Bot My Meals Managed — Privacy Policy
Preamble
Bot My Meals Managed ({handle}.botmymeals.com and related Managed pages on botmymeals.com) is a private household dinner-planning application for people in the United States. It is operated by Kinwyn LLC, a Kentucky limited liability company, under the product brand Bot My Meals / BotMyMeals.
This policy describes how we collect, use, and share information when you use the Managed service. It is not medical, nutrition, or legal advice about meals you cook.
Bot My Meals Managed is a household dinner-planning app subscription (hosting + database + ops). It is not a sale of AI platform seats, bot accounts, Cursor / xAI access, or API credits. Any AI tooling we use is our ops tooling to run the Service, not a product we sell to you.
Contact. For privacy questions or requests, sign in and write us from Support in the app (Account → Support), when that path is available. We do not publish a phone number or a public email inbox. Mail: 212 N. 2nd St., Ste 100, Richmond, KY 40475, US.
1. Who this covers
This policy covers personal information we process about people who create a Managed Bot My Meals account, people who join a Managed household with an invite, and visitors to Managed marketing or checkout pages we operate.
It does not cover:
- DIY self-hosted Bot My Meals instances on infrastructure you control (you are the operator of that instance).
- Third-party sites you open from the app (stores, recipe sites, payment pages on Stripe’s domain, etc.).
2. Information we collect
2.1 You give us
- Account: name or display name, email address, password (if password auth is enabled), and profile settings
- Sign-in provider data: email / basic profile if you use a third-party sign-in we offer
- Household: membership, invites you create, who you invite
- Dinner-planning content: meals, ballots, ratings, preferences, dietary notes you choose to enter, plates-per-night, budgets, week plans, saved meals / recipes, history, and similar household planning fields
- Support: messages you send to Support in the app
2.2 We collect automatically
- Technical data: IP address, browser / device type, request logs needed to run and secure the multi-tenant service
- Product events: sign-in, planning actions, invite use, starting or managing a subscription
- Wake / ops metadata: household host / handle, event type, and related webhook fields needed to operate meal-planning assistance for your household. This is service metadata, not a sold “AI seat.”
2.3 We receive from others
- Sign-in providers (if used)
- Stripe, if a household manager starts Managed billing (card numbers go to Stripe, not into our database; we store customer and subscription identifiers)
- Email delivery providers we use for account / invite / transactional mail (provider as configured at launch — e.g. Resend if used)
- Infrastructure processors that host the Managed app: Cloudflare, Supabase
- Operator tooling (for example Cursor, xAI, or similar) when we use those tools as subprocessors / ops tools to run meal-planning assistance or support — not as products we sell or accounts we create for you
We do not sell personal information. We do not use third-party advertising pixels for cross-context behavioral ads in the Managed app.
3. How we use information
We use this information to:
- Create and secure your account and household
- Host your household’s meal plans and show them to that household
- Operate ballots, ratings, weeks, recipes / saved meals, and related features
- Send account, invite, and billing-related email
- Provide support and prevent abuse / fraud (including trial and handle abuse)
- Bill and manage a Managed subscription via Stripe
- Measure which of our own links and campaigns lead people to start a trial. For this we use campaign labels in the link you followed (such as utm_source or utm_campaign) and the website that referred you, and store them with your Stripe checkout record.
- Operate meal-planning assistance for your household (including processing wake metadata and necessary planning fields through our ops tools / model providers under contract or equivalent controls)
- Comply with law
We do not sell you Cursor, xAI, Grok, or other AI platform seats. Any use of those providers is how we operate the Service.
We do not use your household meal content to train our own foundation model. If we send stored fields to a model provider to operate meal assistance, we use training opt-out or zero-retention settings where the provider offers them.
We do not use your information for cross-context behavioral advertising. We do not sell personal information.
4. Who can see household data
Meals, ballots, ratings, preferences, recipes / saved meals, and related planning data are private to the household that saved them. Anyone you invite can see that household’s data.
We do not publish a public index of customer meal plans.
Service providers see only what they need to host, authenticate, email, bill, or help us operate meal assistance. They are not allowed to use that data for their own advertising.
5. When we share information
We share information only:
- With your household members
- With service providers / subprocessors under contract (or equivalent), including Cloudflare, Supabase, Stripe, email providers, and operator AI / tooling vendors used to run the Service
- If the law requires it or to protect someone from serious harm
- If the Managed business is sold or transferred (this policy still applies until you are notified)
- When you choose to leave our service (for example opening an external link)
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as California uses those words.
6. Subprocessors (ops tools, not sold SKUs)
| Processor | Role |
|---|---|
| Cloudflare | Hosting, CDN, Worker runtime, security |
| Supabase | Database, auth, storage for Managed households |
| Stripe | Payments, Customer Portal, invoices |
| Email provider (as configured at launch) | Transactional / invite email |
| Cursor / xAI / similar | Tools we use to operate meal-ops and support — not customer-facing accounts or seats sold to you |
Naming a vendor here does not mean we sell that vendor’s product to you.
7. Cookies
We use cookies and local storage required to keep you signed in and run the app. We do not use advertising cookies. Blocking cookies may break sign-in.
Campaign labels travel in the page address only. We don’t set cookies or use local storage for them.
8. How long we keep information
| Data | Retention |
|---|---|
| Account and household planning data | While the Managed household is active |
| After cancel / unpaid end | 30 days for export / recovery, then hard-delete household meal / ballot / planning content (prefer hard delete over de-identify-to-retain), except law / billing / security / dispute records |
| Server logs | Short period needed to operate and secure the service |
| Stripe identifiers / payment records | As the processor and tax law require |
| Wake / ops metadata | As needed to operate and debug meal assistance; not retained longer than necessary |
DIY self-host data never enters the Managed database and is not covered here.
9. Security
We use reasonable measures (encrypted transport, access-controlled hosting, household-scoped access / RLS). No consumer app is perfectly secure. Do not put Social Security numbers, full payment card numbers, or bank passwords into notes.
Managed households share multi-tenant infrastructure with logical isolation (RLS + host mapping). DIY customers on their own accounts are separate.
10. Children and household members
Managed Bot My Meals accounts and billing are for adults (18 or older) who manage a household’s dinner planning in the United States. The Service is not directed at children under 13, and we do not knowingly collect personal information from children as account holders.
A household’s meal plans may mention family members (including teens). Contracting parties and account holders remain adults. Adult household managers are responsible for what they invite and what they enter about household members.
We do not claim that this product is COPPA-certified or that a separate child account product exists. If you think a child created an account, write us from Support in the app (Account → Support) and we will delete it.
11. United States only
The Managed service is built for the United States (USD billing). We do not intend to offer Managed Bot My Meals as a localized service to people in the EEA, UK, or Switzerland. If you use it from those places anyway, you understand it is a U.S. service and U.S. law applies.
12. Your choices and rights
You can access and edit your profile, edit household planning data, leave a household, and (household manager) manage or cancel a paid plan via the Stripe Customer Portal.
State law may also give you the right to know, access, correct, or delete personal information; obtain a copy; opt out of sale, sharing for targeted advertising, and certain profiling (we do not sell or share for ads); limit use of sensitive personal information; and appeal a refusal.
We honor these rights for all U.S. users in the same way, including rights under Kentucky’s KCDPA, Texas’s TDPSA, and California’s CCPA/CPRA, to the extent they apply. We will not discriminate against you for exercising a privacy right.
To make a request, sign in and write us from Support in the app (Account → Support), when available, or mail the address above. We will verify it is you. You may use an authorized agent where the law allows. If we refuse, we will say why and how to appeal.
We respond within 45 days, or sooner if your state requires it, with one permitted extension when the law allows.
13. Sensitive information
We do not ask for race, religion, health diagnoses, sexual orientation, or Social Security numbers.
You may voluntarily enter dietary preferences or allergy notes. Treat those as sensitive household content; we use them only to operate dinner planning for your household. Do not enter someone else’s health information without a right to do so.
14. Notice at collection (California)
| Category | Examples | Sources | Purpose | Disclosed to | Sold / shared for ads? | Retention |
|---|---|---|---|---|---|---|
| Identifiers | name, email, account id, IP | you, sign-in provider, logs | account, security, support | household; processors | No | account life + short logs |
| Customer records | household membership, plan | you | operate household | processors | No | account life / 30-day post-cancel then hard-delete (planning content) |
| Commercial / plan | Managed plan; Stripe customer & subscription ids | you, Stripe | billing | Stripe | No | as tax / payment law require |
| Internet activity | app events, invite use, checkout, wake metadata; campaign labels and referring website at checkout | device / service | operate and debug; measure our own marketing | processors (including Stripe, as processor) | No | short cycle / ops need |
| User content | meals, ballots, prefs, budgets, recipes / notes | you | household planning + meal assistance | household; processors; operator model tooling | No | active + 30 days post-cancel, then hard-delete |
We do not collect biometric or genetic data, or precise mobile-device background tracking.
15. Changes
If we make a material change, we will update the date at the top and, when significant, notify you in the app or by email. Continued use after the effective date means you accept the updated policy. If you do not, cancel Managed and stop using the Service.
16. Contact
Operator: Kinwyn LLC
Product brand: Bot My Meals / BotMyMeals
Privacy requests: Sign in and write us from Support in the app (Account → Support), when available. We do not publish a phone number or a public email inbox.
Mail: 212 N. 2nd St., Ste 100, Richmond, KY 40475, US
This policy is for Managed Bot My Meals users.