Supper Kit privacy policy
Last updated: 2026-08-28
Supper Kit is a meal-planning app. This page describes what the hosted service stores and how you can delete it. It is the in-app privacy policy required for App Store submission (guideline 5.1.1(i)). Canonical URL: https://supperkit.app/privacy
What we collect
When you create an account we store:
- Your email address and a hashed password when you choose email sign-in (we never store the raw password)
- If you choose Sign in with Apple: Apple’s app-specific user identifier and, encrypted at rest, the refresh token needed to revoke that authorization if you delete your account. You may use Hide My Email / Apple’s private relay instead of your personal address.
- An optional display name
- Household meal preferences, including allergies, diets, cuisine notes, and any free-form notes you write
- Your cooking calendar and grocery lists
- An Apple Push Notification service (APNs) device token, linked to your account and current household, when you enable notifications
We do not store publisher recipe instructions. Meal detail opens the original recipe on the publisher’s site.
Voice planning
If you speak a plan, the iOS app uses the device microphone and Apple speech recognition to turn audio into text. Supper Kit only receives that text — the same as if you had typed it. We do not store audio recordings. Speech may be processed on device, or by Apple, depending on the device and language.
Subscriptions
Supper Kit Premium is an auto-renewable Apple In-App Purchase. Apple processes the payment. We never see your card number. Subscriptions are billed by Apple; see the Terms.
The products are:
-
app.supperkit.premium.annual— $99.99 USD / year, with a 7-day free introductory offer -
app.supperkit.premium.monthly— $9.99 USD / month, no trial
We store a server-side entitlement for your Supper Kit account: product id, original Apple transaction id, status and expiry, environment (sandbox or production), and whether it auto-renews. The iOS app sends Apple-signed StoreKit transaction JWS; we verify it. Apple may also POST App Store Server Notifications V2 to our API.
If you opt in on the paywall, the app can schedule a local trial-ending reminder on the device. That notification does not go through our servers and is not used for ads.
We do not use subscription data for tracking or advertising.
Deleting a Supper Kit account does not cancel the Apple subscription. Cancel in iOS Settings → Apple Account → Subscriptions. Until you cancel, Apple will keep billing.
How we use it
Preferences and calendar data exist so Supper Kit can plan meals for your household. Allergy and diet notes are treated as sensitive: API logs redact those request bodies and never write passwords or session tokens.
We do not sell your data. We do not write to Apple Health.
The APNs device token is used only to notify you when a meal-planning job is ready, needs an answer, or fails. It is not used for advertising or tracking.
Sharing
If you generate an Instacart shopping list, we send ingredient names and quantities to Instacart so they can build a hosted shopping page. You still choose a retailer and complete checkout with Instacart.
Retention and deletion
Account deletion is immediate and irreversible. Use
Settings → Delete account in the iOS app (or
DELETE /v1/me with a valid session). That removes your
user row, sessions, rate-limit attempts, and any household that has
no remaining members — including preferences, plans, and calendar
meals. It also deletes APNs device tokens associated with your
account. The app makes a best-effort request to remove its current
token when you log out, and the service removes tokens that Apple
reports as invalid. Otherwise, notification tokens are retained while
they remain associated with an active account.
If you signed in with Apple, we revoke that authorization before deleting the account. Any stored Premium entitlement is removed with the account. Deleting the account does not cancel the Apple subscription — cancel in iOS Settings → Apple Account → Subscriptions.
A process-local Instacart link cache on the API host is not household-scoped and is not wiped by account deletion.
Production database backups are retained ≤ 14 days.
Children
Supper Kit is not directed at children under 13. Do not create an account for someone under 13.
Contact
Email the operator listed in App Store Connect, or write to hello@supperkit.app.