Yummerz — Privacy Policy
Yummerz (“the app,” “we,” “us,” “our”) is a small, private meal-sharing app. This policy explains what personal information we collect, why, who can see it, how long we keep it, and the rights you have over it. It's written to be read. The design principle behind all of it: collect only what the app needs, show it only to people you chose, and delete it when you leave.
1. Who we are
Yummerz is operated by Joshua Yeung, the app's builder.
Contact for anything in this policy: help@yummerz.app
2. What we collect and why
2.1 Account identity
| Data | Why | Linked to you |
|---|---|---|
| Apple-issued opaque user ID | Authentication (Sign in with Apple) | Yes |
| Email or Apple private-relay address (if Apple provides one) | Account recovery, moderation notices | Yes |
Display name and @handle | How friends see you in the app | Yes |
| Profile photo (optional) | Avatar in feeds and comments | Yes |
| Date of birth (asked once, at signup) | Age check only — under-13 signups are rejected with nothing stored; 13–17 accounts get minor protections. Never shown to other users, never shared. | Yes (visible to you and us only) |
2.2 Content you create
| Data | Why | Linked to you |
|---|---|---|
| Meal photos, captions, meal type | The product | Yes |
| Place name / rating (optional) | Remembering where you ate | Yes |
| City-level location label (opt-in, per post) | Context on a meal | Yes |
| Reactions and comments | Talking about each other's meals | Yes |
| Reminder settings, rest days, streak state | Reminder timing and your diary streak | Yes |
| Nutrition entries and calorie estimates (opt-in) | The optional curiosity layer | Yes |
We never store GPS coordinates or photo EXIF metadata. EXIF (including embedded GPS) is stripped on your device before upload. If you add a location chip, iOS resolves it to a coarse text label (“Collegetown, Ithaca”) and only that string is stored.
2.3 Collected automatically
| Data | Why | Linked to you |
|---|---|---|
| Push notification token | Delivering the notifications you enabled | Yes |
| App activity events (screens viewed, features used) | Fixing bugs, understanding what's worth building — via our own first-party analytics stored in our own database. No third-party analytics SDK, no ad SDK, no cross-app tracking. | Yes |
| Crash reports (via Apple, only if you opted in to share with developers) | Fixing crashes | No |
2.4 Trust & safety records
| Data | Why | Linked to you |
|---|---|---|
| Reports you submit | Moderation and legal compliance | Yes (never revealed to the person reported) |
| Your block and mute lists | Enforcing blocks in feeds and notifications | Yes (visible to you and us only) |
| Moderation actions on your content | Accountability; you're notified of actions against you | Yes |
| Terms-acceptance record (version + timestamp) | Legal compliance | Yes |
3. What we do NOT collect
- Precise GPS location or location history
- Your contacts or address book
- Photo EXIF metadata (stripped on-device before upload)
- Body measurements, weight, or any health metrics
- Anything from other apps or websites (no tracking, no ATT prompt — we never ask because we never track)
- Advertising identifiers (there are no ads)
4. Calorie estimates and automated analysis
If — and only if — you turn on calorie estimates (Settings → calories), your meal photo is sent to an automated image-analysis service to produce a rough calorie and macro estimate.
- Off by default. You opt in per account, and “off” removes the feature entirely.
- Estimates are labelled as rough (“~520 kcal, rough guess”) and are never used to score, rank, or make any decision about you or your account.
- Nutrition data is used for exactly one thing: showing you (and, only if you pick “share with friends,” your friends) the curiosity layer.
Automated tools may also help screen reported content for the safety rules in our terms; any moderation decision is reviewed by a human.
5. Who we share data with
We do not sell your personal data. Ever. We don't share it with data brokers or advertisers, and we run no ads. The only third parties that touch your data are the infrastructure providers the app runs on:
| Recipient | What | Why |
|---|---|---|
| Supabase (managed database + storage) | Stored app data | Hosting our backend |
| Apple (Sign in with Apple, APNs) | Auth identifiers; push tokens and notification payloads | Sign-in and notifications |
| Our image-analysis provider | Meal photos, only while calorie estimates are turned on | Producing the estimate |
Each provider processes data only to provide the service to us, under terms that prohibit using it for their own purposes. If a law or valid legal process compels disclosure, we comply only as narrowly as required and, where lawful, tell you.
6. Who sees what inside the app
You pick the audience of every meal you post:
- community — the friends in your circle
- one friend — just that person
- just me — only you
Your display name, handle, and avatar are visible to your friend circle. Your date of birth is visible to no one. Blocked users can't see your content and you can't see theirs — enforced on the server, not just hidden in the app.
7. If you're 13–17
Yummerz doesn't allow anyone under 13. If a signup declares an age under 13, we reject it immediately and store nothing from that session.
Accounts aged 13–17 are flagged as minor accounts, which means:
- private-by-default visibility that the standard flow can't widen;
- no advertising use of your data (true for everyone, but we bind ourselves to it specifically for minors);
- automatic cleanup: if a minor account is inactive for 24 months, we delete its data rather than keep it around;
- data about you is retained only per the schedule in §8 — we don't keep minors' data indefinitely.
Parents/guardians can contact help@yummerz.app about a minor's account, including to request its deletion.
8. How long we keep things (retention schedule)
| Data | Kept for |
|---|---|
| Meal posts, photos, captions | While your account is active. Posts you delete are removed from feeds immediately and permanently erased within 30 days. |
| Comments and reactions | Same as the meal they're attached to |
| Profile (name, handle, avatar, date of birth) | While your account is active; permanently erased within 30 days of account deletion |
| Nutrition entries and estimates | While your account is active; erased with the account. Turning estimates off stops new processing. |
| Push notification tokens | Deleted at sign-out or account deletion |
| App activity events (first-party analytics) | 12 months rolling, then deleted; erased earlier with the account |
| Crash logs (Apple-managed, not linked to identity) | ~90 days per Apple's retention |
| Reports you submitted or that concern your content, and moderation records | 3 years — safety accountability and legal compliance |
| Terms-acceptance records | Life of the account + 3 years |
| Inactive minor-account data | Deleted after 24 months of inactivity |
When you delete your account, everything in the “while your account is active” rows above — including your photos in storage, your birthdate, your activity events, and your sign-in record — is permanently erased within 30 days. The only survivors are the safety and acceptance records listed above, kept because the law and basic accountability require them, and they're disclosed here so it's never a surprise.
9. Your rights
Everyone
- See your data: your posts, profile, nutrition entries, and settings are all visible in the app.
- Fix your data: edit your display name, handle, avatar, windows, and visibility choices any time.
- Delete your account: Settings → account → delete account. No email, no phone call, no retention offer. Effects are described in §8.
- Export your data: email help@yummerz.app from the address on your account (or include your @handle) and ask for an export. We verify the request against your account, then deliver a machine-readable copy of your posts, profile, and nutrition entries within 30 days.
- Control notifications and estimates: every notification type and the entire calorie layer can be switched off in Settings.
California residents
You have the rights in the CCPA/CPRA: to know, correct, and delete, and to opt out of sale or sharing — we don't sell or share personal data as those terms are defined, so there's nothing to opt out of. We honor requests via help@yummerz.app and don't discriminate against you for making them.
If you're in the EU/EEA or UK
Yummerz currently launches in the United States. If you nonetheless use the app from the EU/EEA/UK, GDPR/UK-GDPR rights apply: access, rectification, erasure, restriction, objection, and portability (Article 20 — the export process above). Our legal bases are performance of a contract (running the app you signed up for) for core data, consent for the opt-in layers (calorie estimates, location labels, optional notifications), and legitimate interests for safety and abuse prevention. You can lodge a complaint with your local supervisory authority. We answer verified requests within 30 days.
Consumer health data (Washington, Connecticut, Nevada)
Nutrition data may qualify as consumer health data under state laws like Washington's My Health My Data Act. We collect it only with your opt-in consent, use it only for the feature you turned on, never sell it, and you can withdraw consent (Settings → calories → off) or delete it (delete the entries or your account) at any time.
10. Security
Data lives in a managed Postgres database with row-level security enforced at the database layer — visibility rules are checked on the server for every query, not just in the app. Photos are in private storage buckets; every file access is authenticated and authorized. All connections use TLS. Moderation actions are recorded in an append-only audit log.
No system is perfectly secure. If you find a vulnerability, please email help@yummerz.app with “security” in the subject — we read those first and won't take action against good-faith research.
11. Apple privacy nutrition label
What we declare in the App Store privacy label, for transparency:
| Category | Type | Linked to you |
|---|---|---|
| Photos (meal photos) | User Content | Yes |
| User ID (account ID, handle) | Identifiers | Yes |
| Device ID (push token) | Identifiers | Yes |
| Product interaction | Usage Data | Yes |
| Health & Fitness (calorie/macro data — only if you opt in) | Health & Fitness | Yes |
| Coarse location (city label — only if you opt in, per post) | Location | Yes |
| Crash data | Diagnostics | No |
No data is used for tracking. No data is linked to third-party data for advertising. The app never shows Apple's App Tracking Transparency prompt because it never tracks.
12. Changes to this policy
When this policy changes materially, we update the date at the top, tell you in the app before the change takes effect, and — for changes that expand what we collect or share — ask for fresh consent rather than assuming it.
13. Contact
Privacy questions, export or deletion requests, parent/guardian inquiries, security reports:
Email: help@yummerz.app
In-app: Settings → legal → contact us
We answer verified data-rights requests within 30 days, and usually much faster.