Legal
Last updated: September 26, 2026
Which cookies and similar technologies MealVerve uses, why, for how long, and how you control them.
Cookies are small files a website stores in your browser. Local storage, session storage and cache storage work similarly. EU law lets us use them without asking only when they are strictly necessary for a service you asked for. Everything else needs your consent. This policy covers the MealVerve website and Android app, which uses the same web technology. It is operated by Charalambos Rotsides; see the Privacy Policy for how we handle personal data.
These are needed for sign-in, security, remembering your choices and basic app features. They are not used to track you.
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| appSession (may be split into appSession.0, .1 …) | MealVerve (Auth0 SDK) | Keeps you signed in; encrypted | Up to 7 days; renewed while you are active (24-hour idle timeout) | Cookie |
| auth_verification | MealVerve (Auth0 SDK) | Protects the sign-in flow against forgery | Deleted when sign-in completes (max. 1 hour) | Cookie |
| Auth0 session cookies (e.g. auth0, did) | Auth0 (on the login domain) | Sign-in security, single sign-on and bot detection | Up to 3 days / 1 year for device ID | Cookie |
| mealverve_consent_v1 | MealVerve | Stores your privacy choices | 180 days | Cookie |
| mealverve_cookie_consent | MealVerve | Older copy of your analytics choice, kept in sync for compatibility | 180 days | Cookie |
| mealverve_meta_signup, mealverve_acquisition_context | MealVerve | Remembers during sign-up whether you started from a sign-up link and which starter pack or campaign link you followed. Only used for measurement if you gave consent | 15 minutes | Cookie |
| mealverve:consent:v1, mealverve:cookie-consent | MealVerve | Local copy of your privacy choices | 180 days / until cleared | Local storage |
| mealverve:onboarding:v1 | MealVerve | Resumes onboarding where you left it | Until cleared | Local storage |
| Grocery list progress keys | MealVerve | Remembers which grocery items you ticked off on this device | Until cleared | Local storage |
| mm_install_prompt_dismissed, mm_notifications_blocked_dismissed, mm_push_resubscribe_dismissed | MealVerve | Remembers that you dismissed an install or notification prompt | Until cleared | Local storage |
| mealverve:pending-recipe-photo | MealVerve | Holds a photo you chose for recipe import while the page changes | Until the tab closes | Session storage |
| Service-worker caches (start-url, static-*, next-*, google-fonts …) | MealVerve | Lets the app load quickly and work offline. Contains app files and images, not personal profile data | Up to 24 hours for most files; fonts up to 1 year | Cache storage |
If you choose “Allow optional analytics”, PostHog (United States) records pages viewed and product events, such as completing onboarding or generating a meal plan, so we can see which features work. We do not send your email, recipes or health details to PostHog.
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| ph_<project key>_posthog | PostHog | Distinguishes visitors and sessions for product analytics | 1 year | Cookie / local storage |
The same analytics choice also enables the Meta Pixel. It tells us whether our ads on Facebook and Instagram led to visits, sign-ups, checkouts and subscriptions. When you sign up or subscribe with this choice on, our server also sends that event to Meta’s Conversions API with your email address in hashed (scrambled) form, your IP address and your browser type, so Meta can match it to an ad. Meta may use this data under its own terms, including to improve its advertising. Without your consent, nothing is sent to Meta, from your browser or from our server.
| Name | Set by | Purpose | Duration | Type |
|---|---|---|---|---|
| _fbp | Meta (Facebook) Pixel | Measures whether our ads led to sign-ups and subscriptions | 90 days | Cookie |
| _fbc | Meta (Facebook) Pixel | Stores the ad-click identifier when you arrive from a Meta ad | 90 days | Cookie |
We do not currently show ads. The privacy panel already offers a separate advertising choice (“Off”, “Contextual only” or “Personalized”), which defaults to Off. No advertising provider is active. If we add one, we will update this policy and ask again before any advertising cookie is set. Recipe content, account details and health data are never shared for advertising. Paid members are ad-free.
Pages load fonts from Google Fonts, which receives your IP address to deliver them but does not set cookies. Recipe images are delivered by Cloudinary. Payment pages are run by Stripe or Google Play under their own cookie policies.
On your first visit, the privacy panel lets you reject all optional technologies, accept all, or choose analytics and advertising separately. Rejecting is as easy as accepting. A “Privacy choices” button stays at the bottom of the page so you can change or withdraw your consent at any time. Withdrawing stops the tools and deletes the Meta cookies we can reach. Your choice is stored for up to 180 days, after which we ask again. You can also delete cookies and site data in your browser settings; necessary features may then stop working until you sign in again.
Questions: support@mealverve.com.