Foobud

Privacy Policy — Foobud

1. Data Controller

⚠️ To be completed: legal name, address, registration number, DPO contact if applicable.

The publisher of the Foobud application (hereinafter "we", "our", "us") is the controller of your personal data within the meaning of the General Data Protection Regulation (GDPR — EU Regulation 2016/679).

Contact: privacy@foobud.com

2. Fundamental Principle: Your Data Stays With You

Foobud is designed with a local-first approach. Except in cases explicitly listed below, none of your personal data is transferred to our servers.

2.1 Free Users

All your data — contacts, meals, dietary restrictions, photos, profile — is stored locally on your device in a SQLite database and is never transferred to our servers, with the exception of the profile sharing function which uses temporary anonymous transit (see section 4).

Important: if you lose or reset your device, your data is permanently lost. No backup is possible without a Premium subscription.

2.2 Premium Users

Your data is backed up to Firebase (Google Cloud service) with encryption at rest and encryption in transit (TLS). It is synced across your devices to enable multi-device access.

Hosting: Google Cloud European regions (to be confirmed based on project configuration).

3. Anonymous Identification

Foobud generates, on first launch, an anonymous technical identifier via Firebase Anonymous Authentication. This identifier (UID):

This UID is retained on the Firebase side for the duration of the app's use. After extended inactivity (90 days, to be confirmed), the record is automatically purged.

4. Profile Sharing Functions

When you share your dietary profile with a contact (via QR code or deep link), a temporary anonymous transit via Firebase is used:

5. SSO Authentication (Premium)

If you subscribe to Foobud Premium or reconnect to an existing Premium account, you will be prompted to authenticate via Sign in with Apple or Sign in with Google.

At that specific moment, and only at that moment, Foobud receives the following information from SSO providers:

No extended scope is requested: we do not request access to your contacts, calendar, files, or any other data from your Apple/Google account.

Apple relay emails (@privaterelay.appleid.com) are treated as valid emails and enable identical communication.

6. Retention Periods

DataDurationDeletion Trigger
Local data (Free)As long as the app is installedApp uninstall or "Erase my data" action
Anonymous identifier on Firebase90 days of inactivityAutomatic purge
Active Premium cloud dataAs long as the subscription is activeManual deletion or downgrade
Cloud data after Premium downgrade30 days grace periodAutomatic purge after 30 days
Cloud data after account deletionImmediate deletion"Delete my account" action
FCM tokens (notifications)As long as token is validUninstall or revocation

7. Your GDPR Rights

In accordance with articles 15 to 22 of the GDPR, you have the following rights:

Response time: 1 month maximum.

Supervisory authority: you have the right to lodge a complaint with the CNIL (French DPA, www.cnil.fr) or any other European supervisory authority.

8. Security

9. Cookies and Trackers

Foobud uses no cookies or advertising trackers. No third-party analytics (Google Analytics, Facebook Pixel, etc.) are integrated.

10. Push Notifications

Push notifications (Firebase Cloud Messaging) can be enabled to notify you of sharing actions. The FCM token is stored on Firebase associated with your identifier. You can disable notifications at any time from system settings.

11. Minors

Foobud is not designed for children under 13. No data is knowingly collected from minors under 13.

12. Policy Changes

Any substantial change will be notified via the app and will require your consent for Premium users.

13. Contact

For any question regarding your personal data: