Privacy Policy
This Privacy Policy explains how personal data is processed when using Your Fridge – Five Recipes and the public legal pages. The app creates recipe suggestions from photos of fridge contents or ingredients and uses a dedicated backend as well as external analysis and image-generation services.
DeutschController
The controller is:
Alexander Scheck
Chemnitzer Str. 14
44577 Castrop-Rauxel
Germany
Contact for privacy and support requests: scheckas.immo@gmail.com
Phone: 0152/29912203
Data processed
The app processes data that users provide, upload or generate by using the app. Technical identifiers are used so that sign-in, scan balance, recipe history and app features work correctly.
- Account data such as the stable Sign in with Apple identifier, an internal identifier derived from it, support ID, app account token and sign-in status. The app does not request or store a name or Apple email address for the app account.
- Usage and balance data such as free scans, purchased scan credits, consumption, purchase status, transaction references and support cases related to in-app purchases.
- Photos of fridge contents, food or ingredients captured by the user with the camera inside the app.
- Detected ingredients, possible ingredients, manually added or deselected ingredients, selected servings, preparation level and app language.
- Generated recipe suggestions, recipe details, ingredient lists, preparation steps, missing ingredients, time estimates, serving information and recipe images or thumbnails.
- Recipe history and favorites, where the app stores or locally keeps such data.
- Technical data such as timestamp, route, HTTP status, request ID, errors, diagnostic information, IP address, user agent and security events.
- Support data if users contact the provider, for example support ID, message text, app and iOS version, and a reply email address provided voluntarily for that specific request only.
Purposes of processing
- Providing app features for ingredient analysis, recipe generation and recipe idea display.
- Signing in with Apple and restoring the user account on another iPhone.
- Managing free scans, purchased scan packages, consumption and purchase history.
- Storing and displaying recipe history and user-marked favorites.
- Error analysis, abuse prevention, stability, system security and traceability of paid analysis runs.
- Providing public legal, contact and support pages.
- Handling support, privacy and deletion requests and complying with legal obligations.
Legal bases
Where required, processing is carried out to perform the user relationship and provide requested app features under Art. 6(1)(b) GDPR.
Security, error analysis and abuse-prevention measures are based on legitimate interests under Art. 6(1)(f) GDPR, in particular stable and secure operation, abuse prevention, cost control and traceability of scan consumption.
Where users take photos, start analyses, save recipes or send support requests, processing may additionally be based on consent or an active user action under Art. 6(1)(a) GDPR.
Legal retention, tax or evidence obligations may be based on Art. 6(1)(c) GDPR.
Photos and short-lived analysis
Photos are used in a first step to detect food items and ingredients. A separate processing step then creates recipe suggestions from the ingredient list. Photo analysis and recipe generation are technically separate processing steps.
Fridge photos are not intended to be stored permanently in the backend. They are processed for the requested analysis run, sent to the configured analysis provider and discarded after processing, unless short-term technical troubleshooting or security analysis is strictly required.
Users should not photograph or upload people, faces, identity documents, health data or other unnecessary personal data. If such data is nevertheless visible in a picture, it may technically become part of the analysis.
AI, analysis and image-generation services
For ingredient analysis, recipe generation and recipe image or thumbnail generation, content may be sent to external API services, in particular OpenAI. Only content needed for the relevant function is transmitted, for example a compressed photo, detected ingredient list, language, servings and recipe preferences.
External API services may process data outside the European Union or European Economic Area, in particular in the United States. Where required, transfers are based on appropriate safeguards such as data processing agreements, EU Standard Contractual Clauses, adequacy decisions or comparable safeguards of the respective provider.
According to OpenAI's current provider information, API data is not used to train models by default unless an explicit opt-in is enabled. Providers may nevertheless process content for abuse monitoring, safety, troubleshooting or legal obligations for a limited time; the current provider terms and actual technical configuration are decisive.
AI-generated recipes are non-binding cooking aids. They are not medical, nutritional, allergological or food-safety advice and do not constitute automated decisions with legal effect within the meaning of Art. 22 GDPR.
The technical configuration does not request persistent application storage for Responses API calls. Limited provider-side processing for abuse monitoring, security or legal obligations may remain unaffected.
Recipe history, favorites and recipe images
Recipe text, ingredient lists, preparation steps, thumbnails and favorite markers may be stored so that users can view recent recipes again. These data are usually less sensitive than fridge photos, but may reveal eating habits or preferences.
The recipe history may be technically limited, for example to a certain number of recent recipes. Photos are not intended to be stored as a permanent part of recipe history.
Deletion of recipe history or the account can be requested through support if the app does not provide a self-service deletion function.
In-app purchases and Apple
In-app purchases are processed by Apple. The provider does not process full payment data such as credit card numbers where payment is handled exclusively by Apple.
To unlock and verify purchased scans, product ID, transaction ID, purchase status, timestamp, scan balance and technical verification data may be processed. Apple may act as an independent controller for its own App Store, payment, tax and platform processes.
Hosting, server logs and security
The app uses a dedicated backend infrastructure at https://yourfridge.scheckas.synology.me. For delivery, troubleshooting and system security, technical log data may be processed, in particular IP address, timestamp, route, HTTP status, request ID, error message, data volume and user agent.
These data are used for operation, troubleshooting, abuse detection and technical security. The legal pages do not use advertising, external tracking or profiling.
Operational server and error logs are stored only as long as needed for operation, troubleshooting, abuse detection and security. As a guideline, the regular period is 7 to 30 days unless a security, support or evidence case requires longer retention.
iOS permissions
The camera is used when users photograph their fridge or food. A photo is processed only when the user uses it for analysis.
The current iPhone version does not offer general selection from the photo library. Only photos captured by users with the camera inside the app and then submitted for analysis are processed.
Sign in with Apple is used so that users can be recognized and use their account on another iPhone. The app requests neither a name nor an email address during sign-in.
Retention and deletion
Account and balance data are generally stored until account or data deletion, unless legal retention, evidence or abuse-prevention reasons require longer storage.
Fridge photos are intended to be processed only for the analysis run and then discarded. Recipe text, recipe images, recipe history and favorites may be stored longer so users can use the app meaningfully.
Purchase and transaction data are stored as long as necessary for purchase verification, support, abuse prevention, tax obligations or evidence purposes.
Support data are stored to process the request and for an appropriate evidence period, generally no longer than necessary unless an open case, security issue or legal matter requires longer retention. A voluntary reply email address is not stored as regular account data.
User rights
- Access to stored personal data under Art. 15 GDPR.
- Rectification of inaccurate data under Art. 16 GDPR.
- Erasure under Art. 17 GDPR and restriction of processing under Art. 18 GDPR.
- Data portability under Art. 20 GDPR.
- Objection to processing based on legitimate interests under Art. 21 GDPR.
- Withdrawal of consent with effect for the future.
- Complaint to a competent data protection supervisory authority.
Supervisory authority
The data protection supervisory authority for North Rhine-Westphalia is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.