Version 2026-10-04

KIM, WON-BEE (Australian sole trader; ABN 87 684 039 341) operates YUMORY. For privacy questions, access or deletion requests, contact 0xwaeb.zip@gmail.com.

Your food journal stays on your device

YUMORY stores your food and product names, reactions, notes, places, dates, barcode matches and selected or captured photos in the app’s private local storage. The journal does not sync to Supabase or this backend, and account creation does not upload or back up existing records. Deleting an individual entry removes its record and the app’s unshared image files. Clearing app storage or uninstalling removes the local journal; keep any photos you need separately.

If you choose Export in Settings, the app creates a ZIP containing your journal records and available images, then lets you choose another app or destination using Android’s share sheet. That destination receives the exported data under your control and its own privacy practices. Account credentials are not included. If you choose Import, the app reads the compatible ZIP you select and copies supported records and photos into private local storage; the archive is not sent to this service. Deleting the journal or account does not remove copies you have already exported.

Camera and images

The app requests camera access when you choose to take a photo. Android’s photo picker provides only the images you select. YUMORY does not send journal photos to its account or billing backend.

On-device processing and Google ML Kit

Google ML Kit processes scans and cutouts on your device; journal images are not uploaded for this processing. It can download models and sends Google technical data over HTTPS: device/app details, installation/device identifiers, timing, API configuration, input/output sizes, feature versions, events and errors. Google uses this data for diagnostics and usage analytics. See Google’s privacy policy and ML Kit’s data disclosure.

Optional restaurant and address lookup

If you enable location in the camera and grant permission, YUMORY uses a fresh foreground location when you take a photo. Coordinates are sent over HTTPS to OpenStreetMap’s Overpass service to suggest nearby restaurants and their available addresses. Overpass also receives normal network metadata such as your IP address. General street addresses are not looked up automatically. Photos and journal text are not included. The app does not keep a coordinate history or track location in the background. The restaurant/address text you accept is stored locally with your catch and included if you export it. You can edit or remove the place, disable lookup in the camera, or revoke location permission in Android settings. Place data is © OpenStreetMap contributors, available under the ODbL.

Product lookup

When a barcode is not already available locally, the app sends that barcode to Open Food Facts. If no product is found and the Korean lookup service is configured, it next queries FoodSafetyKorea's C005 barcode-linked product service. These providers receive the barcode and normal connection information such as your IP address. Only product identity, such as name, manufacturer or brand, category and quantity when available, is cached locally. Barcode lookup does not download product photos or upload your journal images. FoodSafetyKorea C005 is a historical dataset and may not identify newer products. See Open Food Facts privacy information and FoodSafetyKorea data services. Data-source information is available in the app's settings.

Photo product suggestions

Barcode scanning and Latin/Korean text recognition run on the original photo on your device. If a barcode cannot identify a product, the app can send a short product search phrase to Open Food Facts. Photos and full OCR text are not uploaded. Address and phone-like lines are excluded from search. Providers receive normal connection metadata such as your IP address. Query digests and product candidates are cached locally. OCR candidates are linked to a product only after you confirm them; similar names alone do not merge past reactions.

Optional Supabase account

Email and password sign-up and sign-in requests go directly to Supabase Auth over HTTPS. Supabase stores the account email, password authentication information, user ID, sign-in identities, session information and the terms and privacy versions sent at sign-up. The app stores its session credentials in encrypted local storage so you can remain signed in. Passwords are not sent to YUMORY’s billing or deletion server. Account data is separate from your local food journal. Supabase also processes technical authentication and security logs. See Supabase’s privacy policy.

If you choose Google sign-in, Google shares an ID token and basic account information such as your email and profile with YUMORY and Supabase Auth. Supabase validates the token and stores your account identity. YUMORY keeps only its encrypted Supabase session on your device; this does not upload your food journal. Google’s privacy policy also applies to account selection.

Authentication emails

When Resend (Plus Five Five, Inc.) is enabled for email confirmation or password reset, Supabase Auth sends the authentication message through that service. This involves your recipient email address, sender information, subject and message content, including a time-limited authentication link or code, and sending, delivery and bounce information. This email service does not upload or back up your food journal or photos.

Our sending domain uses the Tokyo region in Japan. Resend stores message and delivery data in the United States and uses disclosed subprocessors for delivery, security and abuse prevention; some messages may undergo security checks. On the current Free plan, email and log data is retained for 30 days and backups for 7 days. Remaining customer data is deleted within 90 days after the operator terminates its Resend service. Legal or security records and copies held by your email service may follow separate retention rules. Deleting your YUMORY account does not instantly erase all email copies. Contact YUMORY support for access or deletion questions. Do not send passwords or authentication links or codes.

Provider information: Resend privacy policy, data processing agreement, subprocessors, and retention information.

Public app content

YUMORY checks this public service for cosmetic catalog information, decorative images and announcements. These requests contain no account token, journal photos or catch details. The hosting provider receives normal connection metadata such as IP address. Validated content is cached privately on the device for offline use. This route does not grant purchases or change journal allowances.

Photo allowances and subscriptions

For the first 7 local calendar days after installation, photo additions are unlimited. After that, free use allows 5 photo additions per protected quota day. This welcome allowance is not a paid subscription trial. Quota counters and the protected clock stay on the device; clock or time-zone changes do not reset them, and an offline restart can delay the next allowance. The monthly Photo subscription, when available, provides unlimited photo additions while valid. Studio, Plus and the cosmetic shop are currently hidden. The wallet, rewards and coin-unlocked cosmetics are stored locally and retained, but are not a cash balance. Allowance checks do not upload your journal.

Google Play purchases and restoration require the original YUMORY account and purchasing Google account. The app sends a temporary account access token and Google Play purchase tokens to this backend; it verifies the account with Supabase Auth and the purchase with Google. For new purchases the app provides Google an SHA-256 hash of the account ID, which the backend compares with Google's receipt. Supabase stores the SHA-256 purchase-token hash, account ID, product, purchase type, and claim time to prevent another account from reusing the purchase. Raw Play tokens are not stored in that table. Older receipts without an account identifier can restore only an existing binding to the same YUMORY account. An unbound legacy receipt requires support verification before it can be linked; a copied purchase token alone cannot establish ownership. The app caches the verified subscription tier, expiry, renewal status, server verification time and a device boot/time anchor locally. Offline access lasts only until the earlier of the verified paid expiry or 72 hours after verification, and requires the same phone boot. Reconnect after a phone restart. Failed network checks do not extend access; a successful verification can update or remove access and advance the protected quota clock.

When Play verification is enabled, the backend uses Upstash Redis to limit request volume. It sends short-lived request counters and a server-keyed pseudonymous client identifier, not purchase tokens, email addresses, photos or journal content. Counters expire after 60 seconds; provider security logs may follow the provider's retention policy. Without a working shared limiter, Play verification is unavailable. See Upstash privacy information.

Retention, deletion and choices

Local journal data remains until you delete it on the device. Deleting catches also clears the app-owned export cache and local product-search cache, but does not reset local attendance, rewards or photo allowances. Copies already shared or saved outside the app remain with their destination. Request account deletion in the app or on this website. The service verifies the current account, revokes refresh sessions and deletes the Supabase Auth identity. Google Play subscriptions must be cancelled separately; account deletion does not cancel them and is not a refund request. Hashed Play purchase ownership records retain the former account ID to prevent another account reclaiming the purchase. Contact support about these records. Existing access tokens may remain valid until expiry; sensitive backend operations verify the current account and its active session; signed-out, banned and deleted accounts are refused. Website deletion cannot erase device files or copies already shared.

Provider backups, security records and payment records can remain under provider retention rules or applicable obligations. YUMORY has no cloud journal database, but maintains the account-linked purchase ownership and subscription records described above. YUMORY adds no advertising SDK or separate app analytics service and does not sell personal data. ML Kit diagnostics are described above. Contact 0xwaeb.zip@gmail.com for access, correction or deletion questions, including if you cannot sign in.

Access, correction and privacy complaints

For access or correction requests, or a complaint about how we handle personal information, contact YUMORY support at 0xwaeb.zip@gmail.com. Describe your request or concern and the relevant account, if any. Do not send passwords, authentication links or codes, or purchase tokens. We may request the minimum information needed to verify your identity. We will assess the request or investigate the complaint, explain our response and available actions, and provide an update if more time is needed. Where the Australian Privacy Act applies and its complaint criteria are met, you may complain to the OAIC. See OAIC complaint information.

개인정보 접근·정정·불만 접수

개인정보 접근·정정 요청이나 처리에 대한 불만은 YUMORY 지원 이메일 0xwaeb.zip@gmail.com로 보내 주세요. 요청 또는 문제와 관련 계정(있는 경우)을 설명하되 비밀번호, 인증 링크·코드, 구매 토큰은 보내지 마세요. 필요한 경우 최소한의 본인 확인을 요청하고, 요청을 검토하여 조사 결과와 가능한 조치를 안내합니다. 검토에 시간이 더 필요하면 진행 상황을 안내합니다. 호주 Privacy Act가 적용되고 OAIC의 접수 요건에 해당하면 OAIC에 불만을 제기할 수 있습니다. OAIC 불만 접수 안내.

Security and changes

HTTP API requests made directly by the YUMORY app and these web pages use HTTPS. Privileged account deletion keys stay on the server; the app and deletion website receive only public project configuration and user session tokens. No system can guarantee absolute security. This policy describes the current implementation; changes to data processing will be reflected here and in the app’s linked policy.