Privacy Policy

Applies to simmr, our household meal-planning and pantry app · Last updated

This Privacy Policy explains what personal data we collect when you use simmr, why we collect it, who we share it with, and the choices and rights you have. It works together with our Terms of Use, which govern your use of the app.

1. Who we are & scope

This Privacy Policy applies to simmr however you install it — through Google Play or the Apple App Store — and to our related website at nestapps.ch. simmr is the only app this policy covers; we do not currently publish any other app.

The data controller responsible for your personal data is:

Emmanuel Janssens, trading as Nest Apps.
Switzerland.
Email: admin@nestapps.ch

If you have any questions about this policy or how we handle your data, or if you want to exercise any of your privacy rights, contact us at the email address above.

Because we are established in Switzerland, the Swiss Federal Act on Data Protection (FADP) applies to our processing. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the EU/UK General Data Protection Regulation (GDPR) also applies, and we process your data in line with it.

2. Account & authentication data

2.1 What we collect

2.2 Theme preference

Your selected theme (light/dark) is stored only on your device and is not sent to or stored on our servers. The app currently runs in English only; we do not collect or store a language/locale preference.

2.3 Why we use it and our legal basis

We use this data to create and secure your account, keep you signed in, let you share recipes and plans within your household group, and tailor onboarding. Our legal basis is the performance of our contract with you (providing the account and the service you sign up for). We also rely on our legitimate interest in keeping the service secure and preventing fraud and abuse, including contacting you about account, security, and billing matters.

2.4 Where it is stored, and an important visibility note

Account and authentication data is stored in our backend (Supabase, EU-hosted) and, for session tokens, on your device. Please be aware that your username and email address are technically readable by other users of the service through our backend access rules. If you would prefer not to expose an email address, you can use a guest account or an Apple private-relay address. We retain account data for as long as your account exists; to delete your account, email admin@nestapps.ch.

3. Content you create

When you use simmr you create content that we store on your behalf so you and the other members of your household group can use it. This includes:

Most of this content is shared within your household group: anyone you add to a group can view and edit the recipes, plans, pantry, and lists in it.

3.1 Images

When you add a photo to a recipe or pantry item — by taking a picture, choosing one from your gallery, or importing it from a recipe's web page — that image is stored in our Supabase Storage so it can be shown as the recipe's cover or pantry photo. Stored images are kept for the lifetime of the recipe and are removed when you delete the recipe or clear its image.

These stored images sit in a public-read bucket: anyone who has the image's (unguessable) link can open it without signing in. Please keep this in mind before adding photos that contain anything sensitive.

This is different from the temporary copy used during AI recipe import. When you scan or import a recipe, the image bytes (or page text) are sent to our AI provider only to extract a structured recipe; that transient copy is processed in memory and discarded once parsing is done — see Section 6 on AI processing. We do not keep those parse-request images, but the cover image you save with a recipe is stored as described above.

3.2 Why we hold it and how long

We process the content above to provide simmr's core features (meal planning, pantry, shopping, cooking, and group sharing) under our agreement with you; feedback is handled on the basis of our legitimate interest in improving the product and only when you choose to send it.

We keep your content for as long as it exists in the app. Group content is removed when the group it belongs to is deleted, or when the related record (for example a recipe) is deleted. We do not currently run an automatic time-based deletion of this content. You can ask us to delete your data by emailing admin@nestapps.ch.

4. Purchase & subscription data

When you buy a Nest Plus subscription or the one-time "Bring Your Own Key" (BYOK) unlock, we receive and store the information needed to confirm the purchase and to grant you the matching features on every device where you sign in.

4.1 What we store

4.2 The BYOK unlock

The BYOK unlock is a one-time, non-consumable purchase. Buying it grants a server-side entitlement that lets the app use your own large-language-model API key. That entitlement record is purchase data and is covered by this section; the API key itself is something different, it is stored only on your device and is never sent to us (see Section 11.4 on security).

4.3 What we never see

We never see or store your card number, CVV, billing address, or any cardholder details. All charges, renewals, price changes, and refunds are handled entirely by Google Play or the Apple App Store, we only receive the confirmation that a purchase or change happened and what it entitles you to.

4.4 Why and on what basis

We process this data to deliver the features you paid for across your devices and household group (performance of our contract with you), to prevent purchase fraud and abuse (our legitimate interest), and, where applicable, to meet accounting and tax obligations (legal obligation). These records are stored on our Supabase backend; the store keeps its own authoritative copy. Sub-processors are listed in Section 9, and retention is described in Section 10.

5. Advertising & consent

On the free tier on Android, simmr shows occasional ads. The free tier on iOS does not currently show ads, and paying subscribers and BYOK-unlock buyers never see ads on either platform (see Section 5.3). This section describes what is collected when ads are shown.

5.1 What applies when ads are shown

Free-tier users on Android see occasional interstitial ads served through Google AdMob (the Google Mobile Ads SDK), shown at natural break points such as after an AI scan or saving a recipe. When ads are active, AdMob may collect your device's advertising identifier (Android Advertising ID / Apple IDFA) and related ad-request and diagnostic data per Google's ads policy. We also keep a local, on-device counter to limit how often an ad can appear; that counter stays on your device and contains no personal data. Ad serving on iOS is currently not enabled.

5.2 Consent in the EU, UK and Switzerland

Where required (the EU/EEA, UK, and Switzerland), we present Google's User Messaging Platform (UMP) consent form before any interest-based ads are shown, and your consent choice is passed to and held by Google's SDK. Without the required consent, you are not shown personalised advertising.

5.3 Paid and BYOK users are exempt

Paying subscribers and users who purchase the BYOK unlock do not see ads, and no advertising identifiers are collected from them. Their entitlement to an ad-free experience is recorded as a flag in our backend (hide_ads), separate from any advertising data.

We will update this policy and the "Last updated" date if the platforms or conditions under which advertising is shown change, so this section reflects what is actually live at any time.

6. Recipe import & AI processing

When you import a recipe — by taking or choosing a photo, pasting text, or giving us the address (URL) of a recipe page — we use an AI model to read that input and turn it into a structured recipe. The same AI processing also powers a few related features: generating make-ahead prep steps for your planned week, and estimating ingredient unit conversions. This section explains what is sent, to whom, and what is and is not kept.

6.1 What is sent for AI processing

Depending on what you import, the content sent to the AI model may include:

6.2 Where it goes — Claude via our server (default)

On the free and Plus tiers, your import is sent through our server to Anthropic's Claude AI model for parsing, using our own API key. We do not keep the content of these requests — the image and text are processed to produce your recipe and then discarded. We do retain a small record of the call itself (such as which feature was used, the AI model, token counts and cost, and, for URL imports, only the website's host name — never the full address or the recipe content) so we can monitor usage and cost.

Anthropic processes this data as our sub-processor. Under Anthropic's commercial API terms, Anthropic states that it does not use API traffic to train its models. This is a contractual commitment by Anthropic governing how they handle the data we send; it is not something we enforce technically. Anthropic processes data in the United States; see Sections 9 and 11.2 for the safeguards that apply.

6.3 Bring your own key (BYOK)

If you purchase the BYOK unlock, you can supply your own AI provider key. In that case the import request is sent directly from your device to the provider you choose — Anthropic (Claude), or any OpenAI-compatible service you configure, including OpenAI, OpenRouter, or a local/self-hosted model on your own network. The same kinds of content described in Section 6.1 are sent, but to your chosen provider rather than through us.

Your API key is stored only on your device, in the platform's secure storage, and is never transmitted to or seen by us. When you use BYOK, the handling, retention and training practices that apply to your import content are governed by whichever provider you have chosen and your own account with them — not by us. We are not responsible for a third-party AI provider's availability, output, retention practices, or charges.

One exception: when you import from a URL, the recipe page is still fetched by our server even in BYOK mode (see Section 6.4). So for URL imports, the page address passes through us before the recipe content is sent to your chosen provider.

6.4 Fetching third-party recipe pages

When you import by URL, our server retrieves the public web page at the address you provide so its text can be parsed into a recipe. We fetch only the page you ask us to and use it only to produce your recipe. If that page references a recipe image, we may download it and store it with your recipe (see Section 3.1 on images). We are not responsible for the content of third-party websites, and you are responsible for ensuring you have the right to import and use the recipes you bring in.

7. Diagnostics & analytics

To keep simmr stable and to understand how its features are used, we collect two kinds of operational data. Neither is used for advertising profiling and neither builds a marketing profile of you.

7.1 Crash and error diagnostics (Sentry)

When the app hits an error or crashes, we send a diagnostic report to Sentry, our error-monitoring provider. These reports are processed on Sentry's EU (Germany) infrastructure. A report typically includes:

We do not intentionally send your email, username, or any recipe, message, or other content you create to Sentry. In one specific diagnostic path we attach a hashed (non-reversible) identifier for your account, group, and subscription so we can correlate a fault without exposing who you are. We also sample a small share of performance traces to help find slow operations. Crash diagnostics start at app launch; we rely on them under our legitimate interest in providing a reliable, working app.

7.2 Product analytics

We collect first-party usage analytics in our own Supabase database to understand which features are used, to measure things like onboarding and purchase funnels and retention, and for an operational check on which app versions are still in active use before we change the backend. Each analytics event includes:

These events do not include free text, your email, or your recipe content. This is first-party product analytics, not advertising profiling: the data stays in our own backend, is not used to target ads to you, and is not sold or shared with advertising networks. We rely on it under our legitimate interest in operating and improving the app. There is currently no in-app opt-out for this first-party analytics; if you object to this processing, contact us at admin@nestapps.ch (see Section 11.1). Analytics events are currently retained indefinitely; if you delete your account, the account identifier on your past events is cleared (the events are anonymised rather than removed).

8. How we use your data

We use the data described above only for the purposes below. We do not sell your personal data, and we do not build advertising or marketing profiles about you ourselves.

We show ads on the Android free tier and do not profile you for advertising ourselves. Any ad personalisation is handled by the ad provider (Google AdMob) under its own terms and, where required in the EU, the EEA, the UK, and Switzerland, only after you make a consent choice (see Section 5). Subscribing to Nest Plus or buying the BYOK unlock removes ads.

9. Third parties we share data with

We share data only with the service providers (sub-processors) we need to run simmr, and only the data each one needs to do its job. We do not sell your personal data. The list below shows every third party that can receive data, what it is used for, where it processes data, and whether it is currently active.

9.1 Backend and storage

9.2 Recipe parsing and AI features

9.3 Purchases and sign-in

9.4 Advertising (free tier)

Paying subscribers and BYOK-unlock buyers do not see ads, and no advertising identifier is collected for them.

9.5 Diagnostics and analytics

We do not send data to any of these services beyond what is necessary to provide the features described above.

10. Retention & deleting your account

We keep your data only as long as we need it to run simmr, meet legal obligations, or resolve disputes. The windows below describe how long different kinds of data are kept.

10.1 How long we keep things

10.2 Deleting your account

The app does not currently include a self-service "delete account" button. You can ask us to delete your account at any time by emailing admin@nestapps.ch from, or referencing, the email address on your account. We action deletion requests manually and confirm when they are complete.

Deleting your account removes your profile and the household content tied to your account — recipes, meal plans, pantry and shopping lists, prep plans, custom ingredients, saved recipe and pantry images, and your group memberships. Preferences stored only on your device (such as your theme choice and any locally cached settings) are removed when you sign out and uninstall the app; they never reach our servers.

Some records are kept after deletion where the law requires it or where we have an overriding legitimate interest:

If you are the sole administrator of a shared household group, you may need to delete the group (or transfer or remove other members) before your account can be fully removed, so that other members are not left without access. We will guide you through this when you contact us.

You can also request access to, correction of, or a copy of your data — see Section 11.1. These requests are currently handled manually by email.

11. Your rights, transfers, children & security

11.1 Your rights

simmr is operated from Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies. If you are in the EU/EEA or the UK, the GDPR (or UK GDPR) also gives you rights over your personal data. Depending on where you live, you have some or all of the following rights:

To exercise any of these rights, email admin@nestapps.ch. We currently fulfil access, deletion, and portability requests manually on receipt of your email; the app does not yet provide a self-service export or in-app "delete account" button. We aim to respond within 30 days.

If you are in the EU/EEA, the UK, or Switzerland and believe we have not handled your data properly, you may also lodge a complaint with your national data-protection authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).

11.2 International transfers

Our backend (Supabase) is hosted in the EU (AWS, Ireland), and our crash and error diagnostics (Sentry) are hosted in the EU (Germany). Some of the third parties we rely on process data outside the EU/Switzerland:

These transfers take place under the relevant provider's own safeguards, such as the EU Standard Contractual Clauses or equivalent measures.

11.3 Children

simmr is not directed at children under 13 (or under 16 in the EU/EEA and UK), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email admin@nestapps.ch and we will delete it.

11.4 Security

We protect your data with appropriate technical and organisational measures:

No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data using industry-standard practices.

12. Changes & contact

12.1 Changes to this policy

We update this policy when we add or change features, add a new service provider, or otherwise change how we handle your data. The "Last updated" date at the top of this page always reflects the current version. When changes are material, we notify you in-app or by email before they take effect. We encourage you to review this page periodically.

12.2 Contact

For any privacy question, to exercise your rights (access, correction, deletion, restriction, objection, or portability), or to raise a complaint, contact the controller, Emmanuel Janssens, trading as Nest Apps: admin@nestapps.ch.

If you are in the EU, EEA, UK, or Switzerland, you may also lodge a complaint with your national data-protection authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC).