1. Purpose and basic principle of Feori
Feori helps users plan meals, save their own dishes and ingredients, and maintain personal and shared shopping lists. Personal use remains local. An account is required only for online features that are explicitly opened, in particular households, shared planning, guest polls, an account-linked Pro trial and server-confirmed Pro entitlements.
Feori is not a messenger or social network. Personal local content is not automatically transferred to a household or another online service.
2. Local data on the device
In personal mode, Feori processes and stores in particular:
- dishes, ingredients, quantities, servings, notes, favourites and cooking history;
- personal weekly plans, including leftovers, eating out and free states;
- personal shopping lists, categories, ordering and completed states;
- app settings and completion of the introduction;
- local backup, restore and export data when these features are deliberately used;
- a local status for the trial period and the most recently confirmed Pro access.
This data is stored in the app's private storage. Android cloud backup and automatic device transfer are disabled for Feori. Backups and export files created by the user are subsequently stored at the location selected by the user and must be protected or deleted there by the user.
3. Dish images, camera and photo selection
A user may optionally select an image for a dish through the Android photo picker or take one with a camera app. Feori does not request permanent, general camera or media-library permission for this. Only the specifically selected or captured image is copied to the app's private storage, reduced in size and processed locally.
User-created dish images are not automatically uploaded to a household, a guest poll or a Vareldan service. They may form part of a local Feori backup deliberately created by the user.
4. Local product signals
Feori keeps a narrowly scoped technical history on the device for certain actions in shared areas, for example whether a dish was suggested, scheduled, rescheduled, deselected or rated. A random local installation identifier and pseudonymised household, user and dish identifiers are used for this purpose. Raw ingredient lists, notes, images and shopping items are not part of these signals.
In the current product version, these signals are expressly LOCAL_ONLY. They are not transmitted to Vareldan Studio or an analytics service and are automatically limited after no more than 180 days or once 5,000 events are exceeded. Feori contains no external analytics or crash-reporting SDK.
5. Google sign-in and Supabase Auth
Personal local use does not require sign-in. When an online feature is started, the user can sign in with Google through Android Credential Manager. Feori does not receive the user's Google password. The Google ID token is passed with a nonce to Supabase Auth and exchanged there for a Feori session.
This may involve processing an internal user identifier, Google account identifier, email address, display name, session timestamps, and access and refresh tokens. Supabase Auth for Feori is configured in the Frankfurt region (eu-central-1). Feori sends only the short-lived Supabase access token to Vareldan Core, not the Google provider token.
Further information: Google Privacy Policy and Supabase Privacy Policy.
6. Vareldan Core and separate Feori services
Vareldan Core processes only cross-app core data such as internal identity, app assignment, trial period, entitlements, purchase status, consent states, and minimal security and audit data. Feori-specific data is processed separately in a dedicated Feori service and database. Content from other Vareldan apps is not combined with Feori household data.
The online interfaces are provided through Cloudflare Workers. Technically necessary connection and security data, such as the IP address, time, requested resource and HTTP status, may be processed temporarily by the infrastructure involved in network requests. Feori does not permanently store IP addresses in its guest-poll data and does not use device fingerprinting.
Further information: Cloudflare Privacy Policy.
7. Shared households
A household is created or joined only after a deliberate user action. Depending on the feature used, processing may include the household name, internal membership and role, invitation processes, shared dish names, the shared weekly plan and servings, meal requests and votes, and shared shopping items with quantity, unit, category and completed state. Necessary revision, synchronisation and change information is also processed.
Personal dishes, ingredients, images, weekly plans and shopping lists are not uploaded as a complete collection. Only a specifically confirmed share, such as selected ingredients for the shared shopping list, is transferred. Household members can see content shared within the relevant household.
A member can leave the household; the owner must first transfer ownership or permanently delete the household. The owner can permanently delete the household and all dependent data that exists only as shared data. Personal local data on users' devices remains unaffected.
8. Guest polls
A signed-in user can share selected dish names for voting through a secret, expiring and revocable link. The poll ID, internal owner identifier, status and timestamps, a hash of the link secret, selected dish names, positions and aggregated votes are transferred. Ingredients, recipes, images, weekly plans, shopping items and guests' contact details are not transferred.
A guest's browser creates a random first-party identifier and stores it locally for that poll. The server stores only an HMAC-pseudonymised value so that the same browser can change its selection. No advertising cookies, third-party analytics, permanent IP profiles or fingerprinting are used.
Optional accompanying text remains in the Android share dialog until sharing and is then passed only to the destination app selected by the user. It is not stored as part of the poll by the Feori service.
Free polls remain visible for no more than 30 days after ending or revocation, and Pro polls for no more than 180 days. The poll, options and votes are then physically deleted. The creator can permanently delete a poll immediately at any time.
9. Feori Pro and Google Play
Feori Pro is an optional monthly subscription that can be cancelled monthly. Payment and payment data are processed by Google Play and the payment services used by Google. Feori does not request credit-card or bank details.
For display, purchase, acknowledgement and restoration, Feori processes in particular the product identifier, product details, localised price, purchase and acknowledgement status, and a purchase token. For server-side verification, the package name, product identifier and purchase token are sent in authenticated form to Vareldan Core. The purchase token is not written to app logs. Google may process its own account, purchase, device, network, security and diagnostic data under its terms.
10. Advertising, tracking, permissions and diagnostics
Feori contains no personalised advertising, advertising-ID use, marketing profiling, proprietary tracking, analytics SDK or crash-reporting SDK. The app does not request location, contacts or microphone permission. The camera and photo picker are opened only after a specific user action through the intended Android system features.
Depending on device, account, Play Console and test settings, Android, Google Play and Google components may process their own crash, ANR, security or diagnostic data. Such platform processing is governed by Google's or Android's settings and terms.
11. Website and support
The public Feori page and the studio@vareldan.com mailbox are provided through STRATO infrastructure. When the website is accessed, the web server processes technically necessary connection data, in particular the IP address, time, requested resource, browser or operating-system information, and HTTP status. Details of website processing are set out in the general Website Privacy Policy.
When a message is sent to studio@vareldan.com, the information provided, such as sender address, name, content, attachments and technical headers, is processed to handle the request. Messages are deleted when they are no longer required and no statutory retention obligation or legitimate security or evidence need prevents deletion.
12. Retention and deletion
Local app data remains stored until the user changes or deletes it, deletes the Android app data, or uninstalls the app. Separately exported backups must be deleted from the storage location chosen by the user. Local product signals are automatically limited to no more than 180 days and 5,000 events.
Shared household data is generally stored for as long as the household exists and the data is needed for the shared feature. Permanently deleting a household removes the data that exists only as shared household data. Security audit data in Vareldan Core is normally scheduled for deletion after 90 days and technical idempotency data after 24 hours. Statutory obligations, particularly those relating to purchases, may require different retention periods.
To request deletion of a Feori account and the associated Feori cloud data, the app can open a prepared request under Settings → Privacy & account → Delete account and cloud data to studio@vareldan.com. Alternatively, users can send a direct message with the subject “Feori – Delete account and cloud data”. Secure confirmation of account ownership may be required to prevent unauthorised deletion.
Following a deletion request, Feori-specific account and cloud data is removed unless statutory retention obligations require otherwise. If the same Vareldan identity is also used in another Vareldan app, that app's separate data is not deleted without a corresponding request. Vareldan Studio cannot remotely view or delete data stored only locally on Feori devices.
13. Legal bases
Local processing and functional processing deliberately initiated by the user generally take place to provide the app's functions and perform the user relationship under Article 6(1)(b) GDPR. Purchase and Pro processing also serves contract performance; records required by law may be processed under Article 6(1)(c) GDPR.
Security, abuse prevention, error-handling and support processing may be based on Article 6(1)(f) GDPR. The legitimate interests are the secure and reliable operation of the service, troubleshooting and answering requests. Where processing requires consent in the future, consent will be requested separately and voluntarily before that processing begins and may be withdrawn with effect for the future.
An Android permission or continuing with a specifically opened online feature does not automatically constitute blanket consent to advertising or tracking. Feori contains no such features.
14. Recipients and international transfers
Depending on the feature used, recipients or processors may in particular include Google for sign-in and Google Play, Supabase for authentication, Cloudflare for online interfaces and separate databases, and STRATO for the website and email. Destination apps selected by users process shared text, links or files under their own terms.
Supabase Auth for Feori is configured in Frankfurt. Individual providers, in particular Google, Supabase or Cloudflare, may also process data outside the EU or EEA. The applicable contractual and privacy information and any adequacy decisions, standard contractual clauses or other permitted safeguards apply.
15. Data subject rights
Where the statutory requirements are met, data subjects have in particular rights of access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests, withdrawal of consent for the future, and complaint to a data protection supervisory authority.
Requests can be sent to studio@vareldan.com.
Supervisory authority responsible at the controller's registered location:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin, Germany
Email: mailbox@datenschutz-berlin.de
Website: www.datenschutz-berlin.de
16. Controller and contact
Ali Demirkol, trading as “Vareldan Studio”
Ritterlandweg 17
13409 Berlin
Germany
Email: studio@vareldan.com
Public version: https://vareldan.com/en/feori/privacy/
No data protection officer has been appointed.
17. Changes to this Privacy Policy
This Privacy Policy will be updated when features, service providers, recipients, the legal situation or publication conditions change. The current version is available at https://vareldan.com/en/feori/privacy/. Material changes will also be indicated in Feori where required.