Skip to main content
NomNomBot Kitchen shopping agent
Home Workflow Agent Sign in
Sign in Open app

Privacy

Privacy notice

This notice explains what the NomNomBot service and Chrome extension process when you plan meals and prepare a grocery basket.

Effective 9 August 2026

Who controls your data

NomNomBot is the controller for information collected through this service. You can contact the operator, exercise privacy rights, or request deletion through Support & data requests.

Information we process

  • Account details, including your email address, login provider identifier, kitchen membership, and subscription status.
  • Kitchen data you provide, such as recipes, ingredients, meal plans, pantry items, household rules, dietary preferences, and shopping lists.
  • Shopping-agent inputs and results, including your prompt, selected meals, retailer, product matches, basket actions, warnings, and approval status.
  • When extension access is enabled, the content and controls needed from the HTTPS shopping origin you explicitly allow. If ordinary product controls fail, AI inference may receive a bounded, redacted accessibility-style view of a selected product card. Raw HTML, selectors, passwords, form values, account and address details, payment details, and checkout fields are excluded from that inference view.
  • The extension keeps its access token in device-local Chrome storage. Non-secret account context and granted-site choices use Chrome sync storage and may follow your signed-in Chrome profile until you disconnect or remove browser access.
  • Limited technical and security records needed to operate, diagnose, and protect the service.

Why we use it

We process account and kitchen data to provide the service you request. Browser access is used only after your explicit consent. We use limited operational records for security, fraud prevention, reliability, and legal compliance. You may remove extension access at any time from the sidebar.

Processors and destinations

We use Supabase for account and database services, Cloudflare for the public web service, Google Cloud for the shopping-agent backend, and DeepInfra for primary AI inference. OpenAI may process the information needed for a request when the configured fallback is used. A selected grocery retailer receives the searches and basket actions made in your browser under that retailer’s own terms and privacy notice.

These providers may process data outside the United Kingdom. We rely on the contractual and transfer safeguards offered by each provider where required.

Retention and control

Kitchen and account records are kept while your account is active and as needed to provide the service. Operational and security records are kept only as long as reasonably necessary for reliability, fraud prevention, dispute handling, and legal duties. Removing browser access clears the extension’s saved NomNomBot session; it does not delete your website account.

Use Support & data requests to request access, correction, export, objection, restriction, or deletion. We may need to verify your identity before acting.

Chrome and Google user data

NomNomBot has required access only to its own service. It requests access to a shopping site only after you choose Allow this shopping site, and each grant is limited to that HTTPS origin. We do not sell personal data or use it to train our own general-purpose AI models. Our use of information received from Google APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements.

Safety and changes

We use access controls, encrypted transport, tenant isolation, and restricted browser commands, but no online service can promise absolute security. NomNomBot is not intended for children under 18. Material changes to this notice will be posted here with a new effective date.

© 2026 NomNomBot
Guide Privacy Terms Support & data requests