Privacy Policy

Last updated: September 14, 2026

1. Introduction

Adapt IT (“we”, “us”, or “our”) operates the Prvi zalogajmobile application (the “App”) and the website at https://prvizalogaj.com(the “Site”). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

By downloading or using the App you agree to this Privacy Policy. If you do not agree, do not use the App.

2. Data We Collect

2.1 Data stored locally on your device

The App stores the following data exclusively on your device using the Hive local database. This data is never transmitted to us:

  • Language and dietary preferences (vegetarian, vegan, gluten-free, dairy-free, meat preferences)
  • Favourite recipes and cooking history
  • Meal plan calendar entries
  • Active cooking session state (for session persistence across app restarts)
  • IAP retry queue (encrypted purchase receipts queued for re-verification on network recovery)

2.2 In-App Purchase receipts

When you make a purchase, the App sends the purchase receipt issued by Apple or Google to our verification backend at api.prvizalogaj.com. We store only:

  • The purchase receipt token (a cryptographic identifier issued by Apple or Google)
  • The product ID purchased
  • The entitlement state (active / expired)
  • Timestamps of purchase and last verification

We do not store your name, email address, payment card details, or any personal identifier. The receipt token is an opaque string; we cannot derive personal information from it.

2.3 Device and install identifiers

The App generates two random identifiers. Neither is bought, shared, or linked to your identity, and neither is an advertising identifier.

  • Install ID — a random UUID created the first time you open the App and erased when you uninstall it. It ties your purchases to your installation so entitlements survive a reinstall.
  • Device ID — on Android the system-provided app-scoped ID, on iOS a random UUID held in the Keychain. It exists so the free allowance of cooking-companion sessions counts per device rather than resetting on every reinstall.

2.4 Location — only if you turn it on

The App can sort supermarket branches by how far they are from you. This is off by default. It is switched on from Settings, at which point your device asks your permission, and you can leave it off and pick your city from a list instead — everything else works the same.

When it is on:

  • We ask the operating system for an approximate position, not a precise one.
  • The coordinates are sent to our backend in the body of a single request, used to calculate distances to shops, and discarded. They are not written to any database, and not recorded in our server logs — the request is deliberately shaped so that the coordinates never appear in a log line.
  • On your phone the coordinates are held in memory only for as long as the App is open. The only thing saved is your yes-or-no answer, so we do not have to ask again.
  • We never track you in the background, and never build a history of where you have been.

Shop positions themselves come from OpenStreetMap, are calculated once on our servers, and are stored as ordinary business addresses. That data is published under the Open Database License, © OpenStreetMap contributors.

2.5 Camera and photos — only if you use them

The App uses the camera for two separate things, both of which you start deliberately:

  • Recipe ideas from a photo (paid feature). If you photograph your fridge or groceries, or pick an existing picture, the image is sent to our backend and forwarded to OpenAI, which reads what food is in it and suggests meals. We do not save the image: it is not written to our database, and our logs record only its size in bytes. What is done with it at OpenAI is governed by their terms, linked in Section 9.
  • Scanning a purchase transfer code. The camera reads a QR code shown on another phone. Only the code itself is sent to us; no image or video from the camera leaves your device.

2.6 Microphone and voice control

During a cook you can turn on voice control and say things like “next”. The microphone is active only while you have switched that on for that cook.

The audio is handled by your phone’s own speech recognition — Apple’s on iOS, Google’s on Android — which, depending on your device and language, may process it on their servers under their privacy policies. The App then matches the recognised words against a short list of commands. Neither the audio nor the transcript is ever sent to us, and nothing is recorded or kept.

2.7 Spoken cooking steps

The cooking companion can read each step out loud. It is off by default, and we ask you once, the first time you cook.

The voice is not produced on your phone, and not in the moment. We record every step of every recipe in advance, in each language, and host the resulting audio files ourselves. Turning the reader on downloads those files the way the App downloads a recipe photo, and keeps them for next time. Nothing you say, type, or cook is sent anywhere to make this work — the App only asks our server for a file.

Like any file request, the download appears in the server logs described in Section 2.9, so the log line names the recipe step being fetched. Those logs are deleted after 14 days and are not used to profile anyone.

We use ElevenLabs to make the recordings. That happens on our side, ahead of time, from our own recipe text. No user data is sent to them, and nothing is sent to them while you cook.

2.8 Things you write to us

If you send a recipe suggestion from Settings, we store the text you wrote together with your device ID, so we can read it and avoid counting the same suggestion twice. Please do not include personal details in it.

2.9 Server logs

Like any web service, our backend records a line for each request: the time, the path called, the response status, the browser or app making the call, and your IP address. These logs exist for security and debugging, are not used to profile anyone, and are rotated and deleted after 14 days. As described in Section 2.4, coordinates are kept out of them by design.

3. Optional analytics and crash reports

Only when you enable analytics in the App or consent to analytics on the Site, we process pseudonymous technical events such as app version, language, feature usage, and crash diagnostics. We use Firebase Analytics and Firebase Crashlytics for the App, and Google Analytics on the Site. We do not send recipe prompts, purchase receipts, names, email addresses, or precise location in analytics events.

Our verification backend at api.prvizalogaj.com may send server error reports, performance traces, and operational logs to Sentry when configured. These contain technical diagnostics only (request path, error type, server environment) — not recipe prompts, purchase receipts, names, or email addresses.

Site analytics are disabled until you grant consent in the Site banner. In-app telemetry is disabled in unconfigured builds and is enabled only for releases that have been configured for this purpose.

4. AI recipe generation

Paid plans can generate a recipe from a description you type, or from a photo as described in Section 2.5. What you write, the number of servings and your language are sent to our backend and forwarded to OpenAI, which writes the recipe.

The finished recipe is saved on our servers as an unpublished draft, so that a good one can be reviewed and added to the catalogue for everyone. It is stored as recipe content — a title, ingredients and steps — and is not filed against you. Your prompt is not stored as a field of its own, and our production logs record only its length, never its text. Please do not type personal details into a recipe prompt.

5. Advertising

People who have not bought anything may be shown ads: a rewarded video if you want an extra cooking-companion session once the free ones are used, and an occasional ad after finishing a cook. Ads are served by Google AdMob.

In the European Economic Area and the UK, Google’s consent form appears before any ad is requested, and no ad loads until you have answered it. Depending on that answer, AdMob may use your device’s advertising identifier. Buying any paid item removes ads entirely — subscription, Chef Pack or Steak Masterclass. We receive no advertising data ourselves; we never send your recipes, prompts, shopping list, or location to an advertiser.

6. Data We Do Not Collect

  • No names, email addresses, payment card details, or contact lists
  • No precise or background location, and no history of where you have been
  • No recordings of your voice, and no transcripts of what you said
  • No photographs stored on our servers
  • No contacts, messages, calendars, health data, or files
  • No sale, rental, or sharing of personal data with data brokers
  • No advertising identifiers or personalised advertising without the applicable consent

7. Purpose of Processing

We process the limited data described above for the following purposes:

  • Purchase verification: to confirm your entitlement to paid content and prevent fraud (legitimate interest / contract performance).
  • Entitlement persistence: to restore your purchases across reinstalls on the same account (contract performance).
  • Product quality: when you consent, to understand feature use and diagnose crashes so we can improve the App and Site (consent / legitimate interest where permitted).

8. Data Retention

  • On your device — until you uninstall the App or clear its data.
  • Purchase entitlements — for as long as the purchase remains valid, plus 90 days so that a restore still works.
  • Free-allowance counts — kept against the device ID while the App is in use.
  • Recipe suggestions you send — until we have read and acted on them.
  • Location — not retained at all. It is used to answer one request and dropped.
  • Photos sent to the AI feature — not retained by us.
  • Server logs — 14 days, then deleted automatically.

You may request earlier deletion at any time; see Section 12.

9. Third Parties

We share data only with the following parties, and only as described:

  • Apple Inc.— to verify iOS purchases via Apple App Store Server API. Apple’s privacy policy: apple.com/privacy
  • Google LLC— to verify Android purchases via Google Play Developer API. Google’s privacy policy: policies.google.com/privacy
  • EU VPS hosting provider — supplies compute and networking for our self-managed verification backend. The provider does not access application data. Contact us at info@adapt-it.agency for the current provider name and privacy policy.
  • Google Firebase / Google Analytics— provides optional analytics and crash diagnostics when enabled or consented to. Google's privacy policy: policies.google.com/privacy.
  • Functional Software, Inc. (Sentry)— provides server-side error monitoring, performance tracing, and operational logs for our verification backend when configured. Sentry's privacy policy: sentry.io/privacy.
  • OpenAI, L.L.C.— writes recipes from the description you type, and reads the food in a photo you choose to send, as described in Sections 2.5 and 4. OpenAI's privacy policy: openai.com/policies/privacy-policy.
  • Google AdMob— serves the ads shown to users who have not made a purchase, as described in Section 5, subject to the consent form Google presents. Google's privacy policy: policies.google.com/privacy.
  • Apple and Google speech recognition— your phone's own voice recognition may process spoken commands on their servers, as described in Section 2.6. This happens between your device and the platform; we neither receive nor store any of it.
  • ElevenLabs, Inc.— records the spoken cooking steps described in Section 2.7. We send them our own recipe text, ahead of time, to produce audio files we then host. No user data reaches them, and your device never contacts them. ElevenLabs' privacy policy: elevenlabs.io/privacy-policy.
  • OpenStreetMap Foundation — supplies the positions of shop branches, looked up once by us from published addresses. No user data is sent to them, and your own location is never shared with them. Store positions are © OpenStreetMap contributors, available under the Open Database License.

We do not sell, rent, or share personal data with advertisers or data brokers.

10. Children's Privacy

The App is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. Security

Our backend is deployed with TLS encryption in transit and uses parameterised queries against a PostgreSQL database. Purchase receipts are stored as received from Apple and Google and are not further transmitted. We apply rate limiting and bearer-token authentication on all verification endpoints.

12. Your GDPR Rights

If you are located in the European Economic Area, you have the following rights regarding personal data we hold about you (i.e., IAP entitlement records):

  • Access — request a copy of the data we hold about your purchase receipts.
  • Erasure — request deletion of your entitlement record. This will invalidate any active entitlements tied to that record.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Complaint — lodge a complaint with your local supervisory authority (in Croatia: AZOP — azop.hr).

To exercise any of these rights, email us at info@adapt-it.agencywith the subject line “GDPR Request”. We will respond within 30 days.

13. Google Play — Data Safety Declaration

This section mirrors what we declare on the Google Play Data Safety form. Everything is encrypted in transit, none of it is sold, and you can ask us to delete it.

  • Purchase history — collected, required for the app to work. Receipt tokens, used to confirm what you have bought.
  • Device or other IDs — collected, required for the app to work. The install and device identifiers in Section 2.3, used for entitlements and the free allowance.
  • Approximate locationaccessed but not collected. Used in the moment to work out which shops are nearest and then discarded; it is not stored on our servers or logged. Optional, and off unless you turn it on.
  • Photosaccessed but not collected. Sent to our server and on to OpenAI only when you use the photo feature, to identify ingredients; not stored by us. Optional.
  • Audio — not collected. Voice commands are recognised by the operating system; neither audio nor transcript reaches us.
  • Other user-generated content — collected when you send a recipe suggestion or a recipe prompt. Optional.
  • App activity and crash logs — collected only in builds configured for telemetry, as described in Section 3. Optional.
  • Not collected at all: name, email address, contacts, messages, calendar, health and fitness, financial details, files, or web browsing history.
  • Children: the app is not directed at children.

14. Apple App Store — App Privacy Nutrition Labels

This is what we declare in App Store Connect. Nothing we collect is used to track you across other companies’ apps or websites.

  • Data Used to Track You: if you consent to personalised ads, the advertising identifier used by AdMob. Declining the consent form, or buying anything, removes this.
  • Data Not Linked to You: purchase history (receipt tokens); identifiers (the install and device IDs in Section 2.3); user content (recipe prompts, photos sent to the AI feature, recipe suggestions); coarse location, used only to rank nearby shops and not retained; usage data and diagnostics in telemetry-enabled builds.
  • Data Linked to You: none. We hold no account, name, or email address to link anything to.
  • Data Not Collected: contact info, health and fitness, financial info, contacts, messages, browsing history, sensitive info, and audio.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy.

16. Contact Us

For privacy-related questions or requests, contact:
Adapt IT
Bregovita ulica 7, 10292 Harmica, Croatia
Email: info@adapt-it.agency