Privacy Policy
Introduction & Scope
Sixish is operated by Principia29 LLC (“Principia29,” “we,” “us”). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It applies to both the Sixish iOS app and the sixishapp.com website. Where a practice applies to only one of these (for example, the early-access email list on the website, or pantry tracking in the app), we say so. By creating a Sixish account or using the app, you agree to the practices described here.
Who We Are
Sixish is a meal-planning app for busy families. For any privacy question or request, contact us at hello@sixishapp.com.
Information We Collect
Account & identity
Sixish uses Sign in with Apple as the only way to create an account. When you sign in, Apple gives us a unique Apple identifier and, the first time only, the name and email address you choose to share (which may be an Apple private-relay address). We immediately convert your Apple identifier into a one-way hashed Sixish user ID for our servers (your raw Apple identifier is never stored on our servers), and we store a session token securely on your device.
Profile & household
The information you provide during onboarding and in Settings: household size (number of adults and children, and children's ages), dietary restrictions (including any custom ones you type), preferred cuisines, kitchen equipment, and recipe preferences.
Content you create in the app
Your pantry / food inventory, saved and imported recipes, meal plans, grocery lists, recipe ratings and saves, cooking history, and any notes you add.
Camera, photos, voice & barcode inputs
With your permission, content you provide to add items or import recipes: photos of groceries or recipes, spoken voice input, and scanned barcodes.
Device & technical data
A vendor device identifier, app and build version, a device-attestation token (see “Abuse prevention” below), and, if you allow notifications, a push token so we can tell your devices when household content changes.
Analytics, diagnostics & feedback
Anonymous product-usage events and crash/performance diagnostics, plus any message you choose to send through in-app feedback. You can also send feedback from the feedback page on this website, which does not ask for your name or email; please leave personal details out of your message.
Website
If you join the early-access list on sixishapp.com, we collect the email address you submit and a few details about the visit: the page that sent you here, the address of the page you signed up on (including any campaign tags in the link), whether your browser window is phone-sized, your time zone, your browser language, your browser window width, and when you signed up. We keep these with your email in our signup list to understand where signups come from. The form also reports how long it was open before you sent it; we log that number to spot automated signups and do not store it with your email. Each new signup also sends our team a message in a private Discord channel with your email, the page that sent you here, your device type, time zone and campaign tags.
How We Use Your Information
- Authenticate you and keep you signed in
- Generate, modify, and personalize recipes, meal plans, and suggestions
- Sync your content across your devices
- Understand product usage and fix crashes (anonymous analytics & diagnostics)
- Prevent abuse and apply rate limits
- Respond to support requests and send service or early-access communications
How Your Data Is Processed
To generate and modify recipes, parse your voice and photo inputs, and import recipes, we send the relevant content (such as your pantry item list, dietary and household preferences, voice transcripts, and recipe text) to our AI provider (Microsoft Azure OpenAI Service / OpenAI). Photos you provide for pantry recognition or recipe import are sent to an image-recognition model to identify items or text; incidental background content may be included in an image. Voice input is sent to Apple's speech-recognition service for transcription (it is not processed on your device by default, so your audio leaves the device). The resulting text is then sent to that same provider to create pantry items. We may also convert recipe text into numerical representations (embeddings) using the same provider to power search and similar-recipe matching. Dish images shown in the app are generated by an image provider (Black Forest Labs / FLUX, via Azure) from only a short text description of the dish, never your photos or personal information. This content is processed to return results to you; it is not used to build an advertising profile of you. We do not store the photos or audio you provide for these features after they are processed.
Accuracy, Nutrition & Allergen Disclaimer
Recipes, cooking times, ingredient lists, and nutrition figures in Sixish are automatically generated estimates and may be inaccurate or incomplete. The dietary and allergy preferences you enter are used to guide suggestions but are not a guarantee: Sixish does not verify that any generated or modified recipe is free of allergens or suitable for a medical diet. Always check ingredients yourself, cook foods to safe temperatures, and consult a qualified professional for medical, allergy, or dietary needs.
Community Sharing & the Explore Feed
Sixish includes a community Explore feed of recipes contributed by users. When you import a recipe from a web or social link and save it, the original recipe (with its source attribution) is automatically added to the shared community library by default and can appear in Explore for other Sixish users. There is currently no per-recipe setting to turn this off for link imports (subject to automated eligibility and safety checks). By contrast, recipes you import from text or photos, or enter manually, are shared only if you opt in. We run an automated check to remove obvious personal information from the attribution before sharing, and we share the original imported recipe rather than any private edits or notes you add. To remove recipes you have contributed, delete your account (see below).
Analytics, Diagnostics & Abuse Prevention
We use PostHog for privacy-preserving product analytics and Apple's MetricKit for crash and performance diagnostics. These events are not tied to your name or email; they use an app-generated analytics identifier and may include your device's vendor identifier (which we also use for abuse prevention), so they are pseudonymous rather than fully anonymous. They contain data such as screen views, feature-usage counts, opaque recipe identifiers, bucketed error codes, and summary attributes (such as your dietary tags, household size, whether you have children, and chosen difficulty). We do not attach your name, email, pantry contents, or free text to analytics. The one exception is the feedback you choose to send us, through in-app feedback or the feedback page on our website, so please don't include sensitive personal information there. Each note from the website is stored with a fresh random identifier that is not linked to an app, a device, or your other notes. To protect the service from abuse and apply rate limits, we use your device's vendor identifier and a device-attestation token generated by Apple's App Attest and verified through Google Firebase App Check; these tokens confirm a request comes from a genuine, unmodified Sixish install and do not contain your personal information.
How Your Data Is Stored & Synced
Your sign-in tokens stay in your device's secure Keychain.
Your pantry, recipes, meal plans, grocery lists, preferences and the household details you set up (how many adults and children you cook for, their ages, and any dietary needs) are stored on your device and on our servers, hosted on Microsoft Azure in the United States, encrypted in transit and at rest. Storing them on our servers is what lets the people in your household share one list and see each other's changes.
Your content is filed under an account identifier, not your name or email. We do not store your name, your email address, or the names you give other members of your household with your content. When you join a household, its members can see and change what it holds, including who checked an item off; you can leave at any time and keep the copy on your phone.
Versions of Sixish before build 192 also kept a copy of your content in your private iCloud account using Apple CloudKit. Current versions no longer write to iCloud. Any copy left there stays under Apple's privacy terms, and when you delete your account we delete that copy as well.
Third-Party Service Providers
We do not sell your personal data. We share data only with service providers who process it on our behalf to run Sixish:
- Apple: Sign in with Apple, speech recognition, device attestation, and push notifications; iCloud storage only for copies made by versions before build 192
- Microsoft Azure: cloud hosting, database, storage, and diagnostics
- Azure OpenAI / OpenAI: text and image-input processing
- Black Forest Labs / FLUX: recipe-image generation
- Google Firebase: App Check device attestation
- PostHog: privacy-preserving product analytics (not linked to your name or email)
- Apify: retrieving captions from social links you choose to import
- Discord: a message to our team's private channel when someone joins the early-access list
When you import a recipe from a link, we also fetch the linked web page or social post to extract the recipe content.
Data Retention
We keep your account data for as long as your account exists. Some data is kept only temporarily: captions from imported social links for up to 30 days, anonymous generated recipe content for about 60 days, and rate-limit counters and session tokens for short, fixed periods. After you delete your account, we keep a minimal record (an opaque identifier and the deletion date) for about a year to prevent old credentials from restoring deleted data. Anonymous, non-identifying content (such as generated recipes and diagnostic logs with truncated identifiers) may persist until it automatically expires.
Content you added to a shared household stays with that household after you leave or delete your account, with your account identifier removed from it; deleting your account removes your own content from our servers.
Your Privacy Rights & Choices
You can:
- Access and edit most of your data directly in the app (profile, pantry, recipes, preferences)
- Permanently delete your account at any time from Settings → Delete Account
- Control camera, photo, microphone, and notification permissions in iOS Settings
- Opt out of our communications, or request a copy of, correction of, or deletion of your data
To exercise any of these rights, contact us at hello@sixishapp.com. We aim to respond within 30 days, and we will not discriminate against you for exercising a privacy right.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of that information, and to request correction of inaccurate information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. You may exercise these rights using the contact above, and we will not deny you service or otherwise discriminate against you for doing so.
European & UK Privacy Rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights to access, correct, erase, restrict, and object to the processing of your personal data, and to data portability. The legal bases on which we rely are: performance of a contract (to provide the core app and your account); your consent (for optional device permissions such as camera, photos, and microphone/voice, which you can withdraw at any time in iOS Settings); and our legitimate interests (to secure the service, prevent abuse, and improve the product through privacy-preserving analytics). You may exercise these rights using the contact above, and you have the right to lodge a complaint with your local data protection authority.
Account Deletion
When you delete your account from Settings, we first delete your server-side data (your preferences, ratings, and any recipes you contributed to the community), revoke Sixish's Sign in with Apple connection, and then erase your data from the app, along with any copy an earlier version left in your iCloud. If any server deletion fails, we do not report success and your data is not erased, so you can try again. Signing out (without deleting) clears your credentials from the device but leaves your synced data in place.
Children's Privacy
Sixish is intended for adults managing a household. We do not knowingly allow children to create accounts or knowingly collect personal information from children. To personalize recipes and serving sizes, a parent or guardian may tell us how many children are in the household and their ages; this information is provided by the adult account holder, is used only to tailor meal suggestions, and is not used to contact or profile children. If you believe a child has provided us personal information, contact us and we will delete it.
Cookies & Website Analytics
The sixishapp.com website does not use cookies for advertising or cross-site tracking. The early-access form collects the email address you submit and the visit details listed under “Website” above, and the feedback page collects only the note you write and whether it is a thought, a bug or an idea. Neither form sets cookies, and neither stores your IP address with what you send. To stop spam, the feedback page keeps a temporary, scrambled counter in memory for about ten minutes. If our website practices change, we will update this policy.
Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit and at rest and secure on-device storage of credentials. However, no method of storage or transmission over the internet is completely secure, and we cannot guarantee absolute security.
International Users
Sixish's servers and service providers process data in the United States (any iCloud copy left by an earlier version is stored according to Apple's infrastructure and terms). If you use Sixish from outside the United States, your information will be transferred to and processed in the United States. By using our services, you consent to this transfer.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the new policy on this page and update the date below; material changes may also be communicated in the app or by email.
Contact Us
If you have any questions about this Privacy Policy, please contact us at hello@sixishapp.com.
Last updated: October 1, 2026