Privacy Policy
Last updated: 25 September 2026
1. Controller
The controller responsible for data processing on this website and in the app is:
Paul Hellmann
Arlesheimerstrasse 24, 4147 Aesch, Switzerland
Email: paul [at] hellmann.swiss
Full details in the legal notice.
The provider is based in Switzerland; the Swiss Federal Act on Data Protection (FADP) applies. For users resident in the EU or in Liechtenstein, the provisions of the GDPR also apply. Where a legal basis is stated below, the EU reference is given alongside it.
2. Overview
This policy applies to the website proviato.com and to the app Provi, in the browser at app.proviato.com and on your phone from the App Store and Google Play. We process personal data sparingly and only for the purpose stated in each case. There is no advertising tracking, there are no analytics cookies and no data is passed on for advertising purposes. Specifically, we process:
- technical access data when the site is accessed (server logs),
- your email address and an encrypted password if you create an account,
- the content you create in the app: shopping list, pantry, recipes, meal plan,
- photos that you attach to an item yourself, until you delete them,
- receipts and cupboard photos, while they are being analysed,
- details of your subscription if you buy Pro or Max,
- a device token and your settings if you turn on notifications on your phone,
- for ‘Refer a friend’: who referred whom, and checksums of confirmed addresses,
- backup copies of the database.
3. Accessing the website and the app (server logs)
When you visit the site, the hosting server automatically records data transmitted by your browser in server log files: IP address, date and time, page accessed, amount of data transferred, browser type and operating system.
Since 28 August 2026, the server of app.proviato.com also keeps such an access log. It records the same details, including the IP address, and serves to detect unauthorised access. These logs are automatically deleted after 30 days.
Purpose: technical operation, security and stability. We rely on our overriding interest in a secure, functioning service (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR). We do not analyse the logs in order to monitor individual persons.
Hosting
The website and the app are hosted by Infomaniak Network SA, Rue Eugène Marziano 25, 1227 Les Acacias (GE), Switzerland. The servers are located in Switzerland. A data processing agreement is in place with the provider (Art. 9 FADP; EU: Art. 28 GDPR).
4. Account
To use the app, you create an account. In doing so, we store your email address, your password in encrypted form only (scrypt; we do not know the password itself), the time of registration and of confirmation, the end of your trial and the plan of your household.
- Purpose: providing the account, signing in, assigning your data to your household.
- Legal basis: processing for the performance of the user agreement (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR).
- Retention period: until you delete your account.
- Deletion: in the app itself, at the very bottom of the settings under ‘Close account’. After that, the account and the associated content are gone. If you prefer to write, an informal email to paul [at] hellmann.swiss will also do.
Unconfirmed registrations. Anyone who registers and never confirms the address cannot get into the app. We automatically delete such registrations after 30 days, together with everything that was created in the process.
Minimum age. You must be at least 16 years old to create an account.
We send you emails to confirm your address and to reset your password. How often an address can request such emails is limited; for this purpose, we store the address with a timestamp and delete the entry after 24 hours.
Refer a friend
If, when creating your account, you enter under ‘Referred by’ the address of a person who already uses Provi, we store who referred whom, when your address was confirmed and whether the credit was granted or has lapsed. If you delete your account, the entry remains with the referring person, without any link to you, so that their count stays correct. If the referring person deletes their account, their entries disappear.
Checksum of confirmed addresses. So that the same address cannot immediately be referred again as new, we store a checksum of that address (HMAC) with the date when an address is confirmed and when an invitation is accepted. The address itself is not stored there and cannot be derived from it; we can only determine whether a particular address has been here before. The checksum remains even after the account is deleted and is automatically deleted 24 months after it was created.
- Purpose: credit for the referring person; for the checksum, protection against the same address triggering a credit more than once.
- Legal basis: processing for the performance of the user agreement (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR); for the checksum, our overriding interest (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR).
5. Content in the app
What you create in the app belongs to your household: shopping list, pantry, products, shops, saved recipes, meal plans, cooking log and the line items read from receipts, including prices. Anyone who belongs to the same household can see this data.
Notes and photos on an item. You can write a note on a line and take a photo, so that it is clear in the shop what is meant. These photos are stored permanently in our database until you delete them or close your account. They are not passed on to third parties and are not analysed; they are shown only to those who belong to the same list or the same household. This is different from the images in section 7, which serve only for analysis.
Shared lists. A shared list is only a shopping list, without a pantry and without learning. Anyone invited to it sees its lines with notes and photos, and sees the email addresses of the other members.
Sharing the list. If you share the shopping list via your phone, it is sent as text to the app you choose for this, for example a messenger. What that app does with it is governed by its provider. We learn nothing about the sharing itself.
- Purpose: operation of the app.
- Legal basis: processing for the performance of the user agreement (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR).
- Retention period: until you delete it or until the account is deleted.
6. Invitations
You can invite someone to your household or to a shared list. To do so, you enter their email address; we store it together with the time and send an invitation to it. The person invited learns your address in the process.
- Purpose: delivering the invitation and assigning the link.
- Legal basis: our and your overriding interest in running the household together (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR).
- Retention period: an invitation is valid for 7 days and is then automatically deleted. You can withdraw it at any time before then.
Only invite people who are expecting it. It is your decision to enter someone else’s address here.
7. Analysis of photos and suggestions (Anthropic)
Four features require a language model: reading receipts, reading cupboard photos, recipe suggestions and assigning new items to shop aisles. For this purpose, the relevant data is transmitted to Anthropic PBC, San Francisco, USA and processed there:
- for a receipt as a photo or screenshot: the image of the receipt,
- for a receipt as a PDF: the text read from it, without lines containing customer, card, loyalty or payment details, insofar as we recognise them,
- for a cupboard photo: the photo taken,
- for recipe suggestions: the names of the items in your pantry and your dietary preference (for example vegetarian),
- for a recipe from a web page: the text of the selected page and the names of the items in your pantry,
- for assignment to shop aisles: in the background, the names of items that our catalogue does not know.
Purpose: providing precisely these features. Legal basis: processing for the performance of the user agreement (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR). This is a disclosure abroad to a country without an adequate level of data protection; it is based on standard contractual clauses (Art. 16 para. 2 let. d FADP; EU: Art. 46(2)(c) GDPR). The content is not used to train models. We do not store the images uploaded for these two features (receipt, cupboard photo) permanently, but only analyse them; what is stored is the result, i.e. the recognised line items. Photos that you attach to an item yourself are not affected by this: they stay with us and are not sent to Anthropic (section 5).
Only with your consent. Before any of this is sent to Anthropic, the app asks for your permission. We store when you gave your consent and to which text. You can withdraw it at any time in the settings under ‘AI analysis’; after that, the app will only carry out these features again once you consent again. This applies to the web app and from iPhone app 1.0.10 and Android app 1.0.9 onwards. Older app versions do not ask; please update the app. For assignment to shop aisles, the app asks with an extended notice. An earlier consent for photos and recipes only is not sufficient for this.
Item names in the household. We only pass the name of an item to Anthropic for assignment if the person who created it or last deliberately renamed it has consented to the analysis including shop aisles. Changing quantities, ticking off or putting an item on the list does not count. Without consent, we assign items only using our own catalogue; unknown items then remain under ‘Other’ until you choose an aisle yourself. Neither the name of your account nor your email address is sent to Anthropic with the item name.
If another member of your household uses recipe suggestions or a recipe from a web page with their consent, the names of all pantry items of the household are sent for this, including items that you created. The shopping list, pantry, scanner and meal plan work without these features.
8. Sending emails (Brevo)
We send confirmation and password emails via Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France). Your email address and the content of the respective message are transmitted. Processing takes place on servers in the EU (France and Germany); a data processing agreement is in place (Art. 9 FADP; EU: Art. 28 GDPR).
For technical reasons, Brevo routes links in these emails through a redirect via the subdomain link.proviato.com. This generates the information that a link has been clicked. We do not use this data for advertising and do not create profiles from it. Each email also contains the target link in plain text, so that you can bypass the redirect.
Replies to our emails reach us via hallo@proviato.com. This mailbox is hosted by Microsoft (Microsoft 365), with servers located in the EU.
9. Payment (Stripe, Link, Apple and Google)
If you buy Pro or Max in the browser at app.proviato.com, you buy from us. The payment is handled by Link, a service of Stripe (Sold through Link, LLC). This way of buying is for persons resident in Switzerland or in Liechtenstein. For this purpose, we transmit to Stripe:
- the email address of the person buying,
- the name of your household as it appears in the app,
- the internal number of your household and of your account, so that the payment reaches the right household.
You enter your card, billing address and other payment details directly on Link’s payment page. We do not see them and do not store them. Link sends you receipts, invoices and emails about the subscription. The payment page is a Stripe page; which cookies it sets is governed by Stripe.
We store the plan, the term, whether the subscription has been cancelled, your customer and subscription numbers at Stripe and which person in the household pays. The others in the household see the email address of the paying person, so that it is clear who can manage the subscription.
Second trial only once. If the paying person deletes their account and the household remains, the household receives a trial once more, only once per address. So that we can check this, we store a checksum of the address (HMAC). The address itself is not stored there; we can only determine whether a particular address has been here before.
- Purpose: purchase, billing and activation of the plan; for the checksum, protection against the same address triggering the trial more than once.
- Legal basis: processing for the performance of the contract (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR); for the checksum, our overriding interest (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR).
- Disclosure abroad: Stripe also processes data in the USA. The disclosure is directly connected with the processing of your purchase (Art. 17 para. 1 let. b FADP; EU: Art. 49(1)(b) GDPR).
- Retention period: the subscription details until the account or the household is deleted; the checksum for as long as Proviato exists.
Stripe itself is responsible for what Link and Stripe do with your data, in accordance with Link’s privacy policy.
Purchase in the iPhone app (Apple)
In the iPhone app, you buy from Apple. Apple sells you access as the merchant; in Europe, this is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. When you buy, we only give Apple a random number of your household, so that the purchase reaches the right household. Apple does not receive your email address or your name from us.
From Apple, we receive signed details of the purchase: the subscription and transaction numbers at Apple, which subscription, the purchase date and end of the term, whether it renews, whether Apple has refunded the money and whether it is a test purchase. Apple reports renewals, cancellations and refunds directly to our server. We do not see your Apple ID, your name or your payment details.
We store these details, the plan and which person in the household pays. The others in the household see the email address of the paying person. For each report, we keep its number, type and time, so that none is processed twice.
- Purpose: activation, renewal and end of the plan.
- Legal basis: processing for the performance of the contract (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR).
- Retention period: The details of the Apple subscription remain even when the account and household have been deleted, in that case without any link to an account.
Apple itself is responsible for what Apple does with your data as the merchant, in accordance with Apple’s privacy policy.
Purchase in the Android app (Google Play)
In the Android app, you buy via Google Play. In Switzerland, you buy from us, and Google handles the payment as an intermediary; in many other countries, Google itself sells you access as the merchant (Google Commerce Limited); which countries these are is shown in Google’s list. When you buy, we ourselves only give Google a random number of your household, so that the purchase reaches the right household. Google does not receive your email address or your name from us. What Google itself collects about your Google account during the purchase is governed by Google.
Our server queries the purchase details from Google: the purchase token at Google, which subscription and which base plan, the status and end of the term, whether it renews, whether a payment is still pending and whether it is a test purchase. Google reports renewals, cancellations and refunds to our server via its messaging service (Google Cloud Pub/Sub). Google Cloud processes these reports on our behalf, through the Google company responsible for our Google Cloud contract (Art. 9 FADP; EU: Art. 28 GDPR). For each report, we keep its number, type and time, so that none is processed twice.
We do not see your name, your address or your payment details. In the Google Play order management, we see the order number, date, amount, tax and the country of the billing address for each order. We use this for refunds and queries.
We store these details, the plan and which person in the household pays. The others in the household see the email address of the paying person.
- Purpose: activation, renewal and end of the plan.
- Legal basis: processing for the performance of the contract (Art. 31 para. 2 let. a FADP; EU: Art. 6(1)(b) GDPR).
- Disclosure abroad: Google also processes data in the USA. According to its own information, Google relies for this on the Data Privacy Framework between Switzerland and the USA or between the EU and the USA and, where this does not apply, on standard contractual clauses (Art. 16 paras. 1 and 2 FADP; EU: Art. 45 and 46 GDPR).
- Retention period: The details of the Google subscription remain even when the account and household have been deleted, in that case without any link to an account.
Google itself is responsible for what Google does with your data when you buy via Google Play, for users in Switzerland and the EEA Google Ireland Limited, in accordance with Google’s privacy policy.
10. Barcode scanner and product data
The app reads the barcode with your phone’s camera. The camera image is analysed on the phone and is not uploaded; only the recognised number is sent to us.
In the Android app, the scanner uses Google’s ML Kit for this. ML Kit also analyses the image on the phone, but sends Google technical information: device and app, performance data, scanner settings and error codes, together with an identifier per installation that is not intended to identify you. No images are sent to Google in the process. Google uses this information for diagnostics and to analyse how ML Kit is used.
If you scan a barcode, we look up the product name at Open Food Facts. Only the number of the scanned product is transmitted, no information about you.
11. Notifications on your phone (Apple and Google)
In the app on your iPhone or Android phone, you can turn on three types under Settings → Notifications: the shopping day, what is to buy again this week, and new items on the household list that someone else has added (only in households with at least two people). All are off until you turn them on yourself. In addition, your phone asks whether the app may send notifications.
If at least one type is turned on and your phone allows notifications, the app registers this phone with us. If you turn off the last type, we delete the device tokens of all your phones.
For this purpose, we store:
- the device token that Apple or Google assigns to the app on your phone, with the platform (iPhone or Android) and the time of registration and of the last update. We delete tokens that Apple or Google report to us as invalid,
- which of the three types you have turned on, whether you have answered the one-time notice after your first shop and when you last changed the settings,
- for shopping day and items to buy again, records of which notice has already been processed for which day or which week, so that we do not attempt the same notice more than once. The records do not prove that a notification has arrived. We delete them once they are older than 60 days,
- for ‘new items’, the name of the item, the household, who added it and when, provided that someone else in the household has turned on this type. So that not every item triggers its own notification, we process the collected items no earlier than 5 minutes after the first one, and at night not before 7 a.m. In doing so, we delete them, even if no notification can be sent.
Delivery on iPhone. Notifications are delivered via the Apple Push Notification service, which is part of your iPhone’s operating system. We transmit the device token and the text of the notification to Apple. For users in Switzerland, in Liechtenstein and in the EU, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, is responsible for this data in accordance with Apple’s privacy policy. Apple also processes data in the USA and, according to its own information, relies for this on standard contractual clauses.
Delivery on Android. Notifications are delivered via Firebase Cloud Messaging from Google (Google LLC, Mountain View, California, USA, or the Google company responsible for our Firebase contract). We transmit the device token and the text of the notification to Google. Google processes this data on our behalf in accordance with the Firebase data processing terms, including in the USA, and relies for this on the Data Privacy Framework and on standard contractual clauses (Art. 9 and 16 FADP; EU: Art. 28, 45 and 46 GDPR).
We do not add names or email addresses from your account to the notifications. However, the text may contain the item names entered in your household and the number of items.
- Purpose: to remind you of your shopping and of items to buy again, and to notify you of new items on the joint list.
- Legal basis: your consent, which you give by turning them on (Art. 31 para. 1 FADP; EU: Art. 6(1)(a) GDPR).
- Withdrawal: at any time, by turning off the types in the app. If you only turn off notifications in your phone’s settings, none will arrive any more; however, the device token remains stored with us until you also turn them off in the app or it becomes invalid.
- Signing out: When you sign out, the app asks us to delete this phone’s token. This may fail without a network connection; in that case, turn off notifications in the app as soon as you are signed in again.
- Deleting your account: We delete device tokens, settings and records. Items already collected for ‘new items’ remain, without any reference to you, until they are processed. For backup copies, see section 13. What Apple and Google store themselves is governed by them.
12. Cookies and local storage
We do not set any tracking or marketing cookies. For signing in, the app sets a technically necessary cookie (pv_session) that keeps you signed in; it expires after 60 days and disappears as soon as you sign out.
So that the shopping list works without a network connection, the app stores parts of your list and changes not yet transmitted in the local storage of your device. These copies stay on your device. If you have turned on notifications, the app also keeps the device token there; that it is additionally sent to us is set out in section 11. A cookie banner is not required for either. For Stripe’s payment page, see section 9.
13. Backup copies
So that nothing is lost after an outage, we make copies of the database. Such a copy contains the same data as the app, including the photos on your items. The copies are created on the server every night, encrypted and additionally stored with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We keep the copies from the last 14 nights and delete older ones.
Legal basis: our overriding interest in secure operation (Art. 31 para. 1 FADP; EU: Art. 6(1)(f) GDPR). If you delete your account, it disappears immediately from the live database. It may still be contained in a backup that has already been made until that backup is replaced by newer ones, at the latest after 14 days.
14. Your rights
You have the right at any time to:
- information about your stored data (Art. 25 FADP; EU: Art. 15 GDPR),
- rectification and erasure (Art. 32 FADP; EU: Art. 16 and 17 GDPR),
- receive your data in a common format (Art. 28 FADP; EU: Art. 20 GDPR),
- withdraw consent you have given (EU: Art. 7(3) GDPR),
- object to processing (Art. 30 para. 2 let. b FADP; EU: Art. 18 and 21 GDPR).
To exercise these rights, an informal message to paul [at] hellmann.swiss is sufficient.
15. Right to lodge a complaint
You can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. If you live in the EU or in Liechtenstein, the supervisory authority of your place of residence is also open to you: in Germany, the authority of your federal state; in Austria, the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien; in France, the CNIL; in Italy, the Garante per la protezione dei dati personali; in Belgium, the Autorité de protection des données (Gegevensbeschermingsautoriteit); in Luxembourg, the Commission nationale pour la protection des données (CNPD); in Liechtenstein, the Datenschutzstelle Liechtenstein.
16. Changes
We adapt this privacy policy when the processing changes. The version published here applies in each case. This policy exists in German, French, Italian and English. In case of discrepancies, the German version prevails.
What the service does and does not do is set out in the terms of use.