Last updated: 2026-09-29 — applies from app version 2.1
The data controller under GDPR is:
Marcel Söndenaa-Defourny
Muldentalstraße 100
04288 Leipzig (Liebertwolkwitz)
Germany
Email: support@vorinoapp.de
The iOS app "Vorino" (the "App") is a pantry-management and recipe-discovery tool. It lets users track their food inventory, find recipes, save favourites, and plan their week.
This policy describes what personal data we process when you use the App, why we process it, and on what legal basis. It applies both to the App itself and to the marketing pages hosted at vorinoapp.de.
The App asks for no identifying details such as your name, address, date of birth, or phone number, and no user account is required. Personal data can nevertheless arise wherever you actively send something yourself: the feedback form (3.7), a recipe submission or recipe wish (3.10), and — only if you switch it on — the anonymous usage statistics (3.11), because you could in principle write something about yourself into their free-text fields. Each section below states exactly what is transmitted and what is not.
| Aspect | Detail |
|---|---|
| What | Food items, recipe favourites, weekly meal plans, shopping lists, and app settings you create, plus the learned product assignments (which base ingredient and which pack price belong to an item you buy — the assignment is made on the device, either from your own correction or from the device’s own recognition) |
| Storage | On your Apple device, in SwiftData / Core Data. If you are signed in to iCloud, the same data is additionally synced between your own devices via Apple iCloud — see 3.9 |
| Classifying unknown ingredients (on-device AI) | The App assigns ingredient names from recipes and from your shopping list for which it has no fixed assignment to a product group — such as “vegetables” or “cheese” — in order to estimate a price for them and to sort them into a store section in the shopping list. For this it first uses a small model that is shipped as a fixed part of the App. The model does not learn from your input and does not store anything itself; the store section derived from it is stored like the other details of a shopping list entry. If it is not confident enough, Apple’s on-device language model (Apple Foundation Models) assigns the ingredient on devices with Apple Intelligence (iOS 26 or later). Both run entirely on the device; nothing is transmitted to us or to any other server in the process. The result of the language model (ingredient name and product group) is stored as a file in the App’s storage on the device (Application Support) and is not synced via iCloud. “Delete All Data” in the App settings clears it |
| Transmission to us | None. This data is not transmitted to us and is invisible to us. If it leaves your device at all, it goes only into your own private iCloud (3.9) — never onto our servers |
| Retention | Until you delete the data manually or uninstall the App |
| Legal basis | Art. 6(1)(b) GDPR — performance of the core service |
| Aspect | Detail |
|---|---|
| What | Photos of receipts, and barcodes that you capture. For “Pantry from a Photo” (a beta for Vorino Pro, only on devices with iOS or iPadOS 27 and Apple Intelligence turned on): photos, e.g. of a shelf or your fridge, that you take with the camera or pick in the system photo picker — without access to the rest of your photo library |
| Purpose | Product detection to populate your pantry automatically. “Pantry from a Photo” produces a list of suggestions; only what you tick is added to your pantry |
| Where processed | On your Apple device only. Text recognition (OCR) and barcode detection run on-device using Apple's Vision framework and Apple Foundation Models (from iOS 26) together with local databases. For “Pantry from a Photo”, Apple's text recognition (Vision) and Apple's on-device language model (Apple Foundation Models with image input, from iOS 27) analyse the photo |
| Transmission to us | None. Neither images nor product names, barcodes, nor any text derived from them are transmitted to or stored on a server |
| Retention | Captured images are processed only transiently on-device for recognition and are not transmitted to us. The recognised products are stored locally on your device, as described in 3.1. The App does not store photos for “Pantry from a Photo”, and does not save camera shots to your photo library |
| Records for Pantry from a Photo | The App stores on your device which version of the notice sheet you have seen and — if you confirmed before buying Pro that photo recognition is a beta — the date and version of each such confirmation (no identifier, at most 50 entries). Neither is transmitted to us or synced via iCloud. “Delete All Data” deliberately keeps these records; deleting the App removes them |
| Legal basis | Art. 6(1)(b) GDPR — performance of the core service |
Note on future versions: Later versions of the App may optionally offer server-side product classification. Any such processing would only take place after a corresponding update to this Privacy Policy and on the legal basis then required. The current version uses no such server processing — barcode lookup reads exclusively from the local database bundled with the App, and no barcode leaves your device.
| Aspect | Detail |
|---|---|
| What | Pro-version purchases and subscriptions, processed exclusively by Apple |
| Who | Apple Distribution International Ltd. is the sole contracting party for in-app purchases. We receive only aggregated, anonymised sales reports via App Store Connect |
| Direct access by us | We do not see your Apple ID or your payment details |
| Retention | Governed by Apple under its own privacy policy |
| Legal basis | Art. 6(1)(b) GDPR (contract performance via Apple) |
Apple's privacy policy: https://www.apple.com/legal/privacy/
| Aspect | Detail |
|---|---|
| When | Only in the free version, never for Pro subscribers |
| ATT permission denied / not requested | Only non-personalised ads are shown. AdMob does not use the advertising identifier (IDFA) for profiling |
| ATT permission granted | Personalised ads may be served. Google processes your device's advertising identifier (IDFA) to choose them |
| What Google processes in the course of this | Per Google's own disclosure in the AdMob SDK privacy manifest: device identifier (IDFA/IDFV), advertising data (which ads were shown and tapped), product interaction (app launches, ad interactions), coarse location — derived from the IP address, not from your device's GPS location, and regardless of whether you ever granted the store finder location access (see 3.12) — plus crash, performance and other diagnostic data for the ad component itself. Showing the consent prompt (Google UMP) adds the same categories on a smaller scale |
| Retention | Governed by Google under its own privacy policy |
| Legal basis | Personalised ads: Art. 6(1)(a) GDPR (explicit consent via the ATT prompt). Non-personalised ads: Art. 6(1)(f) GDPR (legitimate interest in funding the free version) |
Google AdMob privacy policy: https://policies.google.com/privacy
These are also the categories listed under “App Privacy” for Vorino on the App Store. They apply to the free version only: Vorino Pro shows no ads, and none of this data arises.
| Aspect | Detail |
|---|---|
| App-side server communication | The App transmits no pantry, product, or image data to our servers (see 3.2). It does, however, load recipe images from vorinoapp.de — the access logs this necessarily produces are described in 3.8 |
| Marketing website | When you visit the pages hosted at vorinoapp.de, standard access data (IP address, timestamp, requested URL, HTTP status code) may be recorded for technical reasons |
| Purpose | Delivery of the website, security, and error diagnostics |
| Retention | Only as long as necessary for the purposes stated |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest in the security and delivery of the website) |
| Aspect | Detail |
|---|---|
| What | Crash and performance data via Apple's built-in mechanism |
| Provider | Apple — you can disable this in iOS Settings under "Privacy & Security → Analytics & Improvements" |
| What we receive | Only aggregated, non-personal crash reports via App Store Connect |
| Third parties | None. We do not use Firebase Crashlytics, Sentry, or any comparable service |
| Legal basis | Art. 6(1)(f) GDPR |
| Aspect | Detail |
|---|---|
| What is processed | The message you enter in the feedback form at vorinoapp.de/feedback, the chosen category, and — only if you provide it voluntarily — your e-mail address for a reply. |
| Purpose | Handling your feedback, fixing bugs, and improving the app. |
| Storage | On our own server (located in Germany). The IP address is SHA-256 hashed before storage; the plain IP is not stored. |
| Third parties | None. The form submits only to our own server — no external form service (no Formspree, Google Forms, etc.). |
| Retention | Until your request is resolved, then deleted. You can request deletion at any time via support@vorinoapp.de. |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest in support and product improvement); if you voluntarily provide your e-mail, additionally Art. 6(1)(a) GDPR (consent). |
| Aspect | Detail |
|---|---|
| What is processed | The App loads recipe images from our own server at vorinoapp.de. Every such request unavoidably produces a server log entry containing the IP address of the requesting device, the time of the request, the file requested, and the user-agent string sent by the device |
| Purpose | Delivering the recipe images to the App, plus technical operation, operational security, and error diagnostics of the server |
| Who processes | Only us, on our own server located in Germany (see 7.). No image CDN and no other third party is involved |
| Retention | Access logs are rotated daily and automatically deleted after 14 days at the latest |
| Disclosure | None. The log data is not passed on to third parties, not sold, and not used for advertising or audience measurement |
| No profiling | The log data is not combined with other data, not linked into usage profiles, and not used to recognise individual users. In particular, we do not analyse which recipes any given person views |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest in the technical operation and in delivering the images) |
| Aspect | Detail |
|---|---|
| What is processed | The same data as in 3.1: pantry, favourites, weekly plans, shopping lists, shopping presets, restock rules, the cooking history, the learned taste preferences and purchase events (the basis for restock suggestions), and the learned product assignments |
| How | Through Apple's SwiftData/CloudKit sync into the private iCloud database of your own Apple account. Only the private database is used — never a public or a shared CloudKit database |
| When active | Only when an iCloud account is signed in on the device. Without iCloud the App simply keeps working locally, with no loss of data |
| Access by us | None. We have no access to your private iCloud and cannot see this data. It is not stored on our servers |
| Record of the Terms of Use | Whether and when you accepted the Terms of Use or chose “Later” (date and version, no identifier) is stored by the App on the device and — if an iCloud account is signed in — also in the iCloud key-value storage of your Apple account, so that not every one of your devices asks again. We have no access to this either. "Delete all data" deliberately keeps this record |
| How to turn it off | In iOS Settings under "Apple Account → iCloud → Apps using iCloud". Your data then stays local on the device |
| Who processes | Apple, as the operator of iCloud; Apple's terms and storage locations apply (see 5.) |
| Legal basis | Art. 6(1)(b) GDPR (contract performance — cross-device sync as part of the core service), to the extent you have iCloud enabled |
Inside the App you can submit a recipe of your own or wish for a dish. Both happen only when you deliberately send them — nothing is sent automatically. There is no community and no feed: submitted content is not visible to other users; it goes to us alone, for editorial review.
| Aspect | Detail |
|---|---|
| What is transmitted | For a submission: title, short description, ingredient list, preparation steps, plus the optional fields servings, preparation and cooking time, difficulty, category, cuisine, and diet type. For a wish: the wish text (the name of the dish) and an optional note. In both cases the app version is included. No images are transmitted |
| Device token | Every submission carries a randomly generated device token. It is created locally as a random value the first time you send something, and stored locally. It is not derived from your Apple ID, the advertising identifier (IDFA/IDFV), any hardware identifier, the device name, or a phone number, and it does not allow any conclusion about a person. Purpose: detecting duplicate submissions and limiting how often submissions can be sent (abuse prevention). It is sent nowhere else — in particular, it is never included in the usage statistics (3.11) |
| IP address | The IP address is truncated and hashed with SHA-256 together with a secret salt before storage; the plain IP is not stored. The hash serves rate limiting and abuse prevention only |
| Free-text warning | These fields are free text. Please do not enter personal data there — the App already rejects e-mail addresses and links. Anything else you type is transmitted along with the submission |
| Where stored | On our own server at Hetzner Online GmbH, located in Germany (see 7.). No disclosure to third parties |
| Retention | Until editorial review. After that the content is either adopted as editorial content of the App without the device token, or deleted |
| Legal basis | Art. 6(1)(a) GDPR (consent — you actively send it) for the content and the device token; Art. 6(1)(f) GDPR (legitimate interest in abuse prevention) for the hashed IP value |
| Withdrawal and erasure | You may withdraw your consent at any time with effect for the future and request erasure: an informal e-mail to support@vorinoapp.de is enough. So that we can find the submission, please state the title or wish text and the approximate date. The device token on your device also disappears when you choose "Delete all data" in the App's settings or uninstall the App |
The App can collect anonymous usage statistics. This is off by default and only starts once you explicitly switch it on in the App's settings (opt-in). Its sole purpose is product improvement — which searches come back empty, which features anyone actually uses.
| Aspect | Detail |
|---|---|
| What is transmitted | One per-day event record per action, containing: the calendar day (UTC), the search term after automatic filtering, the search mode and the number of results, recipe identifiers from our own recipe database, names of used features drawn from a fixed list, the number of people, weeks and a budget bracket for a weekly plan, the origin of an opened recipe (catalogue or your own), the app version and build, the device language code (without region), and a coarse device class ("iphone"/"ipad") |
| What is expressly not transmitted | No device token and no other field that could link two transmissions from the same device. No clock time — the time granularity is never finer than the calendar day. No IDFA/IDFV, no installation identifier, no account, no location, no device model, no exact budget amount, no pantry data, no submitted recipe texts, and no wish texts. Events are shuffled before sending, so no sequence of use can be reconstructed |
| Filtering of search terms | Search text is lower-cased, whitespace-normalised, and truncated to 60 characters. If a text shows signs of personal data (an e-mail address, a web address, or a longer run of digits), the text is discarded entirely — only the event itself is counted |
| Where stored | On our own server at Hetzner Online GmbH, located in Germany (see 7.). No disclosure to third parties, no advertising or audience measurement |
| Retention on the device | At most 30 days and at most 500 events; sent in batches, at most once per calendar day |
| Turning it off and erasure | If you switch the statistics back off in the App's settings, the queue still waiting on your device is deleted immediately and nothing further is collected. For records already transmitted, contact support@vorinoapp.de — but because they carry no identifier, they cannot technically be traced back to you |
| Legal basis | Art. 6(1)(a) GDPR (consent, given by switching the toggle on), withdrawable at any time by switching it off |
| Aspect | Detail |
|---|---|
| What is processed | Your approximate device location, in order to find supermarkets nearby |
| When | Only when you tap the store finder. The system prompt appears at that moment, never at app launch. Only the "While Using the App" permission is requested — no background location. Accuracy is deliberately limited to roughly 100 metres |
| Transmission to us | None. We neither store your location nor transmit it to our servers. It is used only transiently, in the App's memory. It is not passed to Google either — the “coarse location” named in 3.4 is a different thing: Google derives it from the IP address, and does so even if you never granted the store finder location access |
| Third parties | The proximity search runs through Apple Maps (MapKit). Apple therefore receives the search term and the map region. In that respect Apple is an independent controller; Apple's privacy policy applies: https://www.apple.com/legal/privacy/ |
| Flyer links | The linked online flyers of the retail chains live on those companies' own websites. Tapping such a link takes you out of Vorino, and the respective provider's privacy terms then apply |
| Legal basis | Art. 6(1)(a) GDPR (consent via the iOS location prompt), withdrawable at any time in iOS Settings |
| Aspect | Detail |
|---|---|
| What is processed | The open items on your shopping list are written as entries into a list of the Apple Reminders app on your device that you choose yourself — an existing list or a new list "Shopping List (Vorino)" |
| When | Only when you explicitly ask for it — the system permission prompt appears when you tap "Export to Reminders", never at app launch. It is a one-off export, not an ongoing sync |
| Read access | Apple offers no write-only permission for Reminders. To let you choose, Vorino shows the name, color and account of your Reminders lists (no entries). Vorino reads entries only from the list you chose, only the open ones and only to avoid duplicate entries — on your device. Entries of other lists are not read |
| Stored | Only the identifier of the chosen list, in the app's settings on your device, so the next export goes there without asking. You can switch it via "Change Reminders list…" in the shopping list menu; items already sent stay in the previous list |
| Transmission to us | None. The export ends up in the chosen list — on your device or in the account it belongs to (e.g. your iCloud). If you choose a list shared with others in the Reminders app, its members see the entries; that is Apple's sharing, not Vorino. Nothing reaches us |
| Legal basis | Art. 6(1)(a) GDPR (consent via the iOS permission prompt), withdrawable at any time in iOS Settings |
As a data subject under GDPR, you have the following rights:
Please send any request to: support@vorinoapp.de
Because the App works locally and uses no account, we may not be able to associate a request with a specific person. You can erase all locally stored data at any time by uninstalling the App. "Delete all data" in the App's settings erases your content (such as pantry, favorites, meal plans, shopping list, preferences and what the App has learned) but deliberately keeps the records under 3.2 (Pantry from a Photo) and 3.9 (Terms of Use). For the few things that do reach us: we delete feedback entries (3.7) and recipe submissions or wishes (3.10) on informal request to support@vorinoapp.de — please quote the content and the approximate date so we can find it. Records from the anonymous usage statistics (3.11) deliberately carry no identifier and therefore cannot be attributed to anyone after the fact; they can only be stopped going forward, by switching the toggle off.
The following transfers to third countries may occur:
| Recipient | Country | Safeguard |
|---|---|---|
| Apple Inc. (StoreKit, App Store, crash reports, iCloud sync per 3.9, map search per 3.12) | USA / EEA | EU-US Data Privacy Framework, Apple is certified. Apple Distribution International Ltd. is the European contracting entity |
| Google LLC (AdMob, free tier only) | USA | EU-US Data Privacy Framework, Google is certified. Standard Contractual Clauses under Art. 46 GDPR additionally apply |
No pantry, product, or image data is transmitted to our own servers — product and receipt recognition runs entirely on-device (see 3.2). What does reach our servers is limited to the requests for recipe images with the access logs they generate under 3.8, the content you actively send under 3.7 and 3.10, plus — only after your opt-in — the anonymous usage statistics under 3.11. That server infrastructure is operated in Germany by Hetzner Online GmbH (Nuremberg data centre); no third-country transfer occurs in this respect.
The App itself uses no web cookies. Tracking occurs only via the AdMob advertising network, and only when:
The marketing website at vorinoapp.de does not set tracking or analytics cookies. Strictly necessary cookies (for instance, to remember your language preference) may be used.
The anonymous usage statistics described in 3.11 are not tracking in this sense: they deliberately contain no field that could link two transmissions from the same device, they set no cookie and no identifier, and they produce no usage profile. We continue to use no Firebase, no Sentry, and no third-party analytics service.
The infrastructure (rented server) for the App and the marketing website is supplied by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner is engaged as a data processor under Art. 28 GDPR; a corresponding data-processing agreement is in place. The server is located exclusively in Germany (Nuremberg data centre) — no transfer to a third country takes place in this context. The server processes only the data named in this policy, namely the access logs generated when recipe images are loaded (see 3.8), the entries from the feedback form (see 3.7), recipe submissions and recipe wishes (see 3.10), and — only after opt-in — the anonymous usage statistics (see 3.11). Beyond this, no further external data processors are used for the processing of user data; pantry, product, and image data is still not transmitted to the server (see 3.2).
Apple and Google act as independent (or joint) controllers under their own platform functions, not as classic processors.
We use appropriate technical and organisational measures to protect your data, including:
Despite these measures, absolute security of data transmission over the Internet cannot be guaranteed.
Last updated: 2026-09-29 — applies from app version 2.1
We may update this Privacy Policy to reflect changes in the law or our services. We will inform you about material changes in the App, at the latest when they take effect. The current version is always available at vorinoapp.de/privacy.