Zastillia

Privacy Policy — Застілля (Zastillia)

App: «Застілля» (Zastillia) for iOS and Android Last updated / Effective: 2026-09-22


1. Who we are

«Застілля» ("Zastillia", "we", "us", the "App") is operated by San Byn Nhuien, a sole proprietor (ФОП) registered in Ukraine (the "operator" / data controller under Ukraine's Law "On Personal Data Protection" and, where applicable, the EU/UK GDPR).

Contact: support@zastillia.app.

This Policy explains what personal data the App processes, why, with whom it is shared, how long it is kept, and your rights. It applies to the iOS app and its extensions, to the Android app, and to our backend services. Where the two platforms differ — health data, payments, attestation and on-device storage do — the difference is stated rather than averaged away. It does not cover third-party services you choose to connect to (e.g. a grocery store's website you log into through the App) — those are governed by their own policies.

2. At a glance — what data is processed

Data Where it comes from Why Who receives it Retention
Anonymous install identifier Created automatically when you first open the App Associate your imported recipes and usage with your install; verify your requests come from the App Our backend (Google Firebase) Until you delete the App or request erasure
Recipe text you paste, on-device text recognition output, on-device audio transcripts; for video links — the linked video is downloaded on our server You (paste / photo / video / URL) Turn it into a structured recipe (ingredients, steps, calories/macros) Our backend → Google LLC (Gemini), OpenAI, Inc. and Anthropic, PBC; cached on our backend. Content sent to OpenAI may be used to train its models — see §4 Cached on our backend while you use the App; LLM providers per their own policies (see §4)
A recipe you choose to share, and its cover photo You, by tapping Share and confirming Publish it as a public web page at zastillia.app/r/… so anyone with the link can read it Anyone with the link, and search engines; screened first by OpenAI, Inc., which may use it to train its models — see §4 Until you revoke the link or delete your account (see §5)
Weight, height, biometric characteristics (age, sex) Apple Health (iOS) or Health Connect (Android), only if you connect it Compute your daily calorie/macro targets Nobody — used only on your device Your device only
Delivery address, approximate device location You type the address; iOS or Android provides location ("while using the app") if you allow it Find grocery stores that deliver to you; add items to your store cart Apple's mapping service (iOS) or the device's geocoder, provided by Google Play services (Android); the grocery store you choose, when you order Not sent to our backend; not stored by us. Recent addresses are kept on your device only
Grocery-store session Captured in an in-app browser when you log into a store site Add items from your list to your cart on your own store account Stays on your device; sent only to that store's servers Your device. Cleared when you remove the App
Subscription / purchase status Apple StoreKit (iOS) or Google Play Billing (Android) Unlock Premium features Apple, Inc.; the entitlement state is reflected to our backend's quota records Handled by Apple; we do not receive your payment-card data
App-usage events and screen views (incl. the names of recipes and ingredients/search terms you interact with — never delivery addresses, coordinates, store-account details, or your name), an app-instance identifier, your install identifier, country, app language, accent/theme, subscription status, whether health data is connected, onboarding completion The App Understand which features are used; improve the App; A/B-test the paywall Firebase Analytics (Google LLC) Up to 14 months by default
Crash reports, performance/diagnostic data The App Detect and fix bugs and performance issues Firebase Crashlytics / Performance (Google LLC) Per Firebase's retention (typically up to 90 days for crash data)
App-attestation token Apple App Attest (iOS) or Play Integrity (Android) Verify requests to our backend come from a genuine, untampered install Apple; Firebase App Check (Google LLC) Short-lived
Settings, onboarding state, theme/accent, cached recipe images and metadata, your manual recipes and weekly plan The App / you Run the App Your device and, for your recipe book, your own iCloud private database Your device / your iCloud, until you delete them or the App

We do not: ask for your name, email, or any other personal identifier to use the App; use your data for cross-app/cross-site tracking (no IDFA, no App Tracking Transparency prompt, no ad personalization); sell or rent personal data; share data with data brokers or advertising networks; use health data for advertising, marketing, or any purpose other than computing your in-app calorie/macro targets.

3. How you access the App — anonymous access

The App uses anonymous access. We do not ask for your name, email, or any personal identifier, and there is no "sign-in with [provider]" step. When you first open the App an anonymous install identifier is created automatically on our backend and used to associate your imports and usage with your install. This identifier is not linked to your real-world identity. Legal basis: performance of our agreement with you (the Terms of Use).

4. Recipe content you import

You can build recipes by typing/pasting text, from a photo (we run text recognition on your device), from a video file (we extract text/audio on your device), or from a link to TikTok / YouTube / Instagram.

In all cases the extracted text is sent to our backend, which forwards it to an AI provider to produce a structured recipe (title, ingredients, steps, per-serving calories/protein/fat/carbs). Three providers are involved: Google (Gemini), which handles most imports; OpenAI (speech-to-text, vision text-recognition, recipe synthesis); and Anthropic (recipe synthesis). Which one handles a given import depends on the source and on provider availability, so a single import may reach more than one of them. The result is cached on our backend and associated with your install.

Model training — please read this part. We take part in a programme that gives us free daily capacity from OpenAI in exchange for sharing our API traffic with them. This means the content we send to OpenAI, and what OpenAI sends back, may be used by OpenAI to improve and train its models. Concretely, that can include: recipe text you paste, text recognised from your photos, transcripts of audio from videos you import, the photographs you take of your kitchen shelf when you scan your pantry, the items on your shopping list when you use grocery matching or voice entry, and the text and cover photo of a recipe you publish.

We have not enabled any comparable sharing with Google or Anthropic.

Features that do not use AI — entering a recipe by hand, the plain grocery list, cooking mode, meal planning from recipes you already have — send nothing to any of these providers.

Legal basis: performance of our agreement / your request, for turning your input into a recipe. For the OpenAI sharing described above we rely on our legitimate interest in operating the service at a cost a one-person project can sustain; you can object to it at any time (see §15), and we will tell you what that means for the AI features. If you would rather nothing of yours reached a model's training data, do not use the AI-powered features.

We do not operate a public recipe feed. Recipes you create or import are visible only to you (and synced to your own iCloud) unless you choose to share one — see §5.

5. Recipes you choose to share publicly

The App can turn one of your recipes into a public web page at https://zastillia.app/r/<id>. This never happens automatically. You tap "Share", and the first time you ever share a recipe the App asks you to confirm explicitly that the page will be public. That confirmation is asked once, not once per recipe: afterwards "Share" publishes directly, and every link stays revocable at any time from the recipe's menu.

Sharing a recipe does not change who owns it. You remain responsible for having the right to publish what you share — see the Terms of Use.

6. Health and fitness data (Apple Health / Health Connect)

If you connect Apple Health on iOS, or Health Connect on Android, the App reads your weight and height — and, from Apple Health only, your date of birth and biological sex — to calculate your daily calorie and macronutrient (КБЖВ) targets. This data is used only on your device to perform that calculation — it is not transmitted to our servers, not stored by us, and not shared with anyone. You can disconnect it at any time in the App’s Profile screen, in iOS Settings → Privacy & Security → Health, or in Android’s Health Connect settings. The Android app requests only what it uses — reading weight and height — and asks for no write, activity or history permission. We comply with Apple’s HealthKit requirements and with Google’s Health Connect policy: we do not use Health data for advertising, marketing, data mining, or any use other than your in-app health targets, and we do not sell it.

КБЖВ / nutrition values shown in the App are AI-generated estimates and are not medical or nutritional advice. See §5 of the Terms of Use.

7. Location and delivery address

To help you order groceries, the App can use your location ("while using the app") to find stores that deliver to your area, and you may enter a delivery address (with address autocomplete powered by Apple's mapping service). Your location and address are sent to Apple for autocomplete/geocoding and, only when you place an order, to the grocery store you select. They are not sent to our backend and are not stored by us. The App keeps a short list of your recently used addresses on your device only. You can decline or revoke the location permission in iOS or Android Settings (the grocery-ordering feature will then ask you to enter an address manually). Legal basis: your consent (location permission) and performance of your ordering request.

8. Grocery ordering and store sessions

The grocery-ordering feature (currently available to users in Ukraine) lets you add the items on your shopping list to your cart at Сільпо and stores on Zakaz.ua. To do this the App opens an in-app browser where you browse / log in to the store; it then reuses your own session with that store to add items to your cart. The relevant session data stays on your device.

Zastillia is an independent tool and is not affiliated with, endorsed by, or partnered with Сільпо, Zakaz.ua, or any retail chain. We do not receive your store login credentials, we do not process your payment, and we do not place or fulfil the order — you complete checkout and payment directly with the store on the store's site. Product prices and availability shown come from the stores' systems. The store's own terms and privacy policy apply to your relationship with it.

9. Purchases and subscriptions

Premium subscriptions are sold and billed by Apple via the App Store on iOS, and by Google via Google Play on Android. The store processes your payment; we do not receive your payment-card data. RevenueCat, Inc. sits between the two stores and our backend so one subscription is recognised on either platform; it receives your purchase and entitlement records, not your payment details. We receive your entitlement/transaction status (e.g. "subscribed", plan, renewal date, trial eligibility) so the App can unlock Premium features, and a usage/spend record is kept on our backend associated with your install. See the Terms of Use for subscription details. Legal basis: performance of our agreement.

10. Analytics, diagnostics and integrity

Legal basis: our legitimate interest in maintaining, securing and improving the App (and your consent where required by local law for analytics identifiers).

11. Data stored on your device and in your iCloud

The App stores on your device: settings, onboarding state, theme/accent, analytics opt flags, cached recipe images and their file sizes, your manual recipes, your weekly plan, your shopping list, recent delivery addresses, and the grocery-store session described in §8. On iOS, your recipe book is also synced to your own iCloud private database — that is your personal iCloud storage, governed by Apple’s iCloud terms and privacy policy; we cannot read it. On Android there is no such sync: the recipe book lives only on the device. Android’s own Auto Backup is enabled instead, so the app’s database and settings are copied to your personal Google account backup — again your storage, governed by Google’s terms, and encrypted with your device credential; we cannot read it either. Recipe cover photos are excluded from the cloud copy and travel only in a direct device-to-device transfer. Deleting the App removes the on-device data; iCloud data is managed in iOS Settings and Android backups in Google One.

12. Third parties / sub-processors

We use the following service providers, who process data on our behalf or receive data because you chose to use a feature:

Provider Role Policy
Google LLC (Firebase) Anonymous backend identification, backend processing, analytics, crash reporting, attestation, configuration https://firebase.google.com/support/privacy , https://policies.google.com/privacy
Google LLC (Gemini API) Recipe synthesis, pantry scanning, meal-plan generation — the provider that handles most AI requests https://ai.google.dev/gemini-api/terms , https://policies.google.com/privacy
OpenAI, Inc. Speech-to-text, vision text-recognition, recipe synthesis, grocery product matching, voice grocery entry, screening of shared recipes. Uses our traffic to train its models — see §4 https://openai.com/policies/privacy-policy
Anthropic, PBC Recipe synthesis (Claude) https://www.anthropic.com/legal/privacy
Apple, Inc. iOS app distribution, StoreKit purchases, Apple Health, mapping/location, iCloud, App Attest https://www.apple.com/legal/privacy/
Google LLCAndroid app distribution, Google Play Billing, Play Integrity, geocoding, Android Auto Backuphttps://policies.google.com/privacy
RevenueCat, Inc.Reconciles subscriptions across both storeshttps://www.revenuecat.com/privacy
The grocery retailer you choose (e.g. Сільпо, Zakaz.ua chains) Receives your order, address, and payment when you place an order The retailer's own policy

13. International transfers

Our backend providers (Google/Firebase, OpenAI, Anthropic, Apple, RevenueCat) are based in or operate from the United States and other countries. When you use the App, personal data may therefore be transferred outside Ukraine/the EEA. Where required, such transfers rely on appropriate safeguards (e.g. the providers' Data Processing Agreements and Standard Contractual Clauses).

14. How long we keep data

15. Your rights

Depending on where you live, you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing; data portability; and to withdraw consent (e.g. location, Health) at any time. You also have the right to lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights (Ombudsman) or your local supervisory authority.

Because the App uses anonymous access, your data on our backend is identified only by the install identifier created automatically on your device. To exercise your rights, contact support@zastillia.app from the email address you'd like us to reply to and describe which data you want to access or erase; we may ask you to confirm details that match a request that originated from your install (e.g. recent activity) so we can be sure we're acting on the right account.

In-app controls today: you can disconnect Apple Health or Health Connect and revoke the location permission in your device’s Settings; you can delete individual recipes; you can revoke any recipe you have shared publicly (§5); and the App's Profile screen offers a delete-account action that removes your install's link to our backend. Removing the App also clears the on-device data described in §11.

16. Children

The App is not directed to children. You must be at least 16 years old (or the minimum age set by the Terms of Use / required by your local law) to use the App. We do not knowingly collect personal data from children below that age; if you believe a child has provided us data, contact support@zastillia.app and we will delete it.

17. Security

We use TLS for data in transit; per-install authorization to gate our backend; and store our service-provider keys in a secrets manager (never in the app binary). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

18. Changes

We may update this Policy. Material changes will be notified in the App and/or at https://zastillia.app/privacy. The "Last updated" date shows the current version.

19. Contact

Questions or requests: support@zastillia.app — San Byn Nhuien, sole proprietor (ФОП), Ukraine.