Privacy Policy
Last updated: April 2026
We keep this simple: wft? collects only the data needed to run your family meal planner. We don't sell your data, show you ads, or share your information with third parties except where necessary to operate the service.
1. Who We Are
wft? is operated by Amanda Jones ("we", "us", "our"). For questions about this policy or your personal data, please contact us at hello@whats-for-tea.com.
We are registered with the Information Commissioner's Office (ICO) as a data controller. ICO registration number: ZC138593.
2. What Data We Collect
| Data | Why we collect it |
|---|---|
| Your name | To identify you within your family group |
| Email address | To create your account and send family invites |
| PIN (hashed) | To authenticate you when you sign in |
| Profile emoji / photo | To personalise your in-app avatar |
| Meal preferences and ratings | To generate and improve your meal plans |
| Vetoes and joker plays | To operate the app's game mechanics |
| Push notification token | To send you plan confirmations and updates (if you opt in) |
| Device type | To determine whether you're using the web or Android app |
We do not collect location data, payment card details, or any data beyond what is listed above.
3. How We Use Your Data
- To create and manage your family account
- To generate weekly meal plans based on your family's preferences
- To send family invite emails when an admin requests one
- To deliver push notifications about your meal plan (only if you grant permission)
- To allow family members to rate, veto, and joker meals
- To provide shopping lists based on confirmed meal plans
4. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
- Contract performance — processing your name, email, and PIN is necessary to provide the service you signed up for.
- Legitimate interests — storing meal preferences and ratings helps us deliver a better experience for your family.
- Consent — push notifications are only sent if you explicitly grant permission on your device.
5. Who We Share Your Data With
We use the following third-party services to operate wft?:
- Google Firebase (Firebase Authentication and Cloud Firestore) — stores your account and family data. Google acts as a data processor under our instructions. Data may be processed in the USA under Standard Contractual Clauses. See Firebase Privacy.
- Resend — used to deliver family invite emails. Only the recipient's email address and family name are shared. See Resend Privacy Policy.
- Netlify — hosts the web app and serverless functions. See Netlify Privacy Policy.
We do not sell, rent, or trade your personal information with any third party for marketing purposes.
6. Data Retention
We keep your personal data for as long as your account is active. If you ask us to delete your account, we will remove your data within 30 days, except where we are required to retain it for legal reasons.
Family invite tokens are automatically deleted after 7 days or upon first use, whichever comes first.
7. Children's Privacy
wft? is designed for family use and is intended for users aged 13 and over. We do not knowingly collect personal information from children under 13. If you are under 16, you should have your parent or guardian's permission before creating an account.
If you believe a child under 13 has provided us with personal information without appropriate consent, please contact us and we will delete it promptly.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your account and associated data
- Portability — request your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — ask us to restrict processing in certain circumstances
To exercise any of these rights, contact us at hello@whats-for-tea.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
9. Security
We take reasonable technical and organisational measures to protect your personal data. Your PIN is never stored in plain text. All data is transmitted over encrypted HTTPS connections. Access to your family data is restricted to members of your family group only.
10. Cookies and Tracking
wft? does not use advertising cookies or tracking pixels. Firebase may set technical cookies necessary for authentication. We do not use any analytics services that track individual users across websites.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify family admins by email.
12. Contact Us
For any privacy-related questions or requests, please contact:
Amanda Jones
wft?
hello@whats-for-tea.com