Legal

Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains what information our applications collect, how that information is used, and the choices you have about it. It applies to every iOS application, watch app, widget, App Clip, extension, and related service (each, an “App”) published or operated by Zhi Yao Tan (“we”, “us”, or “our”).

It covers all of our Apps, current and future, whatever their name or subject matter, and any renamed or rebranded version of an App. Not every section applies to every App — each App only collects what its own features actually need, and the App Store privacy label on each App’s listing describes what that specific App collects. By downloading or using an App, you agree to this Privacy Policy.

The short version. We do not ask you to create a named account. We do not sell your data. We do not track you across other companies’ apps or websites. Most of our Apps use a random per-install identifier so your in-app activity (such as favorites and history) stays with you, and where an App stores data you can delete everything from inside the App at any time.

1. Who we are

Each App is published by Zhi Yao Tan, an independent developer, who is the data controller for the purposes of this policy. You can reach us at kelvin.vins@gmail.com for any privacy-related question or request.

2. Information we collect

What we collect depends on which App you use and which features you choose to use. The categories below are the complete set across our whole portfolio; an individual App will typically use only some of them.

2.1 Anonymous installation identifier

When you first launch an App that stores data, we generate a random UUID and store it in your device’s Keychain. This identifier is used solely to associate in-app activity (for example favorites, history, or subscription status) with your install. It is not your real name, email, phone number, or Apple ID, and we do not link it to any external identifier.

2.2 In-app activity and content

Depending on the App, we may store the following on our servers (Google Cloud Firestore) or on your device, under that anonymous identifier:

2.3 Diagnostic and performance data

We use Google Firebase (Crashlytics, Performance Monitoring, Analytics) to record crashes, errors, and aggregate usage information. This may include your device model, iOS version, app version, language, country, coarse region, time zone, and the in-app screens you visited. We use this only to fix bugs and improve the App. It is not used to advertise to you.

2.4 Purchase information

If you buy a subscription or other in-app purchase, payment is processed by Apple. We receive a receipt from Apple (via Adapty Inc., our subscription management provider) confirming that an active entitlement exists for your install, along with basic transaction metadata such as product identifier, country, and renewal status. We never receive your payment card details or your full Apple ID.

2.5 Location (only in Apps with location-based features)

Some Apps offer features that depend on where you are — for example finding places near you. If you grant location permission, your approximate or precise coordinates are used at the moment of the request and sent to our mapping and places provider (Google Maps Platform) to return nearby results. Location is used to fulfil your request; we do not build a location history, track your movements in the background, or use location for advertising. You can decline location access, or change it later in iOS Settings → Privacy & Security → Location Services, and the App will continue to work with reduced functionality (for example, by letting you enter an area manually).

2.6 Microphone and speech (only in Apps with speech features)

Some Apps let you speak so the App can check your pronunciation or accept voice input. If you grant microphone and speech-recognition permission, audio is captured only while you are actively using that feature. Recognition is performed using Apple’s Speech framework; where on-device recognition is available it is used, and where it is not, Apple may process the audio on its servers under Apple’s privacy policy. We do not store your recordings on our servers and we do not use them for any purpose other than returning your result.

2.7 Photos, camera, and other device permissions

An App will only ask for a permission (such as photo library access to save an exported image, or the camera to scan a code) when a feature you have chosen to use requires it, and the reason is shown in the iOS permission prompt. Declining a permission only disables that feature. We do not access your contacts. Health data is covered separately in Section 2.12.

2.8 Notifications

If you grant permission, an App may send local notifications (for example a daily reminder), and some Apps may send push notifications for content updates. For push notifications, Apple issues a device token that is stored with your anonymous identifier so we can deliver the message; it does not tell us who you are. You can revoke notifications at any time in iOS Settings → Notifications.

2.9 Advertising data (only in Apps that show ads)

Some Apps may display advertisements, including optional rewarded video ads, from Google AdMob. Before any ad is requested we present Google’s User Messaging Platform (UMP) consent form where required by law (for example in the EEA and UK). If you decline personalised ads, AdMob will serve only non-personalised ads. We do not request App Tracking Transparency permission and we do not access your Advertising Identifier (IDFA) for cross-app tracking.

2.10 Shared and multi-device sessions (only in Apps that support them)

If you start a SharePlay or similar shared session, your device exchanges a small amount of session state (such as which item is currently visible) directly with the other participants’ devices through Apple’s GroupActivities framework. We do not see or store the contents of those messages. If an App syncs data through iCloud, that data is stored in your own Apple account under Apple’s privacy policy, not on our servers.

2.11 Support correspondence

If you email us, we receive your email address and whatever you include in your message, and we keep it for as long as needed to handle your request and to keep a record of it.

2.12 Health and fitness data (Nourish only)

Nourish can read a small amount of data from Apple Health so that parts of your health picture fill in without you logging them by hand. This applies to no other App, and it only happens if you tap “Connect Apple Health” and then grant permission in the system prompt.

Separately, the habits you log inside Nourish yourself — water, movement minutes, meals and your own habits — are stored with your anonymous identifier so they survive reinstalling and sync between your devices, as described in Section 2.2. Those are your own entries in the App, not data read from Apple Health.

3. What we do not collect

4. How we use your information, and our legal bases

5. Service providers we share data with

We use the following third parties as data processors or independent controllers, depending on the service. Their handling of data is governed by their own privacy policies, which we encourage you to review:

We may also disclose information where we believe in good faith that it is required to comply with a law, regulation, or lawful request, to enforce our Terms, or to protect the rights, safety, or property of us, our users, or the public. If an App or our business is transferred to another party, data may be transferred as part of that transaction, subject to this policy.

We do not share your data with any third party for their own independent marketing purposes.

6. International transfers

Our service providers may process data on servers located outside your country of residence, including in the United States. Where required by law, we and our service providers use Standard Contractual Clauses or equivalent safeguards to protect your information.

7. Data retention

We keep in-app activity for as long as your install exists, or until you delete it from inside the App. Diagnostic and crash data are retained for the periods set by Firebase (typically up to 90 days for performance traces and crash metrics; aggregate analytics may be retained for up to 14 months). Purchase and entitlement records are retained for as long as needed to honour your subscription and to meet tax, accounting, and legal requirements. Support emails are kept for as long as needed to handle and document your request.

8. Your choices and rights

9. Children

Our Apps are not directed at children under the age of 13 (or under the age of digital consent in your jurisdiction, where higher). We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can delete it.

10. Security

We use industry-standard safeguards, including encryption in transit via HTTPS, Firestore security rules, and Apple Keychain protection for identifiers. No method of transmission or storage over the Internet is 100% secure, and we cannot guarantee absolute security.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, and any update applies to all of our Apps. When we do, we will update the “Last updated” date at the top of this page. Material changes will be highlighted in the App or otherwise prominently communicated.

12. Contact us

Questions, comments, or requests about this policy can be sent to kelvin.vins@gmail.com. See also our Terms of Service.