← Glaner

Legal

Privacy Policy

Last updated: 20 May 2026

This policy explains what Glaner does with the information you give it and the information it sees while you use the app. It is written in plain English. If anything is unclear, write to us at the address at the bottom of this page and we will rewrite it.

Who runs Glaner

Glaner is built and operated by André Santana, an individual developer based in Portugal. For the purposes of EU data-protection law (GDPR / RGPD), André Santana is the data controller.

The short version

You take a photo of your fridge. We send that photo to OpenAI so they can list the ingredients in it. We use that list to generate three recipes, which we send back to your phone. We do not store the photo on our servers, we do not link it to you, and OpenAI does not use it to train their models. OpenAI may keep the photo briefly (up to 30 days) for abuse monitoring before deleting it.

Everything else, including the recipes you save, the shopping lists you build, and the preferences you set, stays on your device. You can export it as a single JSON file from Settings, and you can wipe it from Settings too.

What we collect

Photos you take in the app

When you snap your fridge, your phone sends the photo to our recipe engine. The engine is operated by OpenAI under their commercial API terms. They process the image and return a list of detected ingredients. OpenAI may retain the image for up to 30 days for abuse monitoring, after which it is deleted. They do not use your image to train future models. We never see the photo ourselves and we do not write it to our own storage.

Things you save in the app

Recipes you favourite, shopping lists you create, and your cooking preferences (diet, allergies, servings, cooking time, units) are saved on your device in the standard iOS app sandbox. We do not have a copy.

Subscription information

If you subscribe to Glaner Plus, we use RevenueCat to verify the purchase with Apple. RevenueCat receives an anonymous identifier attached to your device (Apple's IDFV) and the purchase receipt from Apple. We do not see your name, email address, or payment details. Apple handles those.

Crash and diagnostic data

If you have opted in to share crash reports with developers in your iOS Settings, Apple may forward anonymised crash logs to us. These contain stack traces and device information, never the contents of your photos or saved data.

What we do not collect

  • We do not have user accounts. There is no name, no email, no password.
  • We do not track you across other apps or websites.
  • We do not use analytics or attribution SDKs.
  • We do not sell or share your data with advertisers.

Who processes your data on our behalf

Processor What they see Where
Apple App Store purchase, app install, iOS crash reports Global
OpenAI The photo you snap, to detect ingredients. Retained up to 30 days for abuse monitoring, not used for training USA
RevenueCat Apple's IDFV and your subscription receipt USA

Sending your photo to OpenAI is an international transfer of personal data outside the EU and UK. OpenAI relies on the EU Standard Contractual Clauses for this transfer. You can read OpenAI's API policy at openai.com/policies/api-data-usage-policies.

Where your data is stored

On your device, except for the brief moment a photo is in transit to OpenAI for processing. We do not maintain a Glaner-side database of user data.

How long we keep it

  • Photos: up to 30 days at OpenAI for abuse monitoring, then deleted. Never retained by us.
  • Saved recipes, lists, preferences: until you delete them or uninstall the app.
  • Subscription receipt: as long as the subscription is active, and afterwards for as long as required by tax and consumer law.

Your rights

Under the EU GDPR, you have the right to:

  • Ask what data we hold about you.
  • Ask us to correct it.
  • Ask us to delete it.
  • Object to processing.
  • Receive a copy in a portable format.
  • Lodge a complaint with your local supervisory authority.

For the on-device data, you can exercise all of these from inside the app: Settings → Data and legal → Export my data / Reset preferences / Delete account. For anything else, write to the address below.

In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.

Children

Glaner is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you think a child has used the app, write to us and we will help.

Changes

If we change this policy, we will update the date at the top and, if the change is material, surface a notice the next time you open the app.

Contact

Write to [email protected]. We answer in English and Portuguese, usually within a few working days.