Legal
Privacy Policy
1 Introduction
Fango is a food waste tracking app for personal use, available on iOS and Android. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
This policy is an information notice provided under GDPR Articles 13 and 14; it explains our processing but is not itself the legal basis for it (the lawful bases are set out in Section 9). Where a feature relies on your consent, that consent is requested separately in the app.
Data controller (GDPR Art. 4(7)): Valtteri Isokorpi, Finland. Contact: support@fango.fi. Fango is operated as an individual project by a natural person established in the European Union; no separate company entity, data protection officer (DPO), or EU representative applies.
2 Data We Collect
Fango does not require registration or a user account. All data you enter — products, prices, expiry dates, your shopping list, settings, and statistics — is by default stored locally on your device only and is not transmitted to external servers. The developer has no access to your items, settings, or statistics. The one exception is Family Sharing (Section 5), which stores the household's shared products, lists and marking log on a server for as long as the household exists — and only if you create or join a household yourself.
Home screen widget. If you add the Fango widget to your home screen, it reads your product expiry data directly from local storage shared between the app and its widget on your device (an App Group container on iOS, and SharedPreferences on Android). No data is copied to external servers. The widget only displays information already stored on your device.
The cases where content you provide leaves your device are the optional receipt scanning feature (Section 3), the optional Report a problem form (Section 4), and the optional Family Sharing feature (Section 5) — the first two pass it through a relay without keeping it, the third stores it. The minimal technical and pseudonymous data flows that operate the service (subscription state, abuse-prevention counters, opt-in analytics, refer-a-friend, currency rates) are described in Sections 3, 4 and 7.
Data we receive about you indirectly (GDPR Art. 14). If you purchase a Fango subscription, Apple App Store or Google Play passes a transaction confirmation to RevenueCat (our subscription manager — see Section 7), and RevenueCat returns to the app a minimal subscription state (active / inactive, entitlement identifier "pro", and an opaque RevenueCat App User ID). Fango does not receive your name, email, payment instrument, billing address, or any other personal information from Apple, Google, or RevenueCat. The source of this indirectly-received data is the store transaction you initiated; the lawful basis is contract performance (Art. 6(1)(b), Section 9). The same minimal data flow applies to the refer-a-friend feature (Section 7) when an invited user redeems a code.
3 Receipt Scanning (Optional)
Fango includes an optional receipt scanning feature that uses AI to identify food products from a receipt image or PDF. This is the only part of the app that sends content off the device.
What is sent. When you scan, the image binary (or the text extracted from a text-based PDF) is transmitted briefly via our relay service (Supabase Edge Function) to an AI provider (Anthropic Claude) for product recognition. The content is not stored permanently on either server, and no name, user account or other information identifying you is attached to the request.
What is returned. The AI returns a structured list of recognised food products. This list is saved only on your device. Fango does not retain the receipt content after the scan completes.
Abuse prevention. To prevent excessive use of the AI service, the app registers a random per-installation identifier the first time you scan, and the usage counters (hourly, daily and monthly) are tied to it. The identifier is generated randomly on the relay service; it contains no device or user information, is not derived from anything about your phone, and is never stored alongside receipt content. It exists so that one installation's usage can be counted on its own — which also means a single abusive installation can be blocked without affecting anyone else sharing the same network. If you never use scanning, no such identifier is ever created. A coarse IP-based ceiling still applies alongside it. Under GDPR, an IP address is treated as personal data (Recital 26); it is processed solely for rate-limit accounting, is not linked to the installation identifier or to any other identifier, and is not used for any other purpose. Records are deleted automatically by a scheduled cleanup job: counters within about 35 days, installation identifiers within 400 days (see Section 14).
Special categories of data (GDPR Art. 9). Receipt content may incidentally include information that, in isolation or in combination, could constitute "special categories of personal data" — for example, a pharmacy receipt containing medication names that may reveal health information, or a receipt containing items associated with religious dietary practice. Fango does not deliberately process such categories and does not infer them from your data. The AI returns a structured list of the items it identified on the receipt (which may include non-food items such as toiletries — those are flagged separately so they are not added to your fridge reminders). Receipt content is not retained after identification: the relay service does not store images or extracted text, and only the structured product list is delivered to your device.
Anonymous telemetry. The relay service writes anonymous scan event logs to its server (scan country setting, mode used, count of products identified). No receipt content, no user identifiers, no IP addresses are logged in this telemetry.
Anthropic policy. Anthropic does not use data sent via the API to train its models. For details, see: Anthropic Privacy Policy.
4 Report a Problem (Optional)
Fango includes an optional in-app feedback form (Settings → Report a problem, the scan error banner, and the receipt review screen). It lets you describe a bug or send feedback to the development team. Submission is always initiated by you — nothing is sent automatically.
What is sent. Only what you type into the form, plus anonymous technical metadata: app version, operating system, device model (e.g. iPhone16,2 (iPhone) or samsung SM-G998B — the raw hardware identifier from the device, not your personalised device name), language and country settings, currency setting, and anonymous metrics from your most recent receipt scan in the same session (mode used, duration in milliseconds, count of products identified, and any error code). The form shows you exactly what will be sent before you submit.
What is NOT sent. Receipt content, images, PDFs, your fridge items, statistics, email, name, IP address as part of the payload, or anything that could identify you. The form does not allow attaching files or photos.
How it is delivered. Your message is transmitted briefly via our relay service (Supabase Edge Function) and forwarded as an email to the development team at support@fango.fi using a transactional email provider (Resend). The relay does not store report bodies in any database; they exist only in the delivered email and, briefly, in the relay platform's short-lived operational logs.
Abuse prevention. To prevent spam, the relay service maintains a pseudonymous IP-based hourly counter (10 messages/hour). The counter records only the IP and an hourly bucket, is automatically deleted by a scheduled cleanup job (see Section 14), and the report body itself is not stored in any database. The same treatment under GDPR applies as described in Section 3.
If you want us to see a specific receipt. Receipts are intentionally never sent through this form. If sharing one would help debug an issue, you can send it from your own email to support@fango.fi — please do not include personal information.
Local error log. In addition to the metadata above, Fango stores up to 20 of the most recent technical error events locally on your device (for example, unexpected app crashes that happened in the background). Each event contains: error type, location in the app code, timestamp, app version, operating system, and language — no personal data, no receipt content, no fridge items, no user-specific identifiers. This local log is never transmitted automatically. It is attached only when you actively choose to submit a Report a problem message, and only as part of that submission. Before you press Send, the form displays the number of errors that will be attached and provides a "Show what you send" link that lets you inspect the exact contents. After successful submission, the local error log is cleared from your device immediately. If you never submit a Report a problem message, the error log is never transmitted to us at all.
5 Family Sharing (Optional)
Fango lets you share your fridge, your shopping lists and your saved/wasted statistics with a household of up to four people. The feature is off by default, and the app is fully functional without it. This is the one feature where part of your food data is stored on a server rather than passed through it — everywhere else in this policy, the server is a relay or a counter. That is why Section 2's promise is written as "by default": creating or joining a household is the deliberate act that changes it.
The identity it creates. Joining a household creates an anonymous sign-in with no email address, no password, no name and no profile of any kind. Its credentials are held in your device's secure keychain and are deliberately not synced to iCloud. Nothing about this identity is derived from your phone, your contacts or your store account.
What the household shares. Product names, emojis, expiry dates, prices, currencies, quantities, storage locations and whether an item was close to expiry when it was marked; shopping list contents including your own free-text notes; the marking log (eaten or wasted, the time, the product name and the amount); the household's shared settings (savings goal, tracking toggles, home currency, rescue window); and the nickname you choose, which the other members can see.
What the marking log deliberately does not contain. It does not record who marked an item. This is not hidden in the interface — it is never collected, so the question "who threw that away" is one this database cannot answer for anyone, including us. Product rows do carry the anonymous household identifier of whoever added them, for one narrow technical reason: two phones adding items in the same millisecond would otherwise collide.
What never leaves your device, household or not. Per-item and global reminder settings, theme, sounds, language, the product memory that improves future scans, and all receipt images and receipt content.
Background connections. While you are in a household, the app refreshes its data in the background even when it is closed, so that reminders for other members' items are scheduled on time. A device used alone makes no background connections at all. You can stop the background refresh in your device settings (iOS: Settings → Fango → Background App Refresh; Android: the app's battery settings), after which household changes appear only when you open the app.
Leaving, and what leaving does not undo. You can leave a household at any time. Your own data returns immediately, and the shopping lists you shared are withdrawn from the household. Products you had already added to the shared fridge stay with the remaining members — sharing a product is not reversible by departure, and we would rather say so here than let you discover it. When the last member leaves, the household and everything in it are deleted from the server immediately, in the same operation (see Section 14).
Lawful basis: your consent (Art. 6(1)(a), Section 9).
6 Push Notifications (Household Only)
If you are in a household and you have allowed Fango notifications — the same permission that gives you expiry reminders — our server sends your device a message when another member adds or changes something.
That message is silent by default. Nothing appears on your screen. It exists to wake the app so it can fetch the changes and reschedule your reminders, which is the only way a member who rarely opens Fango is reminded about food that arrived from somebody else. A visible notification is a separate opt-in in the app's settings; when enabled, it states a count only — never product names, never who added them.
What is stored. Your device's notification token (an APNs token on iOS, an FCM token on Android), the platform, a timestamp and the visible-notification preference, stored against the anonymous household identity described in Section 5. For a device used alone, no notification token is created or stored at all — neither on our server nor in Apple's or Google's systems.
Deletion. The token is deleted when you leave the household, when you turn notifications off, and when the platform reports the token as expired.
Who delivers it. Apple (APNs) on iOS and Google (Firebase Cloud Messaging) on Android — see Section 7. iOS notifications do not travel through Google.
Lawful basis: your consent (Art. 6(1)(a), Section 9).
7 Third Parties
Fango uses the following third parties:
RevenueCat — manages Fango subscriptions. Processes only the data necessary to maintain your subscription status (subscription state and device identifier) via Apple App Store or Google Play. On Android devices, RevenueCat may also process the Android Advertising ID (AAID) if enabled on your device. RevenueCat does not have access to your food or product data.
Supabase — provides the relay services (Edge Functions) that handle receipt scanning requests and Report a problem submissions transiently. Maintains a pseudonymous IP-based rate limit table. Does not store receipt content or user-specific identifiers. Also receives the anonymous, aggregated usage-analytics events described under Anonymous analytics below, keyed only to a pseudonymous device hash. The relay also stores the refer-a-friend records described below.
Refer-a-friend (invite codes). The optional invite feature grants free months when a friend redeems your code. To operate it, the relay stores a pseudonymous, irreversible SHA-256 device hash (derived from a random per-install identifier on iOS, or the Android ID) together with the invite code, the RevenueCat App User ID needed to grant the reward, and timestamps. When you open the app, it briefly checks the relay for any pending reward tied to your device hash. This data contains nothing about your food, receipts, name, or contact details, and is used solely to issue referral rewards and prevent the same device claiming a reward twice. Because it underpins abuse prevention, a record that a device has already been rewarded is retained for as long as the referral programme runs; other referral records are cleared by a scheduled cleanup job after they expire or are claimed (see Section 14). Lawful basis: performance of the promotional benefit you opted into (Art. 6(1)(b), Section 9).
Anthropic (Claude AI) — identifies food products from receipt content. Does not use data sent via the API to train its models. Standard API retention applies for trust & safety monitoring.
Resend — transactional email provider that delivers Report a problem submissions to the development team. Processes only the anonymous bug report content as email; no user-specific identifiers.
Apple App Store and Google Play — payment transactions and subscription billing under their respective privacy policies. Fango never processes payment information directly.
Frankfurter (exchange rates) — to display savings estimates in your local currency, the app periodically fetches published European Central Bank reference rates from the Frankfurter API (frankfurter.app). The request carries no personal data and no parameters about you (only "which base currency"); as with any web request, your IP is visible to that service momentarily to return the response. Rates are cached on your device for 24 hours. See: frankfurter.dev.
Apple Search Ads (AdServices) — on iOS only, if you installed Fango from an Apple Search Ads ad, Apple's AdServices framework provides a campaign-level attribution token (which campaign, ad group, and keyword led to the install). This is first-party Apple attribution: it carries no cross-app identifier and requires no App Tracking Transparency prompt. Fango forwards the token to RevenueCat solely to attribute anonymous subscription and trial metrics to the ad that led to the install — never to you personally. To stay on the safe side of EU rules, this is collected only if you opt in to analytics (Settings → Privacy); it is off by default and never collected without your consent.
Anonymous analytics. Fango can collect anonymous, aggregated usage events to help improve the app — but only if you turn analytics on in Settings → Privacy. It is off by default (opt-in). When enabled, these events cover for example which onboarding steps and screens are opened, whether a free trial or subscription is started, when a scan succeeds, when a friend's invite (referral) code is redeemed, when a reminder's action button is tapped, and when an item is marked as eaten or wasted (the type of mark only — never the product or the price). They carry only a pseudonymous device hash, app version, platform and language — never your products, dates, prices, receipt content, fridge items, or anything that identifies you, all of which remain only on your device. Analytics data is processed on Fango's own relay (Supabase). It is not shared with advertising networks, not used for cross-app tracking, and not used for profiling or targeted advertising. You can switch it on or off at any time. Lawful basis: your consent (Art. 6(1)(a); see Section 9). The Apple Search Ads attribution described above is covered by the same opt-in consent and is likewise off until you turn analytics on.
Apple (APNs) — on iOS only, and only if you are in a household, Apple's Push Notification service delivers the family sharing message to your iPhone. It processes the device notification token and the message payload, which is a count and nothing else (see Section 6).
Google (Firebase Cloud Messaging) — the same task on Android devices, and under the same conditions. This is message transport only: Fango does not use Firebase Analytics, Firebase crash reporting, or any Google advertising product. For technical reasons the Firebase library is bundled inside the iOS app package, but it is never initialised and never used — an iPhone does not contact Google to receive notifications. We state this because anyone can inspect an app package and see the library; the distinction that matters is that it is present, not running.
Apart from this first-party, consent-based (opt-in) analytics, Fango uses no advertising networks and no behavioral tracking technologies.
For more information, see: RevenueCat Privacy Policy · Supabase Privacy Policy · Anthropic Privacy Policy · Resend Privacy Policy
8 Applicable Law
Fango complies with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), which applies directly in all EU/EEA member states (the 27 EU countries plus Iceland, Liechtenstein, and Norway), and the Finnish Data Protection Act (1050/2018) which supplements the GDPR locally. The substantive rules of the GDPR — purpose limitation, data minimisation, lawful basis, security, and the rights enumerated in Section 11 — apply uniformly to all users in those jurisdictions, regardless of the member state in which they reside or the language they use the app in.
As the app collects only minimal pseudonymous data on its own servers — the abuse-prevention counters and the anonymous usage-analytics events described in Sections 4 and 7, neither of which identifies a user — no personal data register requiring separate registration is formed under the meaning of the GDPR. Subscription data processed by RevenueCat, transient receipt scanning content processed by Supabase and Anthropic, and anonymous bug report content delivered by Resend, are subject to those providers' own GDPR compliance.
9 Lawful Basis for Processing
Where any personal data is processed in connection with Fango (whether on-device, by the relay service, or by third-party providers listed in Section 7), the following lawful bases under GDPR Art. 6(1) apply:
Consent (Art. 6(1)(a)). Receipt scanning (Section 3), submitting a Report a problem message (Section 4), Family Sharing (Section 5) and the household notifications that accompany it (Section 6) are processed on the basis of your active consent — you explicitly choose to use these features, and you can decline by not using them. Anonymous usage analytics and Apple Search Ads attribution (Section 7) are likewise processed only on the basis of your consent: they are off by default and collected only if you opt in via Settings → Privacy, where you can withdraw consent at any time.
Performance of a contract (Art. 6(1)(b)). Fango subscription state and the device identifier handled by RevenueCat are processed to deliver the subscription you purchased through the App Store or Google Play. The refer-a-friend feature's irreversible SHA-256 device hash is processed on the same basis (to grant promotional access you opted into).
Legitimate interests (Art. 6(1)(f)). Pseudonymous IP-based rate-limit counters on the relay service, and the random per-installation identifier the scan counters are tied to, are processed on the basis of Fango's legitimate interest in preventing abuse of the AI service and the bug report endpoint; this interest has been balanced against your rights, and the data is short-lived (counter buckets deleted automatically within 48 hours to 35 days, installation identifiers within 400 days — see Section 14), is not linked to any user identifier, and is not used for any other purpose. Anonymous server-side telemetry (country setting, mode, product count — containing no IP and no user identifier) is processed on the same basis to monitor service quality. (In-app usage analytics and Apple Search Ads attribution, by contrast, rely on your consent — see above — and are off by default.)
No processing relies on the "vital interests", "public task", or "legal obligation" bases. Fango does not process "special categories of personal data" (GDPR Art. 9) deliberately — see Section 3 for the limited circumstances in which such data may incidentally appear in receipt content.
10 International Data Transfers
The third-party providers listed in Section 7 may store or process the transient data described in this policy on servers located outside the European Economic Area (EEA), including in the United States and Singapore. Such transfers are permitted under Chapter V of the GDPR through the following safeguards:
Standard Contractual Clauses (SCCs). Transfers to providers operating in the United States (Anthropic, RevenueCat, Resend) and to Supabase data centers in the United States or Singapore rely on the European Commission's Standard Contractual Clauses (Article 46 GDPR) as published in each provider's Data Processing Addendum.
Adequacy decisions. Where the European Commission has issued an adequacy decision under Article 45 GDPR for a destination country, that decision is relied upon instead of SCCs.
Push notification delivery. Family sharing notifications are delivered by Apple (APNs, iOS) and Google (Firebase Cloud Messaging, Android), both of which operate globally and process the data described in Section 6 under their own controller policies. The payload carries a count, never a product name or a member.
Copies of the safeguards may be requested from support@fango.fi or directly from each provider via the privacy policy links in Section 7.
11 Your Rights Under GDPR
Under Articles 15–22 of the GDPR you have the following rights regarding personal data processed about you. Because Fango stores your fridge inventory, statistics and settings on your own device and — outside Family Sharing (Section 5) — maintains no server-side personal data register (Sections 2 and 8), most of these rights are exercised directly on your device:
Right of access (Art. 15) — You can review all data the app holds about you by opening the app on your device. Server-side, only the minimal pseudonymous records described in Sections 7 and 14 may exist (abuse-prevention counters, opt-in analytics events keyed to a device hash, and refer-a-friend records) — plus, if you use Family Sharing, the household data described in Section 5, which you can see in full in the app itself; you may request a copy of any such records via support@fango.fi using the identity-confirmation procedure described below.
Right to rectification (Art. 16) — Edit any item, price, expiry date, or setting directly inside the app.
Right to erasure (Art. 17) — Delete all locally stored data via Settings → "Danger zone" → "Clear all app data", or by uninstalling the app. Both methods permanently remove the data; Fango cannot recover it.
Right to restrict processing (Art. 18) — Disable optional features that send data off-device: do not use receipt scanning (Section 3) and do not submit the Report a problem form (Section 4). The rest of the app continues to work entirely on-device.
Right to data portability (Art. 20) — All your data already resides on your device. Fango does not currently offer a structured export, but iOS and Android device backups (iCloud / Google) include the app's local storage and can be used to move it to a new device of the same platform.
Right to object (Art. 21) — Object to any optional processing by simply not using the relevant feature (scanning, reporting). Disabling notification permissions in your device settings stops local reminder processing.
Right not to be subject to automated decision-making (Art. 22) — Fango does not make automated decisions that produce legal or similarly significant effects about you. The AI receipt scan only identifies food products from an image you actively provide; it does not score, profile, or rank users.
Right to withdraw consent (Art. 7(3)) — Where processing is based on your consent (Section 9) you may withdraw it at any time: for receipt scanning and submitting a Report a problem message, simply by not using the relevant feature again; for anonymous usage analytics, by switching it off in Settings → Privacy (it is off by default and only collected after you opt in). Withdrawal does not affect the lawfulness of processing already carried out before the withdrawal, but no further data will be sent off-device once you withdraw.
Family Sharing and your rights. Because a household identity is anonymous by design, we cannot locate your household data from an email address — the identity exists only in your device's keychain, and that is deliberate. The rights are therefore exercised from the device: Family sharing → Leave household ends your membership on the server and withdraws the lists you shared, and Settings → Clear all app data does the same and then erases everything locally. If you were the last member, the household and all of its contents are deleted from the server in the same operation. Two limits apply and are stated here rather than left to be discovered: products you already shared into a household stay with the remaining members, and the marking log cannot be filtered to "your" entries because it never records who made them.
For data that is processed by third-party providers (RevenueCat, Supabase, Anthropic, Resend — see Section 7), you may exercise your rights directly with each provider via the contact details in their privacy policies linked in Section 7.
If you have questions about these rights or wish to request additional information, contact support@fango.fi.
How requests are handled. Requests are responded to within one month of receipt (GDPR Art. 12(3)); this period may be extended by two further months for complex or numerous requests, in which case we will inform you within the initial month. Responses are provided free of charge (Art. 12(5)); we may charge a reasonable fee or refuse only when a request is manifestly unfounded or excessive, in particular due to its repetitive character. Because Fango does not maintain user accounts, where there is reasonable doubt about your identity we may ask you to provide additional information sufficient to confirm your relationship to the data subject to the request (for example, an IP address, device hash, or RevenueCat App User ID associated with the data in question — Art. 12(6)). If no such identifier can be supplied, we will respond confirming the absence of server-side personal data linked to you.
12 Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence, place of work, or where the alleged GDPR infringement took place (GDPR Art. 77).
Fango operates from Finland; the competent supervisory authority is:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Postal address: PO Box 800, FI-00531 Helsinki, Finland
Street address: Lintulahdenkuja 4, 00530 Helsinki
Email: tietosuoja@om.fi
Phone (switchboard): +358 29 566 6700
Website: tietosuoja.fi
Before contacting the supervisory authority, you may wish to raise your concern with us first at support@fango.fi, but you are not required to do so.
Right to a judicial remedy (Art. 79). In addition to lodging a complaint with the supervisory authority, you have the right to an effective judicial remedy against a supervisory authority's binding decision (Art. 78), against a controller or processor that has infringed your rights, and to recover compensation for damage caused by GDPR infringement (Art. 82). Such proceedings may be brought before the courts of the EU member state where the controller or processor has an establishment, or where you have your habitual residence.
13 Security
Since your fridge inventory, statistics and settings reside on your device, their security depends on your device's own protection (PIN, password, or biometric authentication). Receipt scanning requests and bug report submissions are transmitted over HTTPS. Family sharing data is protected on the server by row-level security tied to household membership, so it is readable only by members of the same household; the client is granted no delete permission on the shared tables, and all traffic is encrypted (HTTPS/TLS). We recommend:
• Keeping your device's operating system up to date
• Using a strong PIN or biometric lock on your device
• Enabling automatic backups if you wish to preserve your data
14 Data Retention
Outside Family Sharing, Fango does not retain your fridge inventory, statistics or settings on any server: the data you create in the app is stored exclusively on your device and remains there for as long as you choose to keep it — or until you delete it or uninstall the app.
Receipt scanning content (image binary or PDF text) is processed transiently and not stored on our servers.
Family sharing data. A household's products, shopping lists, marking log and shared settings are kept for as long as the household has members. When the last member leaves, the household and every record belonging to it are deleted immediately, in the same operation that ends the membership — we do not keep an emptied household waiting. Deletion is immediate rather than delayed because the only way back into an empty household would be an unredeemed invite code, and honouring that code would hand a departed member's fridge to whoever held it.
Notification tokens. A device's push token is deleted when you leave the household, when you turn notifications off, and when Apple or Google reports the token as expired.
Abuse-prevention counters (IP addresses). The pseudonymous IP-based rate-limit records are automatically deleted by a scheduled daily cleanup job once they are no longer needed for their limit window: the hourly counters used by the Report a problem and referral endpoints are removed within about 48 hours, and the scanning counters — which also enforce a rolling monthly abuse cap — are removed within about 35 days. Denylist entries for IPs associated with abuse are kept only as long as needed to prevent that abuse. The random per-installation identifier that scan counters are tied to is deleted 400 days after it was created; an installation still in use simply registers a new one, so the identifier rotates rather than following you indefinitely.
Anonymous usage analytics. If you opt in to analytics, the aggregated events (device hash, app version, platform, language; no food, receipt or personal data) are stored on the relay and automatically deleted after 25 months by a scheduled cleanup job. Anonymous scan telemetry (country, mode, product count — no IP, no identifier) is retained in short-lived server logs.
Refer-a-friend records. Invite codes and their associated pseudonymous device hashes are cleared by the daily cleanup job after they expire (codes expire 30 days after creation). Delivered reward records are stripped of their subscription identifiers 90 days after delivery; a minimal pseudonymous record (device hash and timestamps) is retained for the lifetime of the referral programme, because it enforces the per-device reward cap and prevents repeat claims (see Section 7).
Bug report submissions are forwarded as email and retained in the development team's email inbox for the time needed to debug the reported issue.
RevenueCat retains subscription-related data (subscription status and device identifier) in accordance with their own data retention policy. Anthropic applies its standard API retention for trust & safety monitoring. Resend retains email delivery metadata in accordance with its own policy. You may contact those providers directly to request deletion of data they hold.
15 Children's Privacy
Fango is not directed at children under the age of 13, and we do not knowingly collect personal information from children. Fango has no user accounts and does not ask for a name, email, or any profile information from users of any age. The only data processed off-device is the minimal, pseudonymous data described in Sections 2–4 and 7 (transient abuse-prevention counters, opt-in anonymous analytics, subscription and referral identifiers) — none of which is directed at, or used to identify, a child.
Family Sharing and minors. A household can include a minor family member — a shared fridge is a household tool, and households have children in them. Fango still asks for no age and holds no profile, so it cannot verify who a member is; the adult who creates a household decides who is invited and what is shared in it. A minor member's data in a household is the same food data as anyone else's (Section 5), and the marking log records no member identity at all.
If you are a parent or guardian and believe your child has used the app, all local data can be deleted by uninstalling the app or using the "Clear all app data" option in Settings. If you believe we may hold any pseudonymous server-side record connected to a child, contact support@fango.fi and we will delete it.
16 California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.
Categories of information collected. Fango does not collect information that identifies you on its own servers (see Sections 2–4 and 7). The only categories that may be processed are: (a) commercial information (subscription status, handled by Apple App Store / Google Play and RevenueCat); (b) identifiers: pseudonymous IP addresses used solely for rate-limit abuse prevention (deleted automatically within 48 hours to 35 days), a random per-installation identifier used solely to count scan usage (created on your first scan, deleted within 400 days — Section 3), and a pseudonymous device hash together with a RevenueCat App User ID used by the optional refer-a-friend feature (Section 7); and (c) pseudonymous, aggregated usage-analytics events (a device hash, app version, platform and language — no personal information, no products or receipt content), collected only with your opt-in consent and switchable off anytime in Settings; see Section 7.
No sale, no sharing, no targeted advertising. Fango does not sell or share your personal information, and does not use it for cross-context behavioural advertising. No "Do Not Sell or Share My Personal Information" link is required because no such activity takes place.
Your CCPA/CPRA rights. You have the right to know, delete, correct, and limit use of sensitive personal information, and the right to non-discrimination for exercising these rights. Because Fango stores your data only on your own device, you can exercise the right to know and the right to delete directly via Settings → "Clear all app data" or by uninstalling the app. For data held by third-party providers (Section 7), contact each provider directly.
Questions: support@fango.fi.
17 Other Jurisdictions
Fango is available in many countries. The on-device, no-account architecture described in this policy applies uniformly to all users, irrespective of their location. Where local privacy laws grant rights beyond those listed above, those rights are honoured as far as Fango's data practices allow. Notably:
United Kingdom (UK GDPR). The same rights described in Sections 10 and 11 apply; complaints may be lodged with the UK Information Commissioner's Office (ICO).
Switzerland (revised FADP). Equivalent rights apply; complaints may be lodged with the Federal Data Protection and Information Commissioner (FDPIC).
Other U.S. state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, and others as they enter into force). Fango does not sell personal data, does not use targeted advertising, and does not engage in profiling that produces legal or similarly significant effects. Deletion and access rights are exercised on-device as described in Section 11.
Turkey (KVKK / Law No. 6698). Fango supports Turkish-language receipt formats. The substantive obligations of the KVKK (data minimisation, purpose limitation, security) are met by the privacy-by-design architecture described above. Where data subject rights under KVKK Article 11 are exercised, the on-device deletion procedure in Section 11 applies; for residual third-party data, contact the providers listed in Section 7 directly.
New Zealand (Privacy Act 2020), Singapore (PDPA), Israel (Protection of Privacy Law 5741-1981). The principles common to these regimes — purpose limitation, data minimisation, security safeguards, and access/correction/erasure rights — are satisfied by Fango's on-device storage model. Israeli residents may exercise rights under Section 15 of the PPL; Singapore residents may contact the providers listed in Section 7 for residual data they may hold.
Canada (PIPEDA), Australia (Privacy Act 1988), Brazil (LGPD), Japan (APPI), South Korea (PIPA), South Africa (POPIA), India (Digital Personal Data Protection Act 2023), Mexico (LFPDPPP), Argentina (PDPA), Thailand (PDPA), and other jurisdictions. Fango's privacy-by-design architecture (no user accounts, opt-in consent-based analytics only, no behavioural tracking, no sale of data) satisfies the substantive requirements of these regimes. Where local law grants additional rights or remedies beyond those listed in this policy, those rights are honoured to the extent reasonably possible given Fango's minimal-server-side-data architecture. Contact support@fango.fi if you need additional information specific to your jurisdiction.
18 Website (fango.fi)
Sections 1–17 describe the Fango app. This section describes the fango.fi website, including the blog. The website is operated separately from the app, shares no data with it, and collects nothing that identifies you.
No cookies, no advertising trackers. The website sets no cookies and loads no advertising, social or profiling scripts. There is consequently no cookie banner to accept or reject.
Visitor statistics. Page views are counted by GoatCounter, a cookieless analytics service. It sets no cookies, does not store IP addresses and does not follow visitors across sites. What we receive are aggregate counts — page views per page, referring site, and coarse browser and country categories — never an individual visitor’s browsing history. GoatCounter’s own privacy statement is available at goatcounter.com/help/privacy.
Download-link measurement. When you tap a link to install the app, fango.fi/get/ forwards you to the App Store or Google Play and writes one line to a server log: the time, which article the link appeared on, whether the device is a phone or a computer, and a coarse browser/operating-system family such as Safari/iOS. No IP address, no cookie, no identifier and no full browser string are recorded, so the entries cannot be linked to one another or to you. We use this solely to see which articles lead people to install the app. These entries are deleted automatically after 90 days. The store link you are forwarded to carries the same article-level campaign tag; Apple and Google process it in their own store analytics under their own privacy policies (see Section 7) — it identifies the article, not you.
The one thing stored on your device. If you close the download bar shown at the bottom of a blog article, a single flag named fango_sticky_dismissed is saved in your browser’s local storage so the bar stays closed on later visits. It contains no identifier, is never transmitted anywhere, and you can remove it at any time through your browser’s site-data settings.
Apple’s Smart App Banner. On an iPhone, Safari may display Apple’s own app banner at the top of the page. That banner is generated by Apple from a standard tag in our pages; any interaction with it takes place between your device and Apple and is not visible to us.
Hosting. Like any website, fango.fi is served by a hosting provider (Hostingpalvelu Oy, Finland) whose web server keeps standard access logs containing IP addresses for security and troubleshooting purposes. Those logs are held by the provider under its own retention policy; we do not use them for analytics, profiling or marketing.
Lawful basis. The aggregate statistics and the download-link log rest on legitimate interest (Art. 6(1)(f)) in understanding which content is useful and whether the site functions correctly — an interest balanced by the fact that no personal data is collected. The local-storage flag is strictly necessary to deliver a function you requested (keeping a dismissed bar closed) and therefore requires no consent under the ePrivacy Directive.
19 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective Date at the top of this page. We encourage you to review this policy periodically, especially before using a new version of the app.
Continued use of Fango after changes are published constitutes your acceptance of the updated policy. If changes are significant, we will make reasonable efforts to notify users (for example, through a notice in the app).
20 Contact
For privacy-related questions or requests, please contact us:
Email: support@fango.fi
We aim to respond to all privacy inquiries within 30 days.