Mealumo
Privacy Policy
Effective September 27, 2026
IBRDOS Co., Ltd. (“we”) processes personal information to provide Mealumo accounts, meal records, nutrition estimates, and recommendations.
1. Information and purposes
| Category | Information | Purpose |
|---|---|---|
| Account and authentication | Email, random account ID, verification-code hashes, request and expiry times, session-secret hashes | Sign-in, identity checks, account deletion, security |
| Profile | Birth year, sex used for nutrition references, height, weight, activity, goals, country, language, time zone, dietary preferences, allergies, nutrient targets | Nutrition references, settings and sync, relevant recommendations |
| Meals and photos | Selected photos, food names, meal times, portions, estimated nutrients, notes, ingredients, allergens, edits | Meal records, photo analysis, totals, editing and export |
| Recommendations and processing | Requests and preferences, country and language, results, job status, usage counters, error types, AI response IDs and processing usage | Delivering results, limits, error recovery, duplicate prevention |
| Purchases | Store, product ID, transaction ID or purchase token, subscription status and expiry, account-linking identifiers | Pro access, verification, restoration, refunds, preventing purchase reassignment |
| Notifications | Device identifiers, push tokens, language, time zone, notification choices, associated session | Optional result alerts and notification settings |
| Choices, support, and security | Individual consent choices, notice version and server timestamp, details supplied in support messages, request IDs and error times, IP/email hashes used for rate limits | Recording consent and withdrawal, support, security and abuse prevention |
We do not receive payment-card numbers or store passwords. Apple or Google processes your payment method. The app does not use device-location permission; you select the country for recommendations. Advertising providers may infer a general location from an IP address.
Profiles and manual records created without signing in are stored on your device. Connecting an account can sync those records to that account. Session credentials use the operating system’s secure storage; meal records, settings, and pending photos use app storage. Copies you export or share are controlled at their destination, including any device backups you manage.
2. Health information and your choices
We treat allergies, body information, and records that reveal health information as sensitive. Health-data consent is separate from AI-processing and overseas-transfer consent. Saving, editing or copying profiles and meals in an account requires health-data consent. Uploading photos, requesting AI analysis, and requesting recommendations require all three. Declining these choices prevents the corresponding features while existing records remain available for viewing, export, and deletion.
You may change consent settings or contact dev@ibrdos.com to request restriction or deletion. Withdrawal applies after the server records it. Requests already sent to a provider cannot be recalled retroactively. Queued work is checked again before execution. Withdrawal does not itself erase existing records; use account deletion or make a separate deletion request.
South Korea’s Personal Information Protection Act, Article 23 addresses separate consent for sensitive information, and Article 28-8 addresses overseas transfers.
3. AI processing
Photo analysis sends your selected photo and response language to OpenAI. It assumes you consumed the visible food and creates a meal record with estimates for 25 nutrient fields without an additional confirmation step. You can correct the resulting record and portions.
Personalized recommendations send dietary preferences, allergies, your request, goals, nutrient targets, and the day’s meal count and nutrient totals. Raw birth year, sex, height, and weight are not directly included in recommendation prompts, although calculated targets can reflect that information. AI requests do not include your email, sign-in credentials, or payment information.
Local-brand recommendations first research public menus using country and language. Health information, meal history, and free-text preferences are excluded from that search stage. A separate request without search tools then applies your preferences and daily totals.
We use OpenAI’s store:false setting to disable response application-state storage. It is not a zero-retention guarantee: default abuse-monitoring logs may retain inputs and outputs for up to 30 days, with legal or safety exceptions. OpenAI states API data is not used for model training unless sharing is explicitly enabled. See OpenAI’s API data controls.
4. Service providers and international processing
Our primary application storage is in the AWS Seoul region. Necessary information is transferred over encrypted connections when the relevant feature runs.
| Provider and contact | Processing and information | Location and timing | Retention |
|---|---|---|---|
| Amazon Web Services, Inc. · Privacy | Account, meal, photo, API, job, security and backup services | Primary storage: Seoul, South Korea; during service use | Account lifetime and the deletion/backup periods below |
| OpenAI · Privacy requests | Photo analysis, personalized recommendations and public research described above | United States and subprocessors’ operating countries; when AI is requested | Default abuse logs up to 30 days, subject to legal/safety exceptions |
| Plus Five Five, Inc. (Resend) · support@resend.com | Recipient email, verification code, email content and delivery result | United States; when requesting sign-in or deletion email | As necessary for delivery, security and legal obligations under Resend’s policy |
| 650 Industries, Inc. (Expo) · Contact | Push token, generic alert, job ID and type | United States; when an enabled result alert is sent | Time needed to deliver the alert; Expo push documentation |
| Apple and Google · Apple privacy, Google privacy | Transaction and device identifiers for purchase verification and notification delivery | United States and their operating countries; on purchase checks and notifications | Their transaction, security and legal retention policies |
| Google (AdMob) · Privacy | Advertising and device information described below | United States and Google’s operating countries; when requesting an ad | Advertising, measurement, security and Google’s applicable retention policies |
OpenAI’s published API subprocessors operate in the United States, Canada, United Kingdom, Ireland, France, Germany, Italy, Netherlands, Norway, Spain, Sweden, Switzerland, Poland, Finland, Australia, Brazil, Mexico, India, Indonesia, Japan, Malaysia, Singapore, South Africa, United Arab Emirates, Philippines, and South Korea. Network delivery may use a nearby data center. This does not mean every request is processed in every country. Consult the OpenAI subprocessor list for activities and changes.
AI overseas processing relies on your separate consent. Essential services such as requested email authentication use the applicable legal basis for contract-related processing and this disclosure. Advertising and notifications follow applicable regional choices and device permissions. Decline or withdraw AI transfer in consent settings; avoid account features if you do not want authentication email processing; turn off notifications in app or device settings. Contact us for individual transfer-restriction requests.
5. Advertising and notifications
The free service may display Google AdMob banners. We request non-personalized ads and do not send photos, allergies, body information, meals, or nutrient targets for ad targeting. Even non-personalized ads can involve IP addresses, app/ad interactions, diagnostics and permitted device or app identifiers. See Google’s advertising SDK disclosure.
Where available, use the advertising privacy-choice screen and your device’s privacy controls. Pro removes app banners. Result notifications are optional and contain a generic message, not food names, nutrients, allergies, or body information. Daily reminders are scheduled on your device at your chosen time.
6. Retention and deletion
| Information | Retention and deletion |
|---|---|
| Account, profile, photos, meals, recommendations and consent history | Kept for your account; scheduled for removal from operational storage when the account is deleted |
| Individual deleted meals | Hidden from lists and totals through a deletion marker; server content and associated photos may remain until account deletion |
| Authentication and sessions | Codes expire after 10 minutes; consumed challenges are removed. Refresh sessions expire 30 days after renewal, and sign-out/account deletion blocks access |
| Device and operational records | Device registration expires 90 days after refresh; usage records 90 days after their quota period; billing-event deduplication records after 30 days. Physical expiry cleanup may be delayed by the cloud service |
| Application server logs | 14 days. Application logs exclude photos, health data, emails, codes and raw tokens |
| Recovery backups | Deleted database data may remain in rotating DynamoDB backups for up to 35 days; AWS backup documentation |
| Minimal deletion and purchase-link records | Deleted random account ID and deletion time; an opaque store transaction ID or purchase-token hash linked to that account ID. No email, photo or body information is included. These records currently have no automatic expiry |
Account deletion immediately blocks account access. Photos are erased and another cleanup occurs after approximately 10 minutes to cover late uploads through previously issued links. Large accounts or service failures may take longer; failed cleanup is retried. Deleting an account does not cancel its store subscription.
Minimal deletion and purchase-link records prevent recreation under a deleted account and reassignment of a purchase. We do not treat these identifiers as necessarily anonymous. You may include them in a deletion request, and we will explain any applicable restriction.
Where statutory record-retention duties apply, Korean law provides periods including five years for contract/withdrawal and payment/supply records, three years for consumer complaints/disputes, and six months for advertising records. This describes the scope of applicable legal duties, not a reason to retain all photos or health information. Store receipts and transaction records are not erased by deleting your Mealumo account. See Article 6 of the Korean E-Commerce Act Enforcement Decree.
7. Rights and security
You can view, correct, export and delete information using the app, and contact us for access, correction, erasure, restriction, withdrawal, and other rights available under the law where you live. We request only necessary identity verification and explain any legal exception. Mealumo is intended for people aged 18 and over. Contact us if information about a younger person was supplied in error.
We use encrypted transport, private photo storage, storage encryption, account-based access checks, and restricted operational access. Verification codes and server session secrets are hashed. Service credentials use restricted encrypted secret storage.
8. Contact and changes
Controller: IBRDOS Co., Ltd. · Representative: Taewoong Ra
- Email: dev@ibrdos.com
- Telephone: +82-70-4589-9109
- Address: Room 618A, 6F, 326 Wangsimni-ro, Seongdong-gu, Seoul, South Korea
- Business registration: 829-86-02325
In South Korea, privacy assistance is available at 118 and privacy-dispute mediation at 1833-6972. See the Personal Information Protection Portal.
Material changes to purposes, information, providers or your rights will be announced in the app or on this page before taking effect. We obtain additional consent where required. Terms · Account deletion