Privacy

Privacy Policy

Protecting your personal data is important to us. Tolerly has been designed according to the principles of data minimization and data protection by design.

You can use the Tolerly app without registration and without creating a user account. In particular, you do not need to provide your name, address, or email address in order to use the basic functions of the app.

This Privacy Policy explains which data we process when you use the Tolerly app and the website tolerly.com and for what purposes.


1. Data Controller

The controller responsible for the processing of personal data is:

Creavo Solutions
Am Lingelsberg 1
36110 Schlitz
Germany

Email: info@tolerly.com

2. Principles of Data Processing

We process personal data only to the extent necessary to provide our website, the Tolerly app, and the functions offered through them.

Depending on the respective processing activity, processing is based in particular on the following legal bases:

  • Article 6(1)(b) GDPR, insofar as processing is necessary for the performance of a contract or for taking steps at your request prior to entering into a contract, including providing the functions and services you request.
  • Article 6(1)(f) GDPR, based on our legitimate interest in providing our services securely, reliably, and protected against misuse.
  • Article 6(1)(a) GDPR, where you have given your consent to the processing of specific data.

3. Use Without a User Account

Tolerly generally does not use conventional user accounts.

You do not need to provide your name, address, or email address in order to use the basic functions of the app.

We do not maintain personal user profiles that can be directly linked to your name or to an email address stored with us.

4. Your Dietary Profile

Within the Tolerly app, you can select which intolerances, allergies, or other dietary parameters should be taken into account during an analysis.

This information is generally stored locally on your device.

When you perform a food or product analysis, the criteria selected for the analysis are transmitted to our servers together with your request, insofar as this is technically necessary to perform the requested analysis.

Your individual dietary profile is generally not stored permanently on our servers.

Depending on the information you select, information about allergies or intolerances may relate to your state of health. We process such information solely to the extent necessary to perform the analysis explicitly requested by you.

Where the processing constitutes the processing of special categories of personal data within the meaning of Article 9 GDPR, such processing is carried out only where the applicable legal requirements are met and, where required, on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR.

5. Food and Product Search Requests

When you search for a food or product in the Tolerly app, we process the information necessary to provide the analysis result you requested.

This may include, in particular:

  • the name or designation of a food or product,
  • a scanned barcode or GTIN,
  • product information or ingredient information,
  • the intolerances, allergies, or dietary parameters selected for the analysis,
  • technically necessary information required to process and secure the request.

The processing takes place solely for the purpose of handling your request and providing the corresponding analysis result.

Unless data is required for security, abuse prevention, or technical purposes, individual requests are not permanently stored in a manner that associates them with a specific user account.

6. Barcode Scanning and Camera Access

Tolerly may require access to your device's camera when you use the barcode scanning function.

Camera access is used solely to detect and read the barcode.

Photos or camera recordings are not permanently stored by Tolerly or transmitted to our servers unless this is expressly required for a function you are using.

You can disable camera access at any time through your operating system's settings. In this case, the barcode scanning function may no longer be available.

7. Product Information via Open Food Facts

To identify products based on their barcode, we use the product database provided by Open Food Facts .

When you scan a barcode, the barcode number is first transmitted to our servers. If sufficient information about the product is not available in our own data, we request the relevant product information from Open Food Facts.

In particular, the barcode number or GTIN of the product is processed for this purpose.

Your personal dietary profile is not transmitted to Open Food Facts solely for the purpose of resolving a barcode.

Requests to Open Food Facts are made solely to identify the product and obtain the information required for the subsequent product analysis.

Further information about Open Food Facts is available at: world.openfoodfacts.org

8. AI-Assisted Food Analysis

Tolerly uses artificial intelligence to automatically analyze foods and products.

For this purpose, the information required for the respective analysis is transmitted to an AI service.

This may include, in particular:

  • the name or designation of a food or product,
  • product and ingredient information,
  • intolerances, allergies, or dietary parameters relevant to the assessment,
  • other information necessary to perform the requested analysis.

We generally do not transmit directly identifying information such as your name, address, or email address to perform the analysis, as such information is not required for this purpose.

The AI services are used solely to generate the analysis result requested by you. They are not used to create a personalized advertising or behavioral profile.

8.1 AI Service Providers

We primarily use AI services provided by Google for AI-assisted food analysis.

If the primary service is temporarily unavailable or processing is technically not possible, OpenRouter may be used as a technical fallback.

In this case, OpenRouter may forward the information required for the analysis to an AI model provider or infrastructure provider selected by us for this purpose.

We limit processing to the information necessary for the respective analysis and do not use arbitrary or user-specific selection of AI providers.

Processing is carried out solely for the purpose of performing the food or product analysis requested by you.

8.2 Google Gemini

When our primary AI services are used, the content required for the analysis may be transmitted to and processed by Google.

Further information about data processing by Google is available at: policies.google.com/privacy .

8.3 OpenRouter

If OpenRouter is used as a technical fallback, the information required for the respective analysis may be transmitted to OpenRouter and to the AI model provider or infrastructure provider used for processing.

The providers used for this purpose are selected by us as part of the technical infrastructure of Tolerly.

Further information about data processing by OpenRouter is available at: openrouter.ai/privacy .

9. No Use of Analysis Data for Personal Tracking

The food, product, and analysis information transmitted to us is not used to create a personalized advertising profile or to track you across different websites or applications.

We do not use personalized advertising tracking within the Tolerly app.

10. Randomly Generated Device Identifier

When the Tolerly app is started for the first time, a randomly generated pseudonymous device identifier is created.

This identifier does not contain directly identifying information such as your name or email address.

The device identifier is used in particular for the following purposes:

  • technically associating requests with an app installation,
  • limiting excessive or automated requests,
  • detecting and preventing abusive use,
  • protecting against overload and denial-of-service attacks,
  • enforcing technical security measures,
  • where necessary, blocking app installations used abusively.

Processing is based on our legitimate interest pursuant to Article 6(1)(f) GDPR in protecting the security and stability of our systems.

The device identifier is not used to track you for advertising purposes or to create a usage profile across apps and websites.

11. Rate Limiting and Abuse Prevention

To protect our infrastructure, we use technical measures to limit requests and detect abusive use.

This may include processing the following information:

  • the pseudonymous device identifier,
  • the number and frequency of requests,
  • request timestamps,
  • technical error and security information,
  • where applicable, the IP address.

This processing serves to protect our systems against overload, automated attacks, abusive use, and other security risks.

The legal basis for this processing is Article 6(1)(f) GDPR.

12. Server Log Files and Technical Connection Data

When you visit our website or use the Tolerly app, technically necessary connection data is processed.

This may include, in particular:

  • IP address,
  • date and time of access,
  • requested technical resource,
  • HTTP status code,
  • amount of data transferred,
  • information about the client or user agent used,
  • error and diagnostic information,
  • security-relevant events.

This processing is necessary to provide our systems, identify errors, defend against attacks, and ensure the security and stability of our services.

The legal basis for this processing is Article 6(1)(f) GDPR.

Log data is stored only for as long as necessary for the purposes described above and is subsequently deleted or anonymized, unless security incidents or legal obligations require longer retention.

13. Local Storage on Your Device

Certain data and settings are stored locally on your device to ensure that the app functions properly.

This may include, in particular:

  • your dietary profile,
  • app settings,
  • the device identifier,
  • technical configuration data,
  • where applicable, locally stored analysis results.

This data generally remains on your device unless transmission to our servers or a third-party provider is necessary to perform a function you have requested.

You can generally remove locally stored data through the corresponding functions within the app, by resetting the app, or by uninstalling it.

14. Hosting and Technical Infrastructure

Our own server and backend infrastructure is operated in Germany.

This infrastructure includes, in particular, the technical systems used to process app requests, provide our API, and store technically necessary data.

External services are used for certain functions, in particular for AI-assisted analysis and retrieving external product information.

Processing by such external services is subject to their respective technical and contractual conditions.

15. Data Transfers to Recipients and Service Providers

Where necessary to provide our services, data may be transmitted to technical service providers or external providers.

This includes, in particular:

  • hosting and infrastructure providers,
  • Open Food Facts for retrieving product information,
  • Google for performing AI-assisted analyses,
  • OpenRouter and the model and infrastructure providers used as part of the defined fallback process.

We limit data transfers to the information necessary for the respective function.

16. International Data Transfers

Our own server and backend infrastructure is located in Germany.

However, when using external services, in particular Google and OpenRouter, it cannot be excluded that data may be processed outside Germany or outside the European Union or European Economic Area.

This concerns in particular the data transmitted to the respective service for the purpose of performing an AI-assisted analysis requested by you.

Where personal data is transferred to a third country, such transfer is carried out in accordance with the legal requirements for international data transfers under Articles 44 et seq. GDPR.

17. Contacting Us by Email

If you contact us by email, we process the information you provide, in particular your email address and the content of your message.

Processing is carried out solely for the purpose of handling your request and communicating with you.

The legal basis is Article 6(1)(b) GDPR insofar as your request is related to the initiation or performance of a contractual relationship. In other cases, processing is based on Article 6(1)(f) GDPR due to our legitimate interest in handling inquiries.

18. Payment Processing via App Stores

The purchase of paid content or functions is processed through the respective platform operators, in particular the Apple App Store or Google Play Store.

Payment processing is carried out by the respective platform operator.

We generally do not receive complete payment information such as credit card numbers or bank account details.

The processing of personal data by Apple or Google is carried out under the responsibility of the respective platform operator and in accordance with its own privacy policy.

19. Website and Cookies

When you visit our website, technically necessary data is processed to provide the website and operate it securely.

Where we use only technically necessary cookies or comparable technologies, their use is based on the applicable legal provisions governing the provision of the telemedia service expressly requested by you.

We do not use cookies or comparable technologies for personalized advertising tracking unless expressly stated otherwise in this Privacy Policy.

20. Data Retention

We generally retain personal data only for as long as necessary for the respective purpose.

The following principles apply in particular:

  • Your dietary profile is generally stored locally on your device.
  • Data transmitted for an analysis is processed only for as long as necessary to perform the respective request, unless technical or security-related storage is required.
  • Device identifiers are stored only for as long as necessary for security, abuse prevention, or technical purposes.
  • Server and security logs are deleted or anonymized after the applicable retention period has expired.
  • Data from support requests is deleted once the request has been handled and provided that no statutory retention obligations apply.

21. Data Security

We implement appropriate technical and organizational measures to protect your data against loss, manipulation, unauthorized access, and other security risks.

Communication between the Tolerly app, our website, and our servers is generally carried out using encrypted connections.

Our systems are protected against unauthorized access and misuse by appropriate technical and organizational security measures.

22. Your Rights

Subject to the applicable legal requirements, you have the following rights in particular:

  • Right of access pursuant to Article 15 GDPR,
  • Right to rectification pursuant to Article 16 GDPR,
  • Right to erasure pursuant to Article 17 GDPR,
  • Right to restriction of processing pursuant to Article 18 GDPR,
  • Right to data portability pursuant to Article 20 GDPR,
  • Right to object pursuant to Article 21 GDPR.

Where processing is based on your consent, you may withdraw your consent at any time with effect for the future.

Since Tolerly generally does not use conventional user accounts and we do not require directly identifying information such as your name or email address to use the app, the technical assignment of a request to specific data may be limited in individual cases.

If you have any questions regarding the processing of your data or wish to exercise your rights, you can contact us at info@tolerly.com .

23. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.

The supervisory authority responsible for us is, in particular, the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit).

You may also contact the data protection supervisory authority at your usual place of residence or place of work.

24. Changes to This Privacy Policy

We may amend this Privacy Policy if our app, website, technologies used, or legal requirements change.

The current version of this Privacy Policy is available on our website.

Last updated: August 2026