Updated: August 23, 2026

Privacy Policy

YumDay is an account-based family recipe and meal planning app. This policy explains what is stored in Supabase, what stays on the device, and when content leaves the device.

Kitchen data stored in Supabase

Recipes, categories, fridge items, cart, orders, member names and preferences are stored in Supabase, isolated per kitchen. Recipe images live in private kitchen storage and are readable only by active members of that kitchen through short-lived signed URLs.

Using AI by choice

With BYOK, selected text or images go directly from the device to the configured OpenAI-compatible Provider. With official AI, selected content goes directly from the device to OpenRouter without passing through Supabase; Supabase only keeps the account credit projection, SharedAiKey hash, and usage reconciliation. See AI Data Notice.

Account-bound official AI entitlement

Official AI entitlement is tied to the account email and isolated per platform: the service stores credit limits, credit ledgers, purchase operations, SharedAiKey hashes and status, key-level reconciliation, and necessary risk data. Key plaintext stays in device secure storage. It does not store prompts, request images, AI outputs, or per-request telemetry.

Diagnostics and analytics

The app has no behavioral analytics and does not automatically upload third-party crash reports. User-exported local diagnostics are redacted and exclude business content, images, API keys, recovery codes, full URLs, local file paths, and request headers.

Data transfer

Signing in with the same account restores the current kitchen data on another device. .yumday is an optional user-exported plaintext file that may contain selected member profiles, orders, and images; anyone holding the file can read it, so share and store it through trusted channels.

Contact us

For privacy questions, email yumday@aid0g.com. Do not email API keys, recovery codes, full transaction receipts, or private images.