Privacy Policy
Last updated:
Our Privacy Philosophy
We collect only what we need to make your food choices clearer. We do not sell your personal data. We avoid retaining raw data longer than necessary and give you control over your account.
What We Collect
Data falls into a few categories. Some is required for the app to function (account + operational), some improves analysis quality, and some is optional analytics.
- Account: your name, email (if you sign up with email/password) or the identifier from your sign‑in provider (Apple / Google / Facebook), plus a profile picture if you choose to add one.
- Scan activity: barcode, product metadata, timestamp, nutritional profile derived from external sources, and your scan history, favourites and monthly scan counts (used to apply free‑plan limits).
- Ingredient photos: if you photograph an ingredients panel, that image is sent for analysis and then discarded — it is never stored against your account.
- Daily check‑ins: your 1–5 self‑ratings for mood, how you felt physically, and how well you avoided ultra‑processed food, with the date.
- Notifications: a messaging token for each device you sign in on, your reminder preferences, and your device timezone so reminders arrive at the right local time.
- Support & product reports: the message you write, the product details you are reporting, and your name, email and account id so we can reply.
- Device basics: coarse locale + platform (iOS / Android) for formatting and debugging.
- Purchase state: subscription entitlements (non‑sensitive) via RevenueCat.
- Usage analytics: screen views and feature events (e.g. paywall shown, subscription purchased), tied to your account id and to whether you are on a free or paid plan. We do not put your email or name into analytics events.
What We Do NOT Collect
We intentionally avoid collecting data that is not essential to delivering value to you.
- No precise geolocation.
- No contact list, and no access to your photo library beyond the single picture you pick as a profile photo.
- No medical or health records: check‑ins are your own 1–5 ratings, are never diagnostic, and are visible only to you.
- No selling of your personal data to advertisers or data brokers.
How Analysis Works
When you scan a product, we look up structured nutrition data (e.g., Open Food Facts) and may process text through AI models to identify ultra‑processed characteristics. If a product is not in the catalog, the photo you take of its ingredients panel is sent to an AI vision model to read the ingredients and then discarded — only the extracted text and the result are cached, keyed by barcode. Ingredient deep‑dives are cached by ingredient name. We do not send your name, email or account id to model providers.
Daily Check‑ins & Insights
Your check‑ins are private to you. We store them under your account and use them to build your monthly report. To write your insight summary, our server sends only the dates and 1–5 scores for that period to our AI provider — never your name, email or account id — and the result is shown only to you. Check‑ins are never shared, published, or used for advertising.
Notifications & Reminders
If you allow notifications, we store a messaging token for each device you are signed in on so we can send your daily check‑in reminder, your monthly report, and occasional product announcements.
- Reminders are scheduled using your device timezone.
- Turn individual reminders on or off in Profile > Notification Settings, or disable them entirely in your device settings.
- Signing out removes that device's token from your account, so its notifications stop.
Advertising
Free plans show banner ads supplied by Google AdMob on scan results. Subscribers see no ads.
- On iOS we ask for App Tracking Transparency permission. If you decline, or never respond, ads are non‑personalized.
- On Android, ads may be personalized using your Google advertising ID; you can reset it or opt out of personalization in your device's Google settings.
- Ad requests carry a fixed list of food and nutrition keywords. They are not derived from your scans, check‑ins or account.
- We never share your scan history, check‑ins or account details with ad networks.
- The Facebook SDK is included to support Facebook sign‑in and may collect an advertising identifier under Meta's policy.
Sharing & Links
Sharing is always your choice. When you share a scan result we generate an image card and a nomiapp.io product link, both containing product information only — never your name, email, scan history or check‑ins. Opening one of those links on a device with Nomi installed takes you straight to that product in the app.
Security Practices
We use modern TLS for data in transit and provider‑managed encryption at rest (Firebase, Google Cloud). Access to production data is role‑restricted. Secrets are stored server side, never hard‑coded in the app.
- Authentication via Firebase Auth.
- Profile pictures stored in Firebase Cloud Storage under your account id.
- Entitlements & purchases via RevenueCat (tokenized).
- Usage & crash diagnostics via Firebase (aggregated).
Retention
Scan history, favourites and check‑ins are retained so you can revisit results and track trends over time. Deleting your account runs a server‑side deletion that removes your user record and everything under it — scans, favourites, check‑ins, scan counts and notification tokens — along with your profile picture and your sign‑in credentials. Anonymized product analyses cached by barcode are not linked to you and may persist to speed up scans for everyone.
Your Controls
You can request deletion or export of your account‑linked data. Some data may be briefly retained in backups (automatic rotation).
- Delete account: Profile > Edit Profile > Delete Account (irreversible, and removes the data listed above).
- Notifications: Profile > Notification Settings, or your device settings.
- Ad tracking: iOS Settings > Privacy & Security > Tracking; on Android, your device's Google ads settings.
- Export: email us to request a machine‑readable export.
- Revoke sign‑in provider access: manage in Apple / Google / Facebook settings.
Third‑Party Services
We rely on reputable infrastructure and analytics providers. Each acts as a processor of limited scoped data.
- Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Messaging, Crashlytics, Analytics): core backend, notifications + diagnostics.
- Google Cloud (server functions & model proxy).
- Open Food Facts: public nutrition dataset lookups.
- RevenueCat: subscription entitlement management (no raw payment details stored by us).
- Apple / Google / Meta: whichever sign‑in provider you choose.
- Google AdMob: banner ads shown on free plans.
- AI model providers (via secure proxy): ingredient text and label‑image classification, and check‑in insight summaries.
- Email delivery (via Firebase): sends your support messages and product issue reports to our support inbox.
Links to each provider's policy are available upon request at support@nomiapp.io.
Children's Privacy & Safety
We are committed to protecting children's privacy in compliance with COPPA and applicable laws. This app is suitable for all ages with parental supervision.
- No behavioral advertising: Ads shown to children are non‑personalized and contextual only.
- Limited data collection: We collect only essential data needed for app functionality.
- Parental controls: Parents can request deletion of their child's data at any time.
- Safe content: All food analysis is educational and age‑appropriate.
Parents: Contact support@nomiapp.io for data requests or privacy questions about your child's account.
Policy Changes
If we make material changes, we will highlight them in‑app before they take effect. Continuing to use the app after notice constitutes acceptance of the updated terms.
Contact & Requests
Questions, deletion or export requests, or security concerns? We respond to most inquiries within 7 days.