentication, hosting, storage, logging and optional analytics.
Apple services
We use Apple authentication and App Store services for authentication, in-app purchases, subscription status and purchase validation.
OpenAI API and Gemini API
We use OpenAI API and Gemini API services to generate meal plans, recipes and shopping lists, assist with recipe editing and provide chat responses.
Depending on the function you request, data sent to an AI provider may include household size, allergies or avoided ingredients, dietary goals, preferences, cooking equipment, generation conditions, free-text requests, saved recipes and chat content.
If you enter identifying, confidential or third-party information in a free-text or chat field, that information may be transmitted.
For safety and abuse prevention, OpenAI, the provider of the OpenAI API, may retain prompts and responses for up to 30 days, and Google, the provider of the Gemini API, may retain prompts and responses for 55 days.
5. Your AI consent choices
Before the first AI transmission, the app identifies the external providers, purpose and categories of entered data that may be sent. The consent is off by default and requires an affirmative action.
You can withdraw your consent or consent again at any time in Settings. After withdrawal, new meal-plan, recipe-generation and chat requests that require an external AI transmission are disabled by the server. You can continue to access functions that do not need a new AI transmission.
Withdrawal does not affect the lawfulness of processing completed before withdrawal. Minimal consent and withdrawal records may be retained for accountability and security until you delete your account or they are no longer needed.
6. Server logs and analytics
We use Cloud Logging and Google Analytics for Firebase for operation, security, fault investigation and quality improvement. These services may process IP addresses, timestamps, device and app information, interactions, errors and analytics identifiers.
- Cloud Logging data is retained for the period determined by Google Cloud settings and specifications.
- Google Analytics for Firebase user-level and event-level data is generally retained for no more than 14 months.
Technical and analytics data may not be individually deleted immediately when an account is deleted and may remain until the applicable retention period ends.
7. Processors, disclosures and international transfers
We do not sell personal data. We disclose it only with consent, where required by law, to protect a person or property, as part of a business transfer, or to a provider processing it for the purposes described in this notice.
Google, Apple, OpenAI and other service providers may process data in countries outside your country of residence, including the United States. We use access controls, encryption, data minimisation and contractual protections appropriate to the service.
Where UK transfer rules apply, we use an applicable transfer mechanism, such as UK adequacy regulations or contractual safeguards including the UK International Data Transfer Agreement or UK Addendum, as appropriate. Contact us if you need information about the safeguard used for a particular provider.
8. Retention and account deletion
We generally retain account details, settings, saved preferences, meal plans, recipes, chats and shopping lists while your account remains active. Support correspondence is generally retained for three years after the enquiry is closed.
When you delete your account using the in-app function, principal data associated with the account is ordinarily deleted promptly. Technical logs, analytics, crash data, provider-held data, minimal purchase records and information needed for legal obligations, security, fraud prevention, fault investigation or disputes may remain for their applicable retention period.
9. Your rights
Depending on the law that applies, you may have rights to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, receive portable data, object to processing and complain to a supervisory authority.
Where processing is based on consent, you may withdraw that consent at any time. AI and analytics consent can be changed in Settings. Other requests can be sent to [email protected]. We may need to verify your identity and will respond within the period required by applicable law.
UK users may complain to the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you do not have to contact us before contacting the ICO.
10. Security
We use organisational and technical measures designed to prevent unauthorised access, misuse, loss or disclosure, including access controls, encryption in transit, cloud configuration controls, credential management and supplier oversight. If a personal-data breach occurs, we will take the steps required by applicable law.
11. Children
The Service is not directed specifically to children.
12. Changes and contact
We may update this notice when laws, the Service or our data practices change. We will notify you of material changes through the Service or another appropriate method and request consent where required.
For privacy questions, rights requests, complaints or account-deletion support, contact [email protected].
13. Consumer health data
You may voluntarily save allergy information and other health-related meal considerations as meal settings. External AI data-sharing consent is required before entered content is sent to an AI service. You can edit or delete saved settings, and withdrawing AI data-sharing consent disables new AI generation and chat without deleting those settings. Details and U.S. consumer health rights are described in our Consumer Health Data Privacy Policy.