Privacy Policy

Last updated: September 12, 2026

Noomi ("we", "us") is operated by Mehmet Fatih Demirci, an independent developer (stvy.io). Questions about this policy: mail@stvy.io.

This is a plain-language policy. If anything here contradicts what the app actually does, that is a bug on our side — tell us and we will fix it.

What we collect

Your account. When you first open Noomi we create an anonymous account so your taste profile has somewhere to live. If you sign in with Apple we store the identifier Apple gives us and the email address Apple shares — which may be a private relay address if you chose to hide your real one.

What you tell us about your taste. Ratings, the tags you pick, notes you write, your watchlist and watched list, titles you mark as not interested or dropped, and the answers you give during onboarding. This is the product; there is no version of Noomi that works without it.

How you use the app. Which titles you open, how long a card stays on screen, which recommendation you acted on, and which screen an action came from. We use this to tell whether the recommendations are actually good.

What you ask the advisor. Messages you send to the AI advisor and the context we send with them (your taste profile and candidate titles).

Your preferences. Region, streaming services, content interests, and notification settings.

Subscription status. Whether you have an active subscription, handled through RevenueCat. We never see your payment details — Apple handles payment.

Crash diagnostics. When the app crashes we receive a technical report (device model, OS version, and where in the code it failed). These are not linked to your account.

What we do not do

Who processes your data on our behalf

ServiceWhat it doesWhat it sees
SupabaseDatabase, authentication, server functionsYour account and everything above
AnthropicPowers the AI advisor, curation and written taste summariesYour advisor messages, any free-text viewing history you paste in, and a summary of your taste profile
RevenueCatSubscription stateAn account identifier and purchase status
SentryCrash reportingTechnical crash data, not linked to your account
CloudflareBot protection at sign-upNetwork-level signals only
AppleSign in with Apple, paymentsHandled by Apple under Apple's own policy

We also request title metadata, artwork and streaming availability from TMDB and JustWatch. Those are outbound requests about titles — they do not carry anything about you.

Where your data lives

On our servers in Singapore (Supabase, AWS region ap-southeast-1) and locally on your device. Data in transit is encrypted.

How long we keep it

As long as your account exists. When you delete your account we erase your ratings, library, taste profile, advisor history and account record from our own servers immediately, and it cannot be undone. Aggregated statistics that cannot be traced back to you may remain.

One thing deletion cannot reach right away. Anything that was sent to our AI provider — your advisor messages, pasted viewing history, and taste summaries — also sits on their systems for a short period, and deleting your Noomi account does not shorten it. Anthropic deletes API inputs and outputs within 30 days of receiving or generating them. If a request is flagged under their usage policy, they may keep it for up to two years. Anthropic does not use commercial API data such as ours to train their models.

We tell you this because "we deleted everything instantly" would be true of our own servers and misleading about the whole picture.

Your choices

If you are in the EEA or the UK, our legal basis is performance of the contract (giving you recommendations) and legitimate interest (keeping the service working and free of abuse). You have the right to access, correct, export, restrict or erase your data, and to complain to your local supervisory authority.

If you are in California, we do not sell or share personal information as those terms are defined by the CCPA.

Children

Noomi is not directed at children under 13. We do not knowingly collect data from them. If you believe a child has created an account, write to mail@stvy.io and we will remove it.

Changes

If we change this policy in a way that matters, we will tell you in the app before the change takes effect.