Operator: Global Piggy Inc. · Applies to: the JumunCheck app (part of the NodajiFi ecosystem) · Effective date: October 14, 2026 · Last updated: October 6, 2026
This app-scoped policy supplements the ecosystem-wide NodajiFi Privacy Policy. Where the two differ for JumunCheck, this page prevails.
Introduction
JumunCheck reads restaurant menus from your photos and helps you order abroad. Global Piggy Inc. ("we," "us"; NodajiFi Labs is our research and development studio) respects the privacy of users worldwide and honors the standards of the GDPR and CCPA as well as the data-protection laws of your country of residence. Canada's PIPEDA is the baseline framework for this policy.
In short. Your food profile (diet, allergies, dislikes, budget), your order cards and your meal records stay on your phone. Menu photos are sent to our servers and to an AI provider to be read. The structured result of each scan (menu text, prices, allergen labels) is stored with your account. If "Share menu photos" is on, a reduced copy of photos without people is kept on our servers for at most 90 days.
1. Common account data
| Category | Items | Purpose |
|---|---|---|
| Account / authentication | Email address or phone number, passwordless login credentials (magic link / OTP); or an anonymous guest account | Identification, authentication, account recovery, security |
| Age verification | "Aged 16 or older" result derived from the date of birth you enter (the raw date of birth is discarded; only an anonymous age-band count without your account ID is kept for statistics) | Eligibility, child protection |
| Device / access | Device identifier, OS / app version, IP address, access logs, push token | Operation, security, notifications |
| Usage limits | Number of AI scans you made today; number of restaurant searches you made today | Daily caps that prevent abuse and cost overruns |
2. JumunCheck-specific data & permissions
| Category | Items | Where it is kept | Purpose |
|---|---|---|---|
| Camera / photo library | Menu photos you take or pick (up to 4 per scan) | Checked and compressed on your phone, then sent to our server and an AI provider for reading (see §3). Kept on our servers only under the photo-sharing conditions in §4. | Reading the menu: dish names, prices, translation, allergen labels |
| Scan results | Menu text as printed, translated dish names, prices, per-person pricing, allergen labels detected on the menu, matched dish IDs, restaurant name, country, city, currency, time of scan, which AI provider/model answered | Your account (our database) and your phone | Showing your scan history; building anonymous menu information per restaurant (§5) |
| Food profile | Diet type, allergies, dislikes, spice and salt limits, portion, drink preferences, budget per meal, home currency, travel country | Your phone only | Filtering and recommending dishes on your phone. Only your spice limit, portion preference and app language are included in the AI request; your allergies and diet are not sent. |
| Order cards & meal records | Dishes and quantities you order, food photos you add, your 👍/👎 and spice ratings, the restaurant, an approximate spot where you ordered | Your phone only | Showing the order to staff, your personal dish counts, tuning your next recommendations |
| Location (optional, off by default) | Approximate (coarse) location, turned into country and city on your phone | Your phone; country and city are sent with scans and restaurant searches | Suggesting the country guide and tax/service-charge rules, nearby places on the map, matching a scan to a restaurant |
Location precision. JumunCheck asks only for approximate location (Android: coarse location; precise location is not requested. iOS: "while using the app"). Location is used only after you turn on "Use my location" in Me. Coordinates stay on your phone (for the "you are here" dot and distance on the map, and the optional spot in a meal record); our servers receive only the country and city.
3. AI processing of menu photos
- Before anything is sent, your phone checks on-device that the photo contains text (if not, nothing is sent). Photos are compressed on the phone.
- Our server (Google Cloud Functions, Frankfurt region) forwards the photos and a short instruction to an AI provider: Google (Gemini API) or Anthropic (Claude API). Which provider answers depends on our settings and availability; if one fails, the other may be used. The provider and model are recorded with the scan result.
- The AI provider returns structured text (dish names, prices, allergen labels). We do not ask the AI to identify people.
- These providers may process the data outside your country, for example in the United States.
4. Menu photo sharing ("Share menu photos") — kept at most 90 days
"Share menu photos" in Me is on by default, and you can turn it off at any time. A reduced copy of your menu photos is kept on our servers only when all of the following are true:
- the setting is on;
- on-device face detection found no person in any of the photos of that scan (if detection fails, the photos are not kept);
- your account has passed the age check.
Kept photos are stored in Google Cloud Storage under your account, readable only by you and by our servers, and are deleted automatically no later than 90 days after upload (a daily cleanup job). When the setting is off, only the structured scan result (§2) is stored.
5. Anonymous restaurant information
When a scan is matched to a restaurant, we update that restaurant's anonymous menu summary (number of scans, number of distinct dishes, sample dish names and prices, median price per person, currency, last scan time). We also keep daily totals (number of scans, failures, provider used). These summaries contain no account identifier and may be shown to other JumunCheck users.
6. Restaurant search (Google Places) and maps
When you search for restaurants, the app sends the country, city and your search text to our server. Our server first uses our own restaurant list and a shared cache; when needed it queries the Google Places API with the search text, the city name and the city centre — not your coordinates or your account. Restaurant details obtained from Google are kept in our cache for at most 30 days. Map tiles are loaded by your phone directly from our map tile provider (MapTiler, or OpenStreetMap), which receives your IP address and the map area being viewed.
7. How we use information
- Account management: identification, authentication, recovery, abuse prevention
- Service delivery: the JumunCheck features above
- Service improvement: anonymous, aggregated statistics
- Notices: capped at 1–2 push notifications per day; you control frequency, timing, and type
- Legal compliance and dispute handling
8. Retention and deletion
- Scan results stored with your account: until you delete your account.
- Shared menu photos: while you keep your account, at most 90 days after upload (daily cleanup); when you delete your account, they are deleted together with it.
- Google Places restaurant details: at most 30 days in our cache.
- Data on your phone (food profile, scans, order cards, meal photos and records): until you tap Me → Delete all local data or uninstall the app. Deleting your account does not clear your phone.
Account deletion is actually possible by design — see Delete Your Account.
9. Sharing and sub-processors
We do not sell personal data and do not share it with third parties except with your prior explicit consent or under lawful process. Sub-processors used by JumunCheck:
| Sub-processor | Work |
|---|---|
| Google Firebase / Google Cloud (Google LLC) | Authentication, database, file storage, server functions, push notifications, analytics |
| Google (Gemini API) | Reading menu photos (AI) |
| Anthropic PBC (Claude API) | Reading menu photos (AI) |
| Google (Places API) | Restaurant search results (receives search text and city, not your account) |
| MapTiler / OpenStreetMap | Map tiles (receive your IP address and the map area) |
| Email / SMS delivery providers | Passwordless sign-in (magic link / OTP) |
Some of these providers' servers are located outside your country. Data sharing between ecosystem apps does not operate without your explicit opt-in.
10. Protection of children (ages 16+)
JumunCheck is available only to users aged 16 or older. When you first open it we take a date of birth, keep only the "16+" result, and discard the raw date. If you are under 16, the account just created is deleted and you are signed out. (Exception: a 14- or 15-year-old whose account has a verified Korean (+82) phone number keeps the shared ecosystem account, which BillyGo in Korea allows from age 14, but is signed out of JumunCheck.)
11. Your rights
You may request access, rectification, deletion, portability, restriction of processing, and withdrawal of consent by email to together@nodajifilabs.com. You can turn off "Share menu photos" and "Use my location" in Me at any time. You may also lodge a complaint with your local data-protection authority.
12. Security
TLS encryption in transit, access controls (scan results and kept photos are readable only by you and our servers), server-side daily limits, and no personal data on any blockchain.
13. Contact
Operator: Global Piggy Inc. (Hamilton, Ontario, Canada) · Data Protection Officer: Myongsu Choe (CEO) · Privacy requests: together@nodajifilabs.com
14. Changes to this policy
We give in-app notice at least 7 days before changes take effect (at least 30 days for material changes adverse to users).