Legal

Privacy policy

Translation for information only. Foodlex is operated from Germany and this notice is written to satisfy the GDPR and the German Federal Data Protection Act. The German version is the binding one; if the two differ, the German wording applies. References to German statutes are left in their original form, because an English rendering of a section number would not point at anything.

This notice describes how we process personal data when you use foodlex.app (the marketing site) and app.foodlex.app (the web application). Scope: the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).

1. Controller

The controller within the meaning of Article 4(7) GDPR is:

Stephan Buchfink
Adlerstraße 26
68199 Mannheim
Germany
Email: kontakt@foodlex.app

2. Data protection officer

Given the size and nature of our processing, appointing a data protection officer is not required by law (§ 38 BDSG). For any question about data protection, please write directly to the email address above.

3. General information

We process personal data only where this is necessary to provide a functioning website and our content and services. Personal data is processed only with your consent or on the basis of a statutory permission.

4. Visiting the marketing site (foodlex.app) — server logs

When you open foodlex.app, our hosting provider (Vercel Inc., see section 9) automatically processes technical data that your browser transmits:

  • IP address
  • Date and time of access
  • URL requested and referrer
  • Browser type and operating system (user agent)
  • Volume of data transferred and HTTP status code

Purpose: delivering the content, keeping the service stable and secure.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in a stable, secure operation of the website).
Retention: Vercel anonymises or deletes server logs after a short period by default.

5. Audience measurement (Umami & Google Analytics)

5.1 Umami (self-hosted, cookieless)

On foodlex.app we run a self-hosted instance of the open-source analytics software Umami. Umami works entirely without cookies and without tracking identifiers across sessions or devices, and it runs independently of any consent.

Data collected:

  • The page requested
  • Referrer (where the visit came from, if any)
  • Browser and operating system family
  • Country (derived from the IP address; the IP itself is hashed and not stored)
  • Screen size class (e.g. “Mobile”, “Desktop”)
  • Events without any personal reference — that a button was used and which option was picked. For example: on the English home page you can click which set of rules you need labels under (such as USA/FDA or the United Kingdom). Only that choice is stored, together with the characteristics listed above — no input fields, and no identifier that leads back to a person.

Purpose: understanding how our marketing content is received so we can improve it, and recognising which markets and legal frameworks are in demand so we can steer further development accordingly.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in data-minimising audience measurement). Because Umami works without cookies and sets no cross-device identifiers, the prevailing legal view is that no consent under § 25 TDDDG is required.
Processing on our behalf: the Umami instance runs on Vercel (hosting) with a Neon PostgreSQL database (see section 9).
Retention: aggregated statistics indefinitely; IP hashes are rotated after 30 days.

5.2 Google Analytics 4 (only with your consent)

We additionally use Google Analytics 4 (GA4) – but only if you have expressly consented via our cookie banner. Without consent, no GA4 cookies are set and no data is transmitted to Google (implemented technically via Google Consent Mode v2, with “denied” as the default state).

We use the same GA4 property in the web application app.foodlex.app. The choice you make in the cookie banner applies across both domains – it is stored in a cookie on .foodlex.app and is honoured in the web application too. Without consent there is no GA4 measurement there either.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; where applicable with the involvement of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Purpose: statistical analysis of how foodlex.app and the web application app.foodlex.app are used, for audience measurement, for measuring sign-ups and purchases (conversion measurement, including for Google Ads) and to improve the service.
Data processed: among other things a truncated IP address, device and browser information, the pages requested, time spent, referrer, and a pseudonymous user/cookie identifier (cookies _ga, _ga_*).
Storage on your device: besides those cookies, once you have consented the web application stores markers in your browser’s local storage (keys foodlex.ev.*) so that the one-off events listed below are not counted twice. Without consent these markers are not set.

Events: in addition to page views we transmit individual actions as events. These are:

  • zur_app_click — a click on a link to the web application, with the label and the target address of the link
  • sign_up — a completed registration, with the method used (“email”)
  • first_recipe_created — the first recipe created, at most once per device
  • label_generated — the first label or product data sheet generated, at most once per device and type
  • purchase — a completed purchase, with a transaction number and, where applicable, amount, currency and the plan booked. No payment data is transmitted — that is handled solely by our payment service provider.

Legal basis: your consent pursuant to § 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.
Transfer to third countries: a transfer to the USA (Google LLC) is possible. Google is certified under the EU-US Data Privacy Framework; standard contractual clauses are in place in addition.
Retention: the retention of user-level data is limited to 14 months.
Withdrawal: you can withdraw your consent at any time with effect for the future – via the “Cookie settings” link in the footer. You can also use Google’s browser add-on to opt out of Google Analytics: tools.google.com/dlpage/gaoptout.
Processing on our behalf: a data processing agreement with Google is in place (Google Ads/Analytics Data Processing Terms).

6. Using the web application (app.foodlex.app) — account and content

The application itself, at app.foodlex.app, is built around a user account. The following data is processed:

6.1 Account sign-in (authentication)

  • Email address (for sign-in and magic-link authentication)
  • Password hashes (never stored in plain text)
  • Time of last sign-in, sign-in attempts

Legal basis: Article 6(1)(b) GDPR (performance of a contract, since an account is a prerequisite for using the app).
Processor: Supabase Inc. (see section 9), data centre eu-central-1 (Frankfurt, Germany).

6.2 User content

In the app you can create foods, recipes, weekly plans and the related master data. This content is stored in your account at Supabase (eu-central-1). At any time you can use the backup function in the app (header buttons ⤓ Export / ⤒ Import) to download your data as a JSON file or load it back in.

Legal basis: Article 6(1)(b) GDPR (performance of a contract).
Retention: until you delete your account, or until the service is discontinued.

6.3 AI analysis of food labels and recipes

If you upload a photo or PDF of a food label or a recipe through the app, its content is transmitted to the AI API of Anthropic, PBC (see section 9) for structured extraction. The AI extracts ingredients, nutrition values and allergens from the image. Anthropic processes the transmitted content in accordance with its own privacy policy and, by default, stores API inputs only briefly for abuse detection.

Legal basis: Article 6(1)(b) GDPR (performance of a contract — AI analysis is a core function of the app).
Please note: do not upload sensitive or copyright-protected content that you have no right to have processed by the Anthropic API.

6.4 Local storage in your browser

The app uses your browser’s localStorage to keep settings (for example the local-mode preference, sorting options, the view you last had open). No personal data is transmitted to our servers in the process. You can clear localStorage in your browser settings at any time.

Legal basis: § 25(2) no. 2 TDDDG (technically necessary for a service expressly requested by the user).

6.5 Payment processing for paid plans (Stripe)

For paid plans we process payments through the payment service provider Stripe (see section 9). When you take out a paid plan, the data required for payment processing is processed:

  • Name and email address
  • The plan chosen and the billing period
  • Payment details (e.g. card number) — you enter these directly on Stripe’s payment page; we ourselves neither receive nor store complete payment details
  • A Stripe customer and subscription identifier, which we associate with your account

Purpose: performing the paid contract, invoicing and fraud prevention.
Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (compliance with retention obligations under commercial and tax law).
Retention: payment and invoice data is retained in line with statutory retention periods (as a rule ten years).

6a. Videos (YouTube, two-click solution)

On individual pages – in blog articles, for instance – we embed videos from YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Nothing is loaded from YouTube when the page opens. At first all you see is a preview image that we serve from our own server. No connection to Google is made at that point.

Only when you actively click “Play video” is the player loaded. A connection to Google servers is then established; your IP address and information about the page you are on are transmitted there. If you are signed in to Google while the video plays, Google can associate the view with your account.

We use the youtube-nocookie.com variant (“privacy-enhanced mode”). According to Google, cookies are then only set once you start playback.

Legal basis: Article 6(1)(a) GDPR – your consent, which you give by deliberately clicking the play button. Without that click no transmission takes place.
Transfer to third countries: processing in the USA (Google LLC) is possible; Google is certified under the EU-US Data Privacy Framework.
Further information: Google’s privacy policy.

7. Contacting us by email

If you contact us by email, we process your email address and the content of your message in order to deal with your enquiry. Receipt, sending and storage go through Google Workspace (see section 9); kontakt@foodlex.app is an alias of our mailbox.

Legal basis: Article 6(1)(b) GDPR (pre-contractual measures / answering enquiries) or Article 6(1)(f) GDPR (legitimate interest).
Retention: until the correspondence is concluded, thereafter in line with statutory retention periods.

8. Cookies & consent

The marketing site foodlex.app sets no cookies of its own – audience measurement with Umami is cookieless. Google Analytics 4 (section 5.2), however, only sets cookies after you have consented via our cookie banner. Using the “Cookie settings” link in the footer you can change or withdraw your choice at any time; your decision is stored locally in your browser (in a cookie on .foodlex.app, so that it applies to the marketing site and the web application together).

The web application app.foodlex.app sets technically necessary cookies and storage mechanisms (a Supabase session cookie for sign-in, localStorage for app settings). In addition – only with your consent (see section 5.2) – Google Analytics 4 is used with the same cookies (_ga, _ga_*); without consent no GA4 cookies are set there either. The choice you made on foodlex.app applies across both domains.

9. Processors and transfers to third countries

We use the following service providers as processors pursuant to Article 28 GDPR:

Vercel Inc. — hosting

Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA
Processes: server logs (see section 4), static delivery of the marketing site and the app.
Third country: USA — data is transferred under the European Commission’s standard contractual clauses (SCCs) together with Vercel’s supplementary measures.
Privacy policy: vercel.com/legal/privacy-policy

Supabase Inc. — authentication and database

Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992
Processes: account data, user content (see section 6).
Data centre: eu-central-1 (Frankfurt am Main, Germany). Processing takes place within the EU.
Privacy policy: supabase.com/privacy

Anthropic, PBC — AI API

Anthropic, PBC, 548 Market St PMB 90375, San Francisco, CA 94104, USA
Processes: uploaded images/PDFs, for extracting ingredients and nutrition values (see section 6.3).
Third country: USA — data is transferred under the standard contractual clauses (SCCs).
Privacy policy: anthropic.com/legal/privacy

Neon, Inc. — database for audience measurement

Neon, Inc., 251 Little Falls Drive, Wilmington, DE 19808, USA
Processes: aggregated audience statistics from the Umami instance (see section 5).
Third country: USA (region iad1 / US East) — data is transferred under the standard contractual clauses (SCCs).
Privacy policy: neon.tech/privacy-policy

Google Ireland Limited — web analytics (Google Analytics 4)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; where applicable Google LLC, Mountain View, CA, USA.
Processes: usage data for statistical audience measurement — only after you have consented (see section 5.2).
Third country: USA — certified under the EU-US Data Privacy Framework, with standard contractual clauses (SCCs) in addition.
Privacy policy: policies.google.com/privacy

Stripe Payments Europe, Ltd. — payment processing

Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
Processes: payment and contract data for paid plans (see section 6.5).
Third country: a transfer to the USA (Stripe, Inc.) is possible; Stripe is certified under the EU-US Data Privacy Framework, with standard contractual clauses (SCCs) in addition.
Privacy policy: stripe.com/privacy

Google Ireland Limited — email mailbox (Google Workspace)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; where applicable Google LLC, Mountain View, CA, USA.
Processes: receipt, sending and storage of our business email, including messages addressed to kontakt@foodlex.app (see section 7).
Third country: USA — certified under the EU-US Data Privacy Framework, with standard contractual clauses (SCCs) in addition.
Privacy policy: policies.google.com/privacy

10. Your rights as a data subject

You have the following rights towards us:

  • Access (Article 15 GDPR) to the data stored about you
  • Rectification (Article 16 GDPR) of inaccurate data
  • Erasure (Article 17 GDPR), unless statutory retention obligations stand in the way
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR) — which you can exercise directly via the backup export function in the app
  • Objection (Article 21 GDPR) to processing based on legitimate interests
  • Withdrawal of consent given (Article 7(3) GDPR) with effect for the future

To exercise these rights, please write to kontakt@foodlex.app.

11. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or of the alleged infringement (Article 77 GDPR).

12. Security

All transmission is encrypted, over HTTPS / TLS 1.2 or higher. Passwords are stored exclusively as hashes using bcrypt/argon2 in Supabase; not even we can read them in plain text.

13. Changes to this notice

As Foodlex develops, this privacy notice may change. The current version is always available at foodlex.app/datenschutz, and this English translation at foodlex.app/en/privacy.

Last updated: