Privacy Policy

Privacy Policy

This English text is a convenience translation. The legally binding version is the German original: zur deutschen Fassung.

This statement describes which personal data Breezl processes, for which purposes, and on which legal basis.

Controller

Nethotline Ulli Berthold, Waterhuck 26, 45968 Gladbeck. Email: [email protected]

Principle: no ads, no data selling

Breezl shows no advertising and is funded solely by Plus subscriptions. We do not sell or rent personal data, do not build usage profiles for advertising purposes, and do not pass your data on to third parties for marketing. This applies equally to all plans, Free and Plus alike.

Hosting

Breezl runs on servers of Hetzner Online GmbH (located in Germany). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Hetzner Online GmbH; the servers are located within the EU.

Account and Usage Data

During registration and use, we process: your name, your email address, and a hashed password (bcrypt; the plaintext password is never stored). In addition, there is the content you create: shopping lists, items, stores, and aisle layouts, as well as your household memberships. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).

Login and Session

After you log in, an authentication token (JWT) is stored locally in your browser (`localStorage`) to keep you signed in. This is not a cookie and does not serve tracking purposes.

Email Delivery

For magic-link logins, invitations, and confirmations, we send emails to the address you provide. Legal basis: Art. 6 (1) (b) GDPR.

Real-Time Synchronization

The live synchronization of shared lists runs first-party on our own server (technology: Socket.IO; optionally backed by a self-hosted Redis). No sync data is shared with third parties in the process.

Barcode Lookup (Open Food Facts)

When you scan a barcode, our server queries the product at Open Food Facts. Only the barcode and a technical identifier (user agent) are transmitted, and no personal data. Open Food Facts privacy notice: https://world.openfoodfacts.org/privacy. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in product identification).

Connected Apps (OAuth / MCP)

You can explicitly authorize third-party applications (e.g. AI assistants) to access your lists. Access takes place only after your consent and within the scope of the permissions (scopes) you have confirmed; you can revoke the connection at any time. Legal basis: Art. 6 (1) (a) GDPR.

Audience Measurement (Analytics)

To improve the service, we use the self-hosted, cookieless analytics services Umami and Matomo. Both set no cookies and perform no cross-site or cross-device tracking; for Matomo, the cookie function is additionally disabled (`disableCookies`) and IP anonymization is enabled server-side. Aggregated page and screen views and the referrer are recorded; no personal profiles are created. There is no advertising. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in data-minimizing audience measurement). Umami and Matomo are self-hosted by us; no processing by third parties takes place in this context.

Error Diagnostics (Error and Crash Reports)

So that we can detect and fix errors and crashes, we collect technical error reports using GlitchTip. GlitchTip is self-hosted by us (`errors.nethotline.io`, servers at Hetzner in Germany); no disclosure to third parties and no processing by third parties takes place in this context.

Only technical context about the error is recorded: error message and stack trace, app version, platform (web, iOS, Android, desktop), browser and operating-system details, the path of the page involved, and a short sequence of preceding technical events (e.g. navigation, failed requests). The IP address is anonymized server-side: it is truncated to /24 (the last octet is removed) before the report is stored.

Collection is deliberately configured to be data-minimizing:

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the stability and security of the app). The error reports are self-hosted by us and deleted after 30 days at the latest.

Update Statistics (OTA)

In our native apps (iOS/Android), the update function checks whether a newer version of the app's interface is available. To monitor the stability and adoption of such updates, we process aggregated, per-day counters by platform and app version for update-process events (e.g. update applied, failed, rolled back, download success or failure, app moved to foreground or background). No content, no free text and no IP addresses are stored alongside these counters.

To count active installations per version, we use a pseudonymous identifier that rotates every calendar day: a device-local identifier is combined with a server-side secret and the current calendar day, then irreversibly hashed (SHA-256) before being stored. A new, mathematically unrelated value is produced for each day; the original identifier is never stored or logged. Re-identifying the same device across days is not possible from this data. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the quality and security of app updates). The data is self-hosted by us and deleted after 6 months at the latest.

Retention Period

We store your data for as long as your account exists. If you delete your account, your personal data is completely deleted within 30 days. You can find out how to delete your account on the Data Deletion page. Statutory retention obligations remain unaffected.

Your Rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to lodge a complaint with a supervisory authority. To exercise these rights, contact [email protected]. For deletion of your account, see Data Deletion.