Privacy Policy
Effective Date: September 8, 2026 · Version 1.2
This is the web-hosted copy of the Privacy Policy displayed inside the Corm iOS application. The in-app version at Settings → About → Privacy Policy and this page render the same counsel-drafted Version 1.2 text.
1. Introduction
This Privacy Policy explains how Corm Technologies LLC ("we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use the Corm mobile application (the "Application"). We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and all other applicable data protection laws.
This policy applies to all users worldwide. Where regional laws provide additional rights or protections, those are addressed in Section 11 (Region-Specific Rights).
By using the Application, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Application.
2. Data Controller
Corm Technologies LLC is the data controller responsible for your personal data under the GDPR.
Corm Technologies LLC
P.O. Box 172
Blue Bell, PA 19422-0172
For questions about data processing or to exercise your rights, contact us at: privacy@cormtechnologies.com.
For users in the European Economic Area (EEA) who have concerns about our data handling that we have not satisfactorily addressed, you have the right to lodge a complaint with your local Data Protection Authority (DPA).
3. Data We Collect
3.1 Data You Provide Directly
Account Information: Name, email address, and authentication credentials.
Profile Information: Dietary restrictions, allergy severity levels, and personal preferences.
Household Information: Household member names, dietary restrictions per member, and household composition for Household (Family) accounts. If you invite someone to your household, we process the email address you provide for them in order to send and manage the invitation. If you add profile information about another household member (including a child in your household), you are responsible for having that person's permission — or, for your minor child, giving consent on their behalf — as described in the Terms of Service.
Loyalty Cards: Store loyalty cards you choose to add, including the store name, card number, barcode data, and any notes you attach. Loyalty card data is encrypted and, when cloud sync is enabled for your subscription tier, synchronized to our servers so your cards are available across your devices.
Pantry Data: Items you add to your digital pantry, including item names, quantities, purchase dates, expiration dates, storage locations, and categories.
Meal Plans: Meals you plan, schedule, complete, skip, or modify, including dates, meal types, and associated recipes.
Shopping Lists: Items added to shopping lists, checked-off status, quantities, and associated recipes.
Recipes: User-created recipes including titles, ingredients, instructions, prep/cook times, nutritional information, and images.
Budget Data: Budget limits, spending entries, and financial preferences you configure.
Feedback and Support: Any messages, feedback, or support requests you submit.
3.2 Data Collected Automatically
Device Information: Device model, operating system version, app version, device identifier (for crash reporting only), screen size, and — if you enable notifications — the device push notification token used to deliver alerts to your device.
Usage Analytics: Feature usage patterns, screen views, interaction counts, session duration, and performance metrics. All analytics are processed through technical safeguards that scrub personally identifiable information before transmission.
AI Behavioral Data: Your interactions with AI features, including: recipes viewed, cooked, and rated; meal suggestion acceptance and dismissal patterns; cooking time patterns; and ingredient preference signals. This data is used to personalize your experience.
Perishable Tracking Data: Shelf life learning data derived from your usage patterns (when items are consumed or removed relative to estimated expiration).
Performance Telemetry: App launch time, network request timing, and crash reports.
Pricing Telemetry: Aggregated, anonymized price data for grocery cost estimation (no individual transaction data is stored).
3.3 Data We Do NOT Collect
We do NOT collect precise geolocation data.
We do NOT access your device's camera, microphone, contacts, or photos without explicit per-use permission.
We do NOT collect health data from Apple HealthKit or any health monitoring service.
We do NOT collect financial account numbers, credit card numbers, or banking information (billing is handled entirely by Apple).
We do NOT engage in cross-app tracking.
4. Legal Bases for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Application's core services, including account management, meal planning, pantry tracking, shopping list management, recipe storage, and cloud synchronization.
Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, including: improving the Application through analytics; personalizing AI recommendations; preventing fraud and abuse; and ensuring Application security. We balance these interests against your rights and freedoms, and you may object to this processing at any time.
Consent (Art. 6(1)(a)): Processing based on your explicit, freely given, specific, and informed consent, including: analytics data collection; marketing communications; and non-essential AI behavioral profiling. You may withdraw consent at any time through the Application's consent settings without affecting the lawfulness of processing before withdrawal.
Special Category Data (GDPR Article 9): Dietary restriction and allergy information — including the severity levels you configure — can reveal information about your health, so we treat it as special-category data. Cloud synchronization of your dietary data happens only with your explicit consent (Art. 9(2)(a)), requested separately in the Application before dietary sync is enabled. You may withdraw that consent at any time in the dietary settings; withdrawing stops the synchronization and deletes the synced cloud copy, while on-device dietary features continue to work. Household dietary profiles you enter for family members receive the same protections.
We apply data minimization principles and only collect data that is necessary for the stated purposes.
5. How We Use Your Data
Providing Services: Operating the Application's core features including meal planning, pantry management, shopping lists, recipe management, and cloud sync.
AI Personalization: Using on-device and server-side AI models to provide personalized meal suggestions, recipe recommendations, perishable intelligence, and autonomous meal planning.
Food Safety Notifications: Generating expiration alerts, perishable urgency notifications, and shelf life estimates based on your pantry data and learned patterns.
Dietary Conflict Detection: Checking recipes and meal plans against your configured dietary restrictions and allergen profiles.
Budget Analytics: Calculating spending estimates, budget utilization, and providing cost projections based on your configured budget parameters.
Service Improvement: Analyzing aggregated, anonymized usage patterns to improve features, fix bugs, and optimize performance.
Security: Detecting and preventing unauthorized access, fraud, and abuse.
Communications: Sending service-related notifications (e.g., expiration alerts, plan reminders). Marketing communications are sent only with your explicit consent.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We share data only in the following circumstances:
Household Members: If you join or create a Household (Family) account, data you contribute to shared features — including the shared pantry, shopping lists, meal plans, shared recipes, and the household's combined budget and spending — is visible to the other members of your household. Leaving a household ends this sharing for future data; content you previously shared with the household may remain available to its remaining members.
Service Providers: We use third-party cloud infrastructure for authentication, data synchronization, remote configuration, and storage, and an email delivery provider for transactional messages such as household invitations. Service providers process data on our behalf under Data Processing Agreements compliant with GDPR Article 28.
Apple: Apple processes subscription billing and payment data. We do not receive or store your payment information.
Analytics: With your consent, we collect anonymized analytics events in our own analytics infrastructure for service improvement. Technical safeguards scrub personally identifiable information before transmission. If we ever engage a third-party analytics provider, it will process data only on our behalf under a Data Processing Agreement, and this policy will be updated accordingly.
Legal Requirements: We may disclose data when required by law, court order, or governmental regulation, or when necessary to protect our legal rights, safety, or property.
Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
Grid Carbon-Intensity Service: To schedule non-urgent background work at times when the electrical grid is cleaner, the Application queries a third-party grid carbon-intensity service (Microsoft's Carbon Aware API) with a fixed, non-personal region identifier. These requests contain no account data or personal content; as with any internet request, the provider technically receives your device's IP address.
We do not share your dietary restriction data, health-related preferences, or allergen profiles with any third party for marketing or advertising purposes.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
Account Data: Retained for the duration of your account. When you delete your account or make a verified erasure request, we begin a cascading deletion across our services promptly; residual copies in encrypted backups age out within 30 days.
Meal Plans and Pantry Data: Retained while your account is active. Historical meal plan data older than 12 months may be aggregated and anonymized.
Loyalty Card Data: Retained while your account is active; deleted as part of the cascading deletion when your account is deleted, and from our servers under the Subscription Lapse schedule below when your subscription ends.
Subscription Lapse (Downgrade to Free Tier): The Free Tier is local-only. If your subscription ends, cloud-stored copies of your recipes, pantry, shopping list, meal plans, loyalty cards, budget and spending data, and AI personalization data are deleted from our servers 7 days after the downgrade takes effect. Recipes shared with a household are retained for the remaining household members. Copies already on your device remain on your device, and restarting a subscription within the 7-day window cancels the deletion.
AI Behavioral Data: On-device behavioral models are stored locally and deleted when you uninstall the Application. Server-side behavioral patterns are anonymized within 90 days of account deletion.
Analytics Data: Retained in anonymized form for up to 24 months for service improvement purposes.
Financial/Budget Data: Retained while your account is active and deleted upon account deletion.
Backup Data: Cloud backups are purged within 30 days of account deletion.
Legal Holds: Data may be retained longer if required by legal obligation or ongoing dispute.
8. Data Security
We implement comprehensive security measures to protect your data:
Encryption at Rest: Sensitive data is encrypted using industry-standard encryption.
Encryption in Transit: All network communications use TLS 1.2 or higher.
PII Safeguards: Dedicated technical controls scrub personally identifiable information from analytics and telemetry data before it leaves your device.
Biometric Authentication: Face ID and Touch ID are available for sensitive operations. Biometric data is processed entirely on-device by Apple's framework and is never transmitted to our servers.
Device Integrity: Application integrity verification ensures the Application is running on a genuine, non-compromised device.
Access Controls: Server-side security policies ensure users can only access their own data.
Consent Verification: All data processing operations verify user consent status before proceeding.
Breach Notification: If a personal data breach occurs, we will notify affected users and the competent supervisory authorities as required by applicable law, including GDPR Articles 33 and 34 and applicable US state breach notification laws.
No security system is impenetrable. While we take reasonable precautions to protect your data, we cannot guarantee absolute security.
9. Consent Management
The Application provides granular consent controls through the Consent Settings interface:
Functional Consent: Required for core Application features. Cannot be disabled while using the Application. Covers: account authentication, meal planning, pantry management, shopping lists, recipe storage, and cloud synchronization.
Analytics Consent: Optional. Controls collection of usage analytics, performance telemetry, and anonymized behavioral data for service improvement. You may opt out at any time without affecting core functionality.
Marketing Consent: Optional. Controls marketing communications, promotional notifications, and feature announcements. You may opt out at any time.
Consent preferences are stored locally and synchronized with our servers. Changes to consent take effect immediately. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
10. Your Privacy Rights
Depending on your location, you have some or all of the following rights regarding your personal data:
10.1 Rights Under GDPR (EEA, UK, Switzerland)
Right of Access (Art. 15): Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
Right to Erasure / Right to Be Forgotten (Art. 17): Request deletion of your data. We perform a cascading purge across all services when processing deletion requests.
Right to Restriction of Processing (Art. 18): Request that we limit how we use your data while a complaint is being investigated.
Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
Right to Object (Art. 21): Object to processing based on legitimate interests, including AI profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
Right Not to Be Subject to Automated Decision-Making (Art. 22): Our AI features provide recommendations and suggestions, not binding decisions. You always retain the ability to accept, modify, or reject any AI output.
Right to Withdraw Consent (Art. 7(3)): Withdraw any previously given consent through the consent settings panel.
10.2 Rights Under CCPA/CPRA (California Residents)
Right to Know: Request disclosure of what personal information we collect, use, and share.
Right to Delete: Request deletion of your personal information.
Right to Correct: Request correction of inaccurate personal information.
Right to Opt-Out of Sale/Sharing: Corm Technologies LLC does not sell or share personal information as defined under the CCPA.
Right to Limit Use of Sensitive Personal Information: Dietary restriction and allergen data is used only for providing Application services.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
10.3 Exercising Your Rights
You may exercise your rights by: using the in-app privacy controls; submitting a request to privacy@cormtechnologies.com; or using the account deletion feature within the Application. We will respond to verifiable requests within one month (GDPR) or 45 days (CCPA). Where a request is complex or we receive a high volume of requests, these periods may be extended as permitted by law (by up to two further months under GDPR, or one additional 45-day period under CCPA); we will tell you within the initial period if an extension is needed and why. Identity verification may be required to protect against fraudulent requests.
11. Region-Specific Provisions
11.1 European Economic Area (EEA)
The Application automatically detects your region and applies GDPR-compliant processing for users in the EEA. This includes: enhanced consent requirements before any non-essential data processing; Data Protection Impact Assessments (DPIAs) for high-risk processing activities; appointment of sub-processors only under GDPR-compliant Data Processing Agreements; and international data transfer safeguards for any data transferred outside the EEA.
11.2 International Data Transfers
Your data may be transferred to and processed in the United States or other countries where our service providers operate. For transfers from the EEA/UK, we rely on: EU Standard Contractual Clauses (SCCs) approved by the European Commission; adequacy decisions where applicable; and supplementary technical measures including encryption and access controls. You may request a copy of the applicable transfer safeguards by contacting privacy@cormtechnologies.com.
11.3 California (CCPA/CPRA)
Categories of personal information collected in the preceding 12 months, per CCPA Section 1798.100:
Identifiers: Name, email address, account ID.
Personal Information (Cal. Civ. Code 1798.80(e)): Name and profile details you provide.
Commercial Information: Store loyalty card numbers and barcode data you add; budget limits and spending entries you record.
Internet/Electronic Activity: App usage data, feature interactions, device information.
Inferences: AI-derived preferences, meal patterns, recipe preferences.
Sensitive Personal Information: Dietary restrictions and allergen data (used only to provide services).
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
11.4 Children's Privacy
The Application is not directed at children under 13 (or the applicable minimum age of digital consent in your jurisdiction, whichever is higher), and children under that age may not create an account. We do not knowingly collect personal data directly from children under that age. If we discover that a child under the applicable age has created an account or otherwise provided us with personal data directly, we will delete the account and its data promptly. Parents or guardians who believe their child has provided us with personal data should contact us at privacy@cormtechnologies.com.
Separately, an adult account holder may add a household member profile (such as a name and dietary restrictions) for a child in their household. That information is provided and controlled by the parent or guardian, is used only to provide household features such as dietary conflict detection, and can be edited or deleted by the account holder at any time.
12. AI and Automated Processing Transparency
Consistent with our transparency obligations under applicable law, including the EU AI Act and the GDPR's requirements for automated processing, we disclose the following about our AI features:
No Third-Party AI Providers: Content you enter in the Application — recipes, pantry items, photos, and other text — is not sent to third-party artificial intelligence or large-language-model providers. AI inference runs on your device or on infrastructure operated for Corm Technologies LLC.
Purpose: AI features are used to personalize meal suggestions, predict food perishability, optimize meal plans, and improve user experience. No AI feature makes legally or similarly significant decisions about you.
Logic: Recommendation models use collaborative filtering, similarity matching, and behavioral pattern analysis. Perishable intelligence uses statistical shelf life modeling. Autonomous planning uses weighted scoring across multiple factors including pantry coverage, variety, time constraints, and dietary compliance.
Data Used: AI models are trained on your interaction data (recipes viewed, cooked, and rated; items purchased and consumed; meal patterns) as well as aggregated, anonymized data from other users.
Impact: AI outputs are recommendations only. You always have the option to accept, modify, or reject any suggestion. No automated decision restricts your access to features or content.
Opt-Out: You may disable AI personalization through the Application's settings. You may disable Autonomous Planning at any time. Disabling AI features will result in generic (non-personalized) suggestions.
Model Updates: AI recommendation models may be updated over-the-air. Model updates improve accuracy but may change the nature of suggestions.
13. Cookies and Tracking Technologies
The Corm mobile application does not use browser cookies. We use the following technologies:
Local Storage: App preferences, consent settings, and cached data are stored on-device using standard iOS storage mechanisms.
Analytics SDKs: With your consent, anonymous usage events are collected for performance monitoring. Technical safeguards ensure no personally identifiable data is included.
No Cross-App Tracking: We do not track users across other apps or websites.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through in-app notifications and/or email at least 30 days before they take effect, and the Application will present the updated policy for your review and acceptance. The "Effective Date" at the top of this policy indicates when it was last updated. Where required by law, we will seek your renewed consent for material changes to data processing.
15. Contact Information
For privacy inquiries, data subject requests, or complaints:
Email: privacy@cormtechnologies.com
Data Protection Inquiries: dpo@cormtechnologies.com
Mailing Address:
Corm Technologies LLC
P.O. Box 172
Blue Bell, PA 19422-0172
Response Time: We aim to respond to all inquiries within 30 days.
European users who are not satisfied with our response may lodge a complaint with their local Data Protection Authority. A list of EEA DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
© 2026 Corm Technologies LLC. All rights reserved.
Contact: legal@cormtechnologies.com | Privacy: privacy@cormtechnologies.com