Legal
Privacy Policy
Last updated: April 14, 2026
Cartful is a meal planning and grocery app operated by PrismCore AI, LLC ("we," "us," or "our"). This policy describes what information we collect when you use Cartful, how we use it, and what rights you have over it.
If you have questions, you can reach us at hello@cartfulapp.com at any time.
1. Information we collect
Account information. When you register, we collect your email address, first name, last name, and a hashed version of your password. We never store your password in plain text. If you choose to sign in with Apple, we receive an Apple-issued identifier and, if you share it, your email address.
Household and dietary information. During setup you may tell us about your household, including the number of adults and children, age ranges, dietary preferences, and food allergies. This information is used solely to personalize your meal planning experience.
Recipes, meal plans, and shopping history. We store the recipes you create, import, or save; the meal plans you build; your shopping carts; and your order history. This is the core data that makes Cartful work.
AI feature usage. When you use AI-powered features, we log which feature was used, when, and an estimated token count. This is used to enforce usage limits by plan tier. The content of your requests (recipe descriptions, meal preferences, chat messages) is sent to our AI provider to generate a response but is not retained by us beyond what you see in the app.
Subscription information. If you subscribe to Cartful Premium, your payment is handled by Stripe. We store your Stripe customer ID and subscription status. We do not store card numbers or full payment details.
Authentication tokens. Login tokens are stored on your device using the iOS Secure Enclave via Expo SecureStore. We do not collect device identifiers, advertising identifiers, or location data. Your IP address is visible to our servers when you make requests and is used transiently for rate limiting and abuse prevention. It is not persisted to your user record or used to build an advertising profile.
2. How we use your information
We use the information we collect to operate and improve Cartful. Specifically, that means:
- Saving your recipes, meal plans, and shopping history so you can access them across sessions
- Generating AI-powered recipes, meal plans, and recommendations based on your preferences
- Managing your subscription and processing payments through Stripe
- Sending transactional emails such as account activation and password reset messages
- Enforcing usage limits based on your subscription tier
We do not use your data for advertising. We do not build advertising profiles. We do not sell your data to any third party.
We plan to add app analytics in the future to help us understand how the app is used and where to improve it. When we do, we will update this policy before enabling any analytics collection.
3. Third-party services
Cartful relies on the following third-party services. Each receives only the data necessary to perform its function.
Anthropic. We use Anthropic's Claude models to power AI features including recipe generation, meal planning, and the Brainstorm assistant. When you use these features, the relevant content (recipe descriptions, dietary preferences, chat messages) is sent to Anthropic's API. No account identifiers, names, or email addresses are included in these requests. You can review Anthropic's privacy practices at anthropic.com/privacy.
Stripe. Stripe processes subscription payments. When you subscribe, your email address and billing information are shared with Stripe in order to create and manage your subscription. Stripe's privacy policy is available at stripe.com/privacy.
Resend. We use Resend to deliver transactional emails. Your email address and first name are shared with Resend solely for the purpose of sending account-related messages. Resend's privacy policy is available at resend.com/legal/privacy-policy.
Apple. If you use Sign in with Apple, Apple authenticates your identity and shares a unique identifier and, at your option, your email address with us. Apple's privacy policy is available at apple.com/legal/privacy.
We also use nutrition databases (USDA FoodData Central and Open Food Facts) to retrieve ingredient and product information. These services receive ingredient names or product identifiers only. No personal information is transmitted.
fal.ai. We use fal.ai to generate recipe images. The recipe title and short description are sent to fal.ai's API to produce the image. No account identifiers, names, or email addresses are included. If you choose to put personal information into a recipe-generation prompt, that text will be included in the request to fal.ai. fal.ai's privacy policy is available at fal.ai/privacy-policy.
Once generated, recipe images are stored on infrastructure we own and operate.
4. Data retention
We retain your data for as long as your account is active. If you delete your account, your personal information, recipes, meal plans, and order history are permanently deleted from our systems within 30 days. Aggregated, non-identifiable usage statistics may be retained for internal reporting purposes.
5. Your rights
You have the right to access, correct, export, and delete the data associated with your account. You can delete your account directly from the profile screen inside the app. To request a data export or correction, contact us at hello@cartfulapp.com and we will respond within 30 days.
6. Children's privacy
Cartful is not directed at children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us and we will delete it promptly.
7. Security
All data is transmitted over HTTPS. Passwords are hashed using bcrypt. Authentication tokens are stored in your device's secure enclave. We do not store payment card details.
8. Changes to this policy
We will update this policy as Cartful grows, particularly when we introduce analytics or crash reporting. Material changes will be noted with an updated date at the top of this page. For significant changes, we will provide notice via email or an in-app message.