Privacy Policy

What we hold, and why

This policy covers the hosted NOM service at nommeal.com and nom.nommeal.com, operated by Armory Works Technology, LLC (“Armory Works,” “we,” “us”). If you run your own NOM instance from the open-source code, this policy doesn't apply to it — you are the operator, the data sits on your hardware, and we never see it.

Version 1.0 · Last updated: August 29, 2026.

The short version

We collect what the app needs to plan your household's meals and nothing we can't justify. We don't sell your data, we don't run advertising, and we don't share your recipes, restrictions, or plans with anyone outside your household unless you publish them yourself. You can delete your account from inside the app, and ask us for a copy of your data at any time.

What we collect

Account data. Your email address, a password hash, a display name, and the household you belong to. We need this to sign you in and to keep one household's food separate from another's.

The food data you enter. Recipes, meal plans, pantry contents, shopping lists, ratings, notes, and the dietary restrictions and preferences attached to each person in your household. Some of this — an allergy, an intolerance, a medically motivated diet — can reveal something about health. We treat it as sensitive: it is used to filter recipes and build plans, and for nothing else.

Household messages. In-app messages between members of your household.

Operational logs. Server logs with IP address, user agent, timestamps, and the request path, kept to run and secure the service. These roll off on a short retention window.

We do not run third-party advertising or analytics trackers on the app, and we do not buy data about you from anyone.

Why we're allowed to hold it

For most of it, because we need it to provide the service you asked for (contract). For logs and abuse prevention, because we have a legitimate interest in keeping the service up and secure. For anything optional — and for the health-adjacent parts of restriction data — because you consented, and you can withdraw that consent in the app. NOM records which version of this policy you consented to and on what basis.

Who else sees it

Your household. Members you invite share the plan, pantry, shopping lists, and messages. Individual profiles and their restrictions are visible within the household — that is the point of the feature.

Anyone, if you publish. Marking a recipe public puts it on this instance's public recipe browser under your display name. Nothing else is ever public.

Our infrastructure. The service runs on hardware Armory Works operates, fronted by Cloudflare, which sees request metadata in transit. Outbound email is sent through our own relay. The app also loads its fonts and icons from Google Fonts, so Google sees your IP address and browser when a page loads. We use no other third-party processors, and none of them receive your food or household data.

Nobody who pays us. We have never sold or rented personal data and have no plans to. If that ever changes, it will require your opt-in, not a policy edit.

Your rights

Wherever you live, you can ask us to do all of the following. Deletion is built into the app; the rest we handle for you when you ask:

  • Export — ask for a machine-readable copy of your data, which we send you;
  • Delete — remove your account and the personal data attached to it;
  • Correct — fix anything inaccurate, in the app or by asking us;
  • Withdraw consent — for any processing you consented to;
  • Object or restrict — tell us to stop a particular use.

Account settings has the deletion control, and a button to request an export — that request reaches a person, who sends you the file. Either way, or if you'd rather just use the contact form, we'll respond within 30 days. Deletion removes your personal data and the content only you can see; recipes you deliberately published stay up unless you unpublish them first, and household records that other members also rely on are anonymized rather than destroyed.

How long we keep it

Account and food data live as long as your account does, plus a short grace period after deletion in case it was a mistake or a backup needs restoring — then it's gone from backups on their own rotation. Operational logs are kept for a matter of weeks. Consent records outlive the data they cover, because proving what you agreed to is the point of them.

Cookies

The app sets the cookies it needs to keep you signed in and to protect forms against cross-site request forgery. There are no advertising or cross-site tracking cookies, so there's no consent banner to dismiss.

Children

NOM isn't built for children. You must be at least 13 — or the digital-consent age where you live — to hold an account. Households routinely include children as profiles (a kid with a peanut allergy needs to be in the plan), and those profiles are managed by the adult who created them; they are not accounts and can't sign in. If you believe a child has created an account, tell us and we'll remove it.

Where your data lives

On servers operated by Armory Works in the United States. If you're in the EU, UK, or another jurisdiction with transfer rules, using the hosted service means your data is processed in the US. Self-hosting is the alternative, and it is a real one — the entire stack is Apache-2.0.

Security

Traffic is encrypted in transit, passwords are hashed, and access to production data is limited to the people who operate the service. NOM is a small product built by a small team and provided without warranty — see the terms. If you find a vulnerability, report it to us before disclosing it publicly.

Changes to this policy

When we change this policy in a way that matters, we'll post the new version here, bump the version number above, and give notice in the app or by email. Because NOM records the policy version you consented to, a material change may ask you to re-consent.

Contact

Armory Works Technology, LLC, a Utah limited liability company. Privacy questions, requests, and complaints: use the contact form — a human reads every message.