This privacy policy explains what data the Krossr app ("the app") processes, for what purpose, and what rights you have.
The controller responsible for data processing under the EU General Data Protection Regulation (GDPR) is:
Manuel Staggl
Email: manuel.staggl@gmx.at
Krossr is a privately developed project. For any privacy-related questions, please contact the email address above.
The following data is stored only locally on your device (in an on-device database and in the app settings). It is not sent to us or to any third party:
You can change or delete this data in the app at any time. It only leaves your device if you have enabled an Android backup (e.g. to your Google account) yourself — in which case Google's privacy terms for that backup also apply.
Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract — the app only works with this locally stored data).
When you scan a barcode and the product is not already stored locally, the app looks up the
corresponding article number (EAN/barcode) via the public service
Open Food Facts (world.openfoodfacts.org) to retrieve product master
data (e.g. name, brand, product image).
Legal basis: Art. 6(1)(b) GDPR (the product lookup is a core function of the app and only happens in response to your active action — the scan).
Krossr may display advertising and collect error/usage data. Both are disabled by default on first launch. Before any advertising or analytics data is collected, the app asks for your consent through a consent dialog provided by Google (Google UMP / Consent Mode v2). Without your consent, none of this data is processed and no advertising ID is read.
If you give your consent, advertising is delivered via Google AdMob. Depending on your choice in the consent dialog (personalized vs. non-personalized ads), your advertising ID and technical device data may be transmitted to Google.
Also only after your consent, the following Google/Firebase services may collect data (Firebase project "krossr-f634c"). All of them are switched off in the shipped state and are only activated at runtime if you consent:
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG (consent). You can withdraw your consent at any time with effect for the future — see section 7.
If you want to unlock the Pro version, the purchase is handled via Google Play Billing. Payment data is processed exclusively by Google as part of your Google Play account; the app itself receives no payment or account data, only the confirmation of whether the purchase succeeded. Google Play's privacy terms apply.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority.
In practical terms in Krossr:
To exercise your rights or for any questions, an email to manuel.staggl@gmx.at is sufficient.
Data transmission to Open Food Facts and to the Google/Firebase services is encrypted (HTTPS/TLS). Your locally stored app data is protected against access by other apps by the Android operating system's app sandbox.
Krossr is not directed at children. No data is knowingly collected from children below the age of consent.
This privacy policy may be adjusted if the app or the legal framework changes. The current version is always available at the address linked in the Play Store listing and in the app. The "Last updated" date above is authoritative.