Plain-language summary. Yuva is a nutrition and recipe app operated by UMPROVE SRL. We collect your email, your health data (height, weight, sex, date of birth, activity level, dietary preferences and allergies), and the food and recipes you log, in order to generate personalised recipes. We never sell your data. The app asks for your camera to scan barcodes and your photo library if you add a photo to your own recipe — both only when you use those features. Anonymous usage and crash reporting is optional and off unless you turn it on. You can export or delete everything from inside the app at any time. Health data is processed only with your explicit consent, which is required to use the app.
This Privacy Policy explains how UMPROVE SRL ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use the Yuva mobile application and related services (the "App"). We process personal data in accordance with the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), the Children's Online Privacy Protection Act (COPPA), and Romanian data-protection law.
Data Controller:
UMPROVE SRL
Str. 1 Mai nr. 15, Mun. Rădăuți, Suceava County, Romania
Privacy contact: contact@yuva.one
1. Information we collect
Identity & Account Data. Your email address and password; or, if you sign in with Apple or Google, the authentication tokens those services issue. When you sign in with Apple or Google, those services may also share your name and profile picture as part of the standard sign-in process; we store this information in your account record but the App does not currently display or otherwise use it.
Health & Dietary Data (Special-Category Data). To generate tailored recipes and verify your age, we collect your height, weight, sex, date of birth, activity level, and dietary preferences. Some of this is treated as special-category (health) data under GDPR Art. 9 and Sensitive Personal Information under the CPRA. We process it only with your explicit consent (see Section 2). We store your full date of birth to calculate your daily calorie and macronutrient targets and to verify that you meet the minimum age requirements.
Food & Nutrition Log (Special-Category Data). The foods and recipes you log, including quantities, the meal they belong to, and the date and time you logged them. Where you scan a product barcode, we record the scanned product so we can look up its nutrition information; if a product is not in our database you can add it yourself, and we store the food you created. A record of what you eat is health data under GDPR Art. 9 and Sensitive Personal Information under the CPRA, and is processed on the same explicit consent as the rest of your health data.
Recipe Content. Recipes and recipe instructions you create or save in the App, and any photo you choose to attach to a recipe you created. Your own recipes and photos are private to your account — Yuva has no feed, sharing, or other users who can see them.
Technical & Diagnostic Data. Device and operating-system type, app version, screen views, and error reports including error messages and stack traces. This is collected only if you opt in (see Optional usage and crash reporting in Section 2). Our website is served through Cloudflare, and our app servers, our analytics provider and our crash-reporting provider each necessarily see the IP address your device connects from, as any internet service does. We do not store your IP address in our application database, do not use it to build a profile of you, and do not link it to your health data.
Device Permissions. The App asks for the following permissions, always at the moment you first use the relevant feature, and works without them if you decline:
- Camera — to scan product barcodes when logging packaged foods. We process the barcode; we do not store photographs or video from the camera.
- Photo library — only if you choose to add a photo to one of your own recipes. We access the single image you select; we do not scan or index your library.
- Notifications — to remind you before a free trial converts to a paid subscription.
- Face ID / Touch ID / device biometrics — to confirm it is you before exporting your data, clearing your health data, or deleting your account. Your biometric data never leaves your device and is never sent to or seen by us; the device only tells the App whether the check passed.
The App does not request access to your microphone or your location, and does not use HealthKit or Google Fit.
2. How we use your data and our legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and operate your account; let you save and access recipes | Identity, Recipe Content | Performance of a contract (Art. 6(1)(b)) |
| Generate personalised recipe and nutrition recommendations | Health & Dietary Data | Explicit consent (Art. 9(2)(a)) |
| Let you log what you eat and see your intake against your targets | Food & Nutrition Log | Explicit consent (Art. 9(2)(a)) |
| Personalise and rank suggestions based on your in-app behaviour | Recipes you view, save and cook; dietary preferences | Explicit consent (Art. 9(2)(a)) — the same health-data consent, see Section 3 |
| Optional usage analytics and crash diagnostics | Technical & Diagnostic Data | Consent (Art. 6(1)(a); ePrivacy Art. 5(3)) — off unless you opt in |
| Network security and abuse prevention | Connection metadata, technical data | Legitimate interests (Art. 6(1)(f)) |
Health-data consent. You grant explicit consent to process your health and dietary data during onboarding. Because Yuva's core functionality is providing personalized recipes tailored to your body, you cannot use the App without providing this consent. You may withdraw consent at any time in Settings › Data and privacy › Clear health data, which returns you to the onboarding flow, as we cannot generate personalised recommendations without this information.
What "Clear health data" does, precisely. It erases your height, weight, goal, activity level, sex, allergies, diet type, cooking skill, equipment, meals per day, and all calorie and macronutrient targets from your profile. Your food log, the foods you created, and your own recipes are marked deleted and disappear from the App at the same moment. Two things are deliberately kept:
- Your date of birth, so that the age check cannot be re-taken with a different date. It is no longer used for any nutrition calculation.
- Your account and any active subscription — withdrawing health-data consent does not cancel a plan you have paid for.
A copy of the cleared data is held in a recovery archive for 24 hours in case you clear it by mistake, and is then permanently and automatically deleted. Marked-deleted food-log entries, custom foods and personal recipes remain in our database, invisible to you and unused, until you delete your account — at which point they are erased with everything else. If you want them gone sooner, delete your account rather than clearing health data.
Optional usage and crash reporting. Anonymous analytics (PostHog) and crash diagnostics (Sentry) are switched off by default. We ask you once, during onboarding, on a separate opt-in that is not required to use the App, and you can change your answer at any time in Settings › Data and privacy › Share usage data. Turning it off stops both tools immediately.
When enabled, these tools receive your app version, platform, which screens you opened, your plan tier, and error reports including error messages and stack traces. We configure them not to attach your identity or IP address, we never call any "identify" function, and app logs and session replay are disabled. We do not send health, dietary, food-log, or profile data to either service, and we do not track your activity across other apps or websites.
3. Automated personalisation and profiling
The App ranks and personalises recipe suggestions automatically. This may include analysing which recipes you view, save, and cook to infer your taste preferences and improve future suggestions. This is profiling under GDPR Art. 4(4).
- This personalisation does not produce legal or similarly significant effects about you (it only influences which recipes are suggested), so it does not constitute solely-automated decision-making under GDPR Art. 22.
- It runs on the explicit health-data consent you give during onboarding, and you can stop it at any time by clearing your health data in Settings. It does not depend on the optional usage-analytics consent, and turning analytics off does not turn personalisation off (or vice versa).
- We do not use this profiling for advertising or to make decisions about your eligibility for any service.
4. How we share your data
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. We share data only with vetted processors under data-processing agreements:
- Infrastructure & storage — Supabase (servers in Ireland, EU): hosts your account data and recipe content.
- Network security & content delivery — Cloudflare: serves our website and protects our services against abuse.
- Crash diagnostics — Sentry (servers in Germany, EU): error and crash reporting. Only if you opt in.
- Product analytics — PostHog (EU Cloud, servers in Germany): anonymous, event-level usage analytics — which screens are opened and whether a subscription was started. We never send it your name, email, account identifier, or any health or dietary data. Only if you opt in.
- Subscription management — RevenueCat: processes your subscription status and a pseudonymous identifier to manage Premium entitlements. Payment itself is handled by Apple or Google under their own privacy policies; we do not receive your full payment-card details.
We may also disclose data where required by law, to enforce our Terms, or to protect the rights and safety of our users.
5. Data retention and deletion
You can delete your account at any time: in App settings, via yuva.one/delete-account, or by emailing contact@yuva.one.
- Active data. On a deletion request, your account, personal identifiers, health data, food log, custom foods, personal recipes, and any recipe photos you uploaded are immediately and permanently deleted from our active databases and file storage.
- Recipes you generated or cooked. These are anonymised rather than deleted: we detach them from your account so they can no longer be linked to you, and keep them for up to one year to measure and improve recipe quality, after which they are automatically and permanently deleted. Once detached they are no longer personal data, and they cannot be re-linked to you or returned to you.
- Consent records. Records of the consents you gave and withdrew (what you agreed to, which version, and when) are deleted with your account. Where we are legally required to demonstrate that consent was obtained, we may retain the minimum record needed for that purpose.
- Backups. Our encrypted disaster-recovery backups operate on a 7-day rolling overwrite, so any residual copies of your data are overwritten within that cycle and are placed beyond use in the meantime.
- Rate limiting. Export and deletion requests are rate-limited, so a second request within a short window may be refused with a retry time. This does not restrict your rights — it only prevents automated abuse of those endpoints.
6. Your privacy rights
Subject to your location and applicable law, you have the following rights:
- Access & portability. Request a copy of your data, exportable in-app in structured, machine-readable JSON format. The export contains your account details, profile, recipe history, food log, custom foods, your own recipes, your consent records, and your calorie/macro target history. Because recipe photos are image files rather than text, the export lists each photo with a secure download link valid for 24 hours instead of embedding the image itself — download them before the links expire, or run the export again.
- Rectification. Correct inaccurate data in your account settings.
- Erasure. Delete your account and personal data at any time.
- Withdraw consent. You can withdraw your health-data consent at any time using "Clear health data" in Settings, and your optional usage-analytics consent at any time using the "Share usage data" toggle in Settings. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out beforehand. We do not collect or process personal data for marketing or advertising, so there are no promotional consents to withdraw.
- Object & restrict. Object to or request restriction of processing based on legitimate interests.
- Right to Limit Use of Sensitive Personal Information (CPRA). California residents may direct us to use their Sensitive Personal Information only as necessary to provide the App. We already limit use of your health and dietary data to delivering the recipe service and never use it to infer characteristics for advertising. You may go further and delete that data entirely using "Clear Health Data."
- Non-discrimination. We will not deny you service or charge you differently for exercising these rights.
To exercise any right not available through an in-app control, contact contact@yuva.one. You also have the right to lodge a complaint with your supervisory authority — in Romania, the ANSPDCP (dataprotection.ro).
7. International data transfers
Our core processors (Supabase, Sentry, PostHog) host data within the EEA — Ireland and Germany — so your data primarily stays in the EEA. Where any processing involves a transfer outside the EEA, we rely on appropriate safeguards: Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework where applicable, and supplementary technical measures.
8. How we protect your data
We use encryption in transit and at rest, access controls limiting staff access to personal data, and a fail-closed approach to telemetry that excludes health and profile data from crash diagnostics. No system is perfectly secure, but we maintain measures proportionate to the sensitivity of the data we hold.
9. Children's privacy
We present a neutral date-of-birth screen before account creation. You must be at least 13 years old to use Yuva, and anyone who enters a date of birth under 13 is blocked from creating an account. We do not knowingly collect data from children under 13.
The age of digital consent is higher in some countries — up to 16 in the EU, including Romania. Our age screen enforces a single minimum of 13 and does not detect your country, so if you are between 13 and the age of digital consent where you live, you may only use Yuva with the consent or authorisation of a parent or legal guardian, as set out in our Terms of Service. Parents and guardians can contact us at contact@yuva.one to review or delete a child's data. If we learn an account was created with a falsified age, we will delete the account and its associated personal data.
10. Changes to this policy
We may update this policy. For material changes, we will update the effective date and notify you in-app or by email before the changes take effect.
11. Contact us
UMPROVE SRL
Str. 1 Mai nr. 15, Mun. Rădăuți, Suceava County, Romania
Privacy & data requests: contact@yuva.one