Back to sign in

Privacy notice

Last updated 15 September 2026

OffPlate helps a household plan its meals. This notice says which personal data it processes, why, for how long, who else handles it, and what you can ask for.

Who is responsible

The controller is René Viering, a private person who runs OffPlate.

Address: Halskestr. 5, 12167 Berlin, Germany

Email: hello@reneviering.com

Write to that email address with any question about your data, or to use any of the rights below.

What we process and why

Your account: your email address, your password and, if you set one, your display name. Purpose: to create your account, sign you in and show your household who is in it. Legal basis: Art. 6(1)(b) GDPR, because it is needed to provide the service you signed up for.

Your household’s planning: the dishes your household adds, its week plans, and a history of every change, including which member made it. Purpose: to let the household plan its meals together and keep the plan correct. Legal basis: Art. 6(1)(b) GDPR.

Emails about your account: to confirm your address, reset your password or invite you to a household, your email address receives a link or a code. So that these emails are in your language, your account stores whether they are written in German or English: the language of your device or browser when you sign up, or the language of the person who invited you. Purpose: to prove the address is yours and to let you back in. Legal basis: Art. 6(1)(b) GDPR.

Technical logs: the hosting provider records requests and errors. When a suggestion fails, our log can hold a short excerpt of the AI provider’s answer, which may contain dish names. Purpose: to keep the service secure and fix faults. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a working and secure service.

Error reports: when the app or the website runs into an error, it sends Sentry a report with the error message, the place in the code where it happened (the stack trace), the type of device or browser, the operating system and the app version. Sentry receives the IP address the report comes from, as any server does. A report is not linked to your account: it contains no email address, no display name and no password, and OffPlate removes email addresses from error messages before they are sent. An error message can still contain text from the screen, such as a dish name. Purpose: to notice faults and fix them. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a working and secure service.

The AI suggestion

Suggesting a week plan is optional and only happens when you ask for it.

When you ask, OffPlate sends Mistral AI the names of your household’s dishes, how many weeks ago each was last planned, and the dates of the empty days of that week. It does not send your email address, your display name or any account identifier.

Purpose: to propose a week plan. Legal basis: Art. 6(1)(b) GDPR, because the suggestion is part of the service you use.

The app marks the proposal as an AI suggestion. It is only a proposal: nothing is saved until you accept it, and no decision about you is made automatically.

Who else processes it

These companies process data on our behalf, each under its data processing addendum (Art. 28 GDPR).

Supabase hosts the database, the sign-in and the server functions. Our project runs in its EU region eu-north-1 (Stockholm, Sweden).

Mistral AI, a French company, answers the suggestion. According to its documentation, API data is hosted in the EU by default and may be transferred temporarily to the locations of its subprocessors.

Resend, a company in the United States, sends the account emails. Our domain sends from Resend’s EU region, but according to Resend the region only decides where emails are sent from: it stores message content and delivery logs in the United States. According to Resend, these transfers rely on the EU Standard Contractual Clauses (Art. 46 GDPR) and its certification under the EU-US Data Privacy Framework (Art. 45 GDPR).

Sentry (Functional Software, Inc.), a company in the United States, receives the error reports. Our Sentry organisation stores its error data in Sentry’s EU region (Frankfurt, Germany). According to Sentry, transfers of personal data from Europe to the United States rely on the EU-US Data Privacy Framework (Art. 45 GDPR), with the EU Standard Contractual Clauses (Art. 46 GDPR) as the fallback.

How long we keep it

Your account data is kept for as long as your account exists.

Dishes, week plans and their history belong to the household, so they are kept while the household has at least one member. When a member is erased, the household keeps the dishes and plans, and they no longer name that member.

When the last member of a household is erased, the household is deleted together with all of its dishes, plans and history.

The history of changes is otherwise never edited or deleted. Erasure under Art. 17 GDPR is the only exception.

Copies can remain in the hosting provider’s backups until those backups expire. The hosting provider keeps its sign-in and technical logs for a period that depends on its plan, at most 90 days. Mistral AI may keep suggestion requests for a limited period to detect abuse, as its documentation describes. Resend keeps email and log data for 30 days. Sentry keeps error reports for a period that depends on its plan, at most 90 days.

Your rights

You can ask for access to your data (Art. 15 GDPR), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18) and to receive it in a portable format (Art. 20). Where we rely on our legitimate interest, you can object (Art. 21).

You can change your display name yourself in your profile, and rename your household’s dishes in the app.

You can delete your account yourself, in your profile, after entering your password. You can also have it erased by writing to the email address above.

You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work.

An email address is needed to create an account, and without one OffPlate cannot be used. Everything else you enter is up to you.