Privacy Policy
Last updated: July 17, 2026
1. Scope
This policy explains how Vynn ("we", "us", or "our") handles personal information when you use the Vynn mobile app, vynnapp.com, and the services they connect to (together, the "Service").
2. Information we handle
- Account and security information: email address, name, password hash or chosen sign-in provider, linked-provider records, verification and reset records, active sessions, and security metadata such as IP address and user agent.
- Profile and shopping preferences: postal code, search radius, preferred stores, and optional dietary preferences or food restrictions you save.
- Search information: grocery queries, location or radius inputs, selected stores and filters, result interactions, and product identifiers needed to return and improve results. Recent-search displays may also be stored locally on your device.
- Local app information: the first-release shopping list and some preferences are stored on your device. They are separate from your Vynn account unless a feature explicitly says it is synchronized.
- Recipe information: when guarded recipe features are enabled, recipe URLs, pasted text, images you choose, imported drafts, edits, saved recipes, ingredient choices, quote decisions, and the list you choose as a destination.
- Communications: information you provide when joining a waitlist, contacting support, or making a privacy request. A waitlist submission may include the page, referral, and campaign context associated with that form.
- Technical information: service logs, error and rate-limit records, device/browser type, IP address, and—only after optional analytics consent—the analytics information described below.
3. How we use information
- Provide account access, grocery search, store and location scoping, dietary filtering, product details, lists, and guarded recipe features.
- Secure accounts, prevent abuse, enforce request limits, diagnose failures, and maintain the Service.
- Respond to support, privacy, and account-deletion requests.
- Send launch or product communications you requested.
- Measure and improve public website use only when you allow optional analytics.
4. Optional analytics, cookies, and ads
Optional analytics are off unless you select Allow analytics. Choosing Use necessary only, or making no choice, leaves them off. Your choice is stored in your browser's local storage so the site can remember it.
- Google Analytics 4: after opt-in, Google Analytics may receive a query-free page path, page title, generic interaction events, IP address, and device/browser information on eligible public marketing and content pages. Google Analytics is disabled on Vynn's landing-page search entry, barcode lookup, grocery search, authentication, and account pages.
- Microsoft Clarity: after opt-in, Clarity may use cookies and similar technologies to provide aggregated interaction metrics, heatmaps, and session replay on eligible public marketing and content pages. Clarity is disabled on Vynn's landing-page search entry, barcode lookup, grocery search, authentication, and account pages even after opt-in.
- Sensitive-route boundary: Vynn does not send grocery search terms, postal codes, dietary preferences, account details, or search-result interactions to either optional analytics provider.
- Google AdSense: Vynn does not currently load Google AdSense or serve AdSense advertising. Advertising remains disabled while Vynn evaluates the certified consent tooling required before any future use.
Google and Microsoft may process analytics information outside Canada, including in the United States, under their own terms and privacy practices. See the Google Privacy Policy and Microsoft Privacy Statement.
You can change or withdraw your analytics choice at any time using the Privacy choices button shown on this site. Withdrawal stops future optional measurement from Vynn's site; it does not retroactively erase information already processed by a provider. You can also use browser controls to block or delete cookies and local storage.
5. Service providers and sharing
We do not sell personal information. We use service providers for hosting, email delivery, authentication, security, analytics you opt into, and other operations needed to provide the Service. If you choose Google or Apple sign-in, that provider processes the sign-in request under its own terms.
When guarded Recipe Import is enabled, Vynn first uses deterministic parsing. If that cannot complete an import, unresolved recipe text, visible content fetched from a recipe URL, or sanitized recipe images may be sent to Google Gemini through a paid API for processing outside Canada. Vynn requests stateless processing with store=false; Google may still retain limited abuse-monitoring records for a period Vynn cannot disable.
We may also disclose information where required by law, to protect users or the Service, or as part of a business transaction subject to appropriate safeguards.
6. Location and dietary information
Postal code, search radius, preferred stores, and dietary preferences are used to tailor search and account behavior. The website does not request browser location; you enter a postal code to scope grocery search. Dietary results are informational and depend on available source data; they are not medical advice.
7. Retention
- Account and profile information is kept while your account is active and removed through the account-deletion process, subject to the limited exceptions below.
- Device-local lists, recent searches, postal codes, and preferences remain until you clear them in the app/browser or remove the app's local data.
- Operational, fraud-prevention, security, rate-limit, backup, legal, aggregated, or de-identified records may be kept where reasonably necessary and are not used to recreate a deleted account.
- Optional analytics information is retained according to Vynn's provider settings and the provider's policies.
- Temporary recipe images become eligible for cleanup after an import reaches a terminal state or the 24-hour staging limit expires. Parsed results for public recipe URLs may be used for up to seven days and then become eligible for cleanup.
- Deleting an individual saved recipe removes its database records and attempts to delete associated stored images. Failed image deletion is recorded for retry rather than being treated as complete.
8. Security
We use technical and organizational safeguards designed to protect personal information, including authenticated access controls and restricted service credentials. No method of transmission or storage is completely secure.
9. Your choices and account deletion
You may request access to, correction of, or deletion of personal information by emailing privacy@vynnapp.com. We may need to verify that you control the account before completing a request.
You can delete your Vynn account from the Account screen in the app or website. See the public account-deletion instructions for the steps, what deletion covers, and the separate treatment of device-local data.
10. Policy changes
We may update this policy as the Service changes. We will post the revised policy here and update the date above. Material changes may also be communicated in the app or by another appropriate method.
11. Contact
For privacy questions or requests, contact privacy@vynnapp.com. For general app support, contact support@vynnapp.com.