Privacy Policy
Last Updated: August 6, 2026
1. Who We Are
Fridget is a mobile application published by Verino Calis, an individual
developer based in Croatia ("we", "us"). For the purposes of the EU
General Data Protection Regulation (GDPR), we are the data controller
for the personal data described in this policy.
Contact for any privacy question, data request, or complaint:
verino.calis@gmail.com. We
respond to data protection requests within 30 days.
This policy covers the Fridget mobile app for iOS and Android and its
supporting backend services. It does not cover third-party services you
reach from the app, which have their own policies.
2. Data We Collect
Account Information
- Email address (used to sign in and to identify you to household members you invite)
- Display name, if you provide one
- Password, stored only as a salted hash by our authentication provider — we never see or store it in plain text
- Account creation date and last sign-in time
Inventory and Household Data
- Product names, brands, barcodes and categories
- Expiration dates, quantities and storage locations
- Shopping list entries
- Household membership, invitations you send or accept, and household ownership
- Waste and consumption records (items marked used, wasted or expired)
AI Feature Data
- The inventory items and preferences sent with a recipe or meal plan request
- Dietary preferences, cuisine preferences and other options you choose
- Saved recipes and meal plans
- A daily counter of AI requests, used only to enforce the usage limit described in our Terms of Service
Voice Input Data
- Audio captured while you hold the voice-input button, and the text transcript produced from it
Voice input uses your device's built-in speech recognition. Depending
on your device and settings, Apple or Google may process the audio on
their servers rather than on the device. That processing is governed
by Apple's or Google's privacy policy, not ours. We receive only the
resulting text, which we send to our AI provider to turn into
inventory items. We do not store the audio.
Device and Technical Data
- Push notification token, device type and operating system version, if you enable notifications
- App version and language/region settings
- Crash reports and error diagnostics, including device model, OS version, and the app state at the time of the error
- Session replays for a small sample of app sessions (see below)
Session replay. Roughly 1 in 10 app sessions, and
sessions in which an error occurs, are recorded as a schematic replay
to help us diagnose bugs. All text and all images are masked before
the recording leaves your device, so the replay shows layout and
interaction, not the contents of your inventory. We have deliberately
disabled the option that would attach your email address or IP address
to these reports.
What We Do Not Collect
- We do not collect precise or approximate location data
- We do not collect contacts, photos, or files from your device
- We do not use advertising identifiers and we show no advertising
- We do not track you across other apps or websites
- We do not sell or rent personal data, and we do not share it with data brokers
3. Why We Use Your Data and Our Legal Basis
Under the GDPR, we rely on the following legal bases:
-
Performance of a contract — to create and maintain
your account, store your inventory, run household sharing, generate
recipes and meal plans, and provide expiration reminders. Without this
data the app cannot function.
-
Your consent — for camera access, microphone and
speech recognition access, and push notifications. Each is requested
separately and you can withdraw consent at any time in your device
settings.
-
Our legitimate interests — to keep the service
secure, prevent abuse, enforce usage limits, and fix crashes and bugs.
We balance this against your privacy by masking replay content and by
not attaching identifiers to diagnostic reports.
-
Legal obligation — to respond to lawful requests from
authorities.
4. Automated Processing
Recipes, meal plans and voice-to-inventory parsing are produced by an AI
model. This is automated processing, but it produces suggestions only.
It does not make decisions that have legal effects or similarly
significant effects on you, and no profiling is used for advertising or
for any decision about you.
5. Third-Party Services We Use
We use the following processors and services. Each receives only the
data needed for its function.
-
Supabase — database hosting, authentication and
backend functions. Stores all account, inventory, household and
shopping list data.
Privacy policy
-
OpenAI — generates recipes and meal plans and parses
voice transcripts into inventory items. Receives the ingredient list,
preferences or transcript text for the request. It does not receive
your email address, name or account identifier. OpenAI's API terms
state that data submitted through the API is not used to train their
models.
Privacy policy
-
Sentry — crash reporting, error diagnostics and the
masked session replays described above.
Privacy policy
-
Expo — delivers push notifications and app updates.
Receives your push token and device platform.
Privacy policy
-
Apple Push Notification service and Firebase Cloud
Messaging — deliver notifications to your device.
-
Apple and Google speech recognition — convert your
voice input to text, as described in section 2.
-
Open Food Facts — an open product database we query
with a scanned barcode to retrieve product name, brand and category.
It receives the barcode only, with no account information.
Privacy policy
-
Netlify — hosts this policy page and our terms page.
We may also disclose data when required by law or legal process, or to
establish or defend legal claims.
Shared Barcode Cache
When a barcode is looked up, the resulting product information (barcode,
product name, brand, category) is cached so that other users scanning
the same product get a faster result. This cache holds product facts
only. It contains no user identifier and cannot be traced back to who
scanned an item, and it is not deleted when you delete your account
because it holds no personal data.
6. International Transfers
Some of the services above are operated by companies in the United
States, so your data may be transferred outside the European Economic
Area. These transfers are made under the European Commission's Standard
Contractual Clauses or an equivalent approved safeguard, as set out in
each provider's data processing agreement.
7. How Long We Keep Your Data
-
Account, inventory, household and shopping data —
kept while your account exists, and deleted when you delete your
account.
-
Crash reports and session replays — retained by
Sentry under its default retention period (up to 90 days) and then
deleted automatically.
-
Voice audio — not retained by us at all. The
transcript exists only for the duration of the request.
-
Backups — deleted data may persist in encrypted
backups for up to 30 days before being overwritten.
8. Deleting Your Account and Data
You can delete your account and all associated personal data at any
time, directly in the app: open Account → Delete Account
and confirm. This is immediate and permanent.
Deleting your account removes your profile, inventory, shopping list,
saved recipes, meal plans, waste history, household memberships,
invitations and push tokens. If you own a household, transfer ownership
first if you want the household to survive; otherwise it is deleted with
your account. Deleted data cannot be recovered.
If you cannot access the app, email
verino.calis@gmail.com from
the address on the account and we will delete it for you.
9. Your Rights
If you are in the EEA or the UK, you have the right to access your data,
to correct it, to erase it, to restrict or object to its processing, to
receive a portable copy of it, and to withdraw any consent you have
given without affecting processing already carried out. These rights are
available to all our users regardless of where you live.
Use the in-app account settings, or email
verino.calis@gmail.com. We do
not charge for these requests and we will not discriminate against you
for making one.
You also have the right to lodge a complaint with a data protection
authority. In Croatia this is the Croatian Personal Data Protection
Agency (AZOP),
azop.hr. You
may also complain to the authority in your own country of residence.
10. Device Permissions
-
Camera — used only to read product barcodes. The
camera feed is processed on your device and no images or video are
stored or transmitted. The decoded barcode number is sent to Open Food
Facts to look up the product.
-
Microphone and speech recognition — used only while
you are actively using voice input, to add items by speaking. See
section 2 for where the audio is processed.
-
Notifications — used to remind you about items nearing
expiry and to tell you about household invitations. Never used for
marketing.
Every one of these permissions is optional and can be revoked in your
device settings. The app remains usable without them; only the related
feature stops working.
11. Security
We protect your data with:
- Encrypted transmission for all network traffic (HTTPS/TLS)
- Encryption at rest for stored data
- Row-level security policies, so one account cannot read another account's data at the database level
- Authentication tokens held in the device's secure keychain or keystore
- Server-side rate limiting on AI features to prevent abuse
- Regular dependency and security updates
No system is perfectly secure. If a breach affects your personal data and
poses a risk to your rights, we will notify you and the competent
supervisory authority without undue delay, and within 72 hours where the
GDPR requires it.
12. Age Requirement
Fridget is not intended for anyone under 16 years of age, and we do not
knowingly collect personal data from children. If you believe a child has
provided us with personal data, email
verino.calis@gmail.com and we
will delete the account and its data.
13. Changes to This Policy
We may update this policy from time to time. The "Last Updated" date at
the top always reflects the current version. If a change materially
affects how we handle your personal data, we will notify you in the app
or by email before it takes effect, and where the law requires it we will
ask for your consent again.
14. Contact Us
Questions, requests or complaints about this policy or your data:
verino.calis@gmail.com.
See also our
Terms of Service.