CoFridge (the "App") is a fridge and pantry food-management app. You scan the expiry date and name on grocery packaging; the App uses AI to turn that into structured items, stores them locally on your device, and can optionally share an inventory with your family and answer questions through an in-app assistant. This policy explains what data we handle, why, and the legal basis for each use. CoFridge is operated by Rovina OÜ (Estonia), which acts as the data controller for the processing described here.
2. Data We Collect and Why
We keep data collection to what each feature actually needs:
Device Identifiers (UUIDs & push tokens): The App generates a random device identifier (UUID) and a push (FCM) token. These are stored on a secure database to route sync messages between paired family devices, and they serve as the pseudonymous key for the usage tracking described below. They are not linked to your name, email, or account.
Food & Inventory Data: If you enable AI features or family sharing, the items you scan (name, expiry date, storage location, category) are mirrored to a secure database so the assistant, recipe suggestions, and family members can work with them. If you do not enable these features, your food data stays on your device and is not uploaded.
AI Usage Metadata (per-user usage tracking): Every time you use an AI-powered feature (scanning, product translation, image recognition, recipe suggestions, or the in-app assistant), we record technical metadata about that request — the AI model used, token counts, response time, and the resulting cost — associated with your pseudonymous device identifier (UUID). This metadata does not include your product names or any food content. We use it to monitor and control our operating costs and to detect and prevent abuse: users whose usage is abnormally high may have rate limits applied so the service stays available and affordable for everyone. For security and abuse detection we may also process limited technical signals such as your IP address and session identifiers; these are kept only briefly (see Section 6) and are not used to build a profile of you. The legal basis is our legitimate interest (see Section 3), and you are informed of this the first time you use the App.
Product Translation Cache: To avoid re-translating the same grocery product for every user, the App caches generic product translations (product name, category) keyed by barcode or product name. This cache is a shared dictionary of common products; it is not linked to you or your device.
Purchase & Subscription Data: If you buy CoFridge Pro, our server stores the Google Play purchase token, the plan type, its expiry date, and your pseudonymous device identifier in a secure database, solely to verify your purchase and prevent fraud. All payments are processed by Google Play; we never receive or store your payment card details.
Optional Product Analytics (consent-based): Separately from the usage tracking above, the App can collect anonymous product-usage events (e.g. which features are used, inventory counts) to help us improve the App. This is strictly opt-in: nothing is collected unless you agree, and you can turn it off any time in Settings. No product names or personal content are sent.
3. Legal Bases for Processing
Under the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:
Performance of a contract (Art. 6(1)(b)): Processing your food data, device identifiers, and sync messages to provide the core features you ask for — scanning, storage, family sharing, and the AI assistant.
Legitimate interests (Art. 6(1)(f)): We process per-user AI usage metadata (linked to your device UUID) for cost control and abuse prevention — including applying rate limits to abnormally high usage — based on our legitimate interest in keeping the service secure, reliable, and financially sustainable. This metadata contains no food content, and you have the right to object to this processing at any time (see Section 5).
Consent (Art. 6(1)(a)): Optional product analytics are collected only if you opt in, and you can withdraw consent at any time in Settings without affecting the App's core features.
4. Third-Party Service Providers
We use a small number of processors to run the service. They act on our instructions and only receive the data needed for their function:
OpenAI: Processes the text or image you scan to extract product information and generate recipe suggestions. Requests are relayed through our server; the App itself does not hold any AI keys.
Google Firebase (Cloud Messaging): Delivers push messages that keep paired family devices in sync.
PostHog: Stores the AI usage metadata (Section 2) and, if you opt in, the anonymous product analytics.
Google Play Billing: Processes subscription payments and provides the purchase token we use to verify your plan.
Telegram: If you choose to link CoFridge to a Telegram bot, messages you send to that bot (and the assistant's replies) are relayed through the Telegram Bot API so the assistant can work in Telegram as well as in the App. Telegram is only involved if you set up this optional feature.
5. Your Rights
You have the right to access, correct, or delete your data, to restrict or object to processing (including the right to object to the legitimate-interest usage tracking in Section 3), to data portability, and to withdraw any consent you have given. Because we identify you only by a pseudonymous device UUID, please include that identifier (found in the App's Settings) when contacting us so we can locate the relevant records. To exercise any of these rights, contact us at the address below. You also have the right to lodge a complaint with your local data protection authority; in Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
6. Data Retention & Deletion
We keep each type of data only as long as it is needed, applying the principle of storage limitation:
Food & inventory data: retained while your family group is active. Leaving the group or uninstalling the App removes your device from the group and stops further processing; residual mirrored data is deleted or irreversibly anonymized within 30–90 days.
Real-time rate-limit counters: up to 24 hours (rolling window).
Raw AI usage and security logs: up to 30 days for debugging and abuse detection; security logs may be kept up to 90 days.
Aggregated usage & billing records: up to 12–24 months, in aggregated or pseudonymized form, for cost accounting and dispute resolution.
Purchase verification records: kept only while your subscription is active and removed by periodic cleanup once no longer needed.
Product-translation cache: holds no personal data and is retained to benefit all users.
After these periods, data is automatically deleted or irreversibly anonymized by scheduled background jobs, and backups are purged on a matching rolling schedule.
7. How We Protect Your Data
We apply appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, pseudonymous device identifiers instead of names or emails, role-based access controls that limit internal access to a need-to-know basis, audit logging of administrative access, and a least-privilege design. In addition, family-sync messages are end-to-end encrypted with a key that is shared only between your paired devices, so our relay servers pass them along without being able to read their contents.
8. Automated Processing
We use limited automated processing only to detect abnormal usage patterns and to enforce rate limits or usage caps. This may temporarily throttle or restrict AI features, but it produces no legal or similarly significant effects on you, and we do not carry out high-risk automated decision-making or profiling for advertising.
9. International Data Transfers
Some of our processors (for example OpenAI) are located outside the European Economic Area (EEA), which may involve transferring your data to countries such as the United States. Where this happens, we rely on appropriate safeguards under Chapter V of the GDPR — such as the European Commission's Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.
For privacy-related inquiries, please contact us at: support@rovina.ee Rovina OÜ, Vanakuu 2-8, Tallinn, Harjumaa, Estonia