Privacy Policy
Last updated: 23 July 2026
At MadPlanner, we take the protection of your personal data seriously. This privacy policy describes what data we collect, why, and what rights you have under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
The policy applies to the MadPlanner website (madplanner.dk), the free demo and the MadPlanner app (app.madplanner.dk, including the Android app). The Danish version is legally binding; English and German are courtesy versions.
1. Data Controller
The data controller responsible for processing your personal data is:
MadPlanner v/ Jacopo L. B. Valeri
CVR: registration pending
Email: privacy@madplanner.dk
2. What Data We Collect and Why
2.1 On the website
| Data | Purpose | Legal basis | Stored? |
|---|---|---|---|
| Email address (demo/shopping list) | Delivery of the shopping list by email (optional); marketing only with separate consent | Consent (Art. 6.1.a) | Yes — see section 9 |
| IP address | Rate limiting (abuse protection); not stored beyond the request | Legitimate interest (Art. 6.1.f) | No — transient |
| Plausible Analytics (self-hosted) | Privacy-friendly visit statistics. Now active. No cookies, no personal data, data remains on our own servers in the EU | Legitimate interest (Art. 6.1.f) | No PII |
| Third party (website, addition) | Purpose | Transfer |
|---|---|---|
| Resend | Sending the shopping list by email from the demo (only if you provide your email address) | USA — SCC |
2.2 In the app
| Data | Purpose | Legal basis | Stored? |
|---|---|---|---|
| Account: email, name, login | Creation and operation of your account (via our login provider Clerk) | Contract (Art. 6.1.b) | For as long as the account exists |
| Household members: names, roles (adult/teen/child) | Meal planning for the whole household — you enter the members yourself | Contract (Art. 6.1.b) | For as long as the account exists |
| Dietary restrictions and allergies per member | Safe meal planning (e.g. gluten-free). Health-related data (special category, Art. 9) — encrypted in the database and processed only with your explicit consent | Explicit consent (Art. 9.2.a) | For as long as the account exists; consent can be withdrawn at any time |
| Meal plans, dishes, shopping lists, pantry | The core functionality | Contract (Art. 6.1.b) | For as long as the account exists |
| Receipt images + scanned text (OCR) | Optional feature: purchase tracking. Images are stored encrypted | Contract (Art. 6.1.b) | For as long as the account exists; can be deleted individually |
| Spending/budget figures | Optional feature, requires active opt-in in the app | Consent (Art. 6.1.a) | Until consent is withdrawn |
| AI chat and AI meal plans (Premium) | Your messages and relevant household data (including dietary restrictions) are sent to Google (Gemini) to generate responses — only after your explicit consent in the app, which names Google and the data types | Consent (Art. 6.1.a / 9.2.a) | Chat history for as long as the account exists |
| Payment details | Subscription via Stripe. We never see or store your card details — only Stripe's customer ID and your email address | Contract (Art. 6.1.b) | For as long as the subscription exists |
| Error reports | Troubleshooting (Sentry). Stripped of personal data before being sent | Legitimate interest (Art. 6.1.f) | Briefly at Sentry |
3. Special Note on Dietary Restrictions and Allergies (Art. 9)
Information about allergies and dietary restrictions is health-related and is treated as a special category of personal data. Therefore:
- We ask for your explicit consent before you register dietary restrictions — both for storage and (separately) for AI processing at Google.
- The data is stored encrypted in the database.
- You can withdraw your consent and delete the data in the app at any time — the app continues to work, but without allergy-adapted planning.
- The warning function is fail-closed: if a dish cannot be verified against the household's restrictions, it is marked as unverified rather than shown as safe. The function is an aid and does not replace your own check of ingredients and packaging.
4. Children and Household Members
The account holder must be at least 18 years old. As the account holder you can create household members — including your children — with a name and any dietary restrictions. This information is entered by you as a parent or guardian and is processed solely on the basis of your consent and for meal planning for your household. Member data can be edited or deleted in the app at any time, and it is deleted together with the account. We never address minors directly.
5. Data Processors and Third Parties
All data processors are bound by data processing agreements in accordance with GDPR Art. 28 (copies are kept by the data controller — register maintained as of 20 July 2026).
| Third party | Purpose | Transfer to third countries |
|---|---|---|
| Hetzner Online GmbH | Hosting of the app and the database. All content is stored in the EU (Germany/Finland) | None |
| Clerk, Inc. | Login and account management (email, name, sessions) | USA — EU-US Data Privacy Framework / SCC |
| Stripe, Inc. | Payment processing. Card data is handled exclusively by Stripe | USA — EU-US Data Privacy Framework / SCC |
| Google (Gemini) | AI features (Premium), only after explicit consent | USA — EU-US Data Privacy Framework / SCC |
| Cloudflare, Inc. | Website hosting, CDN and DDoS protection | USA — SCC |
| Sentry (Functional Software, Inc.) | Error reporting, stripped of personal data | USA — DPF / SCC |
| Plausible (self-hosted) | Visit statistics without cookies — runs on our own Hetzner server; no third party receives data | None |
6. Your Rights
As a data subject, you have a number of rights under GDPR (Art. 12–22). You can exercise your rights by contacting us at privacy@madplanner.dk. We will respond within 30 days.
Right of access (Art. 15)
You have the right to obtain confirmation as to whether we process personal data about you, and if so, to receive a copy of that data together with information about the purposes, categories and recipients.
Right to rectification (Art. 16)
You have the right to have inaccurate personal data about you corrected and incomplete data completed.
Right to erasure ("right to be forgotten", Art. 17)
If you have submitted your email address, you may request erasure by contacting us at privacy@madplanner.dk. We will process your request within 30 days.
Right to data portability (Art. 20)
You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format.
Right to restriction of processing (Art. 18)
Under certain circumstances you have the right to request that the processing of your personal data be restricted — for example while the accuracy of the data is being verified, or if you have objected to processing under Art. 21.
Right to object (Art. 21)
You have the right to object to our processing of your personal data that is based on legitimate interest (Art. 6.1.f). This applies to our processing of IP addresses for rate limiting and anonymous usage statistics. We will then cease the processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to withdraw consent
If our processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal. You may unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.
Right to lodge a complaint with the supervisory authority
If you believe that our processing of your personal data is in breach of data protection law, you have the right to lodge a complaint with the Danish supervisory authority, Datatilsynet:
Export in the app (Art. 20)
Under account settings you can download your data in a structured, machine-readable format (JSON) — without contacting us.
Deletion in the app (Art. 17)
You can delete your account directly in the app. The deletion removes your login account (Clerk), your Stripe customer, all household data, receipt images and derived data. See section 9 regarding backups.
7. Cookies
The website uses only necessary cookies (login, payment, security) — therefore no consent banner. See the Cookie Policy for the full overview. The app uses only technically necessary mechanisms for login and operation (no tracking, no third-party cookies).
8. Security
- All traffic is encrypted (TLS 1.2/1.3).
- Particularly sensitive fields — dietary restrictions and receipt images — are additionally encrypted in the database/file system itself.
- Data is hosted in the EU. Access is restricted and logged; isolation between users is tested on an ongoing basis.
- Backups are encrypted.
9. Retention Periods
| Data | Period |
|---|---|
| Account data and household data | For as long as the account exists; deleted when the account is deleted |
| Backups | Deleted data may persist in backups for up to 30 days, after which it is deleted |
| Demo email (website, without marketing consent) | 30 days after sending |
| Email with marketing consent | Until consent is withdrawn |
| Error and operational logs | Up to 30 days, stripped of personal data |
10. Changes
Material changes will be notified visibly.