Fomik Back to Fomik

Privacy policy

Last updated 16 September 2026

Your recipes stay yours

Recipes, attempts, notes, ratings and photos are stored in the app's local database on your device, and synced to your own iCloud so they survive a lost phone. That sync is between you and Apple: it uses iCloud's private database, the developer has no access to it, and the recipes never reach a server belonging to Fomik.

Fomik does now run a server — it is described two clauses below — and it is worth being precise about it: no recipe of yours has ever been sent to it, and it has nowhere to put one. It holds no database of recipes.

If you are signed out of iCloud, or iCloud Drive is off for Fomik, the recipes simply stay on the device. The app's Settings screen tells you which of the two is happening.

Your account

You can sign in with Apple, and you can skip it — the app works either way, and skipping does not cost you the iCloud sync above. If you do sign in, the account holds exactly two things: an email address and a user id. Nothing else, and no recipe of yours is attached to it.

The email may be an @privaterelay.appleid.com alias if you chose Hide My Email on Apple's sheet. The account is handled by Supabase, on servers in the European Union.

You can delete the account from inside the app, in Settings → Delete account. It is gone for good and it is not recoverable. Your recipes are not touched by it: they are in your own iCloud, which the account never had anything to do with. If you would rather ask than tap, hello@fomik.ro does the same thing.

Fomik's own server

There is one, at api.fomik.ro, and it currently does exactly two things: it tells the app which account a sign-in belongs to, and it deletes an account when you ask it to. Deletion needs a key that only the server is allowed to hold, which is the whole reason it exists.

It has no database. Nothing about you is stored on it — not your email, not your user id, not a recipe, not a preference. Each request arrives carrying the sign-in token your device already holds, the server checks that Apple and Supabase really issued it, acts, and forgets it.

What it does keep is an operational log, for as long as the server keeps its logs: the time, which of the two routes was called, whether it succeeded, and how many milliseconds it took. No token, no email address and no user id are ever written to it — that rule is written into the logging code itself, not just intended.

The server runs on a machine rented from Hetzner in Germany. Requests reach it through Cloudflare, which proxies the connection, secures it, and therefore sees the IP address it came from.

Anonymous usage analytics

The app records which of its features get used — a recipe created, an attempt logged, a screen opened — so the parts nobody uses can be found and cut. It never records what you cook. No recipe name, no ingredient, no step, no note, no photograph, and no free text of any kind: every event is a fixed label chosen from a list written into the app, not something you typed.

These events are not attached to your account, your name or your email, and they are not attached to you across other apps or websites. The analytics service assigns a random identifier to the installation, generated on your device and derived from nothing about you or your phone. It cannot be turned back into a person.

What does travel alongside each event, because the analytics service adds it: the time the event arrived, your device model, iOS version, app version, screen size, language and time zone, and whether the app was on Wi-Fi. Dates you enter are never among it — where the app needs to know that an attempt came days after the one before, it sends a range such as "3–7 days" rather than either date.

The processor is PostHog, on their EU Cloud, hosted in Germany. Their servers are configured to discard the IP address that requests arrive from, so it is not stored.

You can switch this off. in the app, Settings → Privacy → Share anonymous usage, at any time, and nothing further is sent or queued from that moment. Turning it off costs you no feature. Until 12 September 2026 this was handled by TelemetryDeck, in Germany; the events collected before then were from test devices only and are being deleted with that account.

Photos

A photo you attach is copied into the local database. Fomik asks for photo library access only when you pick one. Photos are never uploaded.

Notifications and timers

Fomik sends you no notifications at all — it has never asked for permission to, and there is no code in it that could. The cook timer is a sound the app plays while you have it open, not a scheduled alert.

One piece of Apple's push machinery is switched on, and it is silent and invisible: it is how iCloud tells the app that a recipe changed on another of your devices. It shows nothing, needs no permission, and carries no message from us — we cannot send one.

What Apple collects

Getting the app happens through Apple — the App Store, or TestFlight while Fomik is still in beta — and not through Fomik. Apple gives the developer aggregate, anonymised counts: installs, sessions, and later ratings and sales. Never a list of who installed it. TestFlight additionally needs an email address or a public join link to let you in.

If you opt in on your device, Apple also passes on crash reports, containing your device model, iOS version and a stack trace. They do not contain your recipes. See Apple's privacy policy.

Sign in with Apple is Apple's too. What it hands Fomik is the email address — real or relay alias, your choice on their sheet — and an identifier. Apple decides what it keeps about the sign-in itself; Fomik never sees your Apple ID password, and never asks for one.

Feedback you send

Feedback sent through TestFlight or by email reaches the developer directly and may include a screenshot and your email address. Kept for the length of the beta, then deleted.

Asking for an invite

The invite form on the home page asks for your email address and nothing else. It is used to send you a TestFlight invite and to reply to you. Kept for the length of the beta, then deleted. It is not a mailing list and it is not shared or sold.

This website

No cookies, no analytics, no tracking. The app's analytics described above are the app's; this site has none. Nothing loads from a third party; the typefaces are served from this domain. Hosted by Netlify, which processes standard server logs including IP addresses. See Netlify’s privacy notice.

The invite form is the only thing here that sends anything back. Submitting it posts your email address to this domain, where Netlify stores the submission and forwards it to the developer. Spam is caught by a hidden decoy field rather than a CAPTCHA, so no third-party script runs on the page.

Deleting the app

Deleting Fomik removes its local database from the device. If iCloud sync was on, the copy in your iCloud stays there and comes back when you reinstall — that is the point of it, and the app's Settings screen has an "Erase library, iCloud included" action for when it is not what you want.

Deleting the app does not delete an account you created, and does not delete analytics events already sent. Delete the account first if you want it gone — Settings → Delete account, while the app is still installed — or write to hello@fomik.ro afterwards. Analytics events carry no identifier that could be used to find yours.

Your rights

The data controller is Fomik, based in Romania, reachable at hello@fomik.ro. Under the GDPR you can ask what is held about you, have it corrected or erased, or complain to your national supervisory authority. In practice that covers your TestFlight enrolment with Apple, any invite request you have sent, any feedback you have sent, and — if you signed in — the email address and user id on your account.

Erasure of the account is the one you can do yourself, immediately, without asking: Settings → Delete account. The legal basis for holding those two fields in the first place is the contract between us — you asked for an account, and an account is an email address and an identifier or it is nothing.

The anonymous usage analytics above are outside it, and not by a technicality: they carry no identifier that could be traced back to you, so there is genuinely no record of yours to produce or erase. The way to object is the off switch in Settings, which is why it is there. The basis for collecting them without asking first is legitimate interest — knowing which features are used — weighed against a set of data that identifies nobody.

Children

Fomik is not directed at children.

Changes

This policy is rewritten before any build ships that adds analytics, syncing, accounts or any other collection. The date above changes when it does.