Privacy Policy

Last Updated: July 4, 2026

1. Overview

CoFridge (the "App") is a fridge and pantry food-management app. You scan the expiry date and name on grocery packaging; the App uses AI to turn that into structured items, stores them locally on your device, and can optionally share an inventory with your family and answer questions through an in-app assistant. This policy explains what data we handle, why, and the legal basis for each use. CoFridge is operated by Rovina OÜ (Estonia), which acts as the data controller for the processing described here.

2. Data We Collect and Why

We keep data collection to what each feature actually needs:

3. Legal Bases for Processing

Under the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:

4. Third-Party Service Providers

We use a small number of processors to run the service. They act on our instructions and only receive the data needed for their function:

5. Your Rights

You have the right to access, correct, or delete your data, to restrict or object to processing (including the right to object to the legitimate-interest usage tracking in Section 3), to data portability, and to withdraw any consent you have given. Because we identify you only by a pseudonymous device UUID, please include that identifier (found in the App's Settings) when contacting us so we can locate the relevant records. To exercise any of these rights, contact us at the address below. You also have the right to lodge a complaint with your local data protection authority; in Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

6. Data Retention & Deletion

We keep each type of data only as long as it is needed, applying the principle of storage limitation:

After these periods, data is automatically deleted or irreversibly anonymized by scheduled background jobs, and backups are purged on a matching rolling schedule.

7. How We Protect Your Data

We apply appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, pseudonymous device identifiers instead of names or emails, role-based access controls that limit internal access to a need-to-know basis, audit logging of administrative access, and a least-privilege design. In addition, family-sync messages are end-to-end encrypted with a key that is shared only between your paired devices, so our relay servers pass them along without being able to read their contents.

8. Automated Processing

We use limited automated processing only to detect abnormal usage patterns and to enforce rate limits or usage caps. This may temporarily throttle or restrict AI features, but it produces no legal or similarly significant effects on you, and we do not carry out high-risk automated decision-making or profiling for advertising.

9. International Data Transfers

Some of our processors (for example OpenAI) are located outside the European Economic Area (EEA), which may involve transferring your data to countries such as the United States. Where this happens, we rely on appropriate safeguards under Chapter V of the GDPR — such as the European Commission's Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.

For privacy-related inquiries, please contact us at:
support@rovina.ee
Rovina OÜ, Vanakuu 2-8, Tallinn, Harjumaa, Estonia