Privacy Policy
This Privacy Policy explains what personal data we collect when you use simmr, why we collect it, who we share it with, and the choices and rights you have. It works together with our Terms of Use, which govern your use of the app.
1. Who we are & scope
This Privacy Policy applies to simmr however you install it — through Google Play or the Apple App Store — and to our related website at nestapps.ch. simmr is the only app this policy covers; we do not currently publish any other app.
The data controller responsible for your personal data is:
Emmanuel Janssens, trading as Nest Apps.
Switzerland.
Email:
admin@nestapps.ch
If you have any questions about this policy or how we handle your data, or if you want to exercise any of your privacy rights, contact us at the email address above.
Because we are established in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies to our processing. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the EU/UK General Data Protection Regulation (GDPR) also applies, and we process your data in line with it.
2. Account & authentication data
2.1 What we collect
- Email address (when you create a full account). You can also use simmr as a guest, in which case no email is collected until you choose to convert to a full account.
- Username / display name you choose, used to identify you to other members of your household group.
- Password, if you sign up with email and password. Passwords are handled and stored in hashed form by Supabase Auth; we never see or store them in plain text.
- Authentication tokens and session data issued when you sign in. These are stored on your device so you stay signed in, and are sent with each request to authenticate you.
-
Sign-in provider identifiers, if you sign in
with a third-party provider:
- Sign in with Google, we receive a Google identity/access token, which Supabase Auth uses to verify you and link your account.
- Sign in with Apple, we receive an Apple identity token and, if you allow it, your email address (which may be an Apple private-relay address) and your name. Your email is used to create or match your account; the name supplied during Apple sign-in is not stored on our servers.
- Onboarding and household details you provide, such as your household size and onboarding progress, used to set up the app for you and to apply one-time onboarding offers.
- Device and install identifiers, a per-install identifier and a per-launch session identifier, used together with your account to operate and analyse the service (see Section 7.2 on analytics).
2.2 Theme preference
Your selected theme (light/dark) is stored only on your device and is not sent to or stored on our servers. The app currently runs in English only; we do not collect or store a language/locale preference.
2.3 Why we use it and our legal basis
We use this data to create and secure your account, keep you signed in, let you share recipes and plans within your household group, and tailor onboarding. Our legal basis is the performance of our contract with you (providing the account and the service you sign up for). We also rely on our legitimate interest in keeping the service secure and preventing fraud and abuse, including contacting you about account, security, and billing matters.
2.4 Where it is stored, and an important visibility note
Account and authentication data is stored in our backend (Supabase, EU-hosted) and, for session tokens, on your device. Please be aware that your username and email address are technically readable by other users of the service through our backend access rules. If you would prefer not to expose an email address, you can use a guest account or an Apple private-relay address. We retain account data for as long as your account exists; to delete your account, email admin@nestapps.ch.
3. Content you create
When you use simmr you create content that we store on your behalf so you and the other members of your household group can use it. This includes:
- Recipes (titles, descriptions, servings, prep/cook times, instructions, tags, and the source URL you imported from) and their ingredient lists.
- Meal plans and the entries you schedule on them.
- Pantry items, including any expiry dates you record.
- Shopping lists and their items.
- Prep plans and the make-ahead steps generated for your week.
- Custom ingredients you add to the catalogue.
- Groups (households), memberships, and invitations — these control who can see and edit the content above.
- Feedback you choose to send us (a free-text message and an optional rating). Note that feedback is stored against your household group and is visible to the other members of that group, not only to us.
Most of this content is shared within your household group: anyone you add to a group can view and edit the recipes, plans, pantry, and lists in it.
3.1 Images
When you add a photo to a recipe or pantry item — by taking a picture, choosing one from your gallery, or importing it from a recipe's web page — that image is stored in our Supabase Storage so it can be shown as the recipe's cover or pantry photo. Stored images are kept for the lifetime of the recipe and are removed when you delete the recipe or clear its image.
These stored images sit in a public-read bucket: anyone who has the image's (unguessable) link can open it without signing in. Please keep this in mind before adding photos that contain anything sensitive.
This is different from the temporary copy used during AI recipe import. When you scan or import a recipe, the image bytes (or page text) are sent to our AI provider only to extract a structured recipe; that transient copy is processed in memory and discarded once parsing is done — see Section 6 on AI processing. We do not keep those parse-request images, but the cover image you save with a recipe is stored as described above.
3.2 Why we hold it and how long
We process the content above to provide simmr's core features (meal planning, pantry, shopping, cooking, and group sharing) under our agreement with you; feedback is handled on the basis of our legitimate interest in improving the product and only when you choose to send it.
We keep your content for as long as it exists in the app. Group content is removed when the group it belongs to is deleted, or when the related record (for example a recipe) is deleted. We do not currently run an automatic time-based deletion of this content. You can ask us to delete your data by emailing admin@nestapps.ch.
4. Purchase & subscription data
When you buy a Nest Plus subscription or the one-time "Bring Your Own Key" (BYOK) unlock, we receive and store the information needed to confirm the purchase and to grant you the matching features on every device where you sign in.
4.1 What we store
- The product identifier (SKU) of what you bought, and whether it is a monthly subscription, a yearly subscription, or the one-time BYOK unlock.
- The purchase token and package name from Google Play, or the transaction and original-transaction identifiers and bundle id from the Apple App Store, used to verify the purchase with the store and to detect duplicate or fraudulent claims.
- Your entitlement and subscription state: whether it is active, the billing period (monthly/yearly), whether auto-renew is on, the current period's start and expiry/renewal date, the number of household group slots, any introductory-offer or trial details, and whether the purchase came from the store's sandbox or production environment.
- The raw purchase receipt/notification the store sends us (from Google Play or Apple), kept as an audit record so we can validate entitlements and resolve billing disputes.
4.2 The BYOK unlock
The BYOK unlock is a one-time, non-consumable purchase. Buying it grants a server-side entitlement that lets the app use your own large-language-model API key. That entitlement record is purchase data and is covered by this section; the API key itself is something different, it is stored only on your device and is never sent to us (see Section 11.4 on security).
4.3 What we never see
We never see or store your card number, CVV, billing address, or any cardholder details. All charges, renewals, price changes, and refunds are handled entirely by Google Play or the Apple App Store, we only receive the confirmation that a purchase or change happened and what it entitles you to.
4.4 Why and on what basis
We process this data to deliver the features you paid for across your devices and household group (performance of our contract with you), to prevent purchase fraud and abuse (our legitimate interest), and, where applicable, to meet accounting and tax obligations (legal obligation). These records are stored on our Supabase backend; the store keeps its own authoritative copy. Sub-processors are listed in Section 9, and retention is described in Section 10.
5. Advertising & consent
On the free tier on Android, simmr shows occasional ads. The free tier on iOS does not currently show ads, and paying subscribers and BYOK-unlock buyers never see ads on either platform (see Section 5.3). This section describes what is collected when ads are shown.
5.1 What applies when ads are shown
Free-tier users on Android see occasional interstitial ads served through Google AdMob (the Google Mobile Ads SDK), shown at natural break points such as after an AI scan or saving a recipe. When ads are active, AdMob may collect your device's advertising identifier (Android Advertising ID / Apple IDFA) and related ad-request and diagnostic data per Google's ads policy. We also keep a local, on-device counter to limit how often an ad can appear; that counter stays on your device and contains no personal data. Ad serving on iOS is currently not enabled.
5.2 Consent in the EU, UK and Switzerland
Where required (the EU/EEA, UK, and Switzerland), we present Google's User Messaging Platform (UMP) consent form before any interest-based ads are shown, and your consent choice is passed to and held by Google's SDK. Without the required consent, you are not shown personalised advertising.
5.3 Paid and BYOK users are exempt
Paying subscribers and users who purchase the BYOK unlock do not
see ads, and no advertising identifiers are collected from them.
Their entitlement to an ad-free experience is recorded as a flag in
our backend (hide_ads), separate from any advertising
data.
We will update this policy and the "Last updated" date if the platforms or conditions under which advertising is shown change, so this section reflects what is actually live at any time.
6. Recipe import & AI processing
When you import a recipe — by taking or choosing a photo, pasting text, or giving us the address (URL) of a recipe page — we use an AI model to read that input and turn it into a structured recipe. The same AI processing also powers a few related features: generating make-ahead prep steps for your planned week, and estimating ingredient unit conversions. This section explains what is sent, to whom, and what is and is not kept.
6.1 What is sent for AI processing
Depending on what you import, the content sent to the AI model may include:
- the photo(s) you captured or selected (sent as image data);
- the text you pasted, or the text extracted from a recipe web page;
- a short summary of your pantry — on-hand ingredient names, quantities, units and expiry flags (a limited list) — which we include with each server-side import so the AI can match the recipe to what you already have;
- for the "prepare in advance" feature, the recipes planned for your week (their names, instructions and ingredients), so the AI can generate combined prep steps;
- for unit conversion, a single ingredient name and unit.
6.2 Where it goes — Claude via our server (default)
On the free and Plus tiers, your import is sent through our server to Anthropic's Claude AI model for parsing, using our own API key. We do not keep the content of these requests — the image and text are processed to produce your recipe and then discarded. We do retain a small record of the call itself (such as which feature was used, the AI model, token counts and cost, and, for URL imports, only the website's host name — never the full address or the recipe content) so we can monitor usage and cost.
Anthropic processes this data as our sub-processor. Under Anthropic's commercial API terms, Anthropic states that it does not use API traffic to train its models. This is a contractual commitment by Anthropic governing how they handle the data we send; it is not something we enforce technically. Anthropic processes data in the United States; see Sections 9 and 11.2 for the safeguards that apply.
6.3 Bring your own key (BYOK)
If you purchase the BYOK unlock, you can supply your own AI provider key. In that case the import request is sent directly from your device to the provider you choose — Anthropic (Claude), or any OpenAI-compatible service you configure, including OpenAI, OpenRouter, or a local/self-hosted model on your own network. The same kinds of content described in Section 6.1 are sent, but to your chosen provider rather than through us.
Your API key is stored only on your device, in the platform's secure storage, and is never transmitted to or seen by us. When you use BYOK, the handling, retention and training practices that apply to your import content are governed by whichever provider you have chosen and your own account with them — not by us. We are not responsible for a third-party AI provider's availability, output, retention practices, or charges.
One exception: when you import from a URL, the recipe page is still fetched by our server even in BYOK mode (see Section 6.4). So for URL imports, the page address passes through us before the recipe content is sent to your chosen provider.
6.4 Fetching third-party recipe pages
When you import by URL, our server retrieves the public web page at the address you provide so its text can be parsed into a recipe. We fetch only the page you ask us to and use it only to produce your recipe. If that page references a recipe image, we may download it and store it with your recipe (see Section 3.1 on images). We are not responsible for the content of third-party websites, and you are responsible for ensuring you have the right to import and use the recipes you bring in.
7. Diagnostics & analytics
To keep simmr stable and to understand how its features are used, we collect two kinds of operational data. Neither is used for advertising profiling and neither builds a marketing profile of you.
7.1 Crash and error diagnostics (Sentry)
When the app hits an error or crashes, we send a diagnostic report to Sentry, our error-monitoring provider. These reports are processed on Sentry's EU (Germany) infrastructure. A report typically includes:
- the error or exception type, its message, and the stack trace (and, on Android, native crash data);
- technical context automatically attached by the SDK: operating-system version, device model and manufacturer, the app version, the build environment, and device state such as available memory, storage, and screen orientation;
- internal diagnostic tags that identify which operation or backend call failed (for example an API operation name and a database or authentication error code).
We do not intentionally send your email, username, or any recipe, message, or other content you create to Sentry. In one specific diagnostic path we attach a hashed (non-reversible) identifier for your account, group, and subscription so we can correlate a fault without exposing who you are. We also sample a small share of performance traces to help find slow operations. Crash diagnostics start at app launch; we rely on them under our legitimate interest in providing a reliable, working app.
7.2 Product analytics
We collect first-party usage analytics in our own Supabase database to understand which features are used, to measure things like onboarding and purchase funnels and retention, and for an operational check on which app versions are still in active use before we change the backend. Each analytics event includes:
- the event itself (for example a screen view with a coarse screen label, an app-lifecycle event, an onboarding or paywall step, or a recipe, cook, meal-plan, shopping, or pantry action, sometimes with the relevant item's identifier, counts, or durations);
- the app version, the platform (Android or iOS), a per-launch session identifier, and a persistent install identifier for your installation;
- an account identifier once you are signed in (this is left empty for guests and on pre-login screens).
These events do not include free text, your email, or your recipe content. This is first-party product analytics, not advertising profiling: the data stays in our own backend, is not used to target ads to you, and is not sold or shared with advertising networks. We rely on it under our legitimate interest in operating and improving the app. There is currently no in-app opt-out for this first-party analytics; if you object to this processing, contact us at admin@nestapps.ch (see Section 11.1). Analytics events are currently retained indefinitely; if you delete your account, the account identifier on your past events is cleared (the events are anonymised rather than removed).
8. How we use your data
We use the data described above only for the purposes below. We do not sell your personal data, and we do not build advertising or marketing profiles about you ourselves.
- Provide the core simmr service. Create and authenticate your account (including guest accounts and Google or Apple sign-in), keep your recipes, meal plans, pantry, and shopping lists in sync across your devices, and share that content within your household group.
- Parse and generate content. Import and structure recipes from photos, links, or pasted text; normalise ingredients against your pantry; generate make-ahead prep steps; and estimate unit conversions. These features send the relevant content to an AI provider, as described in Section 6.
- Enforce free-tier limits and entitlements. Apply daily and monthly AI import quotas and prep-generation caps on the free tier, track your one-time onboarding bonus scan, and grant the right features to the right members of your household based on your subscription.
- Validate purchases and prevent fraud. Verify and acknowledge subscriptions and the BYOK unlock with Google Play and the Apple App Store, keep your entitlements current across devices, and guard against the same store purchase being claimed by more than one account. We never see or store your card details.
- Diagnose crashes and errors. Collect crash reports, error details, and technical context (such as device model, OS version, and app version) so we can find and fix bugs and keep the app reliable.
- Improve the app through product analytics. Use first-party usage data (such as screen views, feature usage, and onboarding and purchase funnels) to understand how simmr is used, fix problems, and decide what to build next. We also use the app-version data to know when older app versions are safe to stop supporting before we change the backend.
- Communicate about the service. Send you important account, security, and billing-related messages where needed to operate the service.
We show ads on the Android free tier and do not profile you for advertising ourselves. Any ad personalisation is handled by the ad provider (Google AdMob) under its own terms and, where required in the EU, the EEA, the UK, and Switzerland, only after you make a consent choice (see Section 5). Subscribing to Nest Plus or buying the BYOK unlock removes ads.
9. Third parties we share data with
We share data only with the service providers (sub-processors) we need to run simmr, and only the data each one needs to do its job. We do not sell your personal data. The list below shows every third party that can receive data, what it is used for, where it processes data, and whether it is currently active.
9.1 Backend and storage
- Supabase — our hosting backend (database, authentication, file storage, and server functions). It holds your account, content, recipe and pantry images, purchase records, product-analytics events, feedback, and session data. Hosted in the EU (Ireland) under Supabase's data-processing agreement. Active.
9.2 Recipe parsing and AI features
- Anthropic (Claude API) — on the free and Plus tiers, when you import a recipe (photo, pasted text, or URL), generate make-ahead prep steps, or convert units, the relevant content is sent through our server to Anthropic's Claude model. This can include the image bytes or page text, the names and quantities of ingredients on hand in your pantry, and, for the prep planner, the recipes in your planned week. Processed in the United States. Anthropic's commercial terms state it does not train on API traffic; this is a contractual commitment, not something we enforce technically. Active.
- Your own AI provider (Bring Your Own Key / BYOK) — if you buy the BYOK unlock and configure your own key, your device calls your chosen provider directly and our backend never sees that AI traffic. Supported options are Anthropic, an OpenAI-compatible endpoint such as OpenAI or OpenRouter, or a local/self-hosted model you point the app at. The data sent is the same as above; the provider, its region, and its data and training practices are the ones you choose. One exception: for URL imports the web address still passes through our server even in BYOK mode. Active (BYOK unlock only).
9.3 Purchases and sign-in
- Google Play / Google Play Developer API — validates your Android purchases and sends us real-time notifications about subscription changes (renew, cancel, refund). Receives the package name, product ID, and purchase token. Operated globally by Google. Active (Android).
- Apple App Store (App Store Server API and notifications) — validates your iOS purchases and sends us notifications about subscription changes. Receives the transaction identifiers and app bundle ID. Operated globally by Apple. Active (iOS billing).
- Google Sign-In — if you sign in with Google, Google returns an identity token to our authentication backend so we can create or match your account. Operated globally by Google. Active.
- Sign in with Apple — if you sign in with Apple, Apple sends an identity token and, on first sign-in, the email (which may be a private-relay address) and name you choose to share, to our authentication backend. Operated globally by Apple. Built into the app; iOS provisioning of this sign-in method is still being finalised.
9.4 Advertising (free tier)
- Google AdMob — serves interstitial ads to free-tier users and may collect your advertising identifier and ad diagnostic data. Operated globally by Google. Active on Android free tier; ads are currently not served on iOS.
- Google User Messaging Platform (UMP) — shows the consent form in the EU, UK, and Switzerland and records your ads-consent choice. Operated globally by Google. Active where ads are shown.
Paying subscribers and BYOK-unlock buyers do not see ads, and no advertising identifier is collected for them.
9.5 Diagnostics and analytics
- Sentry — receives crash and error reports so we can fix bugs. These include technical context (OS version, device model, app version, error codes) and, in one path, a hashed and therefore non-identifying user, group, or subscription reference. We do not send your email, recipes, or messages. Processed in the EU (Germany). Active.
- Product analytics — this is first-party: usage and behavioural events (screen views, onboarding and purchase funnels, recipe, cooking, meal-plan, shopping, and pantry actions, plus an install identifier and a per-session identifier) are stored in our own Supabase backend, not sent to a third-party analytics provider. Hosted in the EU (Ireland). Active.
We do not send data to any of these services beyond what is necessary to provide the features described above.
10. Retention & deleting your account
We keep your data only as long as we need it to run simmr, meet legal obligations, or resolve disputes. The windows below describe how long different kinds of data are kept.
10.1 How long we keep things
- Your account and content (profile, recipes, meal plans, pantry and shopping lists, prep plans, custom ingredients, group memberships, and saved recipe/pantry images) are kept for as long as your account exists. When you ask us to delete your account we aim to remove this data within 30 days.
- Billing and subscription records (store purchase and subscription identifiers, entitlement state, and the raw purchase receipts from Google Play / Apple) may be retained for up to 7 years where we are required to keep them for accounting and tax compliance. The authoritative copy of your purchase also lives in Google's and Apple's own systems, which we do not control.
- Crash and error reports (handled by Sentry, in the EU) are kept for a limited period (typically around 90 days) set by our error-monitoring configuration.
- Recipe-import images. When you import a recipe, the image you scan is sent for parsing and is not stored by us after the request completes. This is different from a cover or pantry photo you save to a recipe or item: a saved image is stored for the life of that recipe or item (see Section 3.1) and is deleted when you delete the recipe/item or clear its photo.
- Product analytics (the usage events described in Section 7.2) are currently kept indefinitely to understand how the app is used over time. When your account is deleted, the account identifier on past analytics events is removed so those events can no longer be linked to you, but the de-identified events themselves are retained.
10.2 Deleting your account
The app does not currently include a self-service "delete account" button. You can ask us to delete your account at any time by emailing admin@nestapps.ch from, or referencing, the email address on your account. We action deletion requests manually and confirm when they are complete.
Deleting your account removes your profile and the household content tied to your account — recipes, meal plans, pantry and shopping lists, prep plans, custom ingredients, saved recipe and pantry images, and your group memberships. Preferences stored only on your device (such as your theme choice and any locally cached settings) are removed when you sign out and uninstall the app; they never reach our servers.
Some records are kept after deletion where the law requires it or where we have an overriding legitimate interest:
- Billing records needed for tax and accounting compliance, for up to 7 years as described in Section 10.1.
- De-identified analytics and aggregate data that no longer identifies you, as described in Section 10.1.
- Crash and error reports already collected, which age out on their own retention schedule (around 90 days).
If you are the sole administrator of a shared household group, you may need to delete the group (or transfer or remove other members) before your account can be fully removed, so that other members are not left without access. We will guide you through this when you contact us.
You can also request access to, correction of, or a copy of your data — see Section 11.1. These requests are currently handled manually by email.
11. Your rights, transfers, children & security
11.1 Your rights
simmr is operated from Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies. If you are in the EU/EEA or the UK, the GDPR (or UK GDPR) also gives you rights over your personal data. Depending on where you live, you have some or all of the following rights:
- Access — ask what personal data we hold about you and get a copy.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your account and associated data.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing we carry out on the basis of our legitimate interests (for example product analytics).
- Portability — receive the data you provided in a portable format.
To exercise any of these rights, email admin@nestapps.ch. We currently fulfil access, deletion, and portability requests manually on receipt of your email; the app does not yet provide a self-service export or in-app "delete account" button. We aim to respond within 30 days.
If you are in the EU/EEA, the UK, or Switzerland and believe we have not handled your data properly, you may also lodge a complaint with your national data-protection authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
11.2 International transfers
Our backend (Supabase) is hosted in the EU (AWS, Ireland), and our crash and error diagnostics (Sentry) are hosted in the EU (Germany). Some of the third parties we rely on process data outside the EU/Switzerland:
- Anthropic (recipe and meal-plan parsing) processes data in the United States.
- Google (purchase verification, sign-in, and, on the Android free tier, advertising and consent) and Apple (App Store purchase verification and Sign in with Apple) operate globally, including outside the EU/Switzerland.
- If you use "Bring Your Own Key" (BYOK) with a hosted provider such as OpenAI or OpenRouter, your recipe content is sent to that provider, which may be located in the United States.
These transfers take place under the relevant provider's own safeguards, such as the EU Standard Contractual Clauses or equivalent measures.
11.3 Children
simmr is not directed at children under 13 (or under 16 in the EU/EEA and UK), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email admin@nestapps.ch and we will delete it.
11.4 Security
We protect your data with appropriate technical and organisational measures:
- In transit: traffic between the app and our backend and sub-processors is encrypted with TLS. The one exception is that, if you choose to point BYOK at a self-hosted AI server on your own device or local network, the app permits a plain (non-TLS) connection to that local address; all other BYOK endpoints are forced to HTTPS.
- At rest: data stored in our backend benefits from the managed disk encryption provided by Supabase and its cloud infrastructure.
- BYOK keys: any API key you provide for "Bring Your Own Key" mode is stored only on your device, in the platform's secure storage (Android Keystore / iOS Keychain), and is never transmitted to our servers. Your simmr sign-in session token is stored using the app's standard on-device storage.
- Server secrets: our own keys and credentials are held as backend environment secrets and are never exposed to the app.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data using industry-standard practices.
12. Changes & contact
12.1 Changes to this policy
We update this policy when we add or change features, add a new service provider, or otherwise change how we handle your data. The "Last updated" date at the top of this page always reflects the current version. When changes are material, we notify you in-app or by email before they take effect. We encourage you to review this page periodically.
12.2 Contact
For any privacy question, to exercise your rights (access, correction, deletion, restriction, objection, or portability), or to raise a complaint, contact the controller, Emmanuel Janssens, trading as Nest Apps: admin@nestapps.ch.
If you are in the EU, EEA, UK, or Switzerland, you may also lodge a complaint with your national data-protection authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC).