Privacy Policy
Effective Date: September 1 2026
1. Data We Collect
- Account Data: Email address, display name, and profile picture (if provided), collected during account registration via Firebase Authentication.
- Product Data: Barcodes scanned, product names, expiration dates, and nutritional information (calories, macronutrients) entered into your Pantry.
- Device & Notification Data: Device push notification token (FCM token) used to deliver expiration alerts and household sync notifications. This identifier is stored on our servers and processed by Google Firebase Cloud Messaging.
- Usage Data: Aggregated, anonymized interaction data (e.g., frequency of pantry updates, feature usage) used to improve the service.
- Payment Data: Payments are processed entirely by the Apple App Store (iOS) and Google Play (Android), which remain the sole processors of your payment instrument. We do not store your credit card or payment details on our servers, and neither does RevenueCat. Receipt validation and subscription-state management are carried out on our behalf by RevenueCat, which receives purchase and transaction data (product identifier, price, currency, purchase and expiry dates, subscription status, store, and sandbox-vs-production environment) together with a pseudonymous account identifier, but never payment card or bank details. See Section 3.
2. Purpose of Processing
- To provide the smart pantry, expiration tracking, and shopping list services.
- To enable real-time synchronization between household members in a shared Group.
- To calculate nutritional insights, spending analytics, and recipe suggestions.
- To send push notifications for expiration alerts and household activity (requires your explicit permission).
- To manage and validate your subscription entitlements.
3. Third-Party Service Providers (Sub-processors)
We use the following third-party services that may process your data as part of delivering the Korgo service:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Google Firebase (Authentication, Cloud Messaging, Analytics, Crashlytics, Cloud Storage, App Check) | Authentication, push notifications, usage analytics, crash reporting, storage of user-uploaded images, anti-abuse attestation | policies.google.com/privacy |
| RevenueCat, Inc. (United States) | Subscription receipt validation and subscription-state management across the app stores | revenuecat.com/privacy |
| Apple App Store | iOS subscription billing and validation | apple.com/legal/privacy |
| Google Play | Android subscription billing and validation | policies.google.com/privacy |
- Service Providers: We use third-party service providers to operate the app, including Google Firebase for authentication, push notifications, usage analytics, crash reporting, storage of user-uploaded images, and anti-abuse attestation. These providers process data on our behalf under their respective data processing terms.
- Subscription Management: RevenueCat, Inc. (United States) sits between the app and the app stores. It validates purchase receipts, normalises your subscription status across the Apple App Store and Google Play, and notifies our backend of subscription changes. RevenueCat receives a pseudonymous account identifier (your internal Korgo user ID — not your email, name, or store account ID), purchase and transaction data (product identifier, price, currency, purchase and expiry dates, subscription status, store, and sandbox-vs-production environment), and standard SDK diagnostics (app version, SDK version, country). RevenueCat does not receive your name, email address, payment card or bank details, pantry or grocery contents, task lists, photos, or any other app content. RevenueCat declares no tracking and collects purchase history for app functionality only. Apple and Google remain the merchant of record and the only parties that process payment instruments.
- Product Reference Data: Product and nutritional information is derived from the Open Food Facts open database, used as a local snapshot. Open Food Facts does not receive or process any personal data of Korgo users. See our Terms and Conditions for licensing and attribution details.
All providers are contractually bound to process data only as instructed and in compliance with applicable privacy laws.
Data in shared Pantry or shared Task lists is visible only to household members you explicitly invite. We do not sell your personal data to third parties.
4. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure ("Right to be Forgotten"): Delete your account and all associated data at any time via Settings → Account → Delete Account. Deletion is processed within 30 days.
- Restriction: Request that we limit how we process your data in certain circumstances.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Where processing is based on consent (e.g., push notifications), you may withdraw at any time via your device settings.
To exercise any of these rights, contact us at support@korgo.app. We will respond within 30 days.
5. Data Storage, Retention and International Transfers
- Data is stored on secure servers with encryption in transit (TLS) and at rest. Your data is retained for the duration of your active account. Upon account deletion, personal data is purged within 30 days, except where retention is required by law (e.g., transaction records for tax purposes, retained up to 7 years).
- Korgo is operated from the Republic of Belarus, which is not covered by a European Commission adequacy decision. Where personal data of users in the European Economic Area is transferred outside the EEA, we rely on the Standard Contractual Clauses adopted by the European Commission as the transfer mechanism, together with supplementary technical measures including encryption and access controls.
- You may request further information about these safeguards by contacting us at support@korgo.app.
6. Age Restrictions
- Korgo is not intended for use by persons under the age of 13 (or 16 in the European Union under GDPR). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@korgo.app and we will delete it promptly.
7. Contact Us
-
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact:
Email: support@korgo.app
Controller: Dzmitry Lashkevich, Republic of Belarus
8. Governing Law
- This Privacy Policy is governed by the laws of the Republic of Belarus. For users in the European Union or EEA, personal data is processed in accordance with the General Data Protection Regulation (GDPR). For California residents, this policy complies with the California Consumer Privacy Act (CCPA).