Privacy
Transparency matters to us. Here you can see which data we collect, how we use it and which rights you have.
Controller
Information pursuant to Art. 4 No. 7 GDPR
Minty Software
Hauptstr 37
76872 Steinweiler
Deutschland
Deniz Erginos
Minty Software is the new company name of the former provider Flyva Studios. Controller, address and processing activities remain unchanged.
A data protection officer is not required by law and has not been appointed.
Data collected at a glance
Which categories of personal data we process
We only process personal data to the extent necessary to provide our service. Below is an overview of the data categories:
- Account data (email address, hashed password, user ID)
- Authentication data (JWT token, OAuth identity token from Google or Apple)
- Nutrition and health data (diet, allergen and ingredient exclusions, only with consent)
- Location data (coordinates, postcode, city, only with consent)
- Device and push data (platform, app version, language, push token)
- Usage data (selected stores, recipe selection, weekly plan, shopping list, planning streak, estimated savings, feedback)
- Voice input (audio recording or transcript when you dictate items)
- Household data (membership, role, invite code)
- Subscription and referral data (plan, expiry date, redeemed partner code)
- How you heard about Flyva (choice during onboarding, optional free text)
- In-app usage events (screens opened and time spent, recipes shown, expanded, opened and saved in the feed, filters chosen, session start and end)
Hosting & server log files
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)
Website and web app are hosted with Vercel, the API runs on Fly.io in the Frankfurt am Main region, the database with Supabase (PostgreSQL, EU region). Recipe images and database backups are stored in the object storage Cloudflare R2.
When our service is accessed, the servers automatically collect technical connection data (server log files) required for secure operation and protection against attacks. This includes:
- IP address of the requesting device
- Date and time of access
- Requested address or API endpoint
- Browser type and version or app version
- Operating system used
- Referrer URL
This data is usually stored for 7 to 14 days and then deleted automatically. We also use the IP address transiently in memory to limit the number of requests per address. This data is not combined with other data sources.
Authentication & account data
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)
Using Flyva requires a user account. For this we collect:
| Data | Details |
|---|---|
| Email address | Account identification & communication |
| Password (hashed) | Authentication |
| User ID (UUID) | Internal mapping |
Alternatively you can sign in via Google Sign-In or Apple Sign-In. We then receive an identity token from the respective provider. Google and Apple may transmit your email address and your name. We do not process any further data from these services.
Authentication uses JWT (JSON Web Token) with an ES256 signature and JWKS verification. In the mobile app the session is kept in the device's local storage (AsyncStorage), in the web app only in memory. The token is transmitted for verification with every API request.
While a subscription or trial is running we send you service emails about it: a welcome with the first steps, a reminder two days before the first charge, and a weekly summary of your savings. The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Every one of these carries an unsubscribe link; the reminder before the charge is sent even after you unsubscribe, because it belongs to the contract. Sent via Resend.
Nutrition & preference data
Legal basis: Art. 9 (2) (a) GDPR (explicit consent)
For personalised meal planning we collect the following preferences. Allergen and ingredient exclusions can constitute health data. We process this data only with your explicit consent:
| Data | Details |
|---|---|
| Diet | Normal, vegetarian, vegan, pescatarian, plus keto and no pork (max. 3 entries) |
| Allergen exclusions | Up to 14 allergens under EU Regulation 1169/2011 (e.g. gluten, peanuts, milk) |
| Ingredient exclusions | Max. 20 freely entered ingredients (e.g. mushrooms) |
| Number of meals | 1–7 per week |
| Number of portions | 1–10 |
We also store your saved recipes, your weekly plan, your shopping list (consolidated ingredients, checked and manually added entries), the savings mode as well as your planning streak and estimated savings.
If you belong to a household, the weekly plan, shopping list and saved recipes are visible and editable for all members of that household. Your diet and allergen settings stay personal and are not shared.
Location data
Legal basis: Art. 6 (1) (a) GDPR (consent)
Flyva uses location data to find supermarkets and deals near you. Collection happens only with your explicit consent, obtained through a consent dialog.
| Data | Details |
|---|---|
| GPS coordinates | Latitude & longitude |
| Postcode | Manual entry or geocoding |
| City | Manual entry or geocoding |
| Time of consent | ISO timestamp |
You can also enter your location manually (postcode or city) without granting GPS access. Geocoding is handled by the service Geoapify (see the third parties section).
The search for stores near you runs against our own store database. Your coordinates are not transmitted to third parties for it.
Permissions: on Android we request ACCESS_COARSE_LOCATION and ACCESS_FINE_LOCATION. On iOS locationWhenInUsePermission is required. The permission can be revoked in the device settings at any time.
Device data, notifications & usage
Legal basis: Art. 6 (1) (f) and (a) GDPR
We collect the technical details required to operate the app and to deliver notifications:
| Data | Details |
|---|---|
| Platform | iOS, Android or web |
| App version | e.g. 1.2.9 |
| Language | e.g. de or en |
| Push token | Identifier of the Expo push service per device |
Notifications (a reminder for today's dish, a note about a new deal week, occasional product announcements) are sent through the Expo Push Service. The basis is the consent you give via the system prompt; you can withdraw it at any time in the app or system settings. Per device we log which notification was sent last in order to avoid duplicates.
To improve Flyva we also record how the app is used: which screens you open and for how long, which recipes are shown, expanded, opened, saved or shared in the feed, which filters you pick, actions in the weekly plan and the shopping list, and when a session starts and ends (app in the foreground). Each event is stored with your user ID, a random session identifier, platform and app version in our own database and is only evaluated in aggregate, for example as the average time spent in the feed. No third-party analytics service is involved and the data is not shared with anyone. The legal basis is our legitimate interest in improving the app (Art. 6 (1) (f) GDPR). You can object to this processing at any time by emailing hello@flyva.app; the events are deleted after twelve months and when your account is deleted.
We collect no advertising IDs, no device fingerprinting and no cross-device tracking. The push token serves only to deliver notifications to your device and is removed when you turn notifications off or delete the app.
Third parties & data transfers
Services we use to provide Flyva
For services based outside the EU (among them Google, Apple, Supabase, RevenueCat, Cloudflare, Expo, BytePlus) transfers take place on the basis of the EU-US Data Privacy Framework or, where a provider is not certified, on the basis of the EU Commission's standard contractual clauses.
Supabase
Authentication, database, user management
Email, password (hashed), profile data, planning and list data
Art. 6 (1) (b) GDPR — performance of a contract
Fly.io
Running the API (Frankfurt am Main region)
All data sent through the API, server log files
Art. 6 (1) (b) GDPR — performance of a contract
Vercel
Hosting of website and web app
Connection data, server log files
Art. 6 (1) (f) GDPR — legitimate interest
Cloudflare R2
Storage of recipe images and database backups, delivery via cdn.flyva.app
Recipe images, encrypted database backups, request data
Art. 6 (1) (b) and (f) GDPR — contract, operational security
Google (Gemini API)
Recipe generation, leaflet analysis, processing of voice input
Deal items, diet, exclusions, pantry entries, audio recording or transcript — without user ID
Art. 6 (1) (b) and Art. 9 (2) (a) GDPR
BytePlus (image model)
Generation of the recipe images (servers in Singapore)
Recipe title, description, ingredient list — no personal data
Art. 6 (1) (f) GDPR — legitimate interest
Geoapify
Geocoding and location autocomplete
Entered search text (postcode, city, address), filtered to Germany
Art. 6 (1) (a) GDPR — consent
RevenueCat
Subscription management and in-app purchases
User ID, subscription status, plan, expiry date
Art. 6 (1) (b) GDPR — performance of a contract
Google Sign-In / Apple Sign-In
Authentication via OAuth
Identity token, possibly email address and name
Art. 6 (1) (a) GDPR — consent
Expo Push Service
Delivery of push notifications
Push token, content of the notification
Art. 6 (1) (a) GDPR — consent
Amazon Alexa
Optional account linking to add items to the shopping list by voice
Linking token, spoken item names
Art. 6 (1) (a) GDPR — consent
Resend
Email delivery for the contact form, beta access and subscription service emails
Name, email address, message text
Art. 6 (1) (a) and (b) GDPR
Overpass API (OpenStreetMap)
One-off seeding of our store database
Geographic search areas — no personal data
Art. 6 (1) (f) GDPR — legitimate interest
AI-based processing
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)
For recipes, leaflet analysis and voice input we use Google's Gemini models. Depending on the feature, the following is transmitted:
- Current deal items of the stores you selected
- Your diet as well as allergen and ingredient exclusions
- Recipe titles already generated, to avoid repetition
- Ingredients you enter in the pantry
- For voice input, the audio recording or the transcript of what you said
- Leaflet pages of the retail chains for deal recognition (no user data)
Important note on health and voice data:
The transfer happens without your user ID and without any account reference. Diet and allergen settings are only sent as filter criteria, voice recordings only for the duration of processing. We do not store audio recordings.
Internally we log the model, token usage, estimated cost and errors for each operation together with your user ID. These logs do not leave our systems and are not transmitted to Google.
For voice input, speech-to-text conversion may also be performed by the speech recognition of your operating system (Apple or Google). The privacy terms of the device manufacturer additionally apply in that case.
Payments, plans & referrals
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)
Payments are handled exclusively through the app stores (Apple App Store, Google Play) and the service RevenueCat. We do not store any payment information such as credit card numbers or bank details ourselves.
We only store:
| Data | Details |
|---|---|
| Plan | Free, Plus or Pro |
| Subscription status & expiry | Active / inactive, timestamp |
| Store slots | 1 to 3, including grandfathering |
| Redeemed partner code | Code and mapping to the partner |
If you redeem a partner's code, we store the mapping of your account to that partner as well as the commission resulting from your payments. The partner receives no personal data about you, only aggregated settlement figures.
Data security
Technical and organisational measures
- Encrypted transfer of all data via HTTPS/TLS (enforced)
- Passwords are stored hashed only (Supabase Auth)
- JWT-based authentication with ES256 signature and JWKS verification
- Row Level Security (RLS) — users can only access their own data
- Service role keys are used server-side only, administrative access is additionally protected by a separate secret
- Request rate limiting per IP address, where the address is only held transiently in memory
- Data storage with Supabase (PostgreSQL) with encryption at rest
- Automatic database backups in object storage, of which only the last five are retained
Retention periods
How long we keep the individual data
We store personal data only as long as necessary for the respective purpose or as long as statutory retention obligations apply:
| Data | Duration |
|---|---|
| Account and profile data | Until the account is deleted |
| Weekly plan, shopping list, saved recipes | Until you delete them, at the latest with the account |
| Push token | Until the device is unregistered or the account is deleted |
| Server log files | Usually 7 to 14 days |
| Generation and cost logs | Until the account is deleted |
| Billing data on subscriptions and commissions | Up to 10 years |
| Database backups | The last five backups, older ones are deleted automatically |
| In-app usage events | 12 months, then deleted automatically |
The session records of the reach measurement on flyva.app carry no account reference and cannot be attributed to a person. They are evaluated in aggregate and kept for channel comparison.
Your rights
Pursuant to Art. 15–22 GDPR
You have the right at any time to:
Access
Which data we have stored about you (Art. 15)
Rectification
Correction of inaccurate data (Art. 16)
Erasure
Deletion of your personal data (Art. 17)
Restriction
Restriction of processing (Art. 18)
Data portability
Export of your data in a structured format (Art. 20)
Withdrawal
Withdrawal of consent given, with effect for the future
Complaint
Complaint to a supervisory authority (Art. 77)
Right to object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (f) GDPR (legitimate interest).
The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany.
Data deletion & account deletion
Your right to be forgotten (Art. 17 GDPR)
You can delete your account at any time. When your user account is deleted, all associated data is removed automatically (cascading):
- Profile data (location, diet and allergen preferences, notification settings)
- Saved recipes, weekly plans and planning streak
- Shopping lists
- Selected stores and store slots
- Registered devices and push tokens
- Household membership; deleting the creating account also removes the household itself
- Subscription status, feedback entries and generation logs
Deleting the account does not end an active subscription, because it is managed in the App Store or on Google Play. Cancel it there separately. Billing data we have to keep under commercial and tax law remains stored for the statutory period.
Account deletion can be requested through the app settings or via our account deletion page.
Contact for privacy requests
We answer your request within 30 days
For questions about data protection, access requests or the withdrawal of consent you can contact us at any time:
Minty Software
Hauptstr 37, 76872 Steinweiler