Skip to policy
Your data

Privacy Policy

This policy explains what Thymr knows about you, why we use it, who helps us run the service, and the choices you have.

Effective 16 August 2026 · Last updated 16 August 2026

1. Who we are

Thymr is operated by Joshua David Tarfa, trading as Thymr. For privacy questions or requests, email hello@thymr.app. Joshua David Tarfa is the controller responsible for deciding how and why Thymr uses personal information.

2. Information we collect

  • Account information: your email address and authentication details needed to create and secure your account. Passwords are handled by our authentication provider; Thymr does not receive your readable password.
  • Google or Apple sign-in information: if you choose a provider, we receive the basic identity information that provider makes available, such as your email address, display name and optional profile picture.
  • Profile information: your display name, handle, avatar or emoji, identity choices, primary cuisine and weekly cooking goal.
  • Cooking information: dishes and cooking sessions, dates, ratings, notes, optional plate photos, progress and whether a Cook is public or private.
  • Community activity: follows, likes, comments, saved dishes, notifications and content reports.
  • Requests and support: Learn waitlist entries, searches or requests for unavailable dishes and Tables, account-deletion requests, and messages you send us. Signed-out requests may use a random browser identifier rather than an account ID.
  • Technical information: standard service and security information such as IP address, browser or device details, timestamps, error information and request logs generated when you use the site.

Your email address and authentication information are required if you want an account. If you do not provide them, we cannot create or secure one. Profile choices, cooking notes and photos are optional, but some features will not work without the information they need.

3. Google sign-in data

Thymr uses Google sign-in only to authenticate you and create or return you to your Thymr account. We request basic identity access: your Google account identifier, email address, display name and profile picture where available. We do not request access to Gmail, Google Drive, contacts, calendars or other sensitive Google services.

We store the account information needed to operate your Thymr profile in Supabase. If your Thymr profile does not already have a picture, we may store the secure web address of your Google profile picture as your Thymr avatar. We do not sell Google user data, use it for advertising or share it with unrelated third parties.

4. How we use information

  • Provide accounts, profiles, Cook Mode, progress, saved dishes and social features.
  • Display content according to the privacy choice attached to each Cook.
  • Personalise your experience and remember your onboarding and cooking state.
  • Send essential account, security and service messages.
  • Prevent abuse, investigate reports, secure the service and diagnose failures.
  • Understand requests for new recipes, Tables and learning features.
  • Respond to support, privacy and account-deletion requests.

5. Our lawful bases

Under UK data-protection law, we rely on:

  • Contract: to create your account and provide the Thymr features you ask us to use.
  • Legitimate interests: to secure and improve Thymr, prevent abuse, understand product demand and operate a safe community, where those interests are not overridden by your rights.
  • Legal obligation: when we must keep or disclose information to comply with law or respond to valid legal requests.
  • Consent: where we specifically ask for it. You may withdraw consent for that use at any time.

6. What other people can see

Your display name, handle, avatar and public community activity may be visible to other Thymr users. A public Cook may include its dish, date, rating, note and photo. A private Cook is intended to remain visible only to you. Avoid including sensitive personal information about yourself or someone else in a public post.

Public content can be copied, shared or captured by other people outside Thymr. Changing a Cook to private or deleting it stops new access through Thymr, but cannot recall copies someone else already made.

7. Service providers and transfers

We use service providers to run Thymr, including:

  • Supabase for authentication, database services and file storage.
  • Lovable and its infrastructure providers to build, host and deliver the web service and diagnose technical errors.
  • Google or Apple when you choose their sign-in option.
  • Recipe and image providers when Thymr loads attributed third-party content; those providers may receive standard web-request information such as your IP address and browser details.

Some providers may process information outside the United Kingdom. Where required, we rely on UK adequacy regulations or contractual safeguards designed to protect transferred information. You can contact us for more information about the safeguards relevant to your information. We may also disclose information when required by law, to protect someone from serious harm, or as part of a properly managed business transfer.

8. How long we keep information

We keep account and product information while your account is active and while it is needed to provide Thymr. If you request deletion, we verify and process the request and remove or anonymise information from live systems unless we need to retain limited records for security, fraud prevention, legal obligations or legal claims. Deleted information may remain outside the live service in provider backups until those backups are overwritten or expire under the provider’s normal cycle.

Anonymous product requests and technical logs are kept only while they remain useful for deciding what to build, service security or diagnosing failures. We delete or aggregate them when they are no longer reasonably needed for those purposes. We review these retention criteria as the service changes.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to our use of your personal information, and to receive certain information in a portable format. You may also withdraw consent where consent is the lawful basis.

You can update profile information in Settings and request account deletion there. For any other request, email hello@thymr.app. We normally respond within one month. You may complain to the UK Information Commissioner’s Office.

Your right to object: where we rely on legitimate interests, you can object to that use by emailing us. We will stop unless we have compelling legitimate grounds to continue or need the information for legal claims. If we rely on consent, you can withdraw it at any time by using the relevant setting or contacting us; this does not affect earlier lawful use.

10. Automated decisions

Thymr does not currently make decisions about you based solely on automated processing that have legal or similarly significant effects.

11. Local storage and cookies

Thymr uses browser storage and essential cookies or similar technologies to keep you signed in, remember onboarding, protect account sessions, retain an active Cook and make the web app work. We do not currently use third-party advertising cookies or sell your activity to advertisers. If we add non-essential analytics or advertising technology, we will update this policy and provide any choice required by law before using it.

12. Security

We use access controls, authentication, encrypted connections and provider security measures designed to protect personal information. No online service is completely secure, so please use a strong, unique password and tell us promptly if you think your account has been compromised.

13. Age limit

Thymr is intended only for people aged 18 or over. We do not knowingly permit children to hold accounts. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

14. Changes to this policy

We may update this policy when Thymr, our providers or the law changes. We will update the date on this page and, where a change materially affects your rights or how we use your information, provide a prominent in-app notice or email before the change takes effect. Where the law requires consent for a new use, we will ask for it first.

15. Contact

Privacy questions and rights requests: hello@thymr.app. Please do not send passwords, OAuth secrets or other account credentials by email.