Privacy Policy for FridgeLoop

Last updated: January 2025

Important Notice: This Privacy Policy complies with the requirements of the General Data Protection Regulation (GDPR) and provides comprehensive information about the processing of your personal data.

1. Data Controller

The data controller for data processing is:

Dennis Donner
Email: app-support@donner.io
Legal notice

2. Data Collection and Purpose of Processing

2.1 Registration Data

Data Collected: Email address, encrypted password, username (optional)

Purpose: Creation and management of your user account

Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance)

2.2 Food Data

Data Collected: Food information from receipts, manually entered products, expiration dates, quantities

Purpose: Provision of core functionalities (fridge management, expiration reminders, recipe suggestions)

Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance)

2.3 Mobile Device Data

Data Collected: Device ID, operating system and version, app version, device type, screen resolution, language and timezone settings

Purpose: App optimization for different devices, bug fixing, security

Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)

2.4 App Usage Data

Data Collected: App usage statistics, feature usage, crash reports, performance data

Purpose: Improvement of app functionality, bug fixing, user experience enhancement

Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)

2.5 Receipt Photos

Data Collected: Photos of receipts for AI-powered recognition

Purpose: Automatic extraction of product data

Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance)

Retention Period: Photos are deleted after processing; only extracted data is stored

3. Cloud Services Used

3.1 Supabase (Backend Services)

Provider: Supabase, Inc., USA

Purpose: Database hosting, user authentication, API services

Data Transfer: Your data is transmitted encrypted to Supabase servers

Data Protection Level: Supabase is SOC 2 Type II certified and complies with EU data protection standards

More Information: Supabase Privacy Policy

3.2 Firebase (Google Cloud Services)

Provider: Google LLC, USA

Purpose: Push notifications, app analytics, crash reporting

Data Transfer: EU-US Data Privacy Framework

More Information: Firebase Privacy

4. Data Transfer and Security

All data transfers are encrypted via HTTPS/TLS. Your passwords are hashed and cannot be viewed in plain text. We implement technical and organizational measures to protect your data from unauthorized access.

5. Data Retention

6. Your Rights under GDPR

You have the following rights regarding your personal data:

6.1 Right of Access (Art. 15 GDPR)

You can request information about the data stored about you at any time.

6.2 Right to Rectification (Art. 16 GDPR)

You can request the correction of incorrect data.

6.3 Right to Erasure (Art. 17 GDPR)

You can request the deletion of your data, provided there are no legal retention obligations.

6.4 Right to Restriction of Processing (Art. 18 GDPR)

You can request the restriction of processing of your data.

6.5 Right to Data Portability (Art. 20 GDPR)

You can receive your data in a structured, machine-readable format.

6.6 Right to Object (Art. 21 GDPR)

You can object to the processing of your data if it is based on legitimate interests.

7. Push Notifications

The App sends push notifications for expiring food items. You can disable these in the app settings at any time. Notifications are sent via Firebase Cloud Messaging.

8. Data Deletion and Account Deactivation

You can delete your account in the app at any time. This will irreversibly delete all your personal data. Anonymized statistical data may be retained for analysis purposes.

9. Changes to Privacy Policy

We reserve the right to update this Privacy Policy. We will inform you about significant changes via email or through the app.

10. Contact and Complaints

For questions about data protection or to exercise your rights, contact us:

Email: app-support@donner.io
Subject: Privacy FridgeLoop

You have the right to file a complaint with a data protection authority regarding the processing of your data.

11. Minors

The App is not directed at persons under 16 years of age. We do not knowingly collect data from minors under 16 years of age.

Important Note on AI Processing: AI-powered receipt recognition is performed encrypted and original photos are immediately deleted after processing. Only the extracted product data is stored.