Sesame Logo

Sesame

Privacy Policy

Version: 2.0
Last updated: July 1, 2026 - Effective date: July 1, 2026

Your privacy is our secret ingredient.

Let's get straight to the point: at Sesame, we like to keep our sauces well-guarded, and your data even more so. We believe that your cooking habits, your failed soufflé attempts, and your secret family recipes are your business and yours alone. Our servers' mission is to make the application work so your recipes are always at your fingertips, not to sell them to third parties who would try to target you with advertisements for non-stick pans at midnight.

In short, no indigestible cookies here, just the right amount of technology to simplify your life, all while protecting your apron.

1. PREAMBLE AND TRUST COMMITMENT

The protection of your privacy and the security of your data are absolute priorities for MidBox Technologies Inc. ("MidBox", "we", "us", "our", the "Company"). In connection with the operation of the Sesame mobile application ("the Application"), we are committed to managing your personal information with the utmost transparency and in compliance with the strictest legislative standards.

This Privacy Policy comprehensively describes how we collect, use, store, and share your information. It has been specifically drafted to comply with the requirements of:

By installing and using the Sesame Application, you acknowledge that you have read and accepted the practices described in this document.

2. PERSON IN CHARGE OF THE PROTECTION OF PERSONAL INFORMATION

In accordance with Law 25, we have designated a Person in Charge of the Protection of Personal Information (Privacy Officer / Data Protection Officer) within our organization. This person is responsible for ensuring compliance with the legislation and handling your requests.

For any questions regarding this policy, to exercise your rights, or to file a complaint, you may contact:

Privacy Officer:
Title: Director of Data Compliance
Email Address: privacy@midboxtech.com
Mailing Address: 6300 avenue Auteuil, Suite 505-147, Brossard (Quebec) J4Z 3P2

3. COLLECTED DATA AND COLLECTION METHODS

We apply the principle of data minimization, collecting only what is strictly necessary for the proper functioning of the Application and the improvement of our services.

3.1 Data you provide directly to us

This data is collected when you create an account or interact with the Application.

3.2 Data collected automatically

This data is collected via cookies, pixels, and SDKs (software development kits) integrated into the Application.

3.3 Data imported via third-party links

When you use the Application to import a recipe from an external hyperlink, we use an automated tool to extract and format the text at your request. This extracted information is processed and stored solely for the purpose of being added to your private recipe book.

3.4 Use of sensors and local device processing

4. ARTIFICIAL INTELLIGENCE AND TRANSPARENCY (LAW 25 / GOOGLE VERTEX AI)

The Sesame Application integrates advanced generative artificial intelligence features to help you structure your recipes, generate images, or suggest ingredients. These services are provided by Google Cloud Vertex AI (Gemini models).

4.1 Transparency, Consent, and Culinary Assistant (AI)

In accordance with Law 25 (Quebec) and transparency principles:

4.2 Protection of your data in AI ("No Training" guarantee)

We understand your concerns regarding the use of your data to train public AI models.

4.3 Algorithmic recommendations and automated processing

Recipe suggestions provided by the Application (for example, recommending a recipe from your own catalog that you have not cooked recently) are based on the analysis of your usage history. In accordance with Law 25, we inform you that these automated suggestions are intended solely to facilitate the management of your culinary notebook. They do not constitute profiling for advertising purposes and do not lead to any automated decision producing legal effects or significantly affecting you. You remain the sole decision-maker regarding whether to follow or ignore these recommendations.

5. SHARING AND INTERNATIONAL DATA TRANSFERS

We never sell, rent, or market your personal data to third parties for advertising purposes. We share your data only with technical processors necessary to provide the service.

5.1 Our certified processors

To ensure the operation of Sesame, we use the services of third-party providers located in the United States.

Partner Service Provided Location Compliance Mechanism (Law 25 / GDPR)
Google Cloud Platform Hosting, Database (Firestore), AI (Vertex), Authentication United States Data Privacy Framework and international security agreements.
Apify Technologies Indexing of recipes from public sources European Union (Czech Republic) / United States Built-in GDPR compliance (EU-based provider) and Standard Contractual Clauses (SCC) for transfers outside the EU.
RevenueCat Management of subscriptions and purchase receipts United States Data Privacy Framework & Data Processing Agreement (DPA)

5.2 Legal framework for transfers (Data Privacy Framework)

Your data is transferred to and processed on servers located in the United States.

6. YOUR RIGHTS AND CONTROL OVER YOUR DATA

You have extensive rights regarding your data, which we commit to respecting regardless of your place of residence.

6.1 List of your rights

6.2 Right to Data Portability (New—Law 25 & GDPR)

Since September 2024, Law 25 (just like the GDPR) grants you the right to data portability. This means that you can request to receive the computerized personal information you have provided to us in a structured, commonly used technological format (such as JSON or CSV).

6.3 Right to erasure (Right to be forgotten) and revocation

Upon permanent account deletion, all of your data (profile, nutritional history, local and cloud biometric data, media files in Storage, and RevenueCat billing profile) are permanently and irreversibly erased from our servers within 30 days. To satisfy our regulatory obligations to retain proof of consent (required by Law 25 and the GDPR), your history of legal notice acceptance is archived anonymously. This archiving uses a one-way cryptographic hash (SHA-256) of your email address, ensuring that no personally identifying data or data allowing you to be identified directly or indirectly is retained in our compliance records.

"Sign in with Apple" Users: In accordance with App Store guidelines, deleting your account from within the Application will also trigger a call to the Apple API (Sign in with Apple REST API) in order to immediately and permanently revoke the user token associated with your Sesame account. We thus sever any technical link between your Apple ID and our system.

In the event of a technical failure during the automatic revocation of the token by our servers, the Application will inform you and invite you to manually disconnect this link.

For any other request (portability, complex access, or if you no longer have access to the Application), contact us at privacy@midboxtech.com.

7. SECURITY AND DATA RETENTION

7.1 Security

Although no computer system can guarantee absolute security, we implement reasonable technical and organizational measures, adapted to the nature of the data processed, to protect your information. This includes using recognized cloud infrastructure providers (Google Cloud) that ensure the encryption of your data in transit (TLS) and at rest. We limit access to our databases to only those technical necessities related to the maintenance and improvement of the service.

Exclusively Local Biometric Storage and Obfuscation Measures: Your biometric data (such as weight, height, age, gender, and body fat percentage) is recorded exclusively locally on your mobile device and is never transmitted, synchronized, or stored on Sesame's Cloud servers. We apply local technical obfuscation measures (XOR encoding) to prevent direct plain-text access to these files by third parties. These technical measures constitute local protection and not strong cryptographic encryption. We recommend securing physical and logical access to your mobile device (lock code, biometrics) to preserve the confidentiality of this information.

7.2 Retention

We only retain your data for as long as necessary for the purposes for which it was collected.

8. PROTECTION OF CHILDREN AND MINORS (LAW 25 / COPPA / GDPR)

8.1 Age gate and automatic blocking for nutritional calculations : For reasons of protecting the physical and mental health of minors, access to personalized nutritional calculation, caloric estimation, and biometric tracking features is strictly limited to individuals aged 18 or older.

8.2 General access for minors and eligibility thresholds : General use of the Application and account creation are strictly prohibited for individuals under 14 years of age (in Canada and Quebec), under 13 years of age (in the United States) and, more generally, any minor who has not reached the digital age of majority required to personally consent to the processing of their data in their country of residence (according to GDPR thresholds in Europe, varying from 13 to 16 years of age). Minors aged 14 (or having reached the legal threshold of their country) to 17 inclusive may use the Application for its general and collaborative features (such as organizing family recipes, cooking mode, or grocery lists). The personalized nutritional calculation module is strictly closed to them.

8.3 Absence of health data storage for minors : Since access to the nutritional calculation module is blocked for all individuals under 18, Sesame does not collect, process, or store any biometric data or meal logs for minors, whether locally or on the cloud servers of our hosting provider.

8.4 Corrective Measure : If we learn or have reason to believe that an account has been created by a minor in violation of these age limits, we will immediately delete that account and all associated data from our active databases and local storage systems. If you suspect that a minor is using the restricted features or has created an account in violation of these rules, please contact us at privacy@midboxtech.com.

9. CHANGES TO THE POLICY

We may update this policy to reflect technological, legal, or commercial developments. In the event of a material change (for example, a change in the purposes of using AI or the addition of a new major processor), we will inform you via a visible notification in the Application or by email, at least 15 days before the new terms come into effect. Continued use of the Application after this period will constitute acceptance.

10. MEDICAL LIABILITY LIMITATION CLAUSE:

The Sesame Application is a culinary and general wellness tool, designed to help you store, organize, and analyze cooking recipes. It under no circumstances constitutes a medical device and must not be used to diagnose, treat, cure, or prevent medical conditions or diseases (such as diabetes or clinical obesity). The information displayed in the Application does not constitute professional health advice. Furthermore, Sesame does not manage or support the tracking of food allergies, severe intolerances, or medically prescribed dietary restrictions. It is your sole responsibility to validate the safety and harmlessness of the ingredients consumed. Use of the data provided by Sesame is at your own risk.