Privacy Policy
Effective August 9, 2026
On the Menu is a private planning service for two adults. This policy describes the information the service handles on the website and mobile apps using the same service.
Information we handle
- Guest planning data: participant display names, scheduled date and time, proposed menu selections and custom text, decisions, approvals, presence timestamps, and deletion confirmations.
- Account data: the email address, display name, and sign-in identifiers supplied through Clerk; an optional exact handle; Menu Partner requests, connections, blocks, and account-menu attachments. For a current Menu Partner connection, this also includes your private compatibility answers, custom consideration cards, revealed mutual matches, and match-to-menu proposal records.
- Notification data: email preference, recipient account, notification type, delivery state, retry state, and a safe destination path. Notification content does not include menu selections, compatibility labels, answers, match counts, or partner identity.
- Operational data: request, device, network, security, error, and performance information processed by Microsoft Azure to host, secure, and monitor the service.
How we use information
We use this information only to operate the shared menu, authenticate optional accounts, connect a chosen Menu Partner, privately reveal shared interests without disclosing individual answers, preserve account access to attached menus, deliver requested product notifications, enforce retention and deletion, secure the service, and diagnose failures. On the Menu does not sell personal information and does not use it for third-party advertising.
Service providers
Microsoft Azure hosts the application, PostgreSQL data, and operational telemetry. Clerk processes account authentication and federated sign-in. GitHub stores source code and deployment records; production customer data is not intentionally sent there. Resend delivers product email and receives the recipient email address and privacy-minimal notification content, but not menu selections.
Retention
Planning menus are retained until 30 days after their scheduled time or are purged after 30 days without activity, whichever comes first. Agreed and closed menus are retained for 90 days. Notification delivery records are retained for 90 days. Private compatibility data lasts only for its current Menu Partner connection and is deleted when that connection ends or either account is deleted. A compatibility idea already proposed into a shared menu follows that menu's retention. Shared-menu deletion occurs immediately after both participant slots confirm within 24 hours.
Your choices
Accounts are optional. Signed-in users can change or clear a compatibility answer, withdraw a custom card, turn notification categories or product email off, hide a menu from their own library, disconnect or block a Menu Partner, and delete their account. Either participant can leave or close a menu. See Account and menu deletion for the exact effects.
Security and private links
Traffic uses HTTPS. Guest links and account sessions grant access to private data, so keep links between the intended participants and replace a partner link if it may have been shared. Compatibility matching happens on the server: clients receive your answer and a mutual-match result, never the other person's individual answer. No service can guarantee absolute security.
Adults only
On the Menu is intended only for adults age 18 or older and is not directed to children.
Questions and changes
Questions about privacy can be sent to support@getonthemenu.com. Current support options are published on the Support page. Material changes to this policy will be reflected here with a new effective date.