Document version: 1.0 Effective date: 6 June 2026 Last updated: 6 June 2026
This Privacy Policy explains how the Elio mobile application ("Elio", "we", "us", "our") collects, uses, shares, and protects information about you when you use the app. Elio is a recipe and meal-planning app that uses generative AI to suggest meals based on the food you have, your dietary needs, and your household.
If you have any questions about this policy or how your data is handled, contact us at support@eliochef.com.
The business responsible for the personal information described in this policy (the "data controller" under EU/UK law and the "business" under US state laws) is:
Studio Eyespy LLC (the maker of Elio) 2754 NE 103rd St, Seattle, WA 98125, USA Email: support@eliochef.com
We do not currently appoint a representative under Article 27 of the UK or EU GDPR; if you are an EU or UK resident and would prefer to direct enquiries to a representative, contact us at the email above and we will respond directly within 30 days.
We have not appointed a Data Protection Officer. Our processing activities do not meet the thresholds in Article 37(1) of the UK or EU GDPR that would require us to appoint one (we are not a public authority, our core activities do not consist of large-scale monitoring of data subjects, and our core activities do not consist of large-scale processing of special-category data — we process dietary/allergy data only as a small consumer service). If our activities later cross those thresholds, we will appoint a DPO and update this notice.
We collect only the data we need to run the app. We do not collect: phone numbers, dates of birth, profile photos, GPS or precise location, contacts, social-media connections, or web-browsing history outside the app.
| Category | Examples | Where it's stored |
|---|---|---|
| Account identity | Email address, sign-in provider (Google, Apple, or email/password), display name (optional) | Google Firebase Authentication and your user record in Google Cloud Firestore |
| Onboarding profile | Cooking confidence level, household type, household composition, primary cooking goal, time/mood preferences, disliked ingredients | Google Cloud Firestore |
| Dietary and health-related preferences | Dietary requirements (e.g. vegetarian, gluten-free), allergies and intolerances, household members' names and their dietary requirements | Google Cloud Firestore. We treat allergies and dietary requirements as "consumer health data" under Washington's My Health My Data Act and as "special category" / "sensitive" data under EU/UK GDPR and California's CPRA. See §3 (Legal bases) and §8b (Washington Consumer Health Data Privacy Notice). |
| Region and units | Country/region (used to choose imperial vs metric units and currency display) | Google Cloud Firestore |
| Kitchen setup | Available appliances (oven, microwave, blender, etc.), cuisine and style preferences | Google Cloud Firestore |
| Pantry inventory | Names of foods you tell Elio you have, categories, optional expiry dates, optional prices, "running low" flags | Google Cloud Firestore |
| Scanner learning | A normalised mapping of ingredient names to pantry tiers built from your past scanner uses | Google Cloud Firestore (tierMemory subcollection) |
| Recipes you save, generate, or rate | Recipes you bookmark, like, dislike, or generate, plus the resulting "taste profile" we keep for the AI (a list of recipe titles you've liked or disliked) | Google Cloud Firestore |
| Meal plans and shopping lists | Weekly meal plans you create or accept, items on your shopping list and their status | Google Cloud Firestore |
| Photos you import | Photos of recipes (from camera or gallery) used for AI recipe import; photos of receipts used for the AI receipt scanner | Sent to Google's Gemini API for processing; not stored by Elio |
| Barcode scans | Live camera frames during scanning | Processed on-device only; not stored or transmitted |
| Voice input/output | Spoken commands during voice cooking; recipe text spoken back to you by the device | Sent to your device's speech-recognition / speech-synthesis service. On Android most spoken audio is processed by Google Speech Services (which may transmit audio off-device for processing); on iOS it is processed by Apple's Speech framework (typically on-device but may transmit depending on device settings). Elio does not receive or store your voice audio. Google or Apple may receive and process it under their own retention policies — see their privacy policies linked in §4. |
| Notification preferences | Your toggles for weekly meal reminders, restock reminders, and tips & updates | Google Cloud Firestore |
| Category | Examples | Purpose |
|---|---|---|
| Push notification tokens | Firebase Cloud Messaging device token, platform (iOS/Android) | To deliver push notifications you've opted in to |
| Subscription state and usage counters | Subscription tier (free or Pro), trial status, renewal status, recipe-generation counters and reset timestamps (so we can apply free-tier limits) | To unlock paid features and enforce free-tier limits |
| Crash and error reports (Firebase Crashlytics) | Stack traces of crashes and non-fatal errors, a tag describing which feature was being used, plus the standard device metadata Crashlytics collects automatically: device model, OS version, app version, locale, available RAM and disk, device orientation, and a randomly-generated installation identifier | To diagnose and fix bugs |
| Analytics (Firebase Analytics) | Screen views; feature usage events including (but not limited to) onboarding step completed, paywall shown / dismissed / subscribe tapped, purchase completed, purchase restored, recipe generated, recipe saved, recipe rated, ingredient substituted, ingredient added to shopping, side-dish generated, voice cooking started / stopped / completed, hands-free cooking started / exited / completed, scan items added, meal plan generated / regenerated, sign-in method; user properties: authentication method, subscription tier, household size; device type, app version, country derived from IP address, app instance ID (a pseudonymous per-install identifier set by Firebase). We do not send dietary requirements, allergies, or any other consumer health data to Firebase Analytics — see the standalone Washington Consumer Health Data Privacy Notice. | To understand how the app is used so we can improve it |
| App configuration | App build name and number, locale, device language | For sizing UI, localising units, and reporting in crash logs |
We do not run third-party advertising, sell your data to data brokers, or use it for behavioural marketing. We do not assign you an Android Advertising ID or Apple IDFA — both are explicitly disabled in our build configuration.
⚠️ Your controls. Analytics and crash reporting are on by default. When you first open Elio we show you a short data-use notice describing this and linking to this policy, with a one-tap path to manage your choices. You can withdraw your consent at any time in Settings → Privacy & Data (or by emailing support@eliochef.com); turning a category off disables the underlying SDK immediately. We never send your dietary requirements, allergies, or any other consumer health data to Firebase Analytics.
When you ask Elio to suggest a recipe, generate a meal plan, import a recipe from a photo or URL, scan a receipt, or get an ingredient substitution, we send the following information to Google's Gemini API (operated by Google LLC) so it can produce a useful answer:
We do not send your name, email address, location, household member names, or any other directly identifying information to the AI model.
Google's Gemini API processes the request and returns a result. Google retains prompts and responses for a limited period for abuse-monitoring purposes; please refer to Google's Gemini API Additional Terms of Service (https://ai.google.dev/gemini-api/terms) for the current details on Google's processing of API data. We do not separately control Google's retention.
The following data is stored locally in the app's standard preference storage (Android SharedPreferences / iOS NSUserDefaults, which are not encrypted — do not assume secure storage) and is not transmitted to our servers:
This data is wiped when you delete your account in the app. Signing out does not automatically wipe locally-cached recipe history; if you want it gone without deleting the account, reinstall the app.
Subscription billing is handled by RevenueCat in partnership with the Apple App Store or Google Play Store. Card numbers, billing addresses, and payment processing are handled entirely by Apple, Google, and RevenueCat — Elio never sees your payment details.
We receive only:
The legal basis we rely on depends on which jurisdiction's privacy law applies to you.
We collect and process your information based on the notice provided in this Privacy Policy and your continued use of the app. Specifically:
You can withdraw consent or exercise any right at any time through Settings → Privacy & Data or by emailing support@eliochef.com.
We rely on the following legal bases under Article 6 of the UK GDPR and EU GDPR:
| Purpose | Legal basis |
|---|---|
| Creating and running your account, syncing your pantry, processing your subscription | Performance of a contract (Art. 6(1)(b)) |
| Processing your dietary requirements and allergies | Explicit consent (Art. 9(2)(a)) — these are health-related "special category" data under Article 9 |
| Analytics, crash reporting, and any storage/access to your device for non-essential purposes | Consent (Art. 6(1)(a) and PECR / ePrivacy regulations) — on by default; you can withdraw any time in Settings → Privacy & Data |
| Push notifications you've opted in to | Consent (Art. 6(1)(a)) |
| Responding to legal requests, preventing abuse, defending legal claims | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Tax and billing records (held by Apple/Google/RevenueCat) | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
Granular controls. Analytics, crash reporting, and product-update notifications are separately togglable in Settings → Privacy & Data. Separately, declining to provide your dietary requirements/allergies means the AI features that depend on them (recipe generation, meal plan, photo recipe import, receipt scanning) become unavailable, but the rest of the app — including viewing recipes you've already saved, manual pantry editing, manual meal-plan editing, and shopping list — continues to function. This separation is intended to satisfy the requirement under Article 7(4) and EDPB Guidelines 05/2020 that consent be freely given and not bundled with contractual necessity.
We share data with the following service providers ("sub-processors") so the app can work. Each one is contractually required to protect your data and use it only for the purpose we engage them for.
| Sub-processor | Purpose | Where data is processed | More info |
|---|---|---|---|
| Google LLC / Google Cloud / Firebase (incl. Authentication, Firestore, Cloud Messaging, Crashlytics, Analytics, Remote Config) | Authentication, database, push messaging, crash reporting, analytics, remote configuration | US and global Google Cloud regions; transfers from UK/EEA protected by EU Standard Contractual Clauses and the UK International Data Transfer Addendum | https://firebase.google.com/support/privacy |
| Google LLC (Generative AI / Gemini API) | Recipe generation, photo and URL recipe import, receipt scanning, ingredient substitution | US data centres; transfers from UK/EEA protected by EU SCCs / UK IDTA | https://ai.google.dev/gemini-api/terms |
| RevenueCat, Inc. | Subscription management and entitlement | US data centres; transfers from UK/EEA protected by EU SCCs / UK IDTA | https://www.revenuecat.com/privacy |
| Apple Inc. | App Store payment processing on iOS, push notification delivery (APNs), Sign in with Apple where you choose to use it | Apple's global infrastructure | https://www.apple.com/legal/privacy/ |
Google LLC (Google Play, Google Sign-In, Google Speech Services on Android, Google ML Kit via mobile_scanner) | Google Play payment processing on Android, OAuth sign-in, on-device speech recognition (which may transmit audio for processing depending on device settings), on-device barcode scanning (which may use Google Play Services for ML Kit) | Google's global infrastructure | https://policies.google.com/privacy |
We do not share your data with advertisers, data brokers, marketing companies, or any third party for their own marketing purposes.
If we ever engage a new sub-processor, we will update this list before they start processing your data.
Some of our sub-processors are based in the United States or process data outside the UK and EEA. Where this happens:
You can request copies of the relevant safeguards by emailing support@eliochef.com.
We keep your data for as long as your account exists. When you delete your account — in the app via Settings → Account → Delete Account, or by emailing support@eliochef.com with the subject "Delete my account" — we erase your account, profile, pantry, recipes, ratings, meal plans, shopping list, household members, scanner-learning records, and push tokens from our active databases immediately.
Some residual data persists beyond account deletion:
If you would like a more detailed retention statement for a specific category, email us.
The exact rights available to you depend on where you live (see below). For all rights, the easiest way to exercise them today is by emailing support@eliochef.com with the subject "Privacy request". We will respond within 30 days (45 days for California residents where allowed by the CPRA, with notice).
The app provides Settings → Account → Export My Data (a JSON export of everything we hold about you, in line with GDPR Article 20 portability) and Settings → Account → Delete Account (in-app erasure). You can also exercise any right by emailing us.
| Right | Available to | How to exercise it |
|---|---|---|
| Access / Know — get a copy of your data | All users | Email us; we send a JSON file |
| Correction / Rectification | All users | Edit in the app, or email us |
| Deletion / Erasure | All users | In the app via Settings → Account → Delete Account, or email us with "Delete my account" |
| Portability | UK/EEA + California users | The JSON export above is structured and machine-readable |
| Opt out of sale or sharing | California users (and other US states with similar laws) | We do not sell or share personal information for cross-context behavioural advertising. We honour the Global Privacy Control (GPC) signal where the platform supports it. To make an explicit opt-out request, email us. |
| Limit use of sensitive personal information | California users | Email us; we will limit processing to what is strictly necessary to deliver the service |
| Withdraw consent for analytics, crash reporting, or notifications | All users | Toggle in Settings → Privacy & Data, or email us |
| Object to processing based on legitimate interests | UK/EEA users | Email us |
| Restrict processing | UK/EEA users | Email us |
| Lodge a complaint | UK: Information Commissioner's Office (https://ico.org.uk). EEA: your local supervisory authority (https://edpb.europa.eu/about-edpb/about-edpb/members_en). California: California Privacy Protection Agency (https://cppa.ca.gov). Washington: Washington State Attorney General (https://www.atg.wa.gov). |
We do not discriminate against you for exercising any of these rights. We will not charge for these requests unless they are manifestly unfounded or excessive.
California and several other US state laws allow you to authorise an agent to act on your behalf. To do so, the agent must provide us with written, signed permission from you and verify their own identity. Email support@eliochef.com with the subject "Authorised agent request".
This section supplements the rest of the policy and applies if you are a California resident.
Under the CPRA's standard categories:
| CPRA category | Do we collect it? | Source | Purpose |
|---|---|---|---|
| Identifiers (e.g. email, account ID, device IDs) | Yes | You; your device | Account, service delivery, security |
| Customer records (name) | Yes (display name, optional) | You | Personalisation |
| Protected classifications | No | — | — |
| Commercial information (subscription state, usage counters) | Yes | You; the App Store / Play Store / RevenueCat | Billing, free-tier enforcement |
| Biometric information | No | — | — |
| Internet/device activity (analytics events, crash reports, screen views, app instance ID) | Yes (with consent) | Your device | Product improvement, debugging |
| Geolocation (country derived from IP) | Yes (coarse only) | Your device's IP | Localisation, regional store routing |
| Sensory data (voice audio for voice cooking; photos for recipe import / receipts) | Yes (only when you initiate) | You | Feature delivery |
| Professional / employment | No | — | — |
| Education | No | — | — |
| Inferences (taste profile) | Yes | Derived from your usage | AI personalisation |
| Sensitive personal information (account credentials, health-related data: dietary requirements + allergies) | Yes | You | Account access; AI personalisation. We do not use sensitive personal information beyond what is necessary to provide the service you've requested. |
In the preceding 12 months we have disclosed the following categories of personal information to the sub-processors listed in §4 for the business purposes set out in this policy:
We have not sold or shared any category of personal information for cross-context behavioural advertising in the preceding 12 months.
We collect the categories above from: (i) you directly, when you sign up and use the app; (ii) your device, automatically (analytics, crash reports, push tokens); (iii) Apple, Google, and RevenueCat for subscription state.
We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising as those terms are defined under the CPRA. We have not done so in the preceding 12 months and do not currently plan to.
We honour the Global Privacy Control (GPC) browser/device signal where it is technically detectable to us.
See §6.
A condensed notice is presented in the app at first launch (a data-use notice) and at the point of collection (during onboarding for dietary/allergy data). Analytics and crash reporting can be turned off in Settings → Privacy & Data. The full disclosures are in this Policy.
See §7. To exercise any right, email support@eliochef.com.
Verification of consumer requests. We verify your identity by matching the email address you contact us from against the email on your account. For deletion requests and requests involving sensitive personal information, we apply the CPRA-mandated "reasonably high degree of certainty" standard by also requesting at least one additional matching data point — typically your account creation date, the device or sign-in method you most recently used, or a recent transaction identifier. We will not use the verification information for any other purpose.
We do not offer financial incentives in exchange for the collection, sale, retention, or processing of personal information. Subscription tiers (free/Pro) reflect feature differences only, not data-collection differences — Pro subscribers do not pay less and do not surrender additional data.
Email: support@eliochef.com Subject line: "California privacy request"
If you are a Washington State resident, dietary requirements and allergies you tell us are "consumer health data" under Washington's My Health My Data Act (RCW 19.373).
A separate, dedicated notice covering this data — including how we collect, use, and share it; your rights to confirm, access, delete, and withdraw consent; and the appeal mechanism — is provided here:
This standalone notice satisfies the distinct-notice requirement of RCW 19.373.020.
Elio is not directed at children. You must be at least 16 years old to use the app, regardless of where you live.
How we enforce this: when you first set up Elio, you must confirm you are 16 or older before you can continue. We do not collect your date of birth — it is a single confirmation step.
We do not knowingly collect personal information or consumer health data from anyone under 16. If we become aware that a user is under 16, we will delete the account and all associated data. If you believe a child has used the app and given us their data, contact support@eliochef.com and we will investigate and delete the account.
If you are between 16 and 18, we recommend that a parent or guardian reviews this policy with you.
We protect your data using:
Locally-cached data on your device is stored in standard preference storage, which is not encrypted at the application level (it is protected by your device's encrypted file system if you have a device passcode set). Do not assume secure storage for the local-cache items listed in §2.4.
No system is perfectly secure. If we ever become aware of a data breach affecting your account, we will notify you and the relevant supervisory authority within the timeframes required by applicable law:
Recipe suggestions, meal plans, and similar outputs are generated by a large language model (Google Gemini). At a high level, the model takes the following as input: your pantry, your dietary requirements, your appliances, your preferences, your taste profile (recipes you've previously liked or disliked), and any free-text request you've typed; and produces a recipe or meal plan as output.
This constitutes profiling within the meaning of GDPR Art. 4(4) — automated processing of personal data to evaluate aspects relating to a person, including dietary preferences. Under Art. 13(2)(f), we disclose:
These suggestions are not automated decisions in the GDPR Article 22 sense — they have no legal or similarly significant effect on you. You can also opt out of AI features entirely by not using the recipe-generation, meal-plan, photo-import, URL-import, or receipt-scanning features.
We will update this policy when our practices change. The "Last updated" date at the top will reflect the most recent version. If the change is material (for example, adding a new sub-processor or a new category of data), we will notify you in the app or by email before the change takes effect.
We keep prior versions of this policy on request — email support@eliochef.com.
For any privacy question, request, or complaint:
Email: support@eliochef.com Subject line: depends on your request — "Privacy request", "California privacy request", "Washington health data request", "Authorised agent request", etc.
We will respond within 30 days (45 for California / Washington residents where the law allows).