Privacy Policy
Last updated: July 30, 2026
Rummage (“we”, “us”), operated by Refined Data, is built privacy-first. This policy explains what we collect, why, and the control you have. If anything here is unclear, reach us via the support page.
What we collect
- Your kitchen & recipes. The ingredients, saved meals, grocery lists, preferences, meal plans, and private household dinner ballots you create in the app. A ballot contains structured meal choices and up/down votes—not public links, voter names, comments, or other free text. This data is stored on Rummage servers and keyed to your device identifier by default, or to your account if you sign in.
- Photos you scan. When you photograph your fridge, pantry, or a receipt, and explicitly allow AI features, the image is sent to Microsoft Azure AI to detect ingredients or receipt items. AI is optional, and you may revoke consent in Settings. We do not use your photos to train Rummage models, and we do not sell them.
- Usage analytics (optional). If you choose to share usage data, Rummage records product-interaction events linked to your device or account identifier, such as screens and features used, session timing, and recipe titles tied to actions such as saving or cooking. Raw search text and dinner-poll tokens are not included in these events. We use the events to understand feature usage and improve the app and its meal AI. You can change your choice at any time in Settings → Privacy → Share usage data.
- Account info (optional). If you choose to sign in, your email/identifier from your sign-in provider, used only to sync your data and enable households.
- Purchases, diagnostics, support, and AI reports. Subscription status and transaction metadata needed to provide paid access; crash diagnostics needed to operate the app; and the messages or bounded AI-result details you intentionally report. AI reports do not attach your original prompt, photo, authentication header, or token.
How we use it
- With your consent, to generate meal suggestions, substitutions, instructions, and plans.
- To detect ingredients from the photos you scan.
- To operate features you use — grocery lists, dinner votes, households.
- To improve reliability and quality (only if you choose to turn usage analytics on).
What we don’t do
- We don’t sell your personal data.
- We don’t use your scanned photos to train models.
- We don’t require an account to use the app.
Your controls
- Export your data from Settings → Privacy → Download my data.
- Delete your Rummage data with the deletion control in Settings → Privacy. If you no longer have access to the app, submit an account-deletion request on the web.
- Change your analytics choice any time with the usage-data toggle.
- Grant or revoke AI consent in Settings → Privacy. Revocation stops new AI submissions but does not disable your kitchen, grocery, saved recipes, household, or dinner ballots.
Third parties
We use service providers only where needed to deliver a Rummage feature. These include Microsoft Azure (hosting, database, and AI vision/language services); Expo (mobile app update delivery and push notifications); and the sign-in provider you choose, such as Apple, Google, or Microsoft. RevenueCat processes purchase and subscription information for subscriptions. Instacart processes the shopping-list information needed when you choose an Instacart shopping link. Sentry processes crash and reliability diagnostics without default personal-information capture. Resend processes your message and reply address when support email delivery is configured. Each provider receives data for the applicable service, not for unrelated Rummage features.
Children
Rummage is intended for people aged 13 and older, and we do not knowingly collect personal information from children under 13. Accounts, household dinner ballots, and support requests must be created and submitted by someone 13 or older. If a parent or guardian wants younger children's dinner preferences reflected in a household ballot, the parent should cast those votes themselves and should not enter a child's name, photo, or contact information anywhere in Rummage. If you believe a child under 13 has provided personal information to us, contact us via the support page and we will delete it.
How long we keep data
- Your kitchen & recipes. Kept until you delete the content or your account; deletion removes it from Rummage servers as described on the account-deletion page.
- Optional usage analytics. Product-interaction events are retained for 13 months from collection, then deleted.
- Purchase and billing records. Subscription and transaction metadata is retained for up to 7 years where required for tax, accounting, audit, and fraud-prevention obligations, then deleted.
- Support messages and AI-result reports. Retained for up to 12 months after submission so we can resolve issues and track regressions, then deleted.
Changes
We’ll update this page as the app evolves and revise the “last updated” date above. Questions? Contact us.