← Back to Yummy Bites
YummyBites
Privacy Policy
Last updated: September 22, 2026
1. Introduction
Welcome to YummyBites. This Privacy Policy explains how Mimi Studio d.o.o.,
a limited liability company organized under the laws of the Republic of Slovenia,
with its registered office at Trubarjeva cesta 79, 1000 Ljubljana, Slovenia
(hereinafter "Mimi Studio", "we", "us", or "our"), collects, uses, discloses,
and protects your personal information when you use the YummyBites mobile
application and related services (collectively, the "Service").
This notice describes our data handling. Reading this notice or continuing to
use the Service is not, by itself, consent to processing that requires your
separate consent under applicable law.
2. Information We Collect
2.1 Information You Provide
We may collect the following information when you voluntarily provide it:
- Account Information: Email address and password when you create an account.
- Baby Profile Data: Your baby's name, birth or due date, age, gender, prematurity information, and information about siblings, where you provide it.
- Onboarding and Health-Related Responses: Questionnaire answers including feeding stage, dietary preferences, known allergies, family allergy history, eczema, medical concerns, supplements, and parenting goals. Allergy, reaction and medical information may constitute sensitive health data.
- Food Tracking Data: Information about which foods your baby has tried, liked, or reacted to.
- Allergen Tracking Data: Records of allergen introductions, reactions, and notes.
- Meal Plans: Meal plans you create within the app.
- Photos and Scan Results (optional): Photos you take or choose for Scan a Plate, the child's age context, detected foods, automated feedback, scores, errors, and your confirmation or dismissal of results. Photos and results are stored as described below; processing is not limited to the device.
- Device Location (optional): During onboarding you may allow device location to help select nearby grocery stores. The device may return precise coordinates; the app rounds latitude and longitude to two decimal places (approximately kilometre-level, depending on location) before saving or syncing them. You may skip this request.
- Support Communications: Any messages or feedback you send to us.
2.2 Information Collected Automatically
When you use the Service, we may automatically collect:
- Device and Network Information: Device/browser and operating-system information, IP address as part of network requests, app version, language, country, and app-install or analytics identifiers.
- Usage Data: App interactions, screens viewed, food-search text, foods/recipes liked or marked as tried, features used, and frequency of use.
- Identified Analytics Data: Mixpanel and PostHog receive events and person-profile properties. These include onboarding answers and child profile/health-related fields such as name, birth date, age, prematurity, known allergies, eczema and medical concerns, alongside feature use and purchase-flow events. Before sign-in these can be associated with persistent app/analytics identifiers; after sign-in they can be linked to your account ID and email. These records are not anonymous merely because you have not signed in.
- Diagnostics: Error messages, stack traces where available, rejection/error events, and technical performance information sent through our analytics and service infrastructure.
- IP-Based Country: On the welcome screen the app may request a country lookup from country.is or ipapi.co. The lookup provider receives the request's IP address. The app caches the returned country for the current session; this lookup is separate from the optional device-location permission.
2.3 Information from Third Parties
We may receive information from:
- App-store Payments: Apple manages in-app purchases on iOS, and Google Play manages in-app purchases on Android. We receive purchase and subscription-status information to verify access, but do not process or store payment card details for these app-store purchases.
- Attribution and Web Purchases: Referral/campaign information, your answer to how you discovered the app, install and analytics identifiers, and purchase-status information. Where you arrive from our web purchase flow, these identifiers may connect that flow to the app. This information is not necessarily anonymous.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service, including personalized food recommendations and meal plans based on your baby's age and preferences.
- Show you a relevant list of grocery stores for your area, if you chose to share your approximate location.
- Create and manage your account and sync your data across devices.
- Process subscriptions and verify entitlements.
- Send you relevant notifications, including food introduction reminders, allergen schedules, and meal plan suggestions (with your permission).
- Analyze onboarding answers, child-profile properties and usage events to understand cohorts, feature use, conversion and retention, evaluate experiments, and improve features, content and user experience. This includes the identified analytics described above, not only aggregate statistics.
- Process optional plate photos using automated image analysis, return feedback and retain scan history and review actions for troubleshooting and evaluating the quality of the scan feature. Scan feedback is not a medical diagnosis or a guarantee of food safety.
- Respond to your support requests and communications.
- Detect and prevent fraud, abuse, or security incidents.
- Comply with legal obligations.
4. How We Share Your Information
We do not sell your personal information. We may share your data with:
- Service Providers: Third-party companies that help us operate the Service, including:
- Supabase (account authentication, synchronized profile/tracking data, database functions, scan-result records and photo storage)
- RevenueCat (account/customer identifiers, email where supplied, purchases and entitlement status for subscription management)
- Mixpanel and PostHog (identified product analytics, onboarding and child-profile/health-related properties, app interactions and diagnostics as described above)
- Cloudflare AI Gateway and Google's Gemini service (processing selected plate photos and age/check context to generate scan feedback). The app sends the photo through our Supabase function to these services; it retains the uploaded image, model response, derived results and review actions in Supabase. Provider-side processing and logging are separate from the in-app history.
- country.is and ipapi.co (IP-based country lookup)
- Singular and Meta/Facebook (iOS attribution integrations; these native integrations are disabled in the current Android app)
- Stripe and FunnelFox (where you use the separate web purchase flow, payment/order and entitlement records)
- Resend (transactional email delivery)
- Apple (iOS in-app purchases and app distribution)
- Google Play (Android in-app purchases and app distribution)
- Family Members: When you use family sharing, other members can access the child profiles and tracking information shared with that family. Shared records may remain available to them if you delete your own account.
- Legal Compliance: When required by law, regulation, or legal process, or to protect the rights, property, or safety of Mimi Studio, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Storage and Security
App data is stored on your device and with the providers described above.
Connections to our service endpoints use HTTPS, and synchronized data uses
authentication and database access controls. Different providers may process
data in different regions; this is not a promise that every copy stays in the EU.
While we strive to protect your personal information, no method of electronic
transmission or storage is completely secure. We cannot guarantee absolute security.
6. Data Retention
Account, profile and tracking records are kept while needed to provide the
Service. Scan photos, raw model responses, scan results and review actions are
retained for history and evaluation, including records of scans that do not
appear in the meal-history gallery. There is no fixed automatic expiry stated
here for those records.
In-app account deletion removes the account and core data handled by that
workflow, but it does not automatically erase every photo-storage object,
analytics profile/event, attribution record or external billing record. Shared
family data can be transferred to a remaining member. Purchase records may be
retained for accounting and entitlement handling; support/security records and
backups may also remain subject to their applicable retention requirements.
We do not promise that all providers or backups erase every copy within 30 days.
See account and associated-data deletion for the
current scope and how to request review and deletion of remaining data.
7. Your Rights (GDPR)
Depending on your location and applicable law, including the GDPR in the
European Economic Area, your rights may include:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Restriction: Request that we limit the processing of your data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to the processing of your data for specific purposes, including direct marketing.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at
[email protected].
We handle rights requests within the periods required by applicable law and
may need to verify your identity before acting.
You also have the right to lodge a complaint with the Information Commissioner
of the Republic of Slovenia (Informacijski pooblaščenec) or your local supervisory authority.
8. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract Performance: Processing necessary to provide the Service you requested (account management, food tracking, meal planning).
- Legitimate Interests: Service security, fraud prevention and operational improvement where this basis is available and our interests do not override your rights.
- Consent: Where required for a particular use, consent must be separate and can be withdrawn. Device permission for notifications, camera or location does not by itself authorize unrelated uses of health information.
- Legal Obligation: Where we are required to process data by applicable law.
Health-related information can require an additional legal condition beyond a
general processing basis. This notice does not treat identified health-data
analytics as anonymous, or claim that accepting the notice supplies that
condition. Contact us about the basis for a particular use or to request a
restriction; publishing this notice does not replace any required in-app
disclosure or consent.
9. Children's Privacy
YummyBites is designed for parents and caregivers of infants and young children.
The Service is not directed at children and we do not knowingly collect personal
information directly from children under 16 years of age.
Parents or caregivers enter child identity and health-related information.
It is used for the requested features and can also be sent as identified
analytics properties to Mixpanel and PostHog as explained above. It is not used
solely for on-device personalization. Shared family members may also have
access to the child's records. Please do not submit photographs of children or
other people when the plate-scanning feature only needs a photo of food.
If we become aware that we have inadvertently collected personal data from a child
under 16 without appropriate parental consent, we will take steps to delete that
information promptly.
10. Cookies and Tracking Technologies
The YummyBites mobile app uses local storage and device identifiers to maintain
your session and preferences. Mixpanel and PostHog use persistent identifiers
and identified profiles. Their current app configuration does not use the
browser's Do Not Track setting as an analytics opt-out. PostHog session
recording is disabled in the app.
Our website includes Google Tag Manager and Google Analytics scripts and may
use cookies or similar technologies. Requests can transmit device/browser,
network and usage information to Google. Browser controls affect website
storage but do not automatically delete analytics already sent by the app.
11. App Tracking Transparency (iOS)
On iOS devices, we request your permission via Apple's App Tracking Transparency
(ATT) framework before collecting your device's advertising identifier (IDFA) for
attribution and advertising purposes. You may decline this request, and the app
will function normally without it.
12. International Data Transfers
Your data may be transferred to and processed in countries outside of your country
of residence, including the United States, where some of our service providers
are located. Applicable law may require specific safeguards for a transfer.
Contact us for the provider, processing-region and transfer-safeguard details
relevant to your request; this notice does not assert that all providers use
one storage region or one retention schedule.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes,
we will notify you through the app or by other appropriate means. The "Last updated" date
at the top of this page indicates when the policy was last revised.
A policy update does not substitute for a separate permission or consent where
one is required for a changed use of personal information.
14. Digital Products
In addition to the app, we may offer one-time digital products, such as
The Baby & Toddler Cookbook (a downloadable PDF). Digital products
are delivered immediately upon purchase. By purchasing and downloading a digital
product, you expressly consent to immediate delivery and acknowledge that the purchase
is final and non-refundable, as the content is digital and cannot be
returned once delivered, except where a refund is required by applicable law. See our
Terms & Conditions for full refund terms.
15. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us: