Loading...
Loading...
Last Updated: April 7, 2026
Yumroll (“we”, “us”, “our”) operates the website https://yumroll.app (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using Yumroll, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
| Data | When Collected | Purpose |
|---|---|---|
| Email address | Account registration | Authentication, account recovery, transactional emails |
| Password | Account registration | Authentication (stored as a hash by Supabase Auth; we never see your plaintext password) |
| Dietary preferences | Settings page | Allergies, disliked ingredients, serving size — used to personalize recipe generation |
| Data | When Generated | Purpose |
|---|---|---|
| Recipe generation history | Each time you generate a recipe | Display history, prevent duplicate suggestions |
| Feedback data | When you like or dislike a recipe | Train your personal taste profile (Pro feature) |
| Taste profile | Derived from feedback | Personalize future recipe suggestions |
| Generation count | Each generation | Enforce free-tier daily limits |
| Data | How Collected | Purpose |
|---|---|---|
| Usage analytics | Cloudflare Web Analytics | Understand how users interact with the Service, improve features. Cloudflare may process client IP addresses as part of standard HTTP requests; IPs are not stored or logged by the analytics service. |
| Authentication session tokens | Supabase Auth cookies | Maintain your login session |
When you subscribe to Yumroll Pro, your payment information (credit card number, billing address) is collected and processed directly by Stripe, Inc. We do not store your payment card details on our servers. We receive from Stripe only:
We use your information to:
We do not:
We share data with the following third-party services, each with their own privacy policies:
| Service | Data Shared | Purpose |
|---|---|---|
| Supabase | Email, password (hashed), user preferences, generation history, feedback | Database hosting, authentication |
| Stripe | Email, payment information | Payment processing |
| Claude API (Anthropic) | Recipe generation prompts (theme/ingredients, dietary preferences) | AI recipe generation |
| Vercel | Server logs, IP addresses | Web hosting |
| Cloudflare Web Analytics | Page view data, referrer, browser/OS type. Client IP is received during standard HTTP processing but is not stored or used for tracking. | Analytics |
Important note about Claude API:When generating recipes, we send your theme or ingredient input along with your dietary preferences (allergies, disliked ingredients) to Anthropic's Claude API. We do notsend your email address, name, or payment information to the AI. Anthropic's data retention policies apply to these API interactions.
We use a minimal number of cookies:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Supabase Auth session | Essential | Maintain your login session | Session / refresh token expiry |
Essential cookies are required for the Service to function. You cannot opt out of these.
Our analytics provider (Cloudflare Web Analytics) does not use cookies or collect personal data for tracking purposes.
| Data | Retention Period |
|---|---|
| Account data (email, preferences) | Until you delete your account |
| Recipe generation history | Until you delete your account |
| Feedback and taste profile | Until you delete your account |
| Subscription records | Until you delete your account |
| Analytics data | Cloudflare Web Analytics retains aggregated, non-personal analytics data per Cloudflare's retention policies |
Account deletion:When you delete your account, all associated data is permanently deleted from our database (CASCADE deletion). This action is irreversible. To delete your account, use the “Delete Account” option in Settings, or contact us at support@yumroll.app.
We implement reasonable security measures to protect your information:
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
You have the right to:
In addition to the above, you have the right to:
Legal basis for processing:
To exercise these rights, contact us at support@yumroll.app.
California residents have the right to:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
To exercise these rights, contact us at support@yumroll.app.
Yumroll is not intended for use by anyone under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@yumroll.app and we will delete it promptly.
Your data may be processed in countries other than your own, including the United States, where our hosting providers (Vercel, Supabase) and service providers (Stripe, Anthropic, Cloudflare) operate. By using the Service, you consent to such transfers. We rely on the service providers' own compliance mechanisms (e.g., Standard Contractual Clauses) for lawful data transfers.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of the Service after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us: