MorselNote Privacy Policy
MorselNote works without an account. Your library stays on your device unless you choose encrypted sync, and it is never sent to the advertising SDK.
Effective and last updated: July 20, 2026
Data stored on your device
Your food diary, goals, custom foods, meals, recipes, favorites, and settings are stored locally. Morningstar Garden does not receive or sell readable diary data.
Optional end-to-end encrypted sync
If you turn on MorselNote Sync, the app encrypts your diary, recipes, meal plans, pantry, shopping lists, goals, meals, custom foods, and favorites on your device before uploading an encrypted manifest and encrypted data blocks to Cloudflare R2. After the first upload, MorselNote transfers only blocks containing changed records. Morningstar Garden and Cloudflare do not receive the encryption key and cannot read the manifest or blocks.
The sync service stores the encrypted manifest and blocks, a one-way hash of the vault access token, their sizes, update times, and storage metadata. Standard network information such as an IP address is processed to deliver and rate-limit requests. MorselNote application logs omit vault identifiers, access tokens, recovery codes, and vault contents. A recovery code contains the key and should be protected like a password; Morningstar Garden cannot recover it.
Optional Shared Kitchens
If you create or join a Shared Kitchen, MorselNote stores its recipes, menus, meal plans, grocery items, kitchen name, member display names, and membership roles in a separate end-to-end encrypted vault. Personal diary entries, nutrition goals, custom foods, and settings are not copied into a Shared Kitchen. The kitchen invitation contains its encryption key. Anyone who receives the invitation can read and change that kitchen, so it should only be shared with intended household members.
A kitchen owner can rotate access. Rotation creates a newly encrypted vault, invalidates the previous invitation, and stops previously connected devices from receiving future changes. Intended members must join again with the new invitation. Rotation cannot erase kitchen information that another device downloaded before access was rotated.
Advertising
MorselNote displays light, non-personalized banner advertising using the Google Mobile Ads SDK. Ads are not selected from your food diary, goals, searches, or past activity. MorselNote disables Google's publisher first-party identifier and marks every ad request as non-personalized.
Google and its advertising partners may still process your IP address (which can indicate approximate location), device or advertising identifiers, ad interactions, diagnostic and performance information, and advertising data to deliver ads, prevent fraud, limit repetition, and produce aggregated reports. This information may be shared with advertising partners. MorselNote uses Google's User Messaging Platform to request consent where required and displays a Privacy choices control when Google requires an ongoing privacy entry point.
Food searches and barcodes
When you search for food or look up a barcode, the search term or barcode is sent to MorselNote's Cloudflare-hosted nutrition-search service. The service normally searches MorselNote's mirrors of USDA FoodData Central, Open Food Facts, the Canadian Nutrient File, Ciqual, the Australian Food Composition Database, UK CoFID, reviewed MorselNote Community products, and reviewed nutrition disclosures from supported restaurant websites. Restaurant records retain a link to the official product source and cannot enter search without human review. If an exact barcode is absent from the Open Food Facts mirror, MorselNote immediately checks Open Food Facts for that product. USDA and Open Food Facts may also be queried live if a corresponding mirror is unavailable. Successful search responses may remain in Cloudflare's cache for up to six hours; unsuccessful barcode responses remain for no more than five minutes.
When a missing barcode resolves through the live Open Food Facts lookup, MorselNote retains that barcode and the public product name and brand in an operational refresh queue until it is incorporated into a verified mirror refresh. The queue does not contain an account, IP address, diary entry, meal, date, device identifier, or advertising identifier.
MorselNote's application logs omit search terms, barcodes, IP addresses, and USDA credentials. They contain request status, cache state, timing, provider health, and a random request ID. Cloudflare processes standard network information for every search. USDA FoodData Central or Open Food Facts also processes standard network information only when its live fallback is used or when you use a personal USDA key. MorselNote does not associate searches with an account or send search terms, barcodes, diary entries, or goals to the advertising SDK.
Community food submissions
When a barcode has no match, you may choose to share a custom product with the MorselNote Community catalog. Sharing is off by default and requires an explicit choice for each product. A submission contains only the barcode, product name, brand, serving information, nutrition facts, language setting, and country inferred by Cloudflare. It does not contain your diary entry, meal, date, account, advertising identifier, sync vault, or a photo.
Submissions are stored separately from authoritative nutrition mirrors and remain pending until reviewed. Repeated identical submissions may be counted together. By sharing, you grant Morningstar Garden permission to review, modify, combine, and redistribute the submitted product facts as part of the MorselNote Community catalog. Pending or rejected records may be retained to prevent duplicate review and abuse.
Recipe imports
When you import a recipe, MorselNote requests the web address you provide from that recipe website. The site receives standard network information associated with the request.
Optional personal USDA key
If you enter a personal USDA API key in Settings, it is stored in the Apple Keychain or Android encrypted preferences. Searches made with that key go directly to USDA FoodData Central. Secure credential files are excluded from Android cloud backup and device transfer.
Camera
Camera access is used to recognize food barcodes and encrypted sync or Shared Kitchen QR codes. Code recognition happens on the device. MorselNote does not save or upload camera photos or video.
Retention, backups, and deletion
Search-cache entries expire automatically after no more than six hours. MorselNote has no user accounts. A personal sync vault is retained until you delete it from Settings → Encrypted sync → Delete Encrypted Vault. A Shared Kitchen is retained until an owner chooses Delete kitchen for everyone. Leaving a kitchen removes its key and local copy from that device but does not delete the kitchen for other members. You can remove local diary entries and other personal app data with Settings → Delete all local data. Deleting MorselNote removes local data and keys from that device but does not by itself delete cloud vaults. Apple or Google may retain device backups according to your backup settings; you control those copies through your platform account.
Children and health information
MorselNote is not directed to children under 13. Nutrition values are estimates for general wellness and are not medical advice, diagnosis, or treatment.
Contact
For privacy questions, use MorselNote's support page and the developer contact shown in the App Store or Google Play listing for your platform.