Privacy policy
Mumsa is an app for logging food and following your energy balance. This page explains what data we process, why, and what rights you have. Last updated 2026-09-28.
Controller
Christopher af Bjur, a sole trader in Sweden, is the controller for the processing described here. Contact: support@mumsa.app.
Data we process
- Account. Email address (or Apple’s relay address if you chose “Hide My Email”), password stored as a hash, the link to your Apple ID if you sign in with Apple, whether the email is verified, plus language and units.
- Profile. Age, weight, height, sex, activity level, weight goal and an optional calorie goal of your own. They are used to estimate your energy needs.
- Data from Apple Health. Only if you grant access: steps, active energy, resting energy and weight. We read, we never write. What is stored are daily figures (calories, steps and how many minutes an Apple Watch was worn) and weight entries, as the basis for your daily energy balance.
- Content you create. Meal logs, recipes, saved meals, shopping lists, weight entries, corrections to food data, reports of inappropriate content and recipe photos you upload.
- Technical data. Server logs with IP address, browser or app identification, time and the address requested, for operations, troubleshooting and abuse protection. We use no analytics, tracking or crash-reporting tools.
Apple Health
Data from Apple Health (HealthKit) is used solely to calculate and show your own energy balance in Mumsa. It is never used for marketing or advertising, never sold and never disclosed to third parties for such purposes. It is not shared with anyone beyond the providers that store it on our behalf (see below). You can turn off access at any time in the Health app under Sharing → Apps and Services.
Why we process the data
- To provide the service (our contract with you): account, profile, your content and the calculations built on them.
- With your consent: data from Apple Health and photos you upload. You can withdraw consent at any time.
- Legitimate interest: security, logs, abuse protection and improving food data through corrections.
- Legal obligation: where the law requires it.
Sharing and public pages
- Public recipes. A recipe you make public is shown to other users and on a share page on the web. In production, search engines may index public recipes (name, description, ingredients, steps and photo). Private recipes are never visible to others.
- Shopping lists. Shared only through a link you create yourself. Anyone with the link can see the list and tick items off.
- Corrections to food data. Your corrections are visible to you. Once enough users independently make the same correction, the value becomes shared for everyone, with no link to you.
- AI assistants. Only if you connect Claude or ChatGPT yourself by signing in with a code we email you. The assistant can then search the food database, read and write your meal logs, and read your goals and energy balance. It does not see your password and cannot change or delete the account. Disconnect under Settings → Security → Connected AI assistants, or in the assistant’s own settings; access ends immediately. What the assistant does with the data is governed by its own privacy policy.
- We never sell personal data.
Providers and storage
Data is stored with Amazon Web Services in the Stockholm region (eu-north-1): database, image storage (S3 with CloudFront) and email delivery (SES). Data does not leave the EU/EEA. If you sign in with Apple, Apple handles the sign-in under its own terms. We only email you to verify your address, reset your password and send sign-in codes for the AI connector.
Food data
Nutrition figures come from Open Food Facts (Open Database License and CC BY-SA) and Livsmedelsverket, the Swedish Food Agency (CC BY 4.0), complemented by user corrections. This is not personal data, but we want to be clear about where the numbers come from.
How long we keep the data
For as long as your account exists. You delete the account yourself in the app under Settings. That removes the account, profile, meal logs, health data, weight entries, shopping lists, private recipes and uploaded photos. Public recipes are anonymised – the link to you and the photo are removed – because other users may have logged them. If you signed in with Apple, the sign-in is revoked with Apple. Database backups are deleted within 14 days. Server logs are kept for a short time for operations and security.
Your rights
You have the right to access your data, have it corrected, have it erased, receive it in a machine-readable format, restrict or object to processing, and withdraw consent. You correct your profile and content in the app, and you delete in the app. For anything else, email support@mumsa.app. You can also complain to the Swedish Authority for Privacy Protection (imy.se). We make no automated decisions with legal effect; the calorie calculations are guidance, not decisions.
Children
Mumsa is not directed at children. You must be at least 16 to create an account, and we do not knowingly collect data about younger people.
Security
All traffic is encrypted (TLS). Passwords are stored only as hashes, and access to the systems is limited to what operations require.
Changes
We update this page when the processing changes and state the date at the top. For major changes we let you know in the app.