Privacy Policy
Last updated 2026-09-13
This policy explains what yumd collects, what it is used for, and how you stay in control. The shortest version: your original photos never leave your phone, your profile is private by default, and we do not sell personal data.
1. What we collect
Account: email (from Apple, Google, or typed by you), display name, @handle, avatar, a short bio and a city if you fill them in. Sign in with Apple may provide a relay email instead of your real one.
Content: dish cutouts, names, notes, ratings, prices, waiting times, taste tags, venue names and coordinates if you attach them; menus; who you follow and who follows you; menus you pin.
Purchases: if you buy a plan, Apple handles payment and RevenueCat stores the plan status (plan type, expiry date, whether it renews) tied to your account id so the app knows you have a plan. Our servers do not hold this status and never receive card numbers or payment details.
Photos: yumd takes the photo and removes the background on the phone itself. The original stays on your device and is never uploaded. Only the cutout is sent to our servers — to back it up, sync it across your devices, and show it to the people you allow.
Device: model, OS and app version, time zone, language, and a push token if you enable notifications.
Usage: events such as “saved a dish” or “searched”, tied to a pseudonymous key rather than your identity, and only when you have turned analytics consent on.
2. What it is used for
Running yumd: signing you in, saving and syncing your menu, showing it to the people you allow, sending notifications you enabled (for example when someone follows you), and handling purchases through the App Store.
Improving the product: understanding which features get used, only from pseudonymous data and only with your consent.
AI name suggestions, if you turn them on: a cutout or text read from a menu board may be sent to an AI provider to guess the dish name. This is optional and outside the capture-and-save path: with it off, yumd still captures and saves normally.
3. We do not sell personal data
No user-level row ever leaves our system. The only thing that may be shared with partners is an aggregate index by region, dish and day — and only for groups of at least 20 people, so nobody can be traced back. This requires a separate consent, distinct from analytics consent, and is off by default.
We use no advertising networks and do not track you across other apps.
4. Who we share with
RevenueCat (purchase validation): receives your account id and the Apple receipt to determine your plan; it never receives photos, menus or your email.
People you allow: public menus and accepted followers see what you have made public. Private menus are visible only to you, followers included.
Service providers: Apple (sign-in, push, App Store), Google (sign-in), Cloudflare (cutout storage, networking), Vercel (website). They process data on our instructions and under their own policies.
Legal: when the law requires it, or to protect users’ rights and safety.
5. How long we keep it
Content and account: until you delete them. A menu is a memory built over time, so we do not delete it just because you have not opened the app in a while.
When you delete your account: all identifying data (account, profile, content, devices, consents) is deleted. Usage events are anonymised — your identity is permanently removed from them. Evidence of App Store transactions is kept without identity, for tax and refund obligations.
6. Your rights
In the app: edit your profile, switch menus between private and public, remove followers, turn each notification type on or off, turn analytics consent and aggregate data sharing on or off, and delete your account.
By email: request a copy of your data, a correction, or deletion — write to hello@yumd.app. We reply within 30 days.
We record when and to which policy version you consented, so that consent can be demonstrated under Vietnam’s Decree 13/2023/ND-CP and the GDPR.
7. Children
yumd is not intended for anyone under 13 and does not knowingly collect children’s data. If you believe it has, tell us and we will delete it.
8. Security
Data travels over encrypted connections. Cutouts live in a private bucket and are served only through signed, expiring links to people who are allowed to see them. Originals never leave the phone, so there is no copy on our side to leak.
9. International transfers
Our servers and providers may be located in countries other than where you live. We choose providers with equivalent data-protection commitments.
10. Changes
This policy may be updated; the date at the top changes accordingly. Significant changes will be announced in the app.