Stand: 4. September 2026
Diese Datenschutzerklärung informiert dich darüber, wie die App PanteryPal mit deinen Daten umgeht. PanteryPal ist eine Haushalts-Inventar- und Aufgaben-App ("Was steht an"-Loop). Wir legen großen Wert auf Datensparsamkeit: PanteryPal funktioniert vollständig offline und ohne Konto. Cloud-Synchronisation und das Teilen eines Haushalts sind optional (Opt-in) und werden erst aktiv, nachdem du dich angemeldet hast.
Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) ist:
solutionsmw – Martin Wernicke
Ziegeleiweg 16, 19077 Rastow
E-Mail: [email protected]
Bei Fragen zum Datenschutz oder zur Ausübung deiner Rechte kannst du uns jederzeit unter der oben genannten E-Mail-Adresse kontaktieren.
PanteryPal ist so gebaut, dass du die App vollständig ohne Konto nutzen kannst. Solange du dich nicht anmeldest, werden alle Daten ausschließlich lokal auf deinem Gerät in einer lokalen Datenbank (SQLite) gespeichert. Dazu gehören insbesondere:
Solange du nicht angemeldet bist, verlassen keine dieser Daten dein Gerät. Es findet keine Übertragung an uns oder an Dritte statt. Du benötigst kein Konto, um den vollen Funktionsumfang lokal zu nutzen.
Eine Ausnahme bilden automatisierte Absturzberichte, sofern du der Absturzberichts-Funktion zugestimmt hast (siehe § 8, „Absturzberichte (Sentry)").
PanteryPal bietet eine optionale Cloud-Synchronisation und die Möglichkeit, einen Haushalt mit anderen Personen zu teilen. Diese Funktionen sind Opt-in und werden erst aktiv, wenn du dich anmeldest. Bis dahin findet keine Datenübertragung statt (siehe Abschnitt 2).
Anmeldung (Auth):
Anmeldung mit Google-Konto (optional):
Wenn du dich anmeldest und die Cloud-Synchronisation nutzt:
Haushalts-Einladungen:
https://solutionsmw.de/join?token=…) auf einem Gerät, auf dem PanteryPal nicht installiert oder der App-Link nicht bestätigt ist, landet der Aufruf im Browser auf unserer Web-Ausweichseite; das Token kann dabei in den HTTP-Zugriffsprotokollen der eingesetzten Web-Infrastruktur (Cloudflare, nginx) erscheinen. Die Ausweichseite selbst speichert oder überträgt das Token nicht, bindet keine Tracker ein und gibt die Adresse per no-referrer nicht an Dritte weiter.Kontolöschung (DSGVO Art. 17):
delete_account auf.In-App-Feedback (optional):
feedback, EU/Frankfurt) gespeichert. Bist du angemeldet, wird die Nachricht deiner Konto-ID zugeordnet; andernfalls erfolgt sie anonym (ohne Konto-Bezug).Allergie- und Ernährungshinweise (optional, Gesundheitsdaten):
Die Barcode-Abfrage ist optional. Wenn du einen Produkt-Barcode scannst, wird ausschließlich die Barcode-Nummer an den Dienst OpenFoodFacts (openfoodfacts.org) gesendet, um Produktdetails (z. B. Produktname) abzurufen.
Wenn du keine Barcodes scannst, findet keine solche Abfrage statt.
Rezept-Import per URL (optional): Wenn du beim Anlegen eines Rezepts die Funktion „Aus dem Web importieren“ nutzt, ruft die App die von dir eingegebene Rezept-Webseite direkt von deinem Gerät ab, um Titel, Zutaten und Anleitung (schema.org-Rezeptdaten) sowie ggf. das Rezeptfoto zu übernehmen. Der Betreiber der jeweiligen Webseite erhält dabei die üblichen technischen Zugriffsdaten (z. B. deine IP-Adresse) – an uns werden keine Daten übermittelt. Importierte Rezepte und Fotos werden lokal auf deinem Gerät gespeichert. Rechtsgrundlage: deine aktive Nutzung der Import-Funktion (Art. 6 Abs. 1 lit. b/f DSGVO).
Lokale Erinnerungen (ohne Konto):
Geräteübergreifende Push-Benachrichtigungen (optional, Opt-in, nur mit Konto):
device_push_tokens) gespeichert. Die Zustellung erfolgt über den Dienst Expo Push (Expo) – dabei wird das Push-Token zum Zweck der Zustellung an Expo weitergegeben.Zur Auslieferung künftiger App-Updates (JavaScript-Code) kann der Dienst EAS Update (von Expo betrieben, Hosting in der EU/USA) zum Einsatz kommen. Dabei wird die Anwendung mit aktualisiertem Programmcode versorgt.
PanteryPal fragt nur die Berechtigungen ab, die für bestimmte Funktionen erforderlich sind. Die Berechtigungen werden ausschließlich auf dem Gerät und nur für den jeweiligen Zweck genutzt:
Du kannst diese Berechtigungen jederzeit in den Systemeinstellungen deines Geräts widerrufen. Die betroffenen Funktionen stehen dann ggf. nicht mehr zur Verfügung.
In produktiven App-Versionen nutzt PanteryPal den Dienst Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA) zur automatisierten Erfassung von Absturz- und Fehlerberichten.
Diese Funktion ist standardmäßig deaktiviert. Wir fragen dich um Erlaubnis, bevor Absturzberichte übertragen werden; nur wenn du zustimmst, ist die Funktion aktiv. Du kannst deine Zustimmung jederzeit in den Einstellungen unter „Absturzberichte" widerrufen – danach werden keine weiteren Berichte gesendet.
Hast du zugestimmt, werden bei einem Programmabsturz oder unbehandelten Fehler ein technischer Fehlerbericht (Stapelverlauf, betroffenes Codemodul, Zeitpunkt sowie die zuletzt berührten Bedienelemente vor dem Absturz – technische Bezeichnungen wie „Pressable" oder „TaskRow", keine Texteingaben oder Inhalte) sowie grundlegende Geräte- und App-Informationen (Gerätemodell, Betriebssystemversion, App-Version) an Sentry übertragen. Es werden keine Inhalte deiner Haushaltsdaten, keine IP-Adresse, keine Konto-/E-Mail-Adresse und keine Bildschirmaufzeichnung übertragen; ein automatisiertes Performance-Tracing (fortlaufende Zeit-/Streckenmessung einzelner Abläufe, „Spans" über das Sentry-Performance-Produkt) findet nicht statt. Diese Beschränkung gilt für den automatischen Absturzbericht; das separate, nutzerinitiierte Feedback-Formular „Problem melden" (siehe unten) überträgt auf deinen eigenen Wunsch zusätzliche Angaben. Die zuvor an dieser Stelle beschriebene Leistungs-Zusammenfassung (Scan/Synchronisation/App-Start) läuft seit einer technischen Umstellung nicht mehr über Sentry, sondern über die in § 9 beschriebene Nutzungsstatistik (PostHog) – sie ist damit an deine Zustimmung zu „Nutzungsstatistik" gebunden, nicht mehr an „Absturzberichte".
Feedback-Formular „Problem melden": Zusätzlich zum automatischen Absturzbericht bietet dir PanteryPal in den Einstellungen unter „Über & Hilfe" den Button „Problem melden" an. Dieser öffnet ein Formular ausschließlich dann, wenn du selbst darauf tippst – es gibt keinen automatisch eingeblendeten Button und keine automatische Übertragung. Der Button ist nur nutzbar, wenn du der Absturzbericht-Funktion oben bereits zugestimmt hast.
Sendest du dieses Formular ab, werden zusätzlich zu den technischen Angaben des Absturzberichts folgende, von dir freiwillig eingegebene Daten an Sentry übertragen:
Diese Daten werden ausschließlich bei aktiver Nutzung dieses Formulars übertragen – nicht automatisch und nicht bei einem gewöhnlichen Programmabsturz ohne deine Eingabe. Zweck, Rechtsgrundlage, Speicherdauer, EU-Datenhaltung und Auftragsverarbeitung entsprechen den nachfolgend beschriebenen Angaben zum Absturzbericht.
Zweck: Erkennung, Diagnose und Behebung von Programmfehlern zur Sicherstellung eines stabilen App-Betriebs.
Rechtsgrundlage: Deine Einwilligung (§ 25 Abs. 1 TDDDG für den Zugriff auf Geräteinformationen, i. V. m. Art. 6 Abs. 1 lit. a DSGVO für die anschließende Verarbeitung der im Fehlerbericht enthaltenen Daten). Ohne deine Zustimmung findet keine Übertragung statt.
Speicherdauer: Die Berichte werden nach 30 Tagen automatisch gelöscht.
EU-Datenhaltung: Das Sentry-Projekt ist auf EU-Datenverarbeitung eingestellt (Ingest-Endpunkt ingest.de.sentry.io); die Berichtsinhalte werden in der EU verarbeitet. Bestimmte Konto-/Organisations-Metadaten (nicht die Berichtsinhalte) verbleiben bei Sentry technisch bedingt in den USA; hierfür gilt das EU-US Data Privacy Framework bzw. ergänzend Standardvertragsklauseln gemäß dem mit Sentry bestehenden Auftragsverarbeitungsvertrag.
Auftragsverarbeitung: Mit Sentry besteht ein Auftragsverarbeitungsvertrag nach Art. 28 DSGVO. Dies gilt gleichermaßen für die Daten aus dem Feedback-Formular „Problem melden".
PanteryPal verzichtet auf Werbung und auf verdeckte Nachverfolgung:
Ausgenommen sind die in § 8 gesondert beschriebenen, an deine Zustimmung zu „Absturzberichte" gebundenen Datenflüsse sowie die nachstehende Nutzungsstatistik. Beide setzen deine ausdrückliche Einwilligung voraus und dienen weder der Werbung noch der Profilbildung.
In produktiven App-Versionen kann PanteryPal messen, welche Funktionen genutzt werden. Wir setzen dafür den Dienst PostHog ein (PostHog, Inc., 2261 Market Street, San Francisco, CA 94114, USA) als Auftragsverarbeiter. Die Verarbeitung findet ausschließlich auf Servern in der Europäischen Union (Frankfurt am Main) statt; die Serverregion ist in der App fest hinterlegt und nicht umkonfigurierbar.
Diese Funktion ist standardmäßig deaktiviert. Ohne deine Zustimmung wird der Dienst gar nicht erst gestartet – es entsteht keine Verbindung. Du erteilst die Zustimmung in den Einstellungen unter „Nutzungsstatistik" und kannst sie dort jederzeit widerrufen; die Übertragung endet dann sofort.
Hast du zugestimmt, überträgt die App bei bestimmten Handlungen ein Ereignis aus einer festen, im Programmcode hinterlegten Liste. Übertragen werden ausschließlich der Name des Ereignisses sowie Zahlen und feste Kategorien:
| Ereignis | Begleitende Angaben |
|---|---|
| Onboarding beendet | beendet oder übersprungen; erreichte Seite |
| Artikel angelegt | Art des Artikels (Wertgegenstand, Allgemein, Lebensmittel) |
| Aufgabe angelegt | ob sie sich wiederholt |
| Aufgabe erledigt | ob sie überfällig war |
| Zweites Haushaltsmitglied erreicht | Anzahl der Mitglieder |
| Einkauf abgeschlossen | Anzahl der Einträge |
| Rezept angelegt | Anzahl der Zutaten |
| Rezept gekocht | Anzahl der abgezogenen Vorräte |
| Haushalt angelegt | keine Begleitangaben |
| Einladung erstellt | keine Begleitangaben |
| Bezahlschranken-Ergebnis | Ergebnis: gekauft, wiederhergestellt, abgebrochen, Fehler oder nicht angezeigt |
| Batch-Scan abgeschlossen | Anzahl der eingebuchten Artikel |
Nicht übertragen werden Bezeichnungen von Artikeln, Rezepten, Aufgaben, Einkaufseinträgen oder Haushaltsmitgliedern, keine Fotos, keine Notizen und keine sonstigen Freitexte. Die Datenstruktur der App lässt für diese Ereignisse ausschließlich Zahlen, Wahrheitswerte und Werte aus geschlossenen Listen zu; freier Text ist technisch ausgeschlossen. Ebenfalls nicht erhoben werden Bildschirmaufzeichnungen, automatisch erfasste Bildschirmnamen oder Bedienelemente sowie eine Standortbestimmung anhand der IP-Adresse (im Dienst abgeschaltet).
Nutzungshäufigkeit (App geöffnet, installiert, aktualisiert): Stimmst du der Nutzungsstatistik zu, überträgt zusätzlich das Mess-SDK selbst automatisch technische Ereignisse, wenn du die App öffnest, installierst oder aktualisierst, oder wenn sie in den Vorder- oder Hintergrund wechselt – nicht aus der obigen Liste, sondern direkt aus PostHogs eigenem Software-Baustein. Ihre Begleitangaben sind ausschließlich App-Version, Build-Nummer und Wahrheitswerte (z. B. ob die App aus dem Hintergrund kam) – keine Bildschirmnamen, keine Bedienelemente und kein sonstiger Freitext. Sie liefern die Bezugsgröße (aktive Nutzer:innen je Zeitraum), ohne die sich die obigen Ereignisse nicht in Prozentsätze umrechnen lassen.
Leistungs-Zusammenfassung (Scan/Synchronisation/App-Start): Ebenfalls nur mit deiner Zustimmung zu „Nutzungsstatistik" überträgt PanteryPal höchstens einmal pro Sitzung (beim Wechsel der App in den Hintergrund oder bei Abmeldung) eine einzelne, aggregierte Zusammenfassung: Anzahl und durchschnittliche Dauer von Barcode-Scans, Synchronisationsläufen und App-Starts je Erfolgs-/Fehler-Kategorie sowie Zähler für unerwartete Fehler in festen technischen Kategorien („App-Start", „Scan", „Sync", „Benachrichtigungen", „Sonstiges"). Ein einzelner unerwarteter Fehler wird zusätzlich sofort mit seiner festen technischen Kategorie übertragen. Beides enthält ausschließlich Zahlen und feste technische Kategorien – keine Freitexte, keine Barcode- oder Vorratsinhalte, keine IDs und keine fortlaufende Nachverfolgung einzelner Sitzungen oder Nutzer:innen über die Zeit hinweg. Bis zu dieser einen Zusammenfassung werden einzelne Scan-/Sync-/Start-Ereignisse ausschließlich lokal auf deinem Gerät gezählt und nicht übertragen; ohne deine Zustimmung werden weder die Zusammenfassung noch der einzelne Fehler gesendet.
Installationsherkunft (Kanal): Stimmst du der Nutzungsstatistik zu, liest die App einmalig, erst nach dieser Zustimmung und niemals davor, die von Google bereitgestellte Installations-Herkunft (Play Install Referrer) aus und ordnet sie einem von sieben festen Werten zu: Play Store ohne markierten Link, Presse, Foren/Gruppen, Empfehlung, TikTok, Instagram oder unbekannt. Dieser Wert wird an dein Benutzerkonto gebunden und mit jedem künftigen Ereignis mitgesendet, nicht nur mit dem ersten – ohne diese dauerhafte Zuordnung ließe sich nach dem ersten App-Start nicht mehr feststellen, über welchen Kanal du gekommen bist. Übertragen wird ausschließlich dieser feste Kategoriewert – keine Klick-Kennung (z. B. „gclid“), keine Kampagnen- oder Anzeigengruppen-Ebene und keine geräteübergreifende Wiedererkennung über diesen Zweck hinaus. Erteilst du deine Zustimmung erst nachträglich in den Einstellungen, kann das Zeitfenster, in dem Google die Installations-Herkunft bereithält, bereits abgelaufen sein – der Kanal wird dann als „unbekannt“ gespeichert, statt ohne deine Zustimmung ausgelesen worden zu sein.
Speicherdauer: PostHog speichert alle Ereignisse der Nutzungsstatistik zwölf Monate ab Erhebung und löscht sie danach automatisch. Löschst du dein Konto, werden die bereits übertragenen Ereignisse bei PostHog nicht gesondert nachträglich entfernt – die einzige Verknüpfung zu deiner Person ist die pseudonyme Konto-Kennung (siehe oben), und die Zuordnung dieser Kennung zu deiner E-Mail-Adresse besteht ausschließlich bei uns. Mit der Kontolöschung entfällt diese Zuordnung vollständig; die verbleibenden Ereignisse bei PostHog sind für uns danach nicht mehr auf dich zurückführbar und laufen spätestens zwölf Monate nach ihrer jeweiligen Erhebung ohnehin aus.
Bist du angemeldet, werden die Ereignisse deiner Benutzer-ID zugeordnet – derselben zufälligen Zeichenfolge, die auch die Cloud-Synchronisation verwendet. So zählt ein Haushalt mit zwei Geräten als ein Haushalt. Deine E-Mail-Adresse wird nicht an PostHog übermittelt. Meldest du dich ab, wird die Zuordnung zurückgesetzt.
Rechtsgrundlage ist deine Einwilligung nach § 25 Abs. 1 TDDDG in Verbindung mit Art. 6 Abs. 1 lit. a DSGVO. Wir speichern zusätzlich den Zeitpunkt deiner Entscheidung auf deinem Gerät, um sie nach Art. 7 Abs. 1 DSGVO nachweisen zu können.
Ein lokales "Einblicke"-/Retention-Panel existiert ausschließlich in Entwickler-Builds (Dev-Builds) und greift niemals auf das Netzwerk zu. In der für dich verfügbaren App-Version werden dadurch keine Daten erhoben oder übertragen.
PanteryPal richtet sich nicht an Kinder. Wir erheben nicht wissentlich personenbezogene Daten von Kindern. Sollten wir Kenntnis davon erlangen, dass uns ohne entsprechende Berechtigung Daten eines Kindes übermittelt wurden, werden wir diese löschen.
Dir stehen nach der DSGVO insbesondere folgende Rechte zu:
So kannst du deine Rechte ausüben:
delete_account) alle zugehörigen Cloud-Daten sofort und unwiderruflich entfernt.Du hast außerdem das Recht, dich bei einer Datenschutz-Aufsichtsbehörde zu beschweren, wenn du der Ansicht bist, dass die Verarbeitung deiner Daten gegen geltendes Recht verstößt.
Der Kern von PanteryPal ist und bleibt kostenlos und vollständig offline nutzbar. Die Haushalts-Teilen-Funktion („household_sharing") ist eine kostenpflichtige Zusatzleistung (Abonnement).
Wir können diese Datenschutzerklärung anpassen, etwa wenn sich Funktionen der App oder rechtliche Anforderungen ändern. Die jeweils aktuelle Fassung wird in der App und/oder im Store-Eintrag bereitgestellt. Das oben genannte Stand-Datum weist auf die letzte Aktualisierung hin.
Last updated: 4 September 2026
This Privacy Policy explains how the PanteryPal app handles your data. PanteryPal is a household inventory and task app (the "Was steht an" / "What's up next" loop). We are committed to data minimization: PanteryPal works fully offline and without an account. Cloud synchronization and household sharing are optional (opt-in) and only become active after you sign in.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
solutionsmw – Martin Wernicke
Ziegeleiweg 16, 19077 Rastow, Germany
Email: [email protected]
If you have any questions about data protection or wish to exercise your rights, you can contact us at any time at the email address above.
PanteryPal is built so that you can use the app fully without an account. As long as you do not sign in, all data is stored exclusively locally on your device in a local database (SQLite). This includes in particular:
As long as you are not signed in, none of this data leaves your device. There is no transmission to us or to any third party. You do not need an account to use the full feature set locally.
An exception applies to automated crash reports, provided you have consented to the crash reporting feature (see § 8, "Crash Reports (Sentry)").
PanteryPal offers optional cloud synchronization and the ability to share a household with other people. These features are opt-in and only become active when you sign in. Until then, no data is transmitted (see section 2).
Sign-in (Auth):
Signing in with a Google account (optional):
If you sign in and enable cloud synchronization:
Household invitations:
https://solutionsmw.de/join?token=…) on a device where PanteryPal is not installed or the app link is not verified, the request lands on our web fallback page in the browser; the token may then appear in the HTTP access logs of the web infrastructure we use (Cloudflare, nginx). The fallback page itself does not store or transmit the token, loads no trackers and, via no-referrer, does not pass the address on to third parties.Account deletion (GDPR Art. 17):
delete_account function.In-app feedback (optional):
feedback, EU/Frankfurt). If you are signed in, the message is associated with your account ID; otherwise it is anonymous (no account reference).Allergy and dietary information (optional, health data):
Barcode lookup is optional. When you scan a product barcode, only the barcode number is sent to the OpenFoodFacts service (openfoodfacts.org) to retrieve product details (e.g. product name).
If you do not scan barcodes, no such lookup takes place.
Recipe import via URL (optional): If you use the “Import from the web” feature when creating a recipe, the app fetches the recipe web page you entered directly from your device to extract the title, ingredients and instructions (schema.org recipe data) and, where available, the recipe photo. The operator of that website receives the usual technical access data (e.g. your IP address) – no data is transmitted to us. Imported recipes and photos are stored locally on your device. Legal basis: your active use of the import feature (Art. 6(1)(b)/(f) GDPR).
Local reminders (without an account):
Cross-device push notifications (optional, opt-in, account only):
device_push_tokens). Delivery is handled by the Expo Push service (Expo) – the push token is shared with Expo for the purpose of delivery.To deliver future app updates (JavaScript code), the EAS Update service (operated by Expo, hosting in the EU/US) may be used. This supplies the app with updated program code.
PanteryPal only requests the permissions required for specific features. Permissions are used exclusively on the device and only for their respective purpose:
You can revoke these permissions at any time in your device's system settings. The affected features may then no longer be available.
In production app versions, PanteryPal uses the service Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA) for the automated collection of crash and error reports.
This feature is disabled by default. We ask for your permission before any crash report is transmitted; it is only active once you consent. You can withdraw your consent at any time in Settings under "Crash Reports" – after that, no further reports are sent.
If you have consented, a program crash or unhandled error triggers the transmission to Sentry of a technical error report (stack trace, affected code module, timestamp, and the UI elements last touched before the crash – technical names such as "Pressable" or "TaskRow", no text input or content) together with basic device and app information (device model, OS version, app version). No household data content, no IP address, no account/email address, and no screen recording are transmitted; automated performance tracing (continuous timing/tracing of individual operations, "spans" via Sentry's performance product) does not take place. This restriction applies to the automatic crash report; the separate, user-initiated "Report a Problem" feedback form (see below) transmits additional information only at your own request. The performance summary formerly described here (scan/sync/app start) no longer runs through Sentry following a technical change — it now runs through the usage statistics (PostHog) described in § 9, and is therefore tied to your consent to "Usage statistics" rather than "Crash Reports".
"Report a Problem" feedback form: In addition to the automatic crash report, PanteryPal offers a "Report a Problem" button in Settings under "About & Help". This opens a form only when you tap it yourself – there is no automatically displayed button and no automatic transmission. The button is only usable once you have already consented to the crash reporting feature above.
If you submit this form, the following data you voluntarily enter is transmitted to Sentry in addition to the technical crash-report information:
This data is transmitted only when you actively use this form – not automatically, and not during an ordinary program crash without your input. Purpose, legal basis, retention period, EU data hosting, and data processing agreement correspond to the information described below regarding the crash report.
Purpose: Detecting, diagnosing, and fixing program errors to keep the app running reliably.
Legal basis: Your consent (§ 25(1) TDDDG for accessing device information, in conjunction with Art. 6(1)(a) GDPR for the subsequent processing of the data contained in the error report). Without your consent, no transmission takes place.
Retention: Reports are automatically deleted by Sentry after 30 days.
EU data hosting: The Sentry project is configured for EU data processing (ingest endpoint ingest.de.sentry.io); report content is processed in the EU. Certain account/organization metadata (not the report content) technically remains with Sentry in the US; this is covered by the EU-US Data Privacy Framework and/or, additionally, Standard Contractual Clauses under the Data Processing Agreement in place with Sentry.
Data processing agreement: A Data Processing Agreement under Art. 28 GDPR is in place with Sentry. This applies equally to the data from the "Report a Problem" feedback form.
PanteryPal avoids advertising and covert tracking:
In production app versions, PanteryPal can measure which features are used. We use the service PostHog for this (PostHog, Inc., 2261 Market Street, San Francisco, CA 94114, USA) as our processor. Processing takes place exclusively on servers in the European Union (Frankfurt am Main); the server region is hard-coded in the app and cannot be reconfigured.
This feature is disabled by default. Without your consent the service is never started – no connection is established. You grant consent in Settings under "Usage statistics" and can withdraw it there at any time; transmission then stops immediately.
If you have consented, the app transmits an event from a fixed list defined in the source code when certain actions occur. Only the event name plus numbers and fixed categories are transmitted: onboarding completed (finished or skipped; slide reached), item created (item type), task created (whether it recurs), task completed (whether it was overdue), second household member reached (number of members), shopping trip completed (number of entries), recipe created (number of ingredients), recipe cooked (number of stock deductions), household created (no properties), invite created (no properties), paywall result (outcome: purchased, restored, cancelled, error or not presented), batch scan completed (number of items booked in).
Not transmitted are the names of items, recipes, tasks, shopping entries or household members, no photos, no notes and no other free text. For these events the app's data structures permit only numbers, booleans and values from closed lists; free text is technically impossible. Also not collected are session recordings, automatically captured screen names or UI elements, and IP-based geolocation (disabled in the service).
Usage frequency (app opened, installed, updated): If you consent to usage statistics, the measurement SDK itself additionally transmits automatic technical events when you open, install, or update the app, or when it moves to the foreground or background – not from the list above, but directly from PostHog's own SDK component. Their accompanying data is limited to app version, build number, and booleans (e.g. whether the app came from the background) – no screen names, no UI elements, and no other free text. They provide the denominator (active users per period) without which the events above cannot be converted into percentages.
Performance summary (scan/sync/app start): Also only with your consent to "Usage statistics", PanteryPal transmits at most once per session (when the app moves to the background or on sign-out) a single, aggregated summary: the count and average duration of barcode scans, sync cycles, and app starts per success/error category, plus counters for unexpected errors in fixed technical categories ("app start", "scan", "sync", "notifications", "other"). A single unexpected error is additionally transmitted immediately with its fixed technical category. Both contain only numbers and fixed technical categories – no free text, no barcode or inventory content, no IDs, and no continuous tracking of individual sessions or users over time. Until this single summary is sent, individual scan/sync/start events are counted locally on your device only and are not transmitted; without your consent, neither the summary nor the individual error is sent.
Installation channel: If you consent to usage statistics, the app reads the installation channel Google provides (Play Install Referrer) exactly once, only after this consent and never before, and maps it to one of seven fixed values: Play Store with no marked link, press, forums/groups, referral, TikTok, Instagram, or unknown. This value is attached to your account and sent along with every future event, not just the first – without this persistent attachment it would no longer be possible to tell which channel brought you after the first app start. Only this fixed category value is transmitted – no click identifier (e.g. “gclid”), no campaign or ad-group level, and no cross-device recognition beyond this purpose. If you grant consent only later, in Settings, the window in which Google keeps the installation channel available may already have passed – the channel is then stored as “unknown” rather than being read without your consent.
Retention: PostHog stores all usage-statistics events for twelve months from collection and then deletes them automatically. If you delete your account, the events already transmitted are not separately removed from PostHog afterwards – the only link to you is the pseudonymous account identifier (see above), and the mapping of that identifier to your e-mail address exists solely with us. Once your account is deleted, that mapping is removed entirely; the remaining events at PostHog can no longer be traced back to you by us and, in any case, expire at the latest twelve months after their respective collection.
While you are signed in, events are associated with your user ID – the same random identifier used by cloud sync. This way a household using two devices counts as one household. Your e-mail address is not transmitted to PostHog. Signing out resets the association.
The legal basis is your consent under § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR. We additionally store the time of your decision on your device in order to demonstrate it under Art. 7 (1) GDPR.
Excepted are the data flows described separately in § 8, tied to your consent to "Crash Reports": the voluntary, purely technical error diagnostics, and the performance summary (scan/sync/app start) transmitted at most once per session – both without usage profiling and without any advertising purpose.
A local "Insights" / retention panel exists only in developer builds (dev builds) and never accesses the network. In the app version available to you, no data is collected or transmitted through it.
PanteryPal is not directed at children. We do not knowingly collect personal data from children. If we become aware that a child's data has been provided to us without appropriate authorization, we will delete it.
Under the GDPR, you have in particular the following rights:
How you can exercise your rights:
delete_account) immediately and irreversibly removes all associated cloud data.You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes applicable law.
The core of PanteryPal is and remains free and fully usable offline. The household sharing feature ("household_sharing") is a paid add-on (subscription).
We may update this Privacy Policy, for example when app features or legal requirements change. The current version will be made available in the app and/or in the store listing. The last updated date above indicates the most recent revision.