Salvie logo Salvie
How it works Features Pricing Privacy Terms

Legal

Privacy Policy

Effective 13 September 2026 · Last updated 13 September 2026

Salvie reads your grocery receipts. A receipt is a surprisingly personal document — it can say where you shop, what you eat, how many people you feed and when you're home. This policy sets out, in detail and without hedging, what we do with that information and what we don't.

The short version: we keep your pantry, your saved recipes and your preferences so the app works. Receipt photos are read once and never stored. We don't run advertising, we don't embed analytics or tracking SDKs, and we never sell or rent your data. Everything lives on servers run by Microsoft Azure, and you can delete the whole account from inside the app in a couple of taps.

01

Who we are and what this policy covers

Salvie ("Salvie", "we", "us" or "our") is a mobile application published by Salvia Code Labs, based in Denmark. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), Salvia Code Labs is the data controller for the personal data described here. You can reach us at any time at contact@salvie.eu.

This policy applies to the Salvie mobile app on iOS and Android, to the Salvie backend service that the app talks to, and to this website at salvie.eu (together, the "Service").

It does not apply to recipe websites you open from Salvie. Salvie shows you the practical details of a recipe and then links out to the publisher's own page so you can read the method where it was written. Once you tap through, you are on somebody else's website and their privacy policy applies, not ours. The same goes for the App Store and Google Play.

02

The information we collect

We collect only what the app needs to do its job. In detail, that is:

Account information

  • Email address — your account identity and the way we reach you about your account.
  • Password — if you register with an email and password, we store only a one-way bcrypt hash. We never store, log or have any way to read your actual password.
  • First name — optional, used to greet you in the app.
  • Sign-in provider details — if you use Sign in with Apple or Google, we store which provider you used and the stable, opaque user identifier that provider gives us (never their password).
  • Account creation date and session tokens — a short-lived access token, plus refresh tokens stored only as SHA-256 hashes with an expiry and revocation timestamp, so signing out on one device can be enforced on our side.

Your pantry

  • Item names as you wrote them, in your own language, plus a canonical English version of each name that lets us match ingredients across languages and pick the right icon.
  • Quantity, unit and storage location (fridge, pantry, freezer or dry goods).
  • Expiry date, either scanned, estimated from the type of food, or set by you.
  • Confidence state and last-seen timestamp — how certain the app is that an item is still in your kitchen, which fades over time until you confirm it.

Lists and recipes you keep

  • Shopping list items — name, quantity, unit, whether they are ticked off, and whether the item was added by you, generated from something that expired, or from something you used up.
  • Saved recipes — the recipes you bookmark, including their title, ingredients, timings, servings, nutritional estimates and the link to the original page.

Preferences

  • Eating style, intolerances and nutritional goal.
  • Dietary filters — vegan, vegetarian, gluten-free, dairy-free, higher-protein, lower-carb, lower-calorie — and your default meal type.
  • Household size, the languages you want recipes in, and any recipe sources you have starred as favourites.

Some of this — intolerances in particular — can imply something about your health. We treat dietary information as sensitive and use it for one purpose only: filtering and ranking recipe suggestions for you. See Section 04 for the legal basis.

Receipt photos

  • The images you scan are processed and then discarded. A receipt photo is held in memory only for as long as it takes our AI provider to read it, and the extracted list of groceries to come back. We do not write receipt images to disk, we do not keep them in a database, and there is no receipt archive to breach. What persists afterwards is only the pantry items you choose to confirm and add.
  • A local count of how many free scans you have used is kept on your device only.

Recipe links you import

  • If you paste a recipe URL into the app, we fetch that page from our server and extract the recipe from it. We store the resulting recipe if you save it; we don't build a profile of the links you paste.

Notifications and subscription

  • Push notification token — a device token issued by Expo's push service, stored so we can send expiry reminders. Only if you allow notifications.
  • Subscription status — whether your account is on the free tier or Salvie Pro, and the transaction identifier we use to check that with Apple or Google. We never see or store your card details.

Technical information

  • Standard server logs: IP address, request time, endpoint, response status and error details, plus your account identifier on certain operations so we can debug a specific problem.
  • Device and app version information sent with requests, used for compatibility and troubleshooting.

What we never collect: your location, your contacts, your photo library beyond the specific images you pick, advertising identifiers, biometrics, health or fitness data from Apple Health or Google Fit, or anything from other apps on your device. There is no analytics SDK, no advertising SDK and no third-party tracker embedded in Salvie — so there is no behavioural profile of you to sell, and we never sell or rent personal data to anyone.

03

Where that information comes from

  • From you — everything you type, scan, save or set in the app.
  • From your device — with your permission: camera or photo library images for scanning, and a push notification token.
  • From Apple or Google — if you use their sign-in, we receive your email address (or Apple's private relay address), a stable user identifier and, on first sign-in with Apple, the name you choose to share.
  • From the App Store or Google Play — confirmation of whether a Salvie Pro subscription is active. Not your payment details.
  • Derived by us — an English canonical name for each pantry item, an estimated expiry date, and a confidence score that decays as time passes since you last confirmed an item.
04

Why we use it, and our legal basis

Under the GDPR we must have a lawful basis for every use of your personal data. Here is each one:

What we doData usedLegal basis
Create and secure your account, keep you signed in, let you sign out everywhere Account information, session tokens Performance of a contract — Art. 6(1)(b)
Run your pantry — store items, estimate expiry, decay confidence, show what needs using Pantry data Performance of a contract — Art. 6(1)(b)
Read your receipts and turn them into pantry items Receipt images (transiently) Performance of a contract — Art. 6(1)(b)
Suggest recipes ranked by what your pantry covers, and filter them to your diet Pantry data, preferences, dietary filters Performance of a contract — Art. 6(1)(b); for intolerances and other health-adjacent dietary data, your explicit consent — Art. 9(2)(a)
Keep your shopping list and saved recipes List and recipe data Performance of a contract — Art. 6(1)(b)
Send expiry reminders and recipe nudges Push token, pantry item names and dates Your consent, given through the device permission prompt — Art. 6(1)(a). Withdraw it at any time by turning notifications off.
Unlock Salvie Pro and check that a subscription is valid Subscription status, store transaction identifier Performance of a contract — Art. 6(1)(b)
Keep the service secure and working — debugging, preventing abuse, investigating incidents Technical logs Our legitimate interests in operating a secure, functioning service — Art. 6(1)(f)
Answer your emails and handle data protection requests Whatever you send us, plus your account record Legitimate interests — Art. 6(1)(f); legal obligation for rights requests — Art. 6(1)(c)
Meet accounting, tax and legal obligations Subscription records Legal obligation — Art. 6(1)(c)

We do not use your data for advertising, we do not sell or rent it, and we do not use it to build marketing profiles. There is no automated decision-making that produces legal or similarly significant effects for you: recipe ranking is a convenience, not a decision about you.

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded that the processing is limited to what you would reasonably expect from a kitchen app. You can object at any time — see Section 15.

05

Receipt scanning and other AI processing

Three features in Salvie use a third-party AI model. In each case the model is Google Gemini, accessed through Google's API, acting as our processor:

  • Receipt scanning. The photo or photos you capture are sent to the model with an instruction to return the grocery lines as structured data. The extracted items come back to your review screen, where you decide what to add. The image is discarded immediately afterwards.
  • Ingredient name translation. To match a Danish pantry against an English recipe, ingredient names need a canonical English form. Salvie first tries a built-in dictionary that runs entirely on our own servers; only names the dictionary doesn't recognise are sent to the model — a short list of words such as "kylling" or "mandioca", with nothing attached to identify you.
  • Importing a recipe from a link. If you paste a URL, our server fetches that page and sends part of its content to the model to extract the recipe.

What we never send: your email address, your name, your account identifier or any session token. The AI provider receives the image or the words to be interpreted and nothing that identifies whose kitchen they came from.

Google processes this data on our instructions under its API terms, and we use the results only to give you the feature you asked for. We do not use your data to train any model of our own, and we do not send your pantry to an AI provider for any purpose other than the three listed above.

AI is not perfect. Receipts get misread, an item may be named oddly or an expiry date estimated wrongly, which is exactly why the app asks you to review everything before it is added. Please do the same with dietary filters — see the Terms of Use for what Salvie can and cannot promise about allergens and food safety.

06

Camera and photo access

Salvie asks for camera access so you can photograph a receipt, and for photo library access so you can pick one you already took. Both prompts appear only when you first use the scanner, and you can refuse or later revoke them in your device settings — the rest of the app keeps working, you just add items by hand instead.

We access only the images you actively capture or select. Salvie does not browse, index or upload your photo library, and it does not read image location metadata.

07

Push notifications

If you allow notifications, we store the push token your device issues and use it to send you a small number of useful reminders: which items are about to expire, and the occasional suggestion of what you could cook with them.

These are delivered through Expo's push notification service, which relays them to Apple's or Google's push infrastructure. The body of an expiry reminder includes the names of the items expiring (for example, "Spinach expires within 3 days"), so those names pass through Expo and Apple or Google on the way to your lock screen.

Turn notifications off in your device settings at any time and the reminders stop. We do not send marketing push notifications.

08

Signing in with Google or Apple

You can create an account with an email and password, or through Sign in with Apple or Google. If you use one of those, we verify the identity token they issue and receive: your email address, a stable identifier for your account with that provider, and — with Apple, on first sign-in only — the name you choose to share.

We never receive your Google or Apple password. If you use Apple's Hide My Email, we only ever see the private relay address, and that is what we store.

Signing in this way means Apple or Google knows you use Salvie; their own privacy policies govern that. Revoking Salvie's access in your Apple ID or Google Account settings stops future sign-ins but does not delete your Salvie account — use the in-app deletion in Section 14 for that.

09

Subscriptions and payments

Salvie Pro is sold as an auto-renewing subscription through the App Store or Google Play. All payment processing is handled by Apple or Google. We never receive your card number, billing address or any other payment detail.

When you subscribe, the app sends the purchase token to our server so we can confirm it with Apple's or Google's verification service and unlock Pro on your account. What we store is the fact that your account is Pro and the identifier needed to re-check that — nothing more.

Apple and Google act as independent controllers for the purchase itself, including refunds and billing records, under their own privacy policies.

10

Who we share information with

We do not sell, rent or trade your personal data. We share it only with the service providers we need to run the app, each bound by a contract that limits them to processing it on our instructions:

ProviderWhat they processWhere
Microsoft Azure
Hosting and database
Everything stored in your account, plus server logs Microsoft Azure infrastructure
Google
Gemini AI API
Receipt images, unrecognised ingredient names, imported recipe page content — never your identity Google infrastructure, may include the United States
Google
Sign-in
Identity token verification, if you use Google sign-in Google infrastructure
Apple
Sign in with Apple, App Store, push delivery
Identity token verification, subscription validation, notification delivery Apple infrastructure
Expo
Push notification relay
Your push token and the text of each reminder United States

We may also disclose information in two other situations:

  • When the law requires it — a valid court order, a lawful request from an authority, or where disclosure is necessary to protect someone's safety or our legal rights. We will tell you unless we are legally barred from doing so.
  • In a business transfer — if Salvie is ever sold or merged, your data may transfer to the acquirer, who would remain bound by this policy until you are given notice of any change.

We may publish aggregate statistics that cannot identify anyone — for example, how many items an average pantry holds. That is not personal data.

11

Where your data is stored, and international transfers

Your account, pantry, lists, saved recipes and preferences are stored on Microsoft Azure infrastructure.

Some of the processors in Section 10 — including Azure depending on the hosting region in use, the Gemini API, Expo's push relay, and Apple's and Google's identity and store services — may process data outside the EU or EEA, including in the United States. Where that happens, transfers are covered by the safeguards the GDPR requires: the European Commission's Standard Contractual Clauses, adequacy decisions such as the EU–US Data Privacy Framework where the provider is certified, or the derogations in Art. 49 GDPR. You can ask us for details of the safeguards that apply to a specific provider at contact@salvie.eu.

12

How we protect your information

  • Encryption in transit — all traffic between the app and our servers uses TLS.
  • Encryption at rest — the database and its backups are encrypted on disk by the platform.
  • Password hashing — passwords are stored as bcrypt hashes with a per-password salt. We cannot recover your password, and neither can anyone who obtained the database.
  • Hashed session tokens — refresh tokens are stored only as SHA-256 hashes, with expiry and revocation, so a stolen database still does not yield usable sessions.
  • Scoped access — every query is scoped to your account, and our application connects to the database with managed, least-privilege credentials rather than shared secrets.
  • Minimisation — the strongest protection we apply to receipt photos is simply not keeping them.

No system is perfectly secure, and we will not claim otherwise. If a breach ever affects your personal data and is likely to present a risk to your rights, we will notify the Danish Data Protection Agency within 72 hours as required by Art. 33 GDPR, and notify you directly where Art. 34 requires it.

13

How long we keep it

DataRetention
Receipt photosNot retained. Discarded as soon as the scan returns
Account, pantry, shopping list, saved recipes, preferencesFor as long as your account exists; deleted when you delete the account
Refresh tokensUntil they expire (90 days) or you sign out, whichever comes first
Push tokenUntil you disable notifications or delete your account
Server logsA short operational window, typically no more than 30 days
Database backupsRolling 7-day window, then automatically overwritten
Subscription and tax recordsAs long as accounting law requires, currently 5 years in Denmark
Support emailsUp to 2 years after the conversation ends

When a retention period ends, data is deleted or irreversibly anonymised. Note the backup row: after you delete your account, your data is gone from the live service immediately but may persist in encrypted backups for up to 7 days before those backups roll off.

14

Deleting your account

In the app: open You → Account, scroll to Delete account and confirm. Your account and everything attached to it — pantry, shopping list, saved recipes, preferences, push token and sessions — are permanently deleted straight away. There is no waiting period and no recovery.

By email: write to contact@salvie.eu from the address on your account and we will delete it within 30 days, usually far sooner.

Deleting your Salvie account does not cancel an active subscription — subscriptions are managed by Apple or Google, so cancel yours in your App Store or Google Play account settings as well, otherwise it will keep renewing.

Some records survive deletion where the law requires it: subscription and tax records held for accounting purposes, and any information we must keep to defend a legal claim. These are kept only for the periods in Section 13.

15

Your rights under the GDPR

If you are in the EU or EEA, you have the following rights over your personal data:

  • Access (Art. 15) — a copy of the data we hold about you.
  • Rectification (Art. 16) — correction of anything inaccurate. Most of it you can edit yourself in the app.
  • Erasure (Art. 17) — deletion, which you can do yourself as described in Section 14.
  • Restriction (Art. 18) — a pause on processing while a dispute is resolved.
  • Portability (Art. 20) — your data in a structured, machine-readable format; write to us and we will export it.
  • Objection (Art. 21) — to any processing we base on legitimate interests.
  • Withdrawing consent (Art. 7(3)) — at any time, for anything based on consent, such as notifications or the dietary information you chose to give us. Withdrawal doesn't affect processing already carried out.
  • Not to be subject to automated decision-making (Art. 22) — we don't carry out any that has legal or similarly significant effects.

To exercise any of these, email contact@salvie.eu from the address on your account. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you why. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to your local supervisory authority. Ours is the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark (datatilsynet.dk).

16

Children

Salvie is not directed at children. You must be at least 16 years old to create an account, and we do not knowingly collect personal data from anyone younger.

If you are a parent or guardian and believe a child has given us personal data, contact us at contact@salvie.eu and we will delete the account and its data promptly.

17

Changes to this policy

We may update this policy as the app changes. When we do, we update the "Last updated" date at the top of this page and publish the new version here.

If a change materially affects how we use your personal data — a new processor, a new purpose, a longer retention period — we will give you notice in the app or by email at least 14 days before it takes effect, and where the change requires your consent, we will ask for it rather than assume it.

18

Contact us

Questions, requests or complaints about privacy — we read all of them:

  • Email: contact@salvie.eu
  • Website: salvie.eu
  • Controller: Salvia Code Labs, Denmark

We aim to reply within 5 business days, and always within the GDPR's one-month deadline for rights requests.

Salvie © 2026 Salvie by Salvia Code Labs
Privacy Policy Terms of Use contact@salvie.eu