Privacy Policy
Last updated: 29 August 2026
What we collect
- Account: your name, email address and a securely hashed password. We never store your password in readable form.
- Restaurant profile: venue name, type, cuisine, emirate, Instagram handle and logo — used to personalise templates.
- Menu content: everything you type or upload into a menu, including images.
- Usage counters: how many times a published menu has been viewed, and how many AI actions you have used today.
What we do not do
We do not sell your data, we do not run advertising trackers, and we do not use third-party analytics that profile your visitors. Scan counts are a simple number — we do not record who scanned or from where.
Where it lives
Data is stored in MongoDB Atlas. Sessions use a signed, http-only cookie — it identifies your account and nothing more. Published menus are readable by anyone with the link; unpublished menus are visible only to you.
AI processing
When you use AI features — importing a menu from a photo or text, writing descriptions, translating, or remixing a design — that content is sent to Anthropic's Claude API to generate the result. It is used to answer your request, not to train models. If you never use those features, nothing is sent.
Your rights
You can export everything we hold about you as JSON, correct your details, or permanently delete your account and all associated data — all from Settings. Deletion is immediate and irreversible.
Retention and contact
We keep your data while your account exists. Password-reset links expire after 30 minutes. For any privacy question, write to privacy@qaima.example.