Privacy policy
What we collect
Your name and profile photo from the Google, Apple or Facebook account you sign in with, and the meals you add — a name, a day, a time of day, and a photo if you add one. If you manage a brand account, the product names and links you upload, used to generate meal ideas for your catalogue. If you turn on notifications, a device token so we can send them. No location, no contacts, no tracking of you across other apps or sites.
Crashes
When YUM crashes, we receive a crash report through Firebase Crashlytics — what went wrong, and what device and app version it happened on — so we can fix it. Those reports are tied to your account id so we can tell one person’s crash from another’s, and to nothing else. We do not use an analytics SDK: we do not record which screens you open, which features you use, or where you are.
Who can see it
Your name, photo and meals are visible to your friends, and to any brand or Monster account you follow. Monsters are our two AI accounts that post automatic meal ideas — one vegan, one not — and you can unfollow either one at any time if you only want to see vegan meals, for example. Three narrow exceptions: anyone holding your friend code can see your name and photo when they open your link, so they know who invited them; anyone you send a meal link to can open that one meal; and when a friend likes one of your meals, the friends who follow their likes can be shown that meal and your name, which is how people find each other here. You can switch that last one off under Privacy on the You tab. One technical caveat, because it is the honest way to describe how photos work: a photo you upload is stored at its own unguessable web address, and anyone who has that exact address can open it. That is what lets an avatar show next to a friend request and a shared meal open for the person you sent it to. Nothing is listed publicly, indexed by search engines, or shared further.
Family
If you’re in a family group, you can share any meal you see — from a friend, a Monster, or a brand — with your family. If everyone votes yes, that meal is posted on each family member’s own account. We keep a record of who shared it and how each person voted, so the group can see how a meal got there.
How suggested meals are made
Some meals in the feed are generated automatically by our Monster accounts or from a brand’s product catalogue, and are always labelled as such. Making them may involve sending product names — never your personal data — to a third-party AI service to find likely combinations.
Tapping a brand’s product link
Brands can list what they sell, and a meal can link to a product. When you tap one of those links we record the tap — which product and brand, which screen you tapped it from, which meal it was attached to, the time, the country the request came from, and whether you are on a phone or a desktop — before sending you on to the brand’s own site. We do not attach your account to it, so it tells the brand how many people tapped, not who did. Once you arrive on the brand’s site you are on their website, under their privacy policy, not ours.
What we do not do
We do not sell your data, we do not show ads, and we do not use your data to train anything.
Where it lives
Your data is stored using Google Firebase — Firestore for meals and accounts, Firebase Authentication for signing in, Cloud Storage for photos, Cloud Messaging for notifications, and Crashlytics for crash reports — on Google Cloud infrastructure.
Reports you file
If you report a meal or a person, we keep a record of the report — who filed it, who it was about, and what was posted at the time — so we can act on it. Those records outlive account deletion, because a record of why an account was removed has to.
Messages you send us
If you write to us — the support form in the app, the one at yum.monster/support, or plain email — we keep what you sent and the email address you gave, because that is what answering you means. We use it for nothing else, and we delete it once the thing you asked about is settled.
Deleting it
Delete your account from the You tab and we remove your profile, all of your meals, and you from everyone’s friend list. If you cannot sign in, ask us at yum.monster/support and we will do it for you — you do not need to be able to open the app.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it — write to hello@yum.monster and we will handle it. If you think we have mishandled your data, you also have the right to complain to Romania’s data protection authority, ANSPDCP (dataprotection.ro).
Age
YUM is meant for people 16 and older. We don’t knowingly collect data from anyone younger, and if we learn we have, we delete it.
Changes to this policy
If we change this policy in a way that matters, we will tell you in the app before it takes effect. The date at the top always reflects the current version.
Contact
Questions or requests: yum.monster/support, or hello@yum.monster. A person reads both, within 24 hours.
Last updated 2 September 2026.