Corm

Privacy Policy

Effective Date: September 30, 2026 · Version 1.4

This is the web-hosted copy of the Privacy Policy displayed inside the Corm iOS application. The in-app version at Settings → About → Privacy Policy and this page render the same Version 1.4 text.

1. Introduction

This Privacy Policy explains how Corm Technologies, LLC ("we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use the Corm mobile application (the "Application"). We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and all other applicable data protection laws.

This policy applies to all users worldwide. Where regional laws provide additional rights or protections, those are addressed in Section 11 (Region-Specific Rights).

By using the Application, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Application.

2. Data Controller

Corm Technologies, LLC is the data controller responsible for your personal data under the GDPR.

Corm Technologies, LLC

P.O. Box 172

Blue Bell, PA 19422-0172

For questions about data processing or to exercise your rights, contact us at: privacy@cormtechnologies.com.

For users in the European Economic Area (EEA) who have concerns about our data handling that we have not satisfactorily addressed, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

3. Data We Collect

3.1 Data You Provide Directly

Account Information: Name (if you give one), email address, and authentication credentials.

Profile Information: Dietary restrictions, allergy severity levels, and personal preferences.

Household Information: Household member names, dietary restrictions per member, and household composition for Household (Family) accounts. If you invite someone to your household, we process the email address you provide for them in order to send and manage the invitation. If you add profile information about another household member (including a child in your household), you are responsible for having that person's permission — or, for your minor child, giving consent on their behalf — as described in the Terms of Service.

Loyalty Cards: Store loyalty cards you choose to add, including the store name, card number, barcode data, and any notes you attach. On your device, loyalty card data is stored encrypted. When cloud sync is enabled for your subscription tier, it is also synchronized to our servers so your cards are available across your devices; there, our access controls limit it to your account, and our hosting provider encrypts it in transit and at rest. It is not end-to-end encrypted.

Pantry Data: Items you add to your digital pantry, including item names, quantities, purchase dates, expiration dates, storage locations, and categories.

Meal Plans: Meals you plan, schedule, complete, skip, or modify, including dates, meal types, and associated recipes. When you mark a meal complete, we also record how it was completed: the ingredient adjustments and notes you enter, the servings, and the pantry items and quantities that completing it deducted from your pantry.

Shopping Lists: Items added to shopping lists, checked-off status, quantities, associated recipes, and your chosen order of store sections.

Recipes: User-created recipes including titles, ingredients, instructions, prep/cook times, and images.

Budget Data: Budget limits, spending entries, and financial preferences you configure.

Feedback and Support: Any messages, feedback, or support requests you submit.

3.2 Data Collected Automatically

Device Information: Device model, operating system version, app version, screen size, and — if you enable notifications — the device push notification token used to deliver alerts to your device. On a paid plan (Premium, Family, or a plan shared by your household), and only with your Analytics consent, crash and diagnostic reports also carry your device's hardware model code (for example "iPhone15,2"). Device identifiers: the Application creates random identifiers on each device where it is installed; they are not your device's advertising identifier or Apple's identifier for vendors. Each belongs to the device rather than to one account, so every account used on that device has the same one. On a paid plan, one is sent with each price-learning record (the prices you pay and correct, which Corm learns from; see AI Behavioral Data in Section 7), and one can be stored in the version information of the recipes and shopping-list items you sync, and of the meal plans that include those recipes, so that changes made on different devices can be put in order. These identifiers are linked to the account they are sent with, are used only to make the Application work, and are never used for tracking or advertising.

Usage Analytics: Feature usage patterns, screen views, interaction counts, session duration, and performance metrics. These are collected only with your consent, are processed in our own infrastructure, and are never shared with a third-party analytics provider.

AI Behavioral Data: Your interactions with AI features, including: recipes viewed and cooked; meal suggestion acceptance and dismissal patterns; cooking time patterns; and ingredient preference signals. This data is used to personalize your own experience and, only if you allow it, to train and check the models that rank meal ideas for all users (see Section 9).

Perishable Tracking Data: Shelf life learning data derived from your usage patterns (when items are consumed or removed relative to estimated expiration).

Performance Telemetry and Diagnostics: Only on a paid plan (Premium, Family, or a plan shared by your household), and only with your consent, we collect two separate streams, and they differ in whether they are tied to you. AI performance measurements (response times, failure rates, device class, and thermal state) carry no account identifier and cannot be traced back to you. Crash, hang, launch-time, CPU-usage and disk-write diagnostics reported by Apple's MetricKit — including truncated call stacks — are stored against your account identifier, so they are linked to you; they are deleted when your account is deleted. These diagnostics also include a note when the Application could not load the online recipe catalog and showed its built-in recipes instead, with the kind of problem and how many times it happened; the note contains no recipes, pantry items or anything you entered. On the free plan none of this leaves your device: nothing is collected while your account is on the free plan, and nothing recorded then is sent if you later subscribe. Apple hands a crash or diagnostic report to the Application only when the Application next starts, and the report is treated under the plan in place at that moment, so a report about a problem that happened shortly before you subscribed can be sent once you have subscribed.

Pricing Telemetry: Price observations used to estimate grocery costs, collected only on a paid plan (Premium, Family, or a plan shared by your household), with your Analytics consent and while you allow AI personalization. On the free plan no price observations leave your device, and none recorded then are sent if you later subscribe. There are two kinds of record: a price you record when you buy an item, and an occasional sample of the Application's own price estimates. Each record carries the price and its currency, the item's grocery category, a coarse region (US, EU, Asia-Pacific or Global, taken from your device's region setting or from the data region you choose in the Application, not from your location), the date and time it was recorded, the app version, and a code derived from the identifier the Application gave the item. When the price can be converted to a standard unit, a purchase record also carries the price per unit, the unit (such as a pound) and whether the item is measured by weight, volume or count, together with a shared item code derived from the item's name — the same code for the same item across all users, which is what allows prices to be pooled. That code is not secret: it is computed from the name, so the item name can be worked out from it. An estimate sample also carries how the estimate was made: its source, how confident it was, and whether it relied on a package size the Application assumed. These records carry no account identifier and no precise location. Our servers add a record number, the time the record arrived, and a number from 0 to 99 worked out from your account identifier, which about one in every hundred accounts share; it is used only to make sure, before a pooled price is published, that it comes from enough different people and that each group of accounts sharing a number has an equal say in it.

3.3 Data We Do NOT Collect

We do NOT collect precise geolocation data.

We do NOT access your device's camera, microphone, contacts, or photos without explicit per-use permission.

We do NOT collect health data from Apple HealthKit or any health monitoring service.

We do NOT collect financial account numbers, credit card numbers, or banking information (billing is handled entirely by Apple).

We do NOT engage in cross-app tracking.

4. Legal Bases for Processing (GDPR Article 6)

We process your personal data on the following legal bases:

Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Application's core services, including account management, meal planning, pantry tracking, shopping list management, recipe storage, and cloud synchronization.

Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, including: improving the Application through analytics; personalizing your own suggestions from your own activity; preventing fraud and abuse; and ensuring Application security. We balance these interests against your rights and freedoms, and you may object to this processing at any time. You object to AI personalization with the "Personalize my suggestions" choice described in Section 9. On a paid plan (Premium, Family, or a plan shared by your household), your objection is kept with your account and applies on every device where you sign in; on the free plan it is kept on your device, for your account.

Consent (Art. 6(1)(a)): Processing based on your explicit, freely given, specific, and informed consent, including: analytics data collection; marketing communications; using your diet and allergy information in Corm's AI features; and using the records of the meal ideas you were shown and chose to train and check the models that rank meal ideas for all users. You may withdraw consent at any time through the Application's consent settings without affecting the lawfulness of processing before withdrawal.

Legal Obligation (Art. 6(1)(c)): Keeping a record of the AI and Analytics choices you make on a paid plan, and of any objection you send us, so that we can show that we honored them (GDPR Articles 5(2) and 7(1)). Section 7 describes what the record holds and how long it is kept.

Special Category Data (GDPR Article 9): Dietary restriction and allergy information — including the severity levels you configure — can reveal information about your health, so we treat it as special-category data. Cloud synchronization of your dietary data happens only with your explicit consent (Art. 9(2)(a)), requested separately in the Application before dietary sync is enabled. You may withdraw that consent at any time in the dietary settings; withdrawing stops the synchronization and deletes the synced cloud copy, while on-device dietary features continue to work. Household dietary profiles you enter for family members receive the same protections. If your subscription ends, the synced copy of your own dietary data is deleted from our servers under the Subscription Lapse schedule in Section 7, while the household dietary profiles you created for your household stay with the household, including when none of its members has a subscription. Using your dietary and allergy information in Corm's AI features — to rank meal ideas and explain why they fit — also needs your explicit consent (Art. 9(2)(a)), asked for separately from dietary sync. That use happens only on your device, and only the restrictions and diet profiles you entered yourself are used; profiles other household members created are never used by your AI. The allergy and restriction checks that leave out conflicting meals and warn you about conflicting ingredients work whether or not you give this consent.

We apply data minimization principles and only collect data that is necessary for the stated purposes.

5. How We Use Your Data

Providing Services: Operating the Application's core features including meal planning, pantry management, shopping lists, recipe management, and cloud sync.

AI Personalization: Using on-device and server-side AI models to provide personalized meal suggestions, recipe recommendations, perishable intelligence, and autonomous meal planning.

Improving Suggestions for Everyone: Only if you allow it, using the records of the meal ideas you were shown and chose to train the models that rank meal ideas for all users, and to check that those models keep working well.

Food Safety Notifications: Generating expiration alerts, perishable urgency notifications, and shelf life estimates based on your pantry data and learned patterns.

Household Alerts: When you are in a household, notifying you when a food in the household's shared pantry runs low or runs out because of another member's change.

Dietary Conflict Detection: Checking recipes and meal plans against your configured dietary restrictions and allergen profiles.

Budget Analytics: Calculating spending estimates, budget utilization, and providing cost projections based on your configured budget parameters.

Service Improvement: Using the crash and diagnostic reports, AI performance measurements and price observations described in Section 3.2, which are collected only on a paid plan and with your Analytics consent, to improve features, fix bugs, and optimize performance.

Security: Detecting and preventing unauthorized access, fraud, and abuse.

Communications: Sending service-related notifications (e.g., expiration alerts, plan reminders). Marketing communications are sent only with your explicit consent.

6. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

Household Members: If you join or create a Household (Family) account, data you contribute to shared features — including the shared pantry, shopping lists, meal plans, shared recipes, and the household's combined budget and spending — is visible to the other members of your household. Leaving a household ends this sharing for future data; content you previously shared with the household may remain available to its remaining members. When you leave a household, or are removed from it, the pantry, shopping-list and meal-plan items you had before you joined are returned to your own account straight away; items added while you were a member stay with the household.

Household Learning: On a Family plan, what Corm learns from your own activity while you are a member of a household — for example the prices you pay, how often you buy things, how much you usually buy, what you throw away and the swaps you make — is shared with the other members of that household as your part of the household's learning. Your part is labeled with your account so that it can be removed on its own, and the other members' devices receive it with that label. What Corm learned about you before you joined stays on your devices and is not shared with the household. Your part is shared only while you allow AI personalization, and while you do, the records of the meal ideas you were shown and chose include the identifier of your household. If you object to AI personalization, leave the household, or are removed from it, your part is removed from the household's shared learning on our servers, and from the other members' devices the next time they sync. Learning a household built up with earlier versions of the Application was not labeled by member: it stays with the household and cannot be separated by person. Other members can see which member a part belongs to.

Household Food Use: In a household, each member's device learns how quickly the household uses each food from the meals members mark as cooked, which are already shared with the household. If you object to AI personalization, the meals you mark as cooked are not used for this on any member's device, and on a paid plan your device offers them for this only once it has confirmed your choice with your account.

Family Taste: On a Family plan, when at least two members of a household allow AI personalization and have a taste profile, meal ideas can be ranked on the household's combined taste: an average of each member's taste profile, which Corm learns from the recipes each member chooses. Your taste profile is shared with your household only while you allow AI personalization; objecting deletes it, and leaving the household deletes it from that household. It is never built from your diet or allergy information.

Leaving a Household: When you leave a household, the household's learning — other members' parts, the household's earlier shared learning, the household's learned prices and the food use learned from other members' meals — is removed from your device, including when you left on another device or were removed while Corm was closed. What you learned yourself stays with you. Swaps, shelf-life and waste records your device learned with earlier versions of the Application could not be told apart and remain on your device as your own.

Service Providers: We use third-party service providers that process data on our behalf: Supabase, for authentication, data synchronization, remote configuration, storage, and our server functions; Modal, which trains and checks the models that rank meal ideas, using only the records of people who allow it (Section 9); and an email delivery provider for transactional messages such as household invitations. Supabase and our email delivery provider process data on our behalf under Data Processing Agreements compliant with GDPR Article 28. Modal receives personal data only under such an agreement, with a safeguard for any transfer outside the EEA and UK (Section 11.2).

Apple: Apple processes subscription billing and payment data. We do not receive or store your payment information.

Analytics: On a paid plan (Premium, Family, or a plan shared by your household) and with your consent, we collect analytics and diagnostic events in our own infrastructure for service improvement; on the free plan we collect none. AI performance measurements carry no account identifier. Crash and other device diagnostics are stored against your account identifier and are deleted with your account. We do not share either with a third-party analytics provider; if we ever engage one, it will process data only on our behalf under a Data Processing Agreement, and this policy will be updated accordingly.

Legal Requirements: We may disclose data when required by law, court order, or governmental regulation, or when necessary to protect our legal rights, safety, or property.

Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.

We do not share your dietary restriction data, health-related preferences, or allergen profiles with any third party for marketing or advertising purposes.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

Account Data: Retained for the duration of your account. When you delete your account or make a verified erasure request, we begin a cascading deletion across our services promptly; residual copies in encrypted backups age out within 30 days.

Meal Plans and Pantry Data: Pantry data is retained while your account is active. Meal plans are retained for the current week and the previous week only: older meal-plan entries, including their completion records, are deleted automatically from your device and, where they were synced, from our servers.

Loyalty Card Data: Retained while your account is active; deleted as part of the cascading deletion when your account is deleted, and from our servers under the Subscription Lapse schedule below when your subscription ends.

Subscription Lapse (Downgrade to Free Tier): The Free Tier is local-only. If your subscription ends, cloud-stored copies of your recipes, pantry, shopping list, meal plans, loyalty cards, budget and spending data, dietary preferences and currency settings, and AI personalization data are deleted from our servers 7 days after the downgrade takes effect. If your subscription ends because a payment did not go through and the App Store is still trying to collect it (for up to 60 days after the payment failed), we keep those cloud copies while it tries. If the payment goes through, nothing is deleted. If it does not, they are deleted from our servers after the App Store stops trying. The same applies to household members whose plan was shared by the subscriber whose payment is being retried. The record of which suggestions were shown to you and which you accepted or dismissed is deleted with the rest, unless you chose "Use my data to improve suggestions for everyone"; in that case it keeps its own schedule and is deleted after 90 and 180 days, as described under Analytics Data below. Your AI choices are not part of that deletion (see Consent Records below). What you shared with a household is not part of that deletion and stays on our servers for the household, including when none of its members has a subscription: the household's shared recipes, pantry, shopping list, meal plans and spending entries, the household dietary profiles you created, and the patterns learned from the household's shared activity. Copies already on your device remain on your device, and restarting a subscription within the 7-day window cancels the deletion. Crash and diagnostic reports, performance measurements and price observations still waiting on your device to be sent are deleted from it as soon as the Application sees that the subscription has ended.

AI Behavioral Data: On-device behavioral models are stored locally and deleted when you uninstall the Application. On a paid plan, what the AI has learned about your tastes and habits is also kept on our servers while your account is active: your taste profile, your personal learned patterns and meal history, and statistics about which explanations of a suggestion you respond to. Some of the event records it learns from are deleted sooner: price-learning records after 90 days, and the records of the meal ideas shown to you and chosen by you as described under Analytics Data below. If you object to AI personalization, we delete from our servers what the AI learned about you, usually within an hour and at the latest the next day: your taste profile, your suggestion history, your personal learned patterns and the records they are built from, explanation statistics, training copies, the AI budget summaries your device created (and, if you are the account holder of a household, every AI budget summary stored for that household), and your part of any household's shared learning. When your account is deleted, your own copy is deleted as described under Account Data above, including your part of any household's shared learning; if you created the household, the member who takes it over keeps only the household's earlier shared learning and their own part. Learning a household built up with earlier versions of the Application, which was not labeled by member, stays with the household but is no longer linked to you. When your subscription ends, it is deleted under the Subscription Lapse schedule above.

Analytics Data: Usage, performance and diagnostic events are retained for up to 24 months for service improvement purposes. AI ranking records are retained on a shorter schedule, by an automated daily job: records of the meal ideas shown to you, which are kept only if you chose "Use my data to improve suggestions for everyone", are deleted after 90 days, and records of the suggestions you accepted or dismissed are deleted after 180 days. These records are pseudonymous — they are linked to your account identifier rather than to your name. When you delete your account, they are deleted together with the training copies made from them.

Training Copies: If you chose "Use my data to improve suggestions for everyone", a copy of your recent suggestion history is used to train and check the models that rank meal ideas for all users. The copy is rebuilt each week from the records of the people who have given that consent, is linked to your account identifier rather than to your name, and is processed for us by Modal. The embedding samples used to check that the models stay consistent are recorded only with that consent and are deleted after 180 days. If you withdraw, we stop using your records for training and delete the training copies, the samples and the records of the meal ideas shown to you, usually within an hour and at the latest the next day; a model that was already trained keeps what it learned and is not retrained to remove you.

Consent Records: On a paid plan we keep a record of each AI choice you make and of each change to your Analytics setting: which choice, your answer, when you made it, where in the Application you made it, the app version and the version of this Privacy Policy in the Application. We keep these records while your account exists, including after a subscription ends, so that an objection still applies if you subscribe again. They are deleted when you delete your account. On the free plan these choices are kept only on your device. If you send us an objection by email, we record it with your account whatever your plan.

Financial/Budget Data: Spending entries, budgets and financial preferences are retained while your account is active and deleted upon account deletion. Budget insights (the summaries generated from your spending) are derived from those entries and can be regenerated. Copies stored on our servers, including any short finance narrative an earlier version of the Application stored, are removed after 12 months.

Changes Not Yet Sent When You Sign Out: If you sign out before some of your changes have reached our servers, Corm keeps those changes on this device, linked to your account, and sends them the next time you sign in on this device. They stay on the device until then, or until you use Clear All Data or delete your account. Other people who sign in on the same device cannot see or send them. On a paid plan, an AI choice or an Analytics choice that has not yet reached your account also stays on this device and is sent the next time you sign in on it. If you use Corm without a paid plan, your loyalty cards and your "never suggest again" answers are kept on this device for your account when you sign out, so they are there when you sign back in.

Backup Data: Cloud backups are purged within 30 days of account deletion.

Legal Holds: Data may be retained longer if required by legal obligation or ongoing dispute.

8. Data Security

We implement comprehensive security measures to protect your data:

Encryption at Rest: Sensitive data is encrypted using industry-standard encryption.

Encryption in Transit: All network communications use TLS 1.2 or higher.

Biometric Authentication: Face ID and Touch ID are available for sensitive operations. Biometric data is processed entirely on-device by Apple's framework and is never transmitted to our servers.

Device Integrity: Application integrity verification ensures the Application is running on a genuine, non-compromised device.

Access Controls: Server-side security policies ensure users can only access their own data.

Consent Verification: Processing that relies on your consent (analytics, marketing communications, dietary-data sync, the use of your diet and allergy information in AI, and training for all users) checks that consent before it runs.

Breach Notification: If a personal data breach occurs, we will notify affected users and the competent supervisory authorities as required by applicable law, including GDPR Articles 33 and 34 and applicable US state breach notification laws.

No security system is impenetrable. While we take reasonable precautions to protect your data, we cannot guarantee absolute security.

9. Consent Management

The Application provides granular consent controls through the Consent Settings interface:

Functional Consent: Required for core Application features. Cannot be disabled while using the Application. Covers: account authentication, meal planning, pantry management, shopping lists, recipe storage, and cloud synchronization.

Analytics Consent: Optional. Controls collection of usage analytics, performance telemetry, price observations, and crash and diagnostic reports, which are collected only on a paid plan (Premium, Family, or a plan shared by your household); on the free plan they are not collected whatever this setting says. You may opt out at any time without affecting core functionality. Data about which meal suggestions you were shown and which you chose is governed separately by the AI choices described below, not by this one.

Marketing Consent: Optional. Controls marketing communications, promotional notifications, and feature announcements. You may opt out at any time.

Personalize my suggestions: On unless you object. Corm learns from what you buy, cook and pick — including how quickly you use up what's in your pantry, the prices you correct and the categories you fix — to tailor your restock suggestions, price estimates, categories and, with Premium or Family, meal ideas. This rests on our legitimate interest; you may object at any time by turning it off, which stops the learning and deletes what Corm has learned (on your device, and on a paid plan on all your devices and on our servers). This is how you exercise the right to object described in Section 10.

Use my diet and allergy info in AI: Off unless you allow it. If you allow it, Corm's AI uses your dietary restrictions, how strict each one is and the diet profiles you created, on your device, to rank meal ideas and explain why they fit. This choice sends nothing to our servers or to an AI provider. Profiles other household members created are never used by your AI. Allergy and restriction checks work whether or not you allow this.

Use my data to improve suggestions for everyone: Off unless you allow it. It applies only on a paid plan, and only while you have not objected to personalization. If you allow it, the meal ideas Corm showed you, and the ones you picked or skipped, are used to train the models that rank ideas for all users and to check that those models keep working well. These records are linked to your account ID, not your name; ideas shown are deleted after 90 days, and ideas picked or skipped and the samples used for those checks after 180 days. Our service providers Supabase (storage) and Modal (training) process them for us. If you say no, or withdraw later, your records are left out of training from then on and the records kept only for training are deleted; a model that was already trained keeps what it learned. Saying no does not change how Corm personalizes your own suggestions.

Corm asks these three questions when you first sign in, on their own screen after you accept the Terms of Service and this Privacy Policy; accounts created before the questions existed are asked once. Nothing is pre-selected for the two optional uses, and "Don't allow" is as easy as "Allow". You can change each answer at any time in Profile > Privacy Settings, and on a paid plan also in AI Settings. Withdrawing a consent is as easy as giving it: each consent is one switch, and turning it off works offline. Objecting to personalization takes one tap and a confirmation, because it deletes what Corm has learned. On the free plan the answers are kept on your device only, so after a reinstall or on another device Corm asks again. When you move to a paid plan, the answers kept on your device are sent to your account; if your account already holds a refusal, the refusal stands.

Consent preferences take effect immediately. They are stored on your device; on a paid plan (Premium, Family, or a plan shared by your household), your AI choices and any change to the Analytics setting are also recorded with your account. (Your dietary-data sync consent works differently: its state is reflected server-side by the presence or absence of your synced dietary data, so that withdrawal removes the data itself. When that data is deleted because your subscription ended, we keep a note that it was deleted, which contains no dietary data, so that your other devices do not mistake the deletion for a withdrawal; the note is removed when your dietary data is synced again, when you withdraw this consent, or when your account is deleted.) Because they are kept with your account on a paid plan, your AI choices apply on every device you sign in to and after a reinstall. On the free plan your AI choices stay on your device, for your account only, and you are asked again after a reinstall or on a new device. Reinstalling the Application or moving to a new device returns the Analytics and Marketing settings to off, and those consents must be granted again.

On a paid plan, if you withdraw a consent or object on one device, your other devices follow the next time Corm on them checks your account — when it starts, or when you return to it more than 15 minutes after it last checked. A choice you make while offline takes effect on that device at once and reaches your account when the device is next online. Turning a choice on (giving consent, or lifting an objection) needs a connection on a paid plan, so that it cannot overrule a refusal you made on another device. Clear All Data keeps your AI choices, because they belong to your account rather than to the content on your device; deleting your account removes them from this device and from our servers. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.

10. Your Privacy Rights

Depending on your location, you have some or all of the following rights regarding your personal data:

10.1 Rights Under GDPR (EEA, UK, Switzerland)

Right of Access (Art. 15): Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.

Right to Erasure / Right to Be Forgotten (Art. 17): Request deletion of your data. We perform a cascading purge across all services when processing deletion requests.

Right to Restriction of Processing (Art. 18): Request that we limit how we use your data while a complaint is being investigated.

Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format. The export includes your AI choices: those kept on this device and, where your account has them, the records kept with your account.

Right to Object (Art. 21): Object to processing based on legitimate interests, including AI profiling. We will cease processing unless we demonstrate compelling legitimate grounds. For AI personalization, turning off "Personalize my suggestions" stops the processing at once and deletes what Corm has learned, as described in Sections 7 and 12.

Right Not to Be Subject to Automated Decision-Making (Art. 22): Our AI features provide recommendations and suggestions, not binding decisions. You always retain the ability to accept, modify, or reject any AI output.

Right to Withdraw Consent (Art. 7(3)): Withdraw any previously given consent through the consent settings panel.

10.2 Rights Under CCPA/CPRA (California Residents)

Right to Know: Request disclosure of what personal information we collect, use, and share.

Right to Delete: Request deletion of your personal information.

Right to Correct: Request correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing: Corm Technologies, LLC does not sell or share personal information as defined under the CCPA.

Right to Limit Use of Sensitive Personal Information: Dietary restriction and allergen data is used only for providing Application services.

Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

10.3 Exercising Your Rights

You may exercise your rights by: using the in-app privacy controls; submitting a request to privacy@cormtechnologies.com; or using the account deletion feature within the Application. We will respond to verifiable requests within one month (GDPR) or 45 days (CCPA). Where a request is complex or we receive a high volume of requests, these periods may be extended as permitted by law (by up to two further months under GDPR, or one additional 45-day period under CCPA); we will tell you within the initial period if an extension is needed and why. Identity verification may be required to protect against fraudulent requests.

11. Region-Specific Provisions

11.1 European Economic Area (EEA)

Every user, wherever they are, gets the same consent choices as users in the EEA: the choices described in Section 9, and what each is set to until you choose, are the same in every region. Among them, optional analytics, marketing, the use of your diet and allergy information in AI, and training for all users are off until you turn them on, for every user. We also carry out Data Protection Impact Assessments (DPIAs) for high-risk processing activities, appoint sub-processors only under GDPR-compliant Data Processing Agreements, and use international data transfer safeguards for any data transferred outside the EEA.

11.2 International Data Transfers

Your data may be transferred to and processed in the United States or other countries where our service providers operate. For transfers from the EEA/UK, we rely on: EU Standard Contractual Clauses (SCCs) approved by the European Commission; adequacy decisions where applicable; and supplementary technical measures including encryption and access controls. You may request a copy of the applicable transfer safeguards by contacting privacy@cormtechnologies.com.

11.3 California (CCPA/CPRA)

Categories of personal information collected in the preceding 12 months, per CCPA Section 1798.100:

Identifiers: Name (if you give one), email address, account ID, and the device identifiers the Application creates (Section 3.2).

Personal Information (Cal. Civ. Code 1798.80(e)): Name and profile details you provide.

Commercial Information: Store loyalty card numbers and barcode data you add; budget limits and spending entries you record.

Internet/Electronic Activity: App usage data, feature interactions, device information.

Inferences: AI-derived preferences, meal patterns, recipe preferences.

Sensitive Personal Information: Dietary restrictions and allergen data (used only to provide services).

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

11.4 Children's Privacy

The Application is not directed at children under 13 (or the applicable minimum age of digital consent in your jurisdiction, whichever is higher), and children under that age may not create an account. We do not knowingly collect personal data directly from children under that age. If we discover that a child under the applicable age has created an account or otherwise provided us with personal data directly, we will delete the account and its data promptly. Parents or guardians who believe their child has provided us with personal data should contact us at privacy@cormtechnologies.com.

Separately, an adult account holder may add a household member profile (such as a name and dietary restrictions) for a child in their household. That information is provided and controlled by the parent or guardian, is used only to provide household features such as dietary conflict detection and, if the account holder allows Corm's AI to use diet and allergy information, to rank meal ideas on the account holder's device, and can be edited or deleted by the account holder at any time.

12. AI and Automated Processing Transparency

Consistent with our transparency obligations under applicable law, including the EU AI Act and the GDPR's requirements for automated processing, we disclose the following about our AI features:

No Third-Party AI Providers: Content you enter in the Application — recipes, pantry items, photos, and other text — is not sent to third-party artificial intelligence or large-language-model providers. AI inference runs on your device or on infrastructure operated for Corm Technologies, LLC.

Purpose: AI features are used to personalize meal suggestions, predict food perishability, optimize meal plans, and improve user experience. No AI feature makes legally or similarly significant decisions about you.

Logic: Recommendation models use collaborative filtering, similarity matching, and behavioral pattern analysis. Perishable intelligence uses statistical shelf life modeling. Autonomous planning uses weighted scoring across multiple factors including pantry coverage, variety, time constraints, and dietary compliance. When our server ranks meal ideas without the taste profile your device computes, it uses only the ingredients you have, the meal and the time of day, and not your meal history.

Data Used: Your suggestions are personalized from your own activity (recipes viewed and cooked; items purchased and consumed; meal patterns). Models that rank meal ideas for all users are trained and checked only on the suggestion history of people who chose "Use my data to improve suggestions for everyone"; that history is stored per account (pseudonymous, not anonymous) while it is used. Which meal ideas you were shown, and the embedding samples used to check that our models stay consistent, are recorded and sent only if you give that consent and have not objected to personalization.

Impact: AI outputs are recommendations only. You always have the option to accept, modify, or reject any suggestion. No automated decision restricts your access to features or content.

Opt-Out: You may object to AI personalization at any time by turning off "Personalize my suggestions" in Profile > Privacy Settings. Corm then stops learning from your activity and deletes what it has learned on this device: your purchase and restock patterns, learned prices, category corrections, how quickly you use food, which suggestions you accepted or dismissed, and your taste profile. Choices you made yourself — recipes you told Corm never to suggest again, budget-swap choices and your answers to dietary warnings — are kept. Your device also stops sending learned shopping patterns to your account or household and stops receiving them. On a paid plan, your other devices do the same when they next check your account, and what our servers hold is deleted as described in Section 7. On the free plan, objecting sends nothing to Corm: the deletion happens on this device only. You may disable Autonomous Planning at any time. With personalization off, Corm stops its AI suggestions for you, and restock suggestions and price estimates no longer use what it learned about you.

Until Your Answer Is Known: Until Corm knows your answer — on a new device, after a reinstall on the free plan, or before a paid account's choices have loaded — nothing is learned from your activity and nothing about it is uploaded; Corm waits rather than assuming.

Diet and Allergy Information: Corm uses your diet and allergy information to personalize AI suggestions and their explanations only if you allow it ("Use my diet and allergy info in AI"). Even then, only restrictions you entered yourself — your own and those of household members you added — are used; a profile another household member shares with you is used only to check recipes and items for conflicts, never to personalize your suggestions. Using your diet in AI does not send it anywhere: the AI that uses it runs on your device, and nothing that records it is uploaded. (Separately, dietary sync, if you turn it on, stores your restrictions with your account so your other devices and household can use them for safety checks.) The allergy and restriction check that keeps conflicting recipes out of your suggestions and warns you about conflicting items runs whether or not you allow diet use in AI, because it is a safety feature you set up. The starting taste profile for a new account is chosen from your cooking-time and difficulty preferences only, never from your diet.

Budget Summary: The summary sentence on the Budget Analytics screen is calculated from your numbers. Corm does not use AI to write it, and your AI personalization setting does not change it. Earlier versions of the Application could write this sentence with the on-device AI model on a member's device and store it on our servers for the household or for the account; any such summary still stored is deleted after 12 months, and sooner if you object to AI personalization as described under AI Behavioral Data in Section 7. If you are not the household's account holder, objecting deletes sooner only the summaries your own device stored; summaries other members' devices stored stay until the 12-month deletion.

Model Updates: The AI models the Application uses on your device are included in the Application itself and change only when you install an app update. Corm does not download AI models to your device separately. An updated model may improve accuracy but may change the nature of suggestions.

13. Cookies and Tracking Technologies

The Corm mobile application does not use browser cookies. We use the following technologies:

Local Storage: App preferences, consent settings, and cached data are stored on-device using standard iOS storage mechanisms.

Device Search Index (Spotlight): So that you can find your recipes from your iPhone's home screen, the Application writes recipe titles, categories, timings, and ingredient names into Apple's on-device Spotlight index. These entries stay on your device: they are not marked for public indexing, carry no web address, are not readable by other applications, and are never transmitted to us or to Apple. You can turn this off at any time in Settings, under Data & Privacy, using "Recipe search in Spotlight"; turning it off also removes the entries the Application previously wrote.

First-Party Analytics: On a paid plan and with your consent, usage, performance and diagnostic events are collected by our own infrastructure — no third-party analytics SDK is embedded in the Application. AI performance measurements carry no account identifier; crash and device diagnostics are linked to your account and are deleted with it. On the free plan none are collected.

No Cross-App Tracking: We do not track users across other apps or websites.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through in-app notifications and/or email at least 30 days before they take effect, and the Application will present the updated policy for your review and acceptance. The "Effective Date" at the top of this policy indicates when it was last updated. Where required by law, we will seek your renewed consent for material changes to data processing.

15. Contact Information

For privacy inquiries, data subject requests, or complaints:

Email: privacy@cormtechnologies.com

Data Protection Inquiries: dpo@cormtechnologies.com (this mailbox routes data-protection matters to our privacy team; Corm Technologies, LLC has not designated a statutory Data Protection Officer under GDPR Article 37)

Mailing Address:

Corm Technologies, LLC

P.O. Box 172

Blue Bell, PA 19422-0172

Response Time: We aim to respond to all inquiries within 30 days.

European users who are not satisfied with our response may lodge a complaint with their local Data Protection Authority. A list of EEA DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

© 2026 Corm Technologies, LLC. All rights reserved.

Contact: legal@cormtechnologies.com | Privacy: privacy@cormtechnologies.com