Privacy Policy
Last updated: 19 August 2026
Convenience translation: The German Privacy Policy is authoritative. This translation does not limit your rights under applicable data-protection law.
This Policy explains personal-data processing at gulasch-app.de and in its web meal planner. Notices displayed in a mobile app supplement it for additional app-specific processing.
1. Controller
Gulas.app. s.r.o., acting in Germany through its branch
Gulasch GmbH
Trierer Straße 173 A, 56072 Koblenz, Germany
Email: info@gulasch-app.de
Phone: +49 176 66 687 682
2. Website access, hosting and security
When you visit, the server processes technically necessary connection data, including IP address, time, requested URL, data volume, referrer, browser and device details. This delivers the site, detects errors and prevents attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure, stable operation.
Cloudflare, Inc. provides hosting, delivery and protection. Recipe images and cooking videos are delivered through Amazon CloudFront, a service of Amazon Web Services. Resulting logs are retained only as long as necessary for operation, security and abuse investigation, subject to statutory retention duties.
3. Meal planner and shopping lists
When you use the planner, we process selected recipes, planning details, language, a random plan or order identifier and technical connection data. The selection is also stored locally in your browser so it can be restored later. To transfer a list to a retailer, selected items may be sent to that retailer; its privacy notice applies before an order is placed.
The legal basis is Article 6(1)(b) GDPR where necessary to supply the requested feature, otherwise Article 6(1)(f) GDPR. Planner data is deleted when you clear the local plan or the server-side association is no longer needed for delivery, troubleshooting or abuse prevention. Statutory evidence and retention duties may require longer storage.
4. Contact
If you contact us by email or phone, we process your contact details and message. Article 6(1)(b) GDPR applies to contractual or pre-contractual communication and Article 6(1)(f) GDPR otherwise. We delete the data after the matter is resolved unless a statutory retention or evidence duty applies.
5. PostHog audience measurement
We use PostHog with EU infrastructure to understand use and technical errors. Before you make a choice in the consent dialog, cookieless audience measurement that is not directed at a user profile may occur without persistent browser storage. The legal basis is Article 6(1)(f) GDPR and our interest in statistical service improvement. You can object through “Cookie settings” by leaving analytics disabled and confirming your choice.
Persistent analytics and session recording are activated only with consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Session recording is a separate choice. PostHog is configured not to create persistent person profiles. Consent can be withdrawn at any time for the future through “Cookie settings”.
6. Meta Pixel marketing
If you consent to “Marketing”, we load the Meta Pixel from Meta Platforms Ireland Limited. Page views, browser, device and IP information may be sent to Meta and linked to a Meta account. The legal basis is consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. The pixel is not loaded without consent, which can be withdrawn through “Cookie settings”.
7. Local storage and consent
Necessary local storage retains your meal plan, consent choice and temporary interface settings. Where strictly necessary, access is based on section 25(2)(2) TDDDG and the related processing on Article 6(1)(b) or (f) GDPR. Optional technologies are used only after consent. See the Cookie Policy for details.
8. Recipients and international transfers
Recipients may include IT, hosting, security, analytics and marketing providers and the grocery retailer you select. They receive data only as necessary for their task. Transfers outside the European Economic Area use, where required, an adequacy decision, the EU-US Data Privacy Framework or EU Standard Contractual Clauses with supplementary safeguards.
9. Retention
Unless a period is stated above, we retain personal data only while its purpose exists. It is then deleted or anonymised unless commercial, tax or civil law requires longer retention or it is needed to establish, exercise or defend legal claims.
10. Your rights
Subject to the statutory conditions, you have rights including:
- access, rectification and erasure;
- restriction of processing and data portability;
- withdrawal of consent for the future;
- objection, for reasons relating to your situation, to processing under Article 6(1)(e) or (f) GDPR;
- a complaint to a data-protection supervisory authority.
The competent authority includes the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate. You may also contact the authority at your habitual residence.
11. Automated decisions
The described web services do not make decisions based solely on automated processing that produce legal or similarly significant effects under Article 22 GDPR.
12. Changes
We update this Policy when services or law change. The current version is available on this page.