AvecAmiGet the app

AvecAmi — Privacy Policy

Effective date: 13 August 2026 Last updated: 13 August 2026

This Privacy Policy explains what personal data the AvecAmi mobile application and the website at avecami.app (together, the "Service") collect, why, who it is shared with, how long it is kept, and what rights you have over it.

It forms part of, and should be read together with, our Terms of Service.


At a glance

Do we sell your personal data? No. We do not sell it and do not share it for cross-context behavioural advertising.
Are there advertising SDKs in the app? No. There is no advertising, no ad network, no IDFA, and no App Tracking Transparency prompt, because we do not track you across other companies' apps or websites.
Do you have to create an account? No. The app creates an anonymous account for you automatically. You may optionally attach your Apple ID.
Do we know who you are? Only if you choose Sign in with Apple. Otherwise we hold a random identifier and nothing that identifies you by name.
Do we see your payment card? Never. Apple processes all payments. We only learn whether a subscription is active.
Do we store the photos you import? No. They are processed and discarded; only the resulting recipe text is saved.
Where is your library stored? In a Postgres database hosted in the European Union (AWS eu-west-1, Ireland), and on your own device.
Can you delete everything? Yes — Profile → Account → Delete account in the app. It cascades across every table that holds your data.
Who to contact support@avecami.app

1. Who is responsible for your data

AvecAmi is operated by an individual sole trader established in Tbilisi, Georgia, who is the controller of the personal data described in this policy. The provider's name is published on the AvecAmi listing in the Apple App Store; our full legal name and postal address are available on request at the address below.

Contact for all privacy matters, including requests to exercise your rights: support@avecami.app

2. Scope

This policy covers the AvecAmi iOS application, its share extension and widgets, the avecami.app website, and our backend API at api.avecami.app.

It does not cover third-party services you reach through the Service — for example a social platform whose link you paste, or a website whose recipe you import. Those are governed by their own privacy policies.

3. What we collect

3.1 Account identifiers

Data When Notes
Random account identifier (UUID) Automatically, on first launch Created by our authentication provider. It is not derived from your device, phone number or any identifier you own.
Apple email address Only if you use Sign in with Apple May be an Apple private-relay address (…@privaterelay.appleid.com), in which case we never see your real address.
Name Only if you use Sign in with Apple and choose to share it, or type one in Profile → Account Optional. You can change or clear it at any time.
Authentication tokens Continuously Stored in the iOS Keychain on your device.

We do not offer password-based sign-up, so we never hold a password.

3.2 Preferences you give us during onboarding and in Profile

Age range (under 25 / 25–34 / 35–44 / 45–54 / 55+); dietary restriction; your stated goals for using the app; which sources you save recipes from; how you heard about AvecAmi; your interface language; whether recipes should be auto-translated and into which language; your preferred measurement system; your chosen reminder windows and times; optional daily calorie and protein targets; and an invite code if you entered one.

These configure the Service. You can change them in Profile at any time.

3.3 Your content

Recipes you import, create or edit — including titles, descriptions, servings, ingredients, steps, difficulty, cover image references and the original source link; recipe books; your grocery list; and your meal-plan entries.

Messages you exchange with Ami are stored on your device, not in our database. Each time you send a message, the conversation is transmitted to our server and on to the AI provider in order to produce a reply, and is then discarded server-side. It is not written to our database.

3.4 What you submit for import

Links you paste or share; text you type or paste; and photographs you take with the camera or select from your photo library.

Photographs and pasted text are processed and then discarded. They are sent over an encrypted connection to our server, resized, checked by an automated content-safety filter, sent to an AI provider for extraction, and dropped once the recipe has been produced. We do not store your photographs or the raw text on our servers. Only the structured recipe that results is saved to your library.

Note that when you import from a link, our server fetches that page — the third-party site sees our server's address, not yours or your device's.

3.5 Subscription data

From our subscription provider we receive and store: whether an entitlement is active, the entitlement and product identifiers, the period type (normal, trial, introductory or promotional), the store, expiry and renewal dates, the original transaction identifier, the subscription provider's customer identifier, and identifiers used to de-duplicate billing events.

We never receive or store payment card numbers, bank details or billing addresses. Apple is the merchant of record and processes all payments.

3.6 Analytics and crash reports

The app includes Google Analytics for Firebase and Firebase Crashlytics.

Neither is used for advertising. Neither tracks you across other companies' apps or websites, which is why the app does not display an App Tracking Transparency prompt.

3.7 Operational telemetry

For each request to an AI-backed endpoint we record: which endpoint was called, the source link where one applies, how many images were submitted, the character length of the submitted text, the models used, token counts, the cost, how long it took, whether it succeeded, any error message, and your account identifier.

The submitted text and images themselves are deliberately not recorded — only their size.

We also keep simple counters of how many imports and Ami messages you have used in the current period, in order to enforce the free-tier allowance.

3.8 Server logs

Our API server produces operational logs which may contain network addresses, timestamps, requested paths and error information.

3.9 Support correspondence

If you email us, we hold your message, your email address and anything else you choose to include, for as long as needed to deal with it.

4. What we do not collect

5. Device permissions

Permission Why Consequence of refusing
Camera To photograph a recipe for import Photo import from the camera is unavailable; every other feature works
Photo library To pick an existing photo for import Photo import from the library is unavailable
Notifications To show local cooking and meal reminders on your device No reminders. These are scheduled on your device by iOS — we do not operate a push server and do not send remote notifications

You can change any of these at any time in iOS Settings → AvecAmi.

6. Why we use your data, and our legal basis

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases.

Purpose Data used Legal basis
Create and maintain your account; store and synchronise your library across devices §3.1, §3.3 Performance of a contract (GDPR art. 6(1)(b))
Import and structure recipes; translate; answer your questions through Ami §3.3, §3.4 Performance of a contract
Apply your preferences (units, language, diet, reminders, goals) §3.2 Performance of a contract
Schedule the reminders you ask for §3.2 Performance of a contract
Provide, verify and restore paid subscriptions §3.5 Performance of a contract
Enforce free-tier allowances §3.7 Performance of a contract
Screen submitted content for unlawful or harmful material §3.4 Legitimate interests (art. 6(1)(f)) — protecting the Service and other users; compliance with our providers' terms
Keep the Service secure; prevent fraud, abuse and denial of service §3.1, §3.8 Legitimate interests — security of the Service
Diagnose crashes and fix defects §3.6 Legitimate interests — a working, reliable product
Understand which features are used, and improve the product §3.6 Legitimate interests — improving the Service. You may object at any time; see §11.3
Monitor reliability and the cost of AI processing §3.7 Legitimate interests — running the Service sustainably
Answer your support requests §3.9 Legitimate interests; performance of a contract
Comply with legal obligations, and establish, exercise or defend legal claims as required Legal obligation (art. 6(1)(c)); legitimate interests

We do not use your data for automated decision-making that produces legal or similarly significant effects on you.

Sensitive data. Dietary restrictions can in some circumstances reveal information about health or belief. We collect them only because you enter them, and only to filter and label your own recipes. We do not use them for profiling, inference or advertising. Where such data is treated as a special category under GDPR art. 9, we process it on the basis of your explicit consent, given by entering it; you can clear it at any time in Profile → Goals & diet.

7. Who we share data with

We do not sell your personal data. We share it only with the service providers below, only to the extent they need it to perform their function, and under contracts that require them to protect it.

Provider Role What it receives Where
Supabase, Inc. Authentication and database Your account identifier, Apple email and name if provided, preferences, and all of your content Database hosted in the EU (AWS eu-west-1, Ireland); provider is US-based
Hetzner Online GmbH Hosting of our API server (api.avecami.app) Everything that passes through the API in transit, plus server logs Falkenstein, Germany (European Union)
OpenAI, L.L.C. Recipe extraction and structuring; the Ami assistant; automated content moderation; speech transcription of imported videos as a fallback The text, links and images you submit for import; the content of your Ami conversations; audio extracted from imported videos United States
Google LLC (Gemini API) Understanding imported cooking videos — speech and on-screen text The video file downloaded from the link you submitted United States
Google LLC (Firebase Analytics, Crashlytics, BigQuery) Product analytics and crash reporting Analytics events, app-instance identifier, your account identifier, device and OS information, crash diagnostics United States and other Google locations
RevenueCat, Inc. Subscription and entitlement management Your account identifier and purchase/entitlement data received from Apple United States
Apple Inc. App distribution, payment processing, Sign in with Apple, local notification delivery Your purchase and Apple ID data, under Apple's own privacy policy Apple's own infrastructure

We may also disclose personal data where we are legally required to do so, to respond to a valid legal process, to enforce our Terms, to protect the rights, property or safety of our users or of others, or in connection with a merger, acquisition or sale of assets — in which case we will require the recipient to honour this policy, and will notify you before your data becomes subject to a different one.

8. AI providers and model training

The AI providers listed above receive content through their business/API interfaces, not their consumer products.

Under the terms of those interfaces as at the effective date of this policy, OpenAI does not use data submitted through its API to train or improve its models, and Google does not use data submitted through the paid Gemini API to improve its products. OpenAI may retain API content for a limited period (currently up to 30 days) for abuse and misuse monitoring, after which it is deleted, unless a longer period is required by law.

These are the providers' terms, not ours, and they can change them. We will update this section if the position changes materially.

Note separately that our Terms of Service contain a broad content licence (section 8.2). That licence describes rights we hold; this section describes what actually happens today.

9. International transfers

Our database and API servers are located in the European Union. Several of our providers are located in the United States, so your personal data is transferred there.

The United States has not been recognised by the European Commission as providing an adequate level of protection in general. For those transfers we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with each provider, together with the supplementary measures those providers describe in their own documentation. Where a provider is certified under the EU–US Data Privacy Framework, we also rely on that certification.

The controller is established in Georgia and administers the Service from there, so personal data is also accessed from Georgia. Georgia is not the subject of a European Commission adequacy decision. Georgia's Law on Personal Data Protection, in force since 1 March 2024, is modelled on European standards and is supervised by an independent authority, the Personal Data Protection Service of Georgia; for transfers from the EEA we additionally rely on Standard Contractual Clauses and on the safeguards described in this policy.

You may request a copy of the relevant transfer safeguards at support@avecami.app.

10. How long we keep data

Data Retention
Account, preferences and all your content Until you delete your account, or until the account has been inactive for a prolonged period and we notify you before deleting it
Ami conversation history On your device, until you delete it or uninstall the app. Not retained on our servers
Photographs and text submitted for import Not retained. Discarded once the import completes
Subscription records Deleted with your account. Apple and our subscription provider keep their own transaction records under their own policies and legal obligations
Free-tier usage counters Deleted with your account
Operational telemetry (§3.7) 12 months. When you delete your account, the account identifier on these rows is erased, leaving anonymous cost and reliability statistics that can no longer be linked to you
Server logs Up to 30 days
Analytics events Up to 14 months, per our Google Analytics configuration
Crash reports Up to 90 days
Encrypted database backups Up to 30 days after deletion, after which deleted records disappear from backups as well
Support correspondence Up to 24 months after the matter is closed

We may keep data for longer where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.

11. Your rights

11.1 If the EU or UK GDPR applies to you

You have the right to:

11.2 If you are a resident of California or another US state with a privacy law

Depending on your state, you may have the right to know what personal information is collected, used and disclosed; to access and obtain a copy of it; to correct it; to delete it; to opt out of its sale or of sharing for cross-context behavioural advertising; to opt out of targeted advertising and certain profiling; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended, or under comparable state laws. We do not use personal information for targeted advertising. We do not knowingly process the personal information of anyone under 18.

You may exercise these rights, including through an authorised agent, by writing to support@avecami.app.

11.3 How to exercise any of these rights

Email support@avecami.app. We will respond within 30 days, and will tell you if we need longer (GDPR allows an extension of up to two further months for complex requests). We may need to verify that the request comes from you or from someone authorised to act for you; for an anonymous account, that normally means making the request from the app, or supplying your account identifier.

Some rights can be exercised directly in the app without contacting us:

Exercising your rights is free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.

11.4 If Georgian law applies to you

Under the Law of Georgia on Personal Data Protection you have rights of information, access, correction, updating, blocking, erasure and destruction in respect of your data, and the right to complain to the Personal Data Protection Service of Georgia (personaldata.ge).

11.5 Complaints

We would like the chance to resolve your concern first — please write to support@avecami.app.

You also have the right to complain to a supervisory authority: in the EEA, the data protection authority of your country of residence, place of work, or of the alleged infringement; in the UK, the Information Commissioner's Office (ico.org.uk); in Georgia, the Personal Data Protection Service.

12. Representative in the EEA and the UK

We have not yet designated a representative in the European Economic Area or in the United Kingdom. Until we do, please address all data protection matters, including requests and complaints, to support@avecami.app, and we will handle them directly. We will publish our representative's details in this section once appointed.

13. Deleting your account and your data

You can delete your account from inside the app: Profile → Account → Delete account.

This deletes your authentication record, and every record that depends on it cascades away with it: your profile and preferences, every recipe, your recipe books, your grocery list, your meal-plan entries, your subscription record and your usage counters. Your account identifier is erased from our operational telemetry, leaving statistics that can no longer be linked to you. Data on your own device is cleared at the same time.

What this does not do:

Deletion is immediate and irreversible. Export anything you want to keep first — see §11.3.

If you prefer, write to support@avecami.app and we will do it for you.

14. Security

We take reasonable technical and organisational measures to protect your data, including:

No system is perfectly secure. We cannot guarantee absolute security, and you send data to us at your own risk. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, without undue delay.

15. Children

The Service is intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, write to support@avecami.app and we will delete it.

16. Changes to this policy

We may update this policy — for example if we add a feature, change a provider, or respond to a change in the law. We will post the updated policy at this address and update the "Last updated" date. If a change is material, we will give you notice in the app or by other reasonable means before it takes effect.

Continuing to use the Service after a change takes effect means you accept the updated policy.

17. Language

This policy is written in English. Any translation is provided for convenience only; the English text is the only legally binding version and prevails in the event of any inconsistency.


Contact

support@avecami.app

AvecAmi is operated by an individual sole trader established in Tbilisi, Georgia, who is the controller of the personal data described in this policy. Our full legal name and postal address are available on request.