Privacy Policy
Last updated: May 2026
mom menu ("we", "our") respects your privacy. This document explains what personal data we collect, how we use it, and how we protect it when you use our service.
What information we collect
Account data
When you register, we collect: your full name, email address, and password (stored in encrypted form — your actual password is never stored).
Child's data
For meal plan personalization, we collect your child's name, date of birth, and allergy information. This data is used solely to provide the service.
Usage data
We collect information about how you use our service — generated meal plans, selected dishes, subscription status.
Technical data
For authentication, we use an httpOnly JWT cookie. This cookie is secure and cannot be accessed by JavaScript.
Why we use your data
- 1Creating and delivering personalized meal plans
- 2Account management and secure authentication
- 3Processing subscription status and payments
- 4Service improvement and technical support
- 5Compliance with legal obligations
Who can see your data
We do not sell, rent, or share your personal data with third parties, except in the following cases:
- —Technical infrastructure providers (database, server) — solely for service operation
- —As required by law — upon request from a court or authorized authority
Cookies
We use only one cookie — the authentication JWT token (mom_menu_token). This cookie is:
httpOnly
Cannot be accessed by JavaScript
Secure
Only transmitted over HTTPS
SameSite
Protected against CSRF attacks
Temporary
Automatically deleted on logout
We do not use advertising, analytics, or third-party tracking cookies.
Your rights
You have the right to:
- ✓See what data we hold about you
- ✓Correct inaccurate data from your settings
- ✓Request deletion of your account and all associated data
- ✓Cancel your subscription at any time
- ✓Request a copy of your personal data
Data retention
We retain your data for as long as you use the service. Upon a deletion request, all personal data will be erased within 30 days, unless we are legally required to retain it longer.
Changes to this policy
In the event of significant changes to this policy, we will notify you by email or in-app notification. The updated policy will appear on this page with a revised "last updated" date.