Legal · Menyu
Menyu Privacy Policy
This Privacy Policy explains how SolloMi株式会社 ("Sollo," "we," "us," or "our") collects, uses, shares, and protects personal information when you use Menyu, our menu-reading and translation app (the "App"). Menyu is operated by Sollo and is a separate product from the Sollo app and website; this Policy covers Menyu only. For the Sollo app and website, see the Sollo Privacy Policy. This Policy is designed to comply with Japan's Act on the Protection of Personal Information (個人情報の保護に関する法律, the "APPI") and other applicable data protection law. Capitalized terms not defined here have the meaning given in the Menyu Terms of Service.
Sollo is SolloMi株式会社, a company incorporated in Japan on 21 August 2026 (会社法人等番号 0110-01-180064), with its registered office in Shibuya-ku, Tokyo. For the purposes of the APPI, SolloMi株式会社 is the personal information handling business operator (個人情報取扱事業者) responsible for the personal information described in this Policy. Its registered address and representative director are set out in the Contact Us section below and on our Company Information page.
1. Scope of This Policy
This Policy applies to everyone who uses Menyu, wherever they are located. Menyu is built for travelers and residents who need to read a restaurant menu written in a language they do not know. It is used most often away from home.
Menyu does not require an account. When you first open the App it signs in anonymously, which creates an identifier used to keep your own scans separate from everyone else's, and you can use the entire App this way, with no username or password. Everything described below is linked to that anonymous identifier, not to your name, unless you choose to sign in, described next.
If you choose, you can sign in with Apple or Google to create an account. This is optional and never required; declining or skipping it has no effect on what the App does. Signing in shares your email address and, once, your name with us (see Section 2.4).
2. Information We Collect
2.1 Information Created by Using the App
- Menu photos: the photographs you take of menus, or select from your photo library. These are uploaded to our storage and sent to our AI provider so the menu can be read and translated (see Section 5). A menu photo may incidentally capture other things in the frame, such as a table, a hand, or people nearby.
- The menus we produce from them: the dish names, prices, descriptions, translations, detected language, and restaurant name read out of your photo.
- Location, only if you allow it: when you grant location permission, we record the GPS coordinates and accuracy of where a menu was scanned, so we can label the scan with the restaurant and recognize the same menu if you or another user scans it again. Location is optional. Menyu works fully without it, and you can refuse or withdraw the permission at any time in your device settings.
- Venue details you enter or confirm: a restaurant's name, a link you save for it, and which venue you pick when the App offers you a choice of nearby places.
- Allergen and dietary selections: the allergens you ask Menyu to flag and any dietary preferences you set. These are stored on your device. They are sent to our servers only when you use the staff-acknowledgement feature, the screen you show to restaurant staff. That records which allergens were shown, at which venue, and when, so acknowledgements can be counted per restaurant.
- Feedback you give: ratings, tags, and any note you write when you tell us a translation was wrong, along with the scan it refers to. If you leave a note on a thumbs-down rating, that note is included in a daily internal digest posted to a private Discord channel our team uses.
- Feedback you send us: whether you use the feedback form on our website or the feedback screen inside the App, we receive the message you write, any photos you attach, and your email address if you choose to give one. If you report that a menu was wrong, the photographs from that scan are attached to the report as well. To help us troubleshoot reports, we also record some context automatically: your language setting in both cases, plus your browser's user-agent on the website, or the app version, the platform (iOS or Android), the screen you reported from and the scan it refers to, if any, in the App. Photos are stored privately and are not published. Giving an email address is optional; we use it only to reply to you.
2.2 Information Collected Automatically
- Device and app information: device model, operating system version, app build number, and network connectivity type.
- Identifiers: a randomly generated device identifier and a session identifier, used to group a single visit's events together and to distinguish one installation from another for troubleshooting and abuse prevention. The device identifier is stored in your device's secure keychain, so it survives deleting and reinstalling the App. That is deliberate, so quality problems can be traced across reinstalls. It is not linked to your name, email, or any advertising identifier.
- Usage events: records of actions such as starting a scan, a scan succeeding or failing, opening a menu, and adding a dish to an order, together with timing and quality measurements about how well the read performed.
- Diagnostics for scans that go wrong: when a scan fails or returns a partial result, we keep the raw text recognized on the device, image dimensions, and the failure reason, so the cause can be investigated. We do not keep photographs as part of that diagnostic record.
- Crash reports: the error, a stack trace, the app version, and the platform when the App crashes or hits an unexpected error.
2.3 Health-Related Information (要配慮個人情報)
Allergen selections may constitute "Special Care-Required Information" under Article 2(3) of the APPI, because they can indicate a health condition. We collect them only from your own explicit choice to set them, we keep them on your device by default, and we transmit them only in the narrow circumstance described in Section 2.1. Your allergen and dietary selections are never sent to our AI provider. Allergen matching against a menu happens on your device, after the translation comes back.
2.4 If You Sign In
Signing in with Apple or Google is optional; Menyu works fully as a guest without it, as described in Section 1. If you choose to sign in:
- Email address: the provider shares the email address on your Apple or Google account, or, if you use Apple's "Hide My Email," a private relay address that reaches you without revealing your real one. We store it as part of your account.
- Name: the first time you sign in with a given Apple ID or Google account, that provider also shares the name on it, and we store it as part of your account. Apple shares it only on that first authorization, never again on later sign-ins with the same Apple ID, so if it is not captured then, we have no way to receive it later unless you remove Menyu's access in your Apple or Google account settings and sign in again.
- Linking your existing scans: signing in attaches your account to the anonymous identifier that the App was already using, along with the scans and history already linked to it, so nothing you scanned as a guest is lost. Your identifier itself does not change. If that Apple or Google identity already belongs to a different Menyu account, we tell you how many local menus would stay behind before you confirm switching accounts, so you never lose them silently.
Signing out ends your account session and gives the App a fresh anonymous identifier; it does not delete anything you had while signed in (see Section 11).
3. What We Do Not Collect
Menyu does not collect any of the following:
- Your phone number, date of birth, or a password. We do not ask for your name or email address, with two exceptions: if you choose to sign in with Apple or Google, that provider shares your email address and (once) your name with us (see Section 2.4); and if you give us an email address when sending feedback, which we use solely to reply to you (see Section 2.1).
- Payment information. Menyu is free and has no purchases.
- Your contacts, calendar, microphone audio, or your photo library beyond the specific images you choose to import.
- Advertising identifiers. Menyu carries no advertising, no advertising SDKs, and no cross-app or cross-site tracking. That is why the App never asks for permission to track you.
- Your location in the background. Location is read only while you are actively scanning a menu, and only if you granted permission.
4. How We Use Your Information
- To read, translate, and display the menu you photographed, and to keep your own scan history available to you;
- If you choose to sign in, to identify you as the same person across sessions and keep the scan history you already had as a guest;
- To flag dishes that appear to contain allergens you asked us to watch for, and to produce the note you show to restaurant staff;
- To recognize when a menu you scan has been read before, so a known menu can load faster and more accurately;
- To measure and improve how accurately Menyu reads menus, including reviewing scans that failed or returned poor results (see Section 6);
- To investigate crashes, diagnose faults, and keep the service running;
- To detect and prevent abuse of the service, including automated use that would exhaust our AI provider capacity; and
- To comply with our legal obligations and respond to lawful requests from public authorities.
5. AI Processing of Menu Photos and Feedback
When you scan a menu, the photograph is sent to our own server and then forwarded to a third-party large-language-model ("LLM") API provider, which reads the text in the image and produces the translated menu. We currently use the Alibaba Cloud Model Studio (DashScope) API, running a Qwen model, for this purpose. Your photograph is transmitted to that provider and processed there to produce the result, under that provider's API terms. We may change which provider or model we use as the product develops; if we do, we will update this Policy to name the new provider.
When you scan a menu, alongside the photograph we send only what the model needs to read it well: the language you want the menu translated into, a count of the text lines our on-device text recognizer found, the language the text appears to be in, and the country you are in. Separately, each night we send a batch of recent usage statistics and feedback text to the same AI provider so it can summarize what has changed. Before it is sent, an automated pattern match replaces email addresses, links, ID-like strings and long runs of digits with placeholders, and the batch does not carry your account, your email address, or the scan a note refers to. That matching is automatic, so it catches the common shapes of these things rather than every one — please do not put personal details in a feedback note. We do not send your allergen selections, your GPS coordinates, your device identifier, or your scan history to the AI provider.
Our own servers, which handle the orchestration around the model, are hosted by a cloud infrastructure provider acting as our service provider for hosting and computing (an "entrustment" under Article 27, paragraph 5(i) of the APPI); that provider processes data on our behalf and does not use it for its own purposes. The LLM API provider described above is a separate company that processes your photograph to generate the result.
A menu photo is an ordinary photo, so anything visible in the frame is uploaded along with it. If you would rather not send your surroundings, frame the shot on the menu itself.
6. Improving Menyu's Accuracy
Reading a photographed menu is error-prone, and the main way we make it better is by studying real scans that went wrong. We therefore retain menu photographs and the results produced from them, and we review them, including by hand, to find misread prices, missed dishes, and incorrect translations, and to check whether a change to the App or to the model actually helped.
We use this material to evaluate and improve Menyu itself. We do not sell it, and we do not supply it to third parties to train their own models. It is sent to our AI provider only in the ordinary course of producing your result, as described in Section 5.
8. How We Share Your Information
We do not sell your personal information. We share it only as described below.
- Service providers (entrustees): our cloud hosting, database and storage providers, and the LLM API provider described in Section 5, each bound by contractual confidentiality and security obligations or by the provider's API terms, consistent with the APPI.
- Place lookup: when you allow location, approximate coordinates are used to look up nearby restaurants through a third-party mapping provider so the App can suggest which venue you are at. We do not send your photographs or your allergen selections to that provider.
- Discord (feedback): if you send us feedback, or leave a note on a thumbs-down rating, the message and any photos are posted to a private channel in Discord, which our team uses to read and act on reports. If you report that a menu was wrong, the photographs from that scan are posted there too. Discord is operated by Discord Inc. in the United States. Your email address is never posted there — it stays in our database.
- Cloudflare (anti-spam): if you use the feedback form, its anti-spam check sends your IP address, browser user-agent, and other device signals to Cloudflare so it can confirm you are not a bot before we save your report. Cloudflare is operated by Cloudflare, Inc. in the United States. Your message and photos are never sent to Cloudflare.
- Other users: only through a share link you create yourself, as described in Section 7.
- Legal and safety purposes: to comply with applicable law, respond to valid legal process, or protect the rights, safety, or property of Sollo, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of your information consistent with this Policy.
9. Cross-Border Data Transfers
Our hosting, storage and AI infrastructure run on servers located outside Japan, menu photographs are transmitted outside Japan to be read, feedback text — including a note left on a thumbs-down rating — is transmitted outside Japan for nightly analysis by the same AI provider (Section 5), feedback you send us or a note on a thumbs-down rating — including any photos — is transmitted outside Japan to be posted to our team's private Discord channel (Section 8), and the feedback form's anti-spam check transmits your IP address and device signals to Cloudflare outside Japan (Section 8). Where this is the case, we rely on one of the mechanisms recognized under Article 28 of the APPI: your consent, given after we disclose the destination country and the protections in place; confirmation that the recipient maintains a personal information protection system equivalent to the APPI, which we monitor at least once a year; or transfer to a country or region recognized by Japan's Personal Information Protection Commission as offering an adequate level of protection. You can ask us at any time, using the contact details in Section 16, which countries our current providers operate in and which of these mechanisms applies.
10. Data Retention
We keep different categories of information for different lengths of time. The table below reflects what our systems actually do today. You can end this early for most categories using the in-App delete control described in Section 11. But deleting does not mean the same thing for every category: some are removed outright, and others are kept, permanently disconnected from you, because we use them in aggregate to improve reading accuracy (Section 6). The table notes which applies; Section 11 explains why.
| Category | Retention period |
|---|---|
| Menu photographs | Kept until deleted: either by you, using the in-App control (Section 11), or by asking us; deletion removes the photographs outright. Outside of that, we do not currently delete menu photographs automatically, because they are the material we use to improve reading accuracy (Section 6). We are building automatic deletion on a schedule; once it is in place, this Policy will be updated to state the period. |
| Scanned menus, dishes, prices and translations | Kept until deleted, so that your scan history remains available to you and a previously read menu can be recognized again. If you delete your account or data (Section 11), this category is disconnected from your identifier rather than deleted, so we can keep using it in aggregate to improve reading accuracy. |
| Location recorded with a scan | Kept for as long as we keep the menu it belongs to, on the same disconnect-rather-than-delete basis. |
| Staff-acknowledgement records, including allergens shown | Kept until deleted, either by you (Section 11) or by asking us. Because this reflects a health-related choice, deleting it removes the record outright. |
| Diagnostics for failed or partial scans | The diagnostic record is deleted automatically 90 days after it is created, or sooner and disconnected from your identifier if you delete your account or data (Section 11). No photographs are attached to it. If the scan still produced a menu, that menu's photographs fall under the menu photograph row above. |
| Crash reports | Deleted automatically 90 days after they are recorded, or disconnected from your identifier sooner if you delete your account or data (Section 11). |
| Shared menu links | The link expires 24 hours after creation; the frozen copy is deleted 30 days after that, or immediately if you delete your account or data (Section 11). |
| Table orders (nickname, avatar, allergies, dishes ordered) | Deleted within 24 hours of the table closing (a table closes three hours after it starts, or sooner if the host ends it). The table’s own record is kept for 30 days after that, to measure quality: the number of people and dishes, the restaurant name, the menu that was scanned, and the account that started the table. No guest’s nickname, avatar or allergies remain in it. |
| Usage events and device information | Kept until deleted, and used to measure quality and detect abuse. If you delete your account or data (Section 11), we keep this category but remove the device and session identifiers from it, so it can no longer be linked to you. |
| Feedback messages and photos | Feedback records (including any email address you gave us) are deleted automatically 180 days after they are created, or immediately if you delete your account or data (Section 11). Photos attached to feedback are stored in private storage and, like menu photographs, are not otherwise deleted automatically. |
| Your account (if you signed in): email and name | Kept for as long as you keep the account. Deleting your account (Section 11) deletes it outright, including the email address and name a provider shared with us when you signed in. |
11. Your Rights and Deleting Your Data
Subject to identity verification and any applicable legal exceptions, you have the right to request disclosure of the personal information we hold about you and the purposes for which we use it; to request correction or deletion of it; to request that we stop using or providing it; to be informed of the categories of cross-border recipients and the protections in place; and to complain to us or to Japan's Personal Information Protection Commission (PPC). If you reside outside Japan you may have additional rights under your local law, such as the GDPR if you are in the EEA or UK, which we will honor to the extent they apply to our processing.
You can delete your data directly in the App, whether you signed in or not. Open Settings and tap Account, then Delete account (or Delete my data, if you never signed in). This is permanent and cannot be undone; there is no grace period. It deletes: your scan history, your feedback (including any email address attached to it), your shared-menu links, your allergen-acknowledgement records, every menu and feedback photograph tied to you, and, if you signed in, your account itself, including the email address and name a provider shared with us. It also clears the App's own local copy of your menus, preferences, and history on your device.
Some data survives deletion, but only in a form that no longer identifies you. The dishes, prices, and translations produced from your scans, plus usage and diagnostic records, are permanently disconnected from your identifier rather than deleted outright, because we use this material in aggregate to keep improving how accurately Menyu reads menus (Section 6). Once disconnected this way, it cannot be linked back to you, reattached to a future account, or singled out as belonging to any one person. Under the APPI and the GDPR alike, information that can no longer identify anyone is treated as anonymized rather than personal information, so it falls outside the deletion right described above.
Because Menyu does not require an account, the information we hold about a guest is linked only to the anonymous identifier the App created on that device; deleting the App does not by itself delete that information, and reinstalling the App can reconnect you to the same records. If you would rather not use the in-App control, or want to confirm what we hold before deciding, contact us using the details in Section 16 and we will act on your request, subject to identity verification.
12. Data Security
Information is transmitted over encrypted connections (HTTPS/TLS). Menu photographs are held in private storage that is not publicly accessible, other than the deliberately shared, expiring copies described in Section 7. Database access is restricted per user so that one user's scans cannot be read by another. No system is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your rights or interests, we will notify you and the PPC as required by applicable law.
13. Children's Privacy
Menyu is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have done so, we will delete it. If you are under the age of majority where you live, please use Menyu with the involvement of a parent or guardian.
14. International Users
Menyu is operated from Japan and is designed to be used while traveling. Wherever you use it, your information will be processed in Japan and, as described in Section 9, in other countries where our service providers operate.
15. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we will provide notice through the App or by other reasonable means before the change takes effect.
16. Contact Us
Questions, requests, or complaints about this Policy or our handling of your personal information can be directed to:
SolloMi株式会社
オーベル代官山DE, 3-4-14 Ebisu-minami, Shibuya-ku, Tokyo, Japan
東京都渋谷区恵比寿南三丁目4番14号 オーベル代官山DE
Representative Director
Tan Jet Son(タン・ジェット・ソン)
Company number (会社法人等番号)
0110-01-180064
Data Protection Contact
info@sollo.my
Supervisory Authority
Personal Information Protection Commission (PPC), Japan
ppc.go.jp
If you are not satisfied with our response, you may file a complaint directly with the PPC.