Privacy Policy

Broqoli helps you browse recipes, build a shopping list, and send it to your grocery provider's cart. This page explains what the app collects, why, and how to control it.

01Who runs this app

Broqoli is developed and operated by an individual developer based in Lithuania, not a registered company. For the purposes of the General Data Protection Regulation (GDPR), that developer is the data controller for the personal data described below.

Contact details are in Section 11.

02Data we collect

Signing in is required to use the app, so that every action can be tied to one account. We collect the following categories:

Category What it includes Source
Account Email address, display name, profile photo, and a unique account ID, from Google Sign-In. Google · Supabase Auth
Usage & app activity Recipes viewed, searched, or favourited; shopping-list items added, checked, or removed; cart actions with your grocery provider (items matched, swapped, skipped, confirmed) and their prices; app version, platform, and session length. Broqoli backend
Content you create Your own recipes (name, ingredients, instructions, category), recipes imported from a URL, and photos you attach to a recipe via the camera. You, device camera
Nutrition diary Meals you log manually or from a recipe, with date and meal type, if you use the diary. You
Grocery provider session An encrypted session token for a connected provider (e.g. Barbora), stored only on your device. We never see your grocery account password — you sign in on the provider's own site. Your device only

We do not use advertising SDKs, and we do not collect precise location, contacts, or payment card details — grocery checkout happens entirely inside the provider's own app or website.

03Why we collect it

  • To operate the app — your account keeps your recipes, shopping list, and diary in sync; without it there is nothing to save. (Contract performance.)
  • To build your grocery cart — ingredient names and quantities are sent to your chosen provider so items can be matched to real products. (Contract performance.)
  • To understand and improve the app — usage events show which features work and where people get stuck. (Legitimate interest.)
  • To keep the service secure — session tokens and sign-in state prevent unauthorised access to your account. (Legitimate interest.)

04Who we share it with

We do not sell your data. It is shared only with the processors needed to run the app:

  • Google — provides sign-in (Google Sign-In / OAuth).
  • Supabase — hosts our authentication, database, and backend functions that store your account, content, and usage data.
  • Your grocery provider (e.g. Barbora) — receives the ingredient names, quantities, and matched product IDs needed to add items to your cart there, only when you choose to send a list.
We may disclose data if required by law, or to a successor organisation if the app is ever transferred — you would be notified first.

05Where it's stored

Account, content, and usage data are stored in our Supabase project's database. Some data — your grocery provider session token and app preferences — stays only on your device and is never uploaded. If any data is processed outside the European Economic Area, we rely on the safeguards required by GDPR (such as standard contractual clauses) for that transfer.

06How long we keep it

We keep your account and content data for as long as your account exists. If you delete your account, we delete your personal data within 30 days, except where we must keep it longer to comply with the law. Usage events kept for product analysis are retained for up to 24 months, after which they are deleted or aggregated so they no longer identify you.

07Your rights

Under GDPR, you can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing, such as usage analytics.

You can delete your account from within the app's profile screen, or by emailing the contact below. You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) or your local supervisory authority.

08Security

All traffic between the app and our backend is encrypted (HTTPS/TLS). Grocery provider session tokens are stored in encrypted device storage. Access to our database is scoped through short-lived, per-user authentication tokens rather than shared credentials. No method of storage or transmission is 100% secure, but we take reasonable technical measures to protect your data.

09Children

Broqoli is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

10Changes to this policy

We may update this policy as the app changes. Material changes will be reflected by a new effective date at the top of this page, and, where required, we will notify you in the app.

11Contact

For any question about this policy or your data, or to request access, correction, export, or deletion:

Email labas@broqoli.com