Privacy Policy
1. Controller
JH Software Solutions, Inhaber Julien Holtz
Hasselkamp 9c
24119 Kronshagen
Deutschland
Phone: +4915233533025
Email: help@mingel.app
2. Visiting the Website
When you visit our website, our hosting provider Cloudflare processes technically necessary data (IP address, date and time of access, requested page, user agent) in server logs to deliver the website securely and reliably. This data is not combined with other data and is deleted after a short period. The provider is Cloudflare, Inc., based in the USA. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer therefore takes place on the basis of the European Commission's adequacy decision pursuant to Art. 45 GDPR and, additionally, on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. The website does not set cookies and does not use any analytics or tracking services.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of the website).
Privacy policy: https://www.cloudflare.com/privacypolicy/
3. Data Collected and Purpose
We collect and process the following personal data:
- Profile data (first and last name, email address, language setting, status of the one-time onboarding): to create and manage your account and to display the app in your language; legal basis Art. 6(1)(b) GDPR
- Timestamp of your consent to the AI features: as evidence of consent required under Art. 7(1) GDPR; legal basis Art. 6(1)(c) GDPR
- Content data (households, shopping lists, recipes including recipe photos you upload, menu plans): to provide the app's features; legal basis Art. 6(1)(b) GDPR
- Email addresses of invited persons: to send and manage household invitations; legal basis Art. 6(1)(b) GDPR
- Subscription status (Free/Pro) and, for a paid subscription, the time the contract was concluded and whether the free trial has already been used: to provide the Pro features and to calculate the withdrawal deadline; legal basis Art. 6(1)(b) GDPR
- Usage counters for the AI features (number of requests per day): to enforce usage quotas; legal basis Art. 6(1)(b) GDPR
- Abuse-prevention counters (number of household invitation attempts and withdrawal submissions per day): to protect these features against automated abuse; legal basis Art. 6(1)(f) GDPR (legitimate interest in the security of our systems)
- Withdrawal declarations (name, email address, contract concerned, time of receipt): to process your withdrawal and as evidence that the deadline was met; legal basis Art. 6(1)(c) and (f) GDPR
- Device information (device type, operating system, app version, IP address): for the technical provision of the app and for processing in-app purchases; legal basis Art. 6(1)(b) GDPR, for certain technical processing additionally Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of the app)
- Crash reports (see section 15): only with your separate consent; legal basis Art. 6(1)(a) GDPR
Providing your first and last name, email address, and password is required to conclude and perform the user agreement. Without this information we cannot create an account for you or provide the app. All other information, in particular recipe photos, is voluntary; without it, only the relevant features will be unavailable to you.
4. Camera and Photo Access
With your permission, the app may access your device's camera and photo library:
- Recipe photos: You can add photos to your recipes. These are stored on our servers until you delete the photo or the recipe and are visible to the members of your household.
- Smart Import: Photos of recipes are transmitted to the Google Gemini API for text recognition (see section 11) and are not stored permanently on our servers.
- Smart Optimize: If your recipe already has a saved photo, it is transmitted together with the title, ingredients, and steps to the Google Gemini API (see section 11) to complete or improve the recipe.
You can revoke camera and photo access at any time in your device's system settings.
The legal basis is Art. 6(1)(b) GDPR; for the transfer to Google as part of Smart Import and Smart Optimize, additionally your consent pursuant to Art. 6(1)(a) GDPR (see section 11).
5. Notifications for Cooking Timers
In cook mode you can start timers for individual preparation steps. So that you notice when a timer ends even while the app is in the background, we schedule a local notification on your device. It contains the title of the recipe and of the respective step and may therefore be visible on your lock screen.
The notification is created and scheduled exclusively on your device. No data is transmitted to us or to any third party, and we do not use server-based push messages. The first time you start a timer, your operating system asks for notification permission; if you decline, the timer keeps working inside the open app. You can change the permission at any time in your device's system settings.
Legal basis: Art. 6(1)(b) GDPR.
6. Data Sharing Within Households
mingel is a household app. Content of your household (shopping lists, recipes, menu plans) as well as your first and last name are visible to all members of your household. When you join a household or invite people to your household, this data is shared accordingly.
The legal basis is Art. 6(1)(b) GDPR.
7. Recipients of Your Data
We only share your data where this is necessary to operate the app. Recipients are:
- The members of your household (see section 6)
- Processors acting for us and on our instructions: our backend and hosting provider, our email delivery service, our bot protection service, our AI service provider, our subscription management service, our update service, and our crash reporting service (sections 2 and 8 to 12, 14 and 15). We have concluded data processing agreements pursuant to Art. 28 GDPR with all processors.
- Independent controllers: Apple and Google process in-app purchases in their own name and under their own responsibility (see section 13).
We do not share your data for advertising purposes and we do not sell it.
8. Supabase (Backend and Authentication)
We use Supabase as our backend infrastructure for data storage, file storage, and user authentication. Data is stored in a data centre within the European Union. The provider is Supabase, Inc., based in the United States; where access from third countries cannot be ruled out in individual cases, it takes place on the basis of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Legal basis: Art. 6(1)(b) GDPR.
Privacy policy: https://supabase.com/privacy
9. Cloudflare Turnstile (Protection Against Automated Access)
When you sign up, sign in or reset your password, we use Cloudflare Turnstile to prevent automated access (bots) and abuse. Your IP address as well as technical device and browser information are transmitted to Cloudflare and evaluated there in order to determine whether the request originates from a human. Turnstile does not set cookies and, according to the provider, does not use the data for advertising or profiling. The check usually runs invisibly; an additional interaction is only shown in doubtful cases.
The provider is Cloudflare, Inc., based in the United States. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer takes place on the basis of the adequacy decision pursuant to Art. 45 GDPR and, additionally, on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and in the security of our systems).
Privacy policy: https://www.cloudflare.com/privacypolicy/
10. Brevo (Transactional Emails)
For sending transactional emails (e.g. sign-up and confirmation emails, password resets, household invitations) we use Brevo (formerly Sendinblue). The relevant email address is transmitted to Brevo for this purpose. When you invite a person to your household, this also applies to the email address of that person as provided by you; the invitation email also includes your name and the household's name so the invited person can tell what the invitation is about. These details are additionally stored by us to manage the invitation. Brevo is based in the EU; as a rule, no transfer to third countries takes place.
We also use Brevo to send the contract confirmation required under sec. 312f(2) of the German Civil Code when you take out mingel Pro, and, if you exercise your right of withdrawal online, the acknowledgement of receipt of your withdrawal under Art. 11a of the Consumer Rights Directive / sec. 312k of the German Civil Code. At the same time as that acknowledgement, Brevo also delivers an internal notice to our own mailbox so the withdrawal can be processed (see section 17).
Legal basis: Art. 6(1)(b) GDPR; for the acknowledgement of receipt and the contract confirmation, additionally Art. 6(1)(c) GDPR.
Privacy policy: https://www.brevo.com/en/legal/privacypolicy/
11. Google Gemini API (AI Features)
The app's AI features, Smart Import and Smart Optimize, use the Google Gemini API operated by Google LLC, based in the United States: for Smart Import, recipe photos you upload are transmitted to Google for text recognition. For Smart Optimize, the recipe title, ingredients, steps, and, if present, the saved recipe photo are transmitted so the AI can complete or improve the recipe.
Each feature only runs when you actively start it. We obtain your express consent before you use them for the first time. You may withdraw it at any time with effect for the future by turning the AI features off in your profile in the app; alternatively you can contact us at the address given in section 20. The remaining features of the app are unaffected.
Please note that recipe photos may unintentionally contain further personal data, such as people in the frame or information visible in the background. This also applies to an already-saved recipe photo transmitted for Smart Optimize. Where possible, please only upload photos limited to the recipe itself.
We contractually use the Gemini API under the paid tier, under which Google processes the transmitted content solely to provide the service, does not use it to train its models, and stores it at most temporarily for abuse monitoring. We ourselves do not permanently store the transmitted content.
Google LLC is certified under the EU-US Data Privacy Framework; the transfer to the United States therefore takes place on the basis of the adequacy decision pursuant to Art. 45 GDPR. In addition, we have agreed the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, so that the transfer remains safeguarded should the adequacy decision cease to apply. We do not rely on the derogations in Art. 49 GDPR for this transfer.
Legal basis: Art. 6(1)(a) GDPR (consent).
Privacy policy: https://policies.google.com/privacy
12. RevenueCat (Subscription Management)
We use RevenueCat to manage subscriptions (mingel Pro). For this purpose, a pseudonymous user identifier as well as purchase and device data are transmitted to RevenueCat; RevenueCat does not receive your email address or payment data from us. RevenueCat Inc. is based in the United States and is not certified under the EU-US Data Privacy Framework. The transfer is therefore carried out on the basis of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented by additional safeguards: transmission exclusively in encrypted form and limitation to a pseudonymous identifier and purchase data, without name, email address, or payment data.
Legal basis: Art. 6(1)(b) GDPR.
Privacy policy: https://www.revenuecat.com/privacy
13. Apple and Google (In-App Purchases)
In-app purchases are processed through the Apple App Store or Google Play Store. Payment processing is handled exclusively by Apple or Google. We do not receive any payment data. Apple and Google process the data arising in connection with the purchase as independent controllers under their own privacy policies; we have no influence over that processing.
Apple Privacy: https://www.apple.com/privacy/
Google Privacy: https://policies.google.com/privacy
14. Expo (App Updates)
The app uses the EAS Update service provided by Expo, Inc., based in the United States, to keep app content up to date without a store update. When updates are fetched, technically necessary data (IP address, device and app information) is transmitted to Expo. Expo, Inc. is certified under the EU-US Data Privacy Framework; the transfer to the United States takes place on the basis of the adequacy decision pursuant to Art. 45 GDPR and, additionally, on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and up-to-date app).
Privacy policy: https://expo.dev/privacy
15. Sentry (Crash Reports)
For troubleshooting, the app uses the Sentry service provided by Functional Software, Inc. We run our Sentry project in the EU region; reports are processed and stored in a data centre in the European Union.
A report is only created when the app crashes or hits an unhandled error. The data transmitted is technical: device model and operating system version, app and release version, language, the time of the error, the error message with its stack trace, as well as a pseudonymous installation identifier and a rough trail of the last network requests to our backend (the requested path without query parameters, without content).
We have configured the service so that no personal data is sent along: your account data is not attached to the report, your IP address is not stored, query parameters of server requests are removed before sending, app log output is not transmitted, and the content of your shopping lists, recipes and menu plans is not transmitted. No session recording takes place.
At the end of setup we ask you once whether we may send crash reports. Without your consent we send nothing and store nothing on your device for this purpose. You can give and withdraw your consent at any time with effect for the future in the app privacy settings. Withdrawing ends the service on your device: the SDK is closed and sends no further reports from that point on. Reports already transmitted to Sentry before the withdrawal are unaffected and are deleted there after the period stated in this section. The app is fully usable without consent.
Sentry automatically deletes reports after 30 days; the period follows from our booked plan and is set when the data is ingested.
Legal basis: Art. 6(1)(a) GDPR (consent). Because the Sentry SDK also stores information on your device for this purpose, we obtain your consent under sec. 25(1) TDDDG at the same time.
Privacy policy: https://sentry.io/privacy/
16. No Automated Decision-Making
We do not carry out automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR. The app's AI features only generate suggestions for recipe content and preparation steps; they do not make decisions that produce legal effects concerning you or similarly significantly affect you.
17. Retention Period
Your data is stored for as long as your account is active. If you delete your account, your account and the associated personal data, including the recipe photos you uploaded, are erased irreversibly without undue delay, as a rule immediately as part of the deletion process. Technically unavoidable copies in backup media are overwritten as part of our regular backup cycles within no more than 30 days. Statutory retention obligations remain unaffected.
Content you created in a shared household (e.g. shopping lists and recipes) remains available to the other members of that household because it continues to be used there; the link to you as a person is removed.
Household invitations expire after 7 days. The email address of an invitation is deleted as soon as the invitation is accepted, and at the latest shortly after it expires.
If you withdraw from a paid contract, we retain the withdrawal declaration together with your name, email address and the time of receipt in order to evidence that the deadline was met and how the contract was unwound. This record survives deletion of your account and is retained for three years from the end of the year, matching the regular statutory limitation period under sec. 195 and sec. 199(1) of the German Civil Code (a withdrawal received in August 2026 is therefore deleted on 1 January 2030); an automated process deletes expired records monthly. The legal basis is Art. 6(1)(c) and (f) GDPR in conjunction with Art. 17(3)(e) GDPR. The same applies if you declare your withdrawal by email instead (see section 18).
The usage counters for the AI features and the abuse-prevention counters (see section 3) are kept on a daily basis and are removed when your account is deleted; no further retention takes place.
Server logs of our hosting provider are deleted after a short period (see section 2).
18. Getting in Touch
You can reach us at help@mingel.app: for support requests, to exercise your rights as a data subject (see section 19), and to declare your withdrawal informally by email instead of using the app's online withdrawal function (see section 9 of the Terms of Service). In doing so, we process your email address and the content of your message in order to handle it and reply to you.
The legal basis is Art. 6(1)(b) GDPR insofar as your message relates to an existing or prospective contract (e.g. support requests and withdrawal declarations), and otherwise Art. 6(1)(c) GDPR in conjunction with the data subject rights under Art. 15 to 21 GDPR.
The mailbox is provided by our email provider (see section 7).
If you declare your withdrawal by email instead of through the online withdrawal function, the same retention period applies to that email as for the withdrawal declarations described in section 17: three years from the end of the year under sec. 195 and sec. 199(1) of the German Civil Code. For all other requests through this mailbox, we retain your message for as long as necessary to handle it and to document that it was handled, generally no longer than one year after the request has been finally answered.
19. Your Rights
Under the GDPR you have the following rights:
- Access to your stored data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
Where processing is based on consent (Art. 6(1)(a) GDPR), you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Where we base processing on a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.
To exercise your rights, please contact: help@mingel.app
You also have the right to lodge a complaint with a data protection supervisory authority. You may address the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement. The authority competent for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstraße 98, 24103 Kiel
https://www.datenschutzzentrum.de
20. Contact and Version
For privacy-related questions, please contact us at:
help@mingel.app
Last updated: 2026-08-09