Privacy policy for Planuko
This is a translation. If the English and Danish versions differ, the Danish version applies.
Last updated: 9 October 2026
1. Who we are
Planuko is run by Lucas Buur. CVR number will be added once the business is registered. We are the data controller for the information described here.
Contact about privacy: hej@planuko.com
2. In brief
- We use your information to build your meal plan and your shopping list. We never sell it and never use it for advertising.
- We only store allergies if you say yes to it in the app. You can withdraw that yes again.
- We count which screens are used, without linking it to your account. If you say yes, we also recognise the phone from one time to the next.
- Photos you scan are sent to a service that recognises food. We do not store the photo itself.
- You can delete your account inside the app.
3. What we process, and why
| What | Why | Basis |
|---|---|---|
| Account: a user ID. If you log in with Apple or Google, also your email and the name you share | Store your meal plan and recognise you when you log in again | The agreement with you (GDPR Article 6(1)(b)) |
| Household: number of people, weekly budget, kitchen equipment, whether you eat vegetarian or vegan, kitchens you like or dislike, and whether you want breakfast and lunch included | Build a meal plan that fits you and your budget | The agreement (Article 6(1)(b)) |
| Allergies (including "no pork") | Filter out dishes that contain what you have chosen | Your explicit consent (Article 9(2)(a) and Article 6(1)(a)). See section 4 |
| Meal plans: the weeks the app creates, and their prices | Show you the week and the shopping list | The agreement (Article 6(1)(b)) |
| Receipt: the amount you enter yourself after shopping | Show you whether the week kept within budget | The agreement (Article 6(1)(b)) |
| Favourites and hidden dishes | Give you more of the dishes you like | The agreement (Article 6(1)(b)) |
| Feedback: thumbs up/down, the reasons you pick, text you write yourself, which screen, the app's version and the week | Fix bugs and make the app better | Our legitimate interest in improving the app (Article 6(1)(f)) |
| Scan: your photo and what we recognise in it | Recognise the food and suggest dishes | Your consent (Article 6(1)(a)). See section 6 |
| On the phone: your shopping list with ticks and your own lines; what you have bought; a copy of the week's plan; your reminders; the widget (today's dish and its price) | Make the list and the plan work without a connection, and remind you of the week and dinner | The agreement (Article 6(1)(b)). Reminders only if you turn them on |
| Usage: how many meal plans, swaps and scans you have made | Keep track of the free-tier limits and prevent misuse | Our legitimate interest (Article 6(1)(f)) |
| Subscription: whether you have Pro, and your purchases | Unlock Pro | The agreement (Article 6(1)(b)) |
| Usage statistics and error reports | See where people get stuck, and find bugs | See section 5 |
We do not ask for your location, and the app does not use GPS. The prices are REMA 1000's national prices, so we do not need to know where you live.
4. Allergies
Allergies say something about health, and "no pork" can say something about religion. That is why we only store them if you tap yes in a separate step. If you say no, the app still works, but the meal plan is made without an allergy filter.
You can withdraw your yes under Profile. We then delete the allergies you have chosen, and new meal plans are made without a filter.
If the allergies also apply to others in the household, they should know that you are sharing them with us.
The filter is a help, not a guarantee. Recipes and products can change. Always check the product's label yourself.
5. Usage statistics and error reports (PostHog)
We use PostHog for statistics. Their servers are in the EU. In brief:
- Without your yes we count what happens in the app, but we cannot see that it is you coming back.
- With your yes we can see that it is the same phone from day to day.
- Allergies, diet and your user ID are never sent to PostHog.
Without your yes (for everyone): The app tells PostHog which screens are opened. It also reports certain actions, e.g. that a meal plan was created and what it cost, or that the payment screen was shown. This comes with the app's version and the phone's model and operating system.
If the app crashes, we send the type of error and where in the code it happened. We do not send the error message itself, because it can contain what was on the screen.
We store nothing about this on the phone. Every time the app starts, it gets a new random ID. So we cannot see that it is you coming back tomorrow.
PostHog does, however, see your IP address when the app sends data. That is why it still counts as personal data. PostHog can guess where you are from the IP address. We have turned that off.
With your yes: The app stores a statistics ID on the phone, so we can see what works over time. We also send when the app is opened and closed.
We also send the statistics ID to RevenueCat, which keeps track of your subscription. This lets us see how Pro users use the app. At RevenueCat, the statistics ID sits together with your user ID.
You can say no again under Profile ("Share usage data"). Then this part stops immediately, and we delete the statistics ID at RevenueCat.
We do not record the screen, and we do not log what you tap, only the actions we have named ourselves.
Why we are allowed to: With your yes, the basis is your consent (Article 6(1)(a)). Without your yes, we still count, because we have a legitimate interest in seeing where people get stuck and fixing bugs (Article 6(1)(f)).
6. Scan
Scan is turned off in the app today. When it is turned on, this applies:
Before your first scan we ask whether we may send your photo onward. If you say yes, the photo is sent to a service that recognises food (Scaleway in France, using a model from Mistral). It receives the photo and our instruction, but not your name or user ID. We do not store the photo itself. We store what was recognised and a fingerprint of the photo (a code the photo cannot be recreated from), so the same photo does not have to be sent twice. If you save a scan, the result sits in your account. We store at most your 100 most recent.
You can withdraw your consent under Profile. Then scanning stops.
7. Payment
You pay for Pro through Apple. We never see your card details. We use RevenueCat to keep track of whether you have Pro. RevenueCat gets your user ID from Planuko and information about your subscription from Apple.
8. Who receives your information
| Who | What they do for us | Where |
|---|---|---|
| Supabase | Database and login | EU (Frankfurt) |
| PostHog | Statistics and error reports | EU |
| RevenueCat | Subscriptions | USA |
| Scaleway (only when scan is turned on) | Recognises food in photos | EU (France) |
| Apple | Payment and login with Apple | Apple decides for itself over the information |
| Login with Google, if you choose it | Google decides for itself over the information | |
| Vercel | Runs the website | USA |
| Resend | Forwards messages from the contact form to us and sends emails to the waitlist | EU (Ireland) |
| Cloudflare | Forwards email sent to hej@ and support@planuko.com to our inbox | USA (the company), servers worldwide |
The contact form on the website. If you write to us, we receive your name (if you give it), your email and your message. We only use them to reply to you. The website does not store the message: it is sent to us as an email and stays in our inbox until the matter is settled, and at most 12 months after.
9. Information outside the EU
- RevenueCat is based in the USA.
- Supabase stores your data in Frankfurt, but the company is American, so support from the USA may get access.
- PostHog stores your data in the EU, but the company is American.
For all three, the basis is the EU's standard contractual clauses, which form part of their data processing agreements. You can get a copy by writing to us.
10. How long we keep it
| What | How long |
|---|---|
| Account, household, allergies, meal plans, receipt, favourites, saved scans | Until you delete the account |
| Feedback | 24 months, or until you delete the account |
| Fingerprint and result of scans (reuse) | 7 days, or until you delete the account |
| Usage of meal plans and swaps | Counts more than a day old are deleted the next time you make a meal plan or swap a dish, and otherwise when you delete the account |
| What only lives on the phone | Until you delete the account, log out or delete the app |
| Count of scans (type, time, cost for us) | For as long as you have an account. If you delete it, we keep the count without your user ID for 12 months, so our cost overview stays accurate |
| Statistics in PostHog | At most 12 months |
| Subscription information at RevenueCat | Until you delete the account |
| Purchase information at Apple | Under Apple's own rules |
11. Delete your account and get your data
Delete account: Tap "Delete account" under Profile. We then delete your account, your household, your allergies, meal plans, favourites, saved scans and your feedback. We also delete you at RevenueCat, and after that the statistics in PostHog can no longer be linked to you. On the phone we clear the list, the plan, the widget and your reminders. We keep the count of your scans without your user ID (see section 10).
If you have logged in with Apple, we also try to remove Planuko's access to your Apple login. If that fails, you can remove it yourself in the iPhone's Settings → your name → Sign-In with Apple.
Deletion cannot be undone.
Your subscription does not stop when you delete the account. You cancel that in the iPhone's Settings → your name → Subscriptions.
Get your data: Tap "Get my data" under Profile. You then get a copy of what we hold about you in our database, in a common format. What sits at RevenueCat is not included. You get that by writing to us, and if you have said yes to recognising the phone, the phone's statistics ID is included there. PostHog does not know your user ID, so we cannot look up the statistics there for you.
12. Your rights
You have the right to get access to your information, have it corrected or deleted, get it handed over, object to what we do based on legitimate interest, and get the processing restricted. If you have given consent, you can always withdraw it. That applies from the moment you do so.
Write to hej@planuko.com. We reply within a month.
If you are unhappy, you can complain to Datatilsynet (the Danish Data Protection Agency), www.datatilsynet.dk.
13. Age
Planuko is made for the adult who is in charge of the household's food. You must be at least 13 years old to use the app.
14. The waitlist
If you join the waitlist on the website, we store your email address, the language, where on the page you signed up, the time, the text you agreed to and the offer shown by the form. If you came via a link from Instagram or Facebook (a message from us or our profile), we also store which link, and for a message the keyword and the post you commented on. We use the email to tell you when the app launches, and for app news until then, at most one email a month. The legal basis is your consent.
The data is kept in our database at Supabase in the EU. We send emails to you through Resend. If you reply, Cloudflare forwards your reply to our inbox at Gmail (Google). We don't sell your email and don't use it for anyone else's advertising.
You can unsubscribe at any time, and we then delete your email. Reply "unsubscribe" to an email from us, write to hej@planuko.com, or use the support page.
15. Changes
If we change this policy significantly, we will say so in the app before the change takes effect.
