RECIPE BOX & MEAL PLANNER
Privacy Policy.
1. Who we are
Recipe Box & Meal Planner (package com.codeensis.mealplanner, "the app") is an Android application published by CodeEnsis Ltd. ("we", "our", "us"), Χριστόδουλου Σώζου 2, EIFFEL TOWER, Floor 3, Flat/Office 301, 1096 Λευκωσία, Κύπρος. The app is a personal recipe library, a weekly meal plan (breakfast, lunch and dinner) and a shopping list. This policy explains what data the app handles and your rights under the EU General Data Protection Regulation ("GDPR").
2. Data stored on your device
Everything you enter - recipes, ingredients, cooking steps, categories, dish photos, meal plans, shopping list items and your settings - is stored on your device. You can use every feature of the app this way, offline and without signing in. If you never sign in, none of this content is transmitted to us or to anyone else, and we have no ability to access it. The usage and crash statistics described in section 5 never include it.
3. Photos and camera
You can attach a photo to a recipe by picking one from your gallery or taking one with your camera. The app opens the gallery or camera only when you tap the button to add a photo; it does not browse your photo library or use the camera in the background. The photo you choose is saved on your device and, if sync is on, uploaded to your cloud storage as described in section 4.
4. Optional sign-in and sync
Signing in is optional. Its only purpose is to sync your data between devices and keep a copy of it in the cloud. If you never sign in, nothing in this section applies to you.
How you sign in. You sign in with your Google account through Google's own sign-in screen, using Firebase Authentication. We never see your Google password.
What is processed when you sign in. Firebase Authentication processes your Google account email address, your display name, and a Firebase user ID assigned to your account.
What is synced. While you are signed in, your recipes (including their photos), your meal plans and your shopping list items are stored in Google Cloud Firestore under your Firebase user ID. Recipe photos are stored in Firebase Cloud Storage. This data is used only to keep your devices in sync and to restore your data when you sign in again.
Who handles it. Google, through Firebase, stores and processes this data on our behalf as our processor. We do not use it for any other purpose, we do not read it for marketing, and we do not share it with anyone else. Google may process it on servers outside your country; see the Firebase Privacy and Security notice for how Google protects it.
Signing out stops syncing. The data already on your device stays there, and the copy in the cloud stays under your account until you delete the account (section 9).
5. Usage and crash statistics
To find crashes and learn which features people use, the app uses Google Analytics for Firebase and Firebase Crashlytics, both under one switch: Settings → Usage & crash statistics.
When it is on. If your device's region is in the EU, the EEA, the UK or Switzerland, or cannot be determined, the switch starts off and nothing is sent until you turn it on. Elsewhere it starts on, and you can turn it off at any time; turning it off stops collection immediately.
What is sent. Analytics receives events describing how the app is used - for example that a recipe was saved (with counts such as the number of ingredients, and whether it has a photo), that a dish was added to the plan, or that a shopping list was built - together with a random app-instance identifier, device model, Android version, app version, language and an approximate country derived from your IP address. Crashlytics receives, when the app crashes or hits an error, a technical report: the stack trace, device model, Android and app version, free memory and disk space, and a random installation identifier.
What is never sent. The names, ingredients, steps, notes or photos of your recipes, the contents of your meal plan or shopping list, your email address or your Google account. Statistics are not linked to your sign-in account and are not used for advertising.
Retention. Crashlytics keeps crash reports for 90 days. Analytics event data is kept for at most 14 months and is then deleted automatically.
6. What the app does not do
- No advertising and no ad SDKs.
- No AI or other third-party processing of your recipes or photos.
- No payments or subscriptions.
- No access to your location or contacts.
- No selling, renting or sharing of your data with anyone.
7. Third-party services
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage) - only if you sign in, as described in section 4. See the Firebase Privacy and Security notice and the Google Privacy Policy.
- Google Analytics for Firebase and Firebase Crashlytics - usage and crash statistics, as described in section 5, only while the switch in Settings is on. See the Firebase Privacy and Security notice.
- Google Play - app installation and updates are handled by Google Play under Google's own policies.
8. Permissions
The app does not request access to your location, contacts or microphone. Taking a photo hands off to your device's camera, and picking one uses Android's photo picker - in both cases only when you tap the button, and only the single photo you choose comes back to the app. Signing in and syncing use your internet connection.
9. Data retention and deletion
On your device. Your data stays on your device until you delete it. Deleting a recipe, plan or list item removes it; uninstalling the app or clearing its data in Android settings removes everything the app stored on the device.
In the cloud. If you signed in, your synced data is kept for as long as your account exists. To delete it, open Settings → Delete account in the app. This permanently deletes all your cloud data - your Firestore documents and your photos in Cloud Storage - and your Firebase Authentication account. Data on the device itself is not removed by this step; it stays there until you delete the app or its data.
If you no longer have the app installed, you can ask us to delete your account by email. See how to delete your account; we process these requests within 30 days.
10. Children
Recipe Box & Meal Planner is a general-audience cooking and planning tool and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Legal basis (GDPR) and your rights
Data kept only on your device never reaches us, so the rights of access, rectification and erasure over it are satisfied directly on your device, where you can view, edit and delete everything.
If you sign in, we process your account details and synced data to provide the sync feature you asked for, on the legal basis of performance of a contract, Art. 6(1)(b) GDPR. You can stop this at any time by signing out, and end it completely by deleting your account.
Usage and crash statistics are processed on the basis of your consent, Art. 6(1)(a) GDPR, in the EU, EEA, UK and Switzerland, and of our legitimate interest in keeping the app working and improving it, Art. 6(1)(f) GDPR, elsewhere. In both cases you can withdraw at any time with the switch in Settings.
You may contact us to exercise your rights of access, rectification, erasure, restriction, portability or objection, and you may lodge a complaint with your local data protection authority.
12. Security
Data on your device is protected by your device's own security (lock screen, encryption); we recommend keeping your device secured. Synced data travels to Firebase over encrypted connections and is stored under your own user ID, separate from other users' data.
13. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new "Effective" date above. If we ever add a feature that changes what data leaves your device, this policy will be updated before that feature ships.
14. Contact
Privacy questions or requests: [email protected]. A human reads every message.