KalaPlate plans meals for a household, so it holds things households would rather keep private — who eats with you, what they are allergic to, what they ate yesterday. This page says exactly what we hold, why, who else touches it, and how to get rid of all of it.
Effective: 13 August 2026 · Last updated: 9 September 2026
KalaPlate is a meal-planning service operated from Australia by Kala-X Technology Pty Ltd, trading as KalaPlate, reachable at www.kalaplate.com and through the KalaPlate mobile app. Where the law calls someone the data controller for the information described here, that is us. Further registered business details are available on request from the contact address below.
This policy covers KalaPlate on the web and on mobile — the website, the Android app, and the Apple App Store release we are preparing. It is written to describe all three, so it does not change meaning when an app becomes available somewhere new. Every one of them talks to the same servers and holds the same household data.
We collect what the product needs to plan food for the people who live with you. We do not buy data about you, we do not sell or rent your data, and there is no advertising SDK, analytics SDK or crash-reporting SDK in the app. What identifiers we do use, and the narrow purposes they serve, are set out under identifiers and tracking below.
| What | Examples | Why |
|---|---|---|
| Your account | Email address; your password, stored only as a one-way bcrypt hash; an optional security question and a hashed answer; your plan tier; the country you shop in. | To sign you in, to recover your account if you forget your password, and to price a shopping list in the right currency. |
| Your household | Foods the household avoids, cuisine and protein preferences, kitchen equipment, cooking skill, how many nights you cook, weekly food budget, time zone, language, metric or imperial, and any free-text rules you write. | To build a week that fits your kitchen, your budget and your week. |
| The people in it | Each person's first name (or whatever you type), whether they are an adult or a child, allergies, dietary restrictions, and whether they eat everything. For adults, optionally: height, weight, sex, year of birth, activity level and a goal. For children: age, portion size, whether their school is nut-free, canteen days and a recess note. | To keep food someone is allergic to out of the plan, to size portions, and to work out calorie and macro targets where you have asked for them. |
| Targets | Per-person calorie, protein, carbohydrate and fat targets, and meals and snacks per day. | To plan against them and to show progress in the tracker. |
| The tracker | What each person ate on a given day, the serving size, and the calories and macros that go with it. | Only to draw that person's day. Nothing else reads it. |
| What you do in the app | Weekly plans and the meals in them, favourites and imported recipes, shopping regulars and preferred stores, dishes you have declined, ingredients you have added yourself, recipes shared to or from your account, and — if you use them — the reports you make about a share and the senders you block. | To run the product: to show your plans, keep your favourites, stop suggesting a dish you have already said no to, and keep a blocked sender from reaching you again. |
| Your subscription Where you buy one |
Which plan you bought, whether it is active, its renewal and expiry dates, who sold it to you — an app store, or Paddle where a subscription is sold on the website — and that seller's transaction identifiers, and an identifier linking the purchase to your account. Not your card details — those go to the seller and never reach us. | To give the account that paid the features it paid for, and to answer a question about a charge. Set out in full under subscriptions and payment. |
| Operational records | Server logs from our hosting provider, which include the IP address a request came from; a random per-request reference id; and, from the mobile app, its version, build number and platform. Separately, a small durable record of significant failures, holding typed fields only — an operation name, an error code, a timestamp, and where relevant an account or household id. | To keep the service running, to investigate a failure you report, and to detect abuse. The durable failure records deliberately have no free-text field, so they cannot hold a recipe, a prompt, a message or an email address. |
There is no location tracking, no contacts access and no microphone access in the KalaPlate app. Payment and subscription information is a separate subject and has its own section below.
This section is deliberately precise, because "we don't track you" is a sentence that is easy to write and easy to outgrow. Here is the distinction that matters: an identifier that makes your account work is not the same thing as an identifier that follows you around.
These exist to run your account, and each one is described where it belongs elsewhere in this policy:
We describe those as functional identifiers rather than tracking identifiers, and we think the distinction is a real one rather than a convenient one: none of them is shared with an advertising network, sold, or used to build a profile of you.
KalaPlate offers free features and may offer paid ones. Where a paid subscription is offered to you and you buy one, this is what happens to the information involved. Where no paid subscription is offered to you, nothing in this section applies.
There are two ways a KalaPlate subscription can be sold, and they are not the same arrangement:
Whichever of the two sold it, your card or payment method is given to that seller, not to us. KalaPlate does not receive your full card number, your card security code or your bank details, and we could not store them if we wanted to: they never reach us. We hold no payment credentials for anybody, and there is no payment-taking code in KalaPlate that could receive them.
The same goes for the billing details a seller needs and we do not. Your billing address, the country you are taxed in and the invoice or receipt itself belong to the sale, and the receipt is sent to you by the seller rather than by us.
To give you what you paid for, we need to know that a purchase happened and that it belongs to your account. So where a subscription is bought, we may process:
That last one is the "subscription identifier" named in the section above. It is generated by us, it means nothing outside KalaPlate and its subscription infrastructure, and it is not your email address, your name or a device id.
That is the whole of it. We are not sent your card details, your billing address or your tax details, and none of them reaches us by any other route either.
When paid subscriptions are available, purchase and subscription status is handled for us by RevenueCat, a subscription-management provider, acting on our instructions. It receives the subscription information described just above — the plan, the status and dates, the seller's transaction identifiers, and the identifier linking the purchase to your account. It does not receive your household data, your members, your allergies, your plans or your recipes, and it does not receive your card details either.
RevenueCat sits behind every way of buying, including the website one: a subscription sold by Paddle reaches us the same way an App Store or Google Play one does, as a subscription record passed on by RevenueCat. That does not make RevenueCat the seller. Apple, Google and Paddle each remain the seller of what they sold you — RevenueCat keeps the record straight so the account that paid is the account that gets the features, and nothing more.
Where a subscription is sold on the website, the identifier linking it to your account travels with the purchase so it can be matched back to you. It is the same identifier described above: generated by us, meaningless outside KalaPlate and its subscription infrastructure, and not your email address, your name or a device id.
Paid subscriptions are not switched on for every version of KalaPlate. Where they are not, no purchase information exists for your account and none of the processing described in this section takes place. This section is written in advance so that it is accurate on the day it starts applying, rather than being updated after the fact.
Deleting your KalaPlate account does not by itself cancel a subscription, wherever you bought it — see deleting your account. Nor can we erase the record the seller keeps of the sale: an app store, and Paddle as merchant of record for a website purchase, each hold their own transaction records under their own tax, accounting and consumer-law obligations. Those are theirs rather than ours, so a request about them goes to that seller, and we will point you at the right one.
KalaPlate is for adults. Accounts are created and held by an adult, and children do not sign in, do not have accounts of their own, and are not users of the service.
An adult account holder can, however, add children as members of their household — and that means the account can hold a child's first name, age, allergies, dietary restrictions, portion size, whether their school is nut-free, their canteen days and a recess note. Some households also record a child's calorie and macro targets.
We collect that information because it is what makes a plan safe and correctly sized for a family: an allergy that is not recorded is an allergy the planner cannot avoid. We use it for nothing else. It is never used for advertising or profiling, and it is not shared with anyone beyond the service providers listed below.
If you add a child to your household, you are telling us you are that child's parent or guardian, or otherwise entitled to provide their information. If you would rather not record a child's details, you can leave those fields blank — an allergy is the only one we would strongly encourage you to fill in, and you can use a nickname instead of a real name anywhere a name is asked for.
Allergies, dietary restrictions, body measurements, activity level, goals, calorie and macro targets and the daily food log are all health-adjacent, and we treat them as the most sensitive things in the account. They are used to plan meals and to draw the tracker, and for nothing else.
KalaPlate is not medical advice. It is not a diagnostic tool, it is not a dietitian, and it is not a substitute for one. Nutrition figures are estimates worked out from an ingredient table, and allergy handling is a planning aid, not a guarantee. Anyone with a serious allergy, a medical condition or a clinical dietary requirement should check ingredients themselves and take advice from a qualified professional.
Three different things happen to an image in KalaPlate, and they are worth telling apart.
When you import a recipe from a photo of a cookbook page, a screenshot or a PDF, that file is sent to our AI provider to be read into a recipe. The file itself is not stored. What is kept is the recipe that came out of it — title, ingredients, method — saved to your favourites.
Where the fridge-photo feature is enabled for your account, it sends the photos you choose to our AI provider to be read into a list of ingredients, and returns that list. The photos are not stored, by us or in your account. This is a limited-release feature and is not switched on for every account; where it is not available to you, nothing described in this paragraph happens.
If you attach your own photo to a recipe you are saving, that photo is stored with your favourite, so it shows on the card. It is visible to your household — and to another KalaPlate user if you choose to share that recipe with them, because the photo travels with the recipe you sent. Nothing else in KalaPlate shows it to anyone: it is deleted with your account, it is never sent to an image-generation provider, and it is never added to the shared recipe catalogue.
Separately, KalaPlate draws its own illustrations of dishes. Those are generated from a written description of the dish — the image provider receives text, never a photograph of yours and no household information.
KalaPlate uses a small number of service providers. They act on our instructions, for the purposes below and no others. We do not sell your information and we do not share it with advertisers or data brokers.
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Hosts the website and the API. | Every request to KalaPlate, including its IP address and the usual server-log metadata. |
| Supabase | Runs the PostgreSQL database. | Everything in the "What we collect" table above, because that is where it is stored. |
| Anthropic | The AI model that writes plans and recipes, reads an imported recipe, and reads a fridge photo. | The household context a plan needs. This includes each member's first name, whether they are an adult or a child, a child's age, allergies, dietary restrictions and any calorie and macro targets — a plan cannot say "this one is Ana's, no dairy" without them. It also receives the recipe photos, PDFs and page text you import, and any fridge photos you send. It never receives your email address, your password or your password-recovery answer. |
| Replicate | Generates the illustration for a dish. | A written description of the dish only. No household data, no personal information, no photograph of yours. |
| Expo EAS Update — mobile app only |
Delivers updates to the mobile app over the air. When the app starts, it asks Expo in the background whether a newer version of the app's code is available, and downloads it if there is one. This is how a fix reaches you without waiting for a store release. | The random app installation identifier described above; which platform the app is running on (iOS or Android); which version of the app is installed and which release channel it follows; and, if the app's previous launch failed, a short technical error message, which is what lets a bad update be withdrawn. No account, no email address, no household, no members, no allergies, no plans and no recipes — the update check happens before and independently of anything you are signed in to, and carries none of it. |
| Apple and Google Where a subscription is sold |
The App Store and Google Play sell and process a subscription bought inside a mobile app. | Your payment details, which go to the store and not to us, under the store's own privacy policy. They tell us that a purchase happened, which plan it was, and whether it is still active. |
| Paddle Where a subscription is sold on the website |
Sells and bills a subscription bought on the website. Paddle is the merchant of record — the seller of that purchase in its own name — so it takes the payment, works out and collects any tax due, issues your receipt, and runs the page where that subscription is managed and cancelled. | Your payment details, and the billing and tax information Paddle needs in order to sell to you. You give those to Paddle and they do not reach us; Paddle handles them in its own right, under its own privacy notice, rather than on our instructions. We tell it which plan is being bought and give it the identifier that links the purchase to your account, so the purchase can be matched to it. No household data, no members, no allergies, no plans and no recipes. |
| RevenueCat Where a subscription is sold |
Keeps track of subscription status, so the right account gets the features it paid for. | The subscription information described under subscriptions and payment: plan, status, dates, the seller's transaction identifiers, and the identifier linking a purchase to your account. No household data, no members, no allergies, no recipes, and no card details. |
The last three rows apply only where a paid subscription is offered and you buy one. Until then no purchase information exists for your account and none of them receives anything about you. Which of them is involved follows from where you bought it: Apple or Google for a purchase made inside a mobile app, Paddle for one made on the website, and RevenueCat behind either.
The Expo row applies to the mobile app only — there is no equivalent on the website. It is there to deliver software updates and for nothing else: the installation identifier is not an advertising identifier, it is not used to target advertising anywhere, it is not sold or shared with an advertising network or a data broker, and it is not combined with anything you do in KalaPlate. You can stop the update check entirely by using KalaPlate in a browser instead of the app.
These providers are established outside Australia, primarily in the United States, so information described above is transferred to and processed in other countries. We rely on our agreements with them, and on their own published terms, to require that they handle it only for the purposes we have asked for.
We may also disclose information where we are legally required to, or where it is necessary to investigate abuse or protect the safety, rights or property of our users or of KalaPlate.
If you share a recipe with someone by email address, the recipe travels to that person's KalaPlate inbox along with the email address you sent it from, so they know who it is from. If the recipe has a photo you attached yourself, that photo goes with it. That copy is theirs, sits in their account, and stays there even if you later delete yours.
Before the copy is written, personal serving advice is stripped out of the recipe's notes — a plan's notes can name a member of your household and describe how to size their plate, and none of that belongs in a stranger's kitchen. Nothing else about your household travels with a shared recipe: no members, no allergies, no targets and no settings.
If you report a share, we record which share it was, that it was you who reported it, the reason you picked from the list, and when. There is no free-text field on the report, so it cannot carry anything you type. We use it to look at the share and decide what to do, and for nothing else.
If you block a sender, we record that person's email address in your account, along with their account if they have one, so a later attempt to reach you is refused even if they change their address. The person you blocked is not told and cannot see the list. You can see and undo your own blocks from your account page, and the whole list is deleted with your account. What we do about a report, and how quickly, is described in the terms of use.
Recipes generated for your plans, and recipes you import from a link, a photo or a PDF, are also added to the shared KalaPlate recipe catalogue so other households can be offered them. Before that copy is written, personal serving advice is stripped out, and the copy carries no name, no account id and no household id — it is a recipe, not a record of you. An imported recipe is held back for a person to review before it can be served to anyone else. Your own private copy in your favourites is separate and is deleted with your account.
Your account and everything attached to it is kept for as long as the account exists. We do not have a scheduled purge of active accounts — a household's allergies and favourites are meant to be permanent until they change them.
Server logs are held by our hosting provider and are retained according to that provider's applicable retention settings; we do not control how long it keeps them. The durable failure records described above may be pruned periodically under our retention procedures. We do not claim a fixed schedule for that, and we would rather say so than describe a routine we cannot promise you.
You can delete your account yourself, at any time, without asking anyone and without leaving the app you are already in:
Both ask for your password and for you to type DELETE, and the app asks you to confirm once more before it sends anything. Both run the same deletion on our servers, and both are done immediately — there is no grace period and no undo.
Deleting the account deletes, in the same operation: your login and password, your household and its settings, every member and everything recorded about them, every daily tracker entry, every plan and meal, your favourites and their photos, your shopping regulars and store preferences, your declined dishes, your custom ingredients, and any recipes sitting in your shared-recipe inbox.
Being honest about this is more useful than a clean claim. After your account is deleted, the following remain:
Deleting your KalaPlate account does not cancel a subscription you are paying for. An App Store or Google Play subscription is held by the store, on your store account, and only you can cancel it there. A subscription sold on the website is held by Paddle, and is cancelled from the management link in the receipt Paddle sent you. KalaPlate cannot reach into either one and does not attempt to. Cancel the subscription with whoever sold it to you as well, or it goes on renewing after your KalaPlate account is gone. The two are separate actions.
Full detail, including what to do if you cannot sign in, is on the account deletion page.
In general terms, and describing only what we actually do:
No service can promise perfect security, and we do not. If we ever become aware of a breach affecting your information, we will notify affected users and any regulator we are required to notify.
Australian users who are unhappy with how we have handled a privacy matter may complain to the Office of the Australian Information Commissioner. We would rather you told us first.
Privacy questions, requests and complaints:
This is also the address to use if you cannot sign in and need help deleting your account.
If we change what we collect or who processes it, we will update this page and move the "last updated" date at the top. Where a change is significant we will say so in the app as well. The date at the top is always the authority for which version you are reading.