Who is responsible for your information
MenuGleam is operated by Arthur Wang, an individual based in China, who is responsible for the processing described here. For privacy questions or requests, email arthurwang934@gamil.com.
Information we process
We process your email and sign-in profile, restaurant details, uploaded photos and file metadata, analysis results, enhanced images, job status, credit activity and subscription identifiers. We also process information you send when asking for support or deletion. Hosting and other providers may process IP addresses, device information and request logs to deliver and secure their services. Stripe handles payment details; the application stores billing references and status, rather than full card numbers.
Why we use this information
We use account and workspace information to provide the service you request, process enhancements, maintain your credit balance and manage billing and support. Where data protection law requires a legal basis, this processing is necessary to perform our agreement with you or take steps you request before purchasing.
Our legitimate interests in keeping the service secure, preventing misuse, diagnosing failures and resolving disputes support related operational processing, subject to your rights. We also retain and use records where necessary to comply with applicable legal obligations. If we ask for consent for an additional purpose, you can withdraw it without affecting processing that was lawful before withdrawal. Without essential account or payment information, we may be unable to provide the relevant service.
Service providers and image processing
We use Supabase for authentication and storage, Vercel for hosting, Stripe for payments and subscription billing, and Upstash QStash for background task delivery. Google handles authentication when you choose Google sign-in. QStash receives task identifiers rather than photo files.
When you request an enhancement, image content and instructions are sent through EasyRouter to external analysis and image-generation services. Provider processing may involve their downstream providers. Upload only images you are authorized to send for this processing, and avoid unnecessary personal or confidential information in photos. We do not promise that external providers never retain inputs or use them for training. Contact us before uploading if you require a specific retention or training restriction.
Our operator is in China and our providers operate internationally. Information may be processed outside your country. We do not offer a guarantee of storage solely in the EU, UK or US. Contact us for information about the providers and transfer arrangements relevant to your use; this notice does not itself establish a particular transfer safeguard or certification.
Information may also be disclosed where necessary to comply with law or protect accounts and resolve disputes. We do not publish your workspace photos as marketing examples without your permission.
Retention and deletion
Account and workspace content remain stored until deleted; there is no automatic inactive-account expiry. Canceling a subscription does not delete your photos. You can delete supported restaurant, photo and enhancement records through the application.
Submit and track an account-deletion request on the Account page, or contact support. Requests are handled manually after ownership verification. Pending requests can be withdrawn there; contact support for a request already under review. We aim to handle verified requests within 30 days and will explain any delay or information we must retain, subject to applicable response deadlines.
Account closure removes eligible active workspace data and the sign-in identity through a staged process. It is not immediate, and a request does not itself cancel billing. Billing references, credit history and refund records are retained separately for reconciliation, disputes and applicable recordkeeping obligations. Those records can remain associated with you; they are not fully anonymous.
Retention of financial records depends on outstanding payments, refunds and disputes, and applicable recordkeeping and legal-claim periods. Support records are kept as needed to resolve and document requests. Security logs and backup copies follow the relevant providers’ retention and recovery arrangements. Deleting active records does not erase every backup or provider log immediately. Contact us for details about a particular record or deletion request.
Cookies and operational events
We use session cookies to keep you signed in. The application does not include an advertising tracker or a client-side analytics SDK. When operational event logging is enabled, server logs record actions such as uploads, enhancements and checkout, with account or record identifiers and timestamps. These events help us operate and diagnose the service. Authentication and payment providers may use their own cookies when you interact with their services.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion or a copy of your personal information, and may have rights to restrict or object to processing and to data portability. Send requests from your account email where possible; we may need to verify ownership. Do not send passwords, sign-in links or full card details. You may also complain to your local data-protection authority, including an EU supervisory authority or the UK Information Commissioner where applicable.
The service is designed for restaurant owners and managers, not children. Contact us if you believe a child has provided personal information. We will publish updates to this notice here with a new effective date and communicate material changes as appropriate.