NomsAI is a minimalist calorie-tracking app built and operated by a solo developer based in the United Kingdom. References to "we", "us", or "our" mean that developer. We are the data controller under UK GDPR (for UK users) and EU GDPR (for users in the EEA, including Ireland). Our lead supervisory authority for UK users is the Information Commissioner's Office (ICO). For users in Ireland and the wider EEA, the competent supervisory authority is your national Data Protection Authority; in Ireland this is the Data Protection Commission (DPC). Because NomsAI's processing of EEA data is occasional, pseudonymous, and poses no systemic risk to individuals' rights and freedoms, we do not appoint an EU Representative pursuant to Article 27(2) of the EU GDPR. For US users, applicable federal and state privacy laws govern. For questions or data requests, contact [email protected].
NomsAI does not require you to create an account or provide any personal
information such as your name, email address, or date of birth. When you
first open the app, a random UUID (e.g. a3f8…) is generated
on your device. This is your only identifier. We have no way to link it to
you as a person.
The following data is stored on our server, associated only with your anonymous Device ID:
We do not collect your name, email, location, contacts, passwords, or payment card details. Food-entry text and meal ingredient lists are sent transiently to our AI provider to deliver the service and are not stored on our server — see Section 4 for details.
Voice input: If you use the optional voice input feature, your speech is processed by your device's built-in speech recognition engine (provided by Apple or Google). The resulting text is placed into the input field on your device and treated identically to typed input. No audio is recorded or transmitted by NomsAI. Microphone access is requested only when you tap the mic button and is not used at any other time.
The following data is stored exclusively in your app's local storage and never sent to our server:
android.permission.health.READ_EXERCISE) and no other health categories.
For each exercise session we read: activity type, start/end time, and an estimated
calorie burn — nothing else. This data is stored in the app's local storage,
processed entirely on your device, and is never transmitted to our
servers. Health Connect itself aggregates exercise data that third-party
apps (such as Garmin Connect, Strava, and Samsung Health) have written to it;
NomsAI does not interact with those apps directly — your relationship with them
is governed by their own privacy policies. You can revoke NomsAI's access at any
time by toggling off Health Connect in Settings, or via your device's Health Connect
privacy settings, where you can also see exactly when NomsAI last accessed your data.
Barcode scanning: When you use the barcode scanner, your camera is accessed temporarily to read the barcode. No image is stored or transmitted. The barcode number is sent to our server solely to look up nutritional data; it is not stored after the lookup completes.
Nutrition-label scanning (contributing a product): When a scanned barcode isn't already in our food database, you can optionally photograph the product's nutrition label. The photo is processed entirely on your device using an on-device text-recognition library (Google ML Kit) to read the nutrition figures, and the image is then discarded — it is never uploaded to our servers or stored by us. If you choose to save the product, only the resulting details — the barcode, the product name and brand you enter, and the nutrition values you confirm — are submitted to our shared food database. This submission is anonymous: it carries no device identifier and is not linked to you. Contributed product data is factual product information (not personal data) and may be shown to other users once reviewed. Scanning a label is always optional.
Photo food logging: You can optionally log a meal by taking or choosing a photo of your food. Before the photo leaves your device it is re-encoded to a smaller image, which removes all embedded metadata (including any GPS location, device, and timestamp information). The stripped image is sent to our AI provider (Google Gemini) solely to identify the food and estimate portions; it is not stored on our servers and, under Google's paid API terms, is not used to train their models. A small copy of the photo is kept only on your device so you can see it next to the log, and it is deleted automatically when you delete that log (or when the log ages out of your history). Photo logging is always optional — the same meal can be logged by typing it.
Your original free-text input (e.g. "2 eggs and toast") and any ingredient lists you enter in the Meal Ideas feature are sent to our AI provider to estimate macros or generate recipe suggestions, and are then discarded. They are not saved anywhere — not on our server, not on your device.
Consequence: If you uninstall the app or switch to a new phone, your log history, goals, and weight entries are gone. We have no copy and no way to restore them. On iOS, a random device identifier is retained in the system Keychain after uninstall solely to preserve your credit balance if you reinstall; it contains no personal data and is permanently deleted when you use Settings → Delete Account.
Pro subscribers: your subscription is managed by Apple / Google. Tap Restore Purchases in Settings to recover your Pro on a new device.
We process your data under UK GDPR Article 6 (UK users) and EU GDPR Article 6 (EEA users, including Ireland). The table below sets out each processing activity, its purpose, and the legal basis we rely on.
| Processing activity | Purpose | Lawful basis |
|---|---|---|
| Storing your Device ID and credit balance | To identify your account and deliver the core service (AI macro estimation, credit deduction) | Contract — Art. 6(1)(b): necessary to perform the service you use |
| Updating the last-session timestamp; using the account creation date and a single milestone marker to compute day-1, day-7, day-14 and day-30 cohort metrics | Aggregate, anonymised retention analysis (daily totals only — no per-user profiles are built) | Legitimate interests — Art. 6(1)(f): understanding whether the app is useful, balanced against minimal privacy impact (counts only, pseudonymous Device ID, no behavioural profiling) |
| Reading workout data from Apple Health (iOS) or Health Connect (Android), opt-in | To display your imported workouts in the app and include them in calorie-burn summaries. Processed on your device only; never transmitted to our servers. | Consent — Art. 6(1)(a) and Art. 9(2)(a): you explicitly grant permission via the operating system's HealthKit or Health Connect permission prompt and the in-app toggle. You may withdraw consent at any time by revoking the permission. |
| Tracking daily AI usage counter (Pro subscribers only) | Enforce the daily fair-use limit; protect service sustainability | Contract — Art. 6(1)(b): necessary to fulfil the Pro terms |
| Sending food-entry text to Google Gemini | Parse free-text food input and estimate macros | Contract — Art. 6(1)(b): the app cannot function without this; the text is not stored by us after processing |
| Sending meal ingredient lists to Google Gemini | Generate meal ideas with macros and cooking instructions via the Meal Ideas feature | Contract — Art. 6(1)(b): necessary to deliver the Meal Ideas feature; ingredient lists are not stored by us after processing |
| Sending a metadata-stripped food photo to Google Gemini | Identify the food in a photo and estimate portions when you log by photo | Contract — Art. 6(1)(b): necessary to deliver the optional photo-logging feature; the image is stripped of location and device metadata before sending and is not stored by us after processing |
| Sharing Device ID with RevenueCat | Verify and restore in-app purchases and Pro status | Contract — Art. 6(1)(b): necessary to deliver paid features |
| IP address processing by infrastructure providers (Cloudflare, Fly.io) | Routing requests to our servers, DDoS protection, and abuse prevention. We do not log IP addresses ourselves; they are processed transiently by our hosting and security providers as an inherent part of internet infrastructure. | Legitimate interests — Art. 6(1)(f): necessary to operate a secure and reliable service |
We do not sell, rent, share, or use your data for advertising. We do not use your data to train AI models.
Transfers to the United States (Google Gemini, RevenueCat, Cloudflare, Fly.io) are made under Standard Contractual Clauses approved by the European Commission and the UK ICO, providing equivalent safeguards to EU/UK data protection law. Where applicable, transfers may also rely on the UK-US Data Bridge adequacy decision.
A note on device-level OS backups: "Stored only on your device" means NomsAI does not transmit this data to our servers or any third party. It does not override the operating system's own backup mechanisms — Android Auto Backup (Google Drive) and iCloud Backup may include the app's local data in device backups that you have enabled in your phone's system settings. Those backups are governed by Google's or Apple's privacy policies, not ours. To opt out, disable backup for NomsAI in your device's backup settings, or disable the device backup feature entirely.
The data we hold on our servers — a random Device ID, a credit balance, and session/retention timestamps — does not fall under Article 9. Food logs, weight measurements, and dietary goals are stored entirely on your device and never processed on our servers.
Native health platform integration (iOS Apple Health and Android
Health Connect, opt-in): If you enable the integration on your
platform, workout data (activity type, duration, and estimated calorie
burn) is read from Apple HealthKit (iOS) or Android Health Connect
(Android) and stored in the app's local storage on your device. On Android
we request only the Exercise data category (permission
android.permission.health.READ_EXERCISE); on iOS we request
only the HealthKit Workouts permission (technical identifier
HKWorkoutTypeIdentifier). No other health categories (heart
rate, sleep, weight, nutrition written by other apps, etc.) are read.
Health Connect itself may aggregate exercise data from third-party apps
such as Garmin Connect, Strava, Samsung Health, and others — NomsAI does
not interact with those third-party providers directly. Your relationship
with each of them is governed by their own privacy policies; if you
withdraw a third-party provider's write access to Health Connect, NomsAI
will simply stop seeing that provider's new entries on the next sync.
This data constitutes health data under GDPR Article 9. We process it
solely on your device, it is never transmitted to our servers,
and never sent to any AI provider (workouts are not part of the
meal-text prompts our Gemini integration handles). One caveat: as noted in
Section 7 above, device-level OS backups (Android Auto Backup / iCloud
Backup) may include local app data — including imported health data —
if you have those backup features enabled on your phone. NomsAI cannot
override those system-level mechanisms; if you do not want imported
health data to be included in your OS backup, disable backup for NomsAI
in your device's backup settings before enabling the integration.
We rely on your
explicit consent (Art. 9(2)(a)) — granted via the
operating system's or Health Connect's permission prompt and the in-app
toggle — as the lawful basis. You may withdraw consent at any time by
revoking the permission in your device's system settings
(iOS Settings → Health → Apps → NomsAI, or the Android Health
Connect app) or by toggling off the integration in the app's Settings
screen.
Food-entry text and meal ingredient lists are transiently processed by Google Gemini to extract macro estimates or generate recipe suggestions, and are immediately discarded. This transient processing touches on dietary information; however, it is not stored or linked to any identifiable person, and Google's API terms prohibit its use for any purpose beyond fulfilling the API request.
NomsAI does not engage in automated decision-making or profiling within the meaning of GDPR Article 22. AI-generated macro estimates are informational only, have no legal or similarly significant effect on you, and you retain full control to edit or discard them before saving.
NomsAI is an informational macro-tracking tool, not a medical device. It does not provide medical, clinical, or dietary advice. Do not use it to manage any medical condition. Always consult a qualified healthcare professional before making health decisions.
If you are in the EEA or UK you have the following rights. Because NomsAI holds minimal pseudonymous data, most are exercisable directly in the app:
For any requests, contact [email protected]. We will respond within 30 days. Because all data is stored under an anonymous Device ID with no name or email attached, we may ask you to provide your Device ID (visible in Settings) to action your request.
You have the right to lodge a complaint with a supervisory authority at any time — you do not need to contact us first.
NomsAI is intended for users aged 18 and over. We do not knowingly collect data from minors. If you are under 18, you must not use the App.
If you are a US resident, applicable federal and state privacy laws grant you rights regarding your personal information. This section covers California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states with comprehensive privacy laws. The same rights and contact point apply regardless of which state you are in.
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioural advertising. There is no "sale or sharing" to opt out of.
To exercise any of these rights, contact [email protected]. We will respond within 45 days (extendable by a further 45 days where reasonably necessary). Please include your Device ID (visible in Settings) so we can locate your record.
If you are a Canadian resident, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle your personal information. Quebec residents are additionally protected by Quebec's Act respecting the protection of personal information in the private sector (Law 25), which imposes similar obligations to EU GDPR.
For the purposes of Quebec Law 25, the solo developer acts as the Person In Charge of Personal Information (Privacy Officer) and can be reached at [email protected].
Cross-border transfers: Your pseudonymous server-side data (Device ID, credit balance, Pro status) is stored in the European Union via MongoDB Atlas. Transient food-entry text sent for AI processing is handled in the United States by Google Gemini and immediately discarded. By using the app you acknowledge that this data crosses borders and may be subject to the laws of those jurisdictions.
We do not sell your personal information. The same data rights that apply to UK/EU users apply to you:
We will respond to requests within 30 days. If you have a complaint about how we handle your personal information, you may contact:
If you are in Australia or New Zealand, your privacy is protected by:
The protections you receive under these laws closely mirror those granted to UK/EU users under GDPR, and the same data-minimisation, on-device processing, and consent principles apply. The headline point is that by design, NomsAI holds essentially no personal data on its servers — only a randomly generated Device ID, your credit balance, Pro subscription status, and session/usage timestamps. Food logs, weight, water, workouts, recipes, and any imported Apple Health or Health Connect data remain on your device and are never transmitted to us.
Health-related information: the Privacy Act 1988 defines "health information" broadly. While NomsAI is an informational macro-tracking tool and not a medical or health-services provider, dietary and fitness data collected via the Apple Health / Health Connect integrations could be considered health information by an Australian regulator. We treat such data with the same strict on-device-only model described in Sections 4 and 8: it is never transmitted to our servers and is processed entirely on your phone. You explicitly opt in to the integration and may withdraw consent at any time via Settings or your device's system privacy panel.
Cross-border disclosure (APP 8 / NZ IPP 12): your pseudonymous server-side data (Device ID, credit balance, Pro status) is stored in the European Union via MongoDB Atlas. Transient food-entry text sent for AI processing is handled in the United States by Google Gemini and is immediately discarded — never associated with your Device ID server-side and never retained by Google under its API terms. By using the app you acknowledge that this minimal data crosses borders. We have selected providers whose contractual terms commit them to privacy protections substantially similar to those required under Australian and New Zealand law.
Notifiable Data Breaches: Australia's Notifiable Data Breaches scheme and New Zealand's Notifiable Privacy Breaches regime both require us to notify affected individuals and the relevant Commissioner when a breach is likely to cause serious harm. We commit to doing so. As a practical matter, because we hold so little personal data on our servers — no names, no email addresses, no health logs — the realistic worst case from any server-side breach is the disclosure of an opaque Device ID and credit balance, which cannot be used to identify or contact you.
Your rights under both regimes mirror the GDPR rights listed in Section 10:
We will respond to requests within 30 days. If you are not satisfied with our response, you may lodge a complaint with the regulator in your jurisdiction:
We may update this policy. The "last updated" date at the top will change when we do. Continued use of the app after changes are posted constitutes acceptance of the updated policy.