Effective Date: June 02, 2026 Owner and Data Controller: Matej Bumbera (IČO: 23676825) Registered Address: Děčínská 552/1, 180 00, Praha 8 - Střížkov, Czechia Contact Email: support@fridgebutler.app | Phone: +420 736 447 699
Welcome to the Privacy Policy for Fridge Butler ("the App"). We operate a personal and household kitchen management application designed to track food inventory, minimize waste, and streamline shopping. This document explains what data we collect, how it is processed, and your rights under global privacy laws, including the GDPR (EU/UK), US State Laws (CCPA), and the Australian Privacy Act 1988.
Privacy-First Architecture Notice: Fridge Butler features a decentralized dual-mode data system. The free baseline version operates completely locally on your device without transmitting kitchen data to external servers. Cloud processing is strictly activated upon opting into our premium synchronization subscription service.
1. Definitions
Personal Data: Any information that directly, indirectly, or in connection with other information allows for the identification of a natural person.
Data Controller: The natural person (Matej Bumbera) who determines the purposes and means of the processing of Personal Data.
Usage Data: Information collected automatically through the service infrastructure (e.g., anonymous crash logs, system interactions).
2. Information We Collect and Visibility
The type of data collected is dependent on your elected utility tier within the App. We do not sell your personal information or utilize targeted advertising networks.
A. Free Tier (Local Mode)
Zero Server Collection: If you use the App locally, all food lists, item entries, quantities, and expiration dates are stored exclusively on your device's internal storage.
No Account Required: Registration can be entirely bypassed. We do not look at or upload your camera feed during barcode scanning; image interpretation happens entirely on-device. If you delete the App, your local data is instantly erased.
B. Premium Tier (Cloud Mode / Synchronized Household)
Account Data (Mandatory for Cloud Sync): When creating a synchronized kitchen license, we securely collect your email address and authentication credentials.
Household Inventory States: To synchronize your kitchen across multiple devices, product titles, custom household tags, item quantities, and expiration date estimates are encrypted and transmitted to our cloud servers. This data is private and visible only to devices authenticated onto your shared household user account.
Subscription and Receipts: Financial transactions are processed securely through App Distributors (Google Play / Apple App Store) alongside RevenueCat. We maintain an entitlement record verifying premium eligibility but never see or store your physical credit card records.
3. Legal Basis for Processing (EU/UK GDPR)
Contract Performance (Art. 6.1.b): Necessary to provide household synchronization features, process user-initiated lookups, and validate active premium statuses.
Legitimate Interest (Art. 6.1.f): Maintaining backend application performance, executing routine server diagnostics, and monitoring system stability.
Consent (Art. 6.1.a): Handled when opting into user profile changes, cloud sign-ups, or standard communication channels. You possess the right to retract consent at any point.
4. Data Storage, Security & International Transfers
We deploy robust security measures and strict access controls to eliminate vectors for unauthorized data destruction, modification, or exposure.
Service
Provider HQ
Purpose
Data Residency Location
Supabase
USA
Cloud Database & Authentication
European Union (EU)
Resend
USA
Transactional Account Emails
European Union (EU)
RevenueCat
USA
Subscription Validation
USA / Global
International Safeguards: While your primary kitchen data lives securely inside our dedicated European databases, providers operating from the United States are governed strictly by Standard Contractual Clauses (SCCs) approved by the European Commission to ensure a matching metric of international protection.
5. How to Exercise Your Rights
You maintain ultimate sovereignty over your data, easily modifiable directly inside the App's interface:
Rectification: Modify or override inventory values and household tags dynamically within your display view screens.
Erasure (The Right to Be Forgotten): Cloud users can instantly clear all traces of their account via the "Delete Account" utility in settings. This permanently deletes all your synchronized data from our cloud servers instantly.
Access & Portability: You can instantly download a machine-readable export of both your local and synchronized data using the "Export Data" button within the App's settings. If you experience technical issues, formal requests for your data can also be addressed to support@fridgebutler.app, with responses provided within 30 days without charge.
6. Global Regulations Compliance
A. Users in the EU & UK (GDPR)
You possess access, rectification, portability, and restriction processing rights. High-risk application data incidents will be reported to the national supervisory framework (ÚOOÚ within Czechia) alongside impacted subscribers within 72 hours. You retain legal standing to lodge grievances with regional data safety bureaus.
B. Users in the United States (CCPA/CPRA)
We do not swap, distribute, trade, or monetize your inventory entries for targeted cross-context marketing loops. We strictly acknowledge and accommodate Global Privacy Control (GPC) declarations natively. Residents can assert rights of deletion, verification, and correction directly via contact methods.
C. Users in Australia (Privacy Act 1988)
Our structures conform with standard Australian Privacy Principles (APPs). Escaped privacy issues or adjustment demands should be directed to our infrastructure monitoring mail address at support@fridgebutler.app.
7. Children's Privacy (COPPA Compliance)
The application structure does not purposefully capture or retain identifiers from children tracking under the age of 13. If it is discovered that a minor below the threshold of 13 submitted data to our cloud servers without verified parental consent, the logs will be permanently deleted.
8. Changes to this Policy
We reserve the right to modify this policy. Significant changes to tracking policies will be announced to cloud subscribers via app alerts or transactional notifications. The current version is always indicated by the effective date at the top of this document.