Last updated May 22, 2026

Privacy.

Effective May 22, 2026.

Who we are

Nora: Meal Planner is run by ALANAS KALINAUSKAS, an individual trader. The address is Asanaviciutes 4, Vilnius 04301, Lithuania. For privacy requests, email hello@trynora.co.

For GDPR purposes, ALANAS KALINAUSKAS is the controller for personal data processed by Nora. Apple Developer team ID: ZY88ZD66ZJ.

What we collect

You can use Nora without an account. If you do, your meal library, logs, and settings stay on your device in AsyncStorage. Nothing leaves your phone.

If you sign in, we sync the following data to Supabase so your data can be kept with your account:

  • Email address. App Store category: Contact Info. This is linked to you and used for sign-in.
  • Meal photos. App Store category: Photos / Videos, under User Content. These are linked to you and stored in a private Supabase Storage bucket.
  • Meal cards, logs, and settings. App Store category: Other User Content. This includes meal names, slots, nutrition labels, effort labels, sensory tags, balance notes, which meal you logged, the slot, timestamps, notes, reminder preferences, and other settings. This data is linked to you.
  • User ID. App Store category: Identifiers. Supabase creates this ID for your account. It is linked to you.

These are the App Store privacy categories we declare. All are linked to you. None are used for tracking.

What we do not collect

We do not collect location, contacts, health data, financial data, advertising IDs, precise device identifiers, or usage analytics. We do not use Firebase, Mixpanel, Sentry, Crashlytics, ad SDKs, or data broker SDKs. We do not ask Apple for App Tracking Transparency permission because we do not track you across apps or websites.

How we use it

  • Email address. Used for magic-link sign-in, password sign-in, account recovery, and privacy requests.
  • User ID. Used to attach meals, logs, photos, and AI quota to the right account.
  • Meal cards, logs, and settings. Used for app functionality: cloud sync, the daily view, the calendar, account deletion, and restoring your account on another device.
  • Meal photos. Used to show your meal cards with the photo saved for that meal.
  • AI quota. Used to enforce the 30 AI meal creations per calendar month limit. The quota table stores your user ID, the month, and counters.

Local reminders are scheduled on your device. We do not use push notifications, APNs tokens, or server-triggered alerts.

Legal basis

For GDPR users, we rely on Article 6(1)(b), performance of a contract, for the core service. This covers sign-in, cloud sync, account management, account deletion, and showing your saved meals and logs.

We rely on Article 6(1)(a), consent, for AI meal creation. You choose this each time by tapping Create with AI and sending a description. You can stop using AI by not using that button. You can delete AI-created meals the same way you delete any other meal.

Third parties involved

  • Supabase. Provides authentication, database, storage, and edge functions. We use project buqjllzondpjekathuhu in the eu-west-2 region (London). Meal photos are stored in the private meal-photos bucket and served through signed URLs.
  • AWS Bedrock. Processes the description you type when you tap Create with AI. We use the Anthropic Claude model us.anthropic.claude-sonnet-4-6 through AWS Bedrock to draft a meal card.
  • OpenAI. Processes the short food-image prompt when you choose to generate a meal photo. We use gpt-image-1-mini at low quality.
  • Apple. Provides App Store distribution. Apple also handles your Apple ID outside Nora. We do not use Sign in with Apple for our own account system.
  • Vercel. Hosts trynora.co. Vercel can process normal website request data, such as IP address, user agent, and timestamps, to serve this page.

We do not sell your data to anyone. We do not share your data for ads. We do not use data brokers.

International transfers

We store signed-in account data in Supabase in the region noted above. AI providers can process requests in the United States or other countries where they run their services. Vercel can also process website request data outside Lithuania.

When data moves outside the European Economic Area, we rely on Standard Contractual Clauses, adequacy decisions, or equivalent contractual safeguards used by the provider.

Retention

Guest data stays on your device until you delete the app data, delete items inside Nora, or remove the app.

Signed-in account data stays for the life of your account. If you delete a meal, log, or photo, we remove it from the live Supabase tables or storage bucket. If you delete your account, we remove your auth user, meals, logs, quota row, and every object under your user ID in the meal-photos bucket.

Supabase database backups are retained according to the Supabase plan and are purged within 30 days or less. A deleted row can remain in a backup during that window, but it is not restored to the live service unless needed for disaster recovery.

Your rights

If you are in the European Union or another place with similar rights, you can ask to access, correct, delete, export, restrict, or object to the processing of your personal data. You can also withdraw consent for AI processing by not using Create with AI again and by deleting any AI-created meals you do not want to keep.

You can lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania, called Valstybine duomenu apsaugos inspekcija, or with your local supervisory authority.

If you are a California resident, you can ask to know what personal information we have collected about you, request deletion, request correction, and opt out of sale or sharing. We have not sold or shared personal information in the preceding 12 months, so there is no sale or ad-sharing opt-out to exercise. We will not deny service or change service quality because you used your privacy rights.

How to delete your account or data

In the app, open Settings, then Account, then Delete account. The app calls our delete-account edge function. That function deletes meal photos from the private meal-photos bucket under your user ID, then deletes your Supabase auth user. The database rows owned by that user are removed through Supabase cascade deletion.

If you cannot access the app, email hello@trynora.co from the email address on your Nora account. We will verify the request and delete the account data.

AI disclosure

AI in Nora is optional and only runs when you tap Create with AI. Manual meal creation works without AI.

For meal-card text, the description you type is sent through a Supabase Edge Function to AWS Bedrock. AWS Bedrock runs the Anthropic Claude model us.anthropic.claude-sonnet-4-6 and returns a draft meal card: name, slot, nutrition label, effort label, sensory tags, balance notes, and a short food-image prompt. We do not store your original description as a separate record. If you save the card, the saved meal fields become part of your library.

For meal photos, we send the short food-image prompt through a Supabase Edge Function to OpenAI. OpenAI returns an image. We compress it to JPEG, upload it to the private meal-photos bucket, and store the storage path on the meal.

You review and edit the AI result before saving. You can retry, skip the image, or save without a photo. AI is not used for logging, daily plan suggestions, gentle swaps, calendar dots, day status, or weekly recap.

Children

Nora is rated 4+ in the App Store, but it is not directed to children. The intended audience is adults. We do not knowingly collect data from children under 13 in the United States, or under the GDPR age of digital consent in their country, which can be between 13 and 16.

Security

We use HTTPS and TLS for traffic between the app, Supabase, AWS Bedrock, OpenAI, and trynora.co. Supabase stores database data and private storage objects encrypted at rest. Supabase Row Level Security limits signed-in users to their own meals, logs, quota row, and photo paths.

API keys for AWS Bedrock and OpenAI stay on Supabase Edge Functions. They are not shipped in the app.

Changes to this policy

When this policy changes, we update the effective date on this page. If a change materially affects signed-in users, we will give notice in the app or by email when we have an email address.

Contact

Send privacy requests to hello@trynora.co.