Yumori Privacy Policy
This Privacy Policy describes how Yumori (the nutrition-tracking app published under the application ID com.yumori.app, "we", "us") collects, uses, and protects your information. Yumori estimates the nutritional content of meals from photos, voice descriptions, text, and barcodes using artificial intelligence, and lets you track meals, water, weight, activity, and fasting.
Contact for all privacy matters: privacy@yumori.app
1. Summary
- Your meal history and personal profile are stored on your device, encrypted. Meal data leaves your device only when you scan a meal or request an insight. Those requests also include your profile context and your app language, as described in Section 3.
- Meal photos, voice recordings, and meal descriptions are sent to our servers only to run the AI analysis and are not stored after the analysis completes.
- Analytics runs only if you consent.
- Ads (Google AdMob) are shown only to free users, and ad personalization in the EEA/UK is governed by the consent choices you make in the Google consent message.
- We never sell your personal data.
2. Data Stored on Your Device
Yumori stores your meal history, your profile and goals, your favorites, your settings, and your fasting and activity records locally on your device using encryption:
- This data is encrypted using AES-256, an industry-standard encryption algorithm.
- The encryption key is generated uniquely for your device on first use and stored in your device's secure keystore (Android Keystore on Android devices, iOS Keychain on iPhones and iPads).
- The encryption key never leaves your device. It does not sync to iCloud, Google Drive, or any other cloud service.
- If your device is lost or stolen, the encrypted data cannot be read without the encryption key, which is bound to your device.
Your weight history, water intake and meal photos are stored in the app's private storage on your device, which other apps cannot access, but without this additional encryption. Section 9 explains how your device's own backup service treats each of these.
Encryption does not protect data you choose to share or export from the app, information visible on your screen while using the app, or screenshots and backups you create manually.
3. Data Sent to Our Servers for AI Analysis
When you scan a meal photo, record a voice note, or type a meal description, that content is sent to our servers for analysis by AI. This data is:
- Transmitted over an encrypted connection (TLS 1.2 or higher).
- Processed by Google Cloud Functions, which forward the data to Google's Gemini AI model for analysis. The Gemini service is operated by Google under its own data handling terms.
- Not stored on our servers after the analysis is complete. The content of your meal scans (images, audio, transcripts, and detected food items) exists only in memory during the AI call and is discarded once the result is returned to your device.
Each scan or voice request also includes your profile context (such as weight, height, activity level and goal, as entered in the app) so results can be personalised, and your app language so results can be returned in that language.
When you scan a product barcode, the barcode number (not an image) is sent to the Open Food Facts database to look up product nutrition information.
In-app feedback. If you send feedback from Settings, we store your message and its category together with your anonymous account identifier, app version and build, platform, device model, operating system version and app language, so we can understand and fix the problem. Feedback is kept until you delete your account, and is deleted with it.
3a. Weekly Health Insights (Optional)
Yumori can generate a short written summary of your logging over the past week. When you request an insight, a summary of your recent entries — dates, meal names, calories, protein, carbohydrates, fat, weight in kilograms, and water intake — is sent to our servers and forwarded to Google's Gemini AI model, which returns two short observations.
- This happens only when you open Deep Insights in the app. Nothing is sent in the background.
- The data is transmitted over an encrypted connection (TLS 1.2 or higher).
- Neither the summary sent nor the insight returned is stored on our servers. We keep only a daily counter of how many insights you have requested, so we can apply usage limits.
- This data is never shared with advertising networks, never used for advertising, and never sold.
4. Account and Usage Data
- Firebase Authentication. By default, Yumori signs you in with an anonymous account identifier so we can apply free-tier usage limits and, if you subscribe, associate your subscription entitlement. You can use the app fully without giving us a name, an email address, or a password.
- Optional sign-in. If you want your identity and Premium access to follow you to another device, you can choose to sign in with Google, with Apple, or with an email address and password. When you do, we receive the email address associated with that method — if you use Sign in with Apple and choose to hide your address, we receive Apple’s private relay address and never see your real one. That email is held in your Firebase Authentication record and is used only to identify your account and restore your Premium entitlement. It is not written into our database, not used for marketing, and never sold. Signing in does not upload your meals. Your meal history, weight, water, activity, and fasting data are stored on your device, and are sent to our servers only for the AI analysis described in Section 3 and the optional insights described in Section 3a. Deleting your account removes the Authentication record, and the email address with it.
- Usage counters. We store a small daily usage counter (for example, how many of your included AI scans you have used) in Google Firestore, associated with your anonymous account ID. This counter contains no meal content — only counts, timestamps, and your account ID.
- Firebase App Check. To protect the analysis service from abuse, the app sends device integrity signals (via Google Play Integrity on Android and Apple device attestation on iOS) to Firebase App Check. These signals verify that requests come from a genuine copy of the app; they are not used for advertising or profiling.
5. Analytics and Crash Diagnostics
Yumori uses Firebase Analytics to understand how the app is used and to improve it. Analytics collection is disabled by default and is enabled only after you give consent in the app. If you decline or withdraw consent, analytics stays off. Ad-related consent-mode signals (ad storage, ad user data, ad personalization) are handled separately by the advertising consent flow described below.
Yumori also uses Firebase Crashlytics to record crashes and unexpected errors so we can fix them. Unlike analytics, crash reporting is active from first launch and is not tied to your consent choice, because it is what lets us diagnose a failure that would otherwise make the app unusable. A crash report contains diagnostic information — the error and its stack trace, your device model and operating system version, and an installation identifier generated by Crashlytics. It does not contain your Yumori account identifier, your meal content, photos, voice recordings, or health data.
6. Advertising (Google AdMob)
Free users of Yumori may be shown ads served by Google AdMob. Subscribers to Yumori Premium do not see ads.
When ads are shown, we share the following with Google, which uses it for its own advertising purposes:
- Your device's advertising identifier (AAID) and App Set ID.
- Your IP address, from which Google derives an approximate location (typically city level). We never collect or share your precise location.
- Ad interactions, such as which ads were shown and whether they were tapped.
Yumori also offers rewarded ads: you can choose to watch a short video ad to unlock additional AI scans. When you do, your anonymous Yumori account identifier is sent to Google so that the reward can be verified and credited to your account. This identifier is not linked to your name or email address.
Your nutrition, meal, weight, and health data are never shared with Google AdMob or any other advertising network, are never used to target or personalise ads, and are never sold.
- EEA, UK, and Switzerland: before any ads are shown, you are presented with a consent message (Google's consent management platform, certified under the IAB Transparency & Consent Framework). You can choose whether to allow personalized ads, limit them, or refuse consent. Your choice controls whether ads are personalized or non-personalized.
- You can review or change your ad-consent choices at any time from Settings → Ad privacy options in the app, where that option is shown.
- You can also reset or limit your device's advertising ID in your device's own settings — on Android under the Ads section, and on iOS under Tracking.
- How Google uses this data is described at policies.google.com/technologies/partner-sites and policies.google.com/privacy.
7. Purchases and Subscriptions (RevenueCat)
Yumori Premium subscriptions are purchased through Google Play or the Apple App Store. We use RevenueCat to validate purchases and manage subscription entitlements. RevenueCat receives your anonymous app user ID, purchase receipt/token data, and subscription status. We never see or store your payment card details — payment is processed entirely by Google Play or the App Store. RevenueCat's privacy policy is available at revenuecat.com/privacy.
8. Health Data (Optional)
If you turn on wearable sync, Yumori reads your step count and active calories burned from Health Connect (Android) or Apple Health / HealthKit (iOS), with your explicit permission.
- Health data is read-only: Yumori never writes to Health Connect or Apple Health.
- Health data is used solely to display your activity and adjust your daily calorie goal on your device. It is not uploaded to our servers, not shared with third parties, and never used for advertising or sold.
- You can revoke access at any time in Health Connect or the Health app, or by turning off the sync toggle in Yumori's settings.
9. Manual Encrypted Backups
Yumori does not automatically back up or sync your data to any server. Your device's own backup service — Google backup on Android, iCloud on iPhone — may include your weight history, water intake and meal photos if you have device backup turned on; those backups are protected by that service's own encryption. The data encrypted as described in Section 2 is deliberately excluded from device backups and does not move to a new phone — that is what the manual backup below is for. To create one, go to Settings → Backup & Restore:
- You choose a backup password. It never leaves your device and is never sent to us — we cannot see it, reset it, or recover a backup for you if you lose the password.
- The backup file is encrypted (AES-256-GCM, with your password stretched through PBKDF2) before it is written to disk.
- You choose where the encrypted file is saved, using your device's standard file picker — for example, local storage, or a cloud storage app you already use. Yumori does not operate or have access to any cloud storage of its own for backups; a provider you save to handles that file under its own terms.
- Once saved, Yumori has no way to see, modify, or delete that file — including after you delete your Yumori account. Account deletion removes your data from our servers and your device, but cannot reach a backup file you have already exported outside the app.
10. Camera, Photos, and Microphone
- Camera / photos: used only when you actively scan a meal or barcode. Meal photos are processed as described in Section 3.
- Microphone: used only when you actively record a voice meal description. Recordings are processed as described in Section 3 and are not retained on our servers.
11. Data Retention and Deletion
- Meal content sent for AI analysis is not retained after the analysis completes (Section 3).
- Daily usage counters in Firestore are keyed by day and anonymous account ID and are retained only for operating the free-tier limits.
- Your local data (meal history, preferences, goals) stays on your device except as described in Sections 3, 3a, and 9; deleting the app removes it.
- You can delete your account and all associated data at any time from Settings → Delete account & data. This removes your server-side records and wipes the data held on your device.
- You can turn off wearable sync at any time from Settings → Health & Activity, and manage advertising consent from Settings → Ad privacy options where that option is shown.
- To exercise any other data right, or to ask for help with a deletion, contact privacy@yumori.app.
12. Your Rights
Depending on where you live (for example, under the EU/UK GDPR or the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time (withdrawal does not affect processing that happened before withdrawal). You also have the right to lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@yumori.app. Because most Yumori data lives only on your device and our server-side data is keyed to an anonymous account ID, we may ask you for information from your app installation to locate the data.
13. Children
Yumori is not intended for use by anyone under 16 years of age, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has provided us personal data, contact us and we will delete it.
14. International Data Transfers
Our service providers (Google, RevenueCat) may process data on servers located outside your country, including in the United States. Where required, these transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
15. Third-Party Service Providers
- Google Firebase / Google Cloud — authentication, App Check, Cloud Functions, Firestore, crash diagnostics (Crashlytics), and (with consent) Analytics.
- Firebase Remote Config (Google) — lets us adjust app settings, such as usage limits, without an app update. The app fetches its configuration from Google's servers; this request includes a Firebase installation identifier and basic app and device information such as app version, platform and language.
- Google Gemini AI — AI analysis of meal photos, voice notes, and text.
- Google AdMob — advertising for free users.
- RevenueCat — subscription validation and entitlement management.
- Open Food Facts — barcode product lookups.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in the app or on this page before they take effect, and the "Last updated" date above will be revised.
17. Contact
Questions about this policy or your data: privacy@yumori.app