Tellerino

Juridisk · Opdateret

Privatlivs­politik

Denne tekst findes på tysk og engelsk. Nedenfor finder du den engelske version; det er den tyske version, der gælder: læs den tyske version.

1. Controller

Jan Colak
Jürgen-Töpfer-Straße 4
22763 Hamburg, Germany
Email: support@tellerino.app

2. What data we process

We process account, household, subscription and AI data in order to provide the app and its features (Art. 6(1)(b) GDPR – performance of a contract). Where a different legal basis applies, it is stated with the respective item.

  • Account: If you sign in with email, we store your email address and password (encrypted), plus the name or nickname you enter when registering. The members of your household see it, for example in notifications; you can change it in Settings under “Account”.
  • Sign in with Apple or Google: If you sign in with Apple or Google, the provider gives us your email address and your name; we don’t store a password in that case. With Apple, you decide whether to share your name and whether to hide your email address – then we only receive an anonymous relay address from Apple. Google also transmits the address of your profile picture, which we don’t use. The members of your household see the name we receive, as described above.
  • Household data: shopping list, meal plan, recipes, ratings, uploaded photos and the household settings (such as meals, number of people and excluded ingredients) – shared with the members of your household.
  • Camera and photos: the app accesses your camera or photo library only when you take a recipe photo or select one from your gallery. No other photos are read; access occurs solely when you trigger it.
  • Clipboard: If you don’t have a household yet, the app checks once at first launch whether the clipboard contains an invitation or gift code that you copied on our website before. The content stays on your device; the app only sends a recognised code that you accept to our server to redeem it.
  • Notifications: If you switch on “Partner updates” in Settings under “App”, the app registers your device with Expo’s push service (650 Industries, Inc., USA), and we store the push token (an address through which notifications reach your device) together with the platform and app language. When another member adds something to the shopping list or someone joins your household, our server sends the notification via Expo, which delivers it via Apple or Google. The notification contains the member’s name and the item, for example “Anna added milk to the list”. If you switch notifications off or sign out, we delete this device’s push token. The legal basis is Art. 6(1)(b) GDPR.
  • App updates: At launch, the app asks Expo’s update service (EAS Update, 650 Industries, Inc., USA) whether a newer version of the app content is available and downloads it if so. This transmits your IP address, a random identifier of this installation, the platform, the app version and the update channel, but no account or household data. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in delivering bug fixes quickly.
  • Protection against abuse: So that only the genuine Tellerino app can use our server functions, it verifies itself through Firebase App Check: on Apple devices with Apple’s App Attest, on Android with Google’s Play Integrity. Apple or Google confirm that the request comes from the unmodified app on a real device; technical characteristics of the device and app are checked, not names or email addresses. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in protecting our services against abuse.
  • Subscription management: So that the app knows your subscription status and can unlock Tellerino Pro, it transmits your user identifier (a random string) and, after a purchase, your purchase status to RevenueCat (USA). Your payment details remain with Apple or Google.
  • Use of the AI features: links, photos and text that you enter or share with Tellerino are transmitted to OpenAI (USA) for recipe recognition or creation. For recipe ideas and automatic week planning, our server also sends the household settings needed for this (such as the meal, number of people, the desired mix of dishes with meat, fish and vegetarian dishes, and excluded ingredients) and the names of recently saved or poorly rated recipes, so that nothing repeats. No account data is sent along with them.
  • Recipe links: when recognising a recipe from a link, our server automatically retrieves the content of the web page at the address you entered (including any preview image) in order to extract the recipe from it.
  • Direct requests from your device: the app loads some content directly, without going through our server: depending on the recipe, recipe images come from Pexels, from the website the recipe comes from, or as a preview image from YouTube. If a recipe website blocks our server, the app loads the page once itself and sends its content to our server for recognition. The respective provider sees your device’s IP address and the usual technical details such as operating system and app version; what it stores is up to that provider.
  • Crash reports: in the event of a technical error we automatically transmit an error report (affected feature, device type, app version) to Sentry so that we can fix problems. No names, email addresses or IP addresses are transmitted – only your pseudonymous user identifier (a random string), so that related reports can be linked. This processing is based on our legitimate interest (Art. 6(1)(f) GDPR) in a functioning app and cannot be switched off.
  • Usage statistics: only if you expressly consent do we use the PostHog service to record, in pseudonymised form, how the app is used. We record: app openings, which features are used and how often (for example whether the recipe ideas feature was used), individual milestones (household created or joined, setup completed, item added to the list, recipe saved, week planned, invitation sent, Pro offer shown or purchased, gift code redeemed) and the number of people in your household. Your user identifier (a random string) is transmitted so that related events can be linked; no names, email addresses, recipe content or details about other household members are transmitted. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give or decline when first starting the app and can withdraw or grant at any time in Settings under “Improve the app”.

3. Service providers and other recipients

These service providers process data on our behalf:

  • Google Firebase (sign-in, database, file storage, server functions, App Check and hosting of this website; the provider is a US company). The database, file storage and server functions run in the EU; Google processes sign-in (Firebase Authentication) exclusively in the USA.
  • OpenAI (AI recipe features, USA)
  • RevenueCat (subscription management, USA)
  • Expo (delivery of notifications and app updates; 650 Industries, Inc., USA)
  • Sentry (crash reports; EU region, operated by Functional Software, Inc., USA)
  • PostHog (app usage statistics, only with consent, and individual website events; EU region)
  • Cloudflare (website visitor statistics; Cloudflare, Inc., USA)
  • Pexels (recipe photos: our server only transmits a search term; the app loads the photo it finds directly, see section 2)
  • Google’s YouTube Data API (reading video descriptions for YouTube links)

In addition, where you use the respective feature, data is received by Apple and Google as operators of the app stores, of Sign in with Apple and Google sign-in, of the authenticity check (App Attest, Play Integrity) and of notification delivery, and by recipe websites and YouTube when the app loads images or pages directly.

Where data is transferred to the USA, the transfer is based on the EU-US Data Privacy Framework where the respective provider is certified under it, and otherwise on EU standard contractual clauses.

4. Storage period and deletion

Your data remains stored for as long as your account exists. You can delete your account yourself at any time in Settings. Shared household data remains with the household as long as someone is still in it; if you are the last member, we delete the household with all its data. Backup copies of the database expire after seven days at the latest. What exactly is deleted and what remains is explained at tellerino.app/da/account-deletion.

5. Your rights

Access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. Contact: support@tellerino.app.

6. Data export (right to data portability, Art. 20 GDPR)

To receive a copy of your data in a common, machine-readable format (for example JSON), simply write to us at support@tellerino.app. We will process your request within 30 days and send the data to the email address of your account.

7. Website (tellerino.app)

This website is hosted on Google Firebase Hosting. When you visit it, Google processes your IP address and, according to Google, keeps it in server logs for a few months to detect abuse. We set no cookies. Only if you choose a language yourself in the language menu does your browser remember that choice. Two services help us understand whether the site serves its purpose:

  • Cloudflare Web Analytics counts page views without cookies and without user profiles; your IP address is processed technically but not stored (provider: Cloudflare, Inc., USA). We do not use Cloudflare Web Analytics on the invitation and gift pages (tellerino.app/join/… and tellerino.app/gift/…).
  • We send individual events to PostHog (EU region), without a persistent identifier and without a profile: when you press a store button (which store, page language, position on the page and referral source such as “tiktok”), and on the invitation and gift pages when the page is opened, the code is copied or a store button is pressed. These events contain the page language, the device type (iOS, Android or computer), for a store button the store chosen and, when the page is opened, whether the address contained a code in a valid format – never the code itself. PostHog processes your IP address technically in the process.

The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in a working, secure and discoverable website.