← Home

Privacy Policy

Last updated September 10, 2026

This is drafted content, not reviewed by a lawyer or privacy specialist. It describes current intent and actual system behavior as accurately as we can, but it has not been finalized as a legal document — treat it as a good-faith description, not a guarantee.

What we collect

  • Account info: your email address, used only to sign you in (a one-time code or link — we never see or store a password).
  • Child profile info you enter: a first name, age, allergies/restrictions, diet, food preferences, and picky-eater level. This is entered by you, the parent/guardian — we don't collect it directly from a child, and the app is not designed for a child to create their own account.
  • Classroom membership: which classroom you or your child belong to, joined via a code your child's teacher gives you.
  • Barcode scans: the barcode itself and the product data we look up for it (from Open Food Facts, a public database) — not your location or any image.
  • Usage data: favorited lunches, ratings, and week plans you create, tied to your account.

What we don't do

We don't sell your data or your child's data. We don't run ads or use your information for advertising, anywhere, for anyone. We don't share your data with anyone outside your classroom except the third-party services listed below, which we use to run the app itself.

Who can see what

You (a guardian) can only ever see your own children's profiles — the database itself is configured so this isn't just a UI choice. Classroom-level information (the classroom's restriction list, its rules, its shared grocery list, and its change log) is visible to every verified member of that specific classroom — other parents and the teacher who joined the same room with the same code. A classroom's teacher can additionally see and edit that classroom's own restriction list and rules, and see the log of who changed what.

Where your data lives

The app runs on Vercel and stores data with Supabase (a hosted Postgres database), encrypted in transit. Sign-in emails are sent through Google (Gmail SMTP). Barcode product data is fetched from Open Food Facts, a public, open database.

Children's data

This app is intended to be used by parents and teachers, not directly by children. Any information about a child is entered by their parent or guardian, who controls it and can edit or delete it at any time. We don't knowingly collect information directly from a child, and we don't allow a child to create their own account.

Deleting your data

Email lunchboxsafe@gmail.com to request deletion of your account. Deleting your account removes your children's profiles, favorites, and week plans along with it — this cascades automatically and can't be undone.

Changes to this policy

If this policy changes in a meaningful way, we'll update the date at the top of this page. See also our Terms of Service.

Contact

Privacy questions: lunchboxsafe@gmail.com.