Yumori Privacy Policy
This Privacy Policy describes how Yumori (the nutrition-tracking
app published under the application ID com.yumori.app, "we", "us")
collects, uses, and protects your information. Yumori estimates the nutritional
content of meals from photos, voice descriptions, text, and barcodes using
artificial intelligence, and lets you track meals, water, weight, activity, and
fasting.
Contact for all privacy matters: yumori.dev@gmail.com
1. Summary
- Your meal history and personal profile are stored on your device, encrypted.
- Meal photos, voice recordings, and meal descriptions are sent to our servers only to run the AI analysis and are not stored after the analysis completes.
- Analytics runs only if you consent.
- Ads (Google AdMob) are shown only to free users, and ad personalization in the EEA/UK is governed by the consent choices you make in the Google consent message.
- We never sell your personal data.
2. Data Stored on Your Device
Yumori stores your meal history, dietary preferences, body goals, and other personal information locally on your device using encryption:
- Sensitive data stored locally is encrypted using AES-256, an industry-standard encryption algorithm.
- The encryption key is generated uniquely for your device on first use and stored in your device's secure keystore (Android Keystore on Android devices, iOS Keychain on iPhones and iPads).
- The encryption key never leaves your device. It does not sync to iCloud, Google Drive, or any other cloud service.
- If your device is lost or stolen, your stored Yumori data cannot be read without the encryption key, which is bound to your device.
Encryption does not protect data you choose to share or export from the app, information visible on your screen while using the app, or screenshots and backups you create manually.
3. Data Sent to Our Servers for AI Analysis
When you scan a meal photo, record a voice note, or type a meal description, that content is sent to our servers for analysis by AI. This data is:
- Transmitted over an encrypted connection (TLS 1.2 or higher).
- Processed by Google Cloud Functions, which forward the data to Google's Gemini AI model for analysis. The Gemini service is operated by Google under its own data handling terms.
- Not stored on our servers after the analysis is complete. The content of your meal scans (images, audio, transcripts, and detected food items) exists only in memory during the AI call and is discarded once the result is returned to your device.
When you scan a product barcode, the barcode number (not an image) is sent to the Open Food Facts database to look up product nutrition information.
4. Account and Usage Data
- Firebase Authentication. Yumori signs you in with an anonymous account identifier so we can apply free-tier usage limits and, if you subscribe, associate your subscription entitlement. No name, email address, or password is required to use the app.
- Usage counters. We store a small daily usage counter (for example, "used 3 of your free scans today") in Google Firestore, associated with your anonymous account ID. This counter contains no meal content — only counts, timestamps, and your account ID.
- Firebase App Check. To protect the analysis service from abuse, the app sends device integrity signals (via Google Play Integrity on Android and Apple device attestation on iOS) to Firebase App Check. These signals verify that requests come from a genuine copy of the app; they are not used for advertising or profiling.
5. Analytics (Only With Your Consent)
Yumori uses Firebase Analytics to understand how the app is used and to improve it. Analytics collection is disabled by default and is enabled only after you give consent in the app. If you decline or withdraw consent, analytics stays off. Ad-related consent-mode signals (ad storage, ad user data, ad personalization) are handled separately by the advertising consent flow described below.
6. Advertising (Google AdMob)
Free users of Yumori may be shown ads served by Google AdMob. Subscribers to Yumori Premium do not see ads.
- AdMob may collect and use device information such as your device's advertising identifier, IP address, and coarse ad-interaction data to serve and measure ads. How Google uses this data is described at policies.google.com/technologies/partner-sites and policies.google.com/privacy.
- EEA, UK, and Switzerland: before any ads are shown, you are presented with a consent message (Google's consent management platform, certified under the IAB Transparency & Consent Framework). You can choose whether to allow personalized ads, limit them, or refuse consent. Your choice controls whether ads are personalized or non-personalized.
- You can review or change your ad-consent choices at any time from the app's Settings screen ("Privacy options"), where required.
- You can also reset or limit your device's advertising ID in your device settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking).
7. Purchases and Subscriptions (RevenueCat)
Yumori Premium subscriptions are purchased through Google Play or the Apple App Store. We use RevenueCat to validate purchases and manage subscription entitlements. RevenueCat receives your anonymous app user ID, purchase receipt/token data, and subscription status. We never see or store your payment card details — payment is processed entirely by Google Play or the App Store. RevenueCat's privacy policy is available at revenuecat.com/privacy.
8. Health Data (Optional)
If you turn on wearable sync, Yumori reads your step count and active calories burned from Health Connect (Android) or Apple Health / HealthKit (iOS), with your explicit permission.
- Health data is read-only: Yumori never writes to Health Connect or Apple Health.
- Health data is used solely to display your activity and adjust your daily calorie goal on your device. It is not uploaded to our servers, not shared with third parties, and never used for advertising or sold.
- You can revoke access at any time in Health Connect or the Health app, or by turning off the sync toggle in Yumori's settings.
9. Camera, Photos, and Microphone
- Camera / photos: used only when you actively scan a meal or barcode. Meal photos are processed as described in Section 3.
- Microphone: used only when you actively record a voice meal description. Recordings are processed as described in Section 3 and are not retained on our servers.
10. Data Retention and Deletion
- Meal content sent for AI analysis is not retained after the analysis completes (Section 3).
- Daily usage counters in Firestore are keyed by day and anonymous account ID and are retained only for operating the free-tier limits.
- Your local data (meal history, preferences, goals) stays on your device; deleting the app removes it.
- To request deletion of any server-side data associated with your anonymous account ID, or to exercise any other data right, contact yumori.dev@gmail.com.
11. Your Rights
Depending on where you live (for example, under the EU/UK GDPR or the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent at any time (withdrawal does not affect processing that happened before withdrawal). You also have the right to lodge a complaint with your local data-protection authority.
To exercise any of these rights, email yumori.dev@gmail.com. Because most Yumori data lives only on your device and our server-side data is keyed to an anonymous account ID, we may ask you for information from your app installation to locate the data.
12. Children
Yumori is not intended for use by anyone under 13 years of age, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal data, contact us and we will delete it.
13. International Data Transfers
Our service providers (Google, RevenueCat) may process data on servers located outside your country, including in the United States. Where required, these transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
14. Third-Party Service Providers
- Google Firebase / Google Cloud — authentication, App Check, Cloud Functions, Firestore, and (with consent) Analytics.
- Google Gemini AI — AI analysis of meal photos, voice notes, and text.
- Google AdMob — advertising for free users.
- RevenueCat — subscription validation and entitlement management.
- Open Food Facts — barcode product lookups.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in the app or on this page before they take effect, and the "Last updated" date above will be revised.
16. Contact
Questions about this policy or your data: yumori.dev@gmail.com