This policy describes how SmartZonesIndicators (the “Publisher”) collects, uses and protects your personal data in connection with the Frigd mobile app and this website, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
Frigd is a mobile app. It lets you keep an inventory of your household's products, build a shared shopping list, and recognise your food items using your device's camera.
The data controller is SmartZonesIndicators, reachable at support@smart-zones-indicators.com.
Frigd opens an anonymous session the first time you launch it, without asking you for anything. When you later attach an identity to keep your data, the Publisher receives from the provider you chose:
No password is ever created or stored by the Publisher: authentication is entirely delegated to Apple or Google.
When you start, you also enter a first name, visible to the members of your household. If you accept notifications, the app records your device's notification token, which is used only to send them to you.
This is the data you create by using the app:
Log of your actions. Since August 2026, the app also keeps, for your account, a dated record of your actions on the List, at Home, in scans, till receipts and recipes: adding, checking off, buying, removing, opening or cooking a recipe… Depending on the action, the record holds the product name, its family, its quantity, its barcode, how it was added (favourite, search, barcode, scan, receipt, recipe…), the icon shown and the app language, or the recipe or notification concerned. It contains no device identifier. This log stays attached to your account: it is not shared with the other members of your household, and it is erased with your account. It is used only to improve icons (article 5), in aggregate form. It is never analysed to infer your health or your beliefs. You can object to this use by writing to us (article 14).
The images and video produced by the camera during a scan are subject to a specific treatment, described in detail in article 7.
You can photograph a handwritten shopping list when setting up the app, or take one to four photos of a till receipt from your shopping list. These images are described in detail in article 8; in short: they are sent to a reading service and then discarded, without being stored. What comes out of them — the items read from a piece of paper, or the purchase lines, retailer, date and total of a receipt — goes respectively into your shopping list and your household's purchase history.
Frigd collects neither your location, nor your contacts, nor your address book, and no banking data — see article 11. The only images the app transmits are those of the scan and of document reading, described in articles 7 and 8; outside these two uses, camera access serves no purpose and no photo is kept.
What we keep. The household's diet (omnivore, flexitarian, pescatarian, vegetarian or vegan); its restrictions: allergens (the fourteen allergens whose labelling is mandatory in the European Union, for example gluten, milk, peanut, sesame or sulphites), excluded foods (for example pork and its derivatives, alcohol, blood, meat with dairy) and foods to limit (sugar, salt, carbohydrates); and each member's tastes (spicy, quick, fish…). We keep the choice, never the reason for it: the app never asks why a food is excluded.
Why. Only to propose recipes to you: to propose no recipe that contains a restriction, and to rank lower those that contain a food to limit or do not match the household's tastes. This applies to the week of recipes, the dish of the day and recipe notifications.
Sensitive data, kept only with your explicit consent. Restrictions may reveal the state of health or the beliefs of the household's members. That is why all restrictions, except “No red meat” and “None”, are kept only with your explicit consent (GDPR article 9.2.a). You give it through a separate box, never ticked in advance, which appears on the restrictions screen as soon as one of these choices is ticked. Without this consent, such a choice cannot be saved: tick the consent box, or remove the choice. The rest of the app works normally without them.
Within the household. The diet and the restrictions belong to the household: every member sees them and can change them. Each member who adds a sensitive choice gives their own consent. A parent may indicate the restrictions of their minor children; they then give consent on their behalf. Each member's tastes are visible to the other members, but only their author can change them.
What we never do with them. These choices are part of no usage measurement, no statistics, even aggregated, no log of actions (article 3.2), no suggestion system based on your habits, and they are used for no calculation other than proposing recipes. They are sent neither to our artificial intelligence services, nor to RevenueCat, nor to any other third party: only our host, Google Firebase (article 11), stores them for us. We never infer them from what you buy or cook.
Where and for how long. In our database, in the European Union (Belgium, region europe-west1). Until you withdraw your consent or the choice concerned, or until the household is deleted.
Withdrawing your consent. In Profile › Restrictions, untick the consent box, then confirm. All of the household's sensitive choices are erased at once, for the whole household, and the recipes proposed are recalculated without them. The other members are notified. The household's recipe notifications (dish of the day, week announcement and other recipe reminders) are paused until a member reviews and saves the restrictions in Profile › Restrictions: this way, no notification proposes a recipe without taking into account a restriction that has just been erased. Unticking a single option removes that option alone.
Proof of your consent. For each consent, we keep your account identifier, the household concerned, the date, the version and language of the text displayed, and the screen concerned; for each withdrawal, your account identifier, the household, the date and the screen. Never the list of your choices. This proof is kept for as long as your account exists, then for 5 years after it is deleted, the period during which legal action remains possible (article 2224 of the French Civil Code).
Tastes and diet. Each member's tastes and the household's diet are used to provide the service you request (GDPR article 6.1.b). Like the restrictions, they are part of no usage measurement, no statistics and no log of actions, and are sent to no third party other than our host. A member's tastes are erased when they leave the household or delete their account.
United States. Information specific to the health data of US consumers is set out in our Consumer Health Data Privacy Policy.
This is the most sensitive processing in the app, and it is described here without evasion.
During a scan, the app transmits images taken from the camera feed to a recognition service. At the end of the scan, a short video of the sequence — recorded without an audio track — is placed in private storage in order to allow exact counting of quantities. For this counting, the service receives the video, through the file's address, which contains your account's technical identifier, and the names of the products recognised during this scan.
Recognition is performed by Google's artificial intelligence services (Vertex AI). The purpose is single: to identify the visible products and count their quantities. The result returned is limited to the description of the products recognised and their quantities.
Transfer outside the European Union — we say it rather than omit it. Our application servers, our database and the video storage space are located in the European Union (Belgium, europe-west1). However, the artificial intelligence model that analyses your images is called on a “global” endpoint: this is the only arrangement under which Google makes this model available. The infrastructure performing the inference may therefore be located outside the European Union, including in the United States.
This transfer is covered by Google Cloud's contractual safeguards (the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework). It only concerns the scan elements described in article 7.1, for the time it takes to process them; never your inventory, your list, your name or your email address.
A scan's video is deleted as soon as processing is finished. Deletion is triggered by the server across all outcomes — successful analysis, model failure, discarded result or rejected request. If the app receives no response, it deletes the file itself. Finally, a storage lifecycle rule erases any residual object no later than the day after it was placed there. As for any file deleted from this storage, Google Cloud keeps a copy, which only the Publisher can recover, for 7 days, then erases it permanently. On the device, the temporary file is destroyed after upload, after a failure, and whenever you leave the scan screen.
The images are not used to train an artificial intelligence model. Neither the Publisher nor any third party consults them for any purpose other than the recognition described above.
Once the scan is confirmed, only the text of the result remains: product names and their quantities, in your inventory. No image is kept.
Two additional features photograph a document to save you retyping it: a handwritten shopping list, when setting up the app, and a till receipt, at any time from your shopping list.
Handwritten paper. A single photo, taken when you choose to start from an existing paper shopping list, is sent to a reading service that extracts the items from it.
Till receipt. One to four photos of a receipt are sent to the same kind of service. Your current shopping list and the names of your household's storage families are sent along with the photos, so that the receipt's lines can be matched against what you have to buy and against the way your household stores its products.
As with the scan, reading is performed by Google's artificial intelligence services (Vertex AI).
Transfer outside the European Union. The same transfer as the one described in article 7.2 applies here: the reading model is called on Vertex AI's “global” endpoint, so inference may take place outside the European Union, including in the United States, under the same Google Cloud contractual safeguards.
Neither of them: neither the image of the paper, nor those of the receipt, are kept. They pass through the reading service and disappear with the call — nothing is written either to our database or to any storage. On the device, the photo is destroyed after upload, after a failure, and whenever you leave the capture screen.
An additional safeguard applies to receipt reading: any line containing a run of twelve or more digits — a card number, typically — is rejected before it even reaches the result shown to you. Our technical logs contain only your account identifier and counters (number of lines, duration), never a label, an amount or a retailer name.
Handwritten paper. Once the proposed list is confirmed, only the items read (name and quantity) join your shopping list — just like the result of a scan, nothing more.
Till receipt. Once the receipt is confirmed, the app records a receipt in your household's data: the retailer and the town of the shop, the date and time of purchase, the total, the currency, and for each line the printed label, the product name, the brand, the quantity, the price paid, the VAT code, whether the item is food, the printed aisle and the storage family selected; added to this are the member who recorded it and a technical fingerprint that avoids recording the same receipt twice. Never extracted or kept: the loyalty card number, the payment method, the cashier's name, or the image itself.
This receipt is visible to every member of your household, just like your list or your inventory (article 15): it serves to check off the list and put away the inventory in a single gesture, and gives the household a purchase history — prices, shops, dates. It is kept for as long as the household exists, and is erased along with it.
The receipt is only recorded six seconds after the summary screen — enough time to adjust it or to tap “Cancel”, which writes nothing.
When you scan a barcode or search for a product by name, the Publisher queries Open Food Facts, a public and collaborative food database, to find the name, brand, image and allergens of the reference. Only the barcode, or the text of your search, and a display language are transmitted: neither your identifier, nor your account, nor any other household data leaves our servers on that occasion.
The result is stored in a shared reference database across all users, so that the same barcode does not have to be resolved twice. This database contains only public product information — barcode, brand, labels, image, allergens. It never contains household data, nor personal data, nor any link between a product and the user who scanned it. It is read-only for client apps.
Attribution. Product information comes from Open Food Facts, a database made available under the Open Database License (ODbL). Product photographs are published by the Open Food Facts community under the Creative Commons Attribution – ShareAlike licence (CC BY-SA).
This is not an intention, it is a property of the app:
Attribution of installs from Apple Ads. On iPhone, if you installed Frigd after seeing or tapping an Apple Ads advertisement in the App Store, Apple provides the app, through its AdServices service, with a token that lets RevenueCat (article 11) obtain from Apple the identifiers of the campaign, ad group and keyword, the country and the date of the ad. This data is linked to your account for the sole purpose of knowing which ads bring subscribers. It is never used to track you or to show you advertising.
Your data is shared only with the technical providers strictly necessary for the service to work:
| Provider | Role | Data concerned |
|---|---|---|
| Google (Firebase) | Authentication, database, storage, application servers, sending notifications | Account, household data, temporary scan video, notification token |
| Google (Vertex AI) | Product recognition | Scan images and video, names of the products recognised during the scan |
| Google (Vertex AI) | Document reading | Photos of the paper list and of the till receipt; for a receipt, your current list and the names of your item families |
| Apple / Google Play | Sign in with Apple or Google, distribution, subscription and payment | Account identifier, billing data (held by Apple or Google alone) |
| RevenueCat | Subscription management and entitlement verification | Account identifier, subscription status, App Store or Google Play receipt — never the payment method; on iPhone, the Apple Ads attribution described in article 10 |
| Open Food Facts | Barcode resolution and product search | Barcode or search text, and language only |
Your data may also be disclosed to an administrative or judicial authority where the law requires it.
Banking data: the subscription is sold through the App Store or Google Play. Your payment method is registered with Apple or with Google and the Publisher has no access to it, at any time.
Our database — your account profile, your inventory, your list, your household, its diet, restrictions and tastes — is hosted by Google Cloud in the European Union (Belgium, europe-west1 region). The application servers and the scan video storage are located there too.
Some data may be processed outside the European Union, including in the United States, under the European Commission's Standard Contractual Clauses:
The household's diet, restrictions and tastes are part of none of these transfers.
| Data | Period |
|---|---|
| Account and household data | Until your account is deleted |
| Log of your actions | Until your account is deleted |
| Household restrictions subject to your consent | Until the consent or the choice is withdrawn, or until the household is deleted |
| Household diet | Until it is changed or the household is deleted |
| A member's tastes | Until they are changed, the member leaves, their account is deleted or the household is deleted |
| Proof of a consent or a withdrawal (without the list of choices) | For as long as your account exists, then 5 years after it is deleted |
| Video of a scan | Deleted after processing, at the latest the next day; Google Cloud's safety copy erased 7 days later |
| Images transmitted during the scan | Not kept after recognition |
| Photo of a paper list or of a till receipt | Not kept: processed then discarded, on the server as on the device |
| Recorded till receipt (retailer, date, amount, purchase lines) | Until the household is deleted |
| Records of the dish of the day and of the week announcement sent (household technical identifier, date, recipe proposed) | 30 days after sending; erased sooner if the household is deleted |
| Records of the other recipe reminders sent (technical identifier of your account, date, reminder, recipes proposed, language) | 30 days after sending; erased sooner if your account is deleted |
| Monthly icon reports (aggregated product names, with no identifier at all) | For as long as the service exists — they contain no personal data |
| Public product references | No limit — they do not concern you personally |
| Server technical logs | Kept according to Google Cloud's default periods |
The 30-day and 5-year periods are applied by an automatic erasure in our database. It takes place after the due date, typically within the following 24 hours. Records of notifications sent before 27 September 2026 follow the same rule, counted from that date.
You have, over your personal data, the rights of access, rectification, erasure, portability, objection, restriction of processing, and the right to withdraw your consent at any time.
A large part of these rights can be exercised directly in the app: you can view, correct and delete the contents of your inventory and of your list at any time, and remove a member from your household.
Deleting your account. You can delete your account and all the data attached to it directly in the app: Profile › Account › “Delete my account”, then confirm. You can also make the request by email to support@smart-zones-indicators.com, from the address associated with your account. If you are the owner of a household, deleting your account erases the entire household with it: the inventory, the shopping list, the item families, the favourites, the recent products, the scan history and the recorded till receipts — the other members then lose access to that data. If you are a member of a household without owning it, deletion removes your account and your access, but leaves the household's data, including receipts, to the other members; the tastes you had entered there are erased. Public product references from Open Food Facts are not affected: they do not identify you.
Withdrawing your consent to restrictions. In Profile › Restrictions, untick the consent box to erase all of the household's sensitive choices, or untick an option to remove it alone. The withdrawal takes effect at once (article 4). The proof of your consents and withdrawals, which contains none of your choices, is kept for the period stated in article 13, including after your account is deleted.
For any request, or in case of disagreement, you can write to us at support@smart-zones-indicators.com. You also have the right to lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
Frigd brings together up to four people in a single household. Everything is shared there: the shopping list, the “At home” inventory, the recorded till receipts, as well as the household's diet, restrictions and tastes (article 4), are common to all members, who also see the first name each person entered. Every movement — adding, buying or putting away a product, recording a receipt — may trigger a notification to the other members of the household.
By inviting someone into your household, you give them access to that household's shared data. The owner can remove a member at any time, which ends their access and erases their tastes.
The Publisher implements appropriate technical measures: encryption of communications, authentication delegated to Apple and Google, data partitioning per account and per household at the level of the database's access rules, and server-side control of the files the processing may access.
It should nevertheless be remembered that no method of transmission or storage is 100% secure, and that absolute security cannot be guaranteed.
The mobile app uses no cookies. This website is a static information site: it sets no cookies, runs no analytics script and loads no third-party resource.
Frigd is intended for an adult audience or, failing that, for people at least 16 years old. The Publisher does not knowingly collect data concerning younger children. If you find that such an account has been created, write to us and it will be deleted.
A parent may indicate, in the app, the restrictions of their minor children who live in the household; they then give consent on their behalf (article 4).
This policy may be updated, in particular to reflect a change in the app or in regulation. The new version is published on this page with its update date; in case of a substantial change, you will be informed in the app.
For any question about this policy or about your personal data: support@smart-zones-indicators.com.