Last updated: 28 August 2026
Menu Goat is built so that there is very little to say here. This page describes what actually happens, and the architecture is arranged so that it could not easily happen any other way.
Your menu photos are processed as they pass through and are never stored. There is no account and no tracking. Recent scans are kept on your phone for 30 days so you can look one up again — the dish cards only, never the photographs, and never sent to us.
When you scan a menu:
description of the dishes.
The photo exists only for the length of that one request — a few seconds. It is not written to any disk, database, or file store, on our servers or anywhere else. Our server has no storage attached to it at all: there is nowhere for a photo to be kept, even by mistake.
We ask Google not to retain the request either (store: false), and Menu Goat uses the Gemini API on a paid plan, under which Google does not use prompts or responses to improve its products and retains them only briefly for abuse detection and legal compliance. Google's handling of API data is covered by the Gemini API terms.
email address, or phone number.
app on your phone. The recent-menus list holds only the text of the dish cards, and it is deleted automatically after 30 days. You can clear it at any time in Settings, and deleting the app removes it immediately.
came from.
photos, not the text extracted from them, not the results.
advertising identifier, and no third-party tracker in this app.
Two numbers, and nothing else:
They are stored against a one-way hash of the anonymous identifier below, so the value we hold cannot be turned back into that identifier, let alone into you. Both expire on their own — the daily count within two days.
This exists so that free scans mean something and so that the service cannot be used as an open pipe to someone else's expense. It holds no photographs, no text from your menus, and nothing about what you scanned.
Three things, all local to your device and never sent anywhere:
Deleting the app deletes all of them, and the recent-menus list can be cleared on its own in Settings.
The app generates a random identifier the first time it runs. It is not derived from your device, your phone number, or anything about you, and it is not linked to any personal information.
It is used for three things: to let RevenueCat associate a purchase with the device that made it, so you can restore it later; to ask RevenueCat whether that purchase is still active, which is how the app knows you are a subscriber without you ever creating an account; and — as a one-way hash, so that even the original random value never reaches our server in readable form — to count the two numbers above and to space out requests.
Purchases are handled by Apple and by RevenueCat, which manages subscription state. We never see your payment details; Apple does not share them with us. RevenueCat receives the anonymous identifier above and the purchase record, and nothing else.
Dish explanations and allergen tags are generated by an AI model reading a photograph of a menu. They can be wrong, and they can be incomplete.
If you have a food allergy, confirm with restaurant staff before ordering. Menu Goat is a translation aid, not a medical or dietary safety tool.
Menu Goat is not directed at children and does not knowingly collect any information from anyone, of any age.
If this policy changes, the date at the top changes with it, and the updated version appears here.
Questions about privacy: hello@menugoat.app