Privacy policy

Last updated: 29 September 2026
This is a translation of the German Datenschutzerklärung. The German version is binding and prevails in case of any difference. German law applies.

This policy explains which personal data we process when you use the BianCuisine app for iOS and Android or the website biancuisine.com: for what purpose, on what legal basis, who receives it, how long we keep it and what rights you have.

In short

  • BianCuisine requires an account with an email address and a password.
  • Your cookbook, plans and journal are private. Only what you publish yourself or share in a household becomes visible to others.
  • Your content is stored on servers in Frankfurt am Main, Germany.
  • No advertising, no tracking, no analytics tools, no selling of data.
  • AI features only run when you start them. Only then is the data they need sent to OpenAI. We do not store your photos.
  • You can delete your account in the app at any time: More → Account → Delete account.

1. Controller and contact

The controller responsible for processing your personal data under the General Data Protection Regulation (GDPR) is:

Amed Bozo (sole trader)
Moritzstraße 43
65185 Wiesbaden
Germany
Email: [email protected]

For privacy questions and to exercise your rights, write to us at [email protected]. More details about the provider are in the imprint.

2. This website

The website biancuisine.com is hosted by Cloudflare (Cloudflare Pages). When you visit it, Cloudflare processes technically necessary data on our behalf: your IP address, date and time, the requested address, where applicable the page you came from, and information about your browser and operating system. This is needed to deliver the pages and to protect them against attacks and abuse.

The website sets no cookies, uses no analytics or tracking tools and loads no content from other servers, such as fonts or scripts. Links to other websites only open when you tap them; the privacy notices of the respective provider apply there.

Legal basis
Art. 6(1)(f) GDPR. Our legitimate interest is to provide the website securely and reliably.
Recipients
Cloudflare (section 15, section 16).
Retention
Cloudflare keeps this data only for a limited time for security purposes. We do not analyse it to identify visitors or to build profiles.

3. Account and sign-in

You need an account to use BianCuisine. For this we process:

  • your email address and your password; we store the password only as a hash from which it cannot be recovered,
  • an internal account ID, the times of registration, confirmation and last sign-in, and the language in which you receive emails from us,
  • your sign-ins: device type (e.g. iPhone or Android device), time of sign-in and of last activity, and technical details such as IP address and app identifier (user agent). Under More → Account → Signed-in devices you can see where you are signed in and sign devices out,
  • log data created whenever our servers are accessed, such as IP address, time and type of request.

Emails about your account, that is, to confirm your email address and to reset your password, are sent from [email protected] via Cloudflare’s email sending service. The links in them lead back to the app via our app link pages (links.biancuisine.com and open.biancuisine.com, also hosted by Cloudflare). The emails contain our logo, which is loaded from our server when you open them; as with any request, your IP address is processed. We do not analyse whether or when you open an email. We do not send newsletters or advertising emails.

So that you stay signed in, the app stores your sign-in session on your device (section 12).

Purpose
Providing your account, secure sign-in, restoring access, preventing abuse.
Legal basis
Art. 6(1)(b) GDPR (contract). For log data Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation.
Required data
Without an email address and password, no account can be created and BianCuisine cannot be used.
Recipients
Supabase (hosting) and Cloudflare (email sending, app link pages).
Retention
Until your account is deleted. Sign-ins: until you sign out or they expire. Log data: only as long as we need it for security and troubleshooting.

4. Cookbook, recipes and photos

We store what you create in your cookbook: recipes with title, description, ingredients, steps, times, servings, difficulty, language, origin, categories, tags, dietary labels, allergens, source and nutrition values, up to five photos per recipe, collections, favourites, saved and archived recipes, and your personal ingredients, including barcodes and nutrition values.

This content is private. Others only see it if you publish a recipe (section 9) or share a recipe version in a household (section 5).

You choose photos in your device’s system photo picker. The app only receives the photos you select there and has no access to the rest of your photo library. Before uploading, it removes metadata such as location and capture time and reduces the image size.

If you suggest a missing cuisine, category, dietary label or allergen, we store the suggestion to review it and, where appropriate, add it for everyone.

Legal basis
Art. 6(1)(b) GDPR.
Retention
Until you delete the content or your account. Suggestions: until your account is deleted.

5. Weekly plan, shopping list and household

We store your weekly plans and shopping lists. You can use them on your own or share them with others in a household.

Visible in the household are the household’s name, the name you use there, your profile photo if you have one, your role, the shared plan with its portions, the shopping list and the recipe versions selected for the plan. The rest of your cookbook, your recipe photos and your journal stay private.

Invitations: You need Plus to invite someone. You enter the email address of an existing BianCuisine account. We only use it to find that account and store the invitation with the account, not with the email address. The app shows you a code once, which you pass on yourself; we do not send an email for this. The code is valid for seven days.

Suggestions (Plus): BianCuisine calculates week-plan suggestions from your own and saved recipes and your daily goal. “What can I cook?” looks for recipes in your cookbook and in Discover that match the ingredients you select. Both work without AI, and no data is passed to third parties. You see a week-plan suggestion before anything is saved.

If you own a household and delete your account, the household with its plan and shopping list is deleted as well, unless you transfer ownership first. Recipe versions shared in a household remain available to its other members if you leave the household or delete your account; when your account is deleted, their link to your account is removed.

Legal basis
Art. 6(1)(b) GDPR. For looking up the invited person’s account also Art. 6(1)(f) GDPR; our legitimate interest is matching invitations to the right account.
Retention
Until you delete plans, lists or the household, leave the household or delete your account. Invitations: until the household or the invited account is deleted.

6. Nutrition journal and daily goals

In the journal we store your entries: foods, recipe portions or your own entries with amount, meal, date and nutrition values, as well as where the values come from, for example a database, a barcode or a photo estimate. In addition, we store the daily goals you set yourself. From this, the app calculates daily totals and the weekly review; if you have set a calorie goal, “Today” shows a short summary.

Only you can see your journal; members of your household cannot.

Nutrition data is personal. That is why BianCuisine does not ask for your weight, illnesses or diagnoses, does not calculate or recommend goals, and uses your journal and goals only for the features you see in the app, not for advertising, profiles or analyses. Please do not enter health information such as diagnoses in the names of entries.

Consent: The journal is optional. Because what you eat can allow conclusions about your health, the app asks for your explicit consent before you use it for the first time. We store that and when you consented and which version of the notice you saw, so that we can prove your consent. You can withdraw it at any time under More → Privacy & security. We then delete your journal with all entries and goals and switch automatic entries off. This does not affect the lawfulness of the processing before the withdrawal.

You can also hide the journal under More → Settings → Areas and delete individual entries at any time.

Automatic entries (Plus): If you switch them on in the settings, the app adds planned meals you take part in to your journal, even when someone else in your household plans them. For this we store your setting and your device’s time zone. The feature is off by default, requires your journal consent, and only you can switch it on. Other members see neither your goals nor your entries.

Legal basis
Your explicit consent, Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR. For the proof of consent, Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
Retention
Until you delete entries or goals, withdraw your consent or delete your account. The proof of consent until you withdraw it or delete your account.

When you search for foods or scan or enter a barcode, our server searches the German Food Code and Nutrient Database (Bundeslebensmittelschlüssel, BLS), which we host ourselves, and queries the open food database Open Food Facts. If your country is the United States, it also queries FoodData Central, the database of the U.S. Department of Agriculture (USDA). These requests are made by our server, not by your device. Open Food Facts and USDA only receive the search text or barcode, country and language, neither your IP address nor any details about your account.

We cache search results for a limited time without any link to your account so that later requests are faster. If you add a product, we store its details, such as name, nutrition values and barcode, in your cookbook, your ingredients or your journal.

Barcode scanner: The camera is only active while the scanner is open. Your device recognises the barcode itself; camera images do not leave it. On Android, the app uses Google’s ML Kit library for this. ML Kit sends technical usage and diagnostic data to Google, such as device and app information, identifiers, and performance and error data. According to Google, it uses this data to measure, maintain and improve ML Kit and to detect misuse. Google does not receive camera images or recognised barcodes.

Legal basis
Art. 6(1)(b) GDPR. For ML Kit’s diagnostic data Art. 6(1)(f) GDPR; our legitimate interest is reliable barcode recognition directly on the device.
Recipients
Open Food Facts and USDA (without details about your account), Google (Android only).
Retention
Added products: until you delete them or your account. Cached search results: for a limited time. ML Kit diagnostic data: according to Google’s rules.

8. AI features

Three features use artificial intelligence (AI) from OpenAI. They only run when you start them. Our server then sends OpenAI only the data needed for the task, never your name or email address.

Photo estimate

In the journal, you can photograph a meal in the app or choose a photo in the system photo picker and have calories, protein, carbohydrates and fat estimated.

  1. You see the photo before it is sent. The app removes metadata such as location and capture time and reduces the image size.
  2. Our server sends the photo to OpenAI once and receives an estimate.
  3. You review and change the values. Only what you confirm is saved, as an entry in your journal.

We do not store the photo, not in the journal, not in our database and not in our photo storage. When you take or select a photo, your device may create a temporary file; the app tries to delete it after processing.

Please photograph only food, no people and no personal information such as documents or screens.

Recipe import

From a link: Our server loads the public web page. If it contains structured recipe data, as most recipe pages do, the server reads the recipe directly, without AI. Otherwise it sends the text of the page to OpenAI to recognise the recipe. The website only sees a request from our server, not your IP address.

From a photo of a printed recipe, such as a cookbook page: The photo is sent to OpenAI to recognise the recipe. We do not store it.

In both cases, a recipe draft is created in your cookbook, which you review, change or delete. For a link, we keep the link as the source; we do not copy photos from the website.

Shopping list by store area

To sort your shopping list by store area, such as fruit and vegetables or the chilled section, our server sends only the names of new items to OpenAI. We store the result so that the same name does not have to be sent again.

At OpenAI

Our contracting party is OpenAI Ireland Ltd. (address in section 15). Processing may also take place in the USA. We send requests with the setting store: false, so OpenAI does not store the responses for later retrieval. However, OpenAI may keep requests and responses for up to 30 days to detect abuse, and longer only where this is required by law or necessary to protect OpenAI’s services or third parties from harm. According to OpenAI, data from the API is not used to train AI models by default. With the requests we send a pseudonymous identifier, a hash derived from your account ID, so that OpenAI can detect abuse. It does not tell OpenAI who you are.

AI results can be wrong. You review them before you use them. We do not use them to make decisions about you.

Usage limits: Without Plus, you can use up to three photo estimates within any seven days and up to three recipe imports within any 30 days. Technical limits against abuse also apply to all accounts. For this we store when you used these features, without any image or content.

Legal basis
Art. 6(1)(b) GDPR, because you request the feature. For the photo estimate in the journal also your journal consent (section 6, Art. 9(2)(a) GDPR). For the usage limits also Art. 6(1)(f) GDPR; our legitimate interest is limiting abuse and costs.
Recipients
OpenAI (section 15, section 16).
Retention
Photos: not stored by us; at OpenAI up to 30 days, longer in the exceptional cases mentioned. Imported recipes and confirmed journal values: until you delete them or your account. Assignments of items to store areas: without any link to your account, for as long as we offer the feature. Usage counters: until your account is deleted.

9. Profile, publishing and community

Your creator profile consists of a display name and, if you like, a short bio and a profile photo. Others can find it once you publish a recipe.

Publishing

Publishing recipes is optional. For this we create a separate public version with the photos you select; your private original stays private. Published recipes and your creator profile are visible to all users of the app: in Discover, in search, in feeds and on your profile. Others can save them, mark them as favourites, add them to their plan and cook them. You can withdraw a publication at any time; recipe versions that others have already added to their plan remain there.

Likes, follows and recognition

The number of likes on published recipes is visible. The “Followers” and “Following” lists are visible on public creator profiles. Saved recipes and favourites are private.

From your published recipes, likes from others, how long you have been a member and rankings, the app determines recognition such as badges and frames. You decide which of them appear on your profile.

“For you”

This view in Discover sorts published recipes in your recipe languages by how new they are, whether you follow the creator or have already liked recipes by them, and how many likes they have received recently.

Blocking

If you block a creator, neither of you sees the other’s public recipes and profile any more, and existing follows are removed. For this we store your block list. You can find it under More → Privacy & security → Blocked creators.

Legal basis
Art. 6(1)(b) GDPR.
Retention
Until you change your details, withdraw a publication, delete content or delete your account.

10. Reports and moderation

You can report published recipes and creator profiles in the app. We then store the reported content, the reason, your optional description, your account and the time. Anyone can also send notices of illegal content by email to [email protected]; in that case we process the name, email address and content of the notice.

Every report is reviewed by a person. If we take action, we inform the affected person and give reasons. We only name the person who reported if this is strictly necessary, for example when rights holders report a copyright infringement. We inform the person who reported of our decision.

If we become aware of information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of persons, we inform the competent authorities (Art. 18 Digital Services Act).

Legal basis
Art. 6(1)(c) GDPR in conjunction with Art. 16 to 18 of Regulation (EU) 2022/2065 (Digital Services Act). Also Art. 6(1)(f) GDPR; our legitimate interest is a safe community and the defence of legal claims. For the report function in the app Art. 6(1)(b) GDPR.
Retention
Reports: until the reporting or the reported account is deleted. Moderation decisions: until the affected account is deleted, so that we can document decisions and recognise repeated violations. Reports by email: as in section 14.

11. BianCuisine Plus and purchases

You buy Plus in the Apple App Store or on Google Play. Apple or Google handle the purchase and payment under their own responsibility; their privacy notices apply to this. We do not receive payment details such as card numbers.

To verify purchases, we use RevenueCat. The app and our server send RevenueCat a pseudonymous identifier, namely your internal account ID without your name or email address, and the stores’ purchase receipts. RevenueCat verifies them with Apple or Google and tells our server whether and until when you have Plus. In doing so, RevenueCat processes purchase data, such as product, store, purchase, renewal and expiry dates, status and transaction numbers, as well as technical connection data such as IP address, operating system, app version and store country.

In our database we store whether you have Plus, with store, product and expiry date, and when you used free photo estimates and recipe imports. Apple and Google also provide us with sales reports, for example with order number, date, product, price and country, which we keep for our accounting.

Legal basis
Art. 6(1)(b) GDPR. For accounting Art. 6(1)(c) GDPR in conjunction with retention obligations under tax and commercial law. For purchase data at RevenueCat after your account is deleted Art. 6(1)(f) GDPR; our legitimate interest is being able to trace purchases, renewals and refunds.
Recipients
Apple, Google and RevenueCat (section 15, section 16).
Retention
Plus status: until your subscription ends, at the latest until your account is deleted. Usage counters: until your account is deleted. Purchase data at RevenueCat: as long as we need it for purchases, renewals, refunds and legal obligations, also beyond the deletion of your account; on request, we have it deleted earlier unless we are required to keep it. Sales reports: for the statutory retention periods of up to ten years.

12. Data on your device and widgets

On your device, the app stores:

  • your sign-in session in the operating system’s protected storage (Keychain or Keystore) so that you stay signed in,
  • some device settings, such as your start screen,
  • if you use widgets (Plus): a display copy for the widgets with today’s calories and goal, the next planned meal and the open items on your shopping list. The app updates it when something changes and deletes it when you sign out. Widgets do not fetch any data themselves and send nothing to us.

Keep in mind: widgets are visible to anyone who sees your screen.

The app does not store the rest of your content permanently on the device; it loads it over the internet when needed. Temporary files may briefly be created when you take or select photos.

This storage is strictly necessary for the features you use (Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG).

Permissions

The app only uses the camera when you open the barcode scanner or take a photo in the app, for example for the photo estimate. It only receives photos through the system photo picker. The app does not use the microphone, contacts, location or push notifications. It suggests your country based on your device’s region setting.

13. Settings

We store your settings in your account, for example app language, country, recipe languages, units, visible areas, appearance and cooking settings such as automatically starting timers. We use your country to show products from your country first in the food search; your recipe languages determine which recipes you see in Discover.

Legal basis
Art. 6(1)(b) GDPR.
Retention
Until you change them or delete your account.

14. Contact by email

When you write to us, we process your email address, your name if given, the content of your message and any attachments in order to handle your request. Cloudflare (Cloudflare Email Routing) forwards emails sent to [email protected] to our mailbox at Google Workspace, where we store and handle them.

Legal basis
Art. 6(1)(b) GDPR if it concerns your account or BianCuisine. Art. 6(1)(c) GDPR for notices under the Digital Services Act and for requests about your data protection rights. Otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering requests.
Recipients
Cloudflare (forwarding) and Google (mailbox at Google Workspace), see section 15 and section 16.
Retention
We delete messages when we no longer need them, at the latest two years after the last contact. Longer only if we are required by law to keep them or need them to establish or defend legal claims.

15. Recipients and service providers

We only share personal data where this is necessary for the purposes described. Service providers that process data on our behalf are contractually bound by our instructions (Art. 28 GDPR).

Supabase
Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992. Database, sign-in, file storage and server functions of the app. Data location: Frankfurt am Main, Germany. Processor; the data processing agreement is part of Supabase’s terms.
Cloudflare
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Hosting of this website and the app link pages, sending the emails about your account, forwarding emails sent to [email protected], and separate storage for the deletion journal (Cloudflare R2, located in the EU). Processor.
OpenAI
OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. AI features, only when you use them. Processor; processing may also take place in the USA.
RevenueCat
RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. Verifying purchases of BianCuisine Plus. Processor.
Google Workspace
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Mailbox in which we store and handle emails sent to [email protected]. Processor; Google’s data processing terms apply (Cloud Data Processing Addendum).
Apple and Google
Distribution of the app and purchase and payment of Plus, each under their own responsibility. Depending on your device settings, they also provide us with aggregated statistics and crash reports without names, which we use to fix errors (Art. 6(1)(f) GDPR; our legitimate interest is an app that works without errors).
Google ML Kit (Android only)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Usage and diagnostic data from barcode recognition, under Google’s own responsibility (section 7).
Open Food Facts and USDA FoodData Central
Open Food Facts, 21 rue des Iris, 94700 Maisons-Alfort, France, and the U.S. Department of Agriculture (USDA). They only receive search texts or barcodes, country and language from our server, no details about your account.

Other users see what you publish or share in a household (section 5, section 9). Authorities only receive data where we are legally obliged to provide it (Art. 6(1)(c) GDPR).

16. Transfers to third countries

We store your content in the EU. Some service providers are based outside the EU or may process data there. This only happens if the requirements of Art. 44 et seq. GDPR are met:

  • Cloudflare, RevenueCat and Google (USA): They are certified under the EU-U.S. Data Privacy Framework. The European Commission’s adequacy decision of 10 July 2023 applies to them (Art. 45 GDPR). The data processing agreements with Cloudflare and RevenueCat additionally contain the EU standard contractual clauses (Art. 46(2)(c) GDPR).
  • Google Workspace: Our contracting party is Google Ireland Limited. Where Google transfers data to Google LLC in the USA, the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, in addition, the EU standard contractual clauses in Google’s Cloud Data Processing Addendum (Art. 46(2)(c) GDPR) apply.
  • OpenAI: For processing in the USA, the EU standard contractual clauses in OpenAI’s data processing agreement apply.
  • Supabase: Supabase is based in Singapore. For access from outside the EU, for example for operations and support, and for server functions executed outside the EU, the EU standard contractual clauses apply.

If other service providers process data outside the EU, this likewise only happens on the basis of an adequacy decision or the EU standard contractual clauses. You can request a copy of the standard contractual clauses from us.

17. Retention, backups and deletion journal

In general, we keep your data as long as your account exists. You can delete individual content yourself at any time. Specific periods are listed in the relevant sections.

Backups: So that we can restore data after technical failures, we back up the database and photos daily in encrypted backups in the EU. They are overwritten after seven days.

Deletion journal: So that an account deletion stays effective even after a restore from a backup, we keep a minimal, encrypted deletion record for each deletion. It essentially contains the internal account ID and the time, but no email address, recipes, photos or other content. It is stored separately from the database at Cloudflare R2 in the EU and deleted after 35 days. We also log completed deletions without content for 35 days.

Legal basis
Art. 6(1)(f) GDPR; our legitimate interest is reliable restoration. For the deletion journal Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR, so that deletions stay effective.

18. Deleting your account

This is how you delete your account for the BianCuisine app (on Google Play by the developer “Noshi Systems”) together with all related data:

In the app: More → Account → Delete account. You confirm the deletion with your password. After that, it continues automatically on our servers, even if you close the app. It is usually completed within 24 hours.

Without the app: Write to us at [email protected] from your account’s email address. To make sure nobody else deletes your account, we may ask you to confirm the request.

What is deleted: your account with email address and password, your profile, recipes, photos, collections, favourites, saved recipes and personal ingredients, your plans, shopping lists, journal entries, goals, settings and sign-ins, your likes, follows, blocks and reports, your household membership and your Plus status. Published recipes are withdrawn and their public photos deleted. If you own a household, it is deleted together with its plan and shopping list unless you transfer ownership first.

What remains:

  • recipe versions in other households’ plans, without a link to your account,
  • the deletion record and the log of the deletion for 35 days,
  • backups until they are overwritten after seven days,
  • data at OpenAI within its retention of up to 30 days,
  • purchase data at RevenueCat (section 11) and data we are legally required to keep,
  • emails you have sent us (section 14).

Subscription: Deleting your account does not end a Plus subscription. Cancel it first in the App Store or on Google Play.

19. Your rights

You have the right to

  • access your data (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR) and
  • withdraw consent with effect for the future (Art. 7(3) GDPR), where we process data on the basis of consent.

You can view, change and delete much of your data directly in the app. For everything else, an email to [email protected] is enough. We reply within one month and may ask you to confirm your identity.

Right to object

Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Right to lodge a complaint: You can lodge a complaint with any data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany

20. Further information

Minimum age

BianCuisine is intended for people aged 16 and over. Younger people may only use BianCuisine with the consent of their parents or other legal guardians. If a child has created an account without this consent, the parents can contact us; we will then delete the account.

Required data

For an account we need your email address and a password; without them you cannot use BianCuisine. All other information is optional. Without it, some features are not available.

No automated decisions

We do not make automated decisions within the meaning of Art. 22 GDPR. AI results are suggestions that you review and change.

No advertising, no tracking

We show no advertising, use no analytics or tracking tools, do not track you across other apps or websites and do not sell data.

Security

Connections between the app, the website and our servers are encrypted. We store passwords only as hashes. On the server, private content is assigned to your account and protected by access rules against retrieval by others. Backups are encrypted. We continuously adapt our technical and organisational measures; however, no system can offer complete security.

Changes

We update this privacy policy when the app, our service providers or the law change. We inform you of significant changes in the app or by email. The version published here applies.