Privacy policy
Controller
- {{entity_name}} {{entity_form}}
- {{street}}
- {{postal_code}} {{city}}
- {{country}}
- E-mail: {{email}}
What this is about
smekkar is a paid service. It is funded by subscriptions — not by advertising and not by selling data. There are no ads, no third-party analytics and no data sales. The primary data is stored in Germany.
Purposes and lawful bases
- Account and authentication (e-mail, password hash, username, display name, session and verification records) — Art. 6(1)(b) GDPR (contract).
- Profile and settings (display name, avatar, language, privacy and notification preferences) — Art. 6(1)(b) GDPR.
- Subscription and billing (subscription status with trial, period and grace dates, the payment provider’s customer and subscription identifiers, invoice data and invoice documents) — Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for the statutory retention of invoices.
- Health profile and nutrition targets (year of birth, sex, height, weight history, activity, goal, pregnancy or breastfeeding) — Art. 9(2)(a) GDPR, explicit consent. See the dedicated section below.
- Recipes, lists, plans, logbook (your content, shopping lists, the weekly plan, cooked meals, ratings, the food log, cooking circles, guests) — Art. 6(1)(b) GDPR.
- Social features (friendships, follows, blocks, shared cooks, comments) — Art. 6(1)(b) GDPR; blocking additionally Art. 6(1)(f) GDPR (user safety).
- Messages (one-to-one conversations, messages, read and folder state, your support conversation) — Art. 6(1)(b) GDPR. Messages are not end-to-end encrypted; they are protected in transit and at rest. Staff read a message only in the context of a report; your support conversation is read by support staff in order to answer it (every access is logged).
- Transactional e-mail (e-mail address, delivery metadata) — Art. 6(1)(b) GDPR.
- Push notifications (device token, content-free deliveries) — Art. 6(1)(f) GDPR or consent given on the device.
- Security, abuse prevention, rate limiting (user id, IP transiently, counters) — Art. 6(1)(f) GDPR.
- Moderation reports and sanctions — Art. 6(1)(f) and Art. 6(1)(b) GDPR.
- Audit log of administrative and data-subject operations — Art. 6(1)(c) and Art. 6(1)(f) GDPR (accountability).
- Support (tickets, status, internal notes) — Art. 6(1)(b) GDPR; internal notes Art. 6(1)(f) GDPR.
Retention
- Active account data: for the life of the account.
- Deleted account: deletion on request, followed by a 14-day grace period (logging in restores the account), then permanent removal. References in other people’s content are anonymised.
- Health data: until consent is withdrawn or the account is deleted; withdrawal deletes it immediately.
- Closed moderation reports: 12 months. In-app notifications: 90 days. Push tokens: the lifetime of the session, and at the latest after 60 days without refresh.
- Invoices and invoice data: statutory retention periods under German commercial and tax law, as a rule ten years.
- Application logs: a short window, with no personal content.
- Backups: encrypted backups run on a rolling window. A deletion takes effect immediately in the live system; in backups already taken, the data disappears when those backups age out.
- Data exports: until downloaded, at most seven days.
Recipients and processors
Every processor is engaged under a data processing agreement.
- Hetzner — hosting and object storage, Germany. Agreement: {{dpa_links.hetzner}}
- Stripe — payment processing. Agreement: {{dpa_links.stripe}}
- E-mail provider — sending transactional e-mail. Agreement: {{dpa_links.email_provider}}
- Apple (APNs) and Google (FCM) — push delivery, content-free only (a device token and an identifier, never content).
International transfers
Primary processing takes place in the EU. Apple and Google receive only a device token and a content-free delivery for push notifications; those transfers rely on the standard contractual clauses or on an adequacy decision. The payment provider processes payment data partly in its own controller role.
When you choose a password, we check it against a public list of passwords that have appeared in known data breaches. Only the first five characters of a one-way fingerprint of the password are sent to that service — never the password, your e-mail address, or anything that identifies you — and the comparison happens on our own server. If the service cannot be reached, we skip the check rather than block you.
We also decline sign-ups from a list of known disposable e-mail domains, so we can reach you if we ever need to.
Cookies
This website sets no cookies and embeds no third-party content. The web app at app.smekkar.app sets two strictly necessary cookies (session and CSRF protection). No consent banner is therefore required, because none of this requires consent.
Health data
Health details are entirely optional and are stored only after a separate, explicit consent.
- In addition to transport and storage encryption they are encrypted at the application level with a dedicated key.
- They are not visible to staff — there is no internal access path and no internal export path.
- Withdrawing consent is a single action and deletes the health profile including the weight history; targets revert to general reference values.
- A single portion factor is derived from these details. It leaves your own plan only if you switch that on separately — per setting for your cooking circle and per invitation as a guest.
Your rights
- Access and portability (Art. 15, Art. 20 GDPR): you start the export yourself in Settings and receive your data in machine-readable form together with your media. The download is single-use and expires after seven days.
- Rectification (Art. 16 GDPR): change your profile, settings and content directly in the app.
- Erasure (Art. 17 GDPR): delete the account in Settings, with the grace period described above.
- Restriction (Art. 18 GDPR) and objection (Art. 21 GDPR): through support. There is no advertising or profiling to object to.
- Withdrawal of consent (Art. 7(3) GDPR): at any time, with effect for the future; for health data with the immediate deletion described above.
- No solely automated decisions: the planner, the targets and the suggestions are transparent heuristics without machine learning, and they are not binding.
- Right to complain: under Art. 77 GDPR you may lodge a complaint with a data protection supervisory authority.
Self-service takes effect immediately; a request that has to be handled manually is answered within one month.
Changes to this policy
The current version and its effective date are at the end of this page; we will inform you about a new version.
Version 1.0 · In force since {{effective_date_privacy}}