Privacy policy
Your pantry is personal.
This policy explains what Nomly collects, why we need it, which services help us process it, and the choices you have.
1. Who we are
Nomly is operated by Santiago Design Ltd, the controller responsible for the personal data described in this policy. We are registered in England and Wales under company number 13010534. Our registered office is 124 City Road, London, England, EC1V 2NX.
Questions or data requests can be sent to support@nomly.uk.
2. Data we collect
Account details
We process your Firebase user ID, email address and, where made available by your chosen sign-in provider, your display name. If you sign in with Apple or Google, that provider also processes information under its own privacy terms. Firebase Authentication processes authentication and security information such as login credentials, IP address, user agent and sign-in activity.
Ocado order screenshots
Nomly accesses only the image you choose from Photos. We upload the original screenshot, which can include product names, quantities, prices, delivery or order details and any other information visible in the image. Nomly does not need your Ocado password and you should never send it to us.
Pantry information
We store the information extracted from your screenshot and the changes you make, including product names, quantities, pack sizes, use-by or best-before dates, storage status, remaining amounts and whether an item has been frozen, used or removed.
Recipe and app preferences
We process your pantry profile, cooking level, serving count, meal and cuisine choices, recipe requests, generated and saved recipes, and updates made when you mark a recipe as cooked.
Notifications and support
If you enable expiry reminders, we store your notification preference, device notification token, platform and relevant timestamps. If you contact support, we process the information in your message. If you delete your account, you may optionally select a reason for leaving; we may record that selection as operational feedback after deletion succeeds.
3. How and why we use data
- To create and secure your Nomly account.
- To read a receipt screenshot and build your pantry.
- To track stock and help prioritise food that needs using.
- To generate recipes using your pantry and preferences.
- To deduct ingredients when you mark a recipe as cooked.
- To send expiry reminders when you choose to enable them.
- To provide support, diagnose failures and protect the service.
- To comply with legal obligations and enforce our rights.
Under UK data-protection law, we rely primarily on providing the service you request, our legitimate interests in operating and securing Nomly, your consent where a permission or optional notification is requested, and legal obligations where relevant. You can withdraw notification permission at any time in Nomly or your device settings.
4. Firebase and OpenAI processing
Google Firebase
Nomly uses Google Firebase and related Google Cloud services for authentication, database storage, receipt-image storage, backend functions, hosting and push-notification delivery. This means the account, pantry, recipe, upload and notification information described above is processed on Google infrastructure.
OpenAI
We send uploaded receipt imagery to OpenAI’s API so its vision models can identify delivered products and order information. We also send relevant pantry contents, quantities, expiry timing and recipe preferences to OpenAI’s API to generate recipes. We do not send your Ocado login credentials.
AI extraction and recipes can be inaccurate. You should review pantry dates, quantities, allergens and recipe instructions before relying on them. Nomly does not use this processing to make decisions with legal or similarly significant effects.
5. When data is shared
We share data only as needed to operate Nomly, with service providers such as Google Firebase/Google Cloud, OpenAI, and Apple or Google when you choose their sign-in services. Providers act under their own contractual and security commitments.
We may also disclose information where required by law, to protect users or the service, or as part of a corporate sale or restructuring with appropriate safeguards. Nomly does not sell personal data and does not share it for behavioural advertising. We do not currently send marketing emails.
Firebase and OpenAI operate internationally, including in the United States. Where personal data is transferred outside the UK, we rely on the safeguards made available by our providers and applicable data-transfer mechanisms.
6. How long we keep data
Your original Ocado screenshots, extracted pantry information, profile, preferences and recipes are retained until deleted or the account is deleted. Individual pantry items and recipes may also be removed through the controls available in Nomly.
When account deletion completes, Nomly removes the account’s active Firebase Authentication record, Firestore data and stored receipt images. Limited security, operational and deletion logs, and copies in provider backup systems, may remain for the providers’ standard retention periods or where legally required. OpenAI handles temporary API data according to the controls described above.
7. Your choices and rights
You can update pantry stock, profile choices, saved recipes and notification preferences inside Nomly. You can permanently delete your account by opening You, scrolling to the bottom and selecting Delete account. A multi-step confirmation helps prevent accidental deletion.
Depending on the law that applies to you, you may have rights to access, correct, erase, restrict or object to processing of your personal data, and to receive a portable copy. You may also complain to the UK Information Commissioner’s Office. Contact us first if you would like help exercising any of these rights.
8. Security
We use authenticated access, user-specific database and storage rules, encrypted network connections and managed cloud services to protect Nomly data. No online service can guarantee absolute security, so please use a secure sign-in method and contact us if you suspect unauthorised access.
9. Children
Nomly is a general-audience food-planning service and does not currently ask users for their age or impose a specific age limit. It is not designed or marketed specifically to children. If you are a parent or guardian and believe a child has provided personal data inappropriately, contact us so we can investigate and delete it where appropriate.
10. Changes and contact
We may update this policy when Nomly’s features, providers or legal obligations change. We will update the date at the top and, where appropriate, provide an in-app notice.
Santiago Design Ltd
Company number 13010534
124 City Road, London, England, EC1V 2NX
support@nomly.uk