1. Purpose and Scope
1.1 This Privacy Policy explains how Emma Infotech Pty Ltd ABN 16 644 105 368 (Nomming, we, us or our) collects, holds, uses and discloses personal information through the Nomming application, related websites and services (Service).
1.2 We seek to handle personal information consistently with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles and, where applicable, other privacy laws including the General Data Protection Regulation (GDPR).
1.3 Some nutrition, dietary and meal information may constitute health information or other sensitive information. We apply additional protections where required by law.
2. Definitions
2.1 In this Privacy Policy:
Account Data means information associated with an anonymous, registered or linked Account.
AI Output means information generated or inferred through artificial intelligence or automated analysis.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Processing includes collecting, recording, organising, storing, using, analysing, disclosing and deleting information.
Sensitive Information includes health information and other categories given additional protection under applicable law.
User Content means photographs, audio, text, meal records, profile information, reactions and other material submitted through the Service.
3. Information We Collect
3.1 Information you provide
Depending on the features you use, we may collect:
- your name, email address and profile photograph;
- information submitted during Account registration or support requests;
- meal photographs and other uploaded images;
- voice recordings and meal descriptions;
- text entries and speech transcripts;
- meal records and nutrition information;
- corrections and edits to AI-generated results;
- group names, memberships, invitations, challenge activity, likes and reactions;
- notification preferences;
- reports, appeals and communications with us; and
- payment or subscription status information. Full payment-card details are generally processed by the applicable payment or App Store provider rather than by us.
3.2 Information collected automatically
When you use the Service, we may automatically collect:
- anonymous or pseudonymous Account identifiers;
- device model and device identifiers;
- operating system and application version;
- language, timezone and country settings;
- IP address and network information;
- approximate location derived from IP address, device settings or permission-based location information;
- feature usage, interactions, session events and timestamps;
- crash reports, performance information and technical diagnostics;
- notification tokens and delivery information; and
- security, authentication and fraud-prevention events.
3.3 Information generated or inferred
We may generate or infer:
- recognised foods, ingredients, dishes or restaurant indicators;
- estimated calories, protein, carbohydrates, fat and fibre;
- meal categories, portion estimates and confidence scores;
- alternative food matches;
- suggested meal names or descriptions;
- likely country, region, timezone or language;
- usage patterns and feature preferences;
- group and challenge statistics; and
- diagnostic, security or abuse-risk indicators.
Inferred information may be inaccurate and should not be treated as verified fact.
3.4 Information received from third parties
We may receive:
- authentication identifiers, name, email address or profile information from a sign-in provider, according to your settings with that provider;
- subscription status and transaction confirmations from payment or App Store providers;
- crash, analytics and diagnostic information from service providers; and
- information supplied by another user, such as an invitation, reaction, report or group membership request.
4. Anonymous Accounts
4.1 Anonymous Accounts are assigned identifiers so that the Service can maintain meal records, preferences and usage state.
4.2 Although an Account may not initially include a name or email address, associated identifiers, meal photographs, device information and usage information may still constitute Personal Information.
4.3 If an anonymous Account is later linked to a sign-in method, information previously associated with the anonymous identifier may become associated with the linked Account.
5. How We Collect Information
5.1 We collect information:
- directly from you;
- automatically through the application and related technologies;
- from authentication, App Store, infrastructure and other service providers;
- from other users interacting with you; and
- by generating or inferring information through AI and analytics.
5.2 Where required, we provide a collection notice at or before the time information is collected.
6. Optional Permissions
6.1 The Service may request device permissions for:
- camera access, to photograph meals or profile images;
- photo-library access, to select or save images;
- microphone access, to record voice meal descriptions;
- speech recognition, to transcribe spoken meal descriptions;
- notifications, to deliver reminders, invitations, group activity and Service messages; and
- location access, if an optional feature requires location-based context.
6.2 Permission requests will identify their purpose. You may decline or withdraw optional permissions through your device settings.
6.3 Declining a permission will not prevent access to unrelated features but may prevent the relevant feature from working.
6.4 Country, timezone or approximate location may still be inferred from IP address, device settings or regional configuration where reasonably necessary for security, localisation or requested meal analysis.
7. Sensitive and Health-Related Information
7.1 Meal histories, nutrition information, dietary patterns and related inferences may constitute Sensitive Information.
7.2 We collect and process Sensitive Information where:
- you have provided express consent;
- processing is reasonably necessary to provide a feature you requested and the law permits it;
- processing is required or authorised by law; or
- another lawful exception applies.
7.3 You may withdraw consent to optional processing. Withdrawal does not invalidate earlier lawful processing and may require us to disable or delete affected features or information.
7.4 We do not use identifiable Sensitive Information for targeted advertising.
8. Purposes for Which We Use Information
8.1 We may use Personal Information to:
- create, authenticate and manage Accounts;
- accept meal photographs, voice recordings and text entries;
- transcribe audio and perform AI meal analysis;
- generate, store and display nutrition estimates;
- maintain meal history and cloud synchronisation;
- provide groups, invitations, challenges, sharing, likes and reactions;
- deliver notifications selected or reasonably expected by you;
- personalise language, units, country context and application experience;
- provide support and respond to requests;
- process and administer paid features;
- diagnose faults, monitor performance and improve usability;
- secure the Service and prevent fraud, abuse and unauthorised access;
- moderate User Content and enforce our Terms and Community Guidelines;
- comply with legal obligations and respond to lawful requests;
- establish, exercise or defend legal claims; and
- create aggregated or de-identified statistics.
8.2 We will not use Personal Information for a materially unrelated purpose unless we obtain consent or the use is otherwise permitted by law.
9. Legal Bases for EEA and UK Users
9.1 Where GDPR or equivalent UK law applies, we rely on one or more of the following bases:
- contract, where Processing is necessary to provide requested Service features;
- consent, including for certain Sensitive Information, permissions or optional communications;
- legitimate interests, including Service security, fraud prevention, diagnostics, support and proportionate product improvement;
- legal obligation, where Processing is required by law; and
- legal claims or substantial public-interest grounds, where applicable.
9.2 Where we rely on legitimate interests, we assess those interests against the rights and reasonable expectations of affected individuals.
9.3 Where special-category health data is processed under GDPR, we rely on explicit consent or another applicable exception under Article 9.
10. AI Processing
10.1 Information submitted for meal analysis may be processed by automated systems and trusted third-party AI providers.
10.2 AI Processing may:
- analyse images, audio, transcripts and meal descriptions;
- identify probable foods or restaurants;
- estimate nutritional content; and
- generate confidence measures, alternatives and descriptive text.
10.3 AI Output may be incorrect. You may edit meal records and should not treat AI Output as medical advice or verified nutritional analysis.
10.4 We take reasonable steps to limit information sent for AI Processing to what is relevant to the requested function.
10.5 You should avoid including faces, documents, precise location details or unrelated Personal Information in meal photographs or recordings.
10.6 We do not permit trusted AI providers to use identifiable User Content to train their general-purpose models except where:
- we have clearly disclosed the proposed use;
- an appropriate agreement and safeguards are in place; and
- we have obtained any consent required by law.
10.7 We do not use solely automated decision-making to make decisions producing legal or similarly significant effects about users.
11. Disclosure of Information
11.1 We may disclose Personal Information to:
- authentication providers;
- cloud hosting and storage providers;
- AI and speech-processing providers;
- analytics and diagnostic providers;
- notification and communications infrastructure providers;
- payment and App Store providers;
- security, fraud-prevention and moderation providers;
- professional advisers, auditors and insurers;
- regulators, courts, law enforcement or government authorities where required or authorised by law; and
- a purchaser, investor or successor involved in a proposed or completed corporate transaction, subject to appropriate confidentiality and legal safeguards.
11.2 We require service providers to process information only for authorised purposes and to apply appropriate privacy and security protections.
11.3 We may disclose Content to other users when you use groups, sharing, invitations, likes, reactions or other Community Features.
11.4 We do not sell Personal Information in exchange for money.
12. International Processing and Transfers
12.1 We are based in Australia, but trusted third-party providers may process information in other countries.
12.2 Depending on provider infrastructure, support arrangements and the user’s location, information may be processed in Australia, the United States, countries within the European Economic Area, the United Kingdom, Singapore and other countries in which our providers or their approved subprocessors operate.
12.3 Provider locations may change as infrastructure and subprocessors change. It may not always be practicable to identify every country in advance.
12.4 Before disclosing Personal Information overseas, we take reasonable steps required under applicable law. These may include:
- contractual privacy and security obligations;
- due diligence and access restrictions;
- data-processing agreements; and
- approved transfer mechanisms, including standard contractual clauses where GDPR applies.
12.5 Overseas recipients may be subject to laws different from those in your country. You may contact us for current information about material overseas processing locations relevant to your information.
13. Community Sharing
13.1 Content you share with a private group is available to members of that group according to the group’s settings.
13.2 Other users may capture or redistribute shared Content outside the Service. We cannot control information after another user independently copies or exports it.
13.3 Group names, profile photographs, reactions and activity may be visible to other group members.
13.4 You should not share another person’s Personal Information without permission.
14. Analytics, Diagnostics and Advertising
14.1 We may use analytics and diagnostics to understand feature use, identify crashes, improve reliability and protect the Service.
14.2 Analytics may involve device identifiers, pseudonymous Account identifiers, event data and technical information.
14.3 If we introduce advertising or cross-service tracking, we will provide additional notice, obtain any required permission and update applicable App Store disclosures before commencing that activity.
14.4 We do not use health-related information or meal photographs for targeted advertising.
15. Cookies and Similar Technologies
15.1 Our websites may use cookies, local storage, pixels or similar technologies for:
- authentication and security;
- preferences and functionality;
- analytics and performance; and
- consent management.
15.2 Where required by law, non-essential technologies will not be used until consent is obtained.
15.3 Browser settings may allow you to block or delete cookies. Doing so may affect website functionality.
15.4 Mobile applications may use software development kits, device storage and identifiers serving similar operational purposes.
16. Notifications and Communications
16.1 With device permission, we may send push notifications concerning meal reminders, invitations, reactions, challenges, Account activity and Service updates.
16.2 You may manage notification categories in the application, where available, or through device settings.
16.3 We may send essential administrative or security communications where reasonably necessary. These are not promotional messages.
16.4 We will provide an unsubscribe method for direct marketing where required by law.
17. Retention
17.1 We retain Personal Information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with law, resolve disputes and maintain security.
17.2 Retention periods depend on:
- the type and sensitivity of the information;
- whether the Account remains active;
- the feature for which information was collected;
- legal, accounting and security obligations; and
- the risk associated with continued retention.
17.3 Meal records and User Content are generally retained while your Account remains active or until you delete them, subject to technical, legal and backup requirements.
17.4 Voice recordings may be retained for the period necessary to provide transcription, maintain the associated meal record, resolve technical issues or satisfy a user-selected feature. Where the original recording is no longer needed, we will delete or de-identify it within a reasonable period.
17.5 Security logs, transaction records and support communications may be retained for longer periods where reasonably required for fraud prevention, legal compliance or dispute resolution.
18. Account and Data Deletion
18.1 You may request Account deletion:
- through the application;
- through the deletion facility identified on the Nomming website; or
- by contacting support@nomming.com.au.
18.2 We may verify your identity or control of the Account before processing the request.
18.3 Personal Information will be permanently deleted from active systems within 30 days after a valid deletion request unless retention is required or permitted for:
- legal or regulatory compliance;
- fraud prevention and security;
- dispute resolution or legal claims;
- transaction and taxation records; or
- enforcement of our agreements.
18.4 Residual data may remain temporarily in encrypted backups until overwritten through ordinary backup cycles. It will not be restored for ordinary use after deletion.
18.5 We may retain data that has been irreversibly de-identified or aggregated.
18.6 Account deletion does not necessarily remove information another user has independently copied outside the Service.
18.7 Deleting an Account does not automatically cancel an App Store Subscription.
19. Security
19.1 We use technical and organisational safeguards appropriate to the nature and risk of the information we process. These may include encryption in transit, access controls, authentication controls, logging, provider due diligence, secure development practices and backup protections.
19.2 No internet transmission or storage system is completely secure. We cannot guarantee absolute security.
19.3 You are responsible for securing your device, credentials and linked authentication accounts.
19.4 If we become aware of a data breach, we will investigate and provide notifications required by applicable law.
20. Children and Young People
20.1 The Service is not intended for children under 13, and we do not knowingly permit them to create Accounts.
20.2 Where local law requires a higher minimum age or parental authorisation, that requirement applies.
20.3 Certain social or Account features may be unavailable to Australian users under 16 if required by online-safety legislation or the Service’s regulatory classification.
20.4 We seek to apply heightened privacy protections to young users, including proportionate data collection, privacy-protective defaults and restrictions on targeted advertising.
20.5 A parent or guardian who believes that a child has provided information contrary to this Policy should contact us. We will investigate and delete information where required.
21. Your Rights
21.1 Depending on applicable law, you may have rights to:
- obtain information about our Processing;
- request access to Personal Information;
- request correction of inaccurate information;
- request deletion;
- restrict or object to Processing;
- withdraw consent;
- receive certain information in a portable format;
- object to direct marketing;
- complain to a privacy regulator; and
- obtain information about applicable international safeguards.
21.2 Australian users may request access to or correction of Personal Information under the Privacy Act.
21.3 EEA and UK users may object to Processing based on legitimate interests and may request restriction or portability where applicable.
21.4 Rights are subject to legal exceptions. We may request reasonable identity verification and will respond within the period required by law.
21.5 We will not discriminate against you for exercising a privacy right.
22. Complaints
22.1 Privacy questions or complaints should be sent to support@nomming.com.au.
22.2 Please provide enough information for us to understand and investigate the issue.
22.3 We will acknowledge and investigate complaints within a reasonable period. We may request further information and will provide a written outcome where appropriate.
22.4 If you are dissatisfied, you may complain to the Office of the Australian Information Commissioner or another competent privacy authority. EEA and UK users may complain to the supervisory authority in their place of residence, work or alleged infringement.
23. Changes to This Privacy Policy
23.1 We may update this Privacy Policy to reflect changes to the Service, providers, law or information-handling practices.
23.2 We will publish the updated Policy with a revised effective date.
23.3 If a change materially affects how we use Sensitive Information or other Personal Information, we will provide additional notice and obtain consent where required.
24. Contact
Emma Infotech Pty Ltd
ABN 16 644 105 368
Queensland, Australia
Email: support@nomming.com.au