1.Who Is Responsible
The controller for the processing described here is:
skycraft GmbH
Leibnizstraße 5
01187 Dresden
Germany
Managing director: Dr. David Urbansky. For questions about data protection, write to [email protected].
2.This Website
Hosting
simmerset.com runs on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. To deliver a page, Cloudflare processes your IP address, the page you asked for, the time, your browser's user agent and the page you came from, and it uses these data to protect the site from attacks. Cloudflare works for us as a processor under a data processing agreement. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a secure website that loads quickly.
Plausible Analytics
We count visits with Plausible Analytics, a service of Plausible Insights OÜ, Tartu, Estonia. Plausible sets no cookies, stores nothing on your device and builds no profile of you. For each page view it records the page address, the site you came from, your browser, operating system and type of device, and the country, region and city it derives from your IP address.
To count unique visitors per day, Plausible calculates a hash from your IP address, your browser's user agent, the website's domain and a random value that changes every 24 hours and is then deleted. Plausible never stores your IP address or user agent, so neither Plausible nor we can recognize you later or on other websites.
On this website we also count clicks on the buttons that open the app, together with the button's position on the page and the link it opens. These events carry no details about you. In the app, Plausible counts a few steps the same way, such as a planned week or a started subscription, together with numbers like how many dinners were planned and whether billing is monthly or yearly. The app tells Plausible which kind of screen was opened (for example, a recipe page) and never the address of a particular recipe, list or invitation.
Plausible keeps the data in the EU, on servers of Hetzner in Falkenstein, Germany, and uses Bunny, a European network from Slovenia, to deliver its service and protect it from attacks. We use Plausible under a data processing agreement. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest is to learn how people find and use Simmerset without tracking anyone. Plausible neither stores nor reads information on your device, so it needs no consent under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG). You can object at any time (see your rights), and a content blocker also stops the Plausible script.
Campaign tags in links
If you arrive through a link with campaign tags (utm parameters), for example from one of our ads, the website adds those tags to the links on the page, including the links into the app, so we can see which campaign brought you. Nothing is stored on your device for this, and we ignore click ids such as gclid. We use no advertising pixels.
Error monitoring with Sentry
To find and fix errors on this website, in the app and in our API, we use Sentry, a service of Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. We never tell Sentry who you are: it gets no name, email address or account number from us.
Every page on this website loads Sentry's script from Sentry's servers. If the page fails, your browser sends Sentry an error report: the error message, the place in our code where it happened, your browser and operating system, the address of the page without any parameters, and the time.
The app sends the same kind of error report and measures how long one in five screens take to load. It tells Sentry which kind of screen was open (for example, a recipe page) and never the address of a particular recipe, list or invitation.
The app also keeps a recording of the last 60 seconds on screen in your browser's memory. It sends that recording to Sentry only when an error happens, as a replay, and then keeps recording until the visit ends: after 15 minutes without activity, or after 60 minutes at most. The replay shows how the screens looked and where you tapped or scrolled. All text and everything you type are hidden in it, so nobody can read your plans, lists, allergies or diets. Photos are hidden as well, and the replay does not record where they come from.
Our API reports its own errors to Sentry: the error, the kind of request that failed (such as loading a week), the time and a reference number for the request. For one in five requests it also records how long the request took. It never sends the content of your requests, your email address or your sign-in tokens.
Sentry sees your IP address when your browser loads its script or sends it a report, as any server does. We have set Sentry not to store IP addresses, but it may still use yours to work out a rough location, such as the country, before discarding it.
Sentry stores the reports in the EU, in Frankfurt, Germany, and deletes them after 30 days. As a US company, it may still access them from the USA, for example when we ask its support for help. Section 12 explains how such transfers are protected.
We use Sentry under a data processing agreement. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a website and an app that work and stay secure. Sentry sets no cookies and neither stores nor reads information on your device, so it needs no consent under Section 25 TDDDG. You can object at any time (see your rights), and a content blocker also stops the reports.
Chat assistant
The chat button at the bottom right of each page opens our AI assistant. The assistant is Yoonoo, a chat service of skycraft GmbH, the company that operates Simmerset, and it runs on our servers at Hetzner in Germany. Each page loads the chat's script and picture from yoonoo.ai through Cloudflare, which sees your IP address as described under Hosting. Your words reach the assistant only when you send a message.
When you send a message, Yoonoo passes the conversation, along with the passages of this website that fit your question, to OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, which writes the reply. Yoonoo also uses OpenAI to rate how helpful each conversation was and to summarize the week's conversations for us. OpenAI works for us as a processor under its data processing addendum. It keeps the messages for up to 30 days to run the service and detect abuse, does not use them to train its models, and may process them in the USA; Section 12 explains how such transfers are protected.
We keep each conversation (your messages, the replies and when they were sent) for 90 days, to see what visitors ask and to improve the assistant and this website, and then delete it. No IP address, name or page address is stored with it. The chat sets no cookies and stores nothing on your device. An AI writes the replies, and they can be wrong; what this website says is what counts. Please do not type health information, passwords or payment details into the chat.
The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in answering questions about Simmerset. Because the chat neither stores nor reads information on your device, it needs no consent under Section 25 TDDDG. You can object at any time (see your rights), and a content blocker also stops the chat.
3.The Former Waitlist
Before Simmerset opened, people could leave their email address on a waitlist. We deleted those addresses and the details stored with them without using them, and the copies in our nightly backups are gone after 14 days. The legal basis for storing them was the consent given at sign-up (Art. 6(1)(a) GDPR). We no longer collect addresses this way.
4.Your Account
Accounts and sign-in are run by Clerk, Inc., 660 King Street, Unit 345, San Francisco, CA 94107, USA, as our processor. Clerk stores your email address, sends you the sign-in codes by email and keeps your session. To protect accounts against misuse, it also processes your IP address and information about your device. If you sign in with Google where that option is offered, Google shares your name, email address and profile picture with Clerk.
In our own database we keep the email address and name that Clerk passes on to us, your language, and when you last used the app.
The legal basis is Art. 6(1)(b) GDPR, because we need an account to provide Simmerset to you.
5.Your Household and Your Plans
To plan dinners, we store what you enter in the app:
- your household, its members and their roles, and the people without an account whom you add (for example a child), with their names and portion sizes
- servings, dinners per week, cooking days, time per evening and kitchen equipment
- allergies, diets and dislikes, for the household and for each person
- planned weeks, grocery lists and what you check off, and favorites
- the dinners you mark as cooked, your ratings of recipes, and optional comments
- recipes you add or import, and problem reports about recipes with an optional note
Everyone in a household sees the household's week, list, favorites, allergies, diets and dislikes. You invite people with a link that you share yourself. We send no invitation emails and store only a fingerprint (hash) of the link.
When you import a recipe from a web page, our server fetches that page once and stores the link, the name of the site, the time of the fetch and the recipe it found.
When you try Simmerset without an account, your answers, including allergies, go to our server to plan the preview. The server does not store them. Your browser keeps them for up to 7 days, so you can pick up where you left off.
The legal basis is Art. 6(1)(b) GDPR, because we need these data to provide Simmerset. For allergies and other health data, see the next section. If you enter details about other people, for example your child's allergies, make sure you may share them with us.
6.Allergies, Diets and Other Health Data
Allergies and intolerances are data about your health, and so are diets you follow for medical reasons and nutrition goals such as a limit on salt. The GDPR gives these data special protection (Art. 9 GDPR). We process them only with your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), which the app asks for before it saves them.
We use these data only to choose recipes for your household and to show you your goals, never for advertising, and we do not share them with advertisers. Everyone in your household sees them.
You can withdraw your consent at any time, with effect for the future. Remove the allergies, diets and goals under Preferences, or delete your account. We then delete these data, and Simmerset can no longer keep those foods out of your plans. Withdrawing consent does not make the processing up to that point unlawful.
7.Payments
Plus is billed through Stripe. For customers in the European Economic Area, the Stripe company responsible is Stripe Payments Europe, Limited, Dublin, Ireland.
On Stripe's checkout page you enter your payment details and your billing address. Stripe uses them to take the payment, to work out tax (Stripe Tax) and to prevent fraud. Your card number goes to Stripe and never reaches us.
We give Stripe your email address, your language and internal reference numbers for your household. Stripe tells us whether your subscription is active and sends us the billing details you gave it, such as your name, email address and billing address, but never your full card number.
For the payment itself, Stripe works for us as a processor. Where the law requires it, for example to prevent fraud and money laundering, Stripe acts as a controller in its own right. Stripe's privacy policy is at stripe.com/privacy.
The legal basis is Art. 6(1)(b) GDPR for the payment, and Art. 6(1)(c) GDPR for the records that tax and commercial law require us to keep.
8.Where Your Data Is Stored
Cloudflare Pages delivers the app at app.simmerset.com. Our API and our database run on our own server, rented from Hetzner Online GmbH, Gunzenhausen, Germany, in a data center in Falkenstein, Germany. Requests to the API pass through Cloudflare's network, which encrypts the connection and shields the server from attacks. Cloudflare therefore sees your IP address and your requests.
Recipe pictures load from img.spoonacular.com, the image server of the Spoonacular recipe database, which we also run. Cloudflare delivers them as well.
Our server writes access logs with the time, the address asked for and technical details of each request. We keep them for 14 days. We back up the database every night and keep each backup for 14 days.
The app and our API also report errors to Sentry, as section 2 describes.
The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in running Simmerset securely and restoring it after a fault.
9.Storage on Your Device
The website sets no cookies and stores nothing on your device.
The app stores on your device what it needs to work. This is allowed without consent under Section 25(2) no. 2 TDDDG:
- Clerk's sign-in cookies, which keep you signed in
- your language, light or dark display, your selected household and the progress of the recipe you are cooking
- a random device number that stops a change from being saved twice
- a copy of the current week, the grocery list and the planned recipes, so you can read them offline
- your answers while you try Simmerset without an account, for up to 7 days
- during checkout, Stripe's reference for that checkout
10.Export and Deletion
Under Account in the app, you can download your data as a JSON file: your profile, your household with its members and preferences, allergies and diets, weeks, lists, your own recipes, favorites, and your cooking history and ratings. The file also holds what other members entered for the household. The download link works for 72 hours, and then the file is deleted.
You can also delete your account under Account. For your protection, you must have signed in within the last 10 minutes. Deletion runs in the background and takes a few minutes. It removes your data, your sign-in at Clerk and any stored export, and it cancels a running Plus plan at the end of the period you have paid for. If you own a household that has other members, you first hand it to one of them or delete it. What you added to a household that continues stays with that household.
You can also have your Simmerset account deleted by email: write to [email protected] from the address you sign in with, and we delete it as described above.
We keep only what the law requires: billing records, for up to 10 years under German tax and commercial law, and the record of your consents as proof. We also keep a marker with an internal number and without your email address, so that a late message from Stripe or Clerk cannot recreate the deleted account. Stripe keeps its own payment records under the obligations that apply to it.
11.How Long We Keep Data
- Account and household data: until you delete them or your account.
- Data exports: 72 hours.
- Server logs: 14 days.
- Backups: 14 days.
- Billing records: up to 10 years, as German tax and commercial law requires.
- Plausible statistics: they contain no personal data and stay available for as long as we use Plausible.
- Sentry reports: 30 days, including load times and replays.
- Chat conversations: 90 days.
12.Service Providers and Transfers Outside the EU
These service providers process personal data for us, each under a data processing agreement:
- Cloudflare, Inc., USA: hosting of the website and the app, delivery and protection of the API and the recipe pictures.
- Clerk, Inc., USA: accounts and sign-in, including the sign-in emails.
- Stripe Payments Europe, Limited, Ireland: payments and tax calculation. Stripe is also a controller in its own right where the law requires it.
- Hetzner Online GmbH, Germany: the servers for our API, our database and the chat assistant.
- Plausible Insights OÜ, Estonia: visitor statistics without personal data.
- Functional Software, Inc. (Sentry), USA: error reports for the website, the app and the API, and load times for the app and the API, all stored in Frankfurt, Germany.
- OpenAI Ireland Limited, Ireland: replies, ratings and weekly summaries for the chat assistant on this website.
Cloudflare, Clerk and Stripe (through Stripe, Inc.) also process data in the USA. Sentry keeps our reports in Frankfurt but may access them from the USA, for example for support. The European Commission has decided that companies certified under the EU-U.S. Data Privacy Framework ensure an adequate level of data protection (Art. 45 GDPR), and Cloudflare, Clerk, Stripe and Sentry are certified. Our agreements with them also include the EU standard contractual clauses (Art. 46(2)(c) GDPR). OpenAI may also process chat messages in the USA, on the basis of the EU standard contractual clauses in its data processing addendum.
13.Your Rights
You have the right:
- to know which data we hold about you (Art. 15 GDPR)
- to have wrong data corrected (Art. 16 GDPR)
- to have your data deleted (Art. 17 GDPR)
- to have the processing restricted (Art. 18 GDPR)
- to receive your data in a common machine-readable format (Art. 20 GDPR)
- to withdraw a consent at any time, with effect for the future (Art. 7(3) GDPR)
Right to object
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time for reasons arising from your particular situation (Art. 21 GDPR). We then stop, unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.
How to use your rights
Write to [email protected]. You can do much of it yourself in the app: change or remove your details under Preferences, and download your data or delete your account under Account.
You can also complain to a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work. The authority responsible for us is:
Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany
Website: www.datenschutz.sachsen.de
14.The Apps for Android and iOS
This policy also covers the Simmerset apps for Android and for iOS (iPhone and iPad). Both apps open the same service as app.simmerset.com, so everything in this policy applies to them as well.
Google distributes the Android app through Google Play. When you download or update it, Google processes your data under its own privacy policy, as a controller in its own right and not as our processor. Google gives us statistics and crash reports that do not identify you, such as the number of installs per country.
Apple distributes the iOS app through the App Store. When you download or update it, Apple processes your data under its own privacy policy, as a controller in its own right and not as our processor. Apple gives us statistics and crash reports that do not identify you, such as the number of downloads per country. Crash reports and statistics on how the app is used come only from people who have agreed to share analytics with app developers.
If you review one of the apps on Google Play or in the App Store, we see your review and the name shown with it, and we may reply there. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in answering feedback on Simmerset.
You cannot buy anything in the apps. You sign in with your email address and a code; the apps do not offer sign-in with Google or Apple.
The apps label what they send to Plausible with their platform ("android" or "ios"), and their error reports for Sentry with the platform and the app's version number, so we can tell the apps apart from the website. These labels do not identify you.
15.Other Points
You do not have to give us any data. Without an email address, though, we cannot create an account, and without payment details you cannot buy Plus. Allergies and diets are optional, but without them Simmerset cannot keep those foods out of your plans.
We make no automated decisions that have legal effects on you or affect you in a similarly significant way (Art. 22 GDPR). Simmerset proposes dinners automatically, and you decide what to cook.
Simmerset is not meant for children under 16 to use on their own.
We do not sell personal data, show no advertising and use no advertising or social media tracking.
16.Changes to This Policy
We update this policy when Simmerset or the law changes. The date at the top shows when the current version took effect.