Last updated: August 21, 2026. Information provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). In short: Your data is used to run your household’s calendar. It is never sold. You can view, correct, and delete it at any time.

1. Data Controller Gwenaëlle Papin EI (Boost Vitrine) — Individual Entrepreneur, micro-entrepreneur scheme, 2 Place Jean V, Bureau 3, 44000 Nantes, France. Email: gwen@foodrop.org No Data Protection Officer has been designated, as designation is not mandatory given our processing activities. gwen@foodrop.org is the contact point for any questions regarding your data.

2. Data Processed and Legal Bases Each category of data relies on a specific legal basis.

  • 2.1. Account and Identity — Performance of a contract (Art. 6.1.b)
    • email address
    • password (hashed, never stored in plain text)
    • first name displayed in the household
    • profile picture, if you add one
  • 2.2. Household and Membership — Performance of a contract (Art. 6.1.b)
    • household identifier, role (administrator or member)
    • list of household members
  • 2.3. Household Contents — Performance of a contract (Art. 6.1.b)
    • calendar events: title, dates, notes, concerned member, meal indicators
    • attachments to events (images, PDF)
    • shopping list items
    • meal checkboxes
  • 2.4. Data from FooDrop — Performance of a contract
    • expiration dates of your fridge items, for alerts
    • planned dishes in your menus
    • This data is not duplicated: it is read directly from your FooDrop space.
  • 2.5. Interactions with Komi the Assistant — Performance of a contract
    • your messages and the context transmitted to answer them (date, members’ first names, items to consume)
  • 2.6. Subscription — Performance of a contract
    • subscription status and expiration date
    • no banking data: payment is processed by the App Store or Google Play, to which we do not have access.
  • 2.7. Technical Preferences — Legitimate interest (Art. 6.1.f)
    • chosen language, last consulted household
  • 2.8. Calendar Import — Consent (Art. 6.1.a)
    • events you choose to import from your phone’s calendar or an .ics address
    • Calendar access is only requested at the time of import and can be revoked in your phone’s settings.

3. What We Do Not Collect

  • no payment or banking data
  • no geolocation data
  • no access to your contacts
  • no advertising, no ad trackers, no third-party audience measurement cookies
  • Photos you send (avatars, attachments) are systematically stripped of their EXIF metadata before sending — including GPS coordinates automatically added by your device.

4. Who Has Access to Your Data

  • 4.1. Members of your household see content shared within that household: events, shopping list, meals, attachments, first name, and profile picture.
  • 4.2. They do NOT see the contents of your FooDrop fridge, your personal menus, or your interactions with Komi.
  • 4.3. Processors (Art. 28 GDPR):
    • Google Ireland Limited — Firebase hosting (authentication, database, storage, functions)
    • RevenueCat, Inc. — subscription management
    • The provider of the language model used by Komi, solely for generating responses.
  • 4.4. Your data is never sold, rented, or transferred for advertising purposes.

5. Transfers Outside the European Union Some processors are established in the United States. These transfers are governed by the European Commission’s standard contractual clauses and, where applicable, the EU-US Data Privacy Framework adequacy decision. You can obtain a copy of the safeguards put in place by writing to the contact address.

6. Retention Periods

  • Account and content: retained as long as the account exists
  • After account deletion: erased within 30 days, except where legal retention obligations apply
  • Deleted events and shopping items: erased immediately
  • Attachments: erased with the event they are attached to
  • Interactions with Komi: retained for the duration of the session, not archived on our servers
  • Technical backups: purged within 90 days If you leave a household or are removed from it, the content you added remains in that household: it belongs to the collective organization. Your personal account data follows you.

7. Your Rights In accordance with Articles 15 to 22 of the GDPR, you have the following rights, which can be exercised at gwen@foodrop.org:

  • access to your data
  • rectification of inaccurate data
  • erasure (« right to be forgotten »)
  • restriction of processing
  • portability, in a machine-readable format
  • objection to processing based on legitimate interest
  • withdrawal of consent at any time, for treatments depending on it We respond within one month. Proof of identity may be requested in case of reasonable doubt regarding your identity. You can also lodge a complaint with the CNIL (https://www.cnil.fr).

8. Security

  • encryption of communications (HTTPS/TLS) and data at rest
  • hashed passwords, never stored in plain text
  • siloed access per household, enforced server-side: a member of another household cannot technically read your data
  • removal of EXIF metadata from photos
  • administrator access logging In the event of a data breach likely to result in a high risk to your rights, you will be informed as soon as possible, in accordance with Article 34 of the GDPR.

9. Minors The service is not intended for children under 15 without the intervention of a holder of parental authority. A parent can create events concerning a child without the child having an account: in this case, only the information entered by the parent appears. If you notice that a child has provided us with data without authorization, write to gwen@foodrop.org: it will be deleted without delay.

10. Changes to This Policy Any substantial modification will be notified to you in the app before it comes into effect. The date of the last update appears at the top of this document. For any questions: gwen@foodrop.org