Privacy Policy
In short
- MarginRadar works without an account. Your ingredients, prices, recipes, dishes, photos and backups are stored only on your device. We never receive them.
- A small amount of data leaves your device: feedback you choose to send, anonymous usage statistics and crash reports. None of it contains recipe names, ingredient names or prices.
- We do not sell data, show ads or track you across other companies' apps and websites. We do not use the advertising identifier (IDFA).
Who is responsible
The developer of MarginRadar, Eric Z, shown as the seller on the App Store page ("we"), is responsible for the processing described here. Contact: candy66861@gmail.com.
1. Data that stays on your device
Ingredients, purchase prices and price history, recipes and prep recipes, dishes and menu prices, notes, photos you attach, shop settings and automatic backups (in the app's folder in the Files app) are stored only on your device, and in your device backups (for example iCloud Backup) if you use them. We cannot see this data. When you add a photo, iOS passes only the photo you pick to the app. MarginRadar asks for permission to add images to your photo library only if you choose to save a cost report there.
2. Feedback (optional)
If you send feedback from Settings > Send Feedback, we always receive: the category and text you write, the app language, app version, device model and iOS version, and the email address if you enter one. Only if "Include diagnostics" is on do we also receive rough ranges such as "16–50 dishes" and whether Pro is active, plus – only when you leave the email field empty – the app's random analytics installation ID (so we can find related crash reports). Feedback with an email address is never stored together with the analytics installation ID or the device token described below. We use feedback only to answer you and fix problems. Legal basis: your request (Art. 6(1)(b) GDPR) and our legitimate interest in supporting users (Art. 6(1)(f)). Feedback is stored in a database hosted by Cloudflare and deleted 180 days after your request is closed, and in any case 2 years after it was sent. You can ask us to delete it earlier.
Anonymous device token. Before the first feedback, the app gets a random token from our server and keeps it in the device's keychain. The server stores only a one-way hash of it, when it was created and last used, and the app version. It is not your Apple ID or any hardware identifier, is used only to limit abuse of the feedback form, and is deleted after 400 days without use.
Network address. To prevent abuse, the feedback service counts requests per network address (for IPv6, per /64 network). The address is stored only as a one-way hash with a salt that changes every day; the counters are deleted once their hour is over, and each day's salt is deleted after two days, so a hash can no longer be linked to an address.
3. Settings and reference data downloads
The app regularly downloads remote settings and reference data (tax rate presets, unit conversions, starter ingredient list) from our server hosted by Cloudflare. These requests contain the app version but no personal data or recipes, and we do not store them. Cloudflare necessarily processes your IP address to deliver the response.
4. Usage statistics
To learn which features help and where people get stuck, the app sends usage events such as "dish saved" or "suggested price applied", with numbers only in ranges (for example "food cost 25–30%"). Each event includes a random installation ID created by the app (not linked to your Apple ID, reset when you reinstall), app version, iOS version, device model, language/region and time zone. Events never contain dish or ingredient names, prices, quantities or text you type. They are sent to our own analytics service hosted by Cloudflare and kept for at most 25 months. Legal basis: legitimate interest in improving the app (Art. 6(1)(f) GDPR). You can object at any time by writing to candy66861@gmail.com.
5. Crash reports and diagnostic logs
If the app crashes, a crash report is sent to Firebase Crashlytics, a service of Google LLC: stack trace, device model, iOS version, app version, free memory and disk space, time of the crash and a random Crashlytics installation ID. Crashlytics keeps crash reports for 90 days.
The app also keeps a technical log on the device for 7 days (counts, durations and error codes, never recipe names or prices). It is uploaded only if we open a troubleshooting request for your installation ID, usually after you contacted us, and deleted within 90 days. Legal basis: legitimate interest in a stable app (Art. 6(1)(f) GDPR).
6. Purchases
MarginRadar Pro is sold through Apple's App Store. Apple processes the payment; we do not receive your name, Apple ID or payment details. The app checks your purchase on the device with Apple's StoreKit.
7. Service providers and transfers
- Cloudflare, Inc. (hosting of our server, database and analytics service)
- Google LLC (Firebase Crashlytics crash reporting)
- Apple Inc. (App Store, payments, iOS)
These providers may process data outside your country, including in the United States. Where required, transfers are based on the EU Standard Contractual Clauses or an adequacy decision.
8. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR, Japan's APPI, Korea's PIPA or California law), you can ask to access, correct or delete your data, restrict or object to processing, and receive a copy. Write to candy66861@gmail.com; we reply within 30 days. Because we don't have accounts, please tell us the date of your feedback and the email address you used, so we can find it. You can also complain to your local data protection authority.
To delete the data on your device, use Settings > Data > Delete all data, or delete the app.
9. Children
MarginRadar is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
10. Changes
If this policy changes, we will update the date above and, for important changes, tell you in the app.