v
Vorino
Home Terms Support
Back to home

Privacy Policy — Vorino App

Last updated: 2026-09-29 — applies from app version 2.1


1. Data Controller

The data controller under GDPR is:

Marcel Söndenaa-Defourny
Muldentalstraße 100
04288 Leipzig (Liebertwolkwitz)
Germany

Email: support@vorinoapp.de


2. Scope

The iOS app "Vorino" (the "App") is a pantry-management and recipe-discovery tool. It lets users track their food inventory, find recipes, save favourites, and plan their week.

This policy describes what personal data we process when you use the App, why we process it, and on what legal basis. It applies both to the App itself and to the marketing pages hosted at vorinoapp.de.

The App asks for no identifying details such as your name, address, date of birth, or phone number, and no user account is required. Personal data can nevertheless arise wherever you actively send something yourself: the feedback form (3.7), a recipe submission or recipe wish (3.10), and — only if you switch it on — the anonymous usage statistics (3.11), because you could in principle write something about yourself into their free-text fields. Each section below states exactly what is transmitted and what is not.


3. Categories of Data We Process

3.1 Local Data (Pantry, Favourites, Weekly Plans)

Aspect Detail
What Food items, recipe favourites, weekly meal plans, shopping lists, and app settings you create, plus the learned product assignments (which base ingredient and which pack price belong to an item you buy — the assignment is made on the device, either from your own correction or from the device’s own recognition)
Storage On your Apple device, in SwiftData / Core Data. If you are signed in to iCloud, the same data is additionally synced between your own devices via Apple iCloud — see 3.9
Classifying unknown ingredients (on-device AI) The App assigns ingredient names from recipes and from your shopping list for which it has no fixed assignment to a product group — such as “vegetables” or “cheese” — in order to estimate a price for them and to sort them into a store section in the shopping list. For this it first uses a small model that is shipped as a fixed part of the App. The model does not learn from your input and does not store anything itself; the store section derived from it is stored like the other details of a shopping list entry. If it is not confident enough, Apple’s on-device language model (Apple Foundation Models) assigns the ingredient on devices with Apple Intelligence (iOS 26 or later). Both run entirely on the device; nothing is transmitted to us or to any other server in the process. The result of the language model (ingredient name and product group) is stored as a file in the App’s storage on the device (Application Support) and is not synced via iCloud. “Delete All Data” in the App settings clears it
Transmission to us None. This data is not transmitted to us and is invisible to us. If it leaves your device at all, it goes only into your own private iCloud (3.9) — never onto our servers
Retention Until you delete the data manually or uninstall the App
Legal basis Art. 6(1)(b) GDPR — performance of the core service

3.2 Receipt Scanning, Barcodes and Pantry from a Photo (entirely on-device)

Aspect Detail
What Photos of receipts, and barcodes that you capture. For “Pantry from a Photo” (a beta for Vorino Pro, only on devices with iOS or iPadOS 27 and Apple Intelligence turned on): photos, e.g. of a shelf or your fridge, that you take with the camera or pick in the system photo picker — without access to the rest of your photo library
Purpose Product detection to populate your pantry automatically. “Pantry from a Photo” produces a list of suggestions; only what you tick is added to your pantry
Where processed On your Apple device only. Text recognition (OCR) and barcode detection run on-device using Apple's Vision framework and Apple Foundation Models (from iOS 26) together with local databases. For “Pantry from a Photo”, Apple's text recognition (Vision) and Apple's on-device language model (Apple Foundation Models with image input, from iOS 27) analyse the photo
Transmission to us None. Neither images nor product names, barcodes, nor any text derived from them are transmitted to or stored on a server
Retention Captured images are processed only transiently on-device for recognition and are not transmitted to us. The recognised products are stored locally on your device, as described in 3.1. The App does not store photos for “Pantry from a Photo”, and does not save camera shots to your photo library
Records for Pantry from a Photo The App stores on your device which version of the notice sheet you have seen and — if you confirmed before buying Pro that photo recognition is a beta — the date and version of each such confirmation (no identifier, at most 50 entries). Neither is transmitted to us or synced via iCloud. “Delete All Data” deliberately keeps these records; deleting the App removes them
Legal basis Art. 6(1)(b) GDPR — performance of the core service

Note on future versions: Later versions of the App may optionally offer server-side product classification. Any such processing would only take place after a corresponding update to this Privacy Policy and on the legal basis then required. The current version uses no such server processing — barcode lookup reads exclusively from the local database bundled with the App, and no barcode leaves your device.

3.3 Apple StoreKit — Transaction Data

Aspect Detail
What Pro-version purchases and subscriptions, processed exclusively by Apple
Who Apple Distribution International Ltd. is the sole contracting party for in-app purchases. We receive only aggregated, anonymised sales reports via App Store Connect
Direct access by us We do not see your Apple ID or your payment details
Retention Governed by Apple under its own privacy policy
Legal basis Art. 6(1)(b) GDPR (contract performance via Apple)

Apple's privacy policy: https://www.apple.com/legal/privacy/

3.4 Google AdMob (Free Tier Only)

Aspect Detail
When Only in the free version, never for Pro subscribers
ATT permission denied / not requested Only non-personalised ads are shown. AdMob does not use the advertising identifier (IDFA) for profiling
ATT permission granted Personalised ads may be served. Google processes your device's advertising identifier (IDFA) to choose them
What Google processes in the course of this Per Google's own disclosure in the AdMob SDK privacy manifest: device identifier (IDFA/IDFV), advertising data (which ads were shown and tapped), product interaction (app launches, ad interactions), coarse location — derived from the IP address, not from your device's GPS location, and regardless of whether you ever granted the store finder location access (see 3.12) — plus crash, performance and other diagnostic data for the ad component itself. Showing the consent prompt (Google UMP) adds the same categories on a smaller scale
Retention Governed by Google under its own privacy policy
Legal basis Personalised ads: Art. 6(1)(a) GDPR (explicit consent via the ATT prompt). Non-personalised ads: Art. 6(1)(f) GDPR (legitimate interest in funding the free version)

Google AdMob privacy policy: https://policies.google.com/privacy

These are also the categories listed under “App Privacy” for Vorino on the App Store. They apply to the free version only: Vorino Pro shows no ads, and none of this data arises.

3.5 Server Access Logs

Aspect Detail
App-side server communication The App transmits no pantry, product, or image data to our servers (see 3.2). It does, however, load recipe images from vorinoapp.de — the access logs this necessarily produces are described in 3.8
Marketing website When you visit the pages hosted at vorinoapp.de, standard access data (IP address, timestamp, requested URL, HTTP status code) may be recorded for technical reasons
Purpose Delivery of the website, security, and error diagnostics
Retention Only as long as necessary for the purposes stated
Legal basis Art. 6(1)(f) GDPR (legitimate interest in the security and delivery of the website)

3.6 Apple Crash Reports

Aspect Detail
What Crash and performance data via Apple's built-in mechanism
Provider Apple — you can disable this in iOS Settings under "Privacy & Security → Analytics & Improvements"
What we receive Only aggregated, non-personal crash reports via App Store Connect
Third parties None. We do not use Firebase Crashlytics, Sentry, or any comparable service
Legal basis Art. 6(1)(f) GDPR

3.7 Feedback Form (Website)

AspectDetail
What is processedThe message you enter in the feedback form at vorinoapp.de/feedback, the chosen category, and — only if you provide it voluntarily — your e-mail address for a reply.
PurposeHandling your feedback, fixing bugs, and improving the app.
StorageOn our own server (located in Germany). The IP address is SHA-256 hashed before storage; the plain IP is not stored.
Third partiesNone. The form submits only to our own server — no external form service (no Formspree, Google Forms, etc.).
RetentionUntil your request is resolved, then deleted. You can request deletion at any time via support@vorinoapp.de.
Legal basisArt. 6(1)(f) GDPR (legitimate interest in support and product improvement); if you voluntarily provide your e-mail, additionally Art. 6(1)(a) GDPR (consent).

3.8 Recipe Images Served from Our Server

Aspect Detail
What is processed The App loads recipe images from our own server at vorinoapp.de. Every such request unavoidably produces a server log entry containing the IP address of the requesting device, the time of the request, the file requested, and the user-agent string sent by the device
Purpose Delivering the recipe images to the App, plus technical operation, operational security, and error diagnostics of the server
Who processes Only us, on our own server located in Germany (see 7.). No image CDN and no other third party is involved
Retention Access logs are rotated daily and automatically deleted after 14 days at the latest
Disclosure None. The log data is not passed on to third parties, not sold, and not used for advertising or audience measurement
No profiling The log data is not combined with other data, not linked into usage profiles, and not used to recognise individual users. In particular, we do not analyse which recipes any given person views
Legal basis Art. 6(1)(f) GDPR (legitimate interest in the technical operation and in delivering the images)

3.9 iCloud Sync Between Your Own Devices

Aspect Detail
What is processed The same data as in 3.1: pantry, favourites, weekly plans, shopping lists, shopping presets, restock rules, the cooking history, the learned taste preferences and purchase events (the basis for restock suggestions), and the learned product assignments
How Through Apple's SwiftData/CloudKit sync into the private iCloud database of your own Apple account. Only the private database is used — never a public or a shared CloudKit database
When active Only when an iCloud account is signed in on the device. Without iCloud the App simply keeps working locally, with no loss of data
Access by us None. We have no access to your private iCloud and cannot see this data. It is not stored on our servers
Record of the Terms of Use Whether and when you accepted the Terms of Use or chose “Later” (date and version, no identifier) is stored by the App on the device and — if an iCloud account is signed in — also in the iCloud key-value storage of your Apple account, so that not every one of your devices asks again. We have no access to this either. "Delete all data" deliberately keeps this record
How to turn it off In iOS Settings under "Apple Account → iCloud → Apps using iCloud". Your data then stays local on the device
Who processes Apple, as the operator of iCloud; Apple's terms and storage locations apply (see 5.)
Legal basis Art. 6(1)(b) GDPR (contract performance — cross-device sync as part of the core service), to the extent you have iCloud enabled

3.10 Recipe Submissions and Recipe Wishes

Inside the App you can submit a recipe of your own or wish for a dish. Both happen only when you deliberately send them — nothing is sent automatically. There is no community and no feed: submitted content is not visible to other users; it goes to us alone, for editorial review.

Aspect Detail
What is transmitted For a submission: title, short description, ingredient list, preparation steps, plus the optional fields servings, preparation and cooking time, difficulty, category, cuisine, and diet type. For a wish: the wish text (the name of the dish) and an optional note. In both cases the app version is included. No images are transmitted
Device token Every submission carries a randomly generated device token. It is created locally as a random value the first time you send something, and stored locally. It is not derived from your Apple ID, the advertising identifier (IDFA/IDFV), any hardware identifier, the device name, or a phone number, and it does not allow any conclusion about a person. Purpose: detecting duplicate submissions and limiting how often submissions can be sent (abuse prevention). It is sent nowhere else — in particular, it is never included in the usage statistics (3.11)
IP address The IP address is truncated and hashed with SHA-256 together with a secret salt before storage; the plain IP is not stored. The hash serves rate limiting and abuse prevention only
Free-text warning These fields are free text. Please do not enter personal data there — the App already rejects e-mail addresses and links. Anything else you type is transmitted along with the submission
Where stored On our own server at Hetzner Online GmbH, located in Germany (see 7.). No disclosure to third parties
Retention Until editorial review. After that the content is either adopted as editorial content of the App without the device token, or deleted
Legal basis Art. 6(1)(a) GDPR (consent — you actively send it) for the content and the device token; Art. 6(1)(f) GDPR (legitimate interest in abuse prevention) for the hashed IP value
Withdrawal and erasure You may withdraw your consent at any time with effect for the future and request erasure: an informal e-mail to support@vorinoapp.de is enough. So that we can find the submission, please state the title or wish text and the approximate date. The device token on your device also disappears when you choose "Delete all data" in the App's settings or uninstall the App

3.11 Anonymous Usage Statistics (Opt-in)

The App can collect anonymous usage statistics. This is off by default and only starts once you explicitly switch it on in the App's settings (opt-in). Its sole purpose is product improvement — which searches come back empty, which features anyone actually uses.

Aspect Detail
What is transmitted One per-day event record per action, containing: the calendar day (UTC), the search term after automatic filtering, the search mode and the number of results, recipe identifiers from our own recipe database, names of used features drawn from a fixed list, the number of people, weeks and a budget bracket for a weekly plan, the origin of an opened recipe (catalogue or your own), the app version and build, the device language code (without region), and a coarse device class ("iphone"/"ipad")
What is expressly not transmitted No device token and no other field that could link two transmissions from the same device. No clock time — the time granularity is never finer than the calendar day. No IDFA/IDFV, no installation identifier, no account, no location, no device model, no exact budget amount, no pantry data, no submitted recipe texts, and no wish texts. Events are shuffled before sending, so no sequence of use can be reconstructed
Filtering of search terms Search text is lower-cased, whitespace-normalised, and truncated to 60 characters. If a text shows signs of personal data (an e-mail address, a web address, or a longer run of digits), the text is discarded entirely — only the event itself is counted
Where stored On our own server at Hetzner Online GmbH, located in Germany (see 7.). No disclosure to third parties, no advertising or audience measurement
Retention on the device At most 30 days and at most 500 events; sent in batches, at most once per calendar day
Turning it off and erasure If you switch the statistics back off in the App's settings, the queue still waiting on your device is deleted immediately and nothing further is collected. For records already transmitted, contact support@vorinoapp.de — but because they carry no identifier, they cannot technically be traced back to you
Legal basis Art. 6(1)(a) GDPR (consent, given by switching the toggle on), withdrawable at any time by switching it off

3.12 Store Finder and Location

Aspect Detail
What is processed Your approximate device location, in order to find supermarkets nearby
When Only when you tap the store finder. The system prompt appears at that moment, never at app launch. Only the "While Using the App" permission is requested — no background location. Accuracy is deliberately limited to roughly 100 metres
Transmission to us None. We neither store your location nor transmit it to our servers. It is used only transiently, in the App's memory. It is not passed to Google either — the “coarse location” named in 3.4 is a different thing: Google derives it from the IP address, and does so even if you never granted the store finder location access
Third parties The proximity search runs through Apple Maps (MapKit). Apple therefore receives the search term and the map region. In that respect Apple is an independent controller; Apple's privacy policy applies: https://www.apple.com/legal/privacy/
Flyer links The linked online flyers of the retail chains live on those companies' own websites. Tapping such a link takes you out of Vorino, and the respective provider's privacy terms then apply
Legal basis Art. 6(1)(a) GDPR (consent via the iOS location prompt), withdrawable at any time in iOS Settings

3.13 Exporting the Shopping List to Apple Reminders

Aspect Detail
What is processed The open items on your shopping list are written as entries into a list of the Apple Reminders app on your device that you choose yourself — an existing list or a new list "Shopping List (Vorino)"
When Only when you explicitly ask for it — the system permission prompt appears when you tap "Export to Reminders", never at app launch. It is a one-off export, not an ongoing sync
Read access Apple offers no write-only permission for Reminders. To let you choose, Vorino shows the name, color and account of your Reminders lists (no entries). Vorino reads entries only from the list you chose, only the open ones and only to avoid duplicate entries — on your device. Entries of other lists are not read
Stored Only the identifier of the chosen list, in the app's settings on your device, so the next export goes there without asking. You can switch it via "Change Reminders list…" in the shopping list menu; items already sent stay in the previous list
Transmission to us None. The export ends up in the chosen list — on your device or in the account it belongs to (e.g. your iCloud). If you choose a list shared with others in the Reminders app, its members see the entries; that is Apple's sharing, not Vorino. Nothing reaches us
Legal basis Art. 6(1)(a) GDPR (consent via the iOS permission prompt), withdrawable at any time in iOS Settings

4. Your Rights

As a data subject under GDPR, you have the following rights:

  • Access (Art. 15) — to obtain information about the data we hold on you
  • Rectification (Art. 16) — to correct inaccurate data
  • Erasure (Art. 17) — the "right to be forgotten"
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21) — to processing based on legitimate interests
  • Withdraw consent (Art. 7(3)) — for example by revoking ATT in your iOS system settings at any time
  • Lodge a complaint (Art. 77) — with a supervisory authority such as the Federal Commissioner for Data Protection (BfDI) or the data-protection authority of your federal state

Please send any request to: support@vorinoapp.de

Because the App works locally and uses no account, we may not be able to associate a request with a specific person. You can erase all locally stored data at any time by uninstalling the App. "Delete all data" in the App's settings erases your content (such as pantry, favorites, meal plans, shopping list, preferences and what the App has learned) but deliberately keeps the records under 3.2 (Pantry from a Photo) and 3.9 (Terms of Use). For the few things that do reach us: we delete feedback entries (3.7) and recipe submissions or wishes (3.10) on informal request to support@vorinoapp.de — please quote the content and the approximate date so we can find it. Records from the anonymous usage statistics (3.11) deliberately carry no identifier and therefore cannot be attributed to anyone after the fact; they can only be stopped going forward, by switching the toggle off.


5. Transfers to Third Countries

The following transfers to third countries may occur:

Recipient Country Safeguard
Apple Inc. (StoreKit, App Store, crash reports, iCloud sync per 3.9, map search per 3.12) USA / EEA EU-US Data Privacy Framework, Apple is certified. Apple Distribution International Ltd. is the European contracting entity
Google LLC (AdMob, free tier only) USA EU-US Data Privacy Framework, Google is certified. Standard Contractual Clauses under Art. 46 GDPR additionally apply

No pantry, product, or image data is transmitted to our own servers — product and receipt recognition runs entirely on-device (see 3.2). What does reach our servers is limited to the requests for recipe images with the access logs they generate under 3.8, the content you actively send under 3.7 and 3.10, plus — only after your opt-in — the anonymous usage statistics under 3.11. That server infrastructure is operated in Germany by Hetzner Online GmbH (Nuremberg data centre); no third-country transfer occurs in this respect.


6. Cookies and Tracking

The App itself uses no web cookies. Tracking occurs only via the AdMob advertising network, and only when:

  1. You are using the free version and
  2. You have explicitly granted permission via the ATT (App Tracking Transparency) prompt.

The marketing website at vorinoapp.de does not set tracking or analytics cookies. Strictly necessary cookies (for instance, to remember your language preference) may be used.

The anonymous usage statistics described in 3.11 are not tracking in this sense: they deliberately contain no field that could link two transmissions from the same device, they set no cookie and no identifier, and they produce no usage profile. We continue to use no Firebase, no Sentry, and no third-party analytics service.


7. Data Processors

The infrastructure (rented server) for the App and the marketing website is supplied by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner is engaged as a data processor under Art. 28 GDPR; a corresponding data-processing agreement is in place. The server is located exclusively in Germany (Nuremberg data centre) — no transfer to a third country takes place in this context. The server processes only the data named in this policy, namely the access logs generated when recipe images are loaded (see 3.8), the entries from the feedback form (see 3.7), recipe submissions and recipe wishes (see 3.10), and — only after opt-in — the anonymous usage statistics (see 3.11). Beyond this, no further external data processors are used for the processing of user data; pantry, product, and image data is still not transmitted to the server (see 3.2).

Apple and Google act as independent (or joint) controllers under their own platform functions, not as classic processors.


8. Security of Processing

We use appropriate technical and organisational measures to protect your data, including:

  • On-device processing — pantry, product, and image data are processed on your device and not transmitted to our servers; at most they leave the device for your own private iCloud (see 3.9)
  • Data minimisation for everything that does reach us — truncated, salted IP hashes instead of plain IP addresses; a random device token with no personal reference for submissions (3.10); and, in the usage statistics, deliberately no linking field and no time granularity below the calendar day (3.11)
  • TLS encryption (HTTPS) for every network connection the App makes (e.g. with Apple)
  • Purchases via Apple — purchases and subscriptions are managed by Apple through StoreKit (3.3); the App itself stores no payment or account data
  • Hardened server infrastructure for the marketing website (SSH key-only login instead of passwords, firewall with a default-deny policy, protection against brute-force attacks)

Despite these measures, absolute security of data transmission over the Internet cannot be guaranteed.


9. Last Updated and Changes

Last updated: 2026-09-29 — applies from app version 2.1

We may update this Privacy Policy to reflect changes in the law or our services. We will inform you about material changes in the App, at the latest when they take effect. The current version is always available at vorinoapp.de/privacy.

Home FAQ Datenschutz Privacy Policy Nutzungsbedingungen Terms of Use Impressum Support
© 2026 Marcel Söndenaa-Defourny