Privacy Policy
Last updated: 7 October 2026
This policy explains what Foodielyna collects, why, who else sees it, how long we keep it, and what you can do about it. We have tried to write it the way the app works: plainly.
1. Who we are
Foodielyna is run by PAGONA SOFTWARE S.R.L., a company registered in Romania (CUI 54857106, Trade Register no. J2026037502001), with its registered office at Str. Lt. Radu Beller Nr. 3-5, Sectorul 1, București 011701, Romania ("we", "us"). We are the controller of the personal data described here.
Questions, requests and complaints: support@foodielyna.com. We have not appointed a Data Protection Officer; every privacy request goes to that address and is answered by us.
This policy covers the Foodielyna app for iPhone, the Foodielyna web app (app.foodielyna.com) and our website foodielyna.com, together "Foodielyna".
2. The short version
- You can watch every video and read every recipe without giving us anything.
- To plan your week, the app creates an account for your device in the background. It has no name and no email until you choose to add one.
- The questions about your table (how many people, what you avoid, your kitchen, which nights you cook) are used to choose your dinners and build your shopping list. Nothing else.
- Allergies, and dietary needs such as no pork or gluten-free, can reveal your health or your beliefs. We keep them only if you tick the consent box, and you can remove them any time in your Profile.
- We do not sell your data, we do not show ads, and we do not use advertising or analytics companies. The statistics we look at are counted on our own server.
- You can download your data and delete your account from inside the app, at any time.
3. What we collect, and why
3.1 When you only browse
You can open the weekly set, watch the videos and read the recipes without an account. Our servers see the technical data every website sees (see 3.7). When someone opens the set without an account, we count it, with only the country and the week. A few steps of the sign-up path (for example "the questions were answered" or "the offer was shown") are also counted once per device, without an account and without anything that identifies you. These counts cannot point back to you.
3.2 Your account
When you set your table, the app creates a guest account for your device. It has a random identifier and no name or email. If you later choose Keep your week on every device, you add a way to sign in:
- Email code: your email address. We send you a 6-digit code that works for 10 minutes. We store the code only in hashed form.
- Sign in with Apple: Apple gives us an identifier and an email address. It can be a private relay address, if you choose to hide your email. If you choose to share it, Apple also gives us your name.
- Google (web app only): Google gives us your name, email address, whether it is verified, and a link to your profile picture.
From Google we keep only your Google account identifier; we do not keep the sign-in tokens Google issues. From Apple we keep the identifier and one token Apple issues (a refresh token), for one purpose only: when you delete your account, we use it to tell Apple to end Foodielyna's access to your Apple sign-in.
Why: to give you an account and keep your week on it. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
3.3 Your table
When you answer the questions about your table we store:
- how many adults (13 and over) and how many children eat. For children we keep a count, nothing about them;
- your diet and the foods you exclude, for example vegetarian or no pork;
- your allergies (see 3.4);
- your kitchen equipment, the nights you want to cook and the day you shop.
We also store your country. We do not ask for it: the app reads the region set on your phone or in your browser. We use it only to decide whether to show prices and budgets, which today exist only for Romania.
Profiles created with earlier versions of the app may also hold answers to questions we no longer ask (a budget, dishes you dislike, a preference for quick dinners). They are included in your export and deleted with your account.
Why: to choose the dinners in your set and your week, to size portions, and to build your shopping list and, where we have prices, its price estimate. Legal basis: contract (Art. 6(1)(b)), except for the data in 3.4.
3.4 Allergies and sensitive dietary needs: kept only with your consent
Allergies are health data, and some dietary needs can reveal your health or your religious beliefs. These are special categories of personal data under Art. 9 GDPR. We keep:
- the allergies you select (gluten, dairy, nuts, eggs, fish, shellfish, sesame, soy), and
- the dietary needs no pork, gluten-free, lactose-free and nut-free
only if you tick the box "Allergies are health data, and dietary needs like no pork or gluten-free can reveal your health or religious beliefs. Keep them on my Foodielyna profile so every set and every week is filtered by them." Our server refuses to save any of them without that consent. We record the moment you gave it.
Legal basis: your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR).
Withdrawing consent. In Profile, tap Withdraw consent. We then remove your allergies and those dietary needs from your profile, and delete the record of your consent. From then on your sets and weeks are no longer filtered by them. Withdrawing does not affect what we did before you withdrew.
Before you have an account, your answers, allergies included, are kept only on your device while you go through the questions. As soon as your account holds them, the device forgets them. If you stop halfway ("Not now"), they stay on your device so you do not have to answer again. Deleting the app, or clearing the site's data in your browser, removes them.
3.5 Your weeks, lists and cooking
We store the dinners in your weeks, your weekly sets, the dinners you mark "Not for me", the dinners you cook and whether you would have them again, your shopping lists and the items you tick. Why: this is the service, and it is also how your next set gets better. Legal basis: contract (Art. 6(1)(b)).
3.6 Your plan and purchases
We store whether you have a free trial or a subscription, which plan (yearly or monthly), where it came from (App Store, web or complimentary), when it started and when it ends. We also store when you tapped "Not now" on the offer, and the price that was on screen when you chose.
On iPhone, subscriptions are sold and billed by Apple. We never see your card or your Apple account details. To confirm and restore purchases we use RevenueCat (see 5). It receives your Foodielyna account identifier, never your name or email, and Apple's record of your purchases: product, dates, store, country and currency. Like any service the app talks to, it also receives the technical data that comes with a network request (IP address, device type, operating system and app version).
Legal basis: contract (Art. 6(1)(b)). Your plan's details are deleted with your account; Apple, as the seller, keeps its own purchase records under its own policy.
3.7 Technical data
- Sign-in sessions. For each signed-in session we store the IP address and the browser or app identification (user agent) it was opened from, with an expiry date. Sessions last 7 days and renew while you use the app. An expired session is deleted within a day. Why: security, for example recognising a session that is not yours, and limiting abuse. Legal basis: legitimate interest (Art. 6(1)(f)).
- Abuse limits. To stop automated abuse we count requests per account, per email address (for sign-in codes) and per network address (for sign-in). These counters live only in the server's memory for a short time and are never saved.
- Server logs. Our servers record technical request data (time, address requested, response, app version). These logs are rotated automatically: each service keeps at most about 30 MB of them, and older entries are overwritten, usually within a few days.
- Error reports. When something breaks on our server, it records the error, the route, the app version and your account identifier. We do not add your email, your name or the content of your requests. These records stay in the server logs described above.
- App version. The app tells our server which version it is, so we can keep old versions working and ask you to update when needed.
3.8 How the app is used (our own statistics)
We record moments such as "a week was planned", "a list was opened", "an item was ticked", "a trial started" or "data was exported", with a time and sometimes a count or a week. They are linked to your account while it exists, and they never contain your email, your name or your allergies. We use them to see whether the product works, for example whether people come back for a second week, and to fix what does not. They are counted on our own server; no analytics company receives them. A daily summary with totals only, never anything about one person, is sent to the founders through Telegram.
Legal basis: legitimate interest (Art. 6(1)(f)) in understanding and improving a product you use. You can object (see 8).
3.9 When you write to us
If you send us feedback through Foodielyna, we store your message, the screen you were on, the platform and the app version, linked to your account, and we delete it with your account. If you email support@foodielyna.com, we keep the conversation for as long as we need it to help you, and no longer than 24 months after it ends.
3.10 Support access
To fix a problem you reported, a member of our team can open the app as you see it, for a maximum of one hour. Each such access is recorded in an internal log with who did it and when. A support session cannot delete your account. Our team can also suspend an account that breaks the Terms, and record why. Legal basis: legitimate interest (Art. 6(1)(f)), and contract where you asked for help.
3.11 What we do not do
We do not use your data for advertising, we do not sell it, and we do not build a profile of you for anyone else. We do not make decisions about you that have legal or similarly significant effects by automated means. Choosing your dinners is automated, but it only decides what is suggested for your table.
The recipes in our library are prepared by our internal tools from creators' public videos, with the help of Google's Gemini AI. No data about you is ever sent there.
4. YouTube videos
Foodielyna shows creators' videos using YouTube API Services, through YouTube's official embedded player. By using Foodielyna you agree to be bound by the YouTube Terms of Service. Google's use of data is described in the Google Privacy Policy.
When a player loads, YouTube (Google) receives your IP address and information about your device, and may set cookies or use similar technologies, under Google's own terms. The player loads when you tap play, or automatically only after you have said yes to autoplay. You can withdraw that choice in your Profile, or at the end of the set. For videos marked "Made for Kids" we use YouTube's privacy-enhanced mode (youtube-nocookie.com). The page that holds the player is part of the app itself: no other website is involved in loading it.
Video thumbnails are loaded directly from YouTube's image servers (i.ytimg.com), so Google also receives your IP address when a screen with thumbnails appears. We never copy or store the videos or their thumbnails.
About the videos themselves, we keep the video's identifier and our own notes about the recipe. Other information we get from YouTube about a video or its channel, such as the creator's name or whether a video is made for kids, is refreshed or deleted within 30 days. We do not store view counts or subscriber counts.
Foodielyna does not ask for access to your YouTube or Google account through YouTube API Services. If you ever granted Foodielyna access to your Google account, you can revoke it at https://security.google.com/settings/security/permissions.
5. Who else receives data
We use a small number of service providers. They process data on our instructions, under contracts that include the GDPR's data-processing terms:
| Provider | What for | Data | Where |
|---|---|---|---|
| Hetzner Online GmbH | servers, database, encrypted backups | everything described above | Germany (servers in Nuremberg, backups in Falkenstein) |
| Cloudflare, Inc. | secure connection, protection from attacks, delivery of the web app and website | all traffic passes through it in transit, including IP address | global network, US company |
| Resend, Inc. | sending your sign-in code | your email address and the code | United States |
| RevenueCat, Inc. | confirming and restoring App Store purchases | account identifier, purchase records, request data (see 3.6) | United States |
| Apple | Sign in with Apple; App Store purchases | as described in 3.2 and 3.6 | United States / global |
| Google sign-in on the web; YouTube player and thumbnails | as described in 3.2 and 4 | United States / global |
For App Store purchases, Apple acts as the seller, under its own privacy policy. For videos, YouTube acts under its own terms. For Sign in with Apple and Google sign-in, those companies also act under their own terms.
We may disclose data where the law requires it, for example to a court or a public authority with a lawful request, or to protect our rights. If the company or the app is ever sold or merged, your data would pass to the new owner under this policy, and we would tell you first.
6. Transfers outside the EU
Our servers and database are in the EU. Some providers (Cloudflare, Resend, RevenueCat, Apple and Google) are based in the United States or process data there. Where data leaves the European Economic Area, we rely on the provider's certification under the EU–US Data Privacy Framework where it holds one, and otherwise on the European Commission's Standard Contractual Clauses in its data-processing terms. You can ask us for a copy of the relevant safeguards.
7. How long we keep data
| Data | How long |
|---|---|
| Guest account that never set a table | deleted automatically after 24 hours |
| Guest account with a table (no email or Apple sign-in added) | deleted automatically after 12 months without activity, unless an active trial, an App Store subscription or a complimentary plan stands behind it |
| Your account, table, weeks, lists, plan | until you delete your account |
| Allergies and sensitive dietary needs | until you withdraw consent or delete your account |
| Sign-in codes | 10 minutes, hashed |
| Sign-in sessions (IP, user agent) | 7 days, renewed while you use the app; an expired session is deleted within a day |
| Usage statistics (3.8) | linked to you while your account exists; afterwards kept with the link removed, as anonymous counts |
| Feedback messages | deleted with your account |
| Support emails | as long as needed to help you, at most 24 months after the conversation ends |
| Record that our support team deleted an account at your request | kept, with a one-way fingerprint (SHA-256) of the email instead of the email, as proof that we deleted it |
| YouTube data about videos and channels | refreshed or deleted within 30 days (see 4) |
| Backups | encrypted, kept 30 days, then deleted. Data you delete disappears from backups within 30 days. |
| Your customer record at RevenueCat (account identifier, purchase history) | deleted when you delete your account: we ask RevenueCat to delete it at the same moment. The subscription itself is Apple's and keeps billing until you cancel it in your iPhone's settings. |
8. Your rights
Under the GDPR you have the right to:
- access your data. Profile → Export my data gives you a file with your account, table, weeks, lists, cooked dinners, "Not for me" choices, offer choices, usage moments, your sign-ins (with IP address and device), your sign-in methods and your feedback messages. For anything not in the file, write to us;
- portability: the same export, in JSON, a machine-readable format;
- rectification: change your table in the app any time, or write to us;
- erasure: Profile → Delete account deletes your account and everything linked to it, straight away and for good (see 7 for backups). If you used Sign in with Apple, we also end Foodielyna's access to it at Apple. Deleting your account does not cancel an App Store subscription; cancel it in your iPhone's Settings → your name → Subscriptions. You can also ask us to delete your account by writing to support@foodielyna.com from the email address on the account;
- withdraw consent for allergies and sensitive dietary needs at any time (see 3.4);
- object to processing based on our legitimate interest, including our usage statistics;
- restriction of processing in the cases the GDPR provides.
Write to support@foodielyna.com. We answer within one month. We may ask you to confirm the request comes from you.
You can also complain to the Romanian data protection authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, https://www.dataprotection.ro), or to the authority in the EU country where you live.
9. Storage on your device and cookies
The app stores on your phone, or in your browser for the web app:
- your sign-in session. On iPhone it is kept in the phone's secure storage; on the web in a first-party cookie that only our site can read;
- your answers while you go through the questions (see 3.4);
- a copy of your week and list, so they work without a connection;
- small settings, such as your autoplay choice, your theme, which notices you have dismissed and the dinners you marked "Not for me" before you had an account;
- changes made while offline, until they reach our server.
These are necessary for the app to work, so they do not need your consent. We set no advertising or analytics cookies, and our website foodielyna.com sets no cookies at all. While the web app is in testing, access to it goes through Cloudflare Access, which sets its own sign-in cookie. Cloudflare may also set strictly necessary cookies of its own to protect our sites from bots and attacks. YouTube's player sets its own cookies, as described in 4.
10. Age
Foodielyna is for people aged 16 and over. We do not knowingly collect data from anyone younger. The number of children at your table is a count; we collect nothing about them.
11. Security
All traffic is encrypted in transit (HTTPS). Sign-in codes are stored hashed. On iPhone, sessions are kept in the phone's secure storage. Backups are encrypted (AES-256), with a key held by one person. Access to our internal tools is restricted to named team members and recorded. No system is perfectly secure. If a breach puts you at risk, we will tell you and the authority, as the law requires.
12. Changes
If we change this policy in a way that matters, we will tell you in the app before the change applies. The date at the top always shows the current version.
13. Contact
PAGONA SOFTWARE S.R.L., Str. Lt. Radu Beller Nr. 3-5, Sectorul 1, București 011701, Romania · support@foodielyna.com