Privacy Notice
Last updated: 24 September 2026
Who is responsible
The Maruva website at maruva.app and the Maruva mobile application (together, the Service) are run by the operator of the Service, who is the controller of your personal data. Contact:
- dev@maruva.app
This notice applies under the Law of Ukraine "On Personal Data Protection" and, where you use the Service from the European Economic Area or the United Kingdom, the GDPR and UK GDPR. It forms part of our Terms and Conditions.
The website
This website sets no cookies, runs no analytics and embeds no trackers. Our network provider, Cloudflare, processes connection data (IP address, requested page, browser type) to deliver the pages and protect them from abuse. We do not store that data ourselves.
What the application collects
- Account. You sign in with Google or Apple. We receive the name, email address and account identifier that provider shares with you, and we store them with your username and avatar. We never hold a password.
- Taste profile and preferences. Quiz answers, ratings, the equipment you own, units, appearance and notification settings — everything the recommendations are built from.
- Diary, wishlist, challenges and streaks. What you brewed, how, what you thought, what you saved and which goals you set.
- Assistant conversations. The messages you send to the assistant and the replies you receive.
- Photos. Label photos you take to scan a bag. If a label is not recognised, the photo is kept so the product can be added to the catalogue.
- Location. Only if you allow it, and only while you use the café map, your device location is sent to find places near you. You can decline and browse cafés by city instead.
- Push notifications. If you turn them on, a device push token is registered with Firebase Cloud Messaging so we can deliver reminders.
- Usage events. In-app events such as "recipe viewed", "timer started" or "signed in" are sent to our own servers. There is no third-party analytics SDK in the app.
- Purchases. When paid features open, the App Store or Google Play bills you and passes us a purchase receipt and entitlement state. We never see your card or bank details.
- Technical records. Sign-in events, IP address, app version and device type in our server logs, kept for security and troubleshooting.
Why we use it
- To provide the Service you asked for: recommendations, guides, the diary, the assistant, the café map, notifications and purchases (performance of our contract with you).
- With your consent, for the data your device asks you about: location, camera and photos, notifications. You can withdraw consent at any time in your device settings.
- For our legitimate interests in keeping the Service secure, understanding how it is used and improving it, in ways that do not override your rights.
- To meet legal obligations, including tax and accounting rules that apply to purchases.
We do not sell personal data, and we do not use it for third-party advertising.
Who processes it for us
The following providers process data on our behalf under their own data-processing terms. Several of them are outside Ukraine; transfers rely on their standard contractual safeguards.
- Sign in with Google; Firebase Cloud Messaging for push notifications
- Apple
- Sign in with Apple; App Store billing
- OpenAI
- Generates the assistant's replies. Your messages to the assistant are sent to its API for that purpose only
- Langfuse
- Traces assistant conversations so we can review answer quality and cost
- RevenueCat
- Validates purchase receipts and tracks subscription state
- Cloudflare
- Network, DNS and connection security for the website and API
- Oracle Cloud
- Servers and database hosting
When you tap through to buy a product, you leave the Service for the merchant's own website. We do not send merchants your personal data; their privacy terms apply from that point.
How long we keep it
- Account, profile, diary, wishlist and assistant history: for as long as your account exists. Deleting the account removes all of it.
- Sign-in and security events: 12 months, then removed automatically.
- Unrecognised label photos: until the product is added to the catalogue or your account is deleted.
- Encrypted backups: a short rolling window of recovery points that expire automatically. Data deleted from the live Service disappears from backups when the last recovery point containing it expires.
Your rights
You can ask us to access, correct, export or delete your personal data, to restrict or object to its processing, and to withdraw consent. You can edit your profile, preferences and diary in the application. Account deletion and data export are done by us on request: write to dev@maruva.app from the email address on your account and we will complete it within 30 days, confirming when it is done.
If you believe we have handled your data unlawfully, you may complain to the Ukrainian Parliament Commissioner for Human Rights or, in the EEA or UK, to your local supervisory authority.
Children
The Service is not directed at children. You must be at least 16, or the age of digital consent in your country if higher, to create an account. If you believe a child has given us personal data, contact us and we will delete it.
Security
Data travels over TLS and is stored on access-controlled servers with encrypted backups. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.
Changes to this notice
We will post any change here and update the date above. A material change will also be announced in the application before it takes effect.
Contact
Questions about this notice or your data: dev@maruva.app.