Privacy Policy

Last updated: 25 September 2026

1. Controller

The controller responsible for data processing on this website and in the app is:

Paul Hellmann
Arlesheimerstrasse 24, 4147 Aesch, Switzerland
Email: paul [at] hellmann.swiss

Full details in the legal notice.

The provider is based in Switzerland; the Swiss Federal Act on Data Protection (FADP) applies. For users resident in the EU or in Liechtenstein, the provisions of the GDPR also apply. Where a legal basis is stated below, the EU reference is given alongside it.

2. Overview

This policy applies to the website proviato.com and to the app Provi, in the browser at app.proviato.com and on your phone from the App Store and Google Play. We process personal data sparingly and only for the purpose stated in each case. There is no advertising tracking, there are no analytics cookies and no data is passed on for advertising purposes. Specifically, we process:

3. Accessing the website and the app (server logs)

When you visit the site, the hosting server automatically records data transmitted by your browser in server log files: IP address, date and time, page accessed, amount of data transferred, browser type and operating system.

Since 28 August 2026, the server of app.proviato.com also keeps such an access log. It records the same details, including the IP address, and serves to detect unauthorised access. These logs are automatically deleted after 30 days.

Purpose: technical operation, security and stability. We rely on our overriding interest in a secure, functioning service (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR). We do not analyse the logs in order to monitor individual persons.

Hosting

The website and the app are hosted by Infomaniak Network SA, Rue Eugène Marziano 25, 1227 Les Acacias (GE), Switzerland. The servers are located in Switzerland. A data processing agreement is in place with the provider (Art. 9 FADP; EU: Art. 28 GDPR).

4. Account

To use the app, you create an account. In doing so, we store your email address, your password in encrypted form only (scrypt; we do not know the password itself), the time of registration and of confirmation, the end of your trial and the plan of your household.

Unconfirmed registrations. Anyone who registers and never confirms the address cannot get into the app. We automatically delete such registrations after 30 days, together with everything that was created in the process.

Minimum age. You must be at least 16 years old to create an account.

We send you emails to confirm your address and to reset your password. How often an address can request such emails is limited; for this purpose, we store the address with a timestamp and delete the entry after 24 hours.

Refer a friend

If, when creating your account, you enter under ‘Referred by’ the address of a person who already uses Provi, we store who referred whom, when your address was confirmed and whether the credit was granted or has lapsed. If you delete your account, the entry remains with the referring person, without any link to you, so that their count stays correct. If the referring person deletes their account, their entries disappear.

Checksum of confirmed addresses. So that the same address cannot immediately be referred again as new, we store a checksum of that address (HMAC) with the date when an address is confirmed and when an invitation is accepted. The address itself is not stored there and cannot be derived from it; we can only determine whether a particular address has been here before. The checksum remains even after the account is deleted and is automatically deleted 24 months after it was created.

5. Content in the app

What you create in the app belongs to your household: shopping list, pantry, products, shops, saved recipes, meal plans, cooking log and the line items read from receipts, including prices. Anyone who belongs to the same household can see this data.

Notes and photos on an item. You can write a note on a line and take a photo, so that it is clear in the shop what is meant. These photos are stored permanently in our database until you delete them or close your account. They are not passed on to third parties and are not analysed; they are shown only to those who belong to the same list or the same household. This is different from the images in section 7, which serve only for analysis.

Shared lists. A shared list is only a shopping list, without a pantry and without learning. Anyone invited to it sees its lines with notes and photos, and sees the email addresses of the other members.

Sharing the list. If you share the shopping list via your phone, it is sent as text to the app you choose for this, for example a messenger. What that app does with it is governed by its provider. We learn nothing about the sharing itself.

6. Invitations

You can invite someone to your household or to a shared list. To do so, you enter their email address; we store it together with the time and send an invitation to it. The person invited learns your address in the process.

Only invite people who are expecting it. It is your decision to enter someone else’s address here.

7. Analysis of photos and suggestions (Anthropic)

Four features require a language model: reading receipts, reading cupboard photos, recipe suggestions and assigning new items to shop aisles. For this purpose, the relevant data is transmitted to Anthropic PBC, San Francisco, USA and processed there:

Purpose: providing precisely these features. Legal basis: processing for the performance of the user agreement (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR). This is a disclosure abroad to a country without an adequate level of data protection; it is based on standard contractual clauses (Art. 16 para. 2 let. d FADP; EU: Art. 46(2)(c) GDPR). The content is not used to train models. We do not store the images uploaded for these two features (receipt, cupboard photo) permanently, but only analyse them; what is stored is the result, i.e. the recognised line items. Photos that you attach to an item yourself are not affected by this: they stay with us and are not sent to Anthropic (section 5).

Only with your consent. Before any of this is sent to Anthropic, the app asks for your permission. We store when you gave your consent and to which text. You can withdraw it at any time in the settings under ‘AI analysis’; after that, the app will only carry out these features again once you consent again. This applies to the web app and from iPhone app 1.0.10 and Android app 1.0.9 onwards. Older app versions do not ask; please update the app. For assignment to shop aisles, the app asks with an extended notice. An earlier consent for photos and recipes only is not sufficient for this.

Item names in the household. We only pass the name of an item to Anthropic for assignment if the person who created it or last deliberately renamed it has consented to the analysis including shop aisles. Changing quantities, ticking off or putting an item on the list does not count. Without consent, we assign items only using our own catalogue; unknown items then remain under ‘Other’ until you choose an aisle yourself. Neither the name of your account nor your email address is sent to Anthropic with the item name.

If another member of your household uses recipe suggestions or a recipe from a web page with their consent, the names of all pantry items of the household are sent for this, including items that you created. The shopping list, pantry, scanner and meal plan work without these features.

8. Sending emails (Brevo)

We send confirmation and password emails via Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France). Your email address and the content of the respective message are transmitted. Processing takes place on servers in the EU (France and Germany); a data processing agreement is in place (Art. 9 FADP; EU: Art. 28 GDPR).

For technical reasons, Brevo routes links in these emails through a redirect via the subdomain link.proviato.com. This generates the information that a link has been clicked. We do not use this data for advertising and do not create profiles from it. Each email also contains the target link in plain text, so that you can bypass the redirect.

Replies to our emails reach us via hallo@proviato.com. This mailbox is hosted by Microsoft (Microsoft 365), with servers located in the EU.

9. Payment (Stripe, Link, Apple and Google)

If you buy Pro or Max in the browser at app.proviato.com, you buy from us. The payment is handled by Link, a service of Stripe (Sold through Link, LLC). This way of buying is for persons resident in Switzerland or in Liechtenstein. For this purpose, we transmit to Stripe:

You enter your card, billing address and other payment details directly on Link’s payment page. We do not see them and do not store them. Link sends you receipts, invoices and emails about the subscription. The payment page is a Stripe page; which cookies it sets is governed by Stripe.

We store the plan, the term, whether the subscription has been cancelled, your customer and subscription numbers at Stripe and which person in the household pays. The others in the household see the email address of the paying person, so that it is clear who can manage the subscription.

Second trial only once. If the paying person deletes their account and the household remains, the household receives a trial once more, only once per address. So that we can check this, we store a checksum of the address (HMAC). The address itself is not stored there; we can only determine whether a particular address has been here before.

Stripe itself is responsible for what Link and Stripe do with your data, in accordance with Link’s privacy policy.

Purchase in the iPhone app (Apple)

In the iPhone app, you buy from Apple. Apple sells you access as the merchant; in Europe, this is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. When you buy, we only give Apple a random number of your household, so that the purchase reaches the right household. Apple does not receive your email address or your name from us.

From Apple, we receive signed details of the purchase: the subscription and transaction numbers at Apple, which subscription, the purchase date and end of the term, whether it renews, whether Apple has refunded the money and whether it is a test purchase. Apple reports renewals, cancellations and refunds directly to our server. We do not see your Apple ID, your name or your payment details.

We store these details, the plan and which person in the household pays. The others in the household see the email address of the paying person. For each report, we keep its number, type and time, so that none is processed twice.

Apple itself is responsible for what Apple does with your data as the merchant, in accordance with Apple’s privacy policy.

Purchase in the Android app (Google Play)

In the Android app, you buy via Google Play. In Switzerland, you buy from us, and Google handles the payment as an intermediary; in many other countries, Google itself sells you access as the merchant (Google Commerce Limited); which countries these are is shown in Google’s list. When you buy, we ourselves only give Google a random number of your household, so that the purchase reaches the right household. Google does not receive your email address or your name from us. What Google itself collects about your Google account during the purchase is governed by Google.

Our server queries the purchase details from Google: the purchase token at Google, which subscription and which base plan, the status and end of the term, whether it renews, whether a payment is still pending and whether it is a test purchase. Google reports renewals, cancellations and refunds to our server via its messaging service (Google Cloud Pub/Sub). Google Cloud processes these reports on our behalf, through the Google company responsible for our Google Cloud contract (Art. 9 FADP; EU: Art. 28 GDPR). For each report, we keep its number, type and time, so that none is processed twice.

We do not see your name, your address or your payment details. In the Google Play order management, we see the order number, date, amount, tax and the country of the billing address for each order. We use this for refunds and queries.

We store these details, the plan and which person in the household pays. The others in the household see the email address of the paying person.

Google itself is responsible for what Google does with your data when you buy via Google Play, for users in Switzerland and the EEA Google Ireland Limited, in accordance with Google’s privacy policy.

10. Barcode scanner and product data

The app reads the barcode with your phone’s camera. The camera image is analysed on the phone and is not uploaded; only the recognised number is sent to us.

In the Android app, the scanner uses Google’s ML Kit for this. ML Kit also analyses the image on the phone, but sends Google technical information: device and app, performance data, scanner settings and error codes, together with an identifier per installation that is not intended to identify you. No images are sent to Google in the process. Google uses this information for diagnostics and to analyse how ML Kit is used.

If you scan a barcode, we look up the product name at Open Food Facts. Only the number of the scanned product is transmitted, no information about you.

11. Notifications on your phone (Apple and Google)

In the app on your iPhone or Android phone, you can turn on three types under Settings → Notifications: the shopping day, what is to buy again this week, and new items on the household list that someone else has added (only in households with at least two people). All are off until you turn them on yourself. In addition, your phone asks whether the app may send notifications.

If at least one type is turned on and your phone allows notifications, the app registers this phone with us. If you turn off the last type, we delete the device tokens of all your phones.

For this purpose, we store:

Delivery on iPhone. Notifications are delivered via the Apple Push Notification service, which is part of your iPhone’s operating system. We transmit the device token and the text of the notification to Apple. For users in Switzerland, in Liechtenstein and in the EU, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, is responsible for this data in accordance with Apple’s privacy policy. Apple also processes data in the USA and, according to its own information, relies for this on standard contractual clauses.

Delivery on Android. Notifications are delivered via Firebase Cloud Messaging from Google (Google LLC, Mountain View, California, USA, or the Google company responsible for our Firebase contract). We transmit the device token and the text of the notification to Google. Google processes this data on our behalf in accordance with the Firebase data processing terms, including in the USA, and relies for this on the Data Privacy Framework and on standard contractual clauses (Art. 9 and 16 FADP; EU: Art. 28, 45 and 46 GDPR).

We do not add names or email addresses from your account to the notifications. However, the text may contain the item names entered in your household and the number of items.

12. Cookies and local storage

We do not set any tracking or marketing cookies. For signing in, the app sets a technically necessary cookie (pv_session) that keeps you signed in; it expires after 60 days and disappears as soon as you sign out.

So that the shopping list works without a network connection, the app stores parts of your list and changes not yet transmitted in the local storage of your device. These copies stay on your device. If you have turned on notifications, the app also keeps the device token there; that it is additionally sent to us is set out in section 11. A cookie banner is not required for either. For Stripe’s payment page, see section 9.

13. Backup copies

So that nothing is lost after an outage, we make copies of the database. Such a copy contains the same data as the app, including the photos on your items. The copies are created on the server every night, encrypted and additionally stored with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We keep the copies from the last 14 nights and delete older ones.

Legal basis: our overriding interest in secure operation (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR). If you delete your account, it disappears immediately from the live database. It may still be contained in a backup that has already been made until that backup is replaced by newer ones, at the latest after 14 days.

14. Your rights

You have the right at any time to:

To exercise these rights, an informal message to paul [at] hellmann.swiss is sufficient.

15. Right to lodge a complaint

You can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. If you live in the EU or in Liechtenstein, the supervisory authority of your place of residence is also open to you: in Germany, the authority of your federal state; in Austria, the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien; in France, the CNIL; in Italy, the Garante per la protezione dei dati personali; in Belgium, the Autorité de protection des données (Gegevensbeschermingsautoriteit); in Luxembourg, the Commission nationale pour la protection des données (CNPD); in Liechtenstein, the Datenschutzstelle Liechtenstein.

16. Changes

We adapt this privacy policy when the processing changes. The version published here applies in each case. This policy exists in German, French, Italian and English. In case of discrepancies, the German version prevails.

What the service does and does not do is set out in the terms of use.

← Back to the home page