Organr

Privacy Policy

February 3, 2026

Data Controller

Organr is a personal project operated from Norway. For privacy inquiries, use the contact form at organr.com/en/contact.

What data do we collect?

We collect your name, login PIN, and data you create in the apps: calendar entries, tasks, shopping lists, food inventory, recipes, and meal plans. Email address is optional. We also store technical preferences like theme settings and language choice in your browser's localStorage.

Purpose and legal basis

We process personal data to deliver the service (GDPR Art. 6(1)(b) — contract performance) and to improve the service based on legitimate interest (GDPR Art. 6(1)(f)). AI features in Fridgr, Recipr, and Pantr use Google Gemini for image analysis and recipe generation.

Third-party sharing

We share data with: Supabase (database and authentication, EU region), Google Cloud (Gemini AI for food recognition and recipes), and Vercel (hosting and CDN). No data is sold to third parties.

Storage and deletion

Data is stored as long as your account is active. When an account is deleted, all personal data is removed within 30 days. Anonymized usage statistics may be retained.

Your rights

Under GDPR, you have the right to access, rectification, erasure, data portability, restriction of processing, and the right to object. You can exercise these rights via our contact form. We respond within 30 days.

Children

Family accounts may include children. Parents/guardians with the admin role create and manage children's profiles and consent on their behalf.

Cookies

We do not use third-party cookies. Your browser stores authentication tokens, theme preferences, and language settings in localStorage. This is necessary for the service to function.

Security

All data is transmitted encrypted (TLS/HTTPS). Database access is protected with Row Level Security (RLS), ensuring families can only see their own data.

Breach notification

In the event of a data security breach, we will notify affected users and the Norwegian Data Protection Authority within 72 hours per GDPR Art. 33.

Changes

We update this policy when significant changes occur. The last update date is shown at the top of this page.