Back to homepage

Privacy

Transparency matters to us. Here you can see which data we collect, how we use it and which rights you have.

01

Controller

Information pursuant to Art. 4 No. 7 GDPR

Company

Minty Software

Hauptstr 37

76872 Steinweiler

Deutschland

Owner

Deniz Erginos

Minty Software is the new company name of the former provider Flyva Studios. Controller, address and processing activities remain unchanged.

A data protection officer is not required by law and has not been appointed.

02

Data collected at a glance

Which categories of personal data we process

We only process personal data to the extent necessary to provide our service. Below is an overview of the data categories:

  • Account data (email address, hashed password, user ID)
  • Authentication data (JWT token, OAuth identity token from Google or Apple)
  • Nutrition and health data (diet, allergen and ingredient exclusions, only with consent)
  • Location data (coordinates, postcode, city, only with consent)
  • Device and push data (platform, app version, language, push token)
  • Usage data (selected stores, recipe selection, weekly plan, shopping list, planning streak, estimated savings, feedback)
  • Voice input (audio recording or transcript when you dictate items)
  • Household data (membership, role, invite code)
  • Subscription and referral data (plan, expiry date, redeemed partner code)
  • How you heard about Flyva (choice during onboarding, optional free text)
  • In-app usage events (screens opened and time spent, recipes shown, expanded, opened and saved in the feed, filters chosen, session start and end)
03

Hosting & server log files

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

Website and web app are hosted with Vercel, the API runs on Fly.io in the Frankfurt am Main region, the database with Supabase (PostgreSQL, EU region). Recipe images and database backups are stored in the object storage Cloudflare R2.

When our service is accessed, the servers automatically collect technical connection data (server log files) required for secure operation and protection against attacks. This includes:

  • IP address of the requesting device
  • Date and time of access
  • Requested address or API endpoint
  • Browser type and version or app version
  • Operating system used
  • Referrer URL

This data is usually stored for 7 to 14 days and then deleted automatically. We also use the IP address transiently in memory to limit the number of requests per address. This data is not combined with other data sources.

04

Authentication & account data

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

Using Flyva requires a user account. For this we collect:

DataDetails
Email addressAccount identification & communication
Password (hashed)Authentication
User ID (UUID)Internal mapping

Alternatively you can sign in via Google Sign-In or Apple Sign-In. We then receive an identity token from the respective provider. Google and Apple may transmit your email address and your name. We do not process any further data from these services.

Authentication uses JWT (JSON Web Token) with an ES256 signature and JWKS verification. In the mobile app the session is kept in the device's local storage (AsyncStorage), in the web app only in memory. The token is transmitted for verification with every API request.

While a subscription or trial is running we send you service emails about it: a welcome with the first steps, a reminder two days before the first charge, and a weekly summary of your savings. The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Every one of these carries an unsubscribe link; the reminder before the charge is sent even after you unsubscribe, because it belongs to the contract. Sent via Resend.

05

Nutrition & preference data

Legal basis: Art. 9 (2) (a) GDPR (explicit consent)

For personalised meal planning we collect the following preferences. Allergen and ingredient exclusions can constitute health data. We process this data only with your explicit consent:

DataDetails
DietNormal, vegetarian, vegan, pescatarian, plus keto and no pork (max. 3 entries)
Allergen exclusionsUp to 14 allergens under EU Regulation 1169/2011 (e.g. gluten, peanuts, milk)
Ingredient exclusionsMax. 20 freely entered ingredients (e.g. mushrooms)
Number of meals1–7 per week
Number of portions1–10

We also store your saved recipes, your weekly plan, your shopping list (consolidated ingredients, checked and manually added entries), the savings mode as well as your planning streak and estimated savings.

If you belong to a household, the weekly plan, shopping list and saved recipes are visible and editable for all members of that household. Your diet and allergen settings stay personal and are not shared.

06

Location data

Legal basis: Art. 6 (1) (a) GDPR (consent)

Flyva uses location data to find supermarkets and deals near you. Collection happens only with your explicit consent, obtained through a consent dialog.

DataDetails
GPS coordinatesLatitude & longitude
PostcodeManual entry or geocoding
CityManual entry or geocoding
Time of consentISO timestamp

You can also enter your location manually (postcode or city) without granting GPS access. Geocoding is handled by the service Geoapify (see the third parties section).

The search for stores near you runs against our own store database. Your coordinates are not transmitted to third parties for it.

Permissions: on Android we request ACCESS_COARSE_LOCATION and ACCESS_FINE_LOCATION. On iOS locationWhenInUsePermission is required. The permission can be revoked in the device settings at any time.

07

Device data, notifications & usage

Legal basis: Art. 6 (1) (f) and (a) GDPR

We collect the technical details required to operate the app and to deliver notifications:

DataDetails
PlatformiOS, Android or web
App versione.g. 1.2.9
Languagee.g. de or en
Push tokenIdentifier of the Expo push service per device

Notifications (a reminder for today's dish, a note about a new deal week, occasional product announcements) are sent through the Expo Push Service. The basis is the consent you give via the system prompt; you can withdraw it at any time in the app or system settings. Per device we log which notification was sent last in order to avoid duplicates.

To improve Flyva we also record how the app is used: which screens you open and for how long, which recipes are shown, expanded, opened, saved or shared in the feed, which filters you pick, actions in the weekly plan and the shopping list, and when a session starts and ends (app in the foreground). Each event is stored with your user ID, a random session identifier, platform and app version in our own database and is only evaluated in aggregate, for example as the average time spent in the feed. No third-party analytics service is involved and the data is not shared with anyone. The legal basis is our legitimate interest in improving the app (Art. 6 (1) (f) GDPR). You can object to this processing at any time by emailing hello@flyva.app; the events are deleted after twelve months and when your account is deleted.

We collect no advertising IDs, no device fingerprinting and no cross-device tracking. The push token serves only to deliver notifications to your device and is removed when you turn notifications off or delete the app.

08

Third parties & data transfers

Services we use to provide Flyva

For services based outside the EU (among them Google, Apple, Supabase, RevenueCat, Cloudflare, Expo, BytePlus) transfers take place on the basis of the EU-US Data Privacy Framework or, where a provider is not certified, on the basis of the EU Commission's standard contractual clauses.

Supabase

Purpose

Authentication, database, user management

Data

Email, password (hashed), profile data, planning and list data

Legal basis

Art. 6 (1) (b) GDPR — performance of a contract

Fly.io

Purpose

Running the API (Frankfurt am Main region)

Data

All data sent through the API, server log files

Legal basis

Art. 6 (1) (b) GDPR — performance of a contract

Vercel

Purpose

Hosting of website and web app

Data

Connection data, server log files

Legal basis

Art. 6 (1) (f) GDPR — legitimate interest

Cloudflare R2

Purpose

Storage of recipe images and database backups, delivery via cdn.flyva.app

Data

Recipe images, encrypted database backups, request data

Legal basis

Art. 6 (1) (b) and (f) GDPR — contract, operational security

Google (Gemini API)

Purpose

Recipe generation, leaflet analysis, processing of voice input

Data

Deal items, diet, exclusions, pantry entries, audio recording or transcript — without user ID

Legal basis

Art. 6 (1) (b) and Art. 9 (2) (a) GDPR

BytePlus (image model)

Purpose

Generation of the recipe images (servers in Singapore)

Data

Recipe title, description, ingredient list — no personal data

Legal basis

Art. 6 (1) (f) GDPR — legitimate interest

Geoapify

Purpose

Geocoding and location autocomplete

Data

Entered search text (postcode, city, address), filtered to Germany

Legal basis

Art. 6 (1) (a) GDPR — consent

RevenueCat

Purpose

Subscription management and in-app purchases

Data

User ID, subscription status, plan, expiry date

Legal basis

Art. 6 (1) (b) GDPR — performance of a contract

Google Sign-In / Apple Sign-In

Purpose

Authentication via OAuth

Data

Identity token, possibly email address and name

Legal basis

Art. 6 (1) (a) GDPR — consent

Expo Push Service

Purpose

Delivery of push notifications

Data

Push token, content of the notification

Legal basis

Art. 6 (1) (a) GDPR — consent

Amazon Alexa

Purpose

Optional account linking to add items to the shopping list by voice

Data

Linking token, spoken item names

Legal basis

Art. 6 (1) (a) GDPR — consent

Resend

Purpose

Email delivery for the contact form, beta access and subscription service emails

Data

Name, email address, message text

Legal basis

Art. 6 (1) (a) and (b) GDPR

Overpass API (OpenStreetMap)

Purpose

One-off seeding of our store database

Data

Geographic search areas — no personal data

Legal basis

Art. 6 (1) (f) GDPR — legitimate interest

09

AI-based processing

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

For recipes, leaflet analysis and voice input we use Google's Gemini models. Depending on the feature, the following is transmitted:

  • Current deal items of the stores you selected
  • Your diet as well as allergen and ingredient exclusions
  • Recipe titles already generated, to avoid repetition
  • Ingredients you enter in the pantry
  • For voice input, the audio recording or the transcript of what you said
  • Leaflet pages of the retail chains for deal recognition (no user data)

Important note on health and voice data:

The transfer happens without your user ID and without any account reference. Diet and allergen settings are only sent as filter criteria, voice recordings only for the duration of processing. We do not store audio recordings.

Internally we log the model, token usage, estimated cost and errors for each operation together with your user ID. These logs do not leave our systems and are not transmitted to Google.

For voice input, speech-to-text conversion may also be performed by the speech recognition of your operating system (Apple or Google). The privacy terms of the device manufacturer additionally apply in that case.

10

Payments, plans & referrals

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

Payments are handled exclusively through the app stores (Apple App Store, Google Play) and the service RevenueCat. We do not store any payment information such as credit card numbers or bank details ourselves.

We only store:

DataDetails
PlanFree, Plus or Pro
Subscription status & expiryActive / inactive, timestamp
Store slots1 to 3, including grandfathering
Redeemed partner codeCode and mapping to the partner

If you redeem a partner's code, we store the mapping of your account to that partner as well as the commission resulting from your payments. The partner receives no personal data about you, only aggregated settlement figures.

11

Website, cookies & local storage

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest)

Flyva sets no cookies and embeds no advertising or tracking networks. On flyva.app we measure reach ourselves and without third parties: per visit a random session identifier is placed in the browser's sessionStorage and stored together with the page view, path, referrer, language and the campaign's UTM parameters.

The session identifier is discarded when the browser tab closes, is not merged across devices and is not linked to an account. We do not store IP addresses for this. You can object to this measurement at any time (see the section on your rights).

Mobile app (iOS / Android)

AsyncStorage keeps the sign-in session, your theme and language choice as well as hints you have already seen. This data stays on your device.

Web app

Authentication happens purely in memory. No data is stored in localStorage or in cookies.

Website (flyva.app)

Apart from the session identifier for reach measurement, nothing is stored on your device. Short links (flyva.app/go/…) only record the click on the respective code server-side, without any identifier of your device.

12

Data security

Technical and organisational measures

  • Encrypted transfer of all data via HTTPS/TLS (enforced)
  • Passwords are stored hashed only (Supabase Auth)
  • JWT-based authentication with ES256 signature and JWKS verification
  • Row Level Security (RLS) — users can only access their own data
  • Service role keys are used server-side only, administrative access is additionally protected by a separate secret
  • Request rate limiting per IP address, where the address is only held transiently in memory
  • Data storage with Supabase (PostgreSQL) with encryption at rest
  • Automatic database backups in object storage, of which only the last five are retained
13

Retention periods

How long we keep the individual data

We store personal data only as long as necessary for the respective purpose or as long as statutory retention obligations apply:

DataDuration
Account and profile dataUntil the account is deleted
Weekly plan, shopping list, saved recipesUntil you delete them, at the latest with the account
Push tokenUntil the device is unregistered or the account is deleted
Server log filesUsually 7 to 14 days
Generation and cost logsUntil the account is deleted
Billing data on subscriptions and commissionsUp to 10 years
Database backupsThe last five backups, older ones are deleted automatically
In-app usage events12 months, then deleted automatically

The session records of the reach measurement on flyva.app carry no account reference and cannot be attributed to a person. They are evaluated in aggregate and kept for channel comparison.

14

Your rights

Pursuant to Art. 15–22 GDPR

You have the right at any time to:

Access

Which data we have stored about you (Art. 15)

Rectification

Correction of inaccurate data (Art. 16)

Erasure

Deletion of your personal data (Art. 17)

Restriction

Restriction of processing (Art. 18)

Data portability

Export of your data in a structured format (Art. 20)

Withdrawal

Withdrawal of consent given, with effect for the future

Complaint

Complaint to a supervisory authority (Art. 77)

Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (f) GDPR (legitimate interest).

The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany.

15

Data deletion & account deletion

Your right to be forgotten (Art. 17 GDPR)

You can delete your account at any time. When your user account is deleted, all associated data is removed automatically (cascading):

  • Profile data (location, diet and allergen preferences, notification settings)
  • Saved recipes, weekly plans and planning streak
  • Shopping lists
  • Selected stores and store slots
  • Registered devices and push tokens
  • Household membership; deleting the creating account also removes the household itself
  • Subscription status, feedback entries and generation logs

Deleting the account does not end an active subscription, because it is managed in the App Store or on Google Play. Cancel it there separately. Billing data we have to keep under commercial and tax law remains stored for the statutory period.

Account deletion can be requested through the app settings or via our account deletion page.

16

Contact for privacy requests

We answer your request within 30 days

For questions about data protection, access requests or the withdrawal of consent you can contact us at any time:

Minty Software

Hauptstr 37, 76872 Steinweiler