Privacy Policy

Last updated: May 2026

1. Data Controller

The data controller for your personal data is:

As a small business, we are not required to appoint a Data Protection Officer. For all privacy-related queries, contact us at the email above.

2. What Data We Collect

CategoryDataLegal Basis (GDPR)
AccountEmail address, display name, language preferenceContract performance (Art. 6(1)(b))
Recipes & contentRecipes, ingredients, steps, images, tags, translationsContract performance (Art. 6(1)(b))
Meal planningMeal plans, entries, shopping listsContract performance (Art. 6(1)(b))
Social interactionsLikes, bookmarks, comments, follows, collectionsContract performance (Art. 6(1)(b))
BillingSubscription tier, billing period, payment status (no card details — stored by Stripe)Contract performance (Art. 6(1)(b))
Feed personalisationFeed impressions, interactions (views, dwell time, likes)Legitimate interest (Art. 6(1)(f)) — improving content relevance
AnalyticsPage views, referrer (collected by Umami, cookie-free, no personal identifiers)Legitimate interest (Art. 6(1)(f)) — service improvement
AuthenticationClerk session data (auth tokens, OAuth provider info)Contract performance (Art. 6(1)(b))

3. How We Use Your Data

We use your data to:

We do not sell your personal data. We do not use your data for third-party advertising profiling.

4. Sub-processors (Third-Party Services)

We share your data with the following service providers, each acting as a data processor under GDPR:

ServicePurposeData SharedLocation
ClerkAuthentication & identityEmail, OAuth tokensUS (SCCs in place)
StripePayment processingEmail, billing address, payment methodUS (SCCs in place)
NeonDatabase hostingAll application dataEU (AWS eu-central-1)
CloudflareCDN, security, image storage (R2)Request metadata, imagesGlobal (EU-compliant)
UmamiPrivacy-friendly analyticsNo personal data (cookie-free, no IP storage)EU

Where data is transferred outside the EEA (Clerk, Stripe), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

5. Data Retention

DataRetention Period
Account & content dataDuration of your account + 30 days after deletion request
Billing records7 years after the end of the subscription (tax obligations)
Feed interaction data12 months (rolling window)
Analytics data (Umami)24 months (aggregated, no personal identifiers)
Consent recordsDuration of account + 3 years
Abuse/moderation reportsDuration of account + 1 year

6. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

How to exercise your rights

We will respond to all requests within 30 days. If a request is complex, we may extend this period by an additional 60 days with prior notice.

7. Cookies and Tracking

Essential cookies (no consent required)

Non-essential tracking

We do not use advertising cookies, tracking pixels, or social media trackers.

8. Children's Data

Yummoria is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, please contact us at privacy@yummoria.com and we will delete the account promptly.

9. Automated Decision-Making

Yummoria uses automated algorithms to personalise your "For You" feed based on your interaction history, preferences, and community trends. This personalisation does not produce legal effects or similarly significant effects on you. You can switch to the chronological "Following" feed at any time to avoid algorithmic ranking.

10. Data Security

We protect your data with:

11. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days in advance.

12. Supervisory Authority

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence.

13. Contact

For privacy-related questions, contact us at privacy@yummoria.com or by post at: Mateusz Dabrowski IT, ul. Firletki 25F/1, 05-462 Wiazowna, Poland.