What Knoomi knows about you
Knoomi is a nutrition app, so it holds some of the most personal information there is: what you eat, what you weigh, how you train and how you sleep. This is the honest account of what we collect, why, who else sees it, and how to get rid of it.
Last updated 2026-07-27
We collect what the app needs in order to work: your email address, the food and body data you enter, and the activity data you choose to connect. We do not sell it, we run no advertising and no analytics SDK, and you can delete your account and its data from inside the app at any time. Some of what you type or photograph is sent to OpenAI so the app can read a label or estimate a plate — that, and our hosting provider, are the two places your data actually leaves our systems.
Who we are
Knoomi is the nutrition app described on this site, together with its servers. It is operated by EpicTech Solutions LLC, 1209 Mountain Road Pl NE, Albuquerque, NM 87110, United States. Where this policy says “we”, it means that company.
For anything about your data — a question, a correction, a copy, or a complaint — write to privacy@knoomi.app. A person reads it.
What you give us directly
Everything in this list exists because you entered it or connected it. None of it is inferred from tracking you elsewhere.
- Your EMAIL ADDRESS, from signing in. Knoomi supports a one-time code by email, Sign in with Apple, and Google. With Apple's private relay, we only ever see the relay address.
- FOOD AND DRINK you log: meals, snacks, portions, barcodes you scan, recipes you save, and the pantry and shopping lists you build.
- BODY MEASUREMENTS you record: weight, waist, and progress photos if you take them.
- TRAINING: sessions, sports, routines and the adjustments you make to them.
- YOUR ANSWERS from onboarding: goal, height, age, work type, movement, wake and sleep times, drinks, and food preferences — the inputs the day's plan is built from.
- PHOTOS you take of food or of a nutrition label, and the camera roll images you choose to upload.
What your device provides, with your permission
Each of these is behind an iOS permission prompt. Decline it and the app keeps working; the corresponding feature simply has less to go on.
- APPLE HEALTH — steps and flights climbed, read only, to estimate how much you moved. Knoomi requests permission to write health data as well, but only writes if you enable it; nothing is written without that.
- CAMERA — scanning barcodes, photographing meals, and guided progress photos.
- PHOTO LIBRARY — only the images you explicitly pick.
- BLUETOOTH — connecting to a smart scale to read a weight.
- NOTIFICATIONS — reminders about your next meal window. The token is stored so we can send them.
What we collect automatically
This is deliberately short, and it is worth saying what is NOT on it: Knoomi ships no advertising SDK, no analytics SDK, and no third-party tracker. There is no ad identifier, no cross-app tracking, and no profile built for marketing.
- A DEVICE IDENTIFIER we generate ourselves, plus the device name and app version, so a change made on your phone and a change made on your iPad can be told apart when they sync.
- SYNC TIMESTAMPS — when a record was last written, so your devices can agree on what is current.
- IF YOU SEND A BUG REPORT, and only then: your description, your email address, and a snapshot of the app's state at that moment. That snapshot contains your nutrition and body data for the day in question, because that is what makes a bug reproducible. Sending one is always your choice.
Why we process it
Under the GDPR, the legal basis for each of these is the performance of our contract with you — you asked us to run a nutrition service — except where noted.
- To run the product: build your day, estimate portions, predict hunger, generate meals from your pantry, and keep your history.
- To sync your data between your devices and restore it if you reinstall.
- To operate your subscription and honour restores.
- To answer support and fix bugs you report.
- HEALTH-RELATED DATA — food, weight, body measurements, activity — is a special category under GDPR Art. 9. We process it on the basis of your EXPLICIT CONSENT, given when you enter it and when you grant the Health permission. You can withdraw that consent by deleting your account.
Who else sees it
These are the only third parties that receive your data, and each receives only what its job requires. None of them is permitted to use it for their own purposes.
- SUPABASE — our database, authentication, file storage and server functions. Effectively all of your stored data lives here.
- OPENAI — when you photograph a meal or a nutrition label, describe a meal in words, import a recipe from a link, or add an item to your pantry, that content is sent to OpenAI so a model can read it. That means the photo or the text, not your history, your weight or your identity. It is sent from our servers, not from your phone, and it is not used to train their models.
- APPLE — in-app subscription purchases. Apple tells us your transaction identifiers and subscription status; Apple never gives us your payment details, and we never see your card.
- STRIPE — if you subscribed on the website rather than in the app. Stripe processes the payment; we store a customer and subscription reference, never card details.
- RESEND — sending you transactional email, such as a sign-in code.
- EXPO — delivering app updates. It sees an update request from a device, not your content.
- ANYONE YOU SHARE A MEAL LINK WITH. A shared meal link is deliberately public to whoever holds it: that is what makes it shareable. It contains the meal you chose to publish — not your name, your email or any other part of your account — and you can revoke it from the app, which kills the link permanently.
Where it is processed
Our infrastructure providers operate internationally, so your data may be processed outside the country you live in, including in the United States. Where data leaves the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses in our agreements with those providers.
How long we keep it
Your account data is kept for as long as you have an account. When you delete it, the deletion described below runs immediately.
Two things outlive that, and we would rather say so than let you discover it:
- BACKUPS. Our database provider keeps automated backups on its own rotation. Deleted data can persist in those backups until they age out; it is not restored to the live system, and it is not used for anything.
- PAYMENT RECORDS. Records of transactions are retained where tax and accounting law requires. Deleting your account UNLINKS those records from you — the reference to your account is removed — so what remains no longer identifies you.
Deleting your account
In the app: Account → Delete account. It asks you to type DELETE, and then it removes your food and drink logs, your pantry, recipes and lists, your weights, waist measurements and photos, your training and calibration, your onboarding answers and preferences, your shared meal links and their images, your subscription records, and your sign-in itself. Sessions on your other devices are revoked.
Two honest warnings. First, deleting your account does NOT cancel an App Store subscription — only you can do that, in Settings → Apple ID → Subscriptions, and you should do it first if you want the billing to stop. Second, deletion is permanent; we cannot restore it afterwards.
You never have to email us to delete an account. If the in-app flow fails, write to privacy@knoomi.app and we will complete it by hand.
Your rights
If you are in the UK, the EU or a jurisdiction with comparable law, you have the right to access your data, correct it, delete it, take a copy elsewhere, object to or restrict processing, and withdraw consent. Exercise any of them by writing to privacy@knoomi.app.
You also have the right to complain to your data protection authority. We would rather you told us first, but that right is yours regardless.
If you are in California, you have the rights to know, delete, correct and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not offer financial incentives for it.
Security
Traffic between the app and our servers is encrypted in transit with TLS. Data at rest is encrypted by our hosting provider. Access to your rows is enforced at the database level, so one account cannot read another's data even if the app were compromised. Server credentials never reach the app: everything privileged runs in server functions, and the app has no ability to grant itself access to anything.
We will not claim more than that. No system is immune, and if a breach affects you we will tell you and the relevant authority as the law requires.
Children
Knoomi is not for children. It is not directed at anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, write to privacy@knoomi.app and we will delete it.
This website
The site uses no advertising cookies and no third-party analytics. The only stored value is your light/dark theme choice, kept in your own browser so the page does not flash the wrong colour on load. If you start a checkout, Stripe's own hosted page applies its own cookies under Stripe's policy — none of Stripe's components run on knoomi.app.
Changes
When this policy changes we update the date at the top. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect, rather than relying on you to re-read the page.