nourio

Effective July 22, 2026 · Version 1.0

Privacy Policy

Nourio is a personal recipe library. We collect the minimum we need to run the app: your account, the recipes you save, and whether your subscription is active. We don't sell your data, we don't share it with advertisers, and we don't show you ads.

Who we are

Nourio is operated by Noesis App Studio ("Nourio", "we", "us"), based in Cyprus. For GDPR purposes, Nourio is the data controller for the personal data described in this policy. The best way to reach us about anything in this policy — including access, deletion, or complaints — is s.theocharous@noesiscode.com. We aim to respond within 30 days.

What we collect

Account data

  • Email address — from Apple, Google, or email sign-up. If you use Apple's Hide My Email, we only ever see the relay address.
  • Display name — optional; you can edit or remove it in the app.
  • Provider identifier — an opaque ID from Apple or Google confirming your sign-in.

Content you save

  • Recipe links and extracted content — when you share a TikTok, Instagram, Pinterest, or web link into Nourio, we fetch the publicly available page and extract ingredients, steps, and timing. The original link, the extracted recipe, and the source thumbnail are stored under your account.
  • Collections, favourites, and notes — anything you create inside the app.

Subscription data

  • Entitlement state — whether your subscription is active, which plan, and trial status. We do not receive your payment card, billing address, or Apple ID; those stay with Apple.
  • Transaction identifier — Apple provides RevenueCat an anonymous transaction ID so your purchase can be verified and restored on a new device.

Service and abuse-prevention data

  • Daily extraction counters — we count how many recipe imports you run per day to enforce a fair-use limit and stop automated abuse of our extraction service.
  • Server logs — our backend records the fact that an extraction ran, the source link, your account identifier, and any error, so we can debug failures and monitor cost. These are ordinary server logs, retained as described below.

We do not collect: location, contacts, your photo library, your camera, microphone, health data, browsing history outside links you explicitly share into the app, or any advertising identifier. Nourio contains no third-party analytics SDK, no advertising SDK, and no cross-app tracking of any kind. Reminders about your free trial are scheduled locally on your device — we do not operate a push server and never receive a push token.

Automated recipe extraction (AI processing)

Turning a social-media post into a structured recipe is done by an AI model, and we want to be specific about what that involves.

  • When you share a link, our server fetches the public page and sends the page text and any recipe images from it to Google's Gemini model, running on Google Cloud Vertex AI in the United States, which returns the ingredients, steps, and timing in a structured form.
  • What is sent is the content of the public page you chose to share, plus the instructions our system gives the model. Your email address, display name, and the rest of your recipe library are not sent to the model.
  • Google processes this as our processor under the Google Cloud data processing terms, which provide that customer data submitted to Vertex AI is not used to train Google's models.
  • This is automated processing, but it does not produce legal or similarly significant effects about you — it only formats a recipe. If an extraction is wrong you can edit any field by hand in the app.

How we use it

  • To run the app: sign you in, extract and save your recipes, and sync them across your devices.
  • To process subscriptions and free trials, and to comply with App Store billing rules.
  • To respond to your support emails and reproduce bugs you report.
  • To enforce fair-use limits, detect abuse, prevent fraud, and control the cost of our extraction service.
  • To comply with legal obligations.

We do not run targeted advertising, build advertising profiles, or sell your data.

Legal basis (GDPR)

  • Performance of a contract (Art 6(1)(b)) — your account, your saved recipes, recipe extraction, and subscription handling. These are the service you signed up for.
  • Legitimate interests (Art 6(1)(f)) — server logs, fair-use limits, security, and abuse prevention. Our interest is keeping the service working and affordable; we balance it by keeping these records minimal and short-lived.
  • Consent (Art 6(1)(a)) — local reminder notifications, which you opt into and can switch off at any time in your device settings.
  • Legal obligation (Art 6(1)(c)) — retaining transaction records where tax or consumer law requires it, and responding to lawful requests.

Who we share data with

We use a small number of processors. Each is contractually bound to handle your data only on our instructions. We name all of them:

  • Google LLC — Firebase (Authentication, Cloud Firestore, Cloud Functions). Our primary backend; stores your account, recipes, and collections. Processed in the United States. Firebase privacy.
  • Google LLC — Google Cloud Vertex AI (Gemini). Performs the recipe extraction described above. Processed in the United States. Google Cloud data processing terms.
  • RevenueCat, Inc. — subscription state and receipt validation. Receives your account identifier and an anonymous Apple transaction ID. Processed in the United States. RevenueCat privacy.
  • Apple Inc. — App Store billing and Sign in with Apple. Apple is an independent controller for your purchase; it never shares your card or Apple ID with us.
  • Google LLC — Sign in with Google, only if you choose that sign-in method.

We do not share your data with advertising networks, data brokers, or analytics products that build user profiles. We may disclose data if legally compelled, or to protect our rights and the safety of others.

International transfers

Nourio's backend runs in the United States, and all of the processors named above process data there. If you are in the United Kingdom, the European Economic Area, or Switzerland, this means your personal data is transferred outside your home jurisdiction.

For those transfers we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, as incorporated into our agreements with Google and RevenueCat. You can request a copy of the relevant safeguards by emailing us.

How long we keep it

  • Account, recipes, and collections — kept while your account is active. Deleting your account erases them immediately (see below).
  • Fair-use counters — reset daily; historical counters are removed with your account.
  • Server logs — retained for up to 30 days by our hosting platform, then rotated out automatically.
  • Subscription and transaction records — retained for as long as tax and consumer-protection law requires, typically up to 7 years. These are held by Apple and RevenueCat; we keep only your entitlement status.
  • Support emails — kept for up to 24 months so we have context if you write to us again.

Your rights and how to use them

Wherever you live, you can do the two most important things directly in the app, without asking us:

  • Export your dataSettings → Privacy & data → Export my data produces a complete JSON file of your recipes and collections that you can save or send anywhere.
  • Delete your accountSettings → Privacy & data → Delete account permanently erases your account, every recipe and collection, and your sign-in record. This is immediate and irreversible, and we cannot recover it afterwards. Deleting your account does not cancel your App Store subscription — only Apple can do that, in Settings → Apple ID → Subscriptions.

If you are in the UK, EEA, or another jurisdiction with equivalent law, you also have the rights to access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent at any time. Email s.theocharous@noesiscode.com and we will respond within 30 days. We will not charge you or treat you differently for exercising a right.

If you think we have handled your data badly, please tell us first — but you can always complain to a supervisory authority. In Cyprus that is the Office of the Commissioner for Personal Data Protection; in the UK it is the Information Commissioner's Office; elsewhere in the EEA it is your national authority.

Children

Nourio is not directed at children under 13, or under 16 in jurisdictions where that is the age of digital consent. We do not knowingly collect data from children under those ages. If you believe a child has provided us data, contact us and we will delete it.

Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Access to production data is limited to the people who need it. Firebase Security Rules scope every recipe and collection to the account that created it, and your subscription status is written only by our server, never by the app on your device.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours and tell you directly where the law requires it.

Changes to this policy

If we make material changes we will notify you in the app and update the effective date and version at the top of this page. Continuing to use Nourio after a change means you accept the updated policy.

Contact

Privacy questions, data requests, or anything else: s.theocharous@noesiscode.com.