NiblGo Privacy Policy
NiblGo is a photo-first app for sharing meals with friends. This policy explains what we collect, why, who we share it with, and what you can make us do about it.
We are Bryce and Cameron, 4500 E. 33rd St., Sioux Falls, South Dakota 57110, USA, and we are the data controller for the information described here.
Questions, requests, or complaints: privacy@niblgo.com.
1. The short version
- We collect what you give us, meaning your account details and what you post, plus a small amount about how you use the app.
- As the app ships today there are no ads in it and no third-party analytics or tracking SDK. That is a description of the current version, not a promise about every future one. We expect to add advertising and product analytics as NiblGo grows. Before either one starts we will update this policy, say what changed, tell you in the app, and update the privacy labels on the App Store and Play Store to match.
- Your meal photos are stored in a public bucket: anyone with the direct link can view an image, whether or not they use NiblGo. Do not post pictures you would not want seen outside the app.
- You can delete your account from inside the app, and it really deletes.
- Section 7 covers your legal rights, including in the EU/UK and California.
2. What we collect
You give us
| What | When | Why |
|---|---|---|
| Email address | Sign-up | To create and secure your account, confirm it, and reach you about it |
| Password | Sign-up | Stored only as a salted hash by our authentication provider; we never see it |
| Handle, display name | Sign-up | Your public identity in the app |
| Profile photo or emoji, bio | Optional, any time | Shown on your profile |
| Meal photos | Each post | The core of the service |
| Your written blurb | Each post | Displayed with your post, exactly as you wrote it |
| Meal type, and optionally a restaurant | Each post | Organising and browsing meals |
| Comments, likes, reposts, shares, saved posts | As you use them | To make the features work |
| Direct messages, including any photos you attach | When you message someone | To deliver them |
| Follows and blocks | As you use them | To build your feed and enforce your blocks |
| Reports about content or people | When you report | Safety and moderation (section 6) |
| Feedback and bug reports | When you send them | To fix and improve the app |
Collected automatically
| What | Notes |
|---|---|
| Your time zone | Set at sign-up so mealtime reminders arrive at sensible local times |
| Your posting streak | Derived from your own posting dates |
| App version and platform | Attached only to feedback and bug reports you choose to send. Not collected otherwise |
| Server logs | Our hosting provider records standard request logs, including IP address, for security and reliability |
Stored only on your device, never sent to us
- Your mealtime reminder preferences and times
- Your recently searched profiles
- Your login session
These are removed when you delete the app.
What the current version does not collect
Location data (the "where you ate" feature is disabled), contacts, health data, biometrics, or payment details. The version of NiblGo you have today carries no advertising identifier, no in-app purchases and no analytics SDK.
If we add advertising or product analytics later, this section is one of the places that gets rewritten first, along with the store privacy labels, and we will not start collecting anything new under the old wording.
3. AI recipe formatting and nutrition
Two features send text off our servers, both only when you ask for them.
Recipe cards. When you tap the button to turn a blurb into a recipe card, the text of that blurb is sent to Anthropic (Anthropic PBC, USA) for formatting into structured ingredients and steps.
Nutrition estimates. When you tap to estimate nutrition, your ingredient list is sent to Anthropic to convert quantities into weights ("2 cloves of garlic" into grams), and the resulting plain food names ("garlic", "butter") are sent to the USDA FoodData Central database to look up the actual nutrient figures. The nutrient numbers come from USDA, not from the AI, because a model asked for calories will produce a confident number that is not necessarily true.
- Only that text is sent. Your photo, name, handle, email and user ID are not sent to either.
- Anthropic processes it to return the recipe and, under its commercial terms, does not use API inputs to train its models.
- If you never tap either button, nothing is ever sent.
- USDA FoodData Central is a public database run by the US Department of Agriculture. We send it a food name; it sends back nutrient figures. It receives nothing about you.
- Recipe cards are generated by software and can be wrong. Check them, especially for cooking times, temperatures and allergens. See the Terms.
Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
4. Who else we share with
We share with the providers that make the app run. We do not sell your personal information, and the current version of the app shares nothing for advertising. If we later work with an advertising or analytics provider, they get added to the table below and we will tell you before they start receiving anything.
| Provider | What they handle | Where |
|---|---|---|
| Supabase | Accounts, database, photo storage, server functions | United States |
| Anthropic | Blurb text and ingredient lists, only when you ask for a recipe card or a nutrition estimate (section 3) | USA |
| USDA FoodData Central | Plain food names only, when you ask for a nutrition estimate | USA |
| Expo / Apple / Google | App distribution and delivery | USA |
We will also disclose information where we are legally required to, under a valid court order for example, or where it is necessary to investigate a safety issue or protect someone from harm.
International transfers. If you are in the EU, UK or Switzerland, your data may be processed in the United States. Where that happens we rely on Standard Contractual Clauses with the provider concerned.
5. Who can see what
- Visible to anyone signed in: your handle, display name, profile photo, bio, posts, recipe cards, comments, likes, follower and following counts, streak, and the time zone your account is set to.
- Private to you: your email, saved posts, blocked accounts, your reports, and your feedback.
- Between you and the recipient: direct messages. No other user can read a conversation you are in. That is enforced by database rules, not merely by the app, so it holds even against a modified client.
- Your choice: you can make your follower and following lists private in Settings. The counts stay visible; the names do not.
What we can see. Being straight about this: as the people who run NiblGo we hold administrative access to the database, and that access is not limited by the rules above. It can reach any record, including message content and email addresses. We use it to operate the service, investigate reports and abuse, fix faults, and comply with the law. We do not read private messages in the ordinary course of running the app. Any service works this way; we would rather say so than let the section above imply otherwise.
Photos are a real exception and worth reading twice. Meal photos, profile photos and photos sent in messages are stored in a public storage bucket. The link is long and not guessable, and nothing in the app shows it to people who should not see the post, but anyone who obtains the URL can open the image without an account. Treat a photo you upload as potentially public.
6. Reports, moderation and safety
When you report a post, comment or message, we store the report along with a copy of the reported content. That copy is kept even if the author later deletes the original, because otherwise deleting the evidence would defeat the report.
Reports and feedback survive the reporter's or the author's account deletion, with the account handle retained, so that a record of a safety issue is not lost when someone leaves. This is our legitimate interest in running a safe service.
We aim to review reports within 24 hours.
7. Your rights
Whoever and wherever you are, you can:
- See your data. Email privacy@niblgo.com and we will send you a machine-readable copy. There is no self-serve export button in the app; we handle requests by hand. We will confirm you own the account before sending anything.
- Correct it. Edit your profile in the app, or ask us.
- Delete it. Settings → Account → Delete account. This removes your profile, posts, recipes, photos, comments, messages, follows and likes. Reports and feedback are retained as described in section 6.
- Take it elsewhere. The copy we send is JSON.
- Object or restrict. Tell us and we will consider it.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time; it does not affect what we did beforehand.
If you are in the EU or UK, our legal bases are: performance of a contract (running the service you signed up for), legitimate interests (safety, moderation, preventing abuse), consent (mealtime notifications), and legal obligation. You may complain to your national data protection authority, which is the DPC in Ireland and the ICO in the UK.
If you are in California, you may request disclosure of the categories and specific pieces of personal information we hold, request deletion, and request correction. We do not currently sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information beyond providing the service. If that ever changes we will say so here first and give you the opt-out the law requires. We will not discriminate against you for exercising these rights.
We answer within 30 days (GDPR) or 45 days (CCPA), and will tell you if we need longer.
8. How long we keep things
| Data | Kept |
|---|---|
| Account, posts, photos, messages | Until you delete them or delete your account |
| Reports and reported-content copies | While relevant to safety, normally at least 2 years, so repeat behaviour is visible |
| Feedback and bug reports | While relevant to the problem reported |
| Server logs | As retained by our hosting provider |
| Backups | Deleted content disappears as our provider's backups rotate |
9. Security
Passwords are hashed by our authentication provider. We never store or see them. All traffic uses HTTPS. Access to your data is enforced by database-level row security rules, so one account cannot read another's private data even if the app itself were modified. Our AI provider key is held server-side and never ships inside the app.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as required by South Dakota law and by any other law that applies to you. For users in the EU or UK that means the supervisory authority within 72 hours where the breach is likely to present a risk to you.
10. Children
NiblGo is not for children under 13, and we do not knowingly collect their data. In the EU/EEA the minimum age is 16, or the lower age your country sets (13 to 16). If you believe a child has given us personal data, contact privacy@niblgo.com and we will delete it.
11. Changes
We will post any change here and update the date at the top. If a change materially affects your rights, we will tell you in the app or by email before it takes effect. Introducing advertising or analytics counts as a material change, so you will hear about it before it happens rather than after.
12. Contact
Bryce and Cameron 4500 E. 33rd St. Sioux Falls, South Dakota 57110, USA
Privacy requests, and anything about this policy: privacy@niblgo.com Support, and anything else: support@niblgo.com
Either address reaches us. Privacy requests are answered from the first.