Privacy Policy
Effective as of August 12, 2026
This privacy policy explains the nature, scope, and purpose of processing personal data in the Chefito mobile and web applications, associated websites, features and content, and external online presences.
1. Controller
The controller responsible for data processing under the GDPR is:
Diego Felipe Pineda Leiva (pinedapps)
c/o MDC Management#4996, Welserstraße 3, 87463 Dietmannsried, Deutschland
Germany
Email: datenschutz@pinedapps.de
For any privacy questions, please contact us via the aforementioned address.
2. Legal Bases of Processing
We process personal data solely in line with the GDPR and the German Federal Data Protection Act (BDSG).
Art. 6(1)(b) GDPR – to perform pre-contractual steps and to provide and manage your Chefito account.
Art. 6(1)(f) GDPR – to safeguard legitimate interests, in particular ensuring IT security, analysing errors, preventing misuse, and measuring in a data-minimised way whether and which Chefito features are actually used so the service can be improved and operated sustainably.
Art. 6(1)(a) GDPR – where you grant explicit consent (e.g. for optional beta features).
Optional public Chefito Table: Publication of the separate ranking profile and participation in each season rely on your explicit, granular consent under Art. 6(1)(a) GDPR. Participation is not required for an account, kitchen, or private gamification. Automated safety screening, report handling, and abuse prevention rely on Art. 6(1)(f) GDPR; legally required measures may rely on Art. 6(1)(c) GDPR.
Art. 6(1)(c) GDPR – where processing is necessary for compliance with legal obligations.
3. Types of Data Processed
We may process the following categories of personal data:
- Master data (e.g. name, email address).
- Usage data (e.g. log files, IP address, access time, device and operating system information).
- Content data (e.g. uploaded recipes, photos or receipts).
- AI interaction data (e.g. the current Ask Chefito question, short current-turn context, and an optionally attached photo).
- Communication data (e.g. support requests or feedback messages).
- Interaction and onboarding data (e.g. Start Hub mission completion, help-tour steps, manual nutrition entries, and links to inventory items or recipes).
- Basic usage measurement (one daily app-open state, app/instrumentation version, and counters from a fixed list of coarse feature actions). It excludes screen history, search terms, kitchen, recipe or food names, free text, email addresses, and device identifiers.
- Optional food preferences (e.g. dietary style, favorite cuisines, preferred cooking time, and ingredients to avoid). These personalize suggestions and are not an allergy or health guarantee.
- Optional ranking data: public ranking name, seasonal score and rank, all-time level title, self-selected optional country/flag, an optionally published reduced profile-photo copy or initials, and separate visibility, consent, moderation, report, and appeal records. Email, UID, kitchens, inventory, recipes, search history, and precise location are not published in the ranking feed.
We do not intentionally collect special categories of personal data within the meaning of Art. 9 GDPR. Should users voluntarily upload such information, it will be processed solely to provide the core service and will not be analysed for any other purpose.
4. Services Used and Data Transfers
To operate the application we rely on services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) acting as our processor. In particular these services include:
- Firebase Authentication: Secure sign-in, session management and password reset workflows.
- Cloud Firestore: Structured storage of inventory, profile and preference data.
- Cloud Storage for Firebase: Storage of user-generated content such as photos or receipts.
- Firebase App Hosting / Google Cloud: Delivery of the website, web application, and server-side API routes.
- Firebase App Check with reCAPTCHA Enterprise: Invisible risk analysis protecting Firebase resources from automated abuse. This may process IP address, browser/device information, and the strictly necessary _GRECAPTCHA cookie.
- Firebase Cloud Messaging: Delivery of browser notifications that you explicitly enable. This processes a device/browser push token, language preference, and delivery metadata.
- Google Cloud Vision SafeSearch: one-time automated screening of a profile photo you expressly select for public ranking display against limited safety categories such as sexual content and violence.
- Google Cloud Natural Language Text Moderation: automated screening of a new or changed public ranking name against limited categories such as insult, profanity, sexual, derogatory, toxic, or violent language.
Processing is governed by a data processing agreement pursuant to Art. 28 GDPR. Where data are transferred to third countries (notably the USA), Google relies on EU Standard Contractual Clauses and implements additional safeguards such as encryption and access controls. We review on a regular basis that only the data required for operating the service are processed.
The Chefito Table is off by default. Only after your confirmation are the selected public name, seasonal points/rank, all-time title, and your separate photo and country choices published. Country is voluntary self-declaration; Chefito does not infer it from GPS, IP address, a device identifier, or precise position. Private Kitchen Points and the individual actions behind a score are not public.
Name and photo screening runs only for a new or changed publication choice; an approved result is stored with its screening version and is not resent to the screening service on every ranking view. Automated screening can produce false positives and false negatives. If publication is rejected, no new material is published; initials are used or another name is requested. Reports, moderation decisions, and a limited appeal are handled by a human. This does not create general monitoring of private activity.
According to Google, Firebase Authentication is operated from data centres in the United States. The web application stores authentication state in local browser storage so the login remains available between chefito.de and chefito.de/app until sign-out. If you sign in with Google or Apple, the selected identity provider processes the account and technical data needed for sign-in under its own privacy information.
Browser notifications are activated only after your explicit choice in Chefito and the browser permission prompt. The push token is associated with your account server-side and removed on sign-out where possible; you can revoke permission at any time in the browser site settings. The legal basis is consent (Art. 6(1)(a) GDPR; Sec. 25(1) TDDDG). Camera, gallery, and file selection are handled by the operating system and browser; content is transmitted only when you invoke the corresponding Chefito feature.
App Check/reCAPTCHA Enterprise is used solely for IT security and fraud and abuse prevention (Art. 6(1)(f) GDPR; Sec. 25(2) no. 2 TDDDG). It does not replace authentication or server-side authorisation rules.
For AI features such as recipe suggestions, image analysis, receipt scanning or structured text extraction, we process the texts, images or receipt data you submit for that feature server-side via Google AI / Gemini services. The legal basis is Art. 6(1)(b) GDPR where the processing is necessary to provide the feature you requested.
Cooking Mode voice commands are offered only when the device supports on-device recognition. Chefito does not send the recording or recognised transcript to its servers, store either of them, or include the transcript in analytics. Reading recipe steps aloud uses the operating system’s text-to-speech service.
If you save optional food preferences, only a compact selection is sent to relevant recipe, planning, or assistant functions. It does not alter factual scan or extraction results.
Ask Chefito is an AI system, not a human. It receives only bounded kitchen context needed for the request and cannot perform database changes itself. Changes are executed only by typed app functions after the exact proposal is displayed and confirmed by the user. Imported recipe text and image content are treated as untrusted input.
By default, we do not retain a persistent chat history and do not use questions, answers, or photos to train our own model. To reduce cost, an answer and its prepared action data may be cached server-side under a non-readable hash for no more than six hours. When a user deliberately sends feedback about an answer, we store the recent visible text messages up to that answer together with the rating, selected improvement reason, and response/version metadata so the Chefito team can investigate the problem. Photos, attachments, and kitchen contents that were not displayed in the chat are excluded from feedback.
For barcode lookup, the scanned EAN / UPC code is transmitted to Open Food Facts in order to retrieve publicly available product information. No Chefito login credentials or payment data are transmitted to Open Food Facts.
Chefito retrieves the public recipe catalog server-side through the official endpoints of TheMealDB (TheDataDB Ltd). No user identifier, account data, inventory, shopping list, or personal food preference is transmitted to TheMealDB. Automated catalog translation by Google AI / Gemini processes public source recipe material only, not user-specific data.
If you consent to analytics cookies in the web application, Firebase / Google Analytics may be activated to measure reach and usage. Without your explicit consent, this analytics processing remains disabled.
Firebase Analytics in the mobile application remains disabled unless you explicitly enable optional usage analytics in the app settings. When enabled, technical device information and interaction events may be processed without kitchen names, recipe or food names, prompts, photos, or free-text content. You can withdraw this consent at any time in the app settings with future effect.
Separately, Chefito processes strictly limited, content-free basic usage measurement under Art. 6(1)(f) GDPR. The admin dashboard displays aggregate daily and feature counters only and provides no person-level search or drilldown. You may object at any time in the app settings; after that, no new measurement is processed for your account and the account-linked activity state is deleted.
When store brand logos are enabled, shop domains are processed via our proxy endpoint to retrieve favicons/brand marks. No user account credentials are transmitted to the respective retailers.
5. Retention Period
We retain personal data only for as long as necessary for each purpose:
- Account data remain stored until you delete your account or the testing phase ends.
- Support communications are removed after 12 months unless statutory retention periods require longer storage.
- Server log files are kept for 7 days and then deleted or anonymised.
- System backups are encrypted and overwritten automatically after no more than 30 days.
- The visible Ask Chefito conversation is cleared when closed. Short-lived response caches are logically limited to no more than six hours; attached chat photos are held transiently in working memory and are not stored as chat attachments.
- A pre-registration kitchen draft containing food preferences and selected starter items and recipes remains only on the device. It is deleted after seven days or after successful transfer to a verified account.
- Local authentication state generally remains until sign-out, account deletion, server-side revocation/suspension, or deletion of browser data. The cookie/analytics choice remains until changed through “Cookie Settings” or browser data are deleted.
- Browser push tokens remain until sign-out, browser-side invalidation/renewal, account deletion, or detection of an invalid token, after which they are removed.
- The account-linked basic usage state is retained for no more than 90 days. Technical deduplication receipts are deleted after 7 days. Aggregated daily and feature totals without user identifiers are retained for no more than 24 months.
- An active ranking profile and its public photo copy are removed when you leave, are suspended, or delete the account. Seasonal scores are retained for no more than one year after season end, public Top 100 snapshots for no more than 180 days after season end, technical score events for no more than 90 days after season end, and reports, appeals, and moderation cases for no more than one year. Consent evidence is generally retained for up to three years for accountability and legal-defence purposes, but is removed from the operational system on account deletion unless an overriding legal obligation applies.
Once the respective purpose ceases to apply, data are deleted or anonymised unless legal obligations dictate otherwise.
6. Your Rights as a Data Subject
As a data subject you have the rights set out in Art. 15–22 GDPR, including access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Art. 6(1)(f) GDPR. You can object to basic usage measurement directly in the app settings or by email. Ranking consent can be withdrawn just as easily in the ranking view; the public entry and public photo copy are then removed while private Kitchen Points remain. You may withdraw consent at any time with future effect. You also have the right to lodge a complaint with the competent supervisory authority (Lower Saxony State Authority for Data Protection, https://lfd.niedersachsen.de). Please direct any requests to datenschutz@pinedapps.de.
7. Disclosure to Third Parties
Personal data are not transferred to third parties as a matter of course. Exceptions apply to our processors, who are engaged under data processing agreements pursuant to Art. 28 GDPR and act solely on our instructions. We do not sell data and do not share them for advertising or profiling purposes.
8. Cookies and Local Storage
We use strictly necessary cookies and local storage for authentication, the expressly requested persistent session, language settings, security, App Check/reCAPTCHA, cookie choices, and the voluntary pre-registration kitchen draft. Access to the device is based on Sec. 25(2) no. 2 TDDDG; subsequent processing is based on Art. 6(1)(b) or (f) GDPR depending on the purpose. Sign out on shared devices and clear browser data where appropriate.
The draft is not transmitted to Firebase or AI services before an account is created, the email is verified, and the terms are accepted. Firebase / Google Analytics loads only after explicit consent under Art. 6(1)(a) GDPR and Sec. 25(1) TDDDG. Without consent, no analytics events are sent. Consent can be withdrawn just as easily at any time through “Cookie Settings”; advertising, personalisation, and marketing storage remain disabled.
9. Required Information and Automated Decisions
An email address, authentication data, and content required for the requested feature are necessary to provide the account or feature. Without them Chefito cannot provide that account or feature. Optional profile information, food preferences, and analytics consent are not prerequisites for core features.
Chefito does not make solely automated decisions within Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you. AI output is a suggestion; data changes require the user action or confirmation provided by the app.
Automated ranking screening may provisionally reject publication of a name or photo but does not affect the account, private kitchen, subscription, or private points. You can choose another name or photo and, following a moderation measure, use the available human-review and appeal route.
10. Children, Teenagers, and US Regional Notices
The public Chefito Table is intended only for people who confirm that they are at least 16. Chefito is not directed to children under 13. If we obtain actual knowledge that personal information from a child under 13 is processed without required parental consent, we will disable public participation and take reasonable steps to delete it or obtain verifiable parental consent. Concerns may be sent to datenschutz@pinedapps.de.
Chefito does not sell personal information or share it for cross-context behavioural advertising. CCPA/CPRA or other US state-law rights apply only where their personal, territorial, and business-threshold requirements are actually met. Eligible requests for access, deletion, or correction may be submitted through datenschutz@pinedapps.de; Chefito will not discriminate for exercising applicable rights.
11. Right to Amend
We reserve the right to amend this privacy policy to reflect changes in law or in the service. The current version will be published here. In the event of material changes we will notify registered users by email with reasonable advance notice.
