Privacy Policy
Last updated: 8 September 2026
This Privacy Policy describes how mise.en.place ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use the mise.en.place mobile application and website at yourmiseenplace.com (the "App").
The App is operated by mise.en.place, a sole trader business based in Victoria, Australia. We act as the "data controller" for the personal information described in this policy.
If you have any questions about this policy or your personal information, contact us at yourmiseenplace@gmail.com.
1. Summary
In plain terms:
- We collect the information you give us when you sign up and use the App (email, recipes, photos, posts, comments, etc.)
- We collect a small amount of technical information automatically (device type, IP address, app usage) to keep the App running and secure
- We collect analytics about how the App is used (screens viewed, features used), stored on our own infrastructure. A reduced pseudonymous subset is forwarded from our servers to PostHog, our analytics service provider in the EU — the App itself contains no third-party analytics software
- We use this information to operate the App, keep it safe, and improve it — including, for content that qualifies (Section 3.1), building and commercially licensing recipe collections, datasets, products, and services from de-identified original Community recipe content
- We do not sell your personal information, and we do not access your contacts
- We do not track you across other apps or websites for advertising
- You can access, correct, or delete your data at any time from within the App
- Your data is hosted by Supabase in Japan (AWS Tokyo), with other service providers in the United States and Europe (Section 5.2)
The rest of this policy explains all of this in more detail.
2. Information we collect
2.1 Information you give us
When you create an account and use the App, you give us:
- Account information — email address, password (stored as a secure hash, never in plain text), username, display name
- Optional profile information — profile photo, avatar colour, bio, and (optionally) your name. If you add your name to your profile, it can be shown to other users alongside your username (for example in notifications and follow requests). Leave it blank if you prefer to appear by username only.
- Cooking preferences — dietary preferences, cooking goals, grocery list, and pantry staples. These are visible only to you, never to other users.
- Getting-started progress — in App versions with the welcome tutorial and checklist, we remember on your device whether you viewed or skipped them and which checklist tasks you completed. This progress is kept separately for each account on that device; it does not automatically sync between devices.
- Your Content — recipes, photos, posts, comments, reactions, cook history, and any other content you create on the App
- Communications — messages you send us (for example, when you contact support, file a report, or respond to a survey)
2.2 Age confirmation
When you sign up, we ask you to confirm that you are 16 or older. We do not ask for or store your date of birth. We keep only the fact that you confirmed the age requirement and when you confirmed it.
2.3 Information collected automatically
When you use the App, we automatically collect:
- Device and technical information — device type, operating system version, app version, language, time zone, screen size
- Push notification token — a device-level identifier used solely to deliver notifications you have enabled (see Section 5.2)
- Log data — IP address, access times, pages or screens viewed, error reports, and crash data
- Approximate location — derived from your IP address (country/region level, not precise GPS)
- Email-request safeguards — we record keyed hashes of recipient addresses and delivery requests, request times and delivery outcomes to enforce resend limits and reduce duplicate messages. These rate-limit records do not contain the plain email address, login code or message body. Our authentication and email-delivery providers still process your email address and message to deliver it.
2.4 Sign in with Apple or Google
Where Apple or Google sign-in is enabled and you choose it, that provider verifies your identity and shares an account identifier and email address with our authentication service. Depending on the provider and the permissions you grant, it may also share your name or profile image. Apple may supply a private relay email address if you choose Hide My Email. We do not receive your Apple or Google password, and this sign-in does not give us access to your inbox or contacts.
A name supplied by the native Apple sign-in prompt is saved on your device for onboarding. Information held by our authentication service is distinct from your public App profile. Profile details you choose to publish are described in Section 2.1.
Where Apple sign-in is enabled, we store a session-specific Apple identifier in encrypted device storage for native sign-in access checks. Our server retains encrypted Apple credentials needed to manage that sign-in and request revocation of Apple access when applicable, including when you delete your App account. These are not your Apple password and do not grant access to your inbox. Withdrawing Apple sign-in access does not itself delete your App profile or content; use the account-deletion process in Section 7 for that.
2.5 Information we do not collect
To be clear, we do not:
- Collect precise GPS location
- Access your contacts, calendar, or microphone
- Ask for or store your date of birth (Section 2.2)
- Track you across other apps or websites
- Collect health data, financial data (payments are handled by Apple and Google — Section 5.2), or government identifiers
- Use advertising trackers, or analytics that follow you across other apps and websites. Our analytics involve one provider (PostHog — Section 2.6), which receives data from our servers, not from software in the App; Sentry provides crash reporting (Section 5.2)
If we add any new categories of data collection in the future, we will update this policy and notify you.
2.6 Analytics
We collect analytics about how the App is used, so we can see which features people use, find where things break, and improve the App. Analytics events include:
- Usage events — which screens and recipes you view, how far you progress through cooking steps, how many results a search returns, and which features you use
- Technical context — your device platform (iOS or Android), the app version, and a pseudonymous session identifier
Analytics events do not include the text you type into search, the content of your messages or captions, precise location, or advertising identifiers. Analytics data is stored with our hosting provider (Supabase — see Section 5.2) and encrypted in transit.
Where analytics go. Every analytics event is stored on our own infrastructure, and the App itself sends analytics nowhere else — it contains no third-party analytics software and stores no analytics identifier on your device. From our servers, a reduced subset of these events is forwarded to PostHog, our analytics provider, which stores it in the European Union (Section 5.2). The subset is deliberately narrower: it leaves out the record of which posts you were shown, and it never contains another user's identifier. Forwarded events carry a pseudonymous identifier — a random code we generate for your account and hold only in our own database. PostHog never receives your account identifier, email, or name, and the data is not shared with anyone else or used for advertising.
Why this processing occurs. Product analytics are part of how we operate and improve the App; there is no separate analytics-provider switch in the App. Under the EU/UK GDPR we rely on legitimate interests for this processing, as explained in Section 4. This is not described as consent. You may object to analytics processing by contacting us as described in Section 8. Data PostHog receives is retained under Section 7 and erased when you delete your account.
Analytics events are linked to your account while you have one. If you delete your account, the identifiers are removed from the analytics we hold ourselves, and — where any of your events were forwarded — we instruct our analytics provider to erase the pseudonymous profile and the events it holds. Section 7 sets out exactly what happens, and when.
3. How we use your information
We use your information to:
- Operate the App — create and manage your account, store your recipes and posts, deliver notifications, show you other users' content, run the feed and search
- Keep the App safe — detect and prevent fraud, abuse, spam, harassment, and violations of our Terms of Service; respond to reports and moderate content; enforce our Terms
- Improve the App — understand how the App is used in aggregate so we can fix bugs and design new features
- Develop and commercialise recipe products — using only eligible original Community recipe content, de-identified content, and aggregated data, as described in Section 3.1
- Communicate with you — send you account-related emails (password resets, security alerts), respond to your support requests, and notify you of changes to the App or this policy
- Comply with the law — meet our legal obligations, respond to valid legal requests, and protect our rights and the rights of others
We do not use your personal information for automated decision-making that produces legal or similarly significant effects on you.
3.1 Eligible Community recipes, datasets, and product development
Under the content licence in Section 3 of our Terms of Service, we may use Eligible Community Recipe Content and de-identified, aggregated data to build recipe collections, databases, and datasets; develop, train, evaluate, and improve recipe-related models, products, and services; and commercially license, distribute, or sell those recipe collections, databases, datasets, products, and services.
Eligible content means only:
- Recipe titles, ingredients, quantities, instructions, tags, and related recipe information that you wrote yourself and deliberately shared with the Community
What is always excluded:
- Your personal information (name, email, username, account identifiers) — content used this way is first de-identified so it is no longer linked to you
- Imported, copied, or adapted recipes, recipes carrying a source link, and any third-party material
- Recipes kept Only me, drafts, posts, comments, reactions, cook history, grocery or pantry data, and other private/account data
- Photographs. We do not externally license or sell user photographs under the commercial recipe licence without a separate, specific permission.
- Anything that identifies you, unless you separately and expressly opt in. No such opt-in exists in the App today; if we ever offer one, it will be a separate, clearly explained choice that is off by default.
You retain ownership of your content. The Terms grant us a licence to use qualifying recipe content; they do not transfer ownership of your content or personal information to us. De-identified and aggregated data that can no longer reasonably be linked to you may be retained and used for these purposes, including after you delete your account (Section 7). We will not attempt to re-identify de-identified data, and we will contractually prohibit recipients from doing so.
4. Legal basis for processing (EU/UK users)
If you are in the European Union or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Contract — to provide the App to you under our Terms of Service (Article 6(1)(b))
- Legitimate interest — to keep the App safe, prevent abuse, and improve our services (Article 6(1)(f))
- Consent — where you have specifically agreed to a particular use of your data (Article 6(1)(a)). Any future use of content or data that identifies you for the purposes in Section 3.1 would only ever happen with your separate, express consent.
- Legal obligation — where we are required by law to process your data (Article 6(1)(c))
We rely on legitimate interests (Article 6(1)(f)) for analytics (Section 2.6) — understanding how the App is used so we can fix problems and improve it — and for producing de-identified, aggregated statistics. This covers both the analytics we keep on our own infrastructure and the reduced, pseudonymised subset processed by PostHog on our behalf. We have assessed the purpose, necessity, and privacy impact of this processing. Section 8 explains how to object.
You have the right to withdraw consent at any time where consent is the legal basis, without affecting any processing already carried out.
5. How we share your information
We share your information only in the limited ways described below.
5.1 With other users of the App
Some of your information is visible to other users by design:
- Your username, display name, profile photo, avatar colour, bio, and activity stats (level, heat, badges, streaks) are visible to other users, so people can find and recognise you. If you added your name to your profile (Section 2.1), it can also be shown to other users.
- Content has two visibility settings: Community and Only me.
- Community content (recipes, posts, photos, comments, reactions, cook activity you share) is visible to signed-in users of the App.
- Only me content is visible only to you.
- Private accounts. If you switch on "Private account" in Settings, your Community content is visible only to followers you have approved. Your profile basics (username, display name, photo, bio, stats) remain visible so that people can find you and send a follow request.
- Your follow relationships may be visible to your followers and to people you follow.
- If you have an active Supporter subscription and choose to show the supporter badge, other users can see that badge on your profile. You can switch the badge off at any time without losing anything you paid for.
You control what you publish. If you do not want something to be visible to others, set it to Only me or do not post it.
5.2 With service providers (data processors)
We use the following service providers to operate the App. These providers process your data on our behalf under contractual terms that require them to protect your data and use it only for the purposes we specify:
- Supabase, Inc. — database hosting, authentication, and file storage, hosted in Japan (AWS Tokyo). Supabase stores your account information, Your Content, photos, and analytics events.
- Sentry (Functional Software, Inc.) — crash reporting and error monitoring (United States/EU). When the app hits an error, Sentry receives device information, app version, and stack traces. We scrub identifiers and content (such as account IDs and request bodies) from crash reports before they are sent, and this data is used solely to identify and fix bugs. Sentry's privacy policy: sentry.io/privacy.
- PostHog, Inc. — product analytics, stored in the European Union (PostHog EU cloud). PostHog receives the reduced set of usage events described in Section 2.6, forwarded from our servers under a pseudonymous identifier — never your account identifier, email, or name — and no PostHog software runs on, or stores anything on, your device. IP-based location lookup is switched off and we instruct PostHog not to record IP addresses, so no location is derived from your analytics. PostHog processes this data on our behalf under a data processing agreement. PostHog's privacy policy: posthog.com/privacy.
- Scaleway — delivery of transactional account emails and moderation notifications through its Transactional Email service in Paris, France (European Union). Scaleway processes recipient addresses, email contents and delivery information to send these messages and manage delivery failures and abuse. It does not host the App's database or user uploads.
- Expo (650 Industries, Inc.) — push-notification delivery (United States). Expo processes your push token and the notification text, routed onward through Apple and Google's push services.
- Vercel, Inc. — website hosting for yourmiseenplace.com (United States/global).
- Apple Inc. and Google LLC — app distribution, push delivery, and all subscription billing on iOS and Android. We never see your card details; payments are handled entirely by Apple and Google under their own privacy policies.
- RevenueCat, Inc. — subscription management (United States). When supporter-subscription billing goes live it will be processed via RevenueCat, which receives purchase status linked to your account — never your card details.
Analytics events (Section 2.6) are stored with Supabase alongside your other App data. The reduced subset described in that section is additionally processed by PostHog in the European Union.
If we add or change service providers, we will update this policy.
5.3 For legal reasons
We may disclose your information if we believe in good faith that disclosure is necessary to:
- Comply with a court order, subpoena, or other valid legal request
- Investigate suspected fraud, abuse, or violations of our Terms of Service
- Protect the rights, property, or safety of us, our users, or the public
- Cooperate with law enforcement where required by law
Where lawful and practical, we will attempt to notify you before disclosing your data in response to a legal request.
5.4 In a business transfer
If we are involved in a merger, acquisition, restructure, or sale of assets, your information may be transferred as part of that transaction. We will notify you (by email or by a notice in the App) before your information becomes subject to a different privacy policy.
5.5 We do not sell your personal information
We do not sell your personal information to data brokers, advertisers, or other third parties, and we will not. We may commercially license, distribute, or sell recipe collections, databases, datasets, products, or services containing Eligible Community Recipe Content and genuinely de-identified or aggregated data under Section 3.1. That is a licence to qualifying content and non-identifying data, not a sale of your personal information.
6. International data transfers
mise.en.place is operated from Australia, and our service providers store and process data outside Australia. In particular, your account data and content are hosted in Japan (AWS Tokyo) — this applies to every user, including users in Australia — and other providers process data in the United States and the European Union (Section 5.2). Our analytics provider, PostHog, Inc., is incorporated in the United States but stores the analytics data described in Section 2.6 in the European Union.
Our Scaleway email service processes transactional messages in Paris, France. This is separate from our Supabase database and storage in Japan. Messages are also received and processed by your own email provider according to its practices; this does not mean that all copies remain in France.
When your data is transferred outside your country, we rely on appropriate safeguards permitted by law, including:
- Standard Contractual Clauses approved by the European Commission (and the UK IDTA/Addendum) for transfers from the EU/UK
- Adequacy decisions where they exist
- The terms of our agreements with our service providers, which require them to protect your data to a standard equivalent to the laws of your country
You can contact us at yourmiseenplace@gmail.com for more information about international transfers.
7. Data retention and account deletion
We keep your personal information only as long as we need it for the purposes described in this policy.
Deleting your account. You can delete your account at any time from Settings → Your Data → Delete account. Here is exactly what happens:
- Immediately: your account is deactivated and your profile and all of your content are hidden from every other user right away.
- For 30 days: you can restore your account by signing back in and choosing Restore. Nothing is visible to anyone else during this window.
- When the 30-day window ends (in practice within a day after), your personal information is permanently deleted or irreversibly de-identified:
- Your account, email address, sign-in details, profile (username, name, bio, photo), preferences, grocery and pantry lists, push token, posts, comments, reactions, cook history, follow relationships, and notifications are permanently deleted.
- Recipes you imported, and any recipe that doesn't meet the retention conditions below, are permanently deleted.
- Analytics events are irreversibly de-identified: in our own systems, the link to your account, the session identifiers, and any references to your profile — including in events recorded on other users' activity — are removed when your account is permanently deleted. Where usage data has been shared with our analytics provider (Section 5.2), we instruct the provider at the same time to erase your analytics profile and its events; the provider completes this erasure asynchronously, and we monitor each deletion until the provider confirms completion. Events shared with the provider never include identifiers of other users.
- Photos attached to deleted content stop being served when that content is deleted. Copies may persist for a limited time in content-delivery caches, and in the App's on-device image cache on phones that had already viewed them, until those caches expire or are cleared — they are no longer accessible through the App or its links.
What may be retained after deletion:
- De-identified Eligible Community Recipe Content. Qualifying recipe information that you wrote yourself, shared with the Community, and accompanied with a photo you uploaded may be retained in de-identified form — permanently unlinked from your account, with your username, name, profile, and account identifiers removed — and may continue to be used and commercially licensed for the purposes described in Section 3.1. A retained user photograph is not included in external commercial licensing under this clause; if a retained photo shows you, email yourmiseenplace@gmail.com and we will remove it.
- Reports and moderation records — retained for up to 24 months for safety and legal purposes, even if the reporter or reported account is deleted. These records are kept only for moderation, safety, and legal compliance.
- Information we are required to retain by law — kept for the period required by applicable law (for example, tax or financial records).
Other retention windows:
- Log data and technical information — retained for up to 90 days, then deleted or anonymised.
- Analytics events (Section 2.6) — retained for up to 18 months, then deleted.
- Content you delete individually (without deleting your account) — hidden from other users immediately and permanently deleted within 30 days.
After the applicable retention period ends, we delete your data or de-identify it so it can no longer be linked to you.
8. Your privacy rights
Depending on where you live, you have some or all of the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you (you can also export your data yourself from Settings)
- Rectification — ask us to correct information that is wrong or incomplete
- Deletion — ask us to delete your personal information (you can do this yourself at any time from Settings → Your Data → Delete account)
- Restriction — ask us to limit how we use your information
- Objection — object to certain uses of your information, particularly where we rely on legitimate interest
- Portability — ask us to provide your information in a structured, machine-readable format, or to send it to another service
- Withdraw consent — where we rely on your consent, you can withdraw it at any time
- Complain — make a complaint to a privacy regulator (see Section 16 for the regulator in your country)
Analytics objection. If you object to analytics processing based on your particular situation, email yourmiseenplace@gmail.com. We will assess and respond to your objection within 30 days and, where required, stop analytics processing for your account. You may also ask us to explain the legitimate interests assessment for this processing.
To exercise any of these rights, contact us at yourmiseenplace@gmail.com. We will respond within 30 days. We may need to verify your identity before acting on your request.
We will not discriminate against you for exercising your privacy rights.
9. Security
We take reasonable steps to protect your personal information, including:
- Encrypting data in transit using TLS (HTTPS)
- Encrypting passwords with industry-standard hashing
- Restricting access to your data to authorised personnel and service providers
- Enforcing database access rules (Row-Level Security) so that signed-in users can read only the content their permissions allow — including the visibility and private-account rules in Section 5.1
- Scrubbing identifiers and content from crash reports before they leave the device (Section 5.2)
- Regularly reviewing our security practices
No system is completely secure. If we become aware of a security incident that affects your personal information, we will notify you and the relevant regulators where required by law, in accordance with the Notifiable Data Breaches scheme under the Australian Privacy Act and equivalent obligations in other jurisdictions.
You also play a role in keeping your account secure. Choose a strong, unique password and do not share your password with anyone.
10. Children's privacy
The App is not intended for people under 16, and we ask users to confirm that they are 16 or older at sign-up (Section 2.2). Anyone under 16 is blocked from creating or keeping an account. We do not ask for or store a date of birth — only the confirmation and its time.
If we learn that we have collected personal information from someone under 16, we will delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal information, contact us at yourmiseenplace@gmail.com.
11. Cookies and similar technologies
The mise.en.place website uses a small number of necessary cookies and similar technologies to operate, including:
- Authentication cookies — to keep you signed in
- Functional storage — to remember your preferences and settings
We do not use advertising cookies, cross-site tracking pixels, or any analytics that track you across other websites. Our product analytics (Section 2.6) relate to the App only.
You can control cookies through your browser settings, but disabling necessary cookies may prevent parts of the App from working.
Offline App storage. In App versions with offline access, copies of your grocery and pantry lists, pending list changes, and previously downloaded saved recipe text are stored on your device, separately for each account. Pending list changes sync to your account when a connection is available. Downloaded recipe text can include the recipe author's details and content you were permitted to view. Availability and visibility changes cannot always be checked while you are offline; the App checks them again when it reconnects. Images may be cached after viewing, but are not guaranteed to be available offline. Local storage is used to provide these features, not for advertising or cross-app tracking.
12. Marketing communications
If we send you marketing emails in the future (for example, product updates or newsletters), we will only do so where you have agreed to receive them. You can unsubscribe at any time using the link in the email or by contacting us.
We will always send you transactional emails that are necessary for the App to function (password resets, security alerts, account confirmations) regardless of marketing preferences.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify you through the App or by email at least 30 days before the changes take effect, unless a shorter period is needed to comply with law or protect security
- Where a change would materially expand how we use your personal information, ask for your agreement in the App before it applies to you
If you do not agree with a change, you can stop using the App and delete your account at any time (Section 7).
14. Contact us
For any questions, requests, or complaints about this Privacy Policy or how we handle your data, contact us at:
- All enquiries (privacy, general support, and legal): yourmiseenplace@gmail.com
We will respond to all reasonable requests within 30 days.
15. Australian Privacy Principles
This Privacy Policy is intended to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
If you believe we have not handled your personal information in line with this policy or the APPs, please contact us first at yourmiseenplace@gmail.com and we will try to resolve your concern.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Mail: GPO Box 5288, Sydney NSW 2001
16. Region-specific information
16.1 European Union and United Kingdom
If you are in the EU or UK, the General Data Protection Regulation (GDPR) and UK GDPR apply to our processing of your personal information.
You have the rights described in Section 8. You also have the right to lodge a complaint with your local data protection authority:
- EU: edpb.europa.eu/about-edpb/about-edpb/members_en
- UK: ico.org.uk
For reporting illegal content under the EU Digital Services Act, see the "Reporting illegal content" section of our Terms of Service.
16.2 California, United States
If you are a resident of California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the following rights:
- Right to know — what categories of personal information we collect and how we use them
- Right to delete — request deletion of your personal information
- Right to correct — request correction of inaccurate personal information
- Right to opt out of sale or sharing — we do not sell or share your personal information for cross-context behavioural advertising, so there is nothing to opt out of
- Right to limit use of sensitive information — we do not use sensitive information beyond what is necessary to provide the App
- Right to non-discrimination — we will not discriminate against you for exercising your rights
To exercise these rights, contact us at yourmiseenplace@gmail.com.
16.3 Other regions
If you are in another region with specific privacy laws (such as Canada's PIPEDA, Brazil's LGPD, or similar), the rights described in Section 8 apply to you to the extent required by your local law. Contact us at yourmiseenplace@gmail.com for more information.
This Privacy Policy was last updated on 8 September 2026.