Sapere

Privacy policy

Last updated 5 October 2026

Sapere helps you plan meals around the food you already have. This page explains what we collect to do that, who else handles it, and how to remove it.

Who we are

Sapere is run by Oliver Caplan, its founder. He is the data controller: the person responsible for your personal data and for this policy. “We” and “us” on this page mean him.

What we collect

  • Your account: name, email address and a securely hashed password (we never see the password itself).
  • Your preferences: household size, diets, allergies and foods you dislike.
  • Your kitchen: pantry items, quantities and expiry dates, the meal plans and shopping lists we make, and which meals you cook.
  • Your tastes: the meals you like or pass on in the taste trainer, which we use to learn what you enjoy.
  • Receipts: the items read from receipts you scan or orders you paste in. The photo itself is sent for reading and then discarded; we don't store it.
  • What you usually buy: for each product on a receipt or order you confirm, its name as we read it (which can include the brand), the usual amount, and how often and how recently you bought it. We use this to plan meals around what you buy (the names and usual amounts of up to 15 of the products you buy most are sent to Anthropic with each request for a meal plan or a swapped dinner), to top up your shopping list, and to show the brand you buy on it. It has no page of its own in the app; it is in the download of your data and is deleted with your account.
  • How you use the app: a short record of what you do and when (signing up, scanning, planning, cooking, swapping a dinner, opening the app on a given day), kept in our own database so we can see whether the app is useful. For meal planning, we also record how many dinners you asked for, how many were kept after checks, and how many were dropped because of your diet, allergies or other checks. No outside analytics or advertising service is involved.
  • Visits before you sign up: when someone opens our front page or install page, taps to install, or opens the installed app while signed out, we add one to a daily total for that step. We keep only the date and the totals, never who you are, your IP address, your device or your browser, and they are used only to see how many people find and install the app. Your IP address is held only in the server's memory, to stop anyone flooding these counts; it is never saved with them and is cleared when the server restarts.
  • Rate-limit records: to prevent misuse of sign-in, sign-up, password reset, account deletion and other features, we keep counters keyed by a hash of the email address, network address or account involved. These expire within a day of the last attempt. We also keep a keyed hash linking your account to each network address you sign in or reset your password from, held for 30 days from your latest sign-in or password reset on that network. In our database these records hold only keyed hashes, never your plain email address, IP address or account ID. If the database is briefly unavailable, the counters are held in the server's memory instead and are lost when the server restarts.
  • AI usage records: each time you scan a receipt or paste an order, make a meal plan or swap a dinner, we record the kind of request, when it was made and what it cost us, against a keyed hash of your account's email address. We use these records only to apply the weekly limits on those features and to cap what the app spends in a day. They hold no plain email address, IP address or account ID, and nothing from the receipt, pantry or plan itself. Each one counts for 7 days and is deleted when it expires, as part of our daily cleanup, typically within 8 days of the request. They are not included in the download of your data.
  • AI attempt records: each time you scan a receipt or paste an order, make a plan, or swap a dinner, we record whether it was accepted or refused (and if refused, the reason: weekly limit reached, daily app budget reached, or service busy) and the time, against a keyed hash of your email. We use these to understand how often people reach their limits, so the final limits can be set fairly. They are held for up to 12 months and then deleted as part of our cleanup. They hold no plain email, IP, account ID, or content from receipts, pantries or plans. If you ask us by email, we delete all records for that address. They are not included in the download of your data.
  • Sign-in sessions: for each device you are signed in on, we keep a record linking a random session number to your account, with the date it runs out (30 days after you last used it). It holds nothing about the device and no IP address. It is deleted when you sign out, reset your password or delete your account, and usually within a day of running out, as part of our daily clean-up.
  • Notifications: if you turn them on, the address your phone or browser gives us for sending them.

Allergies and diets can say something about your health. We store them only if you tick the box, when you sign up or in Settings, to say we may. We use them only to choose and check your meals, which includes sending them to Anthropic with each meal-plan request. You can withdraw your consent at any time by unticking the box or clearing them in Settings. The rest of the app carries on working, but your meals will no longer be checked against them.

We don't collect your location, contacts or advertising identifiers, and we don't sell or share your data for advertising.

How we use it

Only to run the app: reading receipts, tracking what's in your pantry, planning meals that suit your diet and tastes, and getting in touch. We send account emails (a welcome message and password resets) and, unless you turn them off in Settings, reminders: food about to go off and, if you ask for them, tonight's dinner and a nudge to rate it. Reminders come by email, and as notifications on devices where you've turned those on.

Our grounds for using it: we need your account, kitchen and taste data to provide the app you signed up for. We use your allergies and diets only with your consent. We keep the record of how you use the app, the AI usage records, the server logs and the limits on sign-in attempts because we have a legitimate interest in keeping the app working, secure and affordable to run. Notifications are sent only if you turn them on.

What is kept on your device

A sign-in cookie that keeps you signed in for up to 30 days after your last visit, your choice of light or dark theme, the days you last chose for a meal plan, your invite code if you arrived by an invite link, and a copy of the “you're offline” screen. In the iPhone app only, a copy of your sign-in token is also kept in the app's storage, so that you stay signed in between launches. We don't use advertising or tracking cookies.

Who else handles it

  • Anthropic provides the AI that reads receipt photos and writes meal plans. It receives the receipt image, or your pantry list and preferences, for each request, and handles them under its own commercial data terms.
  • Railway hosts the app and its database on servers in the United States. All of the data described in this policy is stored there.
  • Our email provider sends account emails and reminders to your address.
  • Apple, Google or Mozilla, whichever makes your browser, deliver notifications if you turn them on. They receive the short text of the notification.
  • TheMealDB supplies the recipes and photos in the taste trainer, your picks and the suggestions on your plan. Your device loads the photos directly from them, so they see your IP address, as any website would.

Where your data is kept

Sapere's servers and database are in the United States. Wherever you use the app from, including the UK and the EU, your data is sent to the United States and stored there. Anthropic is also based in the United States. The other companies listed above may handle your data in the United States or in other countries.

Data-protection law in the United States is different from the law in the UK and the EU, and may give you fewer rights. If you live in the UK or the EU and want to know what safeguards cover your data there, ask us and we will tell you.

Keeping and deleting your data

We keep your data while you have an account. You can delete your account at any time in Settings → Delete account, which permanently removes everything above straight away, except the rate-limit records, which are not removed and expire on their own within 30 days; the AI usage records, which are not removed and are deleted by our daily cleanup, typically within 8 days of the request; and the AI attempt records, which are not removed and are kept for up to 12 months, then deleted. Server logs are kept for a short time for security and fixing faults. They record account IDs and what went wrong, which can include the name of a dish or an ingredient.

Security

Data is encrypted in transit, passwords are hashed with bcrypt, and repeated sign-in attempts are limited. No system is perfectly secure, but we take reasonable care to protect what you give us.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. If you live in the UK or the EU you have further rights under data-protection law: to object to or restrict how we use your data, to take your data elsewhere, and to withdraw a consent you have given. You can also complain to your data-protection authority; in the UK that is the Information Commissioner's Office (ico.org.uk).

You can download a copy of your data yourself at any time in Settings → Download my data, after entering your password. The file holds your account details and settings, your pantry, your meal plans and shopping lists, your tastes and ratings, what you usually buy, your receipts (the shop name, items and prices read from each one) and the record of how you use the app. For older accounts that record includes when AI requests were made. The file leaves out the AI usage records, which record what each request cost us, the rate-limit records, your password and the security tokens that keep you signed in or reset your password, and the addresses we send your notifications to.

Children

Sapere isn't aimed at children under 13, and we don't knowingly collect their data.

Changes and contact

If we change this policy we'll update the date above. If the change is significant we'll email you at the address on your account. Questions or requests: ocsoftwaredesign@gmail.com.

Privacy · Terms