Last updated: 2026-05-22
The data controller under GDPR is:
Marcel Söndenaa-Defourny
Muldentalstraße 100
04288 Leipzig (Liebertwolkwitz)
Germany
Email: support@vorinoapp.de
The iOS app "Vorino" (the "App") is a pantry-management and recipe-discovery tool. It lets users track their food inventory, find recipes, save favourites, and plan their week.
This policy describes what personal data we process when you use the App, why we process it, and on what legal basis. It applies both to the App itself and to the marketing pages hosted at vorinoapp.de.
Version 1.0 of the App does not collect directly identifying information such as name, address, or date of birth. No user account is required.
| Aspect | Detail |
|---|---|
| What | Food items, recipe favourites, weekly meal plans, and app settings you create |
| Storage | Local only — kept in SwiftData / Core Data on your Apple device |
| Transmission to us | None. This data never leaves your device and is invisible to us |
| Retention | Until you delete the data manually or uninstall the App |
| Legal basis | Art. 6(1)(b) GDPR — performance of the core service |
| Aspect | Detail |
|---|---|
| What | Photos of groceries or receipts, and barcodes that you capture |
| Purpose | Product detection to populate your pantry automatically |
| Where processed | On your Apple device only. Text recognition (OCR), barcode detection, and image classification run on-device using Apple's Vision framework and Apple Foundation Models (from iOS 26) together with local databases |
| Transmission to us | None. In version 1.0 neither images nor product names, barcodes, or any text derived from them are transmitted to or stored on a server |
| Retention | Captured images are processed only transiently on-device for recognition and are not transmitted to us. The recognised products are stored locally on your device, as described in 3.1 |
| Legal basis | Art. 6(1)(b) GDPR — performance of the core service |
Note on future versions: Later versions of the App may optionally offer server-side product classification. Any such processing would only take place after a corresponding update to this Privacy Policy and on the legal basis then required. Version 1.0 does not use any such server processing.
| Aspect | Detail |
|---|---|
| What | Pro-version purchases and subscriptions, processed exclusively by Apple |
| Who | Apple Distribution International Ltd. is the sole contracting party for in-app purchases. We receive only aggregated, anonymised sales reports via App Store Connect |
| Direct access by us | We do not see your Apple ID or your payment details |
| Retention | Governed by Apple under its own privacy policy |
| Legal basis | Art. 6(1)(b) GDPR (contract performance via Apple) |
Apple's privacy policy: https://www.apple.com/legal/privacy/
| Aspect | Detail |
|---|---|
| When | Only in the free version, never for Pro subscribers |
| ATT permission denied / not requested | Only non-personalised ads are shown. AdMob does not use the advertising identifier (IDFA) for profiling |
| ATT permission granted | Personalised ads may be served. Google processes your device's advertising identifier (IDFA) to choose them |
| Retention | Governed by Google under its own privacy policy |
| Legal basis | Personalised ads: Art. 6(1)(a) GDPR (explicit consent via the ATT prompt). Non-personalised ads: Art. 6(1)(f) GDPR (legitimate interest in funding the free version) |
Google AdMob privacy policy: https://policies.google.com/privacy
| Aspect | Detail |
|---|---|
| App-side server communication | None. In version 1.0 the App does not call any of our own server endpoints (see 3.2). Using the App therefore generates no server-side access logs |
| Marketing website | When you visit the pages hosted at vorinoapp.de, standard access data (IP address, timestamp, requested URL, HTTP status code) may be recorded for technical reasons |
| Purpose | Delivery of the website, security, and error diagnostics |
| Retention | Only as long as necessary for the purposes stated |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest in the security and delivery of the website) |
| Aspect | Detail |
|---|---|
| What | Crash and performance data via Apple's built-in mechanism |
| Provider | Apple — you can disable this in iOS Settings under "Privacy & Security → Analytics & Improvements" |
| What we receive | Only aggregated, non-personal crash reports via App Store Connect |
| Third parties | None. We do not use Firebase Crashlytics, Sentry, or any comparable service |
| Legal basis | Art. 6(1)(f) GDPR |
| Aspect | Detail |
|---|---|
| What is processed | The message you enter in the feedback form at vorinoapp.de/feedback, the chosen category, and — only if you provide it voluntarily — your e-mail address for a reply. |
| Purpose | Handling your feedback, fixing bugs, and improving the app. |
| Storage | On our own server (located in Germany). The IP address is SHA-256 hashed before storage; the plain IP is not stored. |
| Third parties | None. The form submits only to our own server — no external form service (no Formspree, Google Forms, etc.). |
| Retention | Until your request is resolved, then deleted. You can request deletion at any time via support@vorinoapp.de. |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest in support and product improvement); if you voluntarily provide your e-mail, additionally Art. 6(1)(a) GDPR (consent). |
As a data subject under GDPR, you have the following rights:
Please send any request to: support@vorinoapp.de
Because the App works locally and uses no account, we may not be able to associate a request with a specific person. You can erase all locally stored data at any time through the App's settings or by uninstalling the App.
The following transfers to third countries may occur:
| Recipient | Country | Safeguard |
|---|---|---|
| Apple Inc. (StoreKit, App Store, crash reports) | USA / EEA | EU-US Data Privacy Framework, Apple is certified. Apple Distribution International Ltd. is the European contracting entity |
| Google LLC (AdMob, free tier only) | USA | EU-US Data Privacy Framework, Google is certified. Standard Contractual Clauses under Art. 46 GDPR additionally apply |
In version 1.0, no product or pantry data is transmitted to our own servers — product recognition runs entirely on-device (see 3.2). The server infrastructure used for the App and the marketing website is operated in Germany (MC-Host24 (Server-Standort Frankfurt am Main, Deutschland)); no third-country transfer occurs in this respect.
The App itself uses no web cookies. Tracking occurs only via the AdMob advertising network, and only when:
The marketing website at vorinoapp.de does not set tracking or analytics cookies. Strictly necessary cookies (for instance, to remember your language preference) may be used.
The hosting provider that supplies the infrastructure (rented server) for the App and the marketing website — MC-Host24 — is engaged as a data processor under Art. 28 GDPR; a corresponding data-processing agreement is in place. Beyond this, version 1.0 of the App uses no further external data processors for the processing of user data. Because version 1.0 does not transmit any pantry or product data to the server in the first place (see 3.2), the server infrastructure is effectively not relevant to the processing of this App data.
Apple and Google act as independent (or joint) controllers under their own platform functions, not as classic processors.
We use appropriate technical and organisational measures to protect your data, including:
Despite these measures, absolute security of data transmission over the Internet cannot be guaranteed.
Last updated: 2026-05-22
We may update this Privacy Policy to reflect changes in the law or our services. Material changes will be announced in the App and at vorinoapp.de/privacy with reasonable notice. The current version is always available at that URL.