Privacy Policy - Pantryverse App
Version: 1.0.0
Effective Date: December 23, 2025
Last Updated: July 22, 2026
1. Data Controller and Contact Information
Data Controller under GDPR
Torsten Hubertus Kunz
Sole proprietor (natural person)
Pistoriusstraße 9a
13086 Berlin
Germany
Commercial Register: n/a (natural person, beta phase)
Tax Number: n/a (natural person, beta phase)
Contact:
Email: statue-speer-4p@icloud.com
Website: https://pantryverse.com
Product Brand, Legal Entity, and Support
- Product brand: Pantryverse
- Legal controller: Torsten Hubertus Kunz
- Public app domain: https://pantryverse.com
- Legal pages: https://legal.pantryverse.com
- Support and privacy contact: statue-speer-4p@icloud.com
- Technical identifiers: Bundle IDs, Firebase project IDs, and similar internal identifiers may include
omnom; these identifiers do not change the user-facing Pantryverse product brand.
Data Protection Officer
Not appointed (not required for a single-operator beta with limited processing).
2. Scope of This Privacy Policy
This privacy policy applies to the processing of personal data by the Pantryverse App on the following platforms:
iOS App
- App Name: Pantryverse - Smart Grocery Lists & Recipes
- Technical Bundle ID: com.omnom
- Minimum Version: iOS 16.0
- Distribution: Apple App Store
Web Application
- URL: https://pantryverse.com
- Technologies: React, Firebase
- Browsers: Chrome, Safari, Firefox, Edge (current versions)
Geographic Scope: Germany and European Union
Languages: German (primary), English (secondary)
Beta diagnostics: Firebase Crashlytics is used for crash reporting and
coarse non-fatal product-health diagnostics. Firebase Analytics is used only
for coarse web shared-list acquisition events when configured, without recipe
content, grocery content, list IDs, creator IDs, or cross-app tracking.
3. Types of Data Processed
3.1 Required Data for App Usage
This data is necessary for the core functions of the app:
Registration Data:
- Email address (as username)
- Sign-in provider metadata for email-link, Apple, or Google sign-in
- Registration timestamp
- Email verification status
Account Data:
- User settings and preferences
- Language settings
- Notification preferences
- App configuration
3.2 Application Data
Recipe Data:
- Recipe titles and descriptions
- Ingredient lists
- Cooking instructions
- Recipe images (uploaded by you)
- Creation and modification dates
- Ratings and notes
Grocery Lists:
- Grocery list contents
- Item categories and preferences
- Account-wide Quick-add recall (successful item names, use timestamps/counts,
and text-free deletion tombstones). Its Suggestion Identity hashes and
tombstones are pseudonymous personal data, never anonymized data. This recall
is separate from the retired category-resolution Item History. - Category mappings
- List sharing permissions
Synchronization Data:
- Offline queue data
- Synchronization status
- Conflict resolution data
3.3 Special Categories of Personal Data
Pantryverse does not collect biometric templates or server-side biometric
settings during Trusted Beta. Apple may process Face ID or Touch ID locally on
your device for OS-level authentication, such as Sign in with Apple. Pantryverse
receives only the sign-in result and provider metadata needed for account
functionality.
3.4 Technical and Device Data
Device Information:
- Operating system version
- App version
- Device type and model
- Region settings and time zone
- Device identifiers for security and abuse prevention
Access Data:
- IP address and request metadata processed by Firebase and hosting providers
- Access timestamps
- Features used (basic operational logs)
- Error messages, crash reports, and non-fatal diagnostics with coarse context
3.5 Analytics and Performance Data
Pantryverse does not use collected data for advertising tracking or cross-app
tracking. During Trusted Beta, analytics are limited to coarse operational and
shared-list acquisition events when Firebase Analytics is configured for the
web shared-list surface.
4. Purposes of Data Processing and Legal Bases
4.1 Contract Performance (Art. 6(1)(b) GDPR)
Purpose: Providing the main functions of the app
Data Processed:
- Registration and account data
- Recipe and grocery list data
- Synchronization data
- Basic technical data
Duration: During the contract term
4.2 Legitimate Interests (Art. 6(1)(f) GDPR)
Purpose: Security, fraud prevention, and system stability
Data Processed:
- Technical and device data
- Access logs
- Security tokens and attestation data
- Anonymized performance data
Balancing of Interests: Our legitimate interest in the security and functionality of the app outweighs your interests because:
- Only technical, non-identifying data is processed
- Processing is necessary for security
- You benefit from improved security
- Appropriate protective measures are implemented
Right to Object: You can object to the processing (see Section 8).
4.3 Consent (Art. 6(1)(a) GDPR)
Purpose: Additional features and improvements
Data Processed (only with explicit consent):
- Optional user-submitted feedback screenshots
- Optional future beta features if introduced with a separate consent prompt
- Marketing communications only if separately requested
Withdrawal: You can withdraw your consent at any time (see Section 8).
4.4 Legal Obligation (Art. 6(1)© GDPR)
Purpose: Compliance with legal retention requirements
Applicable Laws:
- Tax law retention periods (10 years)
- Consumer protection documentation (3 years)
- GDPR evidence requirements (3 years)
5. AI-Powered Data Processing and EU AI Act
5.1 AI Systems in the App
Recipe Analysis and Categorization:
- System: Third-party AI service providers
- Purpose: Automatic categorization of recipes and ingredients
- Risk Category: Minimal risk (Art. 6 EU AI Act)
- Transparency: You are informed about AI processing
Data Minimization:
- Only recipe content is sent to AI services
- No personal identifiers
- Anonymization before transmission
- Opt-out option available
5.2 Transparency and Explainability
Information about AI Decisions:
- Categorization results are traceable
- Manual correction options available
- No automated decisions with legal effect
Quality Assurance:
- Regular review of AI results
- Bias monitoring and correction
- Continuous model improvement
6. Retention Periods
6.1 Account Data
Duration: Until account deletion for active Firebase account data; limited
provider, backup, security, and legal evidence records may remain only where
required or permitted.
Reason: Account operation, security, legal evidence, and recovery limits.
6.2 Application Data (Recipes, Lists)
Duration: Until account deletion for active Firestore and Storage user
data; backup copies may remain for the backup retention period.
Reason: App functionality and recoverability.
6.3 Device Biometric Processing
Pantryverse does not store biometric templates or biometric settings on its
servers. OS-level Face ID or Touch ID processing remains on your Apple device.
6.4 Analytics and Performance Data
Crash and non-fatal diagnostics: Kept in Firebase Crashlytics according to
Firebase retention controls.
Web shared-list analytics: Optional, coarse event data only when configured.
Reason: Product health, security, and Trusted Beta operations.
6.5 AI Processing Data
Local processing: 90 days
Third-party AI provider logs: Minimization and time-limited retention per provider policies
6.6 Support Communications
Duration: 3 years after problem resolution
Reason: Quality assurance and legal protection
6.7 Legal Evidence
Consent records: 7 years after withdrawal
Compliance documentation: 3 years
Deletion implementation: In-app Account Deletion removes active
user-scoped Firestore data, user-scoped Storage files, and the Firebase Auth
user. Provider logs, backups, and legal evidence are handled through the
applicable provider and retention processes.
7. Recipients and Categories of Recipients
7.1 Data Processors
Google LLC / Google Ireland Limited (Firebase)
- Services: Authentication, Firestore, Storage, Hosting, security and abuse prevention
- Location: EU (Ireland), USA
- Safeguards: EU-US Data Privacy Framework, Standard Contractual Clauses
- Purpose: Backend infrastructure and data storage
Third-party AI service providers
- Services: AI processing for recipe analysis
- Location: USA
- Safeguards: Standard Contractual Clauses
- Purpose: AI-powered recipe categorization
- Data Minimization: Only anonymized recipe content
7.2 Platform Providers
Apple Inc.
- Services: iOS App Store, Sign in with Apple, OS-level device authentication
- Location: USA, EU
- Purpose: App distribution and security features
- Special Note: OS-level biometric templates do not leave your device
7.3 Infrastructure and Development
No additional recipients beyond those listed above.
7.4 New Data Processors
Notification Obligation: 30 days in advance
Right to Object: You can object within 30 days
8. International Data Transfers
8.1 Adequacy Decisions
EU-US Data Privacy Framework
- Applicable to: Google LLC
- Status: Active (as of June 2025)
- Certification: https://www.dataprivacyframework.gov/
8.2 Standard Contractual Clauses (Art. 46 GDPR)
Version: Implementing Decision (EU) 2021/914
Applicable to: US-based processors as required
Additional Safeguards:
- End-to-end encryption for data transmission
- Data minimization and anonymization
- Regular security assessments
- Incident response procedures
- Technical access controls
8.3 Countries with Data Transfer
USA:
- Google (EU-US DPF)
- Third-party AI providers (SCC + safeguards)
- Apple (platform services)
Ireland (EU):
- Google Ireland Limited (GDPR-compliant)
9. Cookies and Tracking (TDDDG § 25)
9.1 Cookie Categories
Technically Required Cookies (no consent required):
- Firebase Authentication Session
- App state management
- Security tokens
- Purpose: Basic application functions
- Storage Duration: Session or until logout
Analytics Cookies (consent required under TDDDG § 25):
No analytics cookies are used during beta.
9.2 Consent Management
Cookie Banner: Not shown during beta because only essential cookies are used
Withdrawal: You can remove cookies via your browser settings
9.3 Local Storage and App Data (iOS)
Local Data Storage:
- UserDefaults for app settings
- Core Data for offline synchronization
- Keychain for security tokens
Purpose: Offline functionality and user experience
Access: Only by the Pantryverse App
10. Your Rights as a Data Subject
10.1 Right of Access (Art. 15 GDPR)
Content: Complete overview of your processed data
Format: Structured, machine-readable (JSON/CSV)
Timeframe: Within 30 days
Contact: statue-speer-4p@icloud.com
10.2 Right to Rectification (Art. 16 GDPR)
Option: Directly in the app or via email request
Timeframe: Without delay, at the latest within 30 days
10.3 Right to Erasure (Art. 17 GDPR)
“Right to be Forgotten”:
- Complete account deletion in app settings
- Partial data deletion on request
- Automatic deletion after retention periods
Exceptions (no deletion):
- Ongoing contracts or legal obligations
- Legitimate interests (e.g., security)
- Consent-based processing until withdrawal
10.4 Right to Restriction of Processing (Art. 18 GDPR)
Cases: Accuracy disputed, processing unlawful, objection lodged
Effect: Data is “frozen” but not deleted
10.5 Right to Data Portability (Art. 20 GDPR)
Format: JSON, CSV, or other structured formats
Scope: All data provided by you
Direct Transfer: Assessed on request for the specific destination. If direct
transfer is not practical, Pantryverse provides a structured export file.
10.6 Right to Object (Art. 21 GDPR)
Against processing based on legitimate interests:
- At any time without giving reasons
- Processing within 30 days
- Processing will be stopped unless compelling grounds exist
Against direct marketing:
- At any time and unconditionally
- Immediate cessation of processing
10.7 Withdrawal of Consent (Art. 7(3) GDPR)
Withdrawal Options:
- In app settings
- Via email to statue-speer-4p@icloud.com
- By deactivating specific functions
Effect: For the future, already completed processing remains lawful
10.8 Legal Remedies
Complaint to Supervisory Authority (Art. 77 GDPR):
Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Str. 153
53117 Bonn
Germany
Contact:
- Website: https://www.bfdi.bund.de/
- Email: poststelle@bfdi.bund.de
- Phone: +49 (0)228 997799-0
- Complaint form: https://www.bfdi.bund.de/SharedDocs/Downloads/DE/Beschwerde/BeschwerdeformularBfDI.html
Judicial Remedy (Art. 79 GDPR):
- Civil courts at the controller’s location
- German law applicable
11. Security Measures
11.1 Technical Safeguards
Encryption and Transport Security:
- Encryption in transit and at rest where appropriate
- Secure connections for all data transfers
Access Controls:
- Restricted access to production data
- Regular access reviews and logging
Abuse Prevention:
- Measures to protect against misuse and automated attacks
11.2 Organizational Safeguards
Privacy by Design and Default:
- Minimal data collection by default
- Anonymization where technically possible
- Regular data protection impact assessments
Training and Awareness:
- Regular data protection training
- Security awareness for all employees
- Incident response training
Monitoring and Auditing:
- Continuous security monitoring
- Regular penetration testing
- Automatic vulnerability analysis
- Compliance audits
11.3 Data Protection Review
Reviewed areas:
- AI-powered recipe processing
- Optional feedback screenshots
- International data transfers
Result: High level of protection, appropriate risk mitigation
12. Automated Decision-Making and Profiling
12.1 No Automated Decisions with Legal Effect
Clarification: The Pantryverse App does not make automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
12.2 AI-Powered Recommendations
Recipe Categorization:
- Automatic suggestions for categories
- Manual correction possible at any time
- No binding effect
- Transparency about decision logic
Grocery List Optimization:
- Suggestions based on your preferences
- Complete control over final decisions
- Opt-out possible at any time
12.3 Profiling (Limited)
Personalization of User Experience:
- Based on your app settings
- To improve user-friendliness
- No categorization or evaluation of your person
- Right to object under Art. 21 GDPR
13. Data Protection for Minors
13.1 Age Limit
Minimum Age: 16 years (Art. 8 GDPR)
Under 16 years: Consent from legal guardians required
13.2 Verification
Age Query: During registration
Parental Consent: Email verification required
Deletion: Within 30 days if consent is missing
13.3 Special Protective Measures
- No marketing communications to minors
- Limited data collection
- Enhanced transparency and control
14. Changes to This Privacy Policy
14.1 Amendment Procedure
Material Changes: 30 days advance notice via email
Minor Changes: Notification in the app
New Legal Bases: Renewed consent required
14.2 Version Control
Current Version: Always at https://legal.pantryverse.com/privacy/en
Previous Versions: Archived for 10 years
Changelog: Detailed change history available
14.3 Your Response Options
Objection: Within 30 days after notification
Termination: Account deletion for unacceptable changes
Consultation: Free support for questions
15. Contact and Data Protection Inquiries
15.1 Data Protection Contacts
General Data Protection Questions:
Email: statue-speer-4p@icloud.com
Response Time: Within 48 hours
Data Subject Rights:
Email: statue-speer-4p@icloud.com
Processing Time: Within 30 days (GDPR Art. 12)
Data Breaches:
Email: statue-speer-4p@icloud.com
Availability: 24/7
15.2 Required Information for Requests
Access Requests:
- Full name
- Email address of app account
- Copy of identity document (for identity verification)
- Specific information you desire
Deletion Requests:
- Account information
- Reason for deletion (optional)
- Identity confirmation
Rectification Requests:
- Data to be corrected
- Correct information
- Proof of accuracy (if required)
15.3 Processing Procedure
- Acknowledgment: Within 24 hours
- Identity Verification: Up to 7 days
- Processing: Up to 30 days (GDPR-compliant)
- Response: Structured and comprehensible
- Follow-up Questions: Free support
15.4 Languages
German: Complete processing
English: Complete processing
Other Languages: Upon request
Appendix: Legal Foundations
Applicable Laws (as of June 2025)
- GDPR: Regulation (EU) 2016/679
- BDSG: Federal Data Protection Act (2018)
- TDDDG: Telecommunications-Telemedia Data Protection Act (2021)
- TMG: Telemedia Act (2007)
- EU General Data Protection Regulation: Primary law
- Digital Services Act: Regulation (EU) 2022/2065
- Data Governance Act: Regulation (EU) 2022/868
- Data Act: Regulation (EU) 2023/2854
- AI Act: Regulation (EU) 2024/1689
Jurisdiction and Applicable Law
Jurisdiction: Germany (Local Court at the controller’s seat)
Applicable Law: German law
EU Law: GDPR and other EU regulations take precedence
Last Updated: July 22, 2026
Next Review: July 22, 2027
For questions about this privacy policy, please contact: statue-speer-4p@icloud.com