Privacy Policy

Last updated: 15 September 2026

1. Overview & scope

This privacy policy informs you about the processing of personal data when using (A) this website and (B) the mobile app "Ernterei" (on the App Store / Google Play). Personal data is any data by which you can be personally identified.

2. Controller

The controller responsible for data processing is:

Thomas Hobrecht
Oberer Hainberg 10
37120 Bovenden, Germany
Email: hallo@ernterei.de

A) Website

3. Data collection on this website

Pre-registration / email form

If you pre-register for the Ernterei app on this website, we collect your email address. It is used solely to inform you about the launch of the app and to send you a confirmation email.

Legal basis: Art. 6 (1) (a) GDPR (consent). You may withdraw your consent at any time by sending an email to hallo@ernterei.de.

Contact form

If you write to us via the contact form, we process the email address you provide, your message and – if given – your name, solely in order to handle and answer your enquiry. We do not pass this data on to third parties and store it only for as long as is necessary to deal with your enquiry.

The legal basis is Art. 6 (1) (b) GDPR (communication in the context of initiating or performing a contract) or Art. 6 (1) (f) GDPR (legitimate interest in answering your enquiry).

Server log files

The provider of this website automatically collects information in what are known as server log files. These are: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. This data is not merged with other data sources. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in technically error-free operation).

4. Website hosting

This website is hosted by all-inkl.com. The provider is ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany.

For details please see the all-inkl.com privacy information: https://all-inkl.com/datenschutzinformationen/

5. Fonts

The fonts used on this website are hosted locally on our own web space. When you load our pages, no connection to Google's servers or any other font provider is established; no data is transmitted to third parties for this purpose.

B) The "Ernterei" app

6. What data the app processes

a) User account

To use the personalised features you create an account. In doing so we process your email address, a password (stored encrypted/hashed and not readable by us in plain text) and a display name of your choosing.
Legal basis: Art. 6 (1) (b) GDPR (performance of the user contract).

b) Your content (journal, pantry, recipes)

Content you create in the app – journal entries, pantry items, quantities, best-before dates, photos, notes and recipes – is stored for you in your account. This content is private and visible only to you unless you actively publish it in the community.
Legal basis: Art. 6 (1) (b) GDPR.

c) Find locations / location data

You can optionally save a location with an entry (for example a mushroom or fishing spot). If you have gathered several kinds, each individual kind can carry its own location as well – so that later you know not just where you set out, but exactly where each find lay.

How these details come about: When you take a photo with the camera inside the app and have granted location access, the app determines where the photo was taken – from the photo’s metadata or by locating the device – and records it as the location: for the entry and, as soon as you assign the photo to one kind, for that kind as well. This happens for every photo taken this way, without asking again. You can also set a location by hand on the map at any time. Without granted location access, no location is created. From photos you pick from your gallery we take no location; there we only evaluate the capture date.

You stay in control: Every location – that of the entry as well as that of an individual kind – can be changed or removed individually at any time. If you remove the entry’s location, the locations of the individual kinds are removed with it. You can withdraw location access at any time in your device settings.

Locations are private and are never shared – not even when you pass an entry on to another person. They belong to the entry they are stored in and are deleted together with it (see sections 9 and 10). To display a map, map tiles are loaded; which data is transmitted to the map service in the process is set out in section 8 (“Maps & place search”).
Legal basis: Art. 6 (1) (a) GDPR (consent).

d) Community content

If you publish a post, a recipe or a photo in the community, that content and your display name are visible to other users of the app. For each item you decide yourself whether it stays private or is published.
Legal basis: Art. 6 (1) (b) GDPR.

e) Reporting and blocking (moderation)

To protect the community, users can report posts and block other users. In doing so we process the report, the content concerned and the accounts involved in order to review and remove impermissible content. This processing is a prerequisite for providing a safe platform and is required by the app store guidelines.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a safe community free from abuse).

f) Push notifications / reminders

If you enable reminders (for example for expiring best-before dates or seasonal tips), these notifications are scheduled and triggered locally on your device. No content is transmitted to us or to third parties for this purpose. You can disable notifications at any time in the app or device settings.
Legal basis: Art. 6 (1) (a) GDPR (consent).

7. Recipe scan (AI text recognition)

The app offers the option to have a photographed recipe – for example from a cookbook or a handwritten card – read out automatically. Using this feature is voluntary: processing only takes place if you explicitly start a scan.

For the text recognition we transmit the photo you have taken to Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA. Only the image is transmitted, together with the technical instruction to read it – no personal data such as your name, your email address or your account identifier.
Legal basis: Art. 6 (1) (b) GDPR (performance of the user agreement).

A data processing agreement pursuant to Art. 28 GDPR is in place with the provider; the transfer to the USA takes place on the basis of the EU Standard Contractual Clauses. Under that agreement the provider may process the transmitted data solely to provide the service – any use for its own purposes, in particular for training AI models, is not permitted under the contract.

We store the photographed original privately in your account so that you can compare the recognised recipe with the source later on. It remains visible to you alone even if you publish the recipe in the community yourself, and it is deleted together with the recipe or your account.

Further information on data protection at the provider: https://www.anthropic.com/legal/privacy

8. Services used & processors

Supabase (database, sign-in & file storage)

The app uses Supabase as the technical basis for user accounts, database and storage of uploaded photos. The provider is Supabase, Inc. App data is stored on servers in the European Union (Frankfurt region). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.

Further information: https://supabase.com/privacy

App stores (distribution & purchases)

The app is distributed and any in-app purchases (for example "Pro" features) are handled via the Apple App Store (Apple Inc.) and Google Play (Google Ireland Limited). Payment data is processed exclusively by the respective store – we neither receive nor store any payment or credit card data. The privacy terms of the respective provider apply.

Expo (app updates)

On launch, the app checks whether an updated program version is available and downloads it if so ("over-the-air update"). This transmits technical details of the installation (platform, app and runtime version, update channel) and your IP address to the update service – no account identifier and no content. The provider is Expo (650 Industries, Inc.), USA.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in keeping the app current and secure).

Further information: https://expo.dev/privacy

Sign in with Apple or Google

You can optionally use "Sign in with Apple" or "Sign in with Google" to register. You are authenticated with the respective provider (Apple Inc. or Google Ireland Limited).

With "Sign in with Apple" we usually receive only an email address; using Apple's "Hide My Email" feature you can use an anonymised forwarding address.

With "Sign in with Google", Google additionally transmits the name stored in your Google account, the address of your Google profile picture and an identifier for your Google account. This information is stored together with your account. We use your name as your display name for as long as you have not set your own display name in the app; the profile picture is not displayed. You can change your display name at any time under Profile.
Legal basis: Art. 6 (1) (b) GDPR.

RevenueCat (subscription management)

We use RevenueCat to manage in-app subscriptions ("Pro"). When a subscription is purchased or restored, we transmit a pseudonymous user identifier and the subscription status so that your Pro status is recognised across devices. Neither we nor RevenueCat receive payment or credit card data – that is processed exclusively by the app store; RevenueCat only receives purchase and subscription information (for example product purchased, time of purchase, status). The provider is RevenueCat, Inc., USA; the transfer to the USA takes place on the basis of the EU Standard Contractual Clauses, and a data processing agreement pursuant to Art. 28 GDPR is in place.
Legal basis: Art. 6 (1) (b) GDPR.

Further information: https://www.revenuecat.com/privacy/

Maps & place search (OpenStreetMap)

We use OpenStreetMap services to display locations on a map and for address and place search. When map tiles are loaded or a place search is carried out, the relevant coordinates or your search term and your IP address are transmitted to the servers of the OpenStreetMap Foundation (St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom).
Legal basis: Art. 6 (1) (f) GDPR (map display) or Art. 6 (1) (a) GDPR for an active place search.

Further information: https://osmfoundation.org/wiki/Privacy_Policy

Maps app (route to the find location)

When you tap “Route” on an entry that has a find location, the app hands the coordinates of that spot to your device’s maps app – usually Apple Maps on iPhones, otherwise Google Maps or whichever app you have set as the default. The same applies to the route button on an individual kind; its own coordinates are handed over in that case. Apple Maps additionally receives a label for the point: for an individual kind its name (for example “porcini”), otherwise the stored place name, or your entry title instead. That provider processes this information under its own privacy terms. This only happens when you tap that button.
Legal basis: Art. 6 (1) (a) GDPR (consent through the deliberate action).

Further information: https://www.apple.com/legal/privacy/ or https://policies.google.com/privacy

Open-Meteo (weather data)

When you save a journal entry with a find location or open the weather detail view, the app retrieves the weather for that place from the Open-Meteo service. This transmits the coordinates of the location and the date, plus your IP address for technical reasons – no account identifier. The provider is OpenMeteo GmbH, Bürglen, Switzerland; Switzerland is covered by an EU adequacy decision (Art. 45 GDPR).
Legal basis: Art. 6 (1) (b) GDPR (provision of the weather feature).

Further information: https://open-meteo.com/en/terms

Sentry (error and crash reports)

We use Sentry for app stability and troubleshooting. If an error or crash occurs, diagnostic data is transmitted to Sentry: error message and stack trace, device type, operating system version, app version and a pseudonymous user identifier so that related errors can be assigned to one sequence. The contents of your journal entries are not transmitted. We do not link these reports to your name or email address; they are deleted after 90 days. The provider is Functional Software, Inc. (Sentry); processing takes place in the European Union (EU region). A data processing agreement pursuant to Art. 28 GDPR is in place.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in stable and secure operation).

Further information: https://sentry.io/privacy/

Email delivery (Brevo)

We use the Brevo service to send system emails (for example registration confirmation, password reset, notifications about your content). This involves processing your email address, the content of the respective system email and the technical data required for delivery. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (part of the Brevo group); processing takes place in the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place.
Legal basis: Art. 6 (1) (b) GDPR (performance of contract).

Further information: https://www.brevo.com/legal/privacypolicy/

Usage statistics (our own, pseudonymous)

To improve the app we record a small number of pseudonymous usage events (for example whether a notice about the Pro features was shown or a purchase was started). This data is processed exclusively on our own infrastructure (Supabase, EU); no external analytics or advertising service is used.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving the product).

9. Retention period

We store your account and content data for as long as your account exists. If you delete your account, your personal data and content are deleted (see point 10). Statutory retention obligations remain unaffected.

10. Account and data deletion

You can delete your account at any time directly in the app: under Profile → Delete account. This irrevocably removes your journal entries, pantry items, community posts, recipes and your account.

Alternatively, an informal email to hallo@ernterei.de is sufficient.

11. Your rights

You have the right at any time to obtain information about the personal data we hold about you, its origin and recipients, and the purpose of the processing. You also have the right to rectification, restriction of processing, data portability and erasure of this data, as well as the right to withdraw consent you have given.

For this and any other questions about data protection you can contact us at any time: hallo@ernterei.de

You also have the right to lodge a complaint with the competent supervisory authority. The authority responsible for Lower Saxony is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).

12. Cookies & tracking

Neither the website nor the app uses cookies for advertising purposes or cross-device user tracking; no advertising IDs are used and no ad networks are integrated. For product improvement we use our own pseudonymous usage statistics, and for stability crash diagnostics (Sentry) – see point 8 for details.

13. Disclaimer regarding content (mushrooms, herbs, wild plants & health)

The articles, tips and user contributions provided in the app are for general information and inspiration only. They do not constitute advice on foraging, identification or consumption of mushrooms, herbs, wild plants or other foods and are no substitute for expert advice or medical guidance.

With wild plants, and mushrooms in particular, there is a risk of confusion with poisonous or deadly species. Foraging, identification and consumption are undertaken entirely at your own risk. If in doubt, do not identify anything yourself but consult a knowledgeable person (for example a mushroom advisory centre). No liability is accepted for health-related or other damage arising from the use of the information provided.

Content published by users reflects their personal views and is not checked for accuracy by the operator.