Privacy Policy

As of: July 11, 2026

Scope: Mobile apps (iOS & Android), web application (PWA), and cloud synchronization services of the application Cheflow (recipe manager & cooking companion).


1. Controller (Data Controller under Data Protection Law)

The controller responsible for data processing within the meaning of the European General Data Protection Regulation (GDPR) and other national data protection laws of the Member States is:

Oliver Müller

Sudetenstrasse 43

35625 Hüttenberg

Germany

Email: support@cheflow.de

Website: https://www.cheflow.de


2. Basic Principles of Our Data Processing: Local-First & Privacy by Design

Cheflow was developed according to the architectural principle of "Local-First & Offline-First":

  • Local Data Storage as Standard: Your cookbooks, recipes, ingredients, shopping lists, and weekly plans are primarily stored directly on your terminal device in a local database (IndexedDB on the web, SQLite on mobile devices). Without activated cloud synchronization, your content data remains locally on your device by default and is only transmitted selectively to external servers when you actively use an online function such as the AI cooking assistant or OS voice recognition (see Sections 3.2 and 3.3).
  • Legal Specification under the TDDDG (Access to Terminal Devices): The storage of information on your terminal device and access to data stored there (in particular the initialization and operation of the local IndexedDB and SQLite databases) are based on Section 25 (2) No. 2 TDDDG (Telecommunications Digital Services Data Protection Act, implementing Art. 5 (3) ePrivacy Directive). Local storage is strictly necessary to provide you with the cooking and recipe assistant explicitly requested by you based on local data retention. Since the application would not function technically without this local data storage, no prior consent via a cookie or consent banner is required for this.
  • Data Minimization (Art. 5 (1) (c) GDPR): We only collect data that is strictly necessary for providing our features.
  • No Mandatory Registration with Real Names: You do not need an email address or password to use Cheflow fully or with cloud synchronization.

3. Collection and Processing of Personal Data by Feature

3.1 Anonymous Device Pairing & Cloud Synchronization (user_uuid)

* Processed Data: Unique, randomly generated identifiers (user_uuid, device_uuid), device name (e.g., "Max's iPhone" or "Unknown Device"), last activity timestamp (last_seen), and your synchronized content (cookbooks, recipes, steps, shopping lists, meal plans).

* Purpose: Enabling real-time cross-device cloud synchronization, resolving data conflicts in the synchronization menu, and pairing new devices via QR code or pairing code.

* Legal Basis: Performance of the user contract pursuant to Art. 6 (1) (b) GDPR.

* Data Protection Notice / Pseudonymization: Although you do not provide an email address, a unique UUID is considered a technical pseudonym under the GDPR. Communication between your devices and our servers is encrypted (HTTPS/TLS). Our cloud data store (primarily JSON files in Azure Blob Storage as well as secondary database services) stores content linked to your user_uuid.

3.2 AI Cooking Assistant, Recipe Standardization & Text Generation (by Models)

* Processed Data: Free text entered by you (recipe instructions, preparation descriptions, ingredient lists) as well as voice-dictated instructions in the AI input masks (in the AI recipe editor, during automatic standardization, step conversion, and recipe tip generation).

* Purpose: AI-supported conversion of unstructured text into structured cooking steps, generation of cooking tips, detection of timers, and dictation support.

* Our AI Privacy Promise (Zero Training Guarantee): Your cooking ideas and private notes belong exclusively to you. Cheflow uses cutting-edge AI interfaces (paid Enterprise APIs / Tier 1) where it is strictly contractually prohibited for your recipes, voice dictations, or private data to ever be used to train or further develop AI models. What you dictate in your kitchen stays in your kitchen.

* Rate Limiting & IP Protection: To prevent system abuse, we check request limits. Your IP address is anonymized on our server using a one-way hashing function (SHA-256(IP + Salt)); no plaintext-readable IP addresses are stored in our AI usage logs.

* Legal Basis: Performance of a contract (Art. 6 (1) (b) GDPR).

* Model-Specific Data Processing & Retention Policies:

Because we offer professional AI interfaces (Enterprise Tier) via our proxy, strict zero-retention requirements apply according to the model used by the app:

| AI Model / Provider | Processor & Seat | Data Retention | AI Model Training |

| :--- | :--- | :--- | :--- |

| Google Gemma 4 31B IT *(Standard model for recipe structuring & step conversion)* | Google LLC / Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland | No permanent storage of API inputs (Zero Retention according to Google Cloud Paid API Terms). | No (Guaranteed no AI training): Paid Enterprise API — your data is not used for training. |

| Google Gemma 4 26B A4B IT *(Compact model for lighter tasks)* | Google LLC / Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland | No permanent storage (Zero Retention, identical terms). | No — identical contractual guarantees as above. |

| Google Gemini 3.1 Flash Lite *(Fast model for short generations & tips)* | Google LLC / Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland | No permanent storage (Zero Retention, identical terms). | No — identical contractual guarantees as above. |

All three models are operated via the paid Google AI Studio Enterprise API (Tier 1). Identical zero-retention and zero-training guarantees apply to all models.

3.3 Voice Control & Speech Recognition (Voice Assistant & Dictation)

* Processed Data: Audio signals from your microphone during the active use of cooking voice dictation in the text field or the hands-free voice assistant in cooking mode.

* How it works:

* On-Device / OS Transcription (STT - Speech-to-Text): The conversion of your speech into text is performed via the integrated speech recognition services of your operating system (Apple iOS Speech Recognition, Google Android Speech Services, or the Web Speech API of your browser). Depending on your system settings, audio data may be transmitted to Apple Inc. or Google LLC for transcription. The data protection provisions of the respective operating system providers apply.

* Speech Output (TTS - Text-to-Speech): Reading out recipe steps takes place purely locally on your device via the system voice output.

* Consent & Withdrawal: Before the first voice usage, your explicit consent is obtained via an in-app dialog. You can withdraw this consent at any time by revoking the microphone permission in your device's system settings. Revocation is just as simple as granting consent (Art. 7 (3) GDPR).

* Legal Basis: Your explicit consent by granting microphone permission (Art. 6 (1) (a) GDPR).

3.4 Camera Access (QR Code Scanning)

* Processed Data: Video image data from the device camera when scanning a pairing QR code.

* Purpose: Fast and secure pairing of terminal devices with your existing Cheflow instance.

* Legal Basis: Consent by granting camera permission (Art. 6 (1) (a) GDPR).

* Notice: Image data is analyzed in real time exclusively locally on the device to read the pairing code. No photos or video recordings are saved or transmitted to our servers.

3.5 Local Push Notifications & Cooking Reminders

* Processed Data: Reminder times set by you for planned meals (in the meal planner) and expiring cooking timers (while cooking).

* Purpose: Notification on your lock screen for upcoming meals or expired timers.

* Notice: All reminders are scheduled and executed locally on your device. No push tokens or calendar data are transmitted to external push servers (APNs/FCM).

3.6 Subscriptions, Paywall & In-App Purchases

* Processed Data: Anonymous transaction receipts (purchase tokens), product identifiers (e.g., monthly package for AI extensions or lifetime cloud synchronization), store allocations (Apple App Store, Google Play Store, Stripe), subscription terms, and optional cancellation feedback (predefined selection reasons and optional free-text comment upon subscription cancellation).

* Purpose: Activation and management of premium features (Sync Pass, AI Quota) and displaying your active subscriptions in the app.

* Payment Processing & Independent Responsibility of Store Providers: We do not use any external subscription middleware (such as RevenueCat). We never collect or store your sensitive payment data (credit card numbers, bank details). Financial transaction processing is handled entirely by our payment partners, who act as independent controllers under their own respective privacy policies:

* Apple Distribution International Ltd. (Ireland) for iOS App Store purchases.

* Google Commerce Limited (Ireland) for Android Google Play Store purchases.

* Stripe Payments Europe, Ltd. (Ireland) for web payments.

* Cancellation Feedback: Upon cancellation, you can optionally select a predefined reason and leave a free comment. The sole purpose is to improve our product. Legal basis: legitimate interest in product improvement (Art. 6 (1) (f) GDPR). Cancellation feedback is automatically deleted after 12 months.

* Legal Basis: Performance of a contract for activation based on anonymous transaction receipts (Art. 6 (1) (b) GDPR), legitimate interest for cancellation feedback (Art. 6 (1) (f) GDPR), as well as statutory retention obligations for accounting data (Art. 6 (1) (c) GDPR).

3.7 Server Diagnostics & Error Tracking (Azure Application Insights)

* Processed Data: Technical metrics, crash reports (stack traces), HTTP status codes, HTTP request paths (excluding query parameters with user content), outgoing API calls (target host and status code), server console outputs, as well as CPU and memory performance data.

* Purpose: Ensuring the stability, security, and performance of our cloud services and data interfaces.

* Provider: Microsoft Azure / Application Insights (Microsoft Ireland Operations Limited, One Microsoft Place, Dublin 18, Ireland).

* Data Protection Notice: No third-party tracking SDKs are integrated into the mobile apps (iOS & Android). At server level, we process technical logs for troubleshooting purposes based on our legitimate interest (Art. 6 (1) (f) GDPR) in secure and error-free operation. Balancing of interests: Our legitimate interest in ensuring trouble-free operation outweighs the interest of users, as we process exclusively anonymized technical data without personal identification (IP address is set to 0.0.0.0, user agent is overwritten to "Anonymous"). Tracing back to individual users is technically impossible.


4. Overview of App Permissions (iOS & Android)

To use the features of the app, Cheflow requests the following system permissions:

| Permission | Purpose | Mandatory / Optional |

| :--- | :--- | :--- |

| Camera (CAMERA) | Scanning the QR code for device pairing in the synchronization menu. | Optional (only required for QR sync) |

| Microphone (RECORD_AUDIO) | Hands-free voice input and dictation in the cooking assistant. | Optional (only required for voice control) |

| Speech Recognition (SPEECH_RECOGNITION) | Transcribing spoken commands and instructions into text. | Optional (only required for voice control) |

| Notifications (NOTIFICATIONS) | Local reminders for planned meals and expired cooking timers. | Optional (only required for reminders) |

| Wake Lock (WAKE_LOCK / KEEP_AWAKE) | Prevents the screen from turning off while cooking in interactive cooking mode. | Automatically active in cooking mode |

You can enable or revoke each of these permissions at any time in your smartphone's system settings.


5. App Store & Google Play Store Required Disclosures (Data Safety & Nutrition Labels)

5.1 Apple App Store – Privacy Nutrition Label

For submission to the Apple App Store, Cheflow declares the following data categories:

* Data Linked to You:

* User ID (User ID / UUID): Used for app functionality (cloud synchronization) and account management.

* Purchases (Purchases): Used for account management and providing subscriptions.

* User Content (User Content): Recipe data, cookbooks, and shopping lists that you synchronize or process via AI assistant (Used for app functionality).

* Audio Data (Audio Data): Voice recordings during active use of cooking voice dictation via OS speech recognition (Used for app functionality).

* Data Not Linked to You:

* Diagnostics (Diagnostics / Crash Data): Used for app performance and troubleshooting.

* No Tracking (No Tracking): Cheflow does not link app data with third-party data for advertising purposes and does not share data with data brokers.

5.2 Google Play Store – Data Safety Section

For the Google Play Store Data Safety section, the following declarations apply:

* Is data shared? Yes – Entered recipe texts when using the AI feature are shared with the Google Gemini API for generation; audio data during active speech recognition is shared with OS providers (Google/Apple); payment receipts with Google Play.

* Is data collected? Yes – UUID, app activities (sync timestamp), user content (recipes/cookbooks with cloud sync enabled or AI usage), and purchase history.

* Security Practices:

* All data in transit is encrypted using SSL/TLS (HTTPS).

* Users can initiate full deletion of their cloud data and local account directly within the app (via the "Delete Cloud Data" option in app settings).


6. Data Sharing with Third Parties & Processors

We never sell or rent your data to third parties. Data is shared exclusively with strictly audited technical service providers within the scope of data processing agreements (Art. 28 GDPR):

  • Microsoft Corporation / Azure: Server hosting, cloud storage (Azure Blob Storage for recipe JSONs as well as secondary database services), and system diagnostics. Server location: EU (West/North Europe).
  • Google LLC / Google Ireland Limited (Google AI Studio & Cloud): Provision of artificial intelligence (Gemini API) for recipe standardization, step conversion, and tip generation as well as OS speech recognition services (Android).
  • Apple Inc. / Distribution International Ltd.: Operating system speech recognition services (Apple dictation feature under iOS) as well as App Store payment processing.
  • Stripe Payments Europe, Ltd.: Payment service provider for processing web subscriptions.

6.1 International Data Transfers (USA) & Legal Safeguards (Art. 44 et seq. GDPR)

Even though our data processing takes place primarily on servers located within the European Union (e.g., in Ireland or the Netherlands), the parent companies of our infrastructure providers (Microsoft Corporation, Google LLC, Apple Inc., Stripe Inc.) are headquartered in the United States. A theoretical or administrative data transfer to a third country (USA) cannot therefore be entirely excluded.

To guarantee the adequate level of protection required under the GDPR in such cases, we base all third-country transfers on the following legal mechanisms:

* EU-US Data Privacy Framework (DPF): The US parent companies of our service providers (Microsoft Corporation, Google LLC, Apple Inc., and Stripe Inc.) are actively certified under the EU-US Data Privacy Framework (Adequacy Decision of the EU Commission pursuant to Art. 45 GDPR of July 10, 2023). This guarantees that data transfers to these companies in the US meet European data protection standards.

* Standard Contractual Clauses (SCCs): Alternatively and additionally, we or our European contractual partners have entered into the Standard Contractual Clauses issued by the European Commission pursuant to Art. 46 (2) (c) GDPR with the respective sub-processors, supplemented by technical and organizational safeguards (such as strict encryption under the zero-knowledge and zero-retention principles).


7. Storage Duration and Deletion (Danger Zone)

* Local Data: Your locally stored content remains on your device until you manually delete it, uninstall the app, or execute the "Delete Local Data" option in settings.

* Cloud Data (user_uuid & Recipes): If you use cloud synchronization, your synchronized content remains stored on our servers for as long as your instance is active.

* Right to Deletion Directly in the App: You can choose the "Delete Cloud Data" option under "Danger Zone" in settings at any time. This permanently deletes all recipes, cookbooks, meal plans, and usage logs linked to your user_uuid from our servers.

* AI Usage Data & IP Hashes: The SHA-256 hashes of your IP address generated for abuse detection are created using a daily rotating salt. The salt is overwritten daily; historical IP hashes in usage logs are automatically deleted after 30 days (Azure Application Insights Retention Policy). LLM request tickets in Blob Storage are deleted immediately after processing; orphaned tickets after 1 day at the latest (automatic lifecycle policy).

* Cancellation Feedback: Automatically deleted after 12 months.

* Statutory Retention Periods: Receipts for in-app subscriptions purchased must be retained in anonymized form for tax and commercial law reasons for up to 10 years (pursuant to Art. 6 (1) (c) GDPR).


8. Your Rights Under the GDPR (Data Subject Rights)

Under the European General Data Protection Regulation (GDPR), you are entitled to the following rights:

* Right of Access (Art. 15 GDPR): You can request information regarding the data we process about you. Since our app uses anonymous UUIDs, you can view your unique account ID (user_uuid) in settings and copy it to the clipboard to assert access claims.

* Right to Rectification (Art. 16 GDPR): You can edit incorrect content directly within the app at any time.

* Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You can remove your data locally and from our servers via the deletion functions in the app.

* Right to Restriction of Processing (Art. 18 GDPR) & Right to Data Portability (Art. 20 GDPR): You can export your entire cookbooks and recipes at any time via the integrated data export feature as a machine-readable backup file.

* Right to Object (Art. 21 GDPR): You can object to processing based on legitimate interests.

* Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a competent data protection supervisory authority.


9. Protection of Minors

Cheflow is a general recipe management application and is not specifically directed at children under the age of 16. We do not knowingly collect personal data from minors. If parents discover that their child is using our cloud services without consent, they can have the data deleted via the app at any time.


10. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy so that it always meets current legal requirements or to reflect new features (e.g., additional AI services or smart home integrations). The current version is accessible at any time within the app under settings and on our website.