The plain-English version
Privacy Policy.
We collect the bare minimum needed to email you when Nibble launches. We don't sell your data. Ever.
Last updated: 1 June 2026
1. Who we are
This site (nibbleapp.co) is operated by Nibble, an independent food-discovery app project. When this policy says "we," "us," or "our," it means Nibble.
For anything privacy-related, you can reach us at [email protected].
2. What we collect
Two kinds of data:
Information you give us
- Email address — required when you join the waitlist.
- Name — optional, included only if you fill in the field.
- Your biggest challenge with saved lists — optional free-text response, only included if you fill in the field.
Information collected automatically
- User agent — your browser and operating system, recorded with your waitlist entry so we can debug device-specific issues.
- IP address — logged transiently by Cloudflare (our hosting provider) for security and DDoS protection. We don't store it ourselves.
We do not collect: your location, browsing history outside this site, contacts, social media accounts, payment information, or any data from third parties about you.
3. Why we collect it
Three reasons, all directly tied to the waitlist:
- To email you when Nibble launches. That's the deal — you give us an email, we tell you when the app is ready.
- To understand what to build. The optional "biggest challenge" answers help us prioritise features. We read every response.
- To prevent abuse. Browser info and IP logs help us spot bots, spam signups, and duplicate submissions.
Our legal basis for processing this data (under GDPR/UK GDPR) is your consent — you affirmatively submit the form. You can withdraw consent at any time by asking us to delete your data.
4. Who we share it with
We do not sell, rent, trade, or hand over your data to advertisers, data brokers, or any third party for marketing purposes. Full stop.
We do use a small number of trusted infrastructure providers (sub-processors) who handle your data on our behalf, under their own strict data-protection terms:
- Supabase, Inc. (USA) — hosts the waitlist database. Your form submission is stored here.
- Cloudflare, Inc. (USA) — hosts this website and handles network-level security. Sees your IP address when you load the page.
If we later add an email-sending provider (e.g. Resend, Mailchimp) to actually email the waitlist, we will update this section before doing so.
We may also disclose data if legally required (e.g. a valid court order), but we'll push back on anything overbroad and will notify you unless the order forbids us from doing so.
5. How long we keep it
- Waitlist entries — kept until 90 days after Nibble's public launch, or until you ask us to delete your record, whichever comes first.
- Security logs (IP addresses, request metadata) — rotated by Cloudflare within 30 days.
6. Cookies & tracking
This page does not set any first-party cookies, run any analytics, or include any third-party tracking pixels.
The only cookie that may appear is __cf_bm, set by Cloudflare for bot management. It expires within 30 minutes and contains no personal information.
If we add web analytics later (e.g. Plausible, Fathom — both privacy-respecting), we'll update this page first. We will not use Google Analytics or any ad-tech tracking.
7. Your rights
Regardless of where you live, you can email [email protected] at any time and ask us to:
- Access — give you a copy of what we hold about you.
- Correct — fix anything wrong (e.g. typo in your email).
- Delete — remove your record from the waitlist database entirely.
- Object — opt out of any specific use of your data.
- Port — receive your data in a portable format (JSON).
If you're in the UK or EU (GDPR)
You additionally have the right to lodge a complaint with your local data-protection authority — for example, the UK's Information Commissioner's Office (ICO) — though we'd appreciate the chance to fix things first.
If you're in California (CCPA / CPRA)
You have the right to know what personal information we collect, to request deletion, and to opt out of any "sale" or "sharing" of your personal information. We don't sell or share personal information as those terms are defined under California law.
8. International data transfers
Our infrastructure providers (Supabase, Cloudflare) are based in the United States, so your data is transferred to and processed in the US. Where required, transfers are protected by the EU Commission's Standard Contractual Clauses or equivalent safeguards.
9. Children's privacy
Nibble is intended for users aged 16 and over. We don't knowingly collect data from anyone under 16. If you believe a child has submitted their email to our waitlist, email us at [email protected] and we will delete it promptly.
10. Changes to this policy
We'll update this page when we change how we handle data — for example, if we add an email-sending provider or analytics tool. The "Last updated" date at the top will change to reflect the most recent revision. For material changes, we'll email everyone on the waitlist with a heads-up.
11. Contact us
Questions, deletion requests, complaints, or anything else privacy-related:
Email: [email protected]
We aim to respond within 5 working days.