Last updated: August 28, 2026
Flame ("we", "us", or "our") is a meal-planning and recipe app for iOS operated by Penny Development. This policy explains what information is collected, how it is used, and your choices.
Information you provide in the app
Most of this is stored locally on your device. We do not operate a central Flame account database. If you choose Sign in with Apple, we receive an Apple identity token to issue a short-lived session for API access; we store a pseudonymous Apple user identifier and subscription status on our servers for authentication and usage limits, not your name or email unless Apple provides it in the token. If you also enable iCloud sync, preferences, saved meals, meal plans, and related settings can sync across your devices through your Apple iCloud account (Key-Value Store). We do not receive that synced payload on our servers.
Information sent to generate recipes
When you generate a recipe or meal plan, your wizard answers and optional dietary preferences are sent to our backend API (hosted on Cloudflare) so we can produce results. Depending on the feature, our servers may forward relevant portions of that information to:
We do not use wizard answers to build advertising profiles. AI-generated allergen and safety notes are informational only and are not medical or allergy testing advice — always verify ingredients yourself.
Subscriptions
Payments are processed by Apple (StoreKit). We receive subscription status from Apple; we do not receive or store your payment card details.
Advertising (free tier)
If you use the free version, Google AdMob may collect device and usage data to show ads, including a full-screen interstitial before you view a newly generated recipe and optional rewarded video ads for extra generations. With your permission, iOS App Tracking Transparency (ATT) may allow additional ad-related identifiers. See Google's Privacy Policy and AdMob's data disclosure guide.
Apple Health (optional, Plus)
If you choose to export nutrition, Flame writes meal nutrition data to Apple Health on your device. We do not read Health data unless you grant permission for features that require it.
We use third parties to run the app:
These providers process data only as needed to provide their services to us. Their privacy policies and data-handling practices apply to processing on their systems.
Data stored on your device remains until you delete the app or clear app data. API requests are processed in real time; we do not maintain a long-term database of your wizard answers on our servers. Generated dish photos may be cached on our infrastructure for a limited period (typically about 30 days) so they load quickly when you revisit a recipe.
Flame is not directed at children under 13. We do not knowingly collect personal information from children.
API traffic uses HTTPS. After you Sign in with Apple, the app uses short-lived access tokens (not a password stored on our servers). Requests are signed to reduce replay abuse. Session tokens are stored in your device Keychain. This is standard for mobile clients but is not a substitute for professional security auditing of your own devices and networks.
If you use Flame outside the United States, your information may be processed in the United States and other countries where our providers operate (including where OpenAI, DeepSeek, Cloudflare, Google, and Apple maintain facilities). Laws in those countries may differ from those in your country.
We may update this policy. We will post the new date at the top. Continued use after changes means you accept the updated policy.
Questions: [email protected]