Privacy policy
In short
- Your account, plan, meals and weigh-ins are stored on our own server in Frankfurt, Germany.
- Meal and label photos are read by an AI service and then discarded. We never store them.
- What you eat and weigh is health data. We store it only with your explicit consent.
- Workouts and active energy from Apple Health stay on your iPhone.
- No ads, no tracking, no selling of data, no third-party analytics.
- You can export your data and delete your account in the app at any time.
1. Who is responsible
The controller for your personal data is:
Burak Özaslan
Maltepe, İstanbul, Türkiye
Email: support@yumta.app
Yumta is run by one person. Write to the address above for any privacy question or request.
2. Where your data is processed
The Yumta server and its database run on our own server, rented from DigitalOcean, in a data centre in Frankfurt, Germany (EU). The database isn't reachable from the internet.
The app talks to api.yumta.app. That address runs through Cloudflare, Inc., which protects our server from attacks: the encrypted connection (HTTPS) from the app ends at Cloudflare, which passes each request on to our server over a second encrypted connection. So the app's traffic, including your health data and photos, passes through Cloudflare's network on the way. Cloudflare acts as our processor; it doesn't store what you send, and handles technical data such as your IP address under its own terms.
This website (yumta.app) is hosted separately on Cloudflare Pages; see section 16.
3. Account and Sign in with Apple
You answer the onboarding questions without an account; those answers stay on your iPhone. When you tap “Save my plan”, you sign in with Apple and we create your account.
- What we store: the user identifier Apple gives us for Yumta, your email address if Apple shares it (often Apple's private relay address), and your first and last name if Apple sent them or you added a first name in the app.
- Apple refresh token: stored encrypted (AES-256-GCM). We need it to revoke Sign in with Apple when you delete your account.
- Session tokens: to keep you signed in. We store them only as hashes. They last 60 days and are deleted 7 days after they expire.
- Apple notifications: if you stop using Sign in with Apple for Yumta, Apple tells our server and we sign you out on all devices. If you delete your Apple account, Apple tells our server and we delete your Yumta account.
Why: to sign you in and greet you. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
4. Profile and plan
- What we store: sex (for the energy formula), birth date, height, weight, optional body fat, whether you're pregnant or breastfeeding (if you tell us, so the plan stays at maintenance), goal and goal weight, daily activity, training days, your language, time zone and units, and the plans calculated from these (energy target, protein, carbs, fat, pace and projected date).
- Why: to calculate your plan and show your progress.
- Legal basis: this is health data. We process it with your explicit consent (Art. 9(2)(a) GDPR, see section 17) and to provide the app (Art. 6(1)(b) GDPR).
- How long: until you delete your account.
5. Meals, weigh-ins and your foods
- What we store: your meal entries (food, grams, the nutrition values at the time, time, meal and how you logged it), your weigh-ins, a daily total per day for your map, your favorites, foods you created yourself, your personal barcode links, and search shortcuts learned from your corrections. We also store whether you have Premium.
- Why: this is your diary; it powers Today, Journey, the map and faster logging.
- Legal basis: health data, processed with your explicit consent (Art. 9(2)(a) GDPR) and to provide the app (Art. 6(1)(b) GDPR).
- How long: until you delete the entry or your account.
6. Food search and barcodes
What you type in search and the barcodes you scan are sent to our server to find foods. Barcodes are read on your iPhone; the camera image isn't sent anywhere.
Our food data comes from USDA FoodData Central, Open Food Facts and labels scanned by users. If a scanned barcode isn't in our database, our server asks Open Food Facts about that barcode. Only the barcode number is sent, never anything about you.
Legal basis: performance of our contract (Art. 6(1)(b) GDPR).
7. Label scans (Premium)
- What happens: when you scan a product's label, the photos of the pack and its nutrition table are sent to our server and passed to our AI service (Anthropic, see section 10) to read the printed values. The AI only copies what's printed; our code converts and checks the values, and you confirm them.
- Photos are not stored. They're processed in memory and discarded. We keep only a fingerprint of each photo (a SHA-256 hash, which can't be turned back into the photo) and its file size, with the draft.
- The draft (the values read from the label) is deleted after 30 days.
- Shared foods: if the product has a barcode and the values pass our checks, it becomes a shared food that other users get when they scan that barcode. It contains product data only (name, brand, nutrition values, serving size) and no information about you. Our link between the shared food and your scan is removed when the draft is deleted (30 days) or when you delete your account; the shared food then stays as product data only. Without a barcode, or with values that don't pass the checks, the food is saved as a private food only you can see.
- Legal basis: performance of our contract (Art. 6(1)(b) GDPR).
8. Meal photos
- What happens: when you log a meal with a photo, the photo is sent to our server and passed to our AI service (Anthropic) together with your language setting. The AI names the foods it sees and estimates portions. The nutrition numbers then come from our food database, never from the AI.
- Photos are not stored. They're processed in memory and discarded. We keep only the photo's hash and file size with the draft.
- Foods we don't have yet: if the AI names a food that isn't in our database, our server asks Anthropic to look that food up on the web. Only the food's name (and any text visible on a pack) and the account code described in section 10 are sent, never the photo or anything else about you. A food that's found is checked and added to our database for everyone.
- The recognition result (food names, positions on the photo, portion estimates) is deleted after 30 days. After that, only an empty record with the date remains, because we count your 3 free photo logs from it. It's deleted with your account.
- Legal basis: performance of our contract (Art. 6(1)(b) GDPR). A photo of a meal can say something about your health; we process it on the basis of your explicit consent (Art. 9(2)(a) GDPR).
9. Typed meals (Describe, Premium)
- What happens: the text you type, for example “two eggs and toast”, is sent to our server and passed to our AI service (Anthropic) with your language setting, which splits it into foods and amounts. Our database supplies the matches and nutrition numbers.
- How long: the text and the draft are deleted after 30 days.
- Legal basis: performance of our contract (Art. 6(1)(b) GDPR) and, as it concerns your diet, your explicit consent (Art. 9(2)(a) GDPR).
10. How the AI service handles your data
Label scans, meal photos and Describe use the Claude API from Anthropic, PBC (USA), which acts as our processor. It receives the photo or the text, your language setting, and a random-looking code per account (a one-way hash), so Anthropic can spot abuse by a single account. The code doesn't contain your name, email or account ID, and we never send your profile. Before a photo goes to Anthropic, our own server checks it for nudity; a photo that fails the check is rejected and never sent. AI is used only for these features: the Premium features and your 3 free photo logs.
Under Anthropic's commercial terms, inputs and outputs from its API are not used to train its models by default, and Anthropic deletes them within 30 days of receipt, except where its terms require longer retention (for example to investigate misuse, or by law).
For cost control we keep usage statistics for each AI request: the feature, the model, token counts, response time and whether it worked. When you delete your account, your user ID is removed from these statistics.
11. Apple Health
Connecting Apple Health is optional, and you choose in iOS what Yumta may read and write.
- Writes: the energy, protein, carbs, fat and fibre of the meals you log.
- Reads weight: weigh-ins from Apple Health are added to your Yumta account (and so stored on our server like weigh-ins you enter).
- Reads workouts and active energy: shown as “Training today” on your iPhone only. They're never sent to our server.
We don't use Apple Health data for advertising, don't sell it, and don't share it with third parties. You can change the permissions any time in Settings → Privacy & Security → Health → Yumta.
12. On your iPhone
- Offline copy: the app keeps a copy of your recent data on your iPhone so it opens instantly and works offline. Entries made offline are sent when you're back online.
- Widgets: the app saves a short summary (for example what's left today and your map) in storage shared with its widgets, on your iPhone only.
- Siri and Shortcuts: when you use a phrase like “Log food in Yumta”, Apple processes your voice under its own terms; Yumta only receives the request to open logging.
- Camera: used only when you scan a barcode, a label or a meal.
- Crash reports: if you've chosen in iOS to share analytics with app developers, Apple may give us crash reports and usage statistics that don't identify you. We don't add any analytics or crash-reporting tools of our own.
13. Purchases and Premium
Premium will be sold as a subscription through the App Store. Apple handles the payment; we never see your payment details. We store whether your account has Premium.
We use RevenueCat, Inc. (USA) to manage Yumta Premium subscriptions across devices. RevenueCat receives your Yumta account ID (a random identifier, not your name or email) and the purchase information Apple provides. We don't send it your name, email or health data, and the app doesn't give it advertising or device identifiers. When you delete your account, we ask RevenueCat to delete your record too.
14. Server logs and security
- Our database stores no IP addresses.
- To limit abuse, some sign-up endpoints keep IP addresses in memory for rate limiting. They're never written to disk.
- The web server and the API write technical logs with the IP address, time and the requested address. For food search and barcode lookups that address includes your search words or the barcode number. Request contents (your meals, weigh-ins, photos) are not logged. These logs rotate: web server logs are kept for about 14 days, API logs are overwritten after a fixed size.
- Daily database backups are kept for 14 days.
- Connections are encrypted, the Apple token is stored encrypted, session tokens only as hashes, and you can only reach your own data.
Legal basis: our legitimate interest in running a secure service (Art. 6(1)(f) GDPR).
15. Email
When you write to support@yumta.app, we use your email and what you tell us to answer you. If you ask to hear about the launch, we use your address only for that one reply. Emails are kept as long as needed to help you, then deleted. Mail to support@yumta.app is received by Cloudflare Email Routing (Cloudflare, Inc.) and forwarded to a mailbox hosted by Google (Gmail), where we read and answer it.
Legal basis: our contract with you, or our legitimate interest in answering you (Art. 6(1)(b) and (f) GDPR).
16. This website
yumta.app is a static website hosted on Cloudflare Pages by Cloudflare, Inc. To deliver the pages and protect them from attacks, Cloudflare processes technical data such as your IP address and browser details, under its own terms. The site sets no cookies, uses no analytics or tracking, and loads its fonts from our own domain, not from third parties. Animation preferences (like Reduce Motion) are read in your browser and never sent anywhere.
Legal basis: our legitimate interest in providing a working, secure website (Art. 6(1)(f) GDPR).
17. Health data and your consent
Your diet, weight, body measurements and goals are health data under Art. 9 GDPR. We process them only with your explicit consent, which we ask for in the app before your data is saved to our server.
You can withdraw your consent at any time by deleting your account in the app (or by emailing us). Withdrawal doesn't affect processing that happened before. Without this consent we can't store your plan and diary, because that is what the app does.
18. Legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Account, sign-in, providing the app | Art. 6(1)(b) contract |
| Profile, plan, meals, weigh-ins, meal photos, typed meals | Art. 9(2)(a) explicit consent, with Art. 6(1)(b) |
| Food search, barcodes, label scans | Art. 6(1)(b) contract |
| Apple Health (optional) | Art. 9(2)(a) explicit consent, given in iOS and the app |
| Security, rate limits, logs, backups, AI cost statistics | Art. 6(1)(f) legitimate interest |
| Answering emails | Art. 6(1)(b) or (f) |
| This website | Art. 6(1)(f) legitimate interest |
19. Processors and recipients
| Who | What for | Data | Where |
|---|---|---|---|
| DigitalOcean, LLC | Server and database hosting (processor) | All data stored on our server | Frankfurt, Germany |
| Anthropic, PBC | Reading photos and typed meals (processor) | The photo or text, language, a per-account code (one-way hash) | USA |
| Apple Inc. | Sign in with Apple, App Store, payments | Apple ID token, purchases | USA / your region |
| Open Food Facts | Looking up unknown barcodes | The barcode number only | France |
| Cloudflare, Inc. | Protecting and passing on the app's connection to our server; hosting this website; forwarding mail to support@yumta.app | App traffic in transit (not stored), IP addresses; website visitors' IP addresses; support emails in transit | Global network |
| Google LLC (Gmail) | The mailbox where we read and answer support emails | Your email address and message | USA / global |
| RevenueCat, Inc. | Subscription status | Random account ID, purchases | USA |
We may disclose data if the law requires it. We don't sell or rent your data to anyone.
20. Transfers outside the EU
Your stored data stays in Germany. Some processors are US companies (Anthropic, Apple, Cloudflare, DigitalOcean and RevenueCat). For transfers to the US we rely on the EU–US Data Privacy Framework where the company is certified, and otherwise on the EU Standard Contractual Clauses in the processor's data processing terms.
21. How long we keep data
| Data | Kept |
|---|---|
| Account, profile, plans, meals, weigh-ins, favorites, your foods, Premium status | Until you delete your account |
| Apple refresh token (encrypted) | Until you delete your account |
| Session tokens (hashed) | 60 days, deleted 7 days after expiry |
| Meal and label photos | Not stored |
| Photo hashes, label drafts, recognition results, typed meal text | 30 days |
| Record that a free photo log was used (date only) | Until you delete your account |
| AI usage statistics | Kept for cost control; your user ID is removed when you delete your account |
| Shared foods from label scans | Kept as product data, with nothing about you |
| Database backups | 14 days |
| Server logs (IP address, time, requested address incl. search words) | About 14 days (web server); API logs are overwritten after a fixed size |
| Support emails | As long as needed to help you |
22. Deleting your account
In the app: You → Account → Delete account. This immediately deletes your account and everything listed in sections 3 to 9 from our database, and revokes Yumta's Sign in with Apple. If Apple tells us you've deleted your Apple account, we do the same. Server logs expire on their own (about 14 days).
Deleted data disappears from our backups within 14 days. Shared foods you contributed stay, without your name. Deleting your account doesn't cancel an App Store subscription; cancel it in Settings → your name → Subscriptions.
If you can't use the app, email us from the address on your account and we'll delete it for you.
23. Your rights
Under the GDPR you have the right to:
- access the data we hold about you, and get a copy;
- have wrong data corrected;
- have your data deleted;
- restrict processing;
- data portability: in the app, You → Account → Export my data gives you your meals and weigh-ins as CSV files and your plan as a JSON file;
- object to processing based on legitimate interest;
- withdraw your consent at any time, for the future;
- complain to a data protection supervisory authority, for example in the EU country where you live.
To use these rights, email support@yumta.app. We answer within one month. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
24. If you live in the US
Some US state laws give you rights over your personal data and your consumer health data, such as the right to know what we collect, to get a copy, to correct it and to delete it. This policy describes what we collect (sections 3 to 16), where it comes from (you, Apple Health if you connect it, and Apple sign-in), why, and who receives it (section 19). We collect consumer health data only with your consent and only to provide the app. We don't sell personal data or health data, and we don't share it for targeted advertising. To use your rights, email us; you can also delete your account and export your data in the app.
25. What we don't do
- No advertising, and no data for advertisers.
- No selling of data.
- No tracking across apps or websites, and no advertising identifier (IDFA).
- No third-party analytics or tracking SDKs at launch.
- No storing of your photos.
- No Apple Health workouts or active energy on our server.
26. Children
Yumta is not meant for anyone under 16, and we don't knowingly collect data from children. If you think a child has given us data, write to us and we'll delete it.
27. Not medical advice
Yumta helps you track food and weight. It isn't a medical device and doesn't give medical advice. Nutrition data can contain errors, and portions are estimates. If you're pregnant or breastfeeding, Yumta plans to keep your weight steady. If you have a health condition, an eating disorder or questions about your diet, talk to a doctor.
28. Changes to this policy
When we change how we handle data, we update this page and the date at the top, and we tell you in the app about important changes before they take effect.
Questions? support@yumta.app