YumRecall
Privacy Policy
Effective September 14, 2026
YumRecall helps adults remember restaurants, dishes, ratings, photos, comments, and other personal food experiences. This Privacy Policy explains what information YumRecall accesses or processes, why it is used, the third-party services involved, and the choices available to you.
Privacy and support contact: yummy.rate.app@gmail.com.
1. Information you provide
YumRecall may process information you choose to save, including:
- restaurant and venue names, addresses, categories, and saved coordinates;
- dish names, ratings, comments, visit dates, and visit history;
- photos you take or select for a food experience;
- account information made available through Firebase Authentication, such as your Firebase user ID, email address, display name, and connected sign-in methods when available;
- text you choose to send through the device sharing flow when reporting a problem.
Your core food history is saved locally on your device. When cloud backup or synchronization is active for your Firebase account, associated YumRecall data and backed-up photos are also stored in Firebase Firestore and Firebase Storage under that account.
2. Location and restaurant search
If you grant foreground location permission, YumRecall may use your current device location to find nearby restaurants. Location and search queries are sent through the YumRecall backend to Google Places for that request. YumRecall does not implement continuous background location tracking.
You can deny location permission and enter or search for a restaurant manually.
3. Photos and optional AI recognition
Photos you select or capture can be stored with food experiences and, when cloud backup is active, uploaded to Firebase Storage. Photos may contain personal information or metadata. Firebase photo download URLs may contain access tokens and should be treated as private.
AI dish recognition is optional and runs only after you explicitly choose Recognize for a newly selected photo. The image is sent through the YumRecall backend to Google Gemini with a generic dish-recognition request. YumRecall does not separately attach your email address, current location, restaurant name or address, comments, or saved history to that recognition request, although information visible inside the image itself is included in the image.
AI suggestions can be wrong. You can ignore, edit, or replace a suggestion and enter a dish manually.
4. Analytics and diagnostics
YumRecall uses optional product analytics to understand feature usage and improve the app. PostHog may receive selected feature events, app and platform information, coarse properties such as rating ranges or whether a photo/comment exists, and a pseudonymous installation ID. YumRecall does not deliberately send restaurant or dish names, addresses, comments, photos, email addresses, or precise location in analytics events. Session replay, screenshots, and input recording are disabled, and GeoIP enrichment is disabled by YumRecall.
YumRecall also uses optional Firebase Crashlytics diagnostics to help identify crashes and failures. Diagnostics may include app/runtime versions, device category, stack traces, sanitized error details, privacy-safe breadcrumbs, and a pseudonymous installation ID. YumRecall does not deliberately attach food history, photos, precise location, email addresses, restaurant/dish names, addresses, comments, or AsyncStorage contents to diagnostics.
Analytics and diagnostics can be turned off in Settings. Turning them off stops future collection by YumRecall for those features; it does not automatically erase records already received by the provider.
5. Authentication and service providers
YumRecall uses third-party services to operate specific features. Depending on what you use, these may include:
- Firebase Authentication, Firestore, Storage, Cloud Functions, Hosting, and Crashlytics;
- Google Sign-In and Google Places;
- Facebook Login;
- Google Gemini for an explicitly requested recognition action;
- PostHog for product analytics.
These providers may receive technical connection information such as IP address, device/browser information, timestamps, and request metadata as part of providing their services. Their own terms and privacy practices also apply to the information they process.
YumRecall does not sell your personal information. YumRecall currently has no advertising SDK or payment SDK.
6. How information is used
YumRecall processes information to:
- save and display your personal food history;
- back up and synchronize data associated with a cloud account;
- find nearby or searched restaurants;
- provide explicitly requested dish recognition;
- authenticate users and protect account access;
- improve product usability and reliability;
- investigate abuse, security, and operational failures;
- process account-deletion requests.
7. Retention and deletion
Local YumRecall data remains on a device until you delete it through the app, clear the app's data, or remove it through device controls. Deleting a YumRecall cloud account does not delete original photos in your phone's gallery or copies of YumRecall data that may still exist locally on another device.
Cloud food data and backed-up photos are retained while the associated YumRecall/Firebase account exists, unless you delete individual content sooner. You can request full account deletion in Settings → Delete account or, for Google/Facebook/email accounts, at yumrecall.web.app/delete-account.
Account deletion removes the associated Firebase Authentication identity, YumRecall Firestore user data, and the user's YumRecall Storage namespace after verification and processing. Processing normally completes within about 10 minutes, but temporary service failures can delay completion while the cleanup job retries.
For deletion reliability and abuse prevention, YumRecall keeps a minimal account-denial marker for seven days after completion. An opaque deletion receipt digest and timestamp may also remain for recovery of interrupted deletion flows; they do not contain the deleted account ID or food content.
YumRecall's current PostHog project reports a 12-month product-analytics retention window. PostHog analytics use a pseudonymous installation ID that is separate from your Firebase account ID. After YumRecall confirms account deletion on a device, the app removes that local analytics installation ID and clears its in-memory copy while preserving your analytics opt-out preference. If analytics is enabled later on the same device, a new anonymous installation ID is created so new activity is not appended to the previous installation timeline.
Historical PostHog records already received under the prior anonymous installation ID are not automatically matched to a Firebase account or erased by Firebase account deletion. They follow PostHog's provider-side retention and privacy processes. Exact automatic deletion timing may depend on PostHog's retention controls and is not guaranteed by YumRecall. Operational request logs, security records, Firebase Crashlytics diagnostics, and provider recovery copies may follow separate provider retention schedules. You can opt out of future analytics/diagnostics in Settings and contact yummy.rate.app@gmail.com with privacy or deletion questions.
8. Security
YumRecall uses platform and Firebase security controls, authenticated access for account data, HTTPS transport, and server-side API credentials for backend integrations. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.
9. Your choices
- use guest mode instead of connecting Google, Facebook, or email credentials;
- deny foreground location permission and enter restaurants manually;
- skip AI recognition and enter a dish manually;
- turn off analytics and crash diagnostics in Settings;
- edit or delete saved visits, dishes, restaurants, and account data;
- request full account deletion in the app or through the external deletion page where supported;
- contact yummy.rate.app@gmail.com with privacy questions or requests.
Depending on where you live, applicable law may provide additional access, correction, deletion, objection, or other privacy rights. Contact us to exercise a right that applies to you.
10. Age eligibility
YumRecall is intended for adults age 18 or older. It is not directed to children or teenagers under 18. If you believe an under-18 user has provided personal information to YumRecall, contact yummy.rate.app@gmail.com so the situation can be reviewed.
11. International processing
YumRecall's service providers may process information in countries other than the country where you live. Those providers use their own infrastructure and contractual/legal safeguards for cross-border processing.
12. Changes to this policy
This policy may be updated when YumRecall changes its features, providers, or data practices. Material changes will be reflected by updating the effective date and, when appropriate, by providing an in-app or release notice.
13. Contact
Privacy and support inquiries: yummy.rate.app@gmail.com.