The short version
Who we are
Mytikas ("we", "us") makes Zymo and decides how the data described here is used. You can reach us at info@mytikas.org. This policy covers the Zymo mobile app for iOS and Android ("the app") and the website at zymo.mytikas.org.
What we collect
The table lists everything the app handles and where it goes. Anything marked "your device" never reaches us.
| Data | Where it lives | Why | Leaves your device? |
|---|---|---|---|
| Journal entries, bake photos, scan reports, conversations, starter schedule, bake plans, templates, settings, and the name, goals and experience level you give during setup | Your device (a local database and private app files) | To run the app and show your history | No, unless you choose to send an entry or photo to Crumb |
| Messages you send to Crumb, journal entries you send for advice, and the recent conversation they need | Sent to our server and OpenAI to write a reply. We do not store the content. | To answer you | Yes, each time you send |
| Photos you submit for a scan (JPEG or PNG, up to 6 MB) | Briefly in our Cloudflare storage, and with OpenAI during analysis | To create the scan report | Yes, each time you scan |
| Installation record: a random installation ID, a hashed credential, subscription status and expiry, usage counts, and a rotating salted hash of your network address (not the address itself) | Our Cloudflare database | To run the service, apply free allowances and limit abuse | Created on first launch |
| Device checks: an Apple DeviceCheck or Google Play Integrity token, and the result of verifying it | Apple or Google, and short-lived records on our side | To keep the free Crumb allowance from resetting on reinstall, and to confirm the app is genuine | Yes, when you use free Crumb |
| Purchase data: store transaction details, subscription state and a customer ID that matches your installation ID | Adapty, Apple and Google | To unlock Zymo Pro and restore purchases | Yes, when you subscribe or restore |
| Usage events: app opened, setup started and finished, screens viewed, plus basic device details such as model, OS version and app version | PostHog (EU region) | To understand which parts of the app work and which confuse people | Yes |
| A recording of first-run setup, including the Zymo Pro offer | PostHog (EU region) | To find and fix confusing steps | Yes, first launch only |
We do not collect your email address, phone number, contacts, precise location, advertising ID or health data. Reminders are scheduled on your device and do not use a push notification service.
How the AI features work
Crumb chat, journal advice and loaf scans use OpenAI's API. We use the API, not the ChatGPT consumer product.
- Chat and journal advice. Your message, the journal entry you chose to send and the recent conversation go from the app to our server and on to OpenAI. We turn off the API option that stores requests on OpenAI's side. OpenAI may still keep API data for a limited period under its own policies, for example to detect abuse. See OpenAI's privacy policy and its API data controls. We do not save the content of your messages on our servers.
- Scans. The app compresses your photo and uploads it to temporary storage with a one-time job token. OpenAI analyses it and our server saves the report. We delete the photo as soon as the analysis succeeds. The report waits for the app to collect it, then we delete that too. Either way, everything expires within 24 hours, plus a short cleanup delay.
- What to leave out. A photo can show more than a loaf. Crop out faces, documents and anything private before you scan, and do not put personal details in a chat.
AI replies can be wrong. They are guidance for baking, not professional advice. Our terms say more.
Subscriptions and payments
Apple or Google takes the payment. We never see your card number or billing details. We use Adapty to manage subscription products, purchases and restores, and our server checks with Adapty that you have an active subscription before it unlocks Pro features. Restoring a purchase restores your access only. It does not restore journal entries or photos, because those never left your device.
Analytics and recordings
We use PostHog, hosted in the EU, to count events such as "app opened", "setup finished" and which tab you view. The events carry your random installation ID so we can follow one installation across sessions. We do not put your name, journal text, chats or photos in event data.
On your first launch, PostHog also records the setup screens, including the Zymo Pro offer, as a session replay. Anything you type, including your name, is masked, and images are masked. The recording stops before you enter the main app. Later launches and previews are not recorded. Surveys are off.
Zymo does not yet have an in-app switch for analytics. If you want us to stop or to delete what we hold, email us. See "Your choices and rights" below.
Permissions
- Camera. Used only when you tap to photograph a loaf or starter.
- Photo library. Used only to let you pick a photo to scan or attach to a journal entry.
- Notifications. Used for starter and bake reminders. You can decline, and you can switch them off in your device settings at any time.
- Internet. Needed for Crumb, scans, subscription checks and recipe updates. On Android, Zymo also asks to run after a restart so your reminders come back.
Who we share data with
These companies process data for us or provide the stores the app runs on.
| Company | Role | Data involved |
|---|---|---|
| OpenAI | AI replies and scan analysis | Messages, journal entries and scan photos you send |
| Cloudflare | Hosting, temporary storage and our database | Installation record, temporary scan files, request metadata |
| Adapty | Subscription management | Customer ID, purchase and subscription state |
| PostHog | Product analytics and first-run replay | Installation ID, events, device details, masked recording |
| Apple and Google | App stores, payments, DeviceCheck and Play Integrity | Purchase records, device integrity tokens |
| Netlify | Website hosting | Standard server logs for this website |
We do not sell personal data or share it for advertising. We may disclose data if the law requires it, to protect people's safety or our rights, or as part of a sale or merger of our business, in which case this policy continues to apply unless we tell you otherwise.
Some of these providers are outside your country, including in the United States. Where the law requires it, we rely on safeguards such as the European Commission's standard contractual clauses.
How long we keep data
| Data | How long |
|---|---|
| Content on your device | Until you delete it or remove the app |
| Scan photo on our storage | Deleted right after a successful analysis, and in any case within 24 hours |
| Scan report on our storage | Deleted once the app confirms it saved the report, and in any case within 24 hours plus a short cleanup delay |
| Chat and journal text | Not stored by us. OpenAI's retention is covered by its own policies. |
| Duplicate-upload receipts (identifiers only) | 7 days |
| Device-check proof hashes | Deleted by an hourly cleanup |
| Installation record, usage counts, subscription metadata | While the installation is active and as long as needed to run and protect the service, then deleted or anonymised. You can ask us to delete it sooner. |
| Analytics events and recordings | Only as long as needed for product analysis |
| Purchase records | As long as tax and accounting rules require, held by Apple, Google and Adapty |
Your choices and rights
- In the app. Delete individual journal entries, scans and conversations, turn off reminders and haptics, and cancel a subscription in your store account.
- On your device. Remove the app to erase everything it stored locally. Your phone's own backup (iCloud or Google) may hold a copy of app data under your device settings, and you can delete that there.
- Ask us. Email info@mytikas.org to ask for a copy of data we hold about you, to correct it, to delete it, to object to analytics or to withdraw consent. We answer within 30 days. The delete your data page explains the steps.
Because Zymo has no accounts, we hold no name or email that points to you. To find a record we may need a detail only you have, such as the Apple or Google order number for your subscription. We will never ask for more personal information than we need to find your record, and if we cannot connect a request to any record we will say so.
You can also complain to your local data protection authority. We would like the chance to fix the problem first, so please write to us.
Rights by region
European Economic Area, United Kingdom and Switzerland
Under the GDPR and similar laws you can ask us to access, correct, erase, restrict or move your data, and you can object to processing based on legitimate interests. Our legal bases are:
- Contract, to provide the features you use, such as scans, Crumb and subscriptions.
- Legitimate interests, to keep the service secure, apply fair usage limits and understand how the app is used so we can improve it.
- Consent, where you grant a permission such as camera access or notifications. You can withdraw it in your device settings.
California and other US states
You have the right to know what we collect, to delete it, to correct it and to be free from discrimination for using these rights. In the last 12 months we collected identifiers (installation ID), commercial information (subscription status), internet and app activity (analytics events), and photos you chose to scan. We do not sell personal information or share it for cross-context behavioural advertising. You can make a request by email, and an authorised agent may do so for you.
Everywhere else
If your country gives you privacy rights, we will honour them. Write to us.
Children
Zymo is not directed at children under 13, or under 16 where the local age of digital consent is higher, and we do not knowingly collect their data. If you think a child has used Zymo, email us and we will delete what we can find.
Security
Traffic between the app and our server uses TLS. Your installation credential sits in your phone's secure storage (Keychain on iOS, Keystore on Android), and our server stores only a hash of it. Provider keys never ship inside the app. No system is perfectly secure, and we cannot guarantee that nothing will go wrong. If a breach affects you we will tell you as the law requires.
This website
This site sets no cookies and runs no analytics or advertising scripts. Our host, Netlify, keeps ordinary server logs (such as IP address and pages requested) for security and operations. If you email us, we use your address only to reply.
Changes to this policy
When we change this policy we update the date at the top. If a change matters, such as a new kind of data or a new provider, we will also say so in the app or in the release notes before it takes effect.
Contact
Mytikas
Email: info@mytikas.org