Privacy Policy
Effective date: August 14, 2026 · Last updated: August 14, 2026
This policy was drafted for an early product and has not been reviewed by an attorney. It is not legal advice and is not a guarantee of compliance with any law.
Lunchbox Setlist helps parents and caregivers plan and track packed lunches. This policy explains, in plain language, what information the app handles and why.
Information you provide
Parents and caregivers may enter information into Lunchbox Setlist, including:
- Account information (such as your email address)
- Child or profile names and nicknames
- An optional birth month and year for a child profile, used only to make food suggestions age-appropriate. We never ask for an exact birth date.
- Food preferences and picks
- Setlists and lineups
- Meal planning information
- Food outcomes such as eaten, some, or untouched
- Notes and any other information you intentionally enter
This information is used to provide Lunchbox Setlist’s functionality: building setlists, planning ahead, tracking outcomes, and syncing with other caregivers in your crew when you choose to sign in. If you use the app without an account, this information stays on your device.
Information collected automatically
When you use Lunchbox Setlist, we may collect technical and product-usage information such as:
- Pages and screens viewed
- Features used
- Buttons and actions used
- Approximate session duration
- Device and browser information
- General performance information
- Anonymous or pseudonymous product analytics events
We use this information to:
- Understand how people use Lunchbox Setlist
- Identify confusing parts of the experience
- Improve features
- Measure product performance
- Diagnose technical problems
Product analytics (PostHog)
Lunchbox Setlist uses PostHog for product analytics. PostHog helps us understand how people navigate and interact with the app — for example, how many caregivers finish setup, or how often the weekly planner is used.
The app is intentionally configured to minimize the personal information sent to analytics. Our architecture separates the two:
- Application data (accounts, kids, foods, setlists) lives in our application database.
- Behavioral analytics (counts, screens, feature usage) goes to PostHog.
When you are signed in, analytics identifies your account only by a pseudonymous internal user ID — a random identifier, not your email or name. Before you sign in, a random device identifier is used instead. Analytics event properties are limited to counts, predefined categories, and the screen path you were on.
Analytics never contains caregiver names, child names, email addresses, food names, notes, feedback text, web addresses with search terms, passwords, authentication tokens, or any other information you type into the app. This is enforced on our servers with an approved-property list: anything not on that list is discarded before it is stored.
Lunchbox Setlist does not use session recording or session replay. If that ever changes, we will update this policy first.
Feedback you send us
When you use the Send Feedback screen, the message you type, the category you pick, and the screen you were on are stored so our team can read and respond to it. Only Lunchbox Setlist administrators can see feedback. Please leave out personal details you would rather not share, and email us at the address below to have a note removed.
Children’s privacy
Lunchbox Setlist is intended for use by parents and caregivers. It is not intended for use directly by children under 13. Parents and caregivers may enter information about children in order to use the planning and tracking features.
We do not create child accounts, child login flows, or features that encourage children under 13 to submit information directly. Lunchbox Setlist has not received any COPPA certification, and nothing here should be read as claiming one.
How information is shared
We do not sell your personal information. Trusted service providers may process information when necessary to operate the app. Providers in use today:
- Supabase — application infrastructure, database, and authentication
- PostHog — privacy-conscious product analytics
We may add other infrastructure providers as the product grows, and will update this list when we do. We may also disclose information if required by law.
Data retention and deletion
We retain information for as long as needed to operate your account and provide the service. Product-usage analytics stored in our own systems are kept for 12 months and then automatically deleted. If you delete your account, the analytics records linked to your account ID are deleted with it.
You can clear the data stored on your device at any time from Account, which includes options to clear lunch history or clear everything. There is no self-service delete for a cloud account yet.
To request deletion of your account, associated profile or child information, or stored application data, contact us at hello@lunchboxsetlist.com. (Founder input needed: a real deletion contact address must replace this placeholder before external testing.)
Changes to this policy
We may update this policy as the product changes. The effective and last-updated dates at the top will always reflect the current version.
Contact
[LEGAL/BUSINESS NAME — TO BE PROVIDED] — hello@lunchboxsetlist.com