The TL;DR
- We do not sell your data, and there is no advertising layer inside the Mise app.
- Before any personal data is sent to a third-party AI service, Mise names the provider, explains the data and purpose, and asks for your permission.
- OpenAI processes approved requests for meal plans, Sage, recipes, imports, scans, and recommendations. fal – Features & Labels, Inc. receives limited recipe text only when you approve an optional recipe cover.
- You may decline and keep using non-AI features. You may later change each choice in iOS Settings under Privacy → AI data sharing, or in Android Settings → AI data & privacy; withdrawing permission stops future sharing.
- Mise does not train AI models on your data. Our providers are contractually limited to the approved service. Mise has assessed their contractual and technical safeguards as providing the same or equivalent protection for the limited data and purposes described here.
- With permission, selected health and fitness observations may be saved to your Mise profile and included in an approved AI request. They are never used for advertising.
- Raw voice audio stays on your device. Dictation is unavailable when on-device speech recognition is unsupported; only a transcript you choose to send may reach OpenAI.
- Scan photos are access-controlled. Mise attempts deletion as soon as processing ends; failed cleanup is retried every five minutes once an upload is more than two hours old.
- You can review or delete Sage memories, withdraw AI permission, or delete your account in the app. Plan data is auto-deleted after 24 months without a login.
1. Who we are
Mise, Inc., Austin, TX, USA, is the data controller for this service. Contact: privacy@getmise.org. Our EU representative under GDPR Article 27 will be appointed before EU launch and listed here.
2. What we collect
2.1 Account and purchase data
We collect your email address, optional display name, a salted password hash managed by Supabase Auth, signup date, pseudonymous account ID, and subscription tier. Apple or Google processes payment-card details; Mise does not receive them. Mise and RevenueCat receive subscription and purchase metadata such as product, entitlement, trial or paid status, and expiration so we can provide the tier you bought. Legal basis under GDPR: contract performance.
2.2 Profile, pantry, and household data you provide
This can include sex, height, activity level, body metrics, nutrition and weight goals, calorie and macro targets, allergies and other dietary restrictions, foods and cuisines you like or avoid, cooking time and skill preferences, pantry inventory, country, ZIP or postal code, stores, and household members' display names, restrictions, preferences, and nutrition targets. Some of this can reveal health or religious information. We use it because you ask Mise to personalize food and meal-planning features. Where applicable, our legal basis is explicit consent, which you may withdraw at any time.
2.3 Health and fitness data
With your permission, Mise reads selected weight and body-composition observations and, when you enable workout-aware features, recent workout and active-energy summaries from Apple HealthKit on iOS or Android Health Connect on Android. The latest weight and body-composition values may be stored in your Mise account to show trends and personalize meal plans. Workout type, duration, energy, and related derived summaries are used for workout-aware recommendations and may be included in a Sage request you approve.
We use HealthKit and Health Connect data only to provide health and fitness features. It is never sold, used for advertising, shared with data brokers, or used to determine advertising eligibility. It is shared with an AI processor only after the separate AI permission described in Section 4 and only for the feature you request.
2.4 Plans and other content
We collect meal plans, grocery lists, pantry items, saved and generated recipes, cooking ratings, Sage messages and saved Sage memories, instructions you type or dictate, and edits you make. For recipe import, we collect the URL you submit, fetch the page, and process its page text or HTML. We store a cleaned source address without URL query parameters as provenance for the imported recipe.
When you choose a camera feature, we collect the photos you select and anything visible in them. These can include refrigerator or pantry contents, grocery-receipt merchants, items and prices, restaurant menu text, or product-label ingredients and nutrition facts. Do not include another person's personal information unless you have permission to share it.
2.5 Product, store, and location data
For Product Fit, we store structured product facts, the heuristic version, and your private assessment result. A barcode may be sent to USDA FoodData Central to retrieve public nutrition data; your identity, health data, allergies, and goals are not sent to USDA. We store the country and ZIP or postal code you provide to personalize seasonal produce and nearby-store results. Product Fit is informational and is not medical advice.
2.6 Optional connected appliances
If you connect Samsung SmartThings, Mise stores encrypted OAuth credentials plus the identifiers, names, capabilities, and last-sync times of the devices you select. Mise requests read-only access and reads only capabilities SmartThings exposes. We do not receive a general refrigerator camera feed, and camera or food-inventory access is not assumed. You can disconnect at any time; Mise then revokes the connection where the provider supports it and deletes stored credentials and cached device metadata.
2.7 Device, usage, and diagnostics data
We may process app and OS version, country, language, device or installation identifier, product interactions, crash stacks, performance data, and limited operation context. Client analytics and crash reporting are off by default and require the separate choice described in Section 6. Server error reports may include a pseudonymous Mise account ID or private storage object path so we can isolate a failed request; they do not include your name, email, or health values. Legal basis: consent for optional client analytics and legitimate interest for essential security, debugging, and reliability.
3. What we do not collect
- Your contacts or calendar; Mise does not request those permissions.
- Your payment-card number or bank details; the app store processes the transaction.
- Raw dictation audio. Speech recognition must run on-device or voice input fails closed. If you approve AI processing and send the resulting text, the transcript is treated as other user content under Sections 2.4 and 4.
- Precise coordinates on Mise servers. If you grant location permission, the app may use your location transiently with Apple MapKit to rank nearby stores; Mise stores the country and ZIP or postal code you provide as coarse location.
- Advertising identifiers such as IDFA or AAID.
4. How we use AI
4.1 Your permission and controls
AI data sharing is optional. Before the first request in each scope, Mise displays a versioned permission sheet that identifies the provider, the data categories, and the purpose. Nothing for that request is sent to the named provider unless you choose Allow. Choosing Not Now keeps non-AI features available and blocks the request. You may permit OpenAI processing, optional fal recipe-cover generation, and optional Sage memory extraction separately.
Review or change these choices in iOS Settings under Privacy → AI data sharing, or Android Settings → AI data & privacy. Turning a choice off stops future requests in that scope. It does not undo processing already completed; provider retention and deletion are described below. If we materially change a provider, data category, purpose, or retention term, we increment the consent version and ask again before sharing under the new terms.
4.2 OpenAI
If you allow OpenAI processing, Mise sends only the information needed for the AI feature you select:
- Meal plans, swaps, recipes, and recommendations: your request plus relevant profile, dietary, health and fitness, pantry, meal, store, preference, and household context. This may include body metrics, goals, macro targets, restrictions, your display name, recent cooking feedback, and—with each represented member's own current permission—household targets and attributed dietary restrictions. Mise uses request-local aliases rather than sending account or catalogue identifiers.
- Sage: the message or user-approved voice transcript, recent conversation, saved memories, and relevant profile, pantry, household, meal-plan, dietary, health, workout, local-date, and time-zone context. Tool results needed to answer or perform your request may also be included.
- Optional Sage memory: when separately enabled, Mise makes a second OpenAI request with your latest Sage message and Sage's reply so useful preferences or facts can be extracted and saved to your account. You can inspect or delete those memories in the same AI data settings.
- Scans: the pantry, refrigerator, receipt, restaurant-menu, or product-label photos you select, including visible text and objects. A menu analysis can also include the macro budget and dietary restrictions needed to rank choices.
- Recipe import: a cleaned form of the recipe URL containing its origin and path but no query parameters or fragment, plus a stripped, size-limited copy of the fetched page text or HTML, so the model can extract the recipe.
For a household plan, Mise includes another account member's targets or restrictions only when every represented household member has a current OpenAI permission. One household member cannot grant that permission for another adult; if a represented member has not allowed it, Mise blocks the household AI request instead of sending that member's data.
Mise does not send your account email, password, authentication token, raw voice audio, or payment-card details to OpenAI. A prompt can still contain identifying or sensitive information that you entered, that appears in a selected photo or page, or that is needed from the categories above.
OpenAI's API data controls say API data is not used to train or improve models by default unless the customer explicitly opts in. Mise does not opt end-user requests into model training or submit them as feedback.
Mise sends foreground requests through OpenAI's Responses API with store: false, so it does not ask OpenAI to retain response application state. OpenAI says standard abuse-monitoring logs may include prompts and responses and are generally retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect OpenAI's services or a third party. OpenAI also documents encrypted prompt-cache processing for up to 24 hours. Image or file inputs flagged as possible child sexual abuse material may be retained for manual review, including under stronger retention controls. Setting store: false does not mean Mise has Zero Data Retention; that is a separate control that requires OpenAI approval, and Mise does not claim it here. See OpenAI's API data controls.
4.3 fal – Features & Labels, Inc.
If you separately allow an optional AI recipe cover, Mise sends fal the recipe title, a short description, and up to five tags to generate the image. We do not include your account email, health data, pantry, household data, source photo, or imported page. Mise sends fal's no-store control with each inference request to prevent storage of the JSON input and output. fal's published default without that control is 30 days. fal initially returns the generated media through a public CDN URL, and Mise downloads the cover to its own storage. Mise asks fal to expire that public CDN copy after one hour, after downloading it to Mise storage. See fal's data-retention documentation.
The FLUX.1 schnell endpoint Mise uses is listed by fal as enterprise-ready. fal's API Services Terms state that client content for covered endpoints is not used to create, train, or develop fal's products or services.
4.4 Protection, withdrawal, and deletion
OpenAI and fal act as processors or service providers for the covered requests. Their data-processing terms require processing under Mise's documented instructions and applicable law, appropriate safeguards, assistance with applicable rights requests, and substantially equivalent data-protection duties for subprocessors. For the limited data and purposes described here, Mise has assessed those contractual and technical safeguards as providing the same or equivalent protection. If that changes, Mise will stop sharing personal data with the provider.
Provider-specific controls are in the AI data settings described in Section 4.1. Disabling OpenAI also disables future Sage memory extraction; disabling Sage memory alone stops the optional second extraction request; disabling fal stops new recipe-cover requests. You may ask us at privacy@getmise.org to pursue deletion of provider-held personal data. We will forward and support the request where applicable, subject to data already deleted, deidentified data, and legal or safety retention exceptions.
5. Retention and deletion
- Plans and account content: Retained while your account is active. Plan data is auto-deleted 24 months after your last login. You may delete saved items sooner where the app provides that control.
- Sage conversations and memories: Retained in your account until you clear the chat, delete individual memories, clear all memories, or delete the account. Turning off Sage memory stops future extraction but does not itself erase memories already saved.
- Recipe imports: The cleaned source URL, status, and imported recipe are retained with your account until you delete your account.
- Scan photos: Mise attempts deletion after the requested pantry, receipt, menu, or product-label analysis completes or fails. If that cleanup fails, the upload becomes eligible for an automated retry every five minutes once it is more than two hours old.
- Product-label extraction: A transient structured extraction is usable for up to 15 minutes and is deleted by the next scheduled cleanup, typically within 30 minutes of creation. Product facts and private Fit assessments you confirm are retained with your account until deleted.
- AI-provider data: OpenAI's standard abuse-monitoring and application- state controls and fal's no-store control are described in Section 4. Generated recipe covers downloaded to Mise are retained with the associated recipe.
- AI consent record: We keep the policy version, scope choices, and grant or withdrawal timestamps with your account so we can enforce your current choice.
- Purchase and subscription data: Retained while needed to provide and verify entitlements, resolve billing issues, and meet legal recordkeeping duties.
- SmartThings connection data: Retained only while connected; credentials and cached device metadata are deleted when you disconnect, unlink in SmartThings, or delete your Mise account.
- PostHog analytics: If you opted in, account deletion deletes the account-linked person and queues its events and recordings for deletion through PostHog's asynchronous erasure process.
- Backups: Encrypted backups roll out within 30 days of deletion.
- Crash logs: Retained for 90 days, then deleted.
- Transactional email logs: Retained for 30 days, then deleted.
Delete your account from Settings → Delete account, or email privacy@getmise.org. We complete deletion of active account data within 30 days. Encrypted-backup rollouts and operational logs follow the specific retention periods above; records we must retain by law and the provider exceptions disclosed in Section 4 may remain longer.
6. Analytics, cookies, and tracking
Analytics are off by default. Only if you affirmatively opt in — and never when your browser sends a Global Privacy Control (GPC) signal — do the site and app enable PostHog product analytics or client-side Sentry crash reporting. We configure those client tools not to attach your email, name, or health values; Sentry also removes user fields and URL query strings before sending a web event. Separately, Mise's server functions report operational failures to Sentry under our legitimate interest in service reliability; those reports may include the pseudonymous identifiers and limited context described in Section 2.7. We do not sell your data and there is no advertising layer inside the app.
The marketing site (getmise.org) also includes Meta and TikTok advertising pixels, but they are disabled by default and load only after you opt in, and are suppressed entirely when GPC is present. Where a server-side advertising event is sent, your email is SHA-256 hashed first so the raw value never leaves our systems. The site sets one functional cookie to remember whether you've dismissed the announcement bar. We respect GPC as a Do Not Sell / Do Not Share opt-out under CPRA.
Optional website analytics use Google Analytics cookies and first-party aggregate visit and App Store click counts only after you choose Allow analytics. You can withdraw permission using Analytics preferences. Global Privacy Control disables this collection. We disable advertising signals and enhanced measurement, exclude private account and sharing routes, and do not send form contents, email addresses, health values, or URL query strings. Google processes these website measurements; see https://policies.google.com/technologies/partner-sites.
7. Subprocessors and other recipients
- OpenAI OpCo, LLC (or OpenAI Ireland Ltd., where applicable) — approved AI inference for meal plans, Sage, recipes, imports, scans, and recommendations, plus separately approved Sage memory extraction. API data controls: developers.openai.com/api/docs/guides/your-data. DPA: openai.com/policies/data-processing-addendum
- fal – Features & Labels, Inc. — separately approved generation of recipe-cover images from limited recipe text. DPA: fal.ai/legal/data-processing-addendum
- Supabase — Postgres, Auth, private object storage, and Edge Functions. DPA: supabase.com/legal/dpa
- Vercel — marketing-site hosting and DNS for getmise.org. DPA: vercel.com/legal/dpa
- Resend — outbound transactional email. DPA: resend.com/legal/dpa
- Google Workspace — inbound email for addresses at getmise.org. DPA: workspace.google.com/terms/dpa_terms.html
- RevenueCat — subscription management and entitlement processing for in-app purchases.
- PostHog — product analytics after opt-in; configured not to receive email, name, or health values.
- Sentry — client crash reporting after opt-in and essential server-side operational monitoring, as described in Sections 2.7 and 6.
- Apple and Google — authentication, app-store purchases, on-device platform services, and permissions you choose.
- Kroger and USDA — grocery-price, seasonal-produce, and packaged-food lookups using item names, general area, or barcodes; no identity, health profile, allergies, or goals are sent.
- Samsung SmartThings — optional, user-initiated, read-only connection to devices you select.
- Meta and TikTok — marketing-site advertising pixels only after opt-in, as described in Section 6.
We review provider terms and safeguards before sharing personal data. We will give at least 30 days' notice before adding a new subprocessor, except when an urgent replacement is necessary for security or service continuity; in that case we will give notice as soon as practical. A new AI provider always requires a new consent version before use.
8. Your rights and choices
You have the right to:
- Access — request a copy of your data by email.
- Delete — delete account data in-app or by email.
- Correct — edit profile data in-app.
- Control AI sharing — allow or disable OpenAI, fal, and Sage memory scopes using the iOS or Android AI data settings described in Section 4.1.
- Review Sage memory — inspect or delete individual memories, or clear all memories, in the app.
- Portability — request your data in a machine-readable format.
- Object — object to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting processing that was lawful before withdrawal.
- Complain — to your local supervisory authority, such as an EU DPA, the UK ICO, or the California Privacy Protection Agency.
Email privacy@getmise.org for any of these. We respond within 7 days and complete requests within 30 days, or within the longer period an applicable law permits for a complex request after we notify you.
9. California-specific disclosures (CCPA / CPRA)
We do not "sell" personal information as defined by CCPA. There is no advertising layer inside the Mise app. On getmise.org, website event data may be considered sharing for cross-context behavioral advertising when it is transferred to Meta or TikTok under California law. That website sharing occurs only after you opt in; you may withdraw that choice by contacting us, and a Global Privacy Control signal always suppresses it. We do not engage in profiling that produces legal or similarly significant effects. We do not knowingly collect personal information from consumers under 16 without consent. California residents have all rights listed above plus the right to non-discrimination for exercising them.
10. International transfers
Mise is operated from the United States. If you access Mise from outside the US, your data may be transferred to the US under an applicable transfer mechanism, including Standard Contractual Clauses for the EEA and the UK International Data Transfer Addendum. Our processor agreements require equivalent safeguards for onward transfers.
11. Children
Mise is not directed to children under 13 (16 in the EU/UK). We do not knowingly collect data from them. If you believe a child has provided us data, contact privacy@getmise.org and we will delete it.
12. Security
We use TLS in transit, encryption at rest through our infrastructure providers, and row-level security so account records are scoped to the authenticated user or household role. We follow an OWASP ASVS Level 2 baseline. Report vulnerabilities to security@getmise.org; we acknowledge reports within 48 hours.
13. Accessibility
Mise targets WCAG 2.1 AA. If you have an accessibility complaint or need help, email accessibility@getmise.org.
14. Changes to this policy
If we change this policy materially, we will give notice before the change takes effect when required by law. For material changes to an AI provider, data category, purpose, or retention term, we will also require a new in-app consent version before future sharing.
15. Contact
Privacy questions: privacy@getmise.org. Postal: Mise, Inc., Austin, TX, USA.
See also how we store and protect your data or contact us with any questions.