Frintake

Privacy

Frintake is a household system, not a viral consumer graph. The family is the tenant. Other families cannot see this door.

Effective date: 8 September 2026
Service: Frintake at https://frintake.com
Contact: [email protected]

This policy describes how we process personal data when you use Frintake on the web or as an installed app (iOS / App Store or Android / Google Play). It reflects the product as it works today: household isolation, encryption at rest with a key we hold, and AI features that send limited context to vendors. It does not describe end-to-end encryption (that is a later phase).

1. Who is responsible

Controller: Juhani Kamila, Espoo, Finland.

Email: [email protected]

No company (no Y-tunnus). No separate DPO. Privacy questions go to that email.

2. What Frintake is

A household app: calendar, meals, shopping, lists, fridge photos, optional voice assistant (FrinAI). Data belongs to a household. Only invited people can use it. Children may have a profile (name, food notes) without an email or login. Public signup is closed.

3. Data we process

Account: email, display name, role, passkeys (public keys only — not your fingerprint), invite codes, language, plan and usage meters.

Kitchen content: events, meal plans, saved recipes, lists, to-dos, cook/shop assignments, allergies / “never serve”, optional work email.

Photos: fridge scans and event/flyer photos you send. We keep at most one current fridge polaroid per household, replaced in place. No album.

Voice: microphone audio for that FrinAI session, plus short context (first names, a few ingredients, your request). Processed live.

Calendars (optional): if you Connect Google or Outlook we store tokens and import events. Default for others in the house is busy-only. Write-back is off unless you turn it on. Disconnect drops imports; Frintake-created events stay.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Frintake does not use Google user data to train AI/ML models. Calendar data is used only to show and optionally write the household calendar. Voice commands that create an event are processed to run that feature and are not used to train models. We do not sell Google user data or send it to data brokers or advertisers.

Device: session cookie, app version, local household cache on the phone (readable if the phone is unlocked).

We do not collect advertising IDs, sell data, or give children emails.

Google user data (Limited Use)

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

  • We request only the Google Calendar scope (calendar.readonly).
  • What we receive: event title, time, location, attendees as Google sends them, plus OAuth tokens.
  • Who we share that Google Calendar data with:
    • stored on our EU host (Hetzner)
    • Cloudflare only as HTTPS transport
    • not sold, not given to advertisers or brokers
    • not sent to Microsoft
    • not sent to xAI / Grok
    • not sent to Apple or Google Play except the fact that you pay, which is not Calendar data
  • FrinAI (xAI Grok Voice API, paid API) receives the user's microphone audio and short household context the user already has in Frintake (first names, fridge items, events they created in Frintake). Imported Google Calendar events are not placed in the FrinAI / xAI payload.
  • xAI is contracted as the Grok API, not grok.com. xAI's API terms: they do not train on API inputs or outputs without explicit permission. We have not granted that permission.
  • Disconnect Google deletes tokens and imported copies. Frintake-created events stay.

4. Legal bases (GDPR)

Contract: running the household you asked for, sign-in, content, mail.

Contract / your request: FrinAI, scans, Connect you tap.

Legitimate interest: quotas, one-live-call limit, security logs.

Legal obligation: accounting for paid plans where it applies.

Allergies are only used to filter recipes because you typed them. Do not store medical records in Frintake.

5. Processors

Hetzner — EU servers and backups

Cloudflare — CDN / DNS / tunnel

Resend — magic link and recovery email

xAI — FrinAI voice and image analysis when you use those features

Google — Calendar if you Connect; Play if you pay

Microsoft — Outlook if you Connect

Staff who operate the server can technically decrypt what the app can decrypt. They are not allowed to browse families.

6. Encryption (honest)

Sensitive fields use AES-256-GCM at rest. Each household has its own data key, wrapped by a master key on our server. A stolen database file is not a readable diary by default. When you are signed in, our app decrypts. The operator who holds the master key can decrypt. This is not end-to-end encryption.

Passkeys: biometrics stay on the device.

7. Children

No child logins or child emails. A parent adds a first name and optional food notes. Child profiles cannot invite or Connect calendars. If we have an under-13 email account, write and we delete it.

8. Transfers outside the EEA

Kitchen servers: EU (Hetzner).

FrinAI / photo analysis: audio or the image and short context go to xAI in the United States. You can use Frintake without FrinAI, scans, or Connect.

9. Retention

Household content: until you delete it or the household.

Fridge polaroid: replaced by the next photo, or deleted with the house.

OAuth tokens: until Disconnect or household delete.

Magic links: short-lived.

Security logs: typically up to 90 days.

Backups: rolling; a deleted house can remain until that backup ages out.

10. Your rights

Access, rectify, erase, export, restrict, object, portability.

Turn off Connect / FrinAI / scans at any time.

Owner can ask to delete the whole kitchen; a member can leave.

Email [email protected] from the account address.

Authority: Tietosuojavaltuutetun toimisto, https://tietosuoja.fi — Lintulahdenkuja 4, 00530 Helsinki.

11. Payments

Pro is billed by Google Play or the App Store. We store that the household is Pro. We do not store your card number.

12. Security (summary)

Invite-only; signup closed; passkeys; household isolation; encryption at rest; HTTPS; origin not a public website; monthly caps on voice and AI photos; revoke devices in Settings.

13. Changes

Material changes: this page and the date, plus a note in the app or email.

14. Contact

[email protected] · https://frintake.com

This policy: https://frintake.com/privacy