Introduction
This Privacy Policy explains how Wellnoria AB processes personal data through Daily Simmer. Wellnoria AB is the controller. Contact us at support@dailysimmer.com or through our contact form.
Definitions
| Term | Meaning |
|---|---|
| we, us, our | Wellnoria AB. |
| Service | Daily Simmer. |
| you, your | The individual whose personal data this Privacy Policy describes. |
What we process and why
Most data comes from you or your use of Daily Simmer. We also receive data from sign-in, payment, app-store and assistant providers you choose, people who share content with you, and public pages you ask us to import.
| Data and source | Purpose and legal basis | Recipients | Retention |
|---|---|---|---|
| Account, identity, authentication and approximate-country data; recipes, images, profile details, collections, plans, lists, chats, prompts, attachments, assistant actions, preferences, connection data and other content, from you, your providers, connected assistants and people who share with you | Provide requested features; operate, administer, support, secure, troubleshoot, enforce, maintain and improve the Service. Contract where objectively necessary for a requested feature or support; otherwise our legitimate interests in service administration, security, integrity, reliability and improvement. | Authorized staff; identity, hosting, database, storage, security, email and AI providers; connected assistants; people you share with; and the public when you publish. | Account and content data remain while the relevant account, content or feature remains, and afterwards where needed for backups, deletion, a specific legal obligation, incident, dispute or claim. Pending assistant authorization data is kept for up to 10 minutes. Access-token, renewable-credential and client-registration records are kept for one hour, 30 days and 90 days respectively. Active connection records are kept until expiry or revocation. Duplicate-write records are kept for 30 days and write-audit records for 90 days. Expired records are removed through routine cleanup. Deletion records follow a 90-day identifier-minimization and 10-year record-retention schedule, subject to routine cleanup and documented legal holds. |
| Dietary preferences, allergies, medical-diet information and other special-category data you provide | Personalize and support requested features; review special-category content where permitted; establish, exercise or defend legal claims. Contract or legitimate interests under Article 6 GDPR, together with explicit consent under Article 9(2)(a) where applicable, or Article 9(2)(f) where processing is necessary for legal claims. | Authorized staff; hosting, storage and AI providers. | Saved health data remains until you clear it, withdraw the relevant consent, delete the account or it is no longer needed for the stated purpose, subject to legal obligations and claims. Special-category data contained in other content follows that content’s retention. |
| Public post text, comments, creator details, links and media from a public page you ask us to import | Retrieve, attribute and convert the named page into a recipe. Our legitimate interest in providing a user-directed import. | Public-content retrieval, hosting, storage and AI providers. | The retrieved source copy is normally kept for about one hour. The saved result follows the retention for user content. The creator's name, handle, profile link and a copy of their profile picture are kept while an imported recipe credits them, and removed on a successful objection. Information needed for objections, rights complaints or claims remains while necessary for that purpose. |
| Purchase, subscription, entitlement, refund and withdrawal data from you, payment providers and app stores; contact, support and feedback messages from you; email and push information generated when we communicate with you | Administer purchases and access; meet legal and accounting duties; handle requests, support and claims; send necessary or requested communications and optional marketing. Contract, legal obligations, our legitimate interests in support and claims, and consent for electronic marketing where required. | Authorized staff; customer-support, payment, entitlement, app-store, email, push-delivery and private staff-messaging providers. | Purchase and accounting records remain for the applicable statutory period and longer where necessary for a dispute or claim. Support records remain while needed to handle the matter and any related obligation or claim. Communication data remains while the relevant account, request, preference or suppression record is needed. |
| Device, browser, IP address, interaction, attribution, feature-use, request, error, performance and other technical data generated through use of the Service | Provide essential device features and preferences; measure acquisition, use and reliability; secure the Service; prevent abuse; investigate faults; enforce limits and terms; and handle claims. Consent for non-essential device access and consent-based analytics; otherwise our legitimate interests in security, reliability, abuse prevention, limited product measurement and claims. | Hosting, analytics, security, logging and error-monitoring providers. | Analytics events are kept for up to seven years. Unlinked attribution data is kept for up to 30 days; account-linked attribution remains while the account exists or until a successful objection. Operational logs and error events are generally kept for up to 30 days. Evidence for an identified incident, obligation, dispute or claim remains while necessary for that matter. |
When signed-in analytics is enabled, we also share your account email address with a customer-support provider to match support requests from the same address.
You must provide the account and content data necessary for a feature you request; without it we cannot create the account or provide that feature. Health data, special-category chat review, analytics, marketing and push notifications are optional.
Authorized staff access
Authorized staff may access ordinary account data and ordinary user content for the purposes stated above. We rely on contract where the access is objectively necessary for a requested feature or support, and on our stated legitimate interests otherwise.
Chats and other content may reveal health information or another special category of personal data. Staff may review that information for support, troubleshooting or service improvement with your explicit account-level or chat-specific consent. We may instead rely on another Article 9 condition where it applies, including when processing is necessary for legal claims.
Cookies and device storage
We use essential cookies and device storage for sign-in, security, preferences, offline data, drafts and feature state. Non-essential analytics cookies or device storage are used only with consent. You may withdraw that consent through Privacy settings or the website’s Privacy choices.
Session storage ends with the session. Language and similar preference cookies last up to one year. Other local feature data remains until cleared by the feature, account, app, browser or device.
Sharing and public content
We disclose personal data to the recipient categories above, people you choose to share with, public visitors when you publish, a buyer or successor in a corporate transaction, and authorities or advisers where necessary for law or legal claims. Identity providers, app stores, payment merchants and connected assistants may process data under their own privacy notices.
Content you make public may be accessible through Daily Simmer, public links and search engines.
International transfers
Some recipients process data outside the EEA, including in the United States. Where GDPR applies, we use an applicable European Commission adequacy decision or the Commission’s Standard Contractual Clauses. Contact support@dailysimmer.com for information about a particular transfer or a copy of its safeguard.
Your choices and rights
Depending on the processing, you may have rights to access, rectify or erase personal data, restrict processing, receive portable data, and object. You may withdraw consent at any time without affecting earlier lawful processing, and you may always object to direct marketing.
Contact support@dailysimmer.com or use our contact form to exercise a right. We may retain data where applicable law permits or requires it.
You may complain to the Swedish Authority for Privacy Protection (IMY) or another competent EEA supervisory authority.
Changes
If we intend to use personal data for a new purpose, we will provide the information required by applicable law before doing so.