Privacy Policy
Effective date: 28 September 2026
The short version: your meal plans, shopping lists and the text you enter while planning stay on your device. The NomNom consumer app has no user accounts and never asks for your name or email. If you explicitly rate a recipe, we save that anonymous rating so we can improve the meals. We collect anonymous usage analytics, selected setup categories and crash diagnostics to improve the app, hosted in the European Union, and you can switch this collection off in the app's settings at any time. If you choose to join the launch waitlist on our website, we keep that email address only to send you launch news, and you can leave the list anytime.
Who we are
NomNom is published by Z Gen Kibernetika Kft. (registered in Hungary), the data controller for the processing described here. If you have any questions about this policy, contact us at help@nomnomplanner.com.
What stays on your device
To do its job, NomNom keeps the working copy of the following information on your device. Selected predefined preference categories are also copied to analytics as described in the next section:
- your preferences (shop, country, budget, servings, cook days, dietary needs, dislikes, kitchen appliances),
- your generated meal plans, bookmarks and shopping list checkmarks.
Your generated plans, shopping-list state and the text of your disliked ingredients are not uploaded as analytics. Deleting the app deletes their local copy.
Usage analytics and crash diagnostics
We use PostHog, an analytics service, to understand how NomNom is used so we can improve it. PostHog processes this data on our behalf on servers located in the European Union (Frankfurt, Germany). The data we collect:
- Usage events: which screens you open and which features you use, for example that a meal plan was generated or a recipe was bookmarked.
- Preference categories: traits such as your selected country, shop, household size, cooking and shopping schedule, appliance choices, meal goals and predefined dietary needs, so we can see which setups work well and whether the recipe catalogue has enough compatible meals. The iOS app also sends your configured weekly budget; the Android app does not. Free-text input, such as your dislikes, is never sent as analytics; for dislikes, only the count is sent.
- Device and app information: device model, OS version, app version, language and a random installation identifier. We do not collect your name, email, contacts, or precise location.
- Crash diagnostics: when the app terminates because of a technical error, the error type, message and stack trace are saved on the device and sent on the next app launch together with the device, OS and app version. This lets us identify and fix the failing code.
- Session replays: anonymised recordings of how the app's screens are used. Anything you type is masked and never recorded.
Your IP address is used to receive this data and derive a rough location (country/city), and is not stored with your events. Analytics profiles are identified by a random identifier, not by who you are.
Opting out: you can turn analytics off at any time in the app under Settings. When switched off, no analytics, crash diagnostics or session replay data is sent. Our legal basis for this processing is our legitimate interest in understanding and improving the app (GDPR Art. 6(1)(f)); the opt-out is always one tap away.
Analytics data is retained for at most 12 months and then deleted or irreversibly aggregated.
Recipe ratings and feedback
When you explicitly tap “like” or “not for me” on a recipe, we send the recipe identifier and name, your selected rating and whether you turned it on or off, your selected app country and language, the app version, and the country-level location supplied by Cloudflare. Each submission uses a fresh random event identifier. It is not linked to your name, email, analytics identifier or a persistent device identifier.
You may also choose to send a written recipe issue or suggestion. We store the recipe identifier and name, the category you select, your message of up to 2,000 characters, your selected app country and language, the app version, submission time and country-level location supplied by Cloudflare. Please do not include your name, email address or other personal information in the message.
Your IP address is used only to prevent automated abuse. We store a one-way hash of it for up to 25 hours and do not attach it to the feedback. Recipe ratings and written feedback are stored on Cloudflare infrastructure for up to 12 months and are then automatically deleted. We use them only to understand which recipes work well and improve the meal catalogue. Our legal basis is our legitimate interest in improving NomNom (GDPR Art. 6(1)(f)). You can object to this processing by contacting help@nomnomplanner.com.
Our website and the waitlist
Our website (nomnomplanner.com) sets no cookies of its own and runs no client-side analytics. To count visits and signups we record server-side events (page viewed, waitlist joined) that contain a rough location (country) and no persistent identifier, processed by PostHog in the EU as described above. Advertising measurement is described in its own section below.
If you join the waitlist, we store your email address, the signup date, your country and, where available, the site that referred you. We use this for one purpose: sending you TestFlight invites and launch announcements for NomNom. The legal basis is your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time by emailing help@nomnomplanner.com or replying to any of our emails; we then delete your address. Waitlist data is stored on Cloudflare infrastructure, is never shared with advertisers or used for any other marketing, and is deleted no later than 6 months after the app's public launch.
Ambassador applications
If you apply on our ambassador page (nomnomplanner.com/ambassador), we store the email address and the social profile links you submit, together with the submission date and your country-level location supplied by Cloudflare. We use this data for one purpose: reviewing your application and contacting you about a possible collaboration. The legal basis is that the processing is necessary for steps taken at your request prior to entering into a contract (GDPR Art. 6(1)(b)).
Application data is stored on Cloudflare infrastructure and is visible only to the NomNom team. If we work together, we keep your contact details for the duration of the collaboration. Applications that do not lead to a collaboration are deleted automatically at the latest 12 months after submission, and earlier on request: email help@nomnomplanner.com at any time to have your application corrected or deleted.
Purchases
Subscriptions are processed by Apple through the App Store or by Google through Google Play, depending on your device. We do not receive your name, address or payment details. Through RevenueCat, we receive an anonymous confirmation of the subscription status, for example that a trial started, a purchase completed or automatic renewal was turned off, so the app can unlock and we can understand subscription performance.
If you turn off automatic renewal, NomNom may show one optional question asking why you cancelled. You can select a structured category, such as price, low usage, content fit or a technical problem, and may add an optional note of up to 300 characters. We store the category and any note you choose to submit with a one-way hash of RevenueCat's anonymous app user identifier, the subscription product and period type, expiry time, selected app country and language, app version, submission time and country-level location supplied by Cloudflare. Please do not include your name, email address or other personal information in the optional note. This lets us measure trial and paid cancellations without receiving your payment details. The response is optional, shown at most once for a subscription period and retained for at most 12 months. Our legal basis is our legitimate interest in improving NomNom and understanding why subscriptions are cancelled (GDPR Art. 6(1)(f)). You can object by contacting help@nomnomplanner.com.
Apple's handling of your purchase data is described in Apple's Privacy Policy. Google's handling of your purchase data is described in Google's Privacy Policy.
Authorised TikTok integration
An authorised NomNom operator may connect a NomNom-managed TikTok account to our private marketing dashboard through TikTok Login Kit. After the operator gives consent, we receive an app-specific account identifier, display name, profile statistics, and public post metadata and statistics such as post identifiers, descriptions, cover images, publication times, views, likes, comments and shares. We do not receive the TikTok password, private posts, messages or contacts.
We use this data only to display and monitor the performance of NomNom's own TikTok content. Access and refresh tokens are stored server-side, encrypted at the application layer, on Cloudflare infrastructure. Tokens are deleted locally and a revocation request is sent to TikTok when the integration is disconnected. Historical public post statistics are retained only while they are needed for NomNom's content performance analysis.
The operator can revoke access from TikTok's app permissions or request disconnection and deletion by writing to help@nomnomplanner.com.
Advertising measurement
We advertise NomNom, and we measure whether those ads work. When you click one of our ads, the advertising platform adds its own click identifier to the link you follow. If, and only if, that identifier is present, we report the visit and the tap on the App Store link back to that platform from our server, together with the click identifier, your IP address and your browser's user agent. We send no email address, no name and no identifier of our own, and we set no cookie to do it. A visitor who did not arrive from one of our ads is never reported to an advertising platform.
The platforms we use this way are Meta (Facebook, Instagram) through its Conversions API, TikTok through its Events API, and Google through its Ads conversion import. Each handles this data as an independent controller under its own terms. Our legal basis is our legitimate interest in knowing which advertising spend is worth repeating (GDPR Art. 6(1)(f)). To object, write to help@nomnomplanner.com.
Our landing pages also load an advertising measurement script supplied by OpenAI, which runs in your browser and may store identifiers there.
Inside the iOS app, we use Meta, TikTok and Firebase (Google) SDKs to measure the first app open and selected subscription steps. Meta receives an app activation signal and an anonymous app identifier. TikTok receives app install or launch signals and, when a trial or direct purchase is started in the app, the event type and the StoreKit product price and currency for direct purchases. The final charged amount may differ when a discount applies. Firebase receives a first-open signal and trial or subscription events; it may also record App Store purchases automatically. These SDKs may process device, app and network information needed to deliver and match events. We do not send meal plans, shopping lists, names or email addresses to these ad measurement SDKs.
RevenueCat also sends Meta the subscription lifecycle events it processes, including trial starts, paid purchases, trial conversions and renewals, with the amount in USD for paid events. When our OpenAI mobile ad measurement connection is enabled, our server sends OpenAI first-launch and subscription events with a hashed anonymous app user identifier, country where available, and the amount and currency of paid transactions. The first-launch event is sent only when the app reports it to our server. These events may happen after the app is closed. Advertising platforms decide whether they can match an event to a campaign; an accepted event does not mean a particular ad caused it.
We also use Apple's SKAdNetwork for privacy-preserving install measurement. The app sends Apple a limited conversion value for the setup or subscription step reached; Apple delays and restricts the postback before sharing it with eligible ad networks. We do not request App Tracking Transparency permission or access the iOS advertising identifier (IDFA). We review the app's advertising measurement against Apple's tracking rules and App Store privacy disclosures.
Who we share data with
We do not sell your data. We share the limited advertising measurement data described above with Meta, TikTok, Google and, when enabled, OpenAI. The third parties processing data on our behalf are PostHog (EU region) for analytics and crash diagnostics, RevenueCat for anonymous subscription status, and Cloudflare for website hosting and storage, each under a data processing agreement. Apple and Google process purchases under their own privacy policies. TikTok supplies authorised account data at the operator's direction and handles TikTok account data under its own privacy policy. We may disclose data if the law requires it.
Children
NomNom is not directed at children under 16 and we do not knowingly collect personal data from them.
Your rights
Under the GDPR you have the right to access, correct, erase, restrict or object to the processing of your personal data, and to lodge a complaint with a supervisory authority (in Hungary: NAIH, naih.hu). Because analytics profiles are keyed to a random identifier rather than your identity, if you contact us to exercise these rights we may ask you for that identifier (shown in the app's settings) to locate your data. Write to help@nomnomplanner.com and we will respond within 30 days.
Changes to this policy
If the app changes in a way that affects your privacy, we will update this page and the effective date above before the change ships.