Deutsch · Nederlands
Privacy policy
Knift
Who is responsible
Idyia Maritime Projects B.V.
privacy@knift.nl
The short version
The app works without an account: recipes, shopping list and your own prices sit on your device and stay there. You only need an account if you want to sync your data between two devices, or share offers and prices with others.
We store no name, no email address and no profile picture — not even from Google.
What we store if you create an account
- Your Google identifier („sub") — a string of digits that only points at you together with Google’s own data — plus when the account was created and when it was last used. Legal basis: contract (Art. 6(1)(b) GDPR).
- Signed-in sessions: a hash of the session key (not the key itself) and two timestamps. They expire after 90 days and are then deleted.
- Deletion codes, if you request one: valid for 30 minutes, deleted afterwards.
What you upload yourself
- Your data package, if you use syncing: your own written recipes, your own prices, your shops with their addresses, the postcode of your household, your shopping statistics, the running shopping list and the list of dishes you bought. The server does not understand the contents and does not analyse them — it stores the package and hands it back to your second device.
- Of recipes you imported from someone else’s website, only the address travels — plus title, language, your own rating and your staple ticks. The recipe text itself does not leave your device. Your second device fetches it from the source itself once it has a connection; in the browser that fetch runs through the external service
api.allorigins.win, which sees the recipe address. In the Android app your device fetches directly.
- Contributions to offers, regular prices and ingredient matches, if you contribute something. That includes a coarse area, derived from your postcode (two digits plus country, e.g. „nl-80") — not the full postcode, no address, no coordinates.
- Reports, if you report a wrong entry.
Contributions and reports hang on your account, so that „confirmed by independent accounts" — at least two, more where many contribute — can be checked at all. They go when the account goes.
Usage figures (only with your consent)
If you turn the switch on in the app, we store plain daily totals: which event happened how often, with app version and date. Without a sender — the table has no column for an account, these figures cannot be attributed to anyone, not even by us. No recipes, no products, no prices, no search terms, no times of day. They are deleted after 90 days. Legal basis: consent (Art. 6(1)(a) GDPR); you can withdraw it in the app at any time, and then nothing is counted any more and the local counter is cleared.
Server log
The server records which path was called with which result — without a sender: no IP address, no identifier, no browser fingerprint, and without the query part of the address (so without area and without search term). The files are deleted after 14 days. Legal basis: legitimate interest in safe operation (Art. 6(1)(f) GDPR).
Who else sees the data
- Google, because signing in runs through a Google account. Google learns that you sign in to this service. From Google we receive only the identifier, no name and no email address.
- Google reports security incidents concerning your Google account to us (Cross-Account Protection): if it was hijacked, disabled or deleted, or you revoked all sessions there. We then end your sign-ins to this service — nothing more. Of the report we keep nothing but the number of events in the server log, without any identifier. Legal basis: legitimate interest in protecting your account (Art. 6(1)(f) GDPR).
- The provider of the server this service runs on.
Your confirmed contributions to offers, prices and matches are visible to other users in your area — but with no indication of who they came from.
Your rights
- Access (Art. 15): You can fetch a complete copy at any time: in the app under Settings → Account → „Request my data". It arrives as a file you can keep or pass on. The path
/v1/auskunft delivers the same thing with your sign-in. On request we send it within 30 days.
- Erasure (Art. 17): In the app under Settings → Account, or without the app via the page /loeschen using a deletion code.
- Rectification, restriction, portability (Art. 16, 18, 20) — write to us at the address above.
- Withdrawing consent to the usage figures: in the app under Settings → Account, while you are signed in, without giving reasons. Without signing in no figures are sent anyway — the switch needs an account.
- Complaint to the data protection authority of your country of residence (in the Netherlands: the Autoriteit Persoonsgegevens).
How long things stay
- Account, data package and contributions: until you delete the account.
- Sessions: 90 days. Deletion codes: 30 minutes.
- Usage figures: 90 days. Server log: 14 days.
- Backups: The database is backed up regularly; the last 14 copies are kept. A deleted detail may therefore sit in a backup for a short while, until it is overwritten in turn. Nothing is analysed from the backups; they exist only for recovery.
Changes
If what we store changes, this page changes with it. It belongs to the program and ships together with it.
Home ·
Terms of use ·
Delete account