Menu Pixie
How it works Features FAQ Feedback Roadmap Changelog
Coming soon
Menu Pixie
How it works Features FAQ
Feedback Roadmap Changelog
Coming soon
On this page
In shortData we process, and whyThe websiteCookiesRecipients of your dataInternational transfersRetentionYour rightsSecurityChildrenChanges to this policyContact

Privacy Policy

Last updated: 26 July 2026

On this page
In shortData we process, and whyThe websiteCookiesRecipients of your dataInternational transfersRetentionYour rightsSecurityChildrenChanges to this policyContact

This Privacy Policy explains how Comis d.o.o. (“Comis”, “we”, “us”) processes personal data in connection with the Menu Pixie mobile application (the “App”) and the menupixie.com website (together, the “Services”). Menu Pixie is anonymous by default: you can scan and browse menus without ever creating an account or telling us who you are.

Data controller:
Comis d.o.o.
Dalmatinova ulica 8
1000 Ljubljana, Slovenia
Company reg. no. 2238047000 · VAT SI48786853
privacy@menupixie.com

In short

  • The App works anonymously by default. On first launch it receives an opaque, random Device Token — no account, no email, no name — and no account exists until you choose to buy credits.
  • Menu photos you take are sent to an AI service to read and translate the menu. That is the product working as described, not tracking.
  • Your dish photos (“Plates”) are shared with other diners only with your explicit consent, given at upload.
  • Your location is used only at scan time, only to identify the restaurant — never in the background.
  • Core infrastructure, product analytics and crash reporting are EU-hosted.
  • No ads, no cross-app tracking, and we never sell your personal data.

Data we process, and why

Device Token & credit balance

On first launch, the App requests an anonymous, opaque Device Token — a random identifier minted by our server, not derived from your hardware and not linked to your identity. It lets the App scan menus, save them, and hold a credit balance, which is maintained server-side against the token. It contains no personal details and can be revoked. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Account (optional)

You can use Menu Pixie without an account. An account is created only if you make a purchase, via Sign in with Apple or Sign in with Google. We store only the sign-in provider and the email address it verifies — no name, no profile. The account exists so your credit balance survives a reinstall or a new device; your device’s history merges into it. You can sign out at any time from the app’s Settings — signing out detaches that device, while your account and credit balance survive for the next time you sign in. Legal basis: performance of a contract (Art. 6(1)(b)).

Menu scans

When you photograph a menu, the photo (and any text parsed from it) is processed to read, structure and translate the menu — that is the core service. This processing uses a US-based large-language-model (LLM) provider acting on our behalf, which constitutes an international transfer safeguarded by the European Commission’s Standard Contractual Clauses (see International transfers below). Parsed menus are stored so you can reopen them later. The dishes and prices parsed from a menu are restaurant knowledge, and may be served to other diners scanning the same restaurant — never your photos, and never anything that identifies you. Dietary suitability, allergen hints, ingredients and calorie figures in parsed menus are automated estimates generated by AI — they may be wrong, and you should always confirm with the restaurant; they are never medical or safety advice. Legal basis: performance of a contract (Art. 6(1)(b)).

Location

If you allow it, the App captures your GPS position at scan time only, solely to identify the restaurant whose menu you scanned (which also lets us show its real photos where available). Location is never collected in the background, and denying location permission keeps scanning fully functional. Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interest in correctly identifying restaurants (Art. 6(1)(f)).

Dish photos (“Plates”)

If you photograph a dish and upload it, that photo may be shown to other diners viewing the same dish at the same restaurant. Plates are uploaded only by your deliberate action, and your explicit consent to cross-user sharing is captured at upload. Before publishing we strip all EXIF metadata (including embedded location) and run an automated moderation check; photos can be reported in-app, and a reported photo is removed from serving immediately. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time by deleting the photo or reporting it.

Product analytics (EU)

The App sends pseudonymous product-usage events — screens viewed, features used, whether a scan succeeded — to an EU-based product-analytics provider, keyed to a pseudonymous identifier rather than your identity. These analytics are always on: they are how we know which features work and where the App fails, and we have deliberately limited them so that the trade-off is fair — they build no advertising profiles, perform no cross-app or cross-site tracking, include no menu photos or location, and are never sold or shared for advertising. Legal basis: our legitimate interest in understanding and improving the Services (Art. 6(1)(f)).

Crash reports (EU)

To diagnose and fix stability problems, the App sends automatic crash reports, scrubbed of secrets, to a specialist crash-reporting provider hosted in the European Union. A crash report tells us where the App failed, not who you are. Legal basis: our legitimate interest in the security and stability of the Services (Art. 6(1)(f)).

Purchases

Credit purchases are made through Apple’s App Store or Google Play, which handle payment as independent controllers under their own privacy policies — we never see your card details. A purchase-infrastructure provider processes store receipts on our behalf so we can verify the purchase and credit your balance. We keep purchase and credit-ledger records to deliver what you bought and to meet our tax and accounting obligations. Legal basis: performance of a contract (Art. 6(1)(b)) and compliance with legal obligations such as tax and accounting (Art. 6(1)(c)).

Restaurant identification

To match your scan to a real place, the parsed restaurant name and (if permitted) your scan-time location may be resolved against Google Places, which returns the restaurant’s public listing details. Legal basis: performance of a contract (Art. 6(1)(b)).

Support requests

If you email us, we process your email address and the contents of your message to respond. Legal basis: our legitimate interest in responding to you, or taking steps at your request (Art. 6(1)(f)/(b)).

Feedback, roadmap & changelog

Our public feedback board, roadmap and changelog live on our /feedback, /roadmap and /changelog pages via a widget embedded from a third-party feedback provider. Opening those pages loads that provider’s script, which may set its own cookies under that provider’s own privacy and cookie notices; it processes the name, email and content you choose to submit. Legal basis: your consent when you choose to participate (Art. 6(1)(a)) and our legitimate interest in improving the Services (Art. 6(1)(f)).

The website

The menupixie.com website uses Google Analytics 4 to understand visits — but only after you accept the cookie banner. We use Google Consent Mode with all consent signals denied by default: no analytics cookies are set and no analytics data is sent unless you choose Accept, and choosing Decline keeps the site fully functional. Google LLC processes this data as our provider; it is certified under the EU-US Data Privacy Framework. Legal basis: your consent (Art. 6(1)(a)), withdrawable at any time via the cookie settings.

On our /feedback and /roadmap pages you can optionally sign in to post and vote as yourself instead of as a guest. Signing in is entirely your choice — the board works either way. If you choose a provider (Apple, Google or GitHub), we verify the proof it issues and pass your name, email address and — where the provider supplies one — your avatar to our feedback provider, solely so that your posts and votes are attributed to you. The exchange is stateless: we keep no copy ourselves — no website account, no session, no record in our database (our server logs note that a sign-in happened, under a pseudonymous identifier, as part of the technical request data described under “The website” below). The board token we receive back is kept in your own browser (see Cookies below) until it expires or you sign out. Because those two pages offer sign-in, opening them also loads sign-in components from Apple and Google, which contacts their servers even if you never sign in; no account data reaches them unless you choose to sign in with them, and the cookie banner governs analytics only. Anything you then post on the board is held by our feedback provider under its own notices — deleting your Menu Pixie app account does not remove board posts, so use the board’s own controls or email us. Legal basis: your consent (Art. 6(1)(a)).

Like any web server, our hosting processes technical request data — IP address, user-agent, timestamps — for both the site and our app’s API, to deliver the Services and protect them against abuse (including rate limiting). Legal basis: our legitimate interest in operating and securing the Services (Art. 6(1)(f)).

Cookies

Cookie / storagePurposeSet whenCategory
Consent choiceRemembers whether you accepted or declined analyticsOn your first choice in the bannerStrictly necessary
Google Analytics 4 (_ga, _ga_*)Aggregated visit statisticsOnly after you accept the cookie bannerAnalytics (consent-based)
Feedback widget (third-party)Our feedback board, roadmap and changelog widget; may set its own cookies under its provider’s noticesOnly when you open /feedback, /roadmap or /changelogFunctional (third-party)
Board sign-in (mpx_fv_auth)Keeps you signed in on the board so your posts and votes are yours; stored in your browser, cleared when you sign outOnly if you sign in on the /feedback or /roadmap pagesFunctional

We set no advertising cookies. Our /feedback, /roadmap and /changelog pages embed a widget from a third-party feedback provider, which may set its own cookies and is governed by that provider’s own privacy and cookie notices.

Recipients of your data

We share personal data only with the service providers needed to run the Services, acting as our processors (or, where noted, as independent controllers). By category, these are:

  • an LLM (AI) provider (US) — parses and translates the menu photos you submit;
  • Google Places — resolves restaurant identity from name and scan-time location;
  • a product-analytics provider (EU-hosted) — pseudonymous app usage events;
  • a crash-reporting provider (EU-hosted) — scrubbed crash reports;
  • a purchase-infrastructure provider — store-receipt verification, linking your store purchase to your credit balance;
  • Apple and Google — payment processing for credit purchases, as independent controllers under their own policies;
  • a feedback, roadmap and changelog provider — operating the embedded feedback widget on our /feedback, /roadmap and /changelog pages under its own notices, and receiving your name, email address and avatar (where the provider supplies one) if you choose to sign in there;
  • Apple, Google and GitHub — optional sign-in on our /feedback and /roadmap pages, as independent controllers under their own policies;
  • Google Analytics 4 — website statistics, only after cookie consent; and
  • our hosting provider (EU) — servers and image delivery.

We can provide the specific identity of any current provider on request. We do not sell personal data or share it for third-party advertising.

International transfers

Our core infrastructure, product analytics and crash reporting are hosted in the European Union. Some providers process data outside the EEA: the LLM provider is US-based, and Google services, our purchase-infrastructure provider, our feedback provider and any board sign-in provider you choose (Apple, Google or GitHub) may process data outside the EEA. Where data leaves the EEA, we rely on a European Commission adequacy decision (such as the EU-US Data Privacy Framework) or appropriate safeguards such as the Commission’s Standard Contractual Clauses.

Retention

  • Menu scans & parsed menus: kept while your device or account is active so you can reopen them; deleted when your device data or account is deleted.
  • Dish photos (Plates): kept until you delete them, a report is upheld, or moderation removes them.
  • Credit ledger & purchase records: retained for as long as required by applicable tax and accounting law.
  • Analytics & crash reports: retained per the provider’s retention schedule, then deleted or aggregated.
  • Support emails: kept as long as needed to handle your request and for a reasonable period afterwards.

Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw any consent you have given. You can delete your data — including your scans, Plates and account — from the app’s Settings or by email. To exercise any of these rights, email privacy@menupixie.com. You also have the right to lodge a complaint with a supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec, ip-rs.si) — or with the authority in your country of residence.

Security

We apply appropriate technical and organisational measures to protect personal data, including TLS encryption in transit, stripping EXIF metadata from uploaded photos before publication, opaque and revocable device tokens instead of hardware identifiers, and keeping credit balances server-side. No method of transmission or storage is completely secure, but we work to protect your information.

Children

Menu Pixie is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the current version here with a revised “Last updated” date and, for material changes, provide reasonable notice (for example on the website or within the App).

Contact

Questions about your data or this policy? Email privacy@menupixie.com. For general support, email support@menupixie.com.

Menu Pixie
support@menupixie.com
Privacy Terms Support Feedback Roadmap Changelog
Comis d.o.o. · © 2026 Comis d.o.o. All rights reserved.
We use Google Analytics to understand visits. No ads, no selling. Cookie details