Privacy Policy
Last updated August 25, 2026
Overview
OnlyMenu IO is a private, end-to-end encrypted product catalog and messaging app operated by Avante Studio LLC ("Avante Studio", "we", "us"). This policy explains what we collect, what we can and cannot see, and the choices you have. It applies to the OnlyMenu IO mobile app and the services behind it.
End-to-End Encryption
Your catalog and message content is encrypted on your device before it reaches our servers, using X25519 key exchange with AES-256-GCM encryption. This covers catalog names, product titles, prices, descriptions and tags, product photos and videos, direct and group message text, and chat attachments. Your private key is generated on your device and held in the operating system secure storage. It is never sent to us. Because of this we cannot read your catalog content or your messages, cannot recover them for you, and cannot produce them in readable form to anyone else.
Encrypted Key Backup
You may create an optional encrypted backup of your key so you can restore access on another device. It is encrypted with a passphrase you choose, using PBKDF2-SHA256 key derivation. We store only the encrypted blob and never receive your passphrase. If you lose that passphrase we cannot restore your content.
Information You Provide
Account details: email address, username, display name and an optional profile photo. Content: the catalogs, products, prices, descriptions, tags, photos and videos you upload, and the messages you send. Support requests: the subject, message and any screenshot you attach, along with your email address if you are signed in. Abuse reports: when you report an account or a message we record who reported whom and the reason you chose, and for a message report an identifier for that message and for the conversation, group or catalog it was in. We never receive the reported message itself — it stays encrypted.
Information Collected Automatically
A push notification token for the device, so notifications you have enabled can be delivered. Operational records such as when an account was created, when a message was sent, and which accounts belong to which catalog or group. Standard server logs kept by our hosting provider for security and reliability.
What Is Not Encrypted
Some information has to stay readable for the app to work: your email address, username, display name, profile photo, catalog cover photos, push notification tokens, support requests, and metadata such as group and catalog membership and message timestamps. Profile photos and catalog cover photos are stored in public storage and can be viewed by anyone holding the direct link. Please do not use an image as a profile photo or catalog cover that you would not want to be public.
How We Use Information
To create and operate your account; to store and deliver your encrypted content; to send transactional email such as account confirmation and password reset; to deliver push notifications you have enabled; to answer your support requests; to investigate abuse reports and enforce our Terms; and to keep the service secure and reliable.
Legal Bases (EEA and UK)
Where the GDPR applies we process personal data to perform our contract with you, which is operating the app; on the basis of your consent for push notifications and device permissions, which you may withdraw at any time in system settings; and for our legitimate interests in securing the service and preventing abuse.
Device Permissions
Photo library access is used to pick images and videos for your catalog or messages. Camera access is used to take a product photo. Saving to your photo library is used when you download media from the app. Notification permission is used to deliver push notifications. Each is optional, is requested only when you first use the feature, and can be changed at any time in your device settings.
Advertising and Analytics
OnlyMenu IO contains no advertising, no third-party analytics or tracking SDKs, and no cross-app tracking. We do not use your data for advertising and we do not build advertising profiles.
Service Providers
We rely on a small number of providers: Supabase for database, file storage and backend hosting; Expo together with the Apple Push Notification service and Google Firebase Cloud Messaging for push delivery; and Resend for transactional email. They process data only to provide their service to us. Because your content is end-to-end encrypted, what they hold is ciphertext.
No Sale or Sharing of Personal Data
We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. We have never done either.
Data Retention
Account data is kept while your account exists. Messages and catalog content remain until you or another participant deletes them, or until the account is deleted. Support requests are kept as a record of the issue and are disassociated from your account if you delete it. Routine backups held by our hosting provider may contain residual copies for a limited period after deletion.
Deleting Your Account
You can delete your account at any time from the Account tab, without contacting us. Deletion removes your profile, the catalogs you own together with their products and media, your catalog memberships, your direct conversations and messages, your group memberships, your stored push notification tokens and your encryption keys held on our servers. Deletion is permanent and cannot be undone. Abuse reports are the one exception: reports filed about you, and reports you filed about someone else, are both kept after your account is deleted, with your account link removed from them, so that deleting an account cannot erase a record needed to protect other people. See Retention of Abuse Reports below. Messages you sent into a group chat may remain visible to the other members of that group.
Retention of Abuse Reports
When someone reports an account or a message, we keep that report even if either account involved is later deleted — the reported account or the account that filed it. Deleting an account removes the profile behind it and severs that account's link to the report, but the report itself — the date, the reason chosen and the identifiers of the reported message and where it was — is retained. Without this, deleting an account would erase the evidence of abuse against other people — including the case where someone who was harassed closes their account and would otherwise take the record of that harassment with them. Alongside the report we keep a separate, restricted identifier derived from the reported account's email address using a secret key we hold. It lets us recognise a returning account that was previously reported. We keep no such identifier for the person who filed a report — once their account is gone, nothing links the report back to them. This identifier is pseudonymous, not anonymous: it can be linked back to a person, so it remains personal data and your rights below apply to it. Reports are kept for a limited period that depends on the outcome: about three years for reports we substantiate, together with the record of what we did about them, and about ninety days for reports we dismiss or never substantiate. The restricted identifier is kept for up to three years as well, and is deleted sooner when no remaining report needs it — so the identifier tied to a report we dismiss goes at ninety days along with that report. Deletion runs automatically on a daily schedule. Access is restricted to the people who handle moderation. You can ask us to erase or object to this retention using the contact details below, and we will review each request individually and weigh it against our need to protect other users.
Your Privacy Rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. California residents may request the categories of personal information collected and request deletion. Most of this you can do directly in the app; otherwise contact privacy@onlymenu.io. We will not treat you differently for exercising these rights.
Children's Privacy
OnlyMenu IO is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have done so, we will delete it. If you believe a child has given us information, contact privacy@onlymenu.io.
International Data Transfers
Our infrastructure runs in the United States. If you use OnlyMenu IO from elsewhere, your information is transferred to and processed there, under appropriate safeguards including standard contractual clauses where they are required.
Security
Content is end-to-end encrypted, private keys stay in device secure storage, and access to data on our servers is constrained by row-level security so an account can reach only the records it is entitled to. No system is perfectly secure and we cannot guarantee absolute security.
Changes to This Policy
We may update this policy. If a change is material we will update the date shown above and, where appropriate, tell you in the app. Continuing to use OnlyMenu IO after a change means you accept the updated policy.
Contact Us
Avante Studio LLC. Privacy questions: privacy@onlymenu.io. Help with the app: support@onlymenu.io.