Notvorrat

Privacy policy

This is a translation. The binding version is the German one; in case of doubt, the German text prevails.

Controller

Stefan Hölting
c/o Autorenglück #42102
Albert-Einstein-Straße 47
02977 Hoyerswerda
Germany
E-mail: support-notvorrat@your-app-world.de

The most important point first

Notvorrat is a purely on-device app. There are no user accounts, no registration, no server run by the developer, no advertising, no tracking and no third-party analytics tools. Everything you enter – household composition, supplies, expiry dates, checklists, notes and shopping list – stays on your device, or, if you turn it on, in your private iCloud.

The one exception is receipts and shelf photos: only if you use these features and have given your consent does the text of the item lines without prices, or the photo, go to Apple for analysis – not to the developer.

The developer has no access to this data at any time.

Processing on the device

The following data is stored exclusively locally:

This data leaves your device only if you use iCloud syncing, send the shopping list to the Reminders app, or export and share a backup yourself. No processing by the developer takes place in doing so.

Special categories of personal data

Information about pregnancy, breastfeeding or medication in the note fields may constitute health data within the meaning of Art. 9 GDPR. It is processed exclusively on your device, is voluntary for calculating your requirement and can be deleted at any time. It is not transmitted to the developer.

Camera

The camera is used exclusively to scan barcodes and expiry dates and to photograph packaging, receipts and storage shelves – and only when you open the relevant feature. Barcode scanning, date scanning and photo recognition of packaging run entirely on the device; no images are stored or transmitted, and the scanned code is not sent to any product database on the internet. When scanning a date, the app takes only the date you select from the recognised text; the rest of the text is not stored. What is transmitted for receipts and shelf photos is set out in the section “Receipts and shelf photos”.

The legal basis is Art. 6 (1) (a) GDPR – you grant the permission in iOS and can withdraw it there at any time.

Photo recognition with Apple Intelligence

On devices with Apple Intelligence you can photograph packaging or choose a photo from your library to obtain suggested items. Apple's language model analyses the photo exclusively on your device; it is transmitted neither to the developer nor to Apple or third parties, and is not stored after analysis. From your library the app receives only the single photo you select. Only the items you confirm in the review list are saved.

Receipts and shelf photos

From iOS 27, on devices with Apple Intelligence, you can have a receipt or a photo of your storage shelf analysed to obtain several suggested items at once. Unlike photo recognition of packaging, this analysis does not run on your device but on Apple Private Cloud Compute – the servers on which Apple Intelligence handles tasks that need more computing power than the device. The app transmits data for this only after your consent, which it asks for the first time you use the feature.

According to Apple, the data in Private Cloud Compute is used only to answer the particular request, is not stored afterwards and is not accessible to Apple either. The developer runs no server and receives neither the photo nor the receipt text nor the result. In the app, the photo and receipt text remain only until you close the dialog; only the items you accept in the review list are saved.

The provider of Private Cloud Compute is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, or Apple Distribution International Ltd., Cork, Ireland. Apple's privacy policy applies: https://www.apple.com/legal/privacy/

The legal basis is your consent under Art. 6 (1) (a) GDPR. You can withdraw it at any time under “More → Cloud recognition”; this does not affect the lawfulness of analyses carried out until then. Without consent, every other way of adding items remains available unchanged.

Notifications

Reminders about expiring supplies are scheduled locally on the device. There is no push service run by the developer, no device tokens and no server connection.

Reminders app

If you send your shopping list using the corresponding button, the app creates the open entries in a list of its own called “Notvorrat” in Apple's Reminders app. Other lists are neither read nor changed. Whether and how Reminders itself syncs via iCloud is for you to decide in the iOS settings.

The legal basis is Art. 6 (1) (a) GDPR.

iCloud syncing

If you turn on syncing, the app mirrors its data through the private iCloud database of your Apple Account (Apple CloudKit). The developer is technically unable to access this private database.

The provider of the service is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, or Apple Distribution International Ltd., Cork, Ireland. Apple's privacy policy applies: https://www.apple.com/legal/privacy/

The legal basis is Art. 6 (1) (b) GDPR – syncing is part of the function you requested. You can turn it off for this app at any time in the iOS settings under “Apple Account → iCloud”.

App Store and in-app purchases

Purchase, payment and management of in-app purchases are handled exclusively by Apple. This applies to “Notvorrat Pro” as well as to the voluntary support payments. From Apple the developer receives only aggregated, non-personal sales and payout reports. Payment data is neither collected nor stored by the developer.

Legal basis: Art. 6 (1) (b) GDPR.

Diagnostic data

The app includes no crash reporting or analytics services of its own. If your device sends diagnostic data to Apple, that is based on your consent in the iOS system settings (“Analytics & Improvements”). At most the developer receives anonymised crash reports from it through App Store Connect.

Contact and support

If you write us a support e-mail, we process your details – sender address, subject, message text and any attachments – exclusively to deal with your enquiry and in case of follow-up questions. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in answering your enquiry. If the enquiry concerns a purchase or the run-up to one, Art. 6 (1) (b) GDPR applies in addition.

We do not run the support mailbox ourselves: it is hosted by Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Your message sits in our mailbox there and is read and answered exclusively by us personally.

No AI service is involved. The contents of your message are neither analysed automatically nor used to train AI models; there is no automated decision-making in individual cases within the meaning of Art. 22 GDPR.

Google acts as our processor under Art. 28 GDPR; a corresponding data processing agreement is in place.

What you write to us is up to you. To deal with a support enquiry we need neither your full list of supplies nor details of your household – please redact such details in screenshots. For sensitive matters you are welcome to write to us without your real name, from a neutral address.

Messages are deleted as soon as they are no longer needed, and at the latest once statutory retention periods have expired.

Recipients and third countries

We do not pass on the data you enter in the app – we have no access to it. Personal data has recipients only in the cases described above:

With both, processing may also take place in the USA. The transfers are safeguarded by the European Commission's standard contractual clauses; Apple and Google are additionally certified under the EU-US Data Privacy Framework.

Retention and deletion

Your data remains stored until you delete it. You delete individual entries directly in the app, and all of them at once under “More → Back up data → Delete all data”. All local data is removed when you delete the app from your device. Data synced via iCloud must additionally be removed in the iOS settings under “Apple Account → iCloud → Manage Storage”.

Your rights

You have the rights to information (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). We hold no data about you from the app itself; to that extent we can only answer a request in the negative. If you have written to us, these rights concern the correspondence in the support mailbox.

You also have the right to lodge a complaint about the processing with a data protection supervisory authority (Art. 77 GDPR). In particular you may contact the authority of your habitual residence, your place of work or the place of the alleged infringement.

Changes

We adapt this statement when changes to the app make that necessary. The current version is available in the app under “More → Privacy” and at https://your-app-world.de/notvorrat/privacy.html

Hosting of this page

This text is additionally served as a web page through GitHub Pages (GitHub, Inc., USA). In doing so GitHub processes technically necessary connection data such as the IP address; we do not receive the server logs ourselves. The legal basis is Art. 6 (1) (f) GDPR. Details are set out in the privacy policy of the website: your-app-world.de

Last updated: 26 September 2026