Skip to privacy policy
Yumsy
Back to YumsyPrivacy Policy

The details behind Yumsy

Privacy Policy

How Yumsy handles and protects your information.

Effective September 8, 2026

In this policy

  1. 1The short version
  2. 2Data we handle
  3. 3How and why we use data
  4. 4Legal bases for processing
  5. 5When we share data
  6. 6International data transfers
  7. 7Retention
  8. 8Your choices and rights
  9. 9Security
  10. 10Children
  11. 11Changes to this Policy
  12. 12Contact us

Questions about your data?

stijn.vanwm@frontiq.eu
Jump to a section12 sections
  1. 1The short version
  2. 2Data we handle
  3. 3How and why we use data
  4. 4Legal bases for processing
  5. 5When we share data
  6. 6International data transfers
  7. 7Retention
  8. 8Your choices and rights
  9. 9Security
  10. 10Children
  11. 11Changes to this Policy
  12. 12Contact us

This Privacy Policy explains how Stijn Van Wijmeersch, trading as Frontiq (“Frontiq”, “we”, “us”, or “our”), handles personal data when you use the Yumsy iOS application (“Yumsy” or the “App”).

Controller and contact details

Frontiq
Rooseveltlaan 115
9420, Erpe-Mere, Belgium
Privacy email: stijn.vanwm@frontiq.eu

If you are in the European Economic Area (EEA), United Kingdom, or another jurisdiction that uses the term, the entity identified above is the controller of the personal data processed through Yumsy.

1. The short version

On first launch, Yumsy automatically creates a pseudonymous account identified by a random user ID. You can use Yumsy solo without providing contact details. If you choose household sharing, we ask you to verify an email address so that you and one invited partner can use separate private logins. We do not ask for your name, phone number, Apple ID, or payment-card details as part of the Yumsy account.

Yumsy stores and synchronizes your meal preferences, plans, favorites, and swipe activity so that the App can work reliably. In a shared household, the current weekly plan, grocery list (including custom items) and check-offs, and cooked status are visible to and synchronized between both members. We use Supabase to provide the account, email authentication, and backend, RevenueCat to manage subscription access, and PostHog’s EU service for product analytics and error diagnosis. Apple processes App Store purchases. Local reminder schedules remain on your device.

We do not sell personal data. We do not use third-party advertising SDKs, show personalized advertising, or track you across other companies’ apps or websites for advertising.

2. Data we handle

Account and authentication data

  • A random Supabase user ID and authentication session are generated automatically. This creates a pseudonymous guest account even though Yumsy does not ask you to register or provide contact details.
  • The random user ID is stored on your device and in Supabase. It is also used as your RevenueCat App User ID so subscription access can be associated with the correct Yumsy account.
  • If you secure an account or accept a household invitation, your verified email address and email-authentication events are processed by Supabase. Yumsy uses passwordless one-time codes rather than an App password.

Household-sharing data

  • Household identifier, owner or partner role, membership, and which member manages billing access.
  • The device time zone recorded when a household is created, which keeps shared calendar dates and widgets consistent between household members.
  • The email address an owner enters for an invitation. It is used to deliver or verify the invitation and to ensure only the intended verified email can accept it. Yumsy stores a one-way hash for the pending invitation rather than the raw invitation email or raw invitation token.
  • Invitation identifier, one-way token hash, creation, expiry, acceptance, and revocation information. Invitations expire after 72 hours and can be used only once.
  • For the current shared week: assigned recipes, serving-count snapshot, recipe-derived groceries, custom grocery item names and categories, grocery check-offs, cooked status, revision information, and the user IDs and timestamps associated with shared changes.

The two household members can see the shared current week, grocery progress, and cooked status. Meal preferences, swipe history, and billing controls remain private to the account that manages them unless this Policy says otherwise.

Meal preferences and onboarding choices

  • Household size or preferred serving count.
  • Diet and dietary preferences.
  • Cooking-time preferences and meal-planning goals.
  • Ingredients and allergens you choose to avoid.
  • Other recipe-personalization choices and onboarding completion status.
  • Whether you enabled Yumsy’s optional weekly reminder.

Allergy-related selections may reveal information about your health, and some dietary selections may reveal beliefs or other information you consider sensitive. We do not ask why you selected a preference. We use these choices only to provide the personalization you request. You can choose no exclusions and can change or remove your selections in the App.

Plans and App activity

  • Weekly meal plans, their dates and status, and recipes assigned to each day.
  • Favorite recipes.
  • Recipe swipe choices, including the direction, context (such as planning or replacing a meal), the affected day where applicable, and timestamps.
  • Custom grocery item names and categories that you add to a completed plan.
  • Identifiers and timestamps used to recover an interrupted plan-generation attempt.
  • When household sharing is enabled, mutation identifiers and revision numbers used to synchronize changes, resolve simultaneous edits, and safely retry offline actions without applying them twice.

Subscription and purchase-access data

  • The random App User ID described above.
  • Subscription product, entitlement, active or expired status, expiration and renewal information, grace period, billing issue, refund, ownership source, purchase or restore events, and store environment.
  • Plan-access grant identifiers, reason, and timestamp.
  • RevenueCat webhook event identifiers and processing status used to reconcile subscription changes and prevent duplicate processing. A household partner receives sponsored access but cannot manage or restore the owner’s purchase.

Apple processes your purchase and payment details. Yumsy and RevenueCat receive purchase and subscription status needed to unlock, restore, and manage access, but we do not receive your full payment-card or bank-account details.

Technical and service data

When Yumsy connects to its service providers, those providers may automatically receive routine technical information such as IP address, request time, device or app information, and service logs. They use this information to deliver, secure, monitor, and troubleshoot their services. The exact information and retention can depend on our production configuration and the provider’s terms.

Product analytics and error reports

Yumsy uses PostHog when analytics is enabled in a production build. PostHog receives the pseudonymous Yumsy user ID, sanitized screen names, feature-interaction events, and limited event properties such as swipe direction, selected-recipe count, grocery category, shared-list status, notification-permission result, and purchase-flow result. A completed-plan event may include the pseudonymous plan ID. We do not send the contents of meal preferences, custom grocery item names, email addresses, or household invite tokens as analytics event properties.

For error diagnosis, PostHog may receive exception messages, stack traces, Yumsy’s error context, and related technical details. Analytics and error events may also include automatically supplied app and device information such as device type, manufacturer and model, operating-system name and version, app name, version and build, bundle identifier, locale, time zone, session ID, and SDK version. GeoIP enrichment is disabled. Yumsy does not enable PostHog session replay and does not use PostHog for advertising or cross-app tracking.

Information you send us

If you contact us for support or a privacy request, we receive the contact details, message, and attachments you choose to send. This information is not added to your anonymous Yumsy account unless needed to handle your request.

Data kept locally on the device

  • Custom grocery items and grocery-item check-offs for solo plans. In a shared household, grocery items, check-offs, and cooked status are also synchronized and cached locally for offline use.
  • Local weekly-reminder settings and scheduled local notifications.
  • Current and upcoming dinner details used by optional iOS home-screen widgets. Yumsy copies the relevant recipe titles, links, timing, and public recipe images to storage shared by the App and its widget extension.
  • A secure recovery record for an interrupted plan request.
  • If you request account deletion, a temporary encrypted device record with a random recovery token and pseudonymous account ID. It is removed only after the server deletion is proven and this device finishes clearing account data.
  • If you choose to replace a guest or other signed-in account with a verified existing account, a temporary encrypted recovery record containing both authentication sessions and pseudonymous account IDs. This prevents a crash from deleting or stranding the wrong account and is cleared when the switch completes or is safely cancelled.
  • Account-scoped copies, pending shared changes, and caches used for offline and reliable App operation. These are cleared when Yumsy detects an account switch or when account deletion completes.

Yumsy uses local notifications and does not currently register an Apple push notification token. iOS controls notification permission. Some local user data is also synchronized as described above; this section does not mean that all Yumsy data is local-only.

3. How and why we use data

We use the data described above to:

  • Create and authenticate the pseudonymous Yumsy account.
  • Secure an account with verified email, create and validate household invitations, and manage owner or partner membership.
  • Personalize recipe suggestions and generate weekly meal plans.
  • Save, synchronize, restore, and display preferences, plans, favorites, and other App state.
  • Synchronize a household’s current dinners, grocery progress, and cooked status, including reliable offline retries and simultaneous-edit handling.
  • Process subscription access, purchases, and restorations.
  • Reconcile subscription lifecycle events and provide one sponsored household seat while preventing a partner from changing the owner’s billing.
  • Recover interrupted requests and prevent duplicate or abusive access grants.
  • Schedule the optional weekly reminder locally on your device.
  • Operate, secure, debug, and improve the reliability of Yumsy and its backend.
  • Understand feature use, onboarding and purchase funnels, subscription performance, app reliability, and errors through PostHog and RevenueCat.
  • Answer support and privacy requests.
  • Comply with legal obligations and establish, exercise, or defend legal claims.

Yumsy uses your selections to filter or rank recipes. This personalization does not produce legal effects or similarly significant effects about you.

4. Legal bases for processing

Where applicable law requires a legal basis, we rely on the following:

  • Performance of a contract or steps requested by you: to provide Yumsy’s core features, authenticate an optional verified account, provide household sharing, synchronize the account, and provide purchased or sponsored subscription access.
  • Legitimate interests: to keep the service secure and reliable, prevent abuse, recover interrupted operations, respond to support, diagnose errors, and understand feature and subscription performance. We balance these interests against your rights.
  • Consent: for optional local notifications and, where applicable law requires it, for allergy-related or other preference data treated as sensitive. You can withdraw consent through Yumsy’s settings, iOS settings, or account deletion. Withdrawal does not affect processing already performed lawfully.
  • Legal obligation: where processing is necessary to comply with applicable law, regulatory requests, tax or accounting requirements, or valid legal process.

Providing personalization and account data is optional, but some Yumsy features cannot work without the relevant information. A verified email is required only to create or accept a household invitation and to recover that private login. Notifications and household sharing are optional.

5. When we share data

We disclose personal data only as needed for the purposes described in this Policy:

  • Supabase (Supabase, Inc.) provides anonymous and email authentication, database, realtime synchronization, storage, and server-side functions. Yumsy email authentication, household membership and invitation records, preferences, plans, shared grocery and cooked activity, access records, subscription status, and user IDs may be processed there. Supabase privacy information.
  • RevenueCat (RevenueCat, Inc.) provides subscription and entitlement management, lifecycle webhooks, and related subscription analytics. It processes the billing user’s App User ID and purchase or subscription information. A household partner’s account is not used to restore or take ownership of the payer’s purchase. RevenueCat privacy information.
  • PostHog (PostHog, Inc.) provides EU-hosted product analytics and error tracking. It processes the pseudonymous Yumsy user ID, product-interaction and screen events, error reports, and app and device details described above. PostHog privacy information.
  • Apple provides the App Store, in-app purchase infrastructure, subscription management, the iOS operating system, and local notification controls. Apple handles information under its own privacy policy. Apple privacy information.

These providers may use approved subprocessors to deliver their services. They are permitted to process data for contracted services and their lawful provider obligations, subject to their agreements and applicable law.

We may also disclose data when reasonably necessary to comply with law or valid legal process, protect users or the service, investigate fraud or security incidents, or establish or defend legal claims. If the business is involved in a merger, financing, reorganization, sale, or transfer, data may be transferred subject to appropriate confidentiality and continued protection.

We do not sell personal data or share it for cross-context behavioral advertising. We do not disclose personal data to data brokers.

6. International data transfers

Our providers and their subprocessors may process data outside your country, including in the United States or other countries whose data-protection laws may differ from yours. Where required, we use an adequacy decision, Standard Contractual Clauses, provider data-processing agreements, or another lawful transfer mechanism and appropriate safeguards. You may contact us for more information about safeguards relevant to your data.

7. Retention

We keep personal data only for as long as needed for the purposes in this Policy, including providing the service, maintaining security, resolving disputes, and complying with legal obligations.

  • The pseudonymous account and synchronized preferences, plans, favorites, and swipe activity are generally kept while the account exists, unless you remove particular data through an available App feature.
  • A verified email and household membership are generally kept while the verified account or membership exists. Pending household invitations expire after 72 hours. Accepted, revoked, and long-expired invitation records, including their one-way hashes, are deleted after 90 days.
  • Shared plan, grocery, cooked, revision, and idempotency records are kept while needed to operate and protect the household sync service. Operational mutation receipts are deleted after 30 days.
  • Subscription status and RevenueCat customer data are kept while needed to provide, restore, and verify access and to meet fraud-prevention, contractual, accounting, or legal requirements. Terminal webhook delivery receipts and their error text are deleted after 90 days.
  • Analytics and error events already sent to PostHog are kept according to our configured PostHog retention settings and are then deleted or anonymized. Resetting the analytics identity on sign-out or account deletion prevents later events on that device from being associated with the previous Yumsy user ID; it does not by itself erase events already received by PostHog. You may ask us to delete those events as part of a privacy request.
  • An unarmed account-switch preparation expires after 24 hours. Once a switch is armed, its operational record remains until recovery finishes so a device crash cannot strand the accounts. Completion redacts the source and RevenueCat identifiers; the remaining destination/status receipt is deleted after 30 days.
  • An account-deletion preparation that never starts deletion expires after 24 hours. Once deletion starts, its private recovery record remains until the operation can be completed safely. On completion, Yumsy removes the account ID, household role, and billing result from that record. A minimal unlinkable tombstone made only from random operation/token-derived hashes and a completion time is retained so a device that was offline can still prove the deletion and clear its local copy.
  • Local data is generally kept until you clear or replace it, delete the Yumsy account, or uninstall the App. A non-personal public recipe cache may remain until iOS or the App removes it or you uninstall the App.
  • Support correspondence is kept only as long as reasonably needed to respond, maintain support records, and meet legal obligations.
  • Security logs and backups are retained according to operational and provider schedules and then deleted or overwritten. Deleted data may remain for a limited time in protected backups before aging out.

Apple retains App Store purchase records independently under its own policies and legal obligations. Deleting a Yumsy account does not delete Apple’s records.

8. Your choices and rights

In-App controls

  • Change or remove meal preferences and exclusions.
  • Clear or replace plan data through available App controls.
  • Create, revoke, or replace a pending partner invitation; remove a partner if you own the household; or leave the household if you joined as a partner.
  • Turn the weekly reminder off in Yumsy or disable notifications in iOS Settings.
  • Manage or cancel an Apple subscription through Apple’s subscription settings.
  • Delete the Yumsy account from Settings > Account & Data > Delete Account.

Account deletion deletes the requesting Supabase account and associated private preferences, favorites, swipes, access records, and account-scoped device data. It also requests removal of the RevenueCat customer record associated with that account’s App User ID and resets the analytics identity stored on the device. Previously received PostHog events remain subject to the retention and privacy request process described above. If a partner deletes their account, they leave the household without deleting the owner’s account, plan, or subscription. If the owner deletes their account, the shared household and shared plan data are deleted and the partner loses access to that household. The public recipe catalogue cache contains no user data and may remain.

RevenueCat can associate more than one App User ID with one customer. If the account being deleted is associated with a RevenueCat customer still used by another live Yumsy account (including the household payer), Yumsy retains that shared RevenueCat customer rather than erase the other account’s purchase record. The requesting Supabase account, membership, and account-scoped Yumsy data are still deleted. Apple retains App Store records independently in all cases.

Deleting the Yumsy account does not cancel an Apple subscription. Cancel or manage the subscription separately through Apple to prevent future renewal. Yumsy warns active subscribers and provides a link to Apple’s subscription management before deletion.

Privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, or a portable copy of your personal data; restrict or object to processing; withdraw consent; and appeal our response. You may also have a right not to receive discriminatory treatment for exercising a privacy right.

For a pseudonymous solo account, we may need information from the App or device to verify that a request relates to your account. A verified email may help us verify a household-sharing account. We will not collect more information than reasonably necessary for verification. Submit a request at stijn.vanwm@frontiq.eu. You may also use an authorized agent where applicable law permits it.

If you are in the EEA or United Kingdom, you may lodge a complaint with your local data-protection authority. We encourage you to contact us first so we can try to address your concern.

9. Security

We use reasonable technical and organizational measures designed to protect personal data. These include pseudonymous accounts, passwordless verified-email authentication for household members, encrypted network connections, single-use hashed invitation tokens, access controls, and database rules that limit private data to the authenticated user and shared data to current household members. No system is completely secure, so we cannot guarantee absolute security.

Protect access to your unlocked device and email account. If you use Yumsy only with an anonymous account, we may be unable to restore it if its local authentication session is permanently lost.

10. Children

Yumsy is not directed to children under 13, or the higher minimum age required for a child to consent to data processing where they live. We do not knowingly collect personal data from a child below the applicable age without legally valid permission. If you believe a child has provided personal data improperly, contact us at stijn.vanwm@frontiq.eu so we can investigate and delete it where required.

11. Changes to this Policy

We may update this Policy to reflect changes to Yumsy, our providers, or the law. We will update the effective date and provide additional notice in the App when required. If we seek to use previously collected data for a materially different purpose, we will provide notice and obtain consent where required.

12. Contact us

Questions, requests, or complaints about privacy may be sent to:

Frontiq
Rooseveltlaan 115
9420, Erpe-Mere, Belgium
Privacy email: stijn.vanwm@frontiq.eu
Back to top
Yumsy

Seven dinners, one relaxed week.

Explore

HomeSupport

Legal

Privacy PolicyTerms of Use

© 2026 Frontiq. All rights reserved.