Privacy

MenUni is a meal planner. It needs to know what you can eat and what you can cook on. It does not need to know much else, and it does not ask.

Without an account

You can use the whole planner signed out. Everything you do then (your preferences, your week, your shopping list, what you have in the cupboard) is stored in your own browser under a key called uks.kitchen.v1. It never leaves your device. We cannot see it, and clearing your browser data deletes it permanently, including from us, because we never had it.

With an account

An account stores the same things on a server so they follow you between devices, plus your email address, which is what you sign in with. That is the entire list. No name, no address, no phone number, no payment details, and we never ask for any.

Accounts and data are held by Supabase on servers in the EU (London region). Every table is protected so that your rows are readable only by you, not by other users, and not by the browser code we ship.

Cookies

This page used to say we set no cookies at all, and that there was therefore no banner. That stopped being true when the free PDF shipped, and it took us too long to notice. It is corrected below, and the cookie in question now does not get written unless you say yes.

Two things are stored no matter what, because the site does not work without them. If you sign in, your session is kept in your browser’s local storage, and it is deleted when you sign out. And your answer to the cookie question is kept in a cookie, because the only way to stop asking is to remember that we asked.

One thing is stored only if you allow it: which free PDF you downloaded, so we can offer you the planner next time instead of the thing you already have. It holds nothing that identifies you. It is still your choice, because the rule is not whether a thing is harmless, it is whether the site would work without it, and it would.

There is nothing under measuring or advertising. Those categories exist in the banner so that the day either changes, you are asked rather than told.

Worth saying because it is widely got wrong: this is not really about cookies. The law covers anything stored on your device, so moving something into local storage would not make it exempt. Nothing here relies on that trick.

What we measure

We record when something breaks, and a small fixed list of events like “a plan was generated”. This is how a site run by one person finds out it is broken without waiting for somebody to complain.

These records hold the page path, the error message, your browser’s user-agent string, and counts such as how many people a plan was for. They do not hold your email, your dietary requirements, your dislikes, your shopping list, or anything you typed. Page paths are recorded without the query string, so a search term cannot end up in a log. There is no third-party analytics service and no advertising anything.

Who else gets your data

Nobody. We do not sell it, share it, or pass it to advertisers. Two companies process it because they run the site: Supabase, which stores accounts and data, and Vercel, which serves the pages.

One third party sees your IP address without us choosing to send it: the page loads fonts from Google Fonts, and loading a font is a request to Google’s servers. We mention it because it is true, not because it is significant.

Getting rid of it

Signed out: clear your browser data for this site and it is gone.

With an account: ask us to delete it and we delete the account and every row attached to it. Under UK GDPR you also have the right to a copy of what we hold, to have it corrected, and to object to us holding it. Given the list above, that is a short conversation.

Terms of useHow dietary filtering works