Privacy Policy
This policy explains how Code Energy processes personal data in the YamYam app (“YamYam AI: Calories & Recipes”, app ID org.codeenergy.yamyam) and on yamyam.codeenergy.org. YamYam is only for adults (18+). It is not a medical service.
Summary
- Most of what you log is stored only on your device and we don't keep it on our servers: meals and their photos, saved recipes, shopping list, fridge, weight, water, workouts, meal plans and chat history. When you use an AI feature, the part it needs goes through our server to Google Gemini (see “Data sent to the AI”). This includes the automatic Home tip, which sends today's calories and protein, and adjusting your AI trainer plan, which sends your latest sets of the plan's exercises (weight, reps, time).
- If you sign in with Google or Apple, we store your account in Google Firebase. Your profile, which includes health data (such as weight, height, goal, diets and allergies), is saved there only if you agree in “Save your profile to your account?”; otherwise it stays on your phone.
- AI features are Premium. When you use one, the photo, voice note or text you choose, plus the profile details that feature needs, goes through our server to Google Gemini, and only after you allow it in the app. Your name, email, user ID, age, weight and height are never sent to the AI.
- Payments are handled by Google Play or the App Store and managed with RevenueCat. We never see your card details.
- No ads, no advertising ID, no analytics or crash-reporting tools. We don't sell your data.
- You can download your data and delete your account in the app, and write to privacy@codeenergy.org at any time.
Who is responsible for your data
The controller is Code Energy (https://codeenergy.org). [Legal name and postal address: pending]
- Privacy, your rights and account deletion: privacy@codeenergy.org
- Help with the app: support@codeenergy.org
- Payments and refunds: billing@codeenergy.org
Who can use YamYam
YamYam is only for people aged 18 or over. The app asks for your age during setup and doesn't let you continue with an age under 18. The age is self-declared. The AI service we use (Google Gemini API) is also restricted to adults.
If you signed in with Google or Apple and then entered an age under 18, the app doesn't let you past setup. On that screen you can tap “Delete Account & Data” to delete the account that signing in created; signing out alone keeps it. You can also write to privacy@codeenergy.org and we'll delete it.
Data that stays on your device
These data are stored only in the app's storage on your phone, and we don't keep them on our servers. When you use an AI feature, the part it needs goes through our server to Google Gemini (see “Data sent to the AI”); this includes the automatic Home tip, which sends today's calories and protein, and adjusting your AI trainer plan, which sends your latest sets of the plan's exercises (weight, reps, time). YamYam doesn't sync these data to another phone. They only move to a new phone if you restore a device backup or transfer (for example an iCloud or computer backup on iPhone, or a device-to-device transfer on some Android phones). Signing out or deleting your account removes them from the device, except your theme and language and the temporary files noted below. If you want to keep a copy, use “Download my data” first.
| Data | Details | Limit kept by the app |
|---|---|---|
| Food log | Meals with calories, protein, carbs, fat and portion; the photo of a meal you logged with a photo (in the app's private folder) or the product image link from Open Food Facts | 500 most recent entries |
| Saved recipes | Recipes you save and the last recipe generated | 200 recipes |
| Shopping list and fridge | Product names, quantities, categories, dates added and expiry dates | 300 list items |
| Weight and water | One weight entry per day (kg) and the water you drink each day | 366 weight entries |
| Workouts | Exercises, sets, weights, repetitions, records, estimated calories and the body weight used for them; the workout in progress | 400 workouts |
| AI trainer | Your answers (goal, level, days, minutes, equipment and any limitations or injuries you type), the plan and its sessions | 200 sessions |
| Meal plans | Your weekly plans | The last 10 plans and the current one |
| Nutrition chat | Messages and answers; photos and voice notes appear only as a text note | The last 50 messages |
| Favourites and achievements | Favourite foods with their macros; unlocked achievements | 60 favourites |
| AI answer cache | Recent recipes and tips, so the same request isn't repeated | Treated as expired after 24 hours and removed when read again |
| Sign-in and profile copy | Your sign-in details (user ID, name, email, provider, Google photo link) and your profile, in the phone's secure storage (Keychain or Keystore). The Firebase sign-in session itself is kept in the app's private storage | Until you sign out |
| AI permission | That you allowed sharing data with the AI, the version of the text you accepted and the time. Withdrawing it removes this from the phone. With a Google or Apple account, each answer is also recorded in the cloud (see “Consent records”) | Until you withdraw it, sign out or delete the account |
| Cloud profile answer | Only with a Google or Apple account: your answer to “Save your profile to your account?” (yes or no), the version of the text and the time. It's also recorded in the cloud (see “Consent records”) | Until you sign out or delete the account |
| Home invitation | If the app was opened with a shared-home invitation link: that link, which contains only the home code, so the same invitation isn't offered again | Until the app is next opened without a link, or until you sign out or delete the account |
| Temporary files | Photos and voice notes are deleted after they're sent, except a Chef camera photo, recipe-card images you shared or saved, and the copy made when you pick a profile photo, which stay in the app's temporary cache until the system clears it (also after signing out or deleting the account). The data export file is replaced by the next export | — |
| Preferences | Theme and language | Kept after sign-out |
Reminders. If you turn on notifications, the app schedules on your phone meal reminders (08:00, 13:00 and 20:00, with a generic text) and fridge expiry alerts that include product names. Nothing leaves the device. Scheduled reminders are cancelled when you sign out or delete your account; notifications already shown stay in your notification tray until you dismiss them.
Uninstalling. On Android the system removes all app data, and the app turns off Android backups to Google Drive. On iPhone the system removes the app's data, but it may be included in your own iCloud or computer backups, and the secure-storage copy of your sign-in details and profile may remain in the iPhone Keychain. Signing out or deleting your account in the app removes it.
Data stored in the cloud
Only if you sign in with Google or Apple. Guest sessions keep everything on the device: a guest only gets an anonymous user ID in Firebase Authentication and an anonymous purchase ID at RevenueCat (see “Purchases and subscriptions”). The Firebase ID is deleted when the guest signs out or deletes the account with an internet connection; if that deletion fails (for example, without a connection), it stays in Firebase Authentication [Pending: decide a cleanup period]. Signing out and the in-app deletion don't remove the RevenueCat anonymous ID (see “How long we keep data”).
| Data | What exactly | Where |
|---|---|---|
| Account | User ID, email, name, Google profile photo link, sign-in provider (Google or Apple) and dates of sign-up and last sign-in. With Apple, the name arrives only the first time and the email may be an Apple private relay address. The service also processes your IP address and device information | Google Firebase Authentication (USA) |
| Profile | Email, name, age, sex, weight, height, goal, activity level, daily calorie and macro targets, diets and allergies, fasting settings, country (optional, free text), travel mode, app settings (notifications, units, theme), home code, and the reference to your profile photo: the Google photo link, or only the file path of a photo chosen from your gallery (the image itself isn't uploaded). Saved only if you agreed in “Save your profile to your account?”; you can remove it in Profile › Privacy › “Save profile to my account” | Google Cloud Firestore [Pending: confirm the database region] |
| Shared home (optional) | Home code, creator, member IDs, members' names and profile photos (up to 10 members) and the shared product list (up to 200 names) | Google Cloud Firestore |
| AI usage counters (Premium) | For each day, how many times you used each AI feature and the total number of attempts | Google Cloud Firestore, written only by our server |
| Premium status cache | Whether your account has Premium and when it was checked (valid for up to 5 minutes, or up to 24 hours if RevenueCat can't be reached) | Google Cloud Firestore, written only by our server |
| Consent records | For the AI permission and the cloud profile: your latest answer (yes or no), the version of the text, the time on your phone and the time on our server | Google Cloud Firestore (only Google or Apple accounts) |
| AI content reports | Only when you send one with “Send report”: your user ID, the feature, the reason you chose, your comment (optional, up to 500 characters), the app version, your operating system, the app language and the time, plus up to 300 characters of the answer only if you tick the box to include them | Google Cloud Firestore (only Google or Apple accounts) |
Your profile includes health data: age, sex, weight, height, goal, diets and allergies. Only you can read or change your profile and your consent records; our database rules block access by other users. Reports can't be read or changed from the app: our team reviews them in the Firebase console. Your comment and the excerpt of the answer, if you include it, may include health details, such as a diet or an allergy; we only process them with your explicit consent, which you give by tapping “Send report” after the notice in the report form (see “Purposes and legal bases”). A shared home can be read by its members and by any signed-in user who has its code (typed, scanned from its QR code or opened from its invitation link), because the code is the invitation. The QR code and the link contain only the home code.
Data sent to the AI (Premium)
AI features only work with YamYam Premium and a Google or Apple account. Before the first AI request, the app shows “Your data and AI” and sends nothing unless you tap “I agree”. You can withdraw this permission at any time in Profile › Privacy › “Share data with the AI”; after that, nothing is sent until you allow it again. Automatic tips (the Home tip and fridge storage tips) only run if you had already given permission.
The app sends each request to our server (Google Cloud Functions, us-central1 region, USA). The server checks your Premium status and daily limits and forwards the content to the Google Gemini API (model gemini-2.5-flash). Our server doesn't store the photos, audio, texts or answers: it processes them in memory and returns the answer to the app. The only AI content we keep is the excerpt of an answer you report, when you choose to include it (see “AI content reports” in “Data stored in the cloud”).
| Feature | What is sent |
|---|---|
| Recipes, drinks, cooking with fridge items and meal swaps | Ingredients, country, cuisine, tags, portions, category, allergies, diets, whether alcohol is allowed, calorie target, titles to avoid and meal type. If alcohol may be included (for example, a drink in the adults-only category), the app also tells our server that you're 18 or over, based on the age you declared during setup, so that it can allow alcohol; this isn't passed to the AI |
| Food photo analysis | The photo of your meal |
| Fridge or ingredients photo | The photo |
| Diet and allergy suggestions during setup (optional) | A photo of your fridge. The AI suggests diets and allergies, which you can change before you save your profile |
| Nutrition chat | Your message, photo or voice note and up to 20 previous turns of the current conversation. If a scanned barcode isn't found in Open Food Facts, the barcode number, to estimate the product |
| Fridge by voice and shopping list dictation | The voice note |
| Sort the shopping list by aisle | The product names (up to 150) |
| Weekly meal plan | Goal, activity level, daily targets, country, allergies, diets, whether alcohol is allowed, and your variety, cooking-time and budget preferences. If alcohol is allowed, the app also tells our server that you're 18 or over, as for recipes; this isn't passed to the AI |
| Home tip | Your goal, the time of day, and today's calories and protein eaten and targets |
| Storage tip | The product name |
| Sort saved recipes | Recipe titles and their origin (up to 200) |
| AI trainer | Goal, level, days per week, minutes, weeks, equipment, the limitations or injuries you type, your feedback, sessions done and missed, the current plan and chat messages. When you adjust the plan, also your latest logged sets of the plan's exercises since it was created or last adjusted (weight, reps, time) |
Every request also includes the app language (English, Spanish or French). Never sent to the AI: your user ID, name, email, age, weight or height. Please don't include other people's personal data in photos, voice notes or messages.
Google keeps prompts and answers for 55 days to detect abuse, as stated in the Gemini API usage policies. Under the Gemini API paid-service terms, Google processes this content as our processor and doesn't use it to improve its products. [Pending: confirm that the paid tier (active billing) is enabled on the Gemini API project]
Purchases and subscriptions
YamYam Premium is sold through Google Play or the App Store, which process the payment under their own terms; we never receive your card or payment details. Purchases are managed with RevenueCat:
- When the app opens, it contacts RevenueCat for every user, guests included, with an anonymous ID, to load the plans and your purchase status.
- If you sign in with Google or Apple, your YamYam user ID is linked in RevenueCat so that Premium follows your account.
- When you buy or restore, RevenueCat receives the store receipt or token, the product and the price. Its SDK also processes device data and your IP address. The app doesn't send RevenueCat any other information about you.
- To unlock AI features, our server asks RevenueCat whether your user ID has Premium.
Only signed-in users can buy or restore Premium.
Barcode lookups
When you scan a barcode (free, guests included), the app asks Open Food Facts, an independent open food database, for that product. It receives the barcode number, your IP address and the app name and version. The product photo is then loaded from its servers. Open Food Facts isn't our processor, and its own privacy policy applies. The product you log is saved only on your device.
Other services
- Sign in with Google and Sign in with Apple authenticate you and give us your name, email and (with Google) your profile photo link. When a Google profile photo is shown, including on the phones of your home members, the device loads it from Google's servers.
- Notifications: reminders are scheduled on your phone. The app doesn't register a push token with any service and YamYam doesn't send push messages from a server.
- Read aloud: chat answers are read with your phone's text-to-speech service.
- Camera: the app uses it only in the features that need it: photographing a meal, your fridge or ingredients for an AI feature, scanning a product barcode and scanning the QR code of a shared home. To read a barcode or a QR code, the app analyses the camera image on your phone; that image isn't saved or sent anywhere. Only the barcode number is used (see “Barcode lookups”), or the home code, which the app shows you and only uses to join that home if you confirm. If you don't allow the camera, you can type the home code instead.
- Shared-home invitations: a member can show the home code as a QR code or share an invitation link with the phone's share menu. The QR code and the link contain only the home code (for example, https://yamyam.codeenergy.org/app/join?h=AB3XY7): no name or any other data about the members. When someone scans the QR code in YamYam, or opens the link on a phone where YamYam is installed, the app shows the code and only joins the home if they confirm. On a device without YamYam, the link opens this website (see “This website”).
- “Report response” opens a short form in the app. When you tap “Send report”, we store your user ID, the feature, the reason you choose, your optional comment (up to 500 characters), the app version, your operating system and the app language in Google Cloud Firestore so our team can review it. Up to 300 characters of the answer are added only if you tick the box to include them. “Email it instead” opens your email app with a message to support@codeenergy.org containing the reason, your comment, the app version and your operating system, and the excerpt of the answer if you ticked the box; nothing is sent until you tap send there.
- Email: if you write to us, we receive your email address and your message.
What we don't do
- No advertising and no advertising ID.
- No analytics, crash-reporting or tracking tools in the app.
- No access to your location, contacts, calendar, Health Connect or Apple Health.
- We don't sell your data or use it for advertising.
- We don't use your data to train AI models.
Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and run your account, including guest mode | Account data and user ID | Contract (art. 6.1.b) |
| Keep your profile in your account so you can restore it on another phone | The profile listed in “Data stored in the cloud”, including age, sex, weight, height, goal, activity level, targets, diets and allergies | Your explicit consent in “Save your profile to your account?” (arts. 6.1.a and 9.2.a). You can withdraw it in Profile › Privacy › “Save profile to my account”; we then delete the cloud copy and your profile stays on your phone |
| AI features | The content and profile details listed in “Data sent to the AI” | Your explicit consent in “Your data and AI” (arts. 6.1.a and 9.2.a), and the contract for Premium (art. 6.1.b) |
| Show that you gave or withdrew consent | Consent records: your answer, the version of the text and the times | Legal obligation to be able to demonstrate consent (arts. 6.1.c and 7.1) |
| Review reports of AI content | The report: user ID, feature, reason, comment, app version, operating system and language, and the excerpt of the answer if you include it | Your explicit consent (arts. 6.1.a and 9.2.a), because your comment and the excerpt may contain health details: you give it by tapping “Send report” after the notice in the report form. We only use a report to review the answer you reported. You can withdraw your consent by writing to privacy@codeenergy.org and we'll delete your reports; deleting your account also deletes them |
| Sell and manage Premium and restore purchases | User ID and purchase data | Contract (art. 6.1.b); records the law requires us to keep (art. 6.1.c) |
| Daily limits, Premium checks and protection against abuse | User ID, usage counters and Premium status | Legitimate interest (art. 6.1.f): keeping the service secure, fair and affordable |
| Server logs | Error logs (error code and message, the AI feature, and for failed deletions the user ID and the affected database records) and the hosting platform's request logs (IP address, user agent, time) | Legitimate interest (art. 6.1.f): keeping the service working and secure |
| Barcode lookups and shared home | Barcode and IP address; home data | Contract (art. 6.1.b): features you choose to use |
| Answer your messages and privacy requests | Email address and message | Contract (art. 6.1.b) and legal obligation (art. 6.1.c) |
| Serve this website | IP address and technical request data | Legitimate interest (art. 6.1.f): delivering and protecting the website |
Your age is required to use the app. Age, sex, weight, height, goal and activity level are asked during setup because the app needs them to calculate your targets; diets, allergies and country are optional. A Google or Apple account is optional: without one you can use the app as a guest, without Premium. Saving your profile to your account is optional too: if you say no, the app works the same, Premium included. Alcohol is only for adults: drinks with alcohol (such as those in the adults-only category “Light cocktails”, marked 18+) and alcohol in recipes, their drink pairings and meal plans are only allowed when the app asks for them and the age you declared during setup is 18 or over (required for everyone), whether or not your profile is saved to your account. The app only tells our server that you're 18 or over, not your age; if your profile is saved, our server may also check the age stored there. You can object to processing based on legitimate interest by writing to privacy@codeenergy.org.
Automated processing and AI
Your daily targets are calculated on your phone with a standard formula (Mifflin-St Jeor) from your age, sex, weight, height and activity level. AI features generate recipes, plans, estimates and tips from what you send. None of this produces decisions with legal or similarly significant effects on you: you decide whether to follow a suggestion.
You are interacting with AI. Answers from AI features are generated automatically by Google's Gemini model, not by a person. They can be inaccurate or incomplete: calorie and macro values are estimates, and you should always check ingredients and allergens yourself. AI recipes, drinks and meal plans show this reminder next to the answer. Every AI answer or suggestion in the app is marked “AI-generated” and can be reported without leaving the app with “Report response”.
Not medical advice. YamYam is not a medical device and doesn't diagnose, treat, cure or prevent any medical condition. For medical advice, diagnosis or treatment, talk to a healthcare professional.
Recipients
| Recipient | Role | What they receive | Location and safeguard |
|---|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Functions) | Processor | Account, profile (if you agreed), shared home, consent records, AI content reports, usage counters and AI requests in transit | USA, and the Cloud Firestore region (see International transfers): EU-US Data Privacy Framework (Google LLC is certified) and Firebase standard contractual clauses |
| Google (Gemini API) | Processor under the paid-service terms [Pending: confirm the paid tier] | The AI requests described above | Any country where Google or its agents have facilities. USA: EU-US Data Privacy Framework (Google LLC is certified). Other countries: an adequacy decision for that country, if there is one, or otherwise the standard contractual clauses in Google's data processing terms (Implementing Decision (EU) 2021/914) [Pending: confirm in the Gemini API paid-service processor terms] |
| RevenueCat, Inc. | Processor | User ID, purchase data, device data and IP address | USA: standard contractual clauses (Implementing Decision (EU) 2021/914) |
| Google Play and Apple App Store | Independent controllers | Your purchase | Their own privacy policies |
| Huawei AppGallery (if you install YamYam from it) | Independent controller | The download and installation of the app. No purchases are made through AppGallery | Its own privacy policy |
| Google Sign-In and Sign in with Apple | Independent controllers (sign-in providers) | Your sign-in request and, when you delete your account, the request to revoke YamYam's access (for Sign in with Apple, the app sends it through Firebase). If revoking Sign in with Apple fails, the app tells you how to remove YamYam in your Apple Account settings | Their own privacy policies |
| Open Food Facts | Independent third party | Barcode number and IP address | Its own privacy policy |
| Vercel Inc. | Website hosting (processor) | IP address and request data when you visit this website | USA [Pending: confirm the safeguard] |
| Members of your shared home | Other users | Your name, profile photo and the shared list | Only if you create or join a home |
We may also disclose data when the law requires it, for example to a court or a public authority. Our processors may only use your data on our instructions and must protect it at least as this policy describes, under their data processing terms.
International transfers
Firebase Authentication runs only in US data centres, our AI server runs in the USA, the Gemini API may process data in any country where Google has facilities, and RevenueCat stores data in the USA. The Cloud Firestore region is [Pending: region to be confirmed].
Transfers to Google LLC in the USA rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795); Firebase also offers standard contractual clauses. When the Gemini API processes data in another country outside the European Economic Area, the transfer relies on an adequacy decision for that country, if there is one, or otherwise on the standard contractual clauses in Google's data processing terms (Implementing Decision (EU) 2021/914) [Pending: confirm in the Gemini API paid-service processor terms]. Transfers to RevenueCat rely on standard contractual clauses (Implementing Decision (EU) 2021/914). You can ask for a copy of these safeguards at privacy@codeenergy.org.
How long we keep data
| Data | How long |
|---|---|
| Data on your device | Until you delete it, sign out, delete your account or uninstall the app, within the limits listed above |
| Account (Firebase Authentication) | Until you delete your account. Signing out doesn't delete a Google or Apple account, and inactive accounts aren't deleted automatically today [Pending: decide an inactivity period]. After deletion, Google removes the data from its backups within 180 days. IP addresses logged by Firebase Authentication are kept for a few weeks |
| Guest ID | Deleted when you sign out as a guest or delete the account with an internet connection. If that deletion fails (for example, without a connection), or if you move from guest to a Google or Apple account, the guest ID (with no profile data) currently stays in Firebase Authentication [Pending: decide a cleanup period]. The anonymous purchase ID that RevenueCat gives a guest (see “Purchases and subscriptions”) isn't removed by signing out or by the in-app deletion [Pending: decide a cleanup period] |
| Cloud profile | Until you withdraw your consent (Profile › Privacy › “Save profile to my account”) or delete your account [Pending: same inactivity period as the account] |
| Shared home | Until its last member leaves it or deletes their account; then it's deleted. When a member leaves or deletes their account, they're removed from it; if they created it, another member takes it over |
| AI usage counters | Each daily counter is marked to expire 3 days after the last AI request of that day [Pending: confirm that the automatic deletion rule (Firestore TTL policy) is enabled; otherwise counters stay until the account is deleted]. Always deleted with the account |
| Premium status cache | Valid for up to 5 minutes (up to 24 hours if RevenueCat can't be reached). The record is removed when a later check finds no Premium, and when you delete your account |
| Consent records | Your latest answer for each purpose is kept until you delete your account; withdrawing consent updates the record instead of erasing it |
| AI content reports | Until you delete your account or ask us to delete them at privacy@codeenergy.org [Pending: decide a review period] |
| Content sent to the AI | Not stored by our server, except the excerpt of an answer you report, when you choose to include it (see “AI content reports”). Google keeps it for 55 days |
| Server logs (errors and requests) | [Pending: confirm the Google Cloud Logging retention period] |
| RevenueCat purchase record | Kept after you delete your account: the in-app deletion doesn't remove it today. You can ask us to delete it at privacy@codeenergy.org [Pending: decide whether to delete it automatically, or keep it for a stated period for tax and fraud-prevention reasons] |
| Google Play and App Store records | Kept by the store under its own policies |
| Emails you send us | [Pending: decide the retention period for support, privacy and billing emails] |
| Website request logs (Vercel) | [Pending: confirm the hosting log retention] |
Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, to data portability, and to withdraw your consent at any time. Withdrawing consent doesn't affect processing carried out before.
- Access and portability: Profile › Privacy › “Download my data” creates a JSON file with your profile, meals, favourites, recent foods, saved recipes, shopping list, fridge, meal plans, weight, water, achievements, workouts, AI trainer and nutrition chat. It doesn't include photos or audio, shared home data or our server counters; for the data we hold, write to us.
- Rectification: edit your profile in the app.
- Erasure: Profile › Account › “Delete Account & Data”, or see https://yamyam.codeenergy.org/delete-account.
- Withdraw AI consent: Profile › Privacy › “Share data with the AI”.
- Withdraw cloud-profile consent, or erase your cloud profile without deleting your account: Profile › Privacy › “Save profile to my account” › “Delete from the cloud”. Your profile stays on your phone.
- Anything else: write to privacy@codeenergy.org.
We answer within one month. For complex requests this can be extended by two more months, and we'll tell you within the first month. We may ask you to confirm your identity, for example by writing from the email address of your account.
You can complain to the Spanish Data Protection Agency (AEPD, https://www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or to the data protection authority of the country where you live.
Security
All connections use HTTPS. The app keeps a copy of your sign-in details and your profile in the phone's secure storage (Keychain or Keystore). The Firebase sign-in session is kept in the app's private storage and is removed when you sign out or delete your account. Our database rules only let you access your own profile and consent records, data such as usage counters can only be written by our server, and AI content reports can be created from the app but not read or changed. AI requests go through our server, which holds the key to the AI service, checks your account and limits, and validates what it receives. No system is completely secure: if a breach puts your data at risk, we'll notify the supervisory authority and, when required, you.
This website
yamyam.codeenergy.org uses no cookies, no JavaScript and no analytics, and it loads nothing from other websites. It's hosted by Vercel Inc., which processes your IP address and technical request data to deliver the pages. If you open a shared-home invitation link on a device without YamYam, your browser loads this website, and the address it requests includes the home code.
Changes to this policy
We'll publish any new version on this page and in the app, with a new effective date. If a change requires your consent, we won't apply it to you until you give it.
Contact
Code Energy · [Legal name and postal address: pending] · privacy@codeenergy.org