Goumi Privacy Policy
Last updated: 8 July 2026
1. Who we are
Goumi is a voice-first AI cooking assistant for iPhone and Apple Watch, made by Generate Your Audience Pty Ltd, an Australian company (“Generate Your Audience”, “we”, “us”, “our”). This policy explains what personal information we collect through the Goumi iOS app and the goumi.ai website, how we use it, who we share it with, and the choices you have.
The short version: we collect what's needed to run Goumi for you — your account, your recipes and plans, your chats, and (only while you're in a voice session) your voice. We don't run analytics or advertising trackers, we don't sell your information, and you can delete your whole account from inside the app.
Our website uses a small number of cookies, described in our Cookie Policy. For anything privacy-related, contact us at hello@goumi.ai.
2. Information we collect
Account and profile
- Sign in with Apple — we request your name and email address. The Apple identity token is exchanged with our authentication provider (Supabase) to create your account, and the name Apple provides is used to prefill your display name.
- Email sign-in — alternatively, you can sign in with just your email address and a 6-digit one-time code we send you. There are no passwords.
- Profile — your display name, plus an optional avatar photo, optional bio, and your cooking skill level.
Family member profiles (optional and sensitive)
You can optionally add family members so Goumi can tailor recipes, nutrition estimates, and meal plans to your household. A family member profile can include a name, relationship, date of birth, height, weight, and biological sex, dietary preferences, notes, and an optional photo.
We treat this as sensitive, health-adjacent information. It is used solely to personalise recipes, nutrition, and meal plans — nothing else. It is entirely optional: Goumi works without it. It may include information about children, entered and controlled by the adult account holder (see section 9). You can edit or delete family member profiles at any time in the app, and they are removed entirely when you delete your account.
Cooking and food data
Stored against your account so it's there when you come back:
- Recipes you create or save, including AI-generated ones (ingredients, steps, nutrition information)
- Meal plan entries — which recipes on which dates, and the meal type
- Cooking session history — what you cooked, when, your step progress, and session notes
- Pantry inventory — items, quantities, expiry dates, notes
- Your kitchen equipment list and dietary preferences
Chat and uploaded content
- AI chat transcripts — your recipe-creation and meal-plan chats, including any free-text preferences you type.
- Photos and documents you upload — for example photos of dishes, ingredients, your fridge or pantry, or recipe pages, and PDFs. These are stored in a private storage bucket that only your account can access.
- Avatar photos are stored in a public-read bucket, which means the image URL is publicly reachable by anyone who knows it. Please don't use an avatar you wouldn't want visible outside the app.
Voice
During hands-free voice sessions, live microphone audio is streamed to ElevenLabs (our voice AI provider, using LiveKit/WebRTC transport) to power the conversation. A live transcript is held in memory during the session so Goumi can follow along; the app does not save voice transcripts to our database. When the session ends, the stream stops.
Subscription data
All billing is handled by Apple — we never see your card or payment details. To confirm your Goumi Pro entitlement, the app sends the Apple-signed transaction to our server, which verifies it with Apple and stores the original transaction ID, product ID, latest transaction ID, subscription status, and environment, plus an audit log of subscription events. We also receive App Store Server Notifications from Apple about renewals, cancellations, and refunds.
On your device only (never sent to us)
- Cook timers (saved locally so they survive an app relaunch)
- A local offline cache of your own data, an image cache, and ingredient-availability checkmarks
- Your sign-in session tokens, kept in the iOS Keychain
- Widget, Live Activity, and Lock Screen content (recipe titles, step text, timer state) — shared only with Goumi's own widget extension on your device
- Apple Watch data (active timers, the current cooking step, today's plan) — sent over Apple's device-to-device WatchConnectivity and stays within your paired devices
3. How we use your information
We use the information above to:
- Provide Goumi — create and sign in to your account, sync your recipes, plans, pantry, and chats across your devices, and run guided cooking sessions;
- Personalise — tailor recipes, nutrition estimates, and meal plans to your preferences, equipment, pantry, and (if you add them) your family members;
- Power AI features — generate recipes and meal plans, respond in voice sessions, and adapt cooking steps (see section 4);
- Verify your subscription — confirm your Goumi Pro entitlement with Apple;
- Support you — respond when you contact us.
That's it. We don't use your information for advertising, we don't build profiles for any purpose other than the features described here, and we don't sell it.
4. AI processing and third-party providers
Goumi is built on a small set of service providers. Each receives only what's needed for its job:
| Provider | What is sent | Purpose |
|---|---|---|
| Supabase | Your account and the app data described in section 2 | Authentication, database, and file storage (our backend host) |
| Anthropic (Claude AI) | Your chat messages, photos and documents you attach to chat, saved-recipe context, and dietary preferences | Generating recipes and meal plans, and adapting and coordinating cooking steps |
| OpenAI | Recipe title, cuisine, and category text only — never your photos | Generating recipe illustration images |
| ElevenLabs (with LiveKit transport) | Live microphone audio and conversation context during voice sessions | The real-time voice conversation with Goumi |
| Apple | Signed StoreKit transactions; App Store server notifications | Subscription billing and entitlement verification |
Content you send to the AI providers (Anthropic, OpenAI, ElevenLabs) is processed by them to provide the feature you're using, under their respective terms.
5. What Goumi doesn't do
- No analytics, tracking, or advertising. The app contains no analytics SDKs, no ad networks, no crash reporters, and no third-party trackers of any kind. We don't touch the advertising identifier (IDFA).
- No Apple Health integration. Goumi does not connect to Apple Health or HealthKit, and does not read or write any Health data.
- No push notifications. Timer alerts are local notifications generated on your device — no device push token ever leaves your phone.
- No location, contacts, or Face ID data. Goumi doesn't request or use any of these.
- No sale of personal information. We do not sell or share your personal information for advertising, and never have.
6. Device permissions
Goumi asks for these iOS permissions, each for one specific purpose:
| Permission | Why Goumi asks |
|---|---|
| Microphone | So you can talk to Goumi hands-free while cooking. Voice sessions use a background-audio mode so the conversation continues with the screen locked. |
| Camera | To capture photos of dishes, ingredients, or recipe pages to attach to chat. |
| Photo library | To pick existing photos to attach to chat or set as your avatar. |
| Notifications | Local cooking-timer alerts only. |
Every permission is optional — you can decline or revoke any of them in iOS Settings, and the rest of the app keeps working.
7. Data storage and security
Your data is stored with Supabase (authentication, Postgres database, file storage, and edge functions). We protect it with:
- Row-level security on the database, so each user can only access their own records;
- Private storage buckets for your uploaded photos and documents (avatars are the one public-read exception, disclosed in section 2);
- Encryption in transit for all connections between the app, our backend, and our providers;
- The iOS Keychain for your sign-in tokens on device.
No system is perfectly secure, but we design Goumi so that the data we hold is limited to what the product actually needs.
8. Retention and deletion
We keep your data for as long as your account exists.
Account deletion is built into the app: go to Profile → Delete account and confirm. This deletes your sign-in account and cascades to every record you own — profile, recipes, saved recipes, meal plans, cooking sessions, chats, family member profiles, pantry, equipment, and subscription records — and removes your avatar files.
One honest caveat: files you previously uploaded as chat attachments may remain in storage after account deletion, even though every database record referencing them is deleted. We purge these residual files on request — email hello@goumi.ai and we'll remove them.
You can also email hello@goumi.ai at any time to request deletion or exercise any of the rights in section 10.
9. Children
Goumi is not directed at children, and accounts are for users who meet the minimum age in our Terms of Use. Family member profiles may describe children (for example, so meal plans suit the whole household), but that information is entered, managed, and deletable only by the adult account holder. If you believe a child has created their own account, contact us at hello@goumi.ai and we will delete it.
10. Your rights
Australia (Privacy Act 1988 and the APPs)
You can ask us for access to the personal information we hold about you and ask us to correct it — much of it you can view and edit directly in the app. Contact hello@goumi.ai and we'll respond within a reasonable time. If you're not satisfied with how we've handled a privacy concern, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
European Economic Area and United Kingdom (GDPR / UK GDPR)
Our legal bases are: performance of a contract (providing the service you signed up for), consent (optional family member profiles, including health-adjacent details, and microphone access for voice sessions — both withdrawable at any time), and legitimate interests (keeping the service secure and preventing abuse). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. Exercise them in the app or via hello@goumi.ai.
California (CCPA/CPRA)
We do not sell personal information and do not share it for cross-context behavioural advertising, and we haven't in the preceding 12 months. You have the right to know what we collect (this policy, especially section 2), the right to delete (built into the app, or by email), the right to correct, and the right to non-discrimination for exercising your rights.
11. International transfers
We are an Australian company, and the providers in section 4 process data in other countries, including the United States. Wherever your information is processed, it is handled in line with this policy, and we take reasonable steps to ensure our providers protect it consistently with the law that applies to you.
12. Changes to this policy
If we change this policy, we'll post the updated version here with a new “Last updated” date. For material changes — especially anything affecting family member data or AI processing — we'll also let you know in the app.
13. Contact us
Generate Your Audience Pty Ltd (ABN 68 620 590 481)
Privacy, support, and deletion requests: hello@goumi.ai