Privacy policy
Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
- Christoph Barton
- Engerthstraße 56/4/7
- 1200 Wien
- Österreich
- Email: hello@cookfuse.app
Principle
This website works without cookies. There is no cross-site tracking, and no data is passed to advertising networks.
Personal data is only processed when you actively enter it — that is, when you sign up for the newsletter or use the contact form.
Hosting and server logs
This website is operated on Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you access the site, Cloudflare processes technically necessary connection data, including your IP address, the time of the request and the browser used. This is required to deliver the site and to protect it against attacks.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation). A data processing agreement is in place with Cloudflare; transfers to the USA are covered by Standard Contractual Clauses.
No separate server log files are kept.
Waiting list (launch newsletter)
If you sign up for the newsletter, the following data is stored:
- your email address
- the language you selected (so the email arrives in the right language)
- the confirmation status (pending or confirmed)
- a random confirmation token
- a hash of your IP address (see below)
- the time of sign-up and of confirmation
Sign-up uses double opt-in: after submitting, you receive an email containing a confirmation link. Consent is only given once you click that link. If you do not click it, no further email will be sent to you.
The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw it at any time — via the unsubscribe link in every email, or informally to hello@cookfuse.app. On withdrawal your entry is deleted entirely, not merely flagged as unsubscribed.
Data is stored until you withdraw. Storage is in a Cloudflare D1 database located in the EU.
IP addresses are stored only as hashes
To prevent automated bulk sign-ups, an identifier derived from the requesting IP address is stored with each entry. What is stored is not the IP address itself, but a SHA-256 hash formed with a secret salt. The original IP address cannot be recovered from that value.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse).
Contact form
If you use the contact form, your email address and your message are forwarded to the mailbox named above in order to answer your enquiry. They are not stored in a database.
The legal basis is Art. 6(1)(b) or (f) GDPR. The message is deleted once your enquiry has been dealt with.
Email delivery
Confirmation and launch emails are sent using Resend (Resend, Inc., USA) as a processor. Your email address is transmitted to Resend for this purpose.
Processing takes place in the eu-west-1 region (Ireland), so your address does not leave the EU for this. As the provider is a US company, any access from the USA is additionally covered by Standard Contractual Clauses.
The CookFuse app
The following additionally applies to the iPhone app. It requires no account and no sign-in. Your pantry, weekly plans, shopping list and progress are stored solely on your device and are not transmitted to us.
There is no advertising, no analytics SDK and no cross-device tracking.
Receipt scanning in the app
The photo of your receipt is processed entirely on your device. It is never uploaded or stored.
Lines the app cannot match on its own are forwarded as plain text to our own server, which has a language model (OpenAI) match them to a food item. Only the text of the line in question is transmitted, for example "WHOLE MILK 3.5%" — no photo, no total, no store, and no identifier that traces back to you.
To prevent abuse the app sends a randomly generated identifier created locally on first launch, which contains no device characteristics. It serves only to limit requests per minute. For the same purpose our server briefly processes your IP address.
The processor for this matching is OpenAI Ireland Ltd., on the basis of OpenAI’s Data Processing Addendum. OpenAI retains the transmitted lines for up to 30 days for abuse monitoring and deletes them afterwards; they are not kept beyond that. They are not used to train AI models.
Where OpenAI Ireland passes data on to group companies in the USA, it does so on the basis of the EU Standard Contractual Clauses of 4 June 2021 (Art. 46(2)(c) GDPR).
On our own server the lines are not stored. Our error logs contain no line content either — only the error type and status code.
The legal basis is Art. 6(1)(b) GDPR (providing the function you invoked). AI matching is optional — without it the app keeps working entirely locally, but recognises fewer lines.
Barcode scanning in the app
When you scan a barcode, the product number is sent to Open Food Facts (France) to retrieve its name and category. Your IP address is transmitted to that service in the process. No further data is passed on.
The legal basis is Art. 6(1)(b) GDPR.
Microphone and speech input in the app
You can dictate ingredients instead of typing them. The microphone is active only for as long as you run the dictation function, and stops as soon as you end it or say nothing for a few seconds.
CookFuse uses your operating system's built-in speech recognition. Once your device has downloaded the offline speech model, recognition runs entirely on the device and no audio data is transmitted. If the offline model is missing (for example because the system's dictation feature was never enabled), Apple's dictation service takes over: your speech input is then processed by Apple under their privacy policy. In no case is audio data transmitted to us, and CookFuse stores no audio recordings.
So that typical ingredient names are recognised more reliably, CookFuse passes the recogniser a list of known ingredient names as a hint. That list does not leave your device either.
The recognised text appears in the input field. Ingredients are only added once you confirm it. You can revoke the microphone permission at any time in your system settings; typing remains fully available.
Notifications (expiry reminders)
On request, CookFuse reminds you when food in your pantry is about to expire. This function is off by default and is only enabled after you explicitly consent in the settings.
Reminders are scheduled locally on your device. Which ingredients are due when is calculated on the device from your pantry. No push service is involved, no device token is created or transmitted, and neither we nor third parties learn what food you own or when you are reminded.
You can switch the reminders off at any time in the app settings, or withdraw the permission in your system settings.
Purchasing CookFuse Plus
CookFuse Plus is a one-time purchase through the App Store. Apple handles the payment; we receive neither your payment details nor your name.
To manage the purchase we use RevenueCat (RevenueCat, Inc., USA) as a processor. What is transmitted is the purchase event and an anonymous identifier generated by RevenueCat, so that your purchase can be restored on a new device. No account is created and the identifier is not linked to your person.
The legal basis is Art. 6(1)(b) GDPR (performance of the purchase contract).
Recipe images in the app
Recipe images are loaded from TheMealDB (themealdb.com) when displayed. As a technical consequence that service receives your IP address. No cookies are set and no further data is passed on.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in keeping the app small rather than bundling several hundred images).
Your rights
You have the following rights vis-à-vis the controller:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing (Art. 21 GDPR)
- withdrawal of consent with future effect (Art. 7(3) GDPR)
An informal message to hello@cookfuse.app is enough to exercise them.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
Changes to this policy
This privacy policy is updated when the processing described here changes. The version published here is the one that applies.