Skip to main content

tracemeal

Analyse recipeExplore foodsRecipe booksMeal plannerMy RecipesLearnAboutHelp
Account
Privacy Policy

How TraceMeal handles personal information

Operator: Jonathan Morris, operating TraceMeal in Australia.

Last updated: 18 September 2026.

This policy explains how TraceMeal collects, uses, stores and protects personal information. It is written conservatively around Australian privacy expectations and the information TraceMeal actually handles. It does not claim a legal certification or guarantee that a security incident can never occur.

What TraceMeal collects

You can use the recipe analyser without creating an account. When you stay signed out, saved recipes and selected nutrient-reference preferences can be stored in your browser's local storage.

If you create an account, TraceMeal may hold your email address, authentication/account identifiers, first or preferred name (requested at email signup), optional age, optional nutrient-reference sex selection, locale/unit preferences, account/plan status, saved recipes, custom nutrient targets and other settings you deliberately save to your account.

When you use the contact form, TraceMeal collects the name, reply email address, enquiry category and message you submit. Hosting and backend providers may also process ordinary technical/security information such as IP address, browser/device information, timestamps and request logs.

You may optionally choose an age-group or pregnancy/breastfeeding nutrient-reference profile. That choice is saved privately with your preferences and can be changed in planner settings.

Optional nutrition preferences

You can choose to save a meal-planning goal, eating style, foods you prefer to avoid, the number of people you cook for, country/region and preferred units. The nutrition-preference fields have a separate, optional consent choice. They are stored in your private account profile with the consent version and time, and can be edited or cleared from Account. They are not included in traffic analytics or copied to anonymous browser storage.

These preferences currently provide a record you can review. They do not automatically filter recipes, calculate portions or generate personalised targets. The foods-avoided field is for preferences, not allergy screening. Skipping setup does not save the optional answers you entered.

Health and sensitive information

Nutrition information can become sensitive depending on what a person records and how it is used. The ordinary TraceMeal profile currently does not ask for diagnoses, medications, pathology results, clinical notes, allergies, height or weight.

Age and the optional “NRV reference sex” field are used only to help select an applicable Australian/New Zealand nutrient-reference comparison. Pregnancy and lactation references are explicit choices in the analyser and household settings; adult meal suggestions use the household selection. If a future feature needs to collect genuinely sensitive or health information, TraceMeal should explain why that information is needed and obtain an appropriate, specific consent before collection where required.

Why the information is used

TraceMeal uses personal information to create and secure accounts, provide requested product functions, save and sync recipes/settings, select relevant nutrient-reference comparisons, provide support, maintain service security, administer account status, respond to privacy requests and meet applicable legal obligations.

TraceMeal does not collect extra medical information merely because it might be useful one day.

Household profiles and meal portions

If you add household members, TraceMeal stores their nicknames, optional ages and nutrient-reference sex selections, archive status and the meal portions you assign to them. These records are private to your account and stored in Supabase. Members have no separate login. Use nicknames and only add information you are authorised to manage. Household details and portions are not included in traffic analytics or copied to anonymous browser storage.

Your “Me” member uses your existing account profile settings. Archiving a member keeps their previous portions available; deleting your account also deletes its household members and allocations. Nutrient comparisons for past dates use each person’s current reference settings.

Optional meal suggestions

When you request meal suggestions, you choose diet, ingredient exclusions and portions for up to two adults. Suggestions use the references already selected by your saved household settings. Requesting or accepting suggestions does not save or change household references. The person managing the account can manage references for everyone in that household; only enter information you are authorised to manage. These choices may reveal sensitive information; they are used only to calculate, review and reproduce your private meal suggestions, not for advertising or traffic analytics. They are not sent to a language model.

Saved previews include these settings, calculated food contributions, the selected dates and a snapshot of the existing plan and household. Up to 100 recent previews are kept per account. Records older than 30 days are removed the next time you generate suggestions; inactive accounts retain them until you clear suggestion history or delete the account. Use “Clear suggestion history” in Account or Suggest meals to remove them sooner, including undo history. Accepted meals remain in your planner until you remove them. References deliberately saved in Household are separate from suggestion history and can be reset there; deleting the account removes these records.

Shopping lists

Saved shopping lists contain the selected dates, ingredient quantities, source recipe references, added groceries, pantry choices and checkmarks. They are private to your account and stored in Supabase. Monthly Free usage records contain shopping dates and a quota month. Shopping contents are not included in traffic analytics, and private lists are not copied to anonymous browser storage.

Where information is stored and processed

TraceMeal uses Supabase for account authentication and database services. The current TraceMeal Supabase project is hosted in Sydney, Australia. TraceMeal also uses Vercel to host and deliver the web application. When enabled, Google sign-in supplies account identity information such as your email and name, and Cloudflare Turnstile processes technical signals to help prevent automated abuse.

The private contact-form email delivery service is not yet enabled in this deployment.

Some service providers, their support systems, logs or related infrastructure may process information outside Australia. TraceMeal does not promise that every copy of every item of information will always remain physically in Australia. Providers and processing locations may change as the service changes, and this policy should be updated when material providers change.

Security

TraceMeal uses authentication, access controls and database row-level security to separate private account data. Privileged credentials are kept server-side and are not intended to be exposed through browser variables. TraceMeal aims to collect only information reasonably needed for current features and to avoid retaining information that is no longer needed.

No online service can guarantee absolute security. If TraceMeal becomes aware of a data breach, it will assess and respond to the incident and meet any notification obligations that apply.

Local storage and cookies

TraceMeal uses browser local storage for anonymous/local recipe saving and selected preferences. When you leave an anonymous recipe to sign up, a temporary draft may be kept in this tab’s session storage for up to two hours so you can return to it; it is not automatically uploaded. Supabase authentication may use browser storage/session mechanisms needed to keep you signed in. TraceMeal uses first-party usage analytics to understand page visits and whether features work. A random browser identifier expires after 30 days; a visit identifier is kept in session storage. Events contain only fixed action names, page categories, broad referral groups and device types—not recipe text, email addresses, IP addresses, URL query strings or health profiles. Recognised staff activity is excluded from public figures. Detailed events are removed after 180 days on the next collection run. Authorised staff can view aggregate reports; confirmed signup counts come from account confirmation timestamps. Total account figures include current registered accounts, with confirmed and unconfirmed accounts shown separately. Do Not Track and Global Privacy Control signals disable browser event collection. You can also exclude this browser below.

For new email signups, TraceMeal may record a broad device type (desktop, mobile or tablet) to understand which signup experience people use. The device type is kept privately with the account until account deletion; authorised staff see only aggregate counts. It is captured at account creation and is not changed by later sign-ins or confirmation on another device. No raw user agent, IP address or browser identifier is added to this record. Older accounts, Google signups and unavailable device information are reported as unknown. Browser exclusion, Do Not Track and Global Privacy Control disable this optional signup-device collection; they do not remove the account from operational account totals.

Access, correction and profile controls

Signed-in users can review and update ordinary profile information from the Account page. For access or correction requests that cannot be completed there, use the contact form and choose the privacy category.

Account deletion

The Account page includes a deliberate account-deletion flow. When deletion is configured and confirmed, TraceMeal deletes the authentication account and deletes or de-identifies user-linked cloud records according to the current database relationships. Browser-local recipes are separate and remain on that device unless you clear them there.

Where information is no longer required, TraceMeal will delete or de-identify it where appropriate, subject to genuine legal, security, fraud-prevention, accounting or dispute-resolution retention needs. Technical backups or provider logs may persist for a limited period according to provider processes, so TraceMeal does not promise instantaneous erasure from every backup copy.

Privacy enquiries and complaints

Jonathan Morris operates TraceMeal. You can make a privacy enquiry, access/correction request or complaint through the TraceMeal contact form without the operator's private email address being displayed publicly. TraceMeal will review the issue and respond within a reasonable period.

If Australian privacy law applies to the issue and you are not satisfied with the response, you may also have rights to raise the matter with the Office of the Australian Information Commissioner.

Changes to this policy

TraceMeal will update this policy when material data practices, providers or product features change. The “Last updated” date above shows the current version.

TraceMeal is intentionally keeping the consumer profile small. Future professional/clinical functionality should use a separate, purpose-built data model and privacy review rather than quietly turning an ordinary consumer profile into a medical record.

tracemealKnow what you eat.
LearnAboutHelpContactData & methodsPrivacyTermsNutrition disclaimerAccessibility
Nutrition information is for general educational use and is not personal medical advice. Food composition data adapted from the Australian Food Composition Database © Food Standards Australia New Zealand, used under CC BY-SA 3.0 AU. Modified. FSANZ does not endorse this tool.