Privacy notice
Effective: 30 September 2026
The short version
FamilyMenu keeps your family's dishes and recipes as a shared menu card. To do that it stores what your household enters, on servers in the European Union.
There are no ads, no analytics and no tracking of any kind. Only the members of a household can see its menu.
Controller
Responsible for data processing within the meaning of Article 4 (7) GDPR is Nicolas Mehlei, Galgenberg 39A, 22880 Wedel, Germany, hello@codebakery.net. Full details are in the imprint.
Signing in
You sign in with your Google account. Sign-in runs through our own sign-in service (Keycloak), which stores your name, your email address and your Google account ID, which links your sign-in to your Google account. We never see your Google password.
What we store, and where
Everything is stored within the European Union:
- Your account — your display name, your language and the ID of your sign-in record — and your household, its members, chapters, dishes and recipes, in a PostgreSQL database in Germany (Hetzner).
- Dish photos — in Microsoft Azure Blob Storage, region Germany West Central. The app uploads and loads them through short-lived signed links; they are never public.
- The app talks to our server, which runs on Microsoft Azure in the West Europe region and is reached through Cloudflare, our processor for transport security.
Technical logs
Our servers record technical data — request times, error messages, performance traces — in our own monitoring system to keep the service running. These records contain no menu content and no photos.
Crash reports
When the app crashes or hits an error, it sends a technical report — the error message, where in the app it happened, the app version, your device model and its operating system version — to our own error-tracking service, which runs on a server rented from netcup in Germany. The report contains no name, email address or menu content, and the service does not store your IP address. We keep these reports for 90 days; backups of the service, in Microsoft Azure region Germany West Central, are kept for at most another 90 days.
This website
This website is hosted on Microsoft Azure Static Web Apps. It sets no cookies, loads nothing from third parties and runs no analytics. The hosting provider processes your IP address to deliver the pages.
Service providers outside the EU
Some of the companies we rely on are based in the United States: Google (sign-in), Microsoft (Azure hosting) and Cloudflare, which terminates the encrypted connection to our API and therefore processes that traffic. We store your data in their EU regions where they offer them. Where data reaches the United States, the transfer relies on the EU–US Data Privacy Framework adequacy decision and on the European Commission’s Standard Contractual Clauses (Article 46 GDPR).
How long we keep it
We keep your data while your account exists. Deleting your account in the app deletes it, with one exception: your record in our sign-in service, which we delete on request — see the data-deletion page. Deleted photos can be restored for 7 days and are then gone for good.
Legal basis
We process your data to provide the app you asked for (Article 6 (1) (b) GDPR) and, for technical logs and crash reports, on the basis of our legitimate interest in running a secure and reliable service (Article 6 (1) (f) GDPR).
Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, and to data portability. Write to hello@codebakery.net. You can also complain to a data protection supervisory authority.