v
Vorino
Home Terms Support
Back to home

Privacy Policy — Vorino App

Last updated: 2026-05-22


1. Data Controller

The data controller under GDPR is:

Marcel Söndenaa-Defourny
Muldentalstraße 100
04288 Leipzig (Liebertwolkwitz)
Germany

Email: support@vorinoapp.de


2. Scope

The iOS app "Vorino" (the "App") is a pantry-management and recipe-discovery tool. It lets users track their food inventory, find recipes, save favourites, and plan their week.

This policy describes what personal data we process when you use the App, why we process it, and on what legal basis. It applies both to the App itself and to the marketing pages hosted at vorinoapp.de.

Version 1.0 of the App does not collect directly identifying information such as name, address, or date of birth. No user account is required.


3. Categories of Data We Process

3.1 Local Data (Pantry, Favourites, Weekly Plans)

Aspect Detail
What Food items, recipe favourites, weekly meal plans, and app settings you create
Storage Local only — kept in SwiftData / Core Data on your Apple device
Transmission to us None. This data never leaves your device and is invisible to us
Retention Until you delete the data manually or uninstall the App
Legal basis Art. 6(1)(b) GDPR — performance of the core service

3.2 Receipt Scanning, Barcodes, and Image Recognition (entirely on-device)

Aspect Detail
What Photos of groceries or receipts, and barcodes that you capture
Purpose Product detection to populate your pantry automatically
Where processed On your Apple device only. Text recognition (OCR), barcode detection, and image classification run on-device using Apple's Vision framework and Apple Foundation Models (from iOS 26) together with local databases
Transmission to us None. In version 1.0 neither images nor product names, barcodes, or any text derived from them are transmitted to or stored on a server
Retention Captured images are processed only transiently on-device for recognition and are not transmitted to us. The recognised products are stored locally on your device, as described in 3.1
Legal basis Art. 6(1)(b) GDPR — performance of the core service

Note on future versions: Later versions of the App may optionally offer server-side product classification. Any such processing would only take place after a corresponding update to this Privacy Policy and on the legal basis then required. Version 1.0 does not use any such server processing.

3.3 Apple StoreKit — Transaction Data

Aspect Detail
What Pro-version purchases and subscriptions, processed exclusively by Apple
Who Apple Distribution International Ltd. is the sole contracting party for in-app purchases. We receive only aggregated, anonymised sales reports via App Store Connect
Direct access by us We do not see your Apple ID or your payment details
Retention Governed by Apple under its own privacy policy
Legal basis Art. 6(1)(b) GDPR (contract performance via Apple)

Apple's privacy policy: https://www.apple.com/legal/privacy/

3.4 Google AdMob (Free Tier Only)

Aspect Detail
When Only in the free version, never for Pro subscribers
ATT permission denied / not requested Only non-personalised ads are shown. AdMob does not use the advertising identifier (IDFA) for profiling
ATT permission granted Personalised ads may be served. Google processes your device's advertising identifier (IDFA) to choose them
Retention Governed by Google under its own privacy policy
Legal basis Personalised ads: Art. 6(1)(a) GDPR (explicit consent via the ATT prompt). Non-personalised ads: Art. 6(1)(f) GDPR (legitimate interest in funding the free version)

Google AdMob privacy policy: https://policies.google.com/privacy

3.5 Server Access Logs

Aspect Detail
App-side server communication None. In version 1.0 the App does not call any of our own server endpoints (see 3.2). Using the App therefore generates no server-side access logs
Marketing website When you visit the pages hosted at vorinoapp.de, standard access data (IP address, timestamp, requested URL, HTTP status code) may be recorded for technical reasons
Purpose Delivery of the website, security, and error diagnostics
Retention Only as long as necessary for the purposes stated
Legal basis Art. 6(1)(f) GDPR (legitimate interest in the security and delivery of the website)

3.6 Apple Crash Reports

Aspect Detail
What Crash and performance data via Apple's built-in mechanism
Provider Apple — you can disable this in iOS Settings under "Privacy & Security → Analytics & Improvements"
What we receive Only aggregated, non-personal crash reports via App Store Connect
Third parties None. We do not use Firebase Crashlytics, Sentry, or any comparable service
Legal basis Art. 6(1)(f) GDPR

3.7 Feedback Form (Website)

AspectDetail
What is processedThe message you enter in the feedback form at vorinoapp.de/feedback, the chosen category, and — only if you provide it voluntarily — your e-mail address for a reply.
PurposeHandling your feedback, fixing bugs, and improving the app.
StorageOn our own server (located in Germany). The IP address is SHA-256 hashed before storage; the plain IP is not stored.
Third partiesNone. The form submits only to our own server — no external form service (no Formspree, Google Forms, etc.).
RetentionUntil your request is resolved, then deleted. You can request deletion at any time via support@vorinoapp.de.
Legal basisArt. 6(1)(f) GDPR (legitimate interest in support and product improvement); if you voluntarily provide your e-mail, additionally Art. 6(1)(a) GDPR (consent).

4. Your Rights

As a data subject under GDPR, you have the following rights:

  • Access (Art. 15) — to obtain information about the data we hold on you
  • Rectification (Art. 16) — to correct inaccurate data
  • Erasure (Art. 17) — the "right to be forgotten"
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21) — to processing based on legitimate interests
  • Withdraw consent (Art. 7(3)) — for example by revoking ATT in your iOS system settings at any time
  • Lodge a complaint (Art. 77) — with a supervisory authority such as the Federal Commissioner for Data Protection (BfDI) or the data-protection authority of your federal state

Please send any request to: support@vorinoapp.de

Because the App works locally and uses no account, we may not be able to associate a request with a specific person. You can erase all locally stored data at any time through the App's settings or by uninstalling the App.


5. Transfers to Third Countries

The following transfers to third countries may occur:

Recipient Country Safeguard
Apple Inc. (StoreKit, App Store, crash reports) USA / EEA EU-US Data Privacy Framework, Apple is certified. Apple Distribution International Ltd. is the European contracting entity
Google LLC (AdMob, free tier only) USA EU-US Data Privacy Framework, Google is certified. Standard Contractual Clauses under Art. 46 GDPR additionally apply

In version 1.0, no product or pantry data is transmitted to our own servers — product recognition runs entirely on-device (see 3.2). The server infrastructure used for the App and the marketing website is operated in Germany (MC-Host24 (Server-Standort Frankfurt am Main, Deutschland)); no third-country transfer occurs in this respect.


6. Cookies and Tracking

The App itself uses no web cookies. Tracking occurs only via the AdMob advertising network, and only when:

  1. You are using the free version and
  2. You have explicitly granted permission via the ATT (App Tracking Transparency) prompt.

The marketing website at vorinoapp.de does not set tracking or analytics cookies. Strictly necessary cookies (for instance, to remember your language preference) may be used.


7. Data Processors

The hosting provider that supplies the infrastructure (rented server) for the App and the marketing website — MC-Host24 — is engaged as a data processor under Art. 28 GDPR; a corresponding data-processing agreement is in place. Beyond this, version 1.0 of the App uses no further external data processors for the processing of user data. Because version 1.0 does not transmit any pantry or product data to the server in the first place (see 3.2), the server infrastructure is effectively not relevant to the processing of this App data.

Apple and Google act as independent (or joint) controllers under their own platform functions, not as classic processors.


8. Security of Processing

We use appropriate technical and organisational measures to protect your data, including:

  • On-device processing — in version 1.0, pantry, product, and image data are processed exclusively on your device and not transmitted to any server
  • TLS encryption (HTTPS) for every network connection the App makes (e.g. with Apple)
  • Apple Keychain for on-device storage of StoreKit tokens
  • Hardened server infrastructure for the marketing website (SSH key-only login instead of passwords, firewall with a default-deny policy, protection against brute-force attacks)

Despite these measures, absolute security of data transmission over the Internet cannot be guaranteed.


9. Last Updated and Changes

Last updated: 2026-05-22

We may update this Privacy Policy to reflect changes in the law or our services. Material changes will be announced in the App and at vorinoapp.de/privacy with reasonable notice. The current version is always available at that URL.

Home Datenschutz Privacy Policy Nutzungsbedingungen Terms of Service Impressum Support
© 2026 Marcel Söndenaa-Defourny