Privacy policy
This policy explains what the NoCrumb app collects, where it is stored and who else receives it. In short: most of what you enter stays on your phone, and the few things that leave it are listed below.
Who we are
NoCrumb is made and run by an individual developer. For privacy questions, to use your rights or to ask for deletion, write to harishanbalagandev@gmail.com.
Stays only on your phone
The app keeps the following in a database on your device. It is never sent to NoCrumb or to anyone else.
- Your profile: app language, severity, country, state and the last restaurant city you opened.
- Your chef card note.
- Your scan history: the label text you analysed and the result, with the matched ingredients.
- Saved product lookups, so a product you scanned before works offline.
- Symptom check-ins: energy, bloating, pain, stool type, skin flare-ups and your own notes. These are never sent to NoCrumb.
- Your weekly meal plan and grocery ticks.
- Your daily reminder settings. Reminders are local notifications created by the app on your phone, not by a server.
- Restaurant lists downloaded for offline use, and the places you saved.
- Any AI provider API key you add (see AI meal plans), kept in your phone's secure storage.
Photos and camera images used to read an ingredient label or barcode are processed on your phone. The text recognition runs on the device, and the image is not uploaded.
Location
If you allow it, the app reads your location once to sort restaurants by distance and to draw a dot on the map. This is used on your phone only. It is never sent to NoCrumb or to any third party by the app. You can refuse or revoke the permission in your phone settings and the app keeps working.
Signing in and your account
Signing in is optional. It is needed only to post reviews, flag reviews, report or suggest restaurants and submit products. You can sign in with Google or, on iPhone, Apple. When you do, NoCrumb's server (hosted by Supabase) stores:
- your email address (if you use Sign in with Apple's private relay, this is the relay address) and the sign-in provider and its user ID;
- a display name. We generate one such as "crumb-1a2b" when you join, and you can change it. Other signed-in people see this name next to your reviews. Your email is never shown to them.
Google and Apple handle the sign-in itself. NoCrumb never sees a password. We ask only for your email address and basic profile from Google and your email from Apple.
What you post
When signed in, anything you choose to submit is stored on NoCrumb's server, tied to your account:
- Restaurant reviews: whether you reacted to gluten, kitchen practices you report (such as a separate tawa or fryer) and an optional comment. Reviews are visible to other people with your display name.
- Review flags you raise on other people's reviews.
- Restaurant suggestions: name, city, country, address, cuisines, a proposed tier, and optional phone and notes.
- Restaurant reports: a reason and optional note about a listing.
- Product submissions: barcode, product name, brand and ingredient text for products that other sources lack.
Once a moderator approves a product submission, its barcode, name, brand and ingredient text are shown to all app users as community data, without your name. An approved restaurant suggestion becomes a public listing, also without your name.
The server also keeps a record of when you posted, so it can enforce daily limits that stop abuse. A volunteer moderator may review suggestions and submissions, and an administrator can hide content or suspend an account that breaks the rules. A moderation log records which moderator took which action on which item. It does not store your content.
Requests to NoCrumb's server without signing in
Even when signed out, the app contacts NoCrumb's server (Supabase) to:
- download restaurant lists for the country and city you open, and the list of cities;
- check a scanned barcode against products submitted by the community;
- fetch NoCrumb's list of recommended AI model names. This request carries no key and no personal data.
As with any internet request, our hosting provider receives your IP address and standard technical details such as the app's request headers. We do not use them to build a profile of you.
Other services the app talks to
- Open Food Facts (privacy): when you scan a barcode, the barcode number is sent to look up the product. Nothing else is sent.
- OpenStreetMap (privacy): the restaurant map loads map tiles from OpenStreetMap's tile server. That server sees your IP address and which map area you view. Your location dot is drawn on your phone and is not part of the request.
- Google (privacy) and Apple (privacy): to sign you in and, when you delete your account, to revoke NoCrumb's access to your Google or Apple account.
- Supabase (privacy): hosts NoCrumb's database and sign-in service, acting on our behalf.
- Map and call buttons: when you tap to open a restaurant in your maps app or to call it, your phone hands the address or number to the app you choose.
AI meal plans (your own key)
"Generate my week" is optional and works only if you add your own API key from Anthropic, Google Gemini or OpenAI. The key is stored in your phone's secure storage. It is checked once by contacting that provider, and then used only for your plan requests. Requests go directly from your phone to the provider you chose. They are never sent through NoCrumb, and NoCrumb never receives your key or the plan.
A request contains NoCrumb's recipe list and your planning choices: servings, meals, preferred grains, ingredients to avoid and slots already filled. It does not contain your profile, scan history or symptoms. The provider's own privacy policy applies to what you send them, and you pay them directly under your own account: Anthropic, Google, OpenAI. Deleting your data in the app removes your saved keys from the phone.
What we do not do
- No advertising, no ad networks and no tracking across apps or sites.
- No analytics and no crash-reporting services in the app.
- We do not sell your data.
- We do not collect your location.
- This website sets no cookies, runs no scripts and loads nothing from other sites.
How long we keep things
- Account data and the things you posted are kept until you delete your account.
- After deletion, copies may remain in our hosting provider's encrypted backups for up to 30 days, until those backups are overwritten. They are not used or restored.
- If you delete your account in the app, it is deleted immediately.
- If you ask by email, we delete it within 30 days.
- Data on your phone stays until you delete it in the app or uninstall NoCrumb.
When an account is deleted, your email, display name, reviews, flags, reports, suggestions and product submissions are removed. A restaurant that moderators created from your suggestion remains in the directory as a business listing, but is no longer linked to you. See how to delete your account.
Your rights
You can ask to see, correct, export or delete the data we hold about you, and to object to or restrict how it is used. You can change your display name in the app under Settings, Account. For anything else, or if you are in the European Economic Area, the UK or another place with data protection laws that give you these rights, email us and we will reply within 30 days. You may also complain to your local data protection authority.
We process your account data to run the features you ask for (a contract), and process contributions and abuse limits for the legitimate interest of keeping the community directory accurate and fair.
Children
NoCrumb is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
If we change what the app collects, we will update this page and its effective date before the change takes effect.