Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how Nibbi collects, uses, shares, and protects personal data when you use our mobile application, website, and related services (the "Service").
Controller and contact
The controller of your personal data is Iurii Shpynev, Efkleidou 9, 3031 Limassol, Cyprus. For privacy questions or to exercise your rights, contact privacy@nibbi.app.
Personal data we collect
Depending on how you use Nibbi, we may collect:
- Account data, including your name, email address, account identifier, and sign-in method.
- Sign-in data received from Apple or Google, limited to the information you choose to share with us.
- Preference and activity data, such as likes, skips, saved dishes, and interactions used to personalise your feed.
- Location data you provide or your device supplies after you grant permission, such as a city or coordinates used to show nearby dishes and places.
- User Content, including dish photos, captions, dish details, and any location information you submit.
- Technical and security data, such as device and app version, IP address, log data, crash reports, and diagnostic events.
- Communications you send to us, including support, moderation, and privacy requests.
We collect data directly from you, automatically when you use the Service, and from Apple or Google when you choose their sign-in options.
How and why we use personal data
We use personal data for the following purposes and legal bases:
- To create and maintain your account, provide the feed, save preferences, and deliver requested features. This processing is necessary to perform our contract with you.
- To personalise recommendations using your interactions and, where enabled, location. We rely on performance of our contract for account-based personalisation and on your permission where the law requires consent, including for device location.
- To moderate User Content, prevent fraud or abuse, secure the Service, troubleshoot problems, and enforce our Terms. We rely on our legitimate interests and, where applicable, legal obligations.
- To understand app performance and fix crashes through Firebase Analytics and Crashlytics. We rely on our legitimate interests to improve a reliable service, or on consent where required by applicable law.
- To respond to your requests and comply with legal, accounting, or regulatory obligations.
Recommendations are generated from your food preferences, interactions, and optional location. This is profiling, but it does not produce legal or similarly significant effects. You can use a guest feed without an account and can change location permissions in your device settings.
How we share data
We do not sell personal data or use it for targeted advertising. We share data only as necessary with service providers that process it on our behalf, including:
- Google, for Google Sign-In, Google Maps, Firebase Analytics, and Firebase Crashlytics.
- Apple, for Sign in with Apple.
- Cloudflare, including Cloudflare R2, for infrastructure and storage of uploaded content.
- Hosting, database, security, and support providers that enable the Service to operate.
We may also disclose information if required by law, to protect rights, safety, and security, or in connection with a merger, sale, or transfer of the Service. User Content approved for discovery may be visible to other users together with the information you include in it.
International transfers
Some providers may process data outside the European Economic Area. Where this happens, we use a lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and apply appropriate safeguards required by law.
Retention
We keep data only for as long as needed for the purposes described here. Our standard retention periods are: account and preference data for the life of your account and up to 30 days after a verified deletion request; User Content until it is removed and up to 30 days in backups; security and server logs for up to 90 days; and Firebase Analytics data for up to 14 months. Crash and diagnostic data is retained for up to 90 days. We may retain limited data longer when necessary to resolve a dispute, prevent abuse, or comply with law.
Security
We use reasonable technical and organisational measures designed to protect personal data. No online service can guarantee absolute security, so please use a strong, unique password and contact us promptly if you believe your account has been compromised.
Your rights
Subject to applicable law, you may ask us to access, correct, erase, restrict, or provide a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent at any time where processing relies on consent; this does not affect processing already carried out. To make a request, email privacy@nibbi.app.
If you are in the EEA or United Kingdom, you also have the right to complain to your local data-protection authority. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.
Children
Nibbi is not directed to children under 14. We do not knowingly allow a person under 14 to create an account or submit User Content without the consent required by applicable law. If you believe a child has provided us personal data in breach of this policy, contact us and we will take appropriate action.
Third-party services and links
Apple, Google, Google Maps, and other linked services have their own privacy policies. We are not responsible for their privacy practices. Review their notices before using those services.
Changes to this policy
We may update this Privacy Policy when our practices or legal obligations change. For material changes, we will provide reasonable notice in the Service or by email where appropriate. The date above shows when this policy was last updated.
Contact us
For privacy questions or requests, contact privacy@nibbi.app.
