Mealsphere Privacy Policy
This policy explains how Mealsphere handles your private food library, optional community activity, location, menu photo recognition, subscriptions, and support requests.
1. Private Library and iCloud Sync
Mealsphere stores a local copy of your mealspheres, frequent places, dishes, specifications, evaluations, reviews, dish photos, meal history, preferences, tasting progress, community import records, feedback, and saved locations. When iCloud is available, this content synchronizes across your Apple devices through your private iCloud/CloudKit database. You do not need a Mealsphere community account to use these private features. Sync availability depends on your iCloud account, network connection, storage, and Apple services.
Your private library is not automatically published to the community. Tasting progress, evaluations, reviews, dish photos, meal history, private mealsphere boundaries and addresses, and your private record identifiers are not included in a community publication.
2. Community Browsing and Nearby Results
You can browse and download public mealspheres without signing in. If you allow location access and choose the Nearby list, Mealsphere rounds your foreground location to an approximately one-kilometer area and sends that coarse coordinate to the Mealsphere community service to sort nearby results. The service uses the coordinate to answer that request and does not store it in the community database.
A downloaded public mealsphere becomes a private copy in your library and may sync through your private iCloud database. Later changes or deletion by the original publisher do not automatically remove a copy that another person has already downloaded.
3. Community Account and Sign in with Apple
Publishing, updating, removing, restoring, reporting, and syncing account-level blocks require a community account created with Sign in with Apple. Mealsphere processes the Apple authorization result and a protected identifier derived from your Apple account to authenticate you. The service stores a cryptographic hash of that identifier rather than the original value. Mealsphere does not request your Apple name or email address. A fixed public nickname such as “食友000001” is assigned in registration order for community display and cannot be customized. Numbers are not reused after account deletion.
Access credentials, refresh credentials, and session records are protected or hashed and are used only to maintain account sessions, authorize community actions, prevent abuse, and support account security.
4. Content You Publish
Publishing is an explicit action. A publication may include the mealsphere name and type, an intentionally rounded community location, frequent-place names and attributes, place locations that you choose to publish, and dish names, prices, and specifications. This information becomes public and can be browsed or downloaded by other Mealsphere users.
Before publishing, review names, locations, and menu information and remove anything you do not want to make public. Do not publish sensitive personal information, private addresses, or content that you do not have permission to share.
5. Reports, Blocks, and Moderation
When you submit a report, Mealsphere processes the publication identifier, report reason, optional details, time, and either your signed-in community account identifier or a cryptographic hash of a random app-scoped device identifier. The publisher does not receive the reporter's identity. Reports are stored in the community database and sent to the support mailbox so they can be reviewed. Moderator actions record limited audit information such as the report, action, reason, moderator identity, and time.
Signed-in blocks can synchronize with your community account. Anonymous blocks remain on the device. Mealsphere may filter, restrict, unpublish, or remove content and may restrict accounts when reasonably necessary to enforce the Terms, protect users, or comply with law.
6. Menu Photo Recognition
When you have access to Menu Photo Recognition and choose to scan or import a menu, the app compresses the selected image and sends it with request information such as image type, preferred language, and app version to the Mealsphere Cloudflare Worker. The Worker forwards the image and recognition instructions to BigModel/GLM to identify dish names, prices, and specifications.
Recognized text and editable dish rows return to the app for your review before saving. Do not submit images containing sensitive personal information. Menu recognition images and results are not published to the community unless you later choose to publish the resulting dish information.
7. Location, Camera, Photos, and Apple Maps
Location access is optional and is used only while the app is in use for nearby community results, mealsphere switching prompts, map setup, and distance-aware recommendations. Mealsphere does not request background or Always Location access. You can deny location access and enter or select locations manually.
The app accesses the camera or photo library only when you choose to scan or import a menu or add or change a dish photo. Saved dish photos remain part of your private library. Apple may process map searches, map interactions, and selected locations through MapKit and Apple Maps under Apple's own privacy practices.
8. Subscriptions and Payments
Menu Photo Recognition is purchased and managed through Apple App Store. Apple handles payment, renewal, refund, and cancellation information. Mealsphere receives the subscription entitlement needed to unlock the feature but does not receive your full payment-card details.
9. How We Use and Share Data
Mealsphere uses data only to provide the features you request, synchronize your private library, authenticate and secure community accounts, publish and deliver community content, process reports and blocks, provide menu recognition, manage subscription access, troubleshoot failures, prevent abuse, and meet legal obligations.
Service providers process data only for these functions: Apple provides private CloudKit sync, Sign in with Apple, StoreKit, MapKit, and Apple Maps; Cloudflare hosts the community service, recognition gateway, and legal/support pages; BigModel/GLM processes menu recognition requests. Mealsphere does not sell personal data and does not use third-party advertising or cross-app tracking SDKs.
10. Retention, Deletion, and Your Choices
- You can delete private library items in the app; the deletion is then synchronized through your private iCloud database when available.
- You can unpublish, restore, or permanently remove your own community publications from the app.
- You can sign out of the community account without deleting your private library.
- You can delete the community account in the app after reauthenticating with Apple. This revokes the associated Apple credential when possible and removes the account, active sessions, community publications, reports, and synchronized blocks from the community service. It does not cancel an App Store subscription or erase private iCloud data.
- Copies that other users downloaded before a publication or account was deleted remain in their private libraries and cannot be remotely recalled by Mealsphere.
- Report, moderation, security, and diagnostic records are retained only as reasonably necessary to investigate abuse, protect the service, resolve disputes, and comply with legal obligations, after which they are deleted or de-identified where practicable.
You can also disable permissions in iOS Settings, manage subscriptions through Apple, and contact us to ask about privacy or deletion. Removing the app from one device removes its local copy but does not by itself erase records already stored in your private iCloud database.
11. Security and International Processing
Mealsphere uses measures such as HTTPS, protected secrets, hashed identifiers and credentials, access controls, and limited public-data fields. No system can guarantee absolute security. Apple, Cloudflare, and BigModel/GLM may process data in locations where they operate, subject to their terms and applicable safeguards.
12. Changes and Contact
We may update this policy when Mealsphere's features or legal obligations change. The effective date above identifies the current version. For privacy questions or requests, contact lendfuz524@gmail.com.