Last updated: September 2026 · Version 1.0

1. Who we are

Yeowly Limited ("ai.butler", "we", "us", "our") operates the ai.butler mobile application and its supporting backend services (the "Service"). This policy explains what personal data we collect, why, how it's used, who we share it with, and the rights you have over it.

Data controller: Yeowly Limited
Registered address: Millhouse, 32-38 East Street, Rochford, Essex, United Kingdom, SS4 1DB
Company number: 17454197 (registered in England and Wales)
Contact for privacy requests: privacy@aibutler.co.uk
Data Protection Officer: Not applicable — we are not required to appoint a DPO at our current size and scope of processing.

If you are located in the European Economic Area (EEA) or United Kingdom, Yeowly Limited is the controller of your personal data for the purposes of the General Data Protection Regulation (GDPR) / UK GDPR.

2. What data we collect

We collect only what's needed to run the Service. Here's what that is, in plain terms:

Account information

  • Full name
  • Email address (used to sign in)
  • Password (stored as a one-way cryptographic hash — we never store or can see your actual password)
  • Sign-up method (email, Google, or Apple)

Profile & preferences

  • Postcode (used to show relevant local grocery stores)
  • Gender and age group (used to tailor recommendations, if you choose to provide them)
  • Dietary preferences, allergies, and preferred cuisines
  • Onboarding progress

Meal-planning conversations

  • The text of your conversations with our AI meal-planning assistant, including any preferences, constraints, or context you share
  • We store this so you can leave a conversation and resume it later without starting over
  • Generated meal plans and recipes tied to those conversations

Shopping & store data

  • Shopping lists you create
  • Which grocery stores you've selected as preferred stores
  • If you choose to connect a grocery store account (e.g. to enable one-tap checkout), we keep you signed in by storing your session for that store (similar to how a browser keeps you logged in) rather than your store password — we do not store your grocery store password

Subscription and billing data

  • Your subscription and free-trial status (e.g. active, trial, expired), managed through our billing partner, RevenueCat, and the App Store or Google Play
  • We do not collect or store your card or payment details — these are handled directly by Apple, Google, or RevenueCat

Sign-in data from third parties

If you sign in with Google or Apple, we receive your name and email address from that provider as part of authentication.

Technical & usage data

  • Session tokens (used to keep you signed in)
  • App version, device platform, and basic diagnostic information needed to keep the Service running

What we do not currently collect

As of this version, the app does not request or collect: precise location (GPS), camera or photo library access, contacts, microphone audio, or push-notification tokens. If this changes in a future version, we'll update this policy and request your permission at the time, as required.

3. Why we collect it, and our legal basis

  • Creating and securing your account — email, password, name — performance of a contract
  • Generating meal plans and recipe recommendations — dietary preferences, allergies, cuisines, conversation text — performance of a contract
  • Letting you resume a saved conversation — conversation history — performance of a contract
  • Showing relevant local grocery stores — postcode — performance of a contract
  • Completing store checkout on your behalf — store session (only for stores you connect) — performance of a contract, based on your explicit action to connect a store
  • Managing your subscription and free trial — subscription/trial status — performance of a contract
  • Keeping the Service secure and preventing abuse — session tokens, sign-in activity — legitimate interest
  • Improving recommendation quality — aggregated/de-identified usage patterns — legitimate interest
  • Sending you service communications (e.g. verification codes) — email — performance of a contract

We do not use your data for advertising, and we do not sell your personal data to anyone.

Special category data: Allergy information can, in some cases, constitute health data under Art. 9 GDPR. We treat allergy data as special category data: it is provided by you voluntarily and only used to filter unsafe recipes and ingredients out of your recommendations, and we do not share it with anyone outside the processors listed in §4 who need it to generate your meal plan. You can remove this information at any time in your profile settings.

4. Who we share data with

We share data only with the service providers needed to run ai.butler, and only the data each one needs to do its job. We do not sell personal data, and we do not share it for third-party advertising.

  • Anthropic (Claude) — your meal-planning conversation text and dietary preferences, to generate meal plan and recipe suggestions — United States
  • FAL.ai — recipe/ingredient descriptions, to generate recipe images — United States
  • Voyage AI — ingredient/product search terms, to power ingredient search — United States
  • Google and Apple — OAuth token and basic profile info (if you sign in with them), or in-app purchase data — to authenticate your sign-in and manage purchases — United States
  • RevenueCat — subscription and trial status — to manage your subscription — United States
  • Amazon Web Services — recipe/product images, database hosting — infrastructure hosting
  • Grocery retailers you connect (e.g. Asda) — your session with that retailer's site (not your password), only for stores you explicitly connect — to complete checkout on your behalf — United Kingdom

Where a provider is located outside the UK/EEA, we put appropriate safeguards in place — such as Standard Contractual Clauses or an equivalent approved transfer mechanism — to ensure your data continues to receive GDPR-level protection, and we work with each provider to have a data processing agreement in place covering their handling of your data.

We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, or property of ai.butler or our users.

5. How long we keep your data

  • Account and profile data — removed from our live/production systems within 30 days of account deletion
  • Meal-planning conversations — kept so you can resume them, until you delete the conversation or your account, at which point the same timelines in this section apply
  • Session tokens — expire automatically and are invalidated on logout or after a period of inactivity
  • Store session data — kept only while a store connection remains active; deleted immediately when you disconnect a store
  • Backups — after deletion from our live systems, a copy of your data may remain in encrypted backups for a limited period before it's cycled out as part of our routine backup rotation. We don't access, use, or restore backup data except to recover from a system failure — if a backup is ever restored, we re-apply any pending deletions immediately afterward

6. How we protect your data

  • Passwords are never stored in plain text — only as a one-way cryptographic hash
  • We do not store your grocery store password — connecting a store keeps you signed in via a stored session, the same way a browser would
  • Data in transit between the app and our servers is encrypted (HTTPS/TLS)
  • Access to production data is limited to personnel who need it to operate the Service
  • We do not log your passwords, session tokens, or full conversation content in our operational logs

No system is 100% secure, but we design the Service to minimize what could be exposed if something goes wrong, and we monitor for and respond to security issues.

7. Your rights

If you're in the UK or EEA, you have the following rights over your personal data, and we've built the Service to let you exercise them directly:

  • Access & export — download a copy of your account data, preferences, and conversation history at any time from Settings → Privacy → Export My Data
  • Deletion — delete your account and all associated data (profile, preferences, conversations, shopping lists, and connected store sessions) from Settings → Privacy → Delete Account. This is applied to our live systems immediately; see §5 for how long a copy may briefly remain in encrypted backups before it's cycled out
  • Correction — update your profile, preferences, and allergy information at any time in Settings → Profile
  • Withdraw consent — where we rely on your consent (e.g. allergy data), you can withdraw it at any time by removing that information from your profile
  • Object or restrict processing — contact us at privacy@aibutler.co.uk to object to a specific use of your data or request that we restrict processing
  • Complain to a regulator — you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office) if you believe we've mishandled your data

We aim to respond to any privacy request within 30 days.

8. Children's privacy

ai.butler is intended for users aged 16 and over. If you are a parent or guardian and believe your child has created an account or provided us with personal data, contact us at privacy@aibutler.co.uk and we will delete the account and associated data.

9. Changes to this policy

We'll update this policy as the Service evolves, and we'll note the "Last updated" date above whenever we do. Where a change is material, we'll notify you in-app before it takes effect.

10. Contact us

Questions about this policy or how we handle your data: privacy@aibutler.co.uk, or write to us at our registered office above.