Summary
What Munch stores
Munch stores the information needed to provide and protect the service, including:
- Account email, passwordless login challenges, sessions, security records, preferences, and authorized connections.
- Meals, meal items, calories, nutrients, meal times, notes, sources, assumptions, drafts, and confirmations.
- Saved foods, usual meals, food-source identifiers, and barcode results you choose to save.
- Water, weight, user-entered goals, timezone, units, and other account preferences.
- Recipes, immutable recipe revisions, ingredients, instructions, servings, factual nutrition, source provenance, planned meals, and grocery-list items.
- Optional Premium Pantry inventory, exact or approximate quantities, storage locations, inventory-event history, structured purchase or receipt reconciliation results, and refreshable planning profiles that can include compact nutrition facts, food-source identifiers, and culinary categories or roles. Munch does not retain raw Pantry or receipt images after the website extraction request is processed.
- Household names, display names, membership roles, invitations, and factual attribution showing who created or changed shared records.
- Stripe customer, subscription, entitlement, renewal, cancellation, payment-status, seat-quantity, and household billing metadata. Munch does not store raw card numbers or payment credentials.
- Short-lived exports, deletion requests, bounded operational logs, and security telemetry needed to run and protect the service.
Tool inputs
When ChatGPT calls a Munch tool, Munch receives the tool arguments needed to perform that request. Those arguments can include food descriptions, quantities, dates, nutrition values, water, weight, goals, recipes, meal-plan instructions, grocery items, Pantry inventory changes, or account instructions. Munch does not automatically receive unrelated parts of your conversation.
Pantry and receipt images
When an eligible Premium user uploads a Pantry, refrigerator, freezer, or grocery-receipt image through the Munch website, Munch sends that image transiently to its configured AI processor to extract structured food or purchase candidates. The raw image is not written to the Munch PostgreSQL database or account export. Uncertain detections are presented for review before they can change Pantry inventory. Images uploaded directly to ChatGPT are handled by ChatGPT under OpenAI's policies; Munch receives only the structured tool arguments ChatGPT sends to the connected Munch app.
Pantry meal planning
When an eligible Premium user asks the Munch website for Pantry meal ideas, Munch can send the relevant structured Pantry inventory, compact planning profiles, explicit assumed staples, request goals, and saved-recipe candidate facts to its configured AI processor. This request is used to rank or generate grounded meal ideas. Raw Pantry or receipt images are not included in this meal-planning request, and the recommendation does not change Pantry, Grocery, or recipe records by itself.
Why it is stored
Munch uses this information to authenticate you, maintain persistent records, search food databases, answer authorized tool requests, apply Free and Premium capability limits, coordinate household workspaces, prevent abuse, support export and deletion, and operate the service.
Household sharing
A household is a shared workspace. Active household members can see household recipes, planned meals, grocery lists, shared Pantry inventory, household display names, roles, and factual activity attribution. Owners and members can edit shared records when the household has applicable access; viewers are read-only.
Personal meal history, water logs, weight logs, personal saved foods, and personal goals are not shared merely because an account joins a household. A record is shared only when it is created in the household workspace.
If a non-owner deletes an account, the account link is removed but the display name recorded on shared household activity may remain so other members can understand the history of the shared workspace. A household owner must transfer ownership or dissolve the household before deleting the owner's account. Dissolving a household permanently deletes its shared workspace records.
ChatGPT and OpenAI are separate from Munch
Your conversation is processed by ChatGPT before or while ChatGPT decides whether to call Munch. OpenAI—not Munch—controls how ChatGPT conversation content is retained, reviewed, or used under the applicable ChatGPT plan, account settings, and OpenAI policies.
Munch cannot promise that OpenAI will not retain or use conversation content. Users should review OpenAI's current privacy controls and avoid entering information they do not want processed by ChatGPT.
Munch does not train a separate model on nutrition records. Munch may use aggregate operational information that excludes nutrition-record content to identify failures, latency, abuse, or capacity needs.
Service providers and external data sources
- Railway hosts the Munch application and PostgreSQL database.
- Stripe processes Premium checkout, recurring billing, payment methods, invoices, cancellations, and subscription recovery on the Munch website.
- Resend processes email addresses and sends passwordless sign-in links and household invitations.
- USDA FoodData Central receives food-search requests when Munch searches USDA data.
- Open Food Facts receives food or barcode lookup requests when that source is used.
- OpenRouter receives Pantry or receipt images uploaded through the Munch website when AI-assisted extraction is enabled, and receives relevant structured Pantry and saved-recipe context when an eligible user asks the website for AI-assisted Pantry meal ideas. Munch requests routing with provider data collection disabled. That routing preference is not a promise of zero retention, and the processors selected through OpenRouter remain subject to their applicable privacy and retention practices.
- OpenAI/ChatGPT processes the conversation and decides what tool arguments to send to Munch.
These providers process information under their own terms and privacy practices. Munch does not use advertising analytics or create advertising profiles.
Security and database protections
Munch uses HTTPS in production, signed and expiring sessions, OAuth authorization with PKCE, verified Stripe webhook signatures, rate limiting, bounded request bodies, hashed invitation and export tokens, and forced PostgreSQL row-level security for personal and household records.
Access to production systems is restricted, but no internet service can guarantee absolute security. Munch does not claim zero-knowledge storage, end-to-end encryption, or that an authorized operator could never access the database during security, legal, backup, or incident-response work.
Export, connections, and deletion
The account portal can generate a short-lived JSON export containing personal Munch data and shared household records the account is authorized to view. The export excludes other household members' email addresses and internal account identifiers. The conversational meal-history CSV export remains available separately.
You can revoke individual ChatGPT/MCP connections, manage website billing through Stripe, leave a household, transfer ownership, dissolve a household, and permanently delete your Munch account through available controls.
Account deletion removes active Munch account data, personal nutrition records, saved foods, drafts, preferences, and active connections from the primary application database. Shared display-name attribution may remain as described above. Limited records may also remain temporarily in security logs, database backups, Stripe records, or records Munch must retain for fraud, accounting, legal, or dispute purposes.
Deleting Munch data does not delete conversation history held by ChatGPT or OpenAI.
Retention
Active account and workspace data is retained while the account or workspace remains active. Passwordless login challenges normally expire after 10 minutes; website sessions expire after 30 days and may be refreshed during active use. OAuth authorization codes expire after 5 minutes, access tokens after 15 minutes, and refresh tokens after 90 days. Expired or revoked authentication artifacts remain only until the next applicable cleanup cycle.
Downloadable account exports expire after one hour. Operational and security records are retained only for the period reasonably needed to investigate failures, prevent abuse, respond to incidents, and meet legal obligations; Munch does not intentionally place nutrition-record contents in ordinary access logs. Database backups may retain deleted data until the hosting provider's configured backup rotation overwrites them. Stripe may retain billing, accounting, fraud, dispute, and tax records for the periods required by law and its own policies.
Consumer wellness product
Munch is not an electronic health record, medical provider, emergency service, or HIPAA-covered clinical service. Nutrition data, database records, and AI-assisted estimates can be incomplete or inaccurate and are not medical advice.
Policy changes
This policy may change as Munch, its providers, or legal requirements change. Material updates will be reflected by a revised date and, where appropriate, an in-product notice.
Contact
Do not place sensitive nutrition or account data in public GitHub issues. Send privacy and support requests to support@munch.business. Report security vulnerabilities privately to security@munch.business.