PRIVACY POLICY
Last Updated: August 9, 2026
This Privacy Policy explains how Stummy™ ("we," "us," "our") collects, uses, processes, stores, and protects personal information when you access or use the Stummy mobile application, the website at stummy.io, and related services (collectively, the "Service"). Full details about who operates Stummy are in the Contact Information section at the end of this Policy.
This Privacy Policy applies to all users of the Service, regardless of how it is accessed (mobile device, web browser, tablet, or other device), and should be read together with our Terms of Service, which governs your use of the Service and is incorporated here by reference.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, do not access or use the Service.
1. Purpose of This Privacy Policy
This Policy explains: what information we collect; how we use and process it; the legal basis on which we process it; when it may be shared with third parties; how long we keep it; and what rights you have over it.
The Service helps users monitor dietary habits and digestive health patterns through food scanning, ingredient/FODMAP analysis, and symptom logging. Because information submitted through the Service may relate to a user's digestive health, some of the data we process is health data — a special, more sensitive category of personal data under most privacy laws. Sections 4, 14, and 15 below explain specifically how we handle it.
2. Information We Collect
2.1 Information You Provide to Us
Stummy does not currently require or offer account creation — there is no email/password login or sign-in. What we collect today, all voluntarily provided by you, is:
- dietary preferences and restrictions
- onboarding/quiz questionnaire answers (website and app)
- shopping list entries
- feedback or support inquiries you send us
Providing this information is voluntary, though some features will not work without it. If we introduce optional accounts in the future (for example, to sync data across devices), we will update this Policy before launch and clearly disclose what account data we collect and why.
2.2 Food Scanning and Image Data
The Service lets you scan food using barcode recognition, packaging text recognition (OCR), and image recognition. When you use these features, the Service processes barcode data, text, and/or images to identify ingredients and analyze potential dietary (FODMAP) triggers. Images and scanned product data may be sent to the third-party AI providers listed in Section 6 for processing, and may be temporarily retained by those providers subject to their own policies.
2.3 Health-Related Information
Stummy does not currently include a symptom-logging or health-tracking feature. This section describes how we will handle this category of data if and when we introduce one — we are documenting our approach in advance so this Policy is ready before that feature ships.
When introduced, digestive symptoms, food-reaction patterns, possible sensitivities, and related dietary notes you choose to log will be treated by us as health data. We will collect and process this category of data only with your explicit, opt-in consent (see Section 3), only to run the features you actively choose to use, and we will apply the additional safeguards described in Section 10.
We will never require you to log symptom or health data to use the core scanning and FODMAP-lookup features of the Service — logging symptoms will be optional and separately consented to, and we will notify you and update this Policy before the feature becomes available.
2.4 Automatically Collected Information
Device type and model, operating system and app version, usage statistics, crash and diagnostic reports, feature interaction data, and approximate geographic location derived from device/IP settings (country/region level — we do not use precise GPS location, and we never use location data to infer visits to specific medical facilities or health clinics).
2.5 Usage and Behavioral Data
Features accessed, time spent in the app, session frequency, and navigation patterns, collected to understand usage and improve the Service.
2.6 Website Analytics
The website at stummy.io uses Vercel Analytics to understand traffic and page performance. Vercel Analytics is cookie-free by default — it does not set persistent identifiers or track you across other websites, and collects only aggregate metrics such as page views, referrers, and approximate location derived from IP address (country/region level). If we add cookie-based tools in the future (e.g., for a login/account feature), we will update this section and request consent where required.
3. Legal Basis for Processing (GDPR / UK GDPR)
Because the Developer is based in Cyprus (EU), the EU General Data Protection Regulation (GDPR) applies directly to our processing, and we apply GDPR-equivalent protections to all users globally. Our legal bases are:
| Processing activity | Legal basis |
|---|---|
| Core app functionality (scanning, FODMAP lookups, meal planning) | Performance of a contract with you (Art. 6(1)(b)) |
| Symptom logs and other health data (not yet a live feature — see Section 2.3) | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — special category data |
| Crash reports, diagnostics, security, fraud prevention | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Analytics (Firebase, Amplitude in the app; Vercel Analytics on the website — see Section 6) | Consent, where required by your jurisdiction, or legitimate interests |
| Legal compliance (e.g. responding to lawful requests) | Legal obligation (Art. 6(1)(c)) |
Once health/symptom logging launches, your consent to that processing will be separate from your general acceptance of this Policy. You will give it by actively choosing to log symptoms or health-related notes in the app. You will be able to withdraw that consent at any time — going forward — by deleting your logged health data in-app (Section 17). Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal, and will not stop you from continuing to use non-health features of the Service.
4. How We Use Information
- providing, maintaining, and personalizing the Service
- running food scanning and ingredient-recognition features
- analyzing potential dietary triggers and generating FODMAP insights
- symptom tracking and data visualization (only for data you chose to log)
- generating meal recommendations and shopping lists
- diagnosing technical issues and improving stability and performance
- responding to support inquiries
- detecting and preventing fraud, abuse, or misuse
- complying with legal obligations
We do not use your health data for advertising, and we do not sell or share it with data brokers.
5. Artificial Intelligence and Automated Processing
Certain features rely on third-party AI systems to analyze data you submit — food images, barcodes, packaging text, ingredient lists, and dietary/symptom notes. We currently use:
- OpenAI — for ingredient/text analysis and generation of dietary insights
- Google (Cloud Vision / Gemini APIs) — for image and text recognition
- AIProxy — a secure API-proxy service that routes AI requests from the app to the above providers without embedding API keys in the app itself
Content you submit for scanning may be transmitted to these providers to generate a result. They process this data as our processors, under their own data-protection and retention terms (see Section 8), and we do not permit them to use your data to train their general-purpose models except where their own terms state otherwise and we cannot influence that.
AI systems have inherent limitations: outputs may contain inaccuracies, depend on the quality of what you submit, and cannot account for every health or nutritional variable. AI-generated insights are informational only and are not medical advice — see the Medical Disclaimer in our Terms of Service.
6. Food Ingredient Information
Ingredient and FODMAP data may originate from public nutrition databases, food manufacturer information, third-party ingredient databases, and automated recognition systems (Section 5). This information can be incomplete, outdated, or vary by region or production batch, and product formulations can change without notice. Always verify ingredients directly from product packaging before making a dietary decision — this is especially important if you have a diagnosed food allergy (see the Allergy Disclaimer in our Terms of Service).
7. Sharing of Information
We do not sell or rent your personal information to third parties, and we do not use your health data for behavioral advertising.
We share information with the following categories of trusted service providers, who process it only as necessary to perform services for us:
| Provider | Where used | Purpose | Data involved |
|---|---|---|---|
| OpenAI, Google, AIProxy | App | AI-based food/ingredient analysis | Scanned images, barcodes, text, dietary notes |
| Firebase (Google) | App | Analytics, crash reporting, push notifications | Device/usage data, crash logs |
| Amplitude | App | Product analytics | Usage and behavioral data |
| RevenueCat | App | Subscription and in-app purchase management | Purchase/entitlement data, anonymized user ID |
| Apple App Store | App | App distribution, purchases, payment processing | Purchase data (governed by Apple's own privacy policy) |
| Vercel | Website | Website hosting, delivery, and Vercel Analytics | Server/request logs, aggregate page-view data |
We do not currently operate a backend database. The app does not sync your food logs, onboarding answers, or preferences to any server we control — they stay on your device (Section 9). The providers above receive only what is needed to run the specific feature each supports (e.g., an image sent for AI analysis, or an anonymized event sent to an analytics SDK).
We may also disclose information where required by law (legal process, government request, or to enforce our legal rights).
8. Aggregated and De-Identified Data
We may use anonymized or aggregated data (which does not identify you) to improve the Service, understand general dietary/FODMAP trends, and develop new features.
9. Data Retention
We do not currently operate a backend database or user accounts. Onboarding answers, dietary preferences, and shopping list entries you provide in the app are stored locally on your device only, and are deleted immediately when you delete the app or clear its local storage — we hold no copy on our side to separately retain or delete.
Data that does pass through our third-party providers (Section 7) — such as an image sent to an AI provider for analysis, or an analytics event — is retained according to that provider's own retention policy, typically for a limited period for debugging, abuse-prevention, and service-improvement purposes, and is not something we separately store ourselves.
If we introduce a backend database, cloud sync, or accounts in the future, we will update this section with specific retention periods before that feature goes live, and will honor deletion requests within 30 days of any data we then hold.
10. Data Security
We apply technical and organizational safeguards designed to protect your information, including encrypted data transmission, secure cloud infrastructure, and restricted access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. International Data Transfers
Your data may be processed in countries outside your own, including the United States, where several of our providers (Section 7) are based. Where we transfer personal data from the EU/UK to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU-U.S. Data Privacy Framework, as applicable.
12. Your Privacy Rights (EU/UK/Global)
Subject to applicable law, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time (Section 3). You also have the right to lodge a complaint with your local data protection authority — in Cyprus, the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights, email support@stummy.io. We will respond within 30 days.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you additionally have the right to: know what personal information we collect, use, and disclose; request deletion or correction; opt out of the "sale" or "sharing" of personal information (we do not sell or share your personal information for cross-context behavioral advertising); and not be discriminated against for exercising these rights. To exercise these rights, email support@stummy.io; we may need to verify your identity first. You may also designate an authorized agent to submit a request on your behalf.
14. U.S. State Health-Data Privacy Notices
Several U.S. states (including Washington, Nevada, and Connecticut) regulate "consumer health data" more strictly than general personal data. In line with these laws, and everywhere you use the Service, regardless of your state:
- We collect health data (symptom logs, dietary reaction notes) only with your affirmative, opt-in consent, separate from your general acceptance of this Policy.
- We do not sell your consumer health data, and we do not use geofencing around medical facilities.
- You may withdraw consent to health data processing at any time via in-app settings or by contacting support@stummy.io; we will honor withdrawal requests within the timeframes required by applicable law.
- You have the right to request access to, and deletion of, your consumer health data at any time.
15. Children's Privacy
The Service is not intended for and may not be used by anyone under 16 years old. We do not knowingly collect personal information — and especially not health data — from anyone under 16. If we learn that we have inadvertently collected such information, we will delete it promptly. If you believe a child under 16 has provided us information, contact support@stummy.io.
16. Third-Party Services
The Service integrates with the providers named in Section 7, plus the Apple App Store for distribution and payments. Each operates under its own privacy policy, and we are not responsible for their practices. We encourage you to review their policies directly.
17. Deleting Your Data
Since Stummy does not currently use accounts or a backend database (Section 9), the simplest way to delete everything associated with your use of the app is to delete the app or clear its data in your device settings — this immediately removes all locally stored information. You can also email support@stummy.io with any deletion-related question.
If we introduce accounts or cloud sync in the future, we will add an in-app account-deletion option, as required by Apple's App Store guidelines, and will update this section accordingly.
18. Changes to This Privacy Policy
We may update this Policy to reflect changes in technology, law, or the Service. We will post the updated version within the Service or on our website and update the "Last Updated" date above. For material changes affecting how we handle health data, we will seek renewed consent where required by law. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
19. About Stummy and Contact Information
Stummy is developed and operated by Artem Voloshanenko, an individual based in Cyprus, registered with the Apple App Store as an individual developer, rather than through a separate company. "Stummy" is his trading name, and "we," "us," and "our" throughout this Policy refer to him personally, in his capacity as the Data Controller for the purposes described here.
"Stummy" and the Stummy logo are trademarks of Artem Voloshanenko.
Data Controller: Artem Voloshanenko, individual developer (Stummy), Cyprus
Email: support@stummy.io
If you have questions about this Privacy Policy or our data practices, contact us at the email above.