Privacy policy for the Cochi app and this website
This English version is a courtesy translation. The German version is legally binding.
Last updated: 8 October 2026
1. Who is responsible?
The controller responsible for processing your data in the Cochi app is:
ThePuffer, owner Ali Maad Hassan (Einzelunternehmen, sole proprietorship)
Goebenstraße 27
65195 Wiesbaden
Deutschland
Phone: +49 176 63062016
Email: hallo@thespoon.ai
You can find further details in the legal notice (Impressum).
We have not appointed a data protection officer.
2. In short
- You can use Cochi without an account, without a name and without an email address.
- We only need your phone number if you voluntarily add it so you can find your plan again on another device.
- There are no ads, no tracking, no analytics services and no crash reports sent to third parties.
- Our server is located in Germany and is operated by us ourselves.
- You can delete your account and your data in the app at any time: Profile → "Delete account".
3. Use without an account
When you open Cochi for the first time, you answer a few questions (budget, household, diet, cuisines, store). At first, these answers are stored only on your device.
As soon as you have a weekly plan created, the app sets up an anonymous session with our sign-in service. This is a random identifier (UUID) without a name, without an email address and without a phone number. It allows our server to link your plans, your pantry and your shopping lists to you without knowing who you are.
4. What data we process
4.1 Only on your device
| Data | Purpose |
|---|---|
| Answers from getting started (draft), current plan, shopping list, checked-off status, settings | So that the app picks up where you left off after closing it |
| Sign-in tokens of your session | Stored in the operating system's protected keychain (iOS Keychain) |
| Place name from the location lookup | Displaying "city detected" during getting started |
This data only leaves your device in the cases described below. When you sign out or delete your account, the app removes it from the device.
4.2 On our server
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Random user identifier (UUID), time of creation, whether the session is anonymous | Linking your data, sign-in | Art. 6(1)(b) GDPR (contract of use) | Until you delete your account |
| Phone number (only if you add it) | Sign-in via SMS code, finding your plan again on a new device | Art. 6(1)(b) GDPR | Until you delete your account |
| Email address and password hash (only if you create an email account, see 4.3) | Sign-in | Art. 6(1)(b) GDPR | Until you delete your account |
| Budget, weekly or monthly mode, number of meals, protein goal | Calculating your plan | Art. 6(1)(b) GDPR | Until you delete your account |
| Household size, number and age groups of children (e.g. "4–8 years", no names or dates of birth) | Suitable quantities and dishes | Art. 6(1)(b) GDPR | Until you delete your account |
| Goals (e.g. "quick & easy", "lose weight"), kitchen equipment, favourite cuisines, dislikes (free text) | Suitable dishes | Art. 6(1)(b) GDPR | Until you delete your account |
| Diet (vegetarian, vegan, gluten-free, lactose-free, halal), halal meat source, halal strictness, name and location of your butcher | Suitable dishes, halal check, two shopping baskets | Halal: Art. 9(2)(a) GDPR (explicit consent, see section 5); everything else: Art. 6(1)(b) GDPR | Until withdrawal or until you delete your account |
| Selected store (branch) | Prices for your store | Art. 6(1)(b) GDPR | Until you delete your account |
| Saved weekly plans, pantry, shopping lists, checked-off items | Core function of the app | Art. 6(1)(b) GDPR | Until you delete your account |
| Confirmed shopping total after shopping (expected / paid) | Comparing the plan with the actual shop | Art. 6(1)(b) GDPR | Until you delete your account |
| Price reports (product, store, price, time) | Better prices for everyone | Art. 6(1)(f) GDPR (legitimate interest in reliable prices) | See section 4.5 |
4.3 Phone number and SMS code
You can add your mobile number under Profile → "Add number". We then send you a six-digit code by SMS, which is valid for five minutes. With the same number, you can later sign in again on a new device.
To send it, we pass your phone number and the text of the SMS ("Dein Cochi-Code: …") to our SMS service provider Telnyx (USA, see sections 7 and 8). Telnyx forwards the SMS to your phone via mobile network operators. In our own logs, your number appears only in shortened form (e.g. "+49•••••••89"), the code never.
The phone number is optional. The app works fully without it; however, you then cannot take your plan to another device.
Email address and password: In some cases, when you save a plan, the app offers to create an account with an email address and password. If you use this, our sign-in service stores your email address and your password, which is stored only as a non-reversible hash value (Art. 6(1)(b) GDPR, stored until you delete your account). We currently do not send any emails to this address.
4.4 Dietary information and profile
The app sends your answers from getting started to our server when you have a plan created, so that the server can calculate suitable dishes and prices. They are stored when you save a plan or change your profile.
4.5 Price reports
When you report prices after shopping, for each report we store not your user identifier, but a hash value calculated from it. This allows us to evaluate reports without linking them to your account in plain text. Because we know the identifier itself, this is pseudonymisation, not anonymisation.
When you delete your account, we replace this value in every single report with a new random value. The reports (product, store, price, time) then remain anonymised in the shared price history and can be linked neither to you nor to each other.
4.6 Location
If you allow it during getting started, the app requests your approximate location once in order to show the nearest stores first.
- The coordinates are sent to our server for this one request, used there to sort the stores and not stored. Our server logs contain only the name of the request, not the coordinates.
- To show you the name of your city, the app uses your operating system's location service. On the iPhone, the position is transmitted to Apple for this purpose; Apple's privacy policy applies to this.
- Only the store you select is stored.
You can decline location permission and choose your store yourself. The app then works fully.
4.7 Product search by barcode number
When you search for a product by its barcode number (EAN), you enter the sequence of digits yourself. The app sends only this number to our server to find the product. The search query is not stored.
4.8 Recipe photos
The app downloads the photos of the dishes from our server. No user identifier is sent with them; only the technical connection data described in section 4.9 arises.
4.9 Connection data and server logs
Every connection to our servers technically involves your IP address, the time, the requested address and information about the app and operating system.
- All connections are encrypted (HTTPS) and run through the network of Cloudflare (see section 7), which forwards the requests to our server and protects it against attacks. Cloudflare processes your IP address in doing so.
- Our app server logs the method, path and status of a request, but neither your IP address nor values from the request (e.g. no coordinates, no phone number, no sign-in tokens). The IP address is used only briefly in memory to limit abuse through too many requests.
- Our sign-in service stores technical data for each sign-in session, such as IP address, device type (user agent) and timestamps. It also keeps a security log of sign-in events (e.g. sign-in, code requested, sign-out) with IP address and time. We delete session data together with your account. We delete entries in the security log after 90 days.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation and the prevention of abuse. We delete server logs after 14 days at the latest.
5. Halal and other specially protected information
Please read this section.
If you select "Halal", we process information from which your religious beliefs can be inferred. This is a special category of personal data under Art. 9(1) GDPR.
We process this information only on the basis of your explicit consent (Art. 9(2)(a) GDPR). The app asks you in a separate dialog ("Consent: halal preference") before halal is selected, saved or sent to our server. We use it exclusively to
- select dishes and products that fit your diet,
- check ingredients (e.g. for gelatine, alcohol, animal rennet) and flag doubtful cases with a reason,
- split your shopping list into "Market" and "Butcher" if you buy halal meat from a butcher.
We treat "vegetarian", "vegan", "gluten-free" and "lactose-free" as preferences for selecting dishes. We do not ask about intolerances, illnesses or diagnoses and do not infer any.
We do not use this information for advertising, profiling or disclosure to third parties.
Withdrawal: You can withdraw your consent at any time with effect for the future by removing the selection in your profile. The information is then deleted, not merely no longer used. The app remains fully usable without this information.
6. What we do not do
- No ads and no advertising SDKs.
- No tracking across other providers' apps or websites, no advertising ID.
- No analytics services and no crash reports sent to third parties. Usage events are generated only locally on your device and are not transmitted.
- No selling and no disclosure of your data for advertising purposes.
- No cookies.
7. Where your data is stored and who receives it
Our server: We operate the app server, database and sign-in service ourselves on our own hardware in Germany. The sign-in service is open-source software (GoTrue) that we run ourselves; no external sign-in provider is involved.
Service providers acting on our behalf (processors, Art. 28 GDPR):
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare, Inc., San Francisco, USA | Forwarding and protection of all connections to our servers (content delivery network, proxy) | IP address, technical connection data; request contents are passed through | USA, worldwide network |
| Telnyx LLC, Chicago, USA | Sending the SMS sign-in code | Phone number, SMS text with code | USA |
Other recipients acting as independent controllers:
- Mobile network operators deliver the SMS with the sign-in code.
- Apple distributes the app via the App Store and provides the iPhone's location service. Apple is responsible for the data that Apple itself collects in doing so.
8. Transfers to third countries
Cloudflare and Telnyx are based in the USA. A transfer of your data there is therefore possible.
Where the respective provider is certified under the EU-US Data Privacy Framework, the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR). Otherwise it is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) in the provider's data processing agreement.
You can request a copy of the respective safeguards from us.
9. Deletion
- Delete account: In the app under Profile → "Delete account". We then immediately and permanently delete your profile, your dietary information, plans, shopping lists, your pantry, your household and your sign-in data including your phone number or email address. Entries in the sign-in service's security log (section 4.9) are deleted only once their retention period has expired. Price reports are retained only in anonymised form (see section 4.5).
- Sign out: removes your data from this device. If you have not added a phone number, you cannot sign back in to this account afterwards; the data on the server remains until you ask us to delete it. If you want to delete everything, it is therefore better to use "Delete account".
- Backups: We create backups of our database. Deleted data may still be contained in them for up to 30 days until the backup is overwritten in the regular cycle. We use backups only to restore after a failure.
10. Your rights
You have the right to
- access the data we store about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR), directly in the app or by email,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR),
- withdraw consent with effect for the future (Art. 7(3) GDPR).
To do so, write to us at hallo@thespoon.ai. So that we can find your account, please tell us the phone number you added. If you have not added one, we do not know your identity; in that case the "Delete account" function in the app is the quickest way to help you. We will respond within one month.
11. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority, for example the authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information, HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, datenschutz.hessen.de.
12. Do you have to provide us with data?
No. However, without the information from getting started, the app cannot calculate a meaningful plan, and without a phone number you cannot take your plan to another device.
13. Automated decisions
Your weekly plan is calculated automatically from your information and current prices. This is a suggestion, not a decision with legal effect within the meaning of Art. 22 GDPR: you choose each dish yourself and can swap it. The halal classification of products is rule-based and describes a product, not you.
14. Storage on your device
The app stores data on your device (section 4.1) because it cannot work without this data. Under § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), this is permitted without separate consent. We do not read device identifiers for advertising or analytics purposes.
15. Data security
All connections are encrypted via HTTPS. Sign-in tokens are stored in the operating system's keychain. Only we have access to the server and database.
16. Data sources
Product and store data come, among other sources, from Open Food Facts and OpenStreetMap as well as from publicly available supermarket offers. No data about you is transmitted to these sources.
17. This website
The Cochi website is a purely informational site. You cannot enter anything or create an account there.
- Hosting: The website runs on the same server in Germany as the app and is likewise delivered via Cloudflare (see sections 4.9 and 7). Each page request technically involves your IP address, the time, the page requested and your browser identifier (user agent). Our server logs only the method, path and status of a request, not your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and fast website. We delete server logs after 14 days.
- No cookies, no tracking: The website sets no cookies and uses no local storage, no analytics or advertising services and no social media plugins. That is why there is no cookie banner either.
- No third-party content: Fonts and images are hosted on our own server; there are no scripts. When you access the site, no data is transmitted to Google Fonts, content delivery networks or other third parties.
- Link to the App Store: Only when you tap "Download on the App Store" do you switch to Apple. From then on, Apple's privacy policy applies.
- Emailing us: If you write to us, we process your email address and your message in order to reply to you (Art. 6(1)(b) or (f) GDPR). Our email inbox is operated by Microsoft (Microsoft Ireland Operations Limited, Dublin) as part of Microsoft 365, as our processor. We delete the message once your request has been dealt with and no statutory retention obligations apply.
18. Changes
We update this policy when the app or the processing changes. You can always find the current version at cochi.the-puffer.com/en/datenschutz and in the app. If a change affects your consent under section 5, we will ask you again.