This Privacy Policy explains how Bellyful.ai ("Bellyful.ai," "we," "us," or "our") collects, uses, shares, and protects personal information when you use our mobile application, our website at bellyful.ai, and related services (collectively, the "Services").
Bellyful.ai is a potluck planning application that helps hosts invite guests, generate balanced menus with AI, and coordinate food assignments. Guests can RSVP through any web browser without installing the app.
We do not sell your personal information. We do not share your data with advertisers. We do not send marketing SMS.
Who We Are
Bellyful.ai is a consumer app operated in the United States. To reach us, use our contact form.
Privacy contact: privacy@bellyful.ai
Who This Policy Applies To
This policy applies to:
- Hosts who create an account in the Bellyful.ai mobile app
- Guests who RSVP to a Bellyful.ai event via a web browser (without creating an account)
- Visitors to bellyful.ai and anyone who joins our pre-launch waitlist
- Family or household members added by a host inside the app
Information We Collect
Information you provide to us
- Email address. Collected when you join our waitlist, create an app account, or RSVP to an event.
- Phone number. Collected when you enter your phone number in the app or on a guest RSVP page to receive a one-time password (OTP).
- Name. Provided by hosts during signup and by guests during RSVP.
- Dietary restrictions and preferences. Including allergies, religious or cultural needs (for example Halal, Kosher), and cuisine preferences. Guests may enter this information when RSVPing to a specific event.
- Household or family members. Hosts may add family members to their account to plan events more easily. This includes names and dietary information for those family members.
- Event details. Date, time, venue, guest list, RSVP responses, items each guest will bring, and any notes the host adds.
- Precise event location. When a host types a venue into an event, we look up that address and store the venue's formatted address, its precise latitude and longitude, its country, its state or province, its time zone, and an identifier for the place. We collect this so that the host and the guests invited to that event can see the venue address and a map pin, and can open directions in their own maps app. California law treats precise geolocation as sensitive personal information (Civ. Code §1798.140(ae)(1)(C)), and we treat it that way too. This is the location of the venue the host chose. It is not the location of your device, and we do not track your device's location.
- Feedback and support messages. Anything you send us when you contact support or submit feedback.
Information collected automatically
- Authentication data. Session tokens, login timestamps, and security events (for example failed OTP attempts).
- Device and technical data. Device type, operating system version, app version, IP address, crash logs, and similar diagnostic information.
- Product analytics. Anonymized or pseudonymized event data (which screens you visit, which buttons you tap) through Mixpanel, and session replay data through UXCam. Both are configured to mask sensitive input fields.
- Cookies (website only). Our mobile app does not use cookies. Our marketing website uses essential cookies for basic site function and a small number of first-party analytics cookies. See the Cookies section below.
Information from third parties
- Sign in with Google or Sign in with Apple. If you choose these options during signup, we receive your name and email address from the provider. We do not receive your password.
How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Let hosts plan events, invite guests, and coordinate who brings what
- Let guests RSVP, view event details, and enter dietary preferences
- Generate balanced AI menus tailored to the dietary profile of attendees
- Send transactional communications (OTP codes, RSVP confirmations, event reminders, cancellation notifications)
- Detect and prevent fraud, abuse, and security incidents
- Diagnose bugs, measure product performance, and improve the Services
- Understand which areas we serve, decide where to offer Bellyful.ai next, and improve our features and our machine learning models, using a coarse location area rather than a precise one
- Communicate with you about support, account issues, and important service changes
- Comply with legal obligations
Coarse location for coverage and product improvement. From the venue's coordinates we derive a coarse area of roughly five kilometers (about three miles) across, and we keep that area alongside the country, the state or province, and the time zone. We use those coarse fields to understand where events are happening, to decide which regions to support next, and as inputs to the machine learning models behind our menu and planning features. We do not use the precise coordinates for any of this. We do not use any of it to build a profile of you, to make decisions about you as an individual, or for advertising of any kind.
We do not use your information for cross-context behavioral advertising. We do not sell your information. We do not use AI-generated menus or your event data to train third-party models.
How We Share Information
We share information only in these situations.
With other users at your direction
- Hosts see RSVP responses, dietary information, and assignment choices for guests they invite.
- Guests see event details, the host's name, and (optionally) what other guests are bringing.
With service providers (processors)
We use a small number of vendors to run the Services. They act as service providers under CCPA and are contractually limited to using data only to provide services to us.
- Amazon Web Services (AWS). Cloud hosting, database storage, and SMS delivery via AWS End User Messaging, in the United States.
- Amazon Location Service (AWS). Address lookup and geocoding when a host enters an event venue. This is covered by the same AWS data processing agreement as our other AWS services, so there is no outstanding agreement for it. AWS may pass the address text to its own map data provider to answer the lookup, which is described under Where we process information below.
- Mixpanel. Product analytics.
- UXCam. Session replay analytics, with sensitive input fields masked.
- Email delivery provider. We use AWS SES (or an equivalent provider) to send transactional email.
- Sign in with Google and Sign in with Apple. For optional federated sign-in.
When you open directions
The event page shows a map pin for the venue and a control that opens directions. If you tap it, we hand the venue's address and coordinates to the maps app you choose, which may be Google Maps, Apple Maps, Waze, or MapQuest. That app then handles your request under its own terms and privacy policy, and we have no further part in it. We do not send anything to those apps unless you tap to open them.
For legal reasons
We may share information if we believe in good faith that it is necessary to comply with a legal obligation, protect our rights or the safety of others, or respond to lawful legal process.
Business transfers
If Bellyful.ai is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
Where we process information
We process and store your information in the United States.
There is one exception. When a host enters an event venue and we look up that address, Amazon Location Service may send the search text and the request details to its map data provider, and that provider may process the request outside the United States. This applies only to the address lookup. Your account, your event records, your dietary information, and your messages stay in the United States.
SMS Program Details
This section describes the SMS practices of Bellyful.ai.
SMS use cases
We use SMS for one purpose today: one-time passwords (OTP). When you enter your phone number in the app or on a guest RSVP page to verify your identity, we send a short numeric code by SMS. Every message is initiated by you.
Event invitations are currently sent by hosts directly from their own devices, or by sharing an event link. Bellyful.ai does not send invitation SMS on a host's behalf. If we introduce platform-sent event notifications in the future, they will require the recipient's own opt-in, and we will update this policy before launch.
Consent
- For OTP: consent is given when you enter your phone number in the app or RSVP page and tap to request a code.
- You can opt out at any time by replying STOP to any message. Reply HELP for help.
What we do not do
- We do not send marketing or promotional SMS.
- We do not share your phone number with advertisers or affiliates.
- We do not sell phone numbers.
Message frequency and rates
SMS frequency varies. Messages are transactional and user-initiated. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
How SMS is delivered
SMS messages are delivered through Amazon Web Services (AWS End User Messaging). Phone numbers are shared with AWS solely for the purpose of delivering messages you have requested or consented to receive. AWS is bound by its own contractual and legal obligations as our processor.
Retention
Phone numbers provided only for OTP verification by non-app users are retained for the duration of the associated event plus 30 days, then deleted. Phone numbers associated with an app account are retained while the account is active and for 30 days after account deletion.
Data Retention
We retain personal information only as long as needed for the purposes described in this policy.
- Non-app user data (dietary preferences, phone, email, name provided by a guest to RSVP): retained for the duration of the event plus 30 days, then deleted.
- App-account data: retained while your account is active and for 30 days after you delete your account, after which it is deleted or anonymized. The one exception is the limited activity-timeline records described in the next bullet, which are neither deleted nor anonymized but kept permanently in masked form. Short-term backups may persist beyond that window but are not used operationally.
- Activity-timeline records. To coordinate an event, Bellyful keeps an append-only activity history of what happened (who RSVP'd, who declined, who was assigned which item, menu changes, and similar events). To keep that history accurate and tamper-evident, a masked form of a participant's display name (their first name plus last initial, for example "Jordan S.") is stored as part of these records and is kept on a permanent basis, including after that participant deletes their account. We do not keep the participant's full name, email address, or phone number in these records. This masked name is personal information; it is not aggregate, deidentified, or anonymized data, and we describe it plainly so you know exactly what is retained. We keep it because an accurate, tamper-evident record of how each event was coordinated is necessary to provide the Service, and retroactively removing names from past events would corrupt that shared history for the host and the other guests. You can ask us for a copy of the timeline records that reference you by contacting privacy@bellyful.ai. Because these records are an integrity-protected, append-only history shared with other participants, we generally cannot remove a name from past events; if a legal exception requires us to act differently in your case, we will do so.
- Event venue location. The venue's formatted address, place identifier, coarse area, country, state or province, and time zone are kept for as long as we keep the event record, because they are part of the record of what the event was. The venue's precise latitude and longitude are kept until 14 days after the event date and are then erased from the event record. We chose 14 days because the map pin and the directions link have no reader once the event is over, and two weeks covers multi-day events, time zone differences, and the period in which guests still open the invite to look back at it. Erasing the coordinates does not erase the address, so the event history stays readable.
- Analytics data. Mixpanel and UXCam retain event and session data under their provider defaults. We review these settings regularly.
- Server and application logs. Retained for 90 days for security and debugging, then deleted.
- Backups. Encrypted database backups may be retained for up to 35 days per our disaster recovery policy.
- Legal hold. If we are legally required to retain information longer (for example tax, audit, or litigation), we keep only what is required and only for the required period.
Your Rights
If you are outside the United States: your rights may vary under your local law. Bellyful.ai's services are intended for users in the United States and Canada, and we process data as described under Where we process information above. To exercise any rights under your local privacy laws, contact us via the contact form.
Rights under CCPA and CPRA (California residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, or share (Civ. Code §1798.100, §1798.110, §1798.115)
- Delete personal information we have collected (§1798.105). This right is subject to the exceptions permitted by law, including our retention of the limited, masked activity-timeline records described under Data Retention above, which we keep to maintain the integrity of event-coordination history.
- Correct inaccurate personal information (§1798.106)
- Opt out of the sale or sharing of your personal information (§1798.120). Bellyful.ai does not sell or share personal information as those terms are defined under CCPA/CPRA, but you have the right to make this request.
- Limit the use and disclosure of sensitive personal information (§1798.121). We collect health-adjacent information (allergies), religious inference (Halal, Kosher), and the precise location of event venues. We use this information only to deliver the Service you requested and do not use it for inferences about you beyond that purpose. The precise venue coordinates are used only to show the venue and to open directions, as described under Information We Collect above.
- Non-discrimination for exercising your rights (§1798.125)
How to exercise your rights
Email privacy@bellyful.ai with the subject line "Privacy Rights Request" and describe what you are asking for. You can also submit requests in-app under Settings > Privacy. We may ask you to verify your identity before we act on your request, typically by confirming control of the email or phone number on your account.
You may designate an authorized agent to act on your behalf. We will ask for reasonable proof of authorization.
Do Not Sell or Share (CCPA Notice)
Bellyful.ai does not sell your personal information. Bellyful.ai does not share your personal information for cross-context behavioral advertising.
This statement applies to all Bellyful.ai users, including California residents. We have not sold personal information in the preceding 12 months and we have no plans to do so.
Children's Privacy (COPPA)
Bellyful.ai is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, contact privacy@bellyful.ai and we will delete it.
Our minimum age is 13.
Cookies and Similar Technologies
- Mobile app. Our iOS and Android apps do not use browser cookies. They use standard platform storage (secure keychain, encrypted storage) to hold session tokens and preferences.
- Marketing website (bellyful.ai). We use minimal first-party cookies for security and basic site function, and a small set of first-party analytics cookies to understand aggregate usage. We do not use third-party advertising cookies.
Security
We use technical and organizational safeguards to protect your information, including:
- Encryption in transit (TLS 1.2 or higher) for all network traffic
- Encryption at rest for databases and backups
- Database authentication with least-privilege access
- Session replay and analytics configured to mask sensitive fields
- Rate limiting and bot protection on authentication endpoints
- Security logging and monitoring
No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and the applicable regulators as required by law.
Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you by email (for app users) or by a notice on bellyful.ai, and we will update the effective date above. Your continued use of the Services after the effective date of the updated policy means you accept the changes.
Contact Us
General privacy questions: privacy@bellyful.ai
California privacy rights requests: privacy@bellyful.ai, subject "California Privacy Rights Request"