Privacy policy

This policy describes which personal data the Gommo app and the website gommo.app process, for what purpose, on which legal basis and for how long. Article references are to the GDPR.

Controller

Leon David Heymann
Dorfwiese 7
56462 Höhn
Germany
Email: support@gommo.app

Where this policy says "we", it means the controller. For any matter concerning your data, an email to the address above is all it takes.

Account and sign-in

Gommo requires an account. You register with an email address and password, with your Google account or with your Apple account. Sign-in is handled by Firebase Authentication from Google. Stored are your email address, for Google or Apple sign-in additionally the details the provider passes on (name and profile picture, where provided), a random user ID, the sign-in method, and the time and IP address of your sign-ins. A password is stored only in encrypted form (as a hash). Emails for resetting your password or confirming a new email address are sent by Firebase on our behalf.

When you sign in with Google or Apple, the provider learns that you are signing in to Gommo; what it processes in doing so is governed by its own privacy policy. With Apple you can hide your email address from us.

Legal basis: Art. 6(1)(b) (providing the account).

Your data in the app

Gommo stores under your user ID what you enter or create in the app:

Details about your body, nutrition and weight are health data within the meaning of Art. 9. We process them solely to show you your goals, your diary and your analytics – not for advertising and not to pass them on. By entering these details in the app, you consent to their processing (Art. 9(2)(a)). You can withdraw that consent at any time by changing or deleting the details in the app or by deleting your account; the lawfulness of the processing up to that point remains unaffected. Without these details Gommo cannot calculate goals.

The data is held in Google's Cloud Firestore and Cloud Storage on servers in the European Union. Other users have no access to it; access rules allow every account its own data alone. We do not evaluate your data on a personal level and do not pass it on.

Legal basis: Art. 6(1)(b); for health data Art. 9(2)(a).

Food search

Nutrition facts for foods come from the FatSecret and Open Food Facts databases. When you search or scan a barcode, the search term or barcode number is sent to the respective provider, which sees your device's IP address in the process. It does not learn your account or any of your other data. The barcode itself is recognised on your device; the camera image never leaves it.

Legal basis: Art. 6(1)(b).

Scanning meals and importing recipes

Two features use an AI model (Gemini from Google, via Firebase AI Logic):

Sent along are only your app language and your chosen food country, so the answer fits – no name, no account, no health data. The requests are processed on Google servers, possibly outside the EU as well. Under the Google Cloud terms that apply to us, Google does not use these inputs to train its models. You see the result in the app and can change it before saving.

For an import by link (TikTok, YouTube, Instagram), the app sends the link to our server (Google Cloud Functions, in the EU). The server fetches the text and preview image of the public post from the platform, for Instagram through a service provider that reads public posts. Platform and service provider receive only the link, not your identity or IP address. The preview image is stored as the recipe image in your collection. Our server logs technical details of the request; they are deleted after 30 days.

Legal basis: Art. 6(1)(b) – you trigger the respective feature yourself.

Gommo Pro

You buy the subscription through the App Store or Google Play. Payment is handled by the store alone; we receive no payment details. To recognise your subscription across devices we use RevenueCat. RevenueCat receives your user ID, the store's purchase receipt and technical details about device and app version, and tells us whether a valid subscription exists. This data remains stored at RevenueCat until we have it deleted at your request.

Legal basis: Art. 6(1)(b).

Analytics and ad measurement

We use Google Analytics for Firebase to understand how Gommo is used and to improve the app. Recorded are events such as app start, which areas you open, the sign-in method, search terms of the food search, the start and completion of a purchase and your star rating – together with device type, operating system, language, app version, approximate location (from the IP address, which Google does not store), a random installation ID and, on Android, your device's advertising ID. Your profile, diary and recipe data are not sent to Analytics.

We advertise Gommo with Google Ads and Apple Search Ads. To measure whether an installation or purchase results from an ad, Google matches the advertising ID against its ad data on Android; on iOS the measurement uses Apple's mechanisms (SKAdNetwork, AdServices) without an advertising ID and without a tracking prompt. The measurement serves solely to attribute our ads; Gommo shows no advertising.

Google processes this data in the USA as well. Google deletes user-level Analytics data after 14 months at the latest.

Legal basis: Art. 6(1)(f) – our legitimate interest in improving the app and measuring the effect of our advertising. You can object at any time: by email to us, on Android additionally by deleting or resetting the advertising ID in the device settings, on iOS by turning off personalised ads in the settings.

Security and abuse protection

So that only the genuine Gommo app can access our services, Firebase App Check checks, with the help of Google (Android) or Apple (iOS), whether a request comes from the genuine app on a genuine device. Google or Apple receive technical details about device and app in the process, but no content. All connections are encrypted.

Legal basis: Art. 6(1)(f) – protecting our services from abuse.

On your device

The app asks for camera and photo permission only when you scan a meal, read a barcode or add a recipe image; for notifications, when it first wants to remind you to continue your streak. The reminder is scheduled on your device, not sent by a server. Locally the app also stores recently used foods and an image cache; both disappear with the app. If you share a meal as an image, it goes only where you send it.

Contact

If you email us, we store the message together with your address to handle your request. Our mailbox is hosted by Hostinger. We delete the correspondence once the matter is settled and no retention obligation applies.

Legal basis: Art. 6(1)(b), otherwise (f) (answering your request).

Website

gommo.app is served by Firebase Hosting (Google). On each visit Google processes, as technically necessary, the IP address, time, requested page, browser and operating system in server logs. The website sets no cookies, loads nothing from third parties and contains no analytics.

Legal basis: Art. 6(1)(f) – secure operation of the website.

Retention and deletion

Account, profile, diary and recipe data including images remain stored until you delete your account – in the app in the settings or by email to us. Deletion is carried out immediately and is final; remnants in Google's backup systems disappear within 180 days at the latest. All other data we delete once its purpose lapses or the period stated in this policy expires, unless a statutory retention obligation stands in the way.

Recipients and third countries

We use the following service providers, which process data on our behalf and under our instructions:

Independent controllers that receive only the requests described: Secure Food Systems Pty Ltd (FatSecret), Melbourne, Australia; Open Food Facts, Saint-Maur-des-Fossés, France; the operators of the platform you import a recipe from; Apple and Google as store and sign-in providers.

Where data reaches countries outside the EU – in particular the USA (Google, RevenueCat) and Australia (FatSecret) – we rely on an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework for companies certified under it) or on the European Commission's standard contractual clauses, which we have concluded with the respective provider.

Children

Gommo is not directed at persons under 18. We do not knowingly collect data from children; if we learn of such an account, we delete it.

Your rights

You have the right to access your stored data (Art. 15), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object to processing based on our legitimate interest on grounds relating to your particular situation (Art. 21). You may withdraw any consent you have given at any time with effect for the future. For all of this, an email to us is enough.

You may also lodge a complaint with a data protection supervisory authority, for instance the one responsible for us: the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Mainz.

Changes

We update this policy when the app or the law changes. The version published here applies.

Last updated: 5 September 2026