Stockora
HomePrivacyLegal noticeSupport
English⌄
DeutschEnglish✓FrançaisItalianoEspañolPolskiHrvatskiSvenskaNorskSuomi
Updated: September 8, 2026

Privacy policy

This translation is provided for readability. The German version is the reference text. Deutsch

1. Controller

Eric Pielo
Landsberger Allee 167
10369 Berlin
Germany
Email: support@stockora.de

2. Scope

This policy describes processing on stockora.de, in the Stockora app, and through api.stockora.de and auth.stockora.de.

3. Website access

IP address, timestamp, requested resource, referrer, browser information, and response status may be processed in server logs to provide the website securely and reliably. The initial landing page uses no advertising or analytics cookies. The legal basis is Article 6(1)(f) GDPR.

4. Account and authentication

Registration and login require an email address, encrypted password hash, verification state, security tokens, and timestamps. Passwords are not stored in plain text. The legal basis is Article 6(1)(b) GDPR.

5. App data

Depending on the features used, we process profile information, shopping lists, items, quantities, group membership, activities, store planning, pantry spaces, stock levels, reminders, product mappings, and optional profile emoji. This processing is necessary to provide the chosen app features.

6. Nutrition and health features

Stockora may calculate general nutrition or quality summaries from purchases and voluntary settings. These do not replace medical advice. The feature is not intended for diagnoses or the entry of medical health data.

7. Shared groups

Members of shared groups may see display name, profile emoji, added items, and list-related activity. Users are informed about this visibility before sharing.

8. Product sources

Product details may come from our database and open sources such as Open Food Facts. Requests are made without user identity where possible. External information may be incomplete or inaccurate.

9. AI-supported features

When receipt recognition is used, a receipt photo or PDF selected by the user may be sent to the AI provider. The original file is not stored permanently by Stockora after analysis; recognized item data confirmed by the user is processed for pantry import. When optional recipe or assistant functions are used, selected pantry and product information may be sent to an AI provider. Email addresses, passwords, and unnecessary identifiers should not be transmitted. The OpenAI API is used. For customers in the EEA, the contracting party is generally OpenAI Ireland Ltd. Processing is governed by the applicable business terms and data processing agreement. Where processing occurs outside the EEA, the safeguards provided in that agreement, including Standard Contractual Clauses, apply.

10. Transactional email

Registration, password reset, and account deletion emails are delivered through STRATO. Recipient address, sender details, delivery metadata, and message content are processed for this purpose.

11. Push and local notifications

When push notifications are enabled, we process a device-related Firebase registration token, platform, language, timestamps, and the selected notification preferences. Delivery uses Google Firebase Cloud Messaging (FCM). FCM uses an installation identifier to route messages to the relevant app installation. Push can be disabled at any time in Stockora or in system settings. Local cooking timers are generally scheduled on the device; their timer data is not used for advertising.

12. Hosting

The website, API and database run on server infrastructure provided by STRATO AG in Germany. Required data processing agreements are concluded with service providers.

13. Retention

Data is retained only as long as required for its purpose or by law. Verification, reset, and deletion tokens expire automatically. Server logs are deleted after 14 days. Personal account data is removed after deletion unless legal retention obligations apply.

14. Account deletion

Delete your account in the app or at auth.stockora.de/public/auth/delete-account. Web deletion requires email confirmation. Shared lists can remain available to other members while the deleted account’s personal attribution is removed or transferred.

15. Your rights

Under the GDPR, users have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Users may also lodge a complaint with a data protection supervisory authority.

16. Contact

Send privacy requests to support@stockora.de.

17. Changes

This policy will be updated when features, providers, or legal requirements change.

18. Location data

We collect and process users’ location data. This is used solely to accompany the personal in-store shopping experience and optimize it as effectively as possible (for example, for location-based offers, a store finder, or in-market navigation).

© 2026 StockoraPrivacy · Legal notice · Terms · Support