Sesame Logo

Sesame

Privacy Policy

Version: 1.0
Last updated: June 26, 2026 - Effective date: June 26, 2026

Welcome! We have no intention of putting you to sleep with a deluge of legal jargon or dry disclaimers... However, since your curiosity has driven you to open this document, you asked for it! Make yourself comfortable: here are the inner workings of our privacy policy, dissected with all the rigor and precision you deserve.

1. PREAMBLE AND TRUST COMMITMENT

The protection of your privacy and the security of your data are absolute priorities for MidBox Technologies Inc. ("MidBox", "we", "us", "our", the "Company"). In connection with the operation of the Sesame mobile application ("the Application"), we are committed to managing your personal information with the utmost transparency and in compliance with the strictest legislative standards.

This Privacy Policy comprehensively describes how we collect, use, store, and share your information. It has been specifically drafted to comply with the requirements of:

By installing and using the Sesame Application, you acknowledge that you have read and accepted the practices described in this document.

2. PERSON IN CHARGE OF THE PROTECTION OF PERSONAL INFORMATION

In accordance with Law 25, we have designated a Person in Charge of the Protection of Personal Information (Privacy Officer / Data Protection Officer) within our organization. This person is responsible for ensuring compliance with the legislation and handling your requests.

For any questions regarding this policy, to exercise your rights, or to file a complaint, you may contact:

Privacy Officer:
Title: Director of Data Compliance
Email Address: privacy@midboxtech.com
Mailing Address: 6300 avenue Auteuil, Suite 505-147, Brossard (Quebec) J4Z 3P2

3. COLLECTED DATA AND COLLECTION METHODS

We apply the principle of data minimization, collecting only what is strictly necessary for the proper functioning of the Application and the improvement of our services.

3.1 Data you provide directly to us

This data is collected when you create an account or interact with the Application.

3.2 Data collected automatically

This data is collected via cookies, pixels, and SDKs (software development kits) integrated into the Application.

3.3 Data imported via third-party links

When you use the Application to import a recipe from an external hyperlink, we use an automated tool to extract and format the text at your request. This extracted information is processed and stored solely for the purpose of being added to your private recipe book.

3.4 Use of sensors and local device processing

4. ARTIFICIAL INTELLIGENCE AND TRANSPARENCY (LAW 25 / GOOGLE VERTEX AI)

The Sesame Application integrates advanced generative artificial intelligence features to help you structure your recipes, generate images, or suggest ingredients. These services are provided by Google Cloud Vertex AI (Gemini models).

4.1 Transparency, Consent, and Culinary Assistant (AI)

In accordance with Law 25 (Quebec) and transparency principles:

4.2 Protection of your data in AI ("No Training" guarantee)

We understand your concerns regarding the use of your data to train public AI models.

4.3 Algorithmic recommendations and automated processing

Recipe suggestions provided by the Application (for example, recommending a recipe from your own catalog that you have not cooked recently) are based on the analysis of your usage history. In accordance with Law 25, we inform you that these automated suggestions are intended solely to facilitate the management of your culinary notebook. They do not constitute profiling for advertising purposes and do not lead to any automated decision producing legal effects or significantly affecting you. You remain the sole decision-maker regarding whether to follow or ignore these recommendations.

5. SHARING AND INTERNATIONAL DATA TRANSFERS

We never sell, rent, or market your personal data to third parties for advertising purposes. We share your data only with technical processors necessary to provide the service.

5.1 Our certified processors

To ensure the operation of Sesame, we use the services of third-party providers located in the United States.

Partner Service Provided Location Compliance Mechanism (Law 25 / GDPR)
Google Cloud Platform Hosting, Database (Firestore), AI (Vertex), Authentication United States Data Privacy Framework and international security agreements.
Apify Technologies Indexing of recipes from public sources European Union (Czech Republic) / United States Built-in GDPR compliance (EU-based provider) and Standard Contractual Clauses (SCC) for transfers outside the EU.
RevenueCat Management of subscriptions and purchase receipts United States Data Privacy Framework & Data Processing Agreement (DPA)

5.2 Legal framework for transfers (Data Privacy Framework)

Your data is transferred to and processed on servers located in the United States.

6. YOUR RIGHTS AND CONTROL OVER YOUR DATA

You have extensive rights regarding your data, which we commit to respecting regardless of your place of residence.

6.1 List of your rights

6.2 Right to Data Portability (New—Law 25 & GDPR)

Since September 2024, Law 25 (just like the GDPR) grants you the right to data portability. This means that you can request to receive the computerized personal information you have provided to us in a structured, commonly used technological format (such as JSON or CSV).

6.3 Right to erasure (Right to be forgotten) and revocation

Upon permanent account deletion, all of your data (profile, nutritional history, local and cloud biometric data, media files in Storage, and RevenueCat billing profile) are permanently and irreversibly erased from our servers within 30 days. To satisfy our regulatory obligations to retain proof of consent (required by Law 25 and the GDPR), your history of legal notice acceptance is archived anonymously. This archiving uses a one-way cryptographic hash (SHA-256) of your email address, ensuring that no personally identifying data or data allowing you to be identified directly or indirectly is retained in our compliance records.

"Sign in with Apple" Users: In accordance with App Store guidelines, deleting your account from within the Application will also trigger a call to the Apple API (Sign in with Apple REST API) in order to immediately and permanently revoke the user token associated with your Sesame account. We thus sever any technical link between your Apple ID and our system.

In the event of a technical failure during the automatic revocation of the token by our servers, the Application will inform you and invite you to manually disconnect this link.

For any other request (portability, complex access, or if you no longer have access to the Application), contact us at privacy@midboxtech.com.

7. SECURITY AND DATA RETENTION

7.1 Security

Although no computer system can guarantee absolute security, we implement reasonable technical and organizational measures, adapted to the nature of the data processed, to protect your information. This includes using recognized cloud infrastructure providers (Google Cloud) that ensure the encryption of your data in transit (TLS) and at rest. We limit access to our databases to only those technical necessities related to the maintenance and improvement of the service.

Exclusively Local Biometric Storage and Obfuscation Measures: Your biometric data (such as weight, height, age, gender, and body fat percentage) is recorded exclusively locally on your mobile device and is never transmitted, synchronized, or stored on Sesame's Cloud servers. We apply local technical obfuscation measures (XOR encoding) to prevent direct plain-text access to these files by third parties. These technical measures constitute local protection and not strong cryptographic encryption. We recommend securing physical and logical access to your mobile device (lock code, biometrics) to preserve the confidentiality of this information.

7.2 Retention

We only retain your data for as long as necessary for the purposes for which it was collected.

8. PROTECTION OF CHILDREN AND MINORS (LAW 25 / COPPA / GDPR)

8.1 Age gate and automatic blocking for nutritional calculations: By default, access to personalized nutritional calculation and biometric tracking features is strictly prohibited for individuals under 14 years of age to comply with Law 25 (Quebec) and the GDPR. When creating a profile or accessing these services, the Application queries the device's native age verification system (API DeclaredAgeRange under iOS 26.0+ or Android equivalent) or presents an age self-declaration questionnaire. If the user is identified as being under 14 years of age, access to these personalized features is automatically blocked, except in the case of express parental consent (see section 8.4).

8.2 Processing of data from adolescents (ages 14 to 17 inclusive)—Young Audience Mode: If a user is identified as a minor aged 14 to 17 inclusive, the Application automatically switches to "Young Audience Mode". In this mode, in order to prevent eating disorders (EDs) and limit focus on caloric intake among adolescents:

8.3 Transitional data migration upon change in age status: In the event of a change in the user's age status (for example, reaching the age of majority at 18 or a corrective modification of the profile):

8.4 Parental consent for minors under 14 years of age within the Household: Activating personalized nutritional tracking for a household member under 14 years of age requires the explicit authorization of the household owner (parent or legal guardian). The latter can grant this authorization via the parental consent modal integrated into the Application. By this action, the legal guardian formally consents to the local processing of their nutritional and biometric data, as well as the cloud storage of basic profile data (identifier, email address, household link) essential for linking and managing the Household, under their exclusive responsibility and in derogation of the strict blocking by default.

8.5 Specific provisions for the protection of children and minors (Law 25 / COPPA / GDPR)

9. CHANGES TO THE POLICY

We may update this policy to reflect technological, legal, or commercial developments. In the event of a material change (for example, a change in the purposes of using AI or the addition of a new major processor), we will inform you via a visible notification in the Application or by email, at least 15 days before the new terms come into effect. Continued use of the Application after this period will constitute acceptance.

10. MEDICAL LIABILITY LIMITATION CLAUSE:

The Sesame Application is a culinary and general wellness tool, designed to help you store, organize, and analyze cooking recipes. It under no circumstances constitutes a medical device and must not be used to diagnose, treat, cure, or prevent medical conditions or diseases (such as diabetes or clinical obesity). The information displayed in the Application does not constitute professional health advice. Furthermore, Sesame does not manage or support the tracking of food allergies, severe intolerances, or medically prescribed dietary restrictions. It is your sole responsibility to validate the safety and harmlessness of the ingredients consumed. Use of the data provided by Sesame is at your own risk.