Privacy Policy

AiSLE App Privacy Policy

Last updated: 20 April 2025

Welcome to AiSLE App, the AI‑powered meal‑planning and grocery companion. Your privacy matters to us. This Privacy Policy explains what data we collect, how we use it, the limited cases in which we share it, and the choices you have.

Heads‑up: AiSLE App is not a medical device. Our meal suggestions are for informational purposes only and are not medical or dietary advice.


1. Who We Are

AiSLE APP, LLC
4204 Six Forks Rd, Raleigh, NC 27609, USA
support@ai‑sle.app


2. Scope

This Policy applies to our:

  • Mobile & web apps (ai‑sle.app, TestFlight, PWA)
  • Browser extensions & APIs
  • Marketing sites, emails, and social channels

It does not cover third‑party services we link to (e.g., Instacart, Apple Health, Google Fit). Those services have their own policies.


3. Data We Collect

CategoryExamplesPurpose
Account DataName, email, password hash, OAuth tokens (Google / Apple ID)Account creation & login
Profile DataHeight, weight, age, dietary goals, allergies, ingredient likes/dislikesPersonalized meal plans
Device DataIP, mobile OS, browser, language, time‑zoneSecurity, localization
Usage DataLog files, clickstreams, swipe history, recipe ratingsApp analytics & AI model training
Pantry DataItems scanned, quantities, expiration datesInventory tracking & waste reduction
Health MetricsApple Health calories, step countsCalorie & macro adjustments
Payment DataLast 4 digits & tokenized payment ID from StripeSubscription billing
Support DataChat messages, screenshotsTroubleshooting & QA

We never store plain‑text passwords or full payment card numbers.


4. How We Use Data

  • Service delivery – generate meal plans, grocery lists, and Instacart carts
  • Personalization – adapt recommendations to your goals and feedback
  • Research & development – train our AI (de‑identified & aggregated)
  • Security – detect fraud, abuse, and unauthorized access
  • Marketing – send opt‑in newsletters, promotions, beta updates

We rely on the legal bases of contract performance, legitimate interests, and user consent (where required).


5. Sharing & Disclosure

RecipientReasonSafeguards
Cloud vendors (AWS/GCP)Hosting & data storageISO 27001 data centers, encrypted at rest
Payment processor (Stripe)BillingPCI‑DSS compliant, tokenization
Analytics (Plausible, PostHog)Usage insightsIP anonymization, no cross‑site tracking
Instacart APIBuild & sync cartsOAuth scope limited to cart creation
Regulators / law enforcementLegal obligations or to protect rightsOnly with valid subpoena or court order

We never sell your personal data.


6. Cross‑Border Transfers

We’re U.S.‑based. When we move data overseas, we rely on:

  • Standard Contractual Clauses (SCCs)
  • GDPR Art. 49 derogations (your explicit consent)

7. Data Retention

We keep personal data while your account is active and for up to 90 days after deletion (to satisfy audit & fraud checks) unless a longer period is required by law.


8. Your Rights

RegionRights
GDPR (EEA)Access, rectify, erase, restrict, object, data portability, lodge complaint
CCPA/CPRA (California)Know, delete, correct, opt‑out of “sale,” non‑retaliation
Other U.S. statesVirginia CDPA, Colorado CPA, Utah UCPA rights
GlobalEmail us to review or delete personal data

To exercise any right, email support@ai‑sle.app. We respond within 30 days.


9. Security

  • AES‑256 encryption at rest, TLS 1.3 in transit
  • Periodic penetration testing and dependency scanning
  • Role‑based access & MFA for employees
  • Incident response plan with 72‑hour breach notice (GDPR Art. 33)

10. Children’s Privacy

AiSLE App is not directed to children under 13 (or equivalent minimum age). We do not knowingly collect data from minors without verifiable parental consent (COPPA).


11. Changes to This Policy

We may update this Policy from time to time. Material changes will appear in‑app and on our website with a 14‑day notice before they take effect.


12. Contact Us

Questions? Email support@ai‑sle.app or write to the address above.