Scope and who operates Tablumi
This policy covers the Tablumi app and tablumi.com. Tablumi is developed and operated by independent developer Kun Yang. You can make a privacy request using the domain support address in the Contact section.
Information you provide
Depending on the features you use, you may provide food and ingredient names, tags, ratings, prices, notes, meal records, meal plans, grocery lists, budget information, dietary preferences, selected photos, menu text, and corrections to recognition results. You decide what to add and can use core features without creating an account.
Photos and image data
Photos you select or take are held in memory while a recognition task runs. A compatible Apple on-device route processes the image without sending it to Tablumi. If you choose a mode that permits Tablumi Cloud and cloud routing is selected, the image needed for that request is sent over an encrypted connection to the Tablumi Worker and one configured AI provider.
The Worker does not persist raw original AI photos and does not put raw images into analytics logs. A user-confirmed diary photo or other asset you explicitly save is different: it remains with the saved record on your device and may sync to your private CloudKit database when iCloud is enabled, until you delete it.
Ingredient, meal, and planning data
Pantry contents, food items, meal records, meal-plan entries, grocery items, and related notes are stored in the app's SwiftData store. They stay local unless you enable private iCloud sync, export a backup, or actively request a cloud feature that needs selected context. Diary insight requests use aggregate statistics rather than individual diary text.
Preference and personalization data
Tablumi may store favorites, skipped choices, meal filters, cooking preferences, recent-food exclusions, language, appearance, AI processing mode, and similar settings. These are used to improve local recommendations and preserve your choices. Recommendation scoring is weighted and probabilistic; it does not create a sensitive profile for advertising.
Account information
Core Tablumi features do not require a user account or sign-in. Free cloud AI access may use an anonymous App Attest or limited DeviceCheck session to verify app integrity, prevent abuse, and apply quotas. This session is not an account, is not linked to an advertising identifier, and is not designed to survive reinstall or synchronize across devices.
Purchase and entitlement data
Apple StoreKit handles payments. To validate Pro access, the app may send Apple-signed transaction information to the Tablumi Worker. The server stores only the product, environment, status, expiry information where relevant, and an irreversible HMAC identity needed for entitlement processing. It does not retain the transaction JWS or raw transaction identifiers and does not receive your full payment-card details.
Device, diagnostic, analytics, and advertising information
The app uses Firebase Analytics for content-free events such as feature name, route type, success state, latency bucket, and purchase-flow state. Meal names, pantry contents, photos, prompts, model responses, diary text, and support-message bodies must not be added to these events.
The free version may load Google Mobile Ads. The current app requests non-personalized ads, does not request App Tracking Transparency permission, and does not intentionally perform cross-app tracking. Google SDKs may still process device, app, network, ad-delivery, anti-abuse, frequency, and ad-interaction signals. Once Pro entitlement is resolved, the app does not create or load banner ads.
How information is used
- Provide food decisions, recognition, planning, grocery, diary, backup, sync, Widget, Watch, and Shortcut features.
- Personalize recommendations using your local choices and feedback.
- Validate purchases, restore Pro access, protect cloud quotas, and prevent abuse.
- Diagnose reliability and performance using content-free metrics.
- Meet legal obligations and respond to privacy or support requests.
Tablumi does not sell your pantry, meal, photo, or preference content.
AI and automated processing
Tablumi can route a request to an Apple on-device model, an Apple private cloud environment when production entitlement and feature configuration allow it, or Tablumi Cloud. Production currently keeps the Apple Private Cloud Compute route disabled unless both the verified entitlement and remote feature flag are available.
Only after cloud routing is selected does Tablumi send the user-initiated input needed to complete the task, such as a selected photo, candidate list, recipe context, preference text, or aggregate statistic. A request is not sent to multiple cloud providers in parallel by default. Recognition and suggestions can be wrong; review ingredients, allergens, food condition, quantities, prices, nutrition estimates, and safety yourself. AI does not provide medical diagnosis.
For a feature-by-feature explanation, read AI & Data Transparency.
Service providers and subprocessors
CloudKit, StoreKit, App Attest, DeviceCheck
Private sync, purchases, signed transaction validation, integrity, and device trust.
Tablumi Worker, D1, and security services
Cloud requests, structured-result retry cache, rate limits, entitlement status, and content-free reliability data.
Alibaba Cloud Qwen, DeepSeek, Google Gemini
Qwen generally handles image recognition, DeepSeek generally handles text reasoning, and Gemini may be a fallback. Actual routing depends on task and production configuration.
Firebase Analytics and Google Mobile Ads
Content-free product events and, in the free version, non-personalized advertising as described above.
Provider terms, infrastructure, and legal retention obligations can differ from Tablumi's own systems. Material changes to the processing described here will be reflected in this policy.
Data retention
- Local and private CloudKit content remains until you delete it, clear app data, replace it during backup import, or Apple removes it under your iCloud settings.
- Structured cloud results may be cached by request ID for up to 24 hours for safe retries.
- Daily hashed rate-limit records may remain for up to 35 days.
- Content-free cost and reliability metrics may remain for up to 90 days.
- Anonymous AI sessions generally remain valid for up to 30 days; restricted DeviceCheck sessions for up to 7 days.
- Provider-side temporary retention is governed by the applicable provider configuration and terms.
Data deletion
You can delete individual foods, ingredients, tags, plans, grocery items, meal records, and saved photos, or use the app's Clear All Data control. With iCloud enabled, SwiftData/CloudKit processes corresponding synced deletions. You can also disable iCloud for future storage, subject to Apple's iCloud controls.
Deleting local app data does not automatically cancel an Apple purchase, produce a refund, or delete Apple's transaction history. Anonymous server sessions and short-lived caches expire under the schedules above. For practical steps, see Delete Account or Data.
Data sharing
Tablumi shares data only as needed to provide the service, validate purchases, prevent abuse, meet law, protect rights and safety, or complete an action you request. Cloud AI inputs are shared with the selected provider for that request. Data may also be disclosed if legally required or in connection with a business transfer, subject to applicable protections. Tablumi does not share app content for cross-context behavioral advertising.
International processing
Apple, Cloudflare, Google, Alibaba Cloud, DeepSeek, and their infrastructure may process information in countries outside the one where you live. Those locations may have different data-protection laws. The processing described in this policy is limited to providing, protecting, and operating the selected feature.
Security measures
Measures include encrypted network transport, private CloudKit storage when enabled, App Attest or DeviceCheck for integrity, short-lived anonymous sessions, irreversible HMAC identifiers for entitlements, content-minimized logs, bounded retries, and access controls on backend services. No system can guarantee absolute security. Contact us if you believe Tablumi data has been exposed.
Children's privacy
Tablumi is not directed to children below the minimum age required to consent to digital services in their location. The app does not require an account, but optional AI, analytics, and advertising SDKs can process device or request data as described above. A parent or guardian who believes a child provided personal information can contact us to request review and deletion.
Your choices and rights
You can avoid photo and cloud AI features, choose an AI processing mode, edit results before saving, disable iCloud sync, manage ads by obtaining Pro, export a backup, delete saved content, and contact us. Depending on your location, you may also have rights to access, correct, delete, restrict, or object to certain processing and to complain to a data-protection authority. We may need enough information to verify and scope a request without asking for passwords or unnecessary identity documents.
Region-specific disclosures
Mandatory consumer and privacy rights in your country or state continue to apply. Tablumi does not knowingly sell personal information or use app content for targeted advertising. Where consent is required for optional processing, the app's feature and system controls provide the relevant choice. Some rights may not apply to anonymous or device-local information that the operator cannot access or identify.
Changes to this policy
We may update this policy when product features, providers, law, or production configuration change. The Last Updated date will change, and material changes may also be communicated in the app or on this website. Earlier use is governed by the version in effect at that time.
Contact and privacy requests
Email privacy@tablumi.com with “Tablumi Privacy Request” in the subject. Describe the feature and device involved and the action you want. Do not send your Apple ID password, full payment credentials, government ID, health information, or private photos unless they are strictly necessary and you deliberately choose to include them.