Crumely
FunkcjeJak to działaSpołecznośćCennikFAQ
Pobierz aplikację
FunkcjeJak to działaSpołecznośćCennikFAQRegulaminPolityka prywatności
Pobierz aplikację
Powrót do strony głównej

Dokumenty

Polityka prywatności

Wersja robocza

Ten dokument jest jeszcze wersją roboczą — przygotowujemy Crumely do premiery. Zaktualizujemy tę stronę, gdy tylko wersja finalna będzie gotowa.

Application: Crumely (the “App”)
Controller: Adrian Gaik Software, a business established under the laws of Poland, with business address at Armeńska 5/8 street, 52-121, Wrocław, Poland, NIP/VAT ID: PL8992914427 (“Crumely”, “we”, “us”, “our”).
Privacy contact: privacy@crumely.app
Support contact: support@crumely.app
Effective date: - Last updated: - Version: 1.0

This Privacy Policy explains how we collect, use, disclose, transfer, store, and protect personal data when you create an account, access, download, install, purchase a subscription for, or use Crumely.

We are established in Poland and make the App available globally through Apple App Store and Google Play. For users in the European Union, European Economic Area, United Kingdom, and Switzerland, this Privacy Policy is intended to provide the information required by the GDPR and equivalent data protection laws. For users in the United States, it also describes rights and disclosures relevant under applicable U.S. federal and state privacy laws.

This Privacy Policy is provided as data-protection information. It explains how we process personal data and is not a contract that you must agree to. Use of the App is governed by our Terms and Conditions.


1. Who Is Responsible for Your Data

1.1. Controller. For personal data processed to provide, secure, improve, and administer the App, the controller is:

Adrian Gaik Software
Armeńska 5/8 street, 52-121, Wrocław, Poland
NIP: 8992914427
REGON: 520853243
EU VAT: PL8992914427 Email: privacy@crumely.app

1.2. No appointed DPO. We have not appointed a formal Data Protection Officer because we are not required to designate one under Article 37 GDPR. You may contact us about privacy matters at privacy@crumely.app.

1.3. Processors and independent controllers. We use third-party service providers to operate the App. Some act as our processors or sub-processors; others, such as Apple and Google for store accounts and payment handling, may act as independent controllers for their own services.


2. Personal Data We Collect

We collect personal data only where it is needed for the App, where you provide it, where it is generated by your use of the App, or where a third-party platform provides it to us for subscription and entitlement verification.

2.1 Account and authentication data

  • email address, verified through a confirmation email before registration is completed;
  • password credentials processed through our authentication provider; we do not store your plain-text password;
  • internal user ID and authentication/session identifiers;
  • sign-in/sign-up status, failed sign-in throttling metadata, and account creation timestamps;
  • email delivery records for verification and password-reset messages, which store only an HMAC-hashed form of your normalized email address (not the raw address), together with locale, template identifier, delivery status, provider message ID, attempt count, timestamps, and sanitized error categories; raw confirmation and reset tokens are stored only as hashes and deleted upon use;
  • registration request records created during email-confirmed sign-up, including verification status and the Terms acceptance and Privacy Policy acknowledgement metadata provided during registration;
  • Terms and Conditions acceptance records, including document type, document version, acceptance time, source, platform, app version, native app version, and native build version;
  • consent records (for example, for optional analytics and for the sensitive-image consent described in Section 2.7), including consent version, source, platform, and timestamp.

2.2 Profile and preference data

  • display name, if you provide one;
  • avatar URL or storage reference, if you provide one;
  • a short public bio, if you provide one, shown on your baker profile page as described in Section 6.5;
  • preferred locale, allowed content locales, and measurement unit system;
  • app preferences such as theme preference and product analytics consent state;
  • subscription tier and feature entitlement state.

2.3 Content you create or upload

Depending on how you use the App, we process:

  • recipes, recipe titles, descriptions, ingredients, ingredient amounts, steps, timers, temperatures, tags, yield information, linked recipes, images, thumbnails, and related metadata;
  • baking plans, planned dates, shopping/prep selections, recipe items, and plan status;
  • collections, collection titles, descriptions, images, recipe membership, and ordering;
  • saved recipe references and recipe shadow snapshots used to preserve saved, collected, linked, or baking-plan recipes;
  • Baked & Liked reviews, ratings, comments, baked status, creation images, and review metadata;
  • community-published recipes and other community-visible content;
  • app issue reports, including title, description, optional reporter email, optional screenshot, platform, app version, build version, and locale;
  • content reports for community recipes or reviews, including selected reason, optional details, target IDs, target owner IDs, target snapshots, and report metadata;
  • AI import inputs and outputs, including submitted recipe URLs and video links, uploaded import images, recipe text you share into the App, reduced public page content or caption text retrieved from video platforms and uploaded from your device (as described in Section 5), video metadata (platform, video ID, channel, and duration where available), fetch metadata (such as byte sizes, content type, and fetch time), generated structured recipe data, model name, status, attempts, sanitized error codes, locale hints, and quota metadata; the intermediate text extracted from webpages during processing is transient and is not stored in the import record.

2.4 Subscription and purchase data

Paid subscriptions are purchased through the applicable app store and managed through RevenueCat. We process subscription-related records needed to grant App access, including:

  • Crumely user ID used as the RevenueCat app user ID;
  • provider customer ID and subscription ID;
  • purchased product/entitlement, assigned tier, effective tier, subscription status, subscription period start/end, trial or grace period information, cancellation status, and trusted subscription event history;
  • AI import quota usage by subscription period.

We do not directly collect or store your payment card number, bank account details, or full app-store billing credentials. The RevenueCat SDK embedded in the App communicates directly with RevenueCat and processes the device and app metadata needed to attribute, verify, and restore purchases.

2.5 Device, diagnostics, and security data

We process technical and operational data such as:

  • platform, operating system, app version, native app version, native build version, locale, environment, and release identifiers;
  • error reports, crash diagnostics, performance traces, breadcrumbs, and structured logs;
  • server-side audit events for important account, profile, recipe, collection, baking-plan, review, report, recipe-import, subscription, and security-relevant actions;
  • upload metadata and Convex storage IDs for files uploaded through the App;
  • aggregated baker-profile view counters (a single total per profile, with no record of which users viewed it), used to operate and rank community features such as the featured-bakers section (Section 6.5);
  • network and request metadata that our infrastructure providers necessarily process to deliver the service, such as IP address and request timing.

Diagnostics are configured to avoid default PII collection where supported. The App redacts or suppresses emails, passwords, tokens, authorization headers, cookies, URLs, local file paths, image paths, recipe body text, report details, comments, and other free-text fields before sending diagnostic or analytics payloads where the App controls the payload.

2.6 Optional product analytics data

Product analytics are disabled unless you explicitly enable them in the App. If enabled, we collect allow-listed usage events such as sign-in/sign-out, feature usage, paywall opens, plan selection, purchase/restore flow status, search submission metadata, offline sync status, and similar product events.

Product analytics do not include recipe body text, review comments, report details, email addresses, image paths, file paths, raw URLs, tokens, provider secrets, or session replay. Analytics autocapture, lifecycle capture, logs, and session replay are disabled in the App’s PostHog configuration.

2.7 Potentially sensitive data in user-submitted content

We do not deliberately collect special categories of personal data within the meaning of Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, data concerning health, sex life, or sexual orientation). However, content that you voluntarily submit to the App, such as recipe images, review photos, dietary tags, allergen notes, or the text of a recipe or review, may incidentally contain or reveal information that could be considered sensitive (for example, an identifiable face in a photo, dietary practices linked to a religion, or allergen information that reveals a health condition). Where you submit such content, the lawful basis for our processing is your explicit consent within the meaning of Article 9(2)(a) GDPR. For images uploaded to the App, this consent is obtained through a distinct, affirmative step rather than inferred from the act of uploading alone: before you upload an image for the first time, the App presents a clear, separate confirmation prompt that explains the Article 9 processing and asks you to confirm. We record your consent (including its version, source, platform, and timestamp), and our servers will not issue an upload authorisation for such images until that consent has been given; consent is therefore enforced server-side, not merely assumed. You are responsible for the content you submit, and you may withdraw your consent at any time by deleting the relevant content; withdrawal does not affect processing carried out before withdrawal. Please note that if you published the content as community content, copies, versioned shadows, remixes, and references held by other users may persist after you delete the original or your account, as described in Section 6 and the Terms and Conditions, so deleting your account does not guarantee removal of sensitive data contained in community content you have published. You should therefore not include sensitive information in content you publish to the community, and where you wish to withdraw consent you should delete the specific content before other users save, collect, shadow, or remix it. We recommend that you do not include sensitive information unless it is necessary for the use you intend to make of the App.

2.8 Local/offline device data

Crumely is an offline-first mobile app. The App stores some data locally on your device, including:

  • session snapshot with user ID, email, validation time, and last-used time;
  • profile cache, lookup cache, recipe documents, baking-plan documents, collection documents, drafts, sync metadata, and queued offline operations in the App’s local SQLite store;
  • app-level preferences and markers in device storage, including analytics consent state, a pending email verification marker (storing the email address awaiting confirmation), content shared into the App for import that has not yet been submitted, sensitive-image consent state, and a flag recording that welcome screens were shown;
  • authentication session tokens stored in your device’s secure storage (Keychain on iOS, Keystore-backed storage on Android);
  • local image URIs temporarily retained for offline edits until they can be uploaded and synchronized.

Local data may remain on your device until you sign out, delete it through the App where available, clear app data, uninstall the App, or the App’s cleanup and sync routines remove it.


3. Sources of Personal Data

We collect personal data from:

  • you, when you create an account, configure your profile, create content, upload images, submit reports, use AI imports, or contact us;
  • your device and App installation, when the App generates diagnostics, local cache, sync metadata, or technical information;
  • Apple App Store, Google Play, and RevenueCat, when subscription and entitlement information is needed to process purchases, restore purchases, verify subscriptions, or resolve access;
  • public webpages you ask us to import from, where the URL import feature fetches a single validated public HTTP(S) page (following a limited number of re-validated redirects) and extracts recipe-related text and structured metadata for the import you requested;
  • video platforms, when you submit a supported video link for import: Google’s YouTube Data API provides public video metadata (title, description, channel, duration), and public page content or caption text is retrieved directly from your device, as described in Section 5;
  • other apps on your device, when you use your device’s share sheet to share a link or text into the App for import.

4. Why We Process Personal Data and Our Legal Bases

Where the GDPR or equivalent law applies, we rely on the following legal bases.

PurposeExamplesLegal basis
Provide the App and your accountauthentication, profile, recipes, collections, baking plans, offline sync, storage, access controls, subscriptions, AI imports you requestcontract, Article 6(1)(b) GDPR
Process subscriptions and entitlementsRevenueCat sync, app-store entitlement checks, subscription lifecycle history, AI import quotascontract, Article 6(1)(b); legal obligation, Article 6(1)©, where accounting or consumer law applies
Store legal acceptance recordsTerms acceptance version, timestamp, app/platform metadatalegal obligation, Article 6(1)©; legitimate interests, Article 6(1)(f), in proving agreement
Secure the App and prevent abuseauth throttling, authorization checks, idempotency, audit events, rate limits, fraud/abuse investigations, content-report aggregationlegitimate interests, Article 6(1)(f)
Moderate and administer community featurescontent reports, target snapshots, review state, appeals, copyright/security/legal contactslegitimate interests, Article 6(1)(f); legal obligation, Article 6(1)©, where DSA or other law applies
Handle support and issue reportssupport messages, issue report descriptions, optional screenshots, reporter emailcontract, Article 6(1)(b); legitimate interests, Article 6(1)(f)
Diagnostics and reliabilitycrash reports, performance traces, sanitized logs, app version/build metadatalegitimate interests, Article 6(1)(f)
Optional product analyticsopt-in product events through PostHog Cloud EUconsent, Article 6(1)(a)
Comply with law and enforce rightslegal requests, tax/accounting obligations, dispute records, consumer rights, platform requirementslegal obligation, Article 6(1)©; legitimate interests, Article 6(1)(f)

You may withdraw consent for optional product analytics at any time in the App. Withdrawal does not affect processing that occurred before withdrawal.


5. AI-Assisted Recipe Imports

5.1. URL imports. If you submit a URL for import, the backend validates that it is a public HTTP(S) URL, denies localhost/private-network targets and credentialed URLs, fetches a single page (following a limited number of re-validated redirects), extracts recipe-related text and JSON-LD metadata, and sends that extracted content to OpenAI to generate structured recipe data.

5.2. Image imports. If you upload an image for import, the image is uploaded to Convex storage, converted into a model-compatible image payload, and sent to OpenAI to generate structured recipe data. Uploading an image (including for import) requires the separate sensitive-image consent described in Section 2.7.

5.3. Video imports. If you submit a link to a video on a supported platform (currently YouTube, TikTok, or Instagram), the App does not download, store, or analyze the video or audio itself. Instead: (a) the backend validates the link against the supported-platform list and the same network safeguards as URL imports; (b) for YouTube links, our backend requests public video metadata (title, description, channel, duration) from Google’s YouTube Data API; © publicly available page content (TikTok, Instagram) or caption text (YouTube) is fetched directly from your device, reduced, and uploaded to our backend as a small text artifact — the platform involved receives that request from your device (including your IP address) in the same way as if you had opened the page yourself, and its own privacy policy applies to that request; and (d) only extracted and sanitized text and metadata are sent to OpenAI to generate structured recipe data. The video import feature uses YouTube API Services for YouTube links; Google’s Privacy Policy is available at https://policies.google.com/privacy.

5.4. Text imports. If you share recipe text into the App (for example, through your device’s share sheet), that text is sent to OpenAI to generate structured recipe data.

5.5. No model training on your data. We use the OpenAI API under terms that prohibit OpenAI from using API inputs (the URLs, images, and extracted text we send) or API outputs (the structured recipe data returned) to train, fine-tune, evaluate, or otherwise improve OpenAI’s models, except for short-term abuse-monitoring purposes that OpenAI applies to its API. We do not enable any opt-in mechanism that would allow such training. We do not ourselves use your personal data or your content to train any AI or machine-learning model. Users of the App are also contractually prohibited from using the App or its outputs to train any machine-learning model (see the Terms and Conditions).

5.6. Human review and AI transparency. AI output may be inaccurate. You are responsible for reviewing and correcting imported recipe data before saving, publishing, or using it. The App identifies AI-assisted imports as such in the user interface, and import records include the AI model used.

5.7. No legal or similarly significant automated decisions. The App does not use AI imports or product analytics to make decisions that produce legal or similarly significant effects about you within the meaning of Article 22 GDPR. Subscription access is determined by verified subscription status and App rules, not by profiling.


6. Community Features and Visibility

6.1. Private content. Personal recipes, private collections, private baking plans, drafts, and offline data are intended for your own account unless you publish or otherwise share them through App features.

6.2. Community content. If you publish a recipe or submit a visible Baked & Liked review, other users may see and interact with that content according to the Terms and Conditions. Community recipe cards and review payloads may include your display name or fallback author label, rating information, review text, image presence, and recipe/review metadata.

6.3. Recipe shadows and remixes. When another user saves, collects, links, or adds your published community recipe to a baking plan, the App may create read-only versioned recipe shadows so that the other user’s library remains stable. Users may also remix published recipes into their own editable recipes with attribution. These behaviors are described in more detail in the Terms and Conditions.

6.4. Reports. Content reports may store a snapshot of the reported recipe or review, including a truncated recipe title or review excerpt, author IDs, rating, image presence, and report reason, so that we can assess the report even if the original content later changes.

6.5. Baker profile pages. Once you have published at least one community recipe, your baker profile becomes visible to other signed-in users on a dedicated profile page showing your display name (or a fallback author label), avatar, bio, and published recipe count. Your profile also becomes findable through in-App baker search by name, and may be shown in the “Bakers” section of the Discover screen, which periodically features bakers based on the number and recency of their published recipes; the cached profile details shown there may lag your latest edits by a few hours. If you have never published a community recipe, your profile page is not visible to other users. Links you include in your bio are rendered as tappable links for other users; opening such a link leaves the App, and the destination’s own terms and privacy policy apply. We also maintain an aggregated view counter for each baker profile; it stores only a total view count and records nothing about who viewed the profile.


7. When We Share Personal Data

We do not sell your personal data. We do not share personal data for cross-context behavioral advertising or targeted advertising.

We share personal data only as needed for the purposes described in this Privacy Policy. The table below lists the recipients, the role they play with respect to your personal data (processor acting on our instructions, or independent controller acting on its own terms), and the legal mechanism we rely on where the recipient processes personal data outside the European Economic Area, the United Kingdom, or Switzerland (as required by Article 13(1)(f) GDPR).

App technical sub-processors. These recipients process personal data on our behalf to operate the App.

RecipientPurposeRoleInternational transfer mechanism
Convexbackend database, authentication, serverless functions, file storage, synchronization, and webhook/API runtimeprocessorStandard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and supplementary technical and organizational measures where required
Sentry (Functional Software, Inc.)crash/error diagnostics, performance tracing, and reliability monitoringprocessorEU-U.S. Data Privacy Framework certification, with Standard Contractual Clauses as a fallback mechanism
PostHog Cloud EUoptional product analytics, only after you opt inprocessorEU hosting; no transfer outside the EEA is required for the analytics workload
OpenAIAI-assisted recipe imports from URLs, images, video links (extracted text and metadata only), and shared text that you submitprocessorEU-U.S. Data Privacy Framework certification and Standard Contractual Clauses under OpenAI’s data-processing addendum (EEA contracting entity: OpenAI Ireland Ltd); OpenAI is contractually prohibited from using API inputs or outputs to train its models
Resenddelivery of transactional account emails (email verification, password reset); receives your email address for delivery, while our own records store only a hashed formprocessorStandard Contractual Clauses and supplementary technical and organizational measures where required

App distribution, store, and billing recipients. These recipients operate app distribution and in-app payment infrastructure. With respect to the data they process for their own store, billing, payment, and platform purposes, they act as independent controllers under their own terms and privacy policies.

RecipientPurposeRoleInternational transfer mechanism
Apple App Store (Apple Distribution International Ltd. and Apple Inc.)app distribution, in-app purchase processing, subscription management, refunds, taxes, and store compliance on iOSindependent controller for store account, billing, and platform analytics; processor to the extent it executes our specific instructionsApple’s own transfer arrangements, including Standard Contractual Clauses where applicable, as described in Apple’s privacy documentation
Google Play (Google Ireland Ltd. and Google LLC)app distribution, in-app billing, subscription management, refunds, taxes, and store compliance on Androidindependent controller for store account, billing, and platform analytics; processor to the extent it executes our specific instructionsGoogle’s own transfer arrangements, including Standard Contractual Clauses where applicable, as described in Google’s privacy documentation
RevenueCatsubscription management, purchase restoration, entitlement state, subscription lifecycle analytics, and provider customer/subscription identifiersprocessorStandard Contractual Clauses and supplementary technical and organizational measures where required
Google (YouTube Data API)retrieval of public YouTube video metadata (title, description, channel, duration) for video imports you request; our backend sends the video identifier to Googleindependent controller for its processing of API requests under its own termsEU-U.S. Data Privacy Framework certification (Google LLC) and Google’s own transfer safeguards

Other recipients.

RecipientPurpose
Email, support, legal, security, and hosting providers we use to communicate with you or to operate our public legal pagesresponding to requests, operating public legal pages, and administering business communications
Authorities, courts, regulators, and professional adviserscompliance with law, legal claims, consumer rights, security incidents, and enforcement of our rights
Video platforms (YouTube, TikTok, Instagram)when you import from a video link, public page or caption content is fetched directly from your device, so the platform receives that request (including your IP address) under its own privacy policy, as if you had opened the page yourself
Other users of the Appcommunity content, reviews, author labels, recipe shadows, remixes, and visible App interactions you choose to make available

We do not sell your personal data, do not share personal data for cross-context behavioral advertising, and do not use personal data for targeted advertising. A copy of, or further information about, the safeguards listed above is available on request at privacy@crumely.app.


8. International Transfers

We are established in Poland. Some providers we use may process personal data outside Poland, the EEA, the United Kingdom, or Switzerland, including in the United States.

Where personal data is transferred internationally and the GDPR or equivalent law requires safeguards, we rely on appropriate transfer mechanisms such as adequacy decisions (including the EU-U.S. Data Privacy Framework for U.S. recipients that hold an active certification), Standard Contractual Clauses, contractual commitments with processors, and supplementary measures where necessary. Where we rely on the EU-U.S. Data Privacy Framework, we aim to maintain Standard Contractual Clauses as a fallback mechanism.


9. Retention

We keep personal data only as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the App, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and preserve security. Specific retention windows are:

  • Account and profile data: retained for the lifetime of your account, then deleted or irreversibly anonymized within 30 days of account deletion, except where a longer retention is required by Applicable Law (in particular Polish tax and accounting law: 5 years from the end of the calendar year in which the relevant accounting event occurred, in accordance with art. 74 of the Polish Accounting Act and art. 86 of the Tax Ordinance).
  • Private content: retained for the lifetime of your account or until you delete it, then deleted within 30 days of account or content deletion, subject to backup expiry as described below.
  • Community content: retained while published. Versioned shadows, remixes, reports, moderation records, and references created by other users may persist for as long as those other users continue to reference or use them, as described in the Terms and Conditions and this Privacy Policy.
  • AI import records and import source artifacts (including uploaded import images and the reduced page/caption text artifacts described in Section 5): retained for 24 months from creation, or for the lifetime of your account if shorter, then deleted; quota counters are retained only for the duration of the relevant subscription period.
  • Auth email dispatch and registration request records (containing only HMAC-hashed email addresses): retained while needed to operate and secure the sign-up, verification, and password-reset flows, and deleted upon account deletion.
  • Baker profile view counters: a single aggregated total per profile, retained for the lifetime of your account and deleted upon account deletion.
  • Issue and content reports: retained for 24 months from the date the report is closed, or longer where required to handle a pending appeal, regulatory request, or legal dispute, in accordance with Article 24(5) DSA and the general 6-year civil-claims limitation period under art. 118 of the Polish Civil Code.
  • Legal acceptance records: retained for the lifetime of your account and for a further 6 years after account deletion (matching the civil-claims limitation period), to enable us to prove acceptance of the applicable legal document version if a dispute arises.
  • Subscription records and subscription events: retained for 5 full calendar years from the end of the calendar year in which the relevant accounting event occurred, to satisfy Polish tax and accounting obligations; entitlement history needed only for product operation is deleted earlier where possible.
  • Server audit events: default retention is 180 days; authentication, subscription, and report categories are retained for up to 365 days; audit events linked to a regulatory request or legal dispute are retained until that matter is closed.
  • Diagnostics (Sentry): retained for up to 90 days by default, in line with our Sentry configuration.
  • Product analytics (PostHog Cloud EU): retained for up to 12 months from the event date, only where you have opted in.
  • Local device data: retained on your device until cleared by App cleanup, sign-out, app data clearing, uninstall, synchronization, or account/content deletion flows.
  • Encrypted backups and security logs: retained for up to 90 days after the underlying record is deleted from the production database, then overwritten in the ordinary course, unless a longer retention is required by Applicable Law.

10. Account Deletion and Data Deletion

You may request deletion of your account and associated personal data by contacting privacy@crumely.app or support@crumely.app. Where available in the App or on our website, you may also use the account deletion request flow.

When we delete an account, we will, without undue delay and in any event within 30 days of the deletion request, delete or irreversibly anonymize personal data associated with that account in our primary production systems. Encrypted backups and security logs are overwritten in the ordinary course and in any event within a further 90 days. The following data may, however, survive deletion to the extent permitted or required:

  • data we must retain to comply with Applicable Law, in particular tax and accounting law (in Poland, 5 full calendar years from the end of the calendar year in which the relevant accounting event occurred), and to defend or pursue legal claims (up to the applicable civil-claims limitation period, generally 6 years under art. 118 of the Polish Civil Code);
  • data necessary to operate notice-and-action, statement-of-reasons, and out-of-court dispute mechanisms required by the DSA, retained for as long as required by that Regulation;
  • surviving community content: published community recipes that you did not delete or unpublish before account deletion remain available in the App with an anonymized author label (reviews you submitted are anonymized and their text and images removed), and community-content licenses, shadows, remixes, moderation records, and other user references survive as described in the Terms and Conditions;
  • a minimal record of the deletion request itself, retained to document that deletion was requested and carried out;
  • data held by independent controllers such as Apple, Google, and RevenueCat, for which you may also need to use their account, purchase, or privacy controls.

Where data is retained for any of the above reasons, we restrict its processing to those purposes only.

Deleting the App from your device does not by itself delete your server-side account. It may remove local device data depending on your operating system.


11. Your GDPR and International Privacy Rights

Depending on where you live and subject to legal limits, you may have the right to:

  • access your personal data (Article 15 GDPR);
  • receive a copy of your personal data;
  • correct inaccurate or incomplete personal data (Article 16 GDPR);
  • delete personal data (Article 17 GDPR);
  • restrict processing (Article 18 GDPR);
  • object, on grounds relating to your particular situation, to processing based on legitimate interests (Article 21(1) GDPR);
  • object at any time to processing of your personal data for direct marketing purposes (Article 21(2) GDPR); we do not currently send direct marketing, but this right applies if we ever do;
  • receive your data in a portable format (Article 20 GDPR);
  • withdraw consent where processing is based on consent (Article 7(3) GDPR);
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects (Article 22 GDPR); the App does not make such decisions about you;
  • lodge a complaint with a data protection authority.

To exercise these rights, contact privacy@crumely.app. We may need to verify your identity before fulfilling a request. We will respond within the time required by applicable law, normally within one month for GDPR requests unless an extension is permitted.

If you are in Poland or the EU, you may lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Moniuszki 1A, 00-014 Warszawa, Poland
Website: https://uodo.gov.pl

You may also contact your local EU/EEA data protection authority.


12. U.S. State Privacy Disclosures

If you reside in a U.S. state with a comprehensive privacy law, you may have rights to know/access, correct, delete, obtain a portable copy, and appeal a denied request. You may also have the right to opt out of “sale”, “sharing”, targeted advertising, or certain profiling, and to limit the use of sensitive personal information.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising. We do not use sensitive personal information to infer characteristics or for purposes beyond providing and securing the App. We do not collect or process biometric identifiers or biometric information.

We do not track users over time and across third-party websites or online services, and we do not permit third parties to collect such cross-site tracking data through the App. Because we do not engage in such tracking and do not sell or share personal information, the App does not respond differently to browser or platform “Do Not Track” or Global Privacy Control signals — there is no tracking or sale to opt out of.

Categories of personal information we may collect are described in Section 2 and may include identifiers, account credentials, commercial/subscription information, internet or electronic network activity information, app/device information, user-generated content, photos you upload, inferences limited to subscription entitlement or feature access, and support/moderation information.

To exercise U.S. privacy rights or appeal a privacy-rights decision, contact privacy@crumely.app. If your state permits use of an authorized agent, the agent may contact us at the same address, and we may require proof of authorization and identity verification.


13. Children and Minors

The App is not directed to children under 13, and we do not knowingly collect personal data from children under 13.

You must be at least 16 years old to create an account, or older where your country requires a higher age for digital consent. If you are a minor where you reside, you may use the App only with the consent of a parent or legal guardian.

If you believe that a child under 13 has provided personal data to us, contact privacy@crumely.app. We will take reasonable steps to delete the data unless we are legally required to retain it.


14. Permissions and Device Features

The App may request access to device features only when needed for App functionality:

  • Photo library/media access: to attach images to recipes, collections, reviews, imports, or issue reports.
  • Camera access: declared so that, where the App offers it, you can take photos for recipes or related App features; current App versions use the photo library picker only.
  • Microphone: the App does not record audio and does not request or use the microphone; no microphone permission is declared by the App.
  • Notifications: to send local bake-timer notifications; the App does not use remote push notifications and does not collect push tokens.
  • Local network access on iOS debug builds: to connect to the Metro development server during development; this is not intended for normal production use.

You can manage permissions through your device settings. Denying a permission may limit the related feature.


15. Security

We use technical and organizational measures designed to protect personal data, including:

  • server-side identity checks for protected operations;
  • owner, locale, subscription, and purpose-specific authorization checks;
  • strong password requirements and failed sign-in throttling;
  • idempotent write operations and validation at backend boundaries;
  • private-by-default file URL lookup;
  • upload scope validation;
  • local sync conflict handling and scoped local cleanup on sign-out;
  • structured audit logging with retention limits;
  • redaction of secrets and sensitive fields in logs, diagnostics, and analytics payloads where the App controls those payloads;
  • optional product analytics with explicit opt-in and provider-side privacy controls.

No system is perfectly secure. In the event of a personal data breach, we will notify affected users and competent authorities where and as required by applicable law (including Articles 33 and 34 GDPR and applicable U.S. state breach notification laws). If you believe your account or data has been compromised, contact security@crumely.app.


16. Store Privacy Disclosures

Apple and Google require developers to provide accurate privacy information in App Store Connect and Play Console. This Privacy Policy is intended to be consistent with the App’s store privacy disclosures. If our privacy practices change, we will update this Privacy Policy and the applicable store disclosures where required.

Apple, Google, and RevenueCat may separately process purchase, refund, tax, fraud-prevention, device, and account data under their own privacy policies and terms.


17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our processing activities, our sub-processor list, our security measures, applicable law, or regulatory guidance.

Material changes. A change is material if it (a) introduces a new processing purpose, (b) introduces a new category of personal data, © changes the legal basis for an existing processing activity, (d) introduces an international transfer to a new jurisdiction or under a new transfer mechanism, (e) introduces a new sub-processor or recipient category not already disclosed, (f) extends a retention period in a way that affects you, or (g) otherwise affects your rights under the GDPR or comparable laws in a way that is more than insignificant. For material changes we will notify you at least thirty (30) days before the change takes effect, via in-App notice and, where we have your verified email address, by email. The notice will summarize the change, identify the reason, and state the effective date.

Non-material changes. Clarifications, contact-detail updates, address corrections, formatting changes, and updates to legal references take effect upon posting. We will update the “Last updated” date at the top of this Privacy Policy and record the change in the Changelog at the end of this Policy.

Consent-based processing. Where a change relies on your consent under Article 6(1)(a) GDPR or explicit consent under Article 9(2)(a) GDPR, we will request a fresh opt-in in the App before commencing the new processing. Continued use of the App will not be treated as consent for those purposes. You may withdraw any previously given consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Your options. You may, at any time, exercise the rights described in Section 11 (including the right to object, the right to erasure, and the right to lodge a complaint with a supervisory authority), and you may delete your Account in accordance with Section 10 if you do not wish to continue under the updated Policy.


18. Contact

Privacy: privacy@crumely.app
Support: support@crumely.app
Legal: legal@crumely.app
Security: security@crumely.app

Adrian Gaik Software
Armeńska 5/8 street, 52-121, Wrocław, Poland
NIP: 8992914427
REGON: 520853243
EU VAT: PL8992914427


Changelog

This section records the version history of this Privacy Policy. Material changes (as defined in Section 17) are flagged accordingly. The “Notice given” column states how affected Users were notified.

VersionEffective dateMaterialitySummary of changesNotice given
0.1-n/a (initial)Initial draft of the Privacy Policy.n/a (pre-launch)
1.0-n/a (pre-launch release version)Added video imports (Section 5.3: device-side retrieval from YouTube/TikTok/Instagram, YouTube Data API, Google recipient) and text imports (5.4); added Resend as an auth-email processor and hashed email dispatch records (2.1); corrected local device data inventory (2.8: server-side Terms acceptance, secure-storage tokens, share-sheet and consent markers); noted RevenueCat SDK device metadata (2.4); updated transfer mechanisms with EU-U.S. Data Privacy Framework status per recipient (7, 8); added deletion-request record and anonymized-community-content effects of account deletion (10); added Do-Not-Track/Global Privacy Control and no-biometrics statements (12); corrected camera/microphone/notifications permission descriptions (14); added breach-notification statement (15); added retention entries for import artifacts and auth email records (9); added baker profile pages: public bio field (2.2), profile visibility, baker name search, and featured-bakers section (6.5), aggregated profile view counters (2.5, 6.5), and their retention/deletion entries (9).n/a (pre-launch)
Crumely

Crumely to przytulne miejsce dla przepisów, do których wraca się częściej niż tylko raz.

FunkcjeJak to działaSpołecznośćCennikFAQ
RegulaminPolityka prywatności

© 2026 Crumely. Wszelkie prawa zastrzeżone.