Back to home

Legal

Privacy Policy

This Policy explains what the NomNom mobile application, operated by Nom Apps LLC, collects and why. · Version 2026-06-01 · Effective June 1, 2026

This Privacy Policy explains what NomNom, operated by Nom Apps LLC, actually collects, why, where it goes and the choices you have. It was written from an audit of the app's implementation.

1. Information you give us

Account: email address, password (stored only as a salted Argon2 hash — we cannot read it), display name, username, custom Nom name, optional invite code, and the version/date of the Terms and Privacy Policy you accepted.

Profile and goals: goal (lose, maintain, gain, improve), age, sex (optional), height, current weight, starting weight, goal weight, weekly pace, activity level, dietary preference, allergies, and preferred units. From these we calculate calorie, protein, carbohydrate, fat, fiber and water targets, which you can edit.

Nutrition logs: foods you log (name, brand, serving, quantity, meal, nutrients, source, barcode), water entries, exercise entries (activity, duration, estimated calories burned), body-weight entries, and saved meals.

Meal photos: if you use photo scanning, the photo is sent for AI analysis and stored privately in your account so it can be shown next to that log entry.

Feeling check-ins: the standardized feeling states you pick (for example "tired", "sick", "happy") and, if you type one, your short free-text note. These are stored per day so Nom can react and so your history can show patterns. We do not use them to diagnose anything.

Nom customization: the shape, color, outfit and accessories you equip; achievements and levels.

Social: friend requests, friendships, blocks, reactions, invite codes and the automatic achievement posts shared with friends according to your privacy toggles. Your weight, calorie totals, food entries, photos and feeling check-ins are never shared with friends.

Support messages you send to us.

2. Information collected automatically

Device and app data: your device's time-zone offset (so "today" is calculated correctly), platform (iOS/Android/web), app version, and a device push-notification token if you enable notifications.

Usage analytics: first-party event names (for example "food_logged", "water_logged", "paywall_viewed") with limited properties, stored in our own database. We deliberately strip body weight and calorie values from analytics events and we do not use third-party advertising or analytics SDKs.

AI usage counts: how many AI scans, descriptions and suggestions you used each day, to enforce free-tier limits.

Server logs: standard request logs (timestamps, endpoints, status codes, errors) kept for security and debugging. We avoid writing food, weight or feeling content into logs.

Cookies: the mobile app does not use cookies. The web preview stores your session token and appearance preference in local device storage only.

3. Location

NomNom does not request device location and does not store coordinates. Camera and photo-library access are optional and requested only when you choose photo scanning; we do not read photo location metadata. If a location feature is ever added, it will be opt-in and this Policy will be updated first.

4. How we use information

To run the Service: authenticate you, calculate targets, show your logs, charts, streaks, Nom reactions, widgets and weekly reports.

To provide AI features you request: identify foods in a photo, parse typed meals, suggest meals that fit your remaining targets and stated diet/allergies, and map a free-text feeling note to standard states when keyword matching fails.

To operate subscriptions: confirm your Premium entitlement and unlock premium features.

To send notifications you opted into: meal, water and streak reminders (scheduled on your device) and push notifications about friend activity and achievements (sent through our push provider).

To keep the Service safe: prevent abuse, enforce limits, debug errors, and respond to support requests.

To improve NomNom using aggregated, de-identified usage statistics. We do not sell personal information and we do not use it for targeted advertising.

5. Who receives your information

Emergent — hosts the NomNom backend, MongoDB database and private object storage, and operates the gateway through which AI requests and push notifications are relayed.

OpenAI (via the Emergent gateway) — receives meal photos, typed meal descriptions, your remaining nutrition targets, dietary preferences, allergies, today's food names and free-text feeling notes only when you use those features. We do not send your name, email or identifiers. Provider terms govern their retention; we do not permit use of your data to train their models where the gateway allows us to opt out.

USDA FoodData Central and Open Food Facts — receive only the search text or barcode you look up, not your identity.

RevenueCat, Apple App Store and Google Play — process subscription purchases. RevenueCat receives an anonymous app user ID equal to your NomNom account ID and purchase receipts; Apple/Google hold your payment details, which we never see.

Apple Push Notification service, Firebase Cloud Messaging and Emergent's push relay (SuprSend) — receive your device token and the notification text in order to deliver notifications you enabled.

Other users — only your username, display name, Nom appearance and, subject to your privacy toggles, streak, achievements and goal-completion posts.

Authorities or others when required by law, to protect rights and safety, or as part of a merger or acquisition (you would be notified).

6. Where information is stored

Data is stored in Emergent-hosted infrastructure. Transfers to the providers above may involve other countries; we rely on their contractual safeguards. If you are in the EU/UK, the legal bases we rely on are performance of our contract with you (running the Service), your consent (camera/photos, notifications, optional feeling check-ins and free text) and our legitimate interests (security, abuse prevention, aggregated analytics). You may withdraw consent at any time in the app.

7. How long we keep information

Your account data, logs, photos and check-ins are kept while your account is active so your history remains available. Search and barcode results are cached without your identity for 7–30 days. Server logs are kept for up to 90 days. When you delete your account (section 9), personal data is deleted promptly, typically within 30 days from backups. We may keep de-identified aggregates and records we must retain for tax, legal or fraud-prevention purposes (for example subscription transaction records held by the stores and RevenueCat).

8. Security

All traffic uses HTTPS. Passwords are hashed with Argon2. API access requires a signed session token and every request is scoped to your own account. Meal photos are private and served only with your session. Widgets receive only your Nom name, current Nom appearance, and today's calorie and protein numbers — never your password, session token or history. No system is perfectly secure; contact support@nomappsllc.com if you suspect a problem.

9. Your choices and rights

Access and correct: everything you entered can be viewed and edited in the app (You → Personal information, My Goal, Daily Targets; Log; Progress). Request a machine-readable export at support@nomappsllc.com.

Delete: You → Account → Delete account permanently deletes your account, profile, food/water/exercise/weight logs, meal photos, feeling check-ins, saved meals, AI usage records, analytics events, friendships, posts, reactions and invite records. Referral records that link a friend to your invite are anonymized. Active store subscriptions must be cancelled in the App Store or Google Play separately.

Notifications: manage toggles in You → Notifications and in your device settings. Camera/photos: manage in device settings. Feeling check-ins and free text are optional and can be cleared for the day.

Depending on where you live you may also have rights to object, restrict processing, port your data, or complain to a supervisory authority. Contact support@nomappsllc.com; we respond within 30 days. We do not discriminate against you for exercising your rights.

10. Sensitive information

Weight, food intake, exercise, feeling check-ins and information such as "sick" may be considered health-related in some jurisdictions. We collect them only because you enter them to use the Service, use them solely to provide the features described here, never sell them, and never share them with friends, advertisers or data brokers.

11. Children

NomNom is not directed to children under 16. We do not knowingly collect personal information from children below that age; if you believe a child has provided data, contact support@nomappsllc.com and we will delete it.

12. Changes to this Policy

We will post the new version and effective date in the app. For material changes we will show you the updated Policy in the app before you continue, and where required ask for your consent again.

13. Contact

Nom Apps LLC, Green Bay, Wisconsin, United States. Privacy questions and requests: support@nomappsllc.com.

Questions? Email us at support@nomappsllc.com. NomNom is a product of Nom Apps LLC.