Your data
Privacy Policy
Effective August 29, 2026 ยท Last updated August 29, 2026
Who operates Flourtune
Flourtune ("Flourtune", "we", "us", or "our") is operated by Individual Entrepreneur YEVGEN KAPELKO, located in Ukraine at 79/5 Pushkinska Street, Kharkiv 61000, Ukraine. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Flourtune mobile application, website, and related services (the "Service").
Contact us at support@flourtune.com.
Information we process
Account information
When you create an account, we process your email address, name, profile image, authentication provider, Firebase user identifier, account preferences, and login metadata. If you sign in with Google or Apple, those providers send us the account information you authorize them to share. We do not receive your Google or Apple password.
Bakery business data
You may enter or import recipes, ingredients, suppliers and stores, purchases, inventory information, equipment, orders, clients, tasks, prices, costs, payments, notes, images, and related business records. Some records can include personal data about your customers. You are responsible for having a lawful basis to enter and use that customer data in Flourtune.
AI scan data
When you explicitly use recipe or receipt scanning, the selected images and relevant catalog context are sent through our Firebase Cloud Functions to OpenAI for extraction. Images may contain handwritten text, merchant data, prices, dates, or other content visible in the source. Review AI output before saving it because automated extraction can be incorrect.
Flourtune does not intentionally persist source scan images on its backend as part of AI processing. Temporary request results are stored for retry and recovery and are scheduled to expire after approximately 24 hours. Saved recipes, ingredients, and purchases then follow the normal account-data rules. Under OpenAI's default API data controls, abuse-monitoring data may be retained for up to 30 days unless a different approved configuration applies.
Subscription and payment information
Google Play or Apple processes subscription payments. We do not receive or store your full payment-card details. RevenueCat provides us with purchase and entitlement information such as product, subscription status, expiration, store, and an application user identifier so we can unlock paid access and prevent fraud.
Support and feedback
When you contact us or submit in-app feedback, we process the message type, subject, message, account email and identifier, app/build version, platform, operating-system version, timestamps, and support correspondence.
Diagnostics and usage data
We use Firebase Analytics and Firebase Crashlytics to understand feature use, app stability, crashes, and performance. Events use controlled values and are designed not to contain recipe names, customer names, notes, search terms, or other user-entered free text. Diagnostic data can include device and app information, IP-derived information, identifiers, crash traces, and usage events. Firebase Remote Config delivers operational configuration.
Device permissions and local data
Flourtune requests camera or photo-library access only when you choose an image or scan flow. Notifications are used for reminders you configure. The app keeps a local cache and preferences on your device to improve performance and offline use. Device-level copies may remain in system backups until removed under your device or backup provider's rules.
Why we use information
We use information to:
- create and secure accounts;
- sync, calculate, display, export, and back up business data;
- process recipe and receipt scans that you request;
- provide subscriptions, restore purchases, and enforce quotas;
- respond to support requests and prevent abuse;
- diagnose failures and improve the Service; and
- comply with legal obligations and protect users and others.
Where applicable, our legal bases include performing our contract with you, our legitimate interests in operating and securing the Service, your consent for optional device access or processing, and compliance with law. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
Service providers and disclosure
We use the following providers:
- Google Firebase for authentication, database, file storage, Cloud Functions, analytics, crash reporting, App Check, and remote configuration;
- Google Play and Apple for distribution and payments;
- RevenueCat for subscriptions and purchase analytics;
- OpenAI for user-initiated recipe and receipt extraction;
- Resend for delivering support messages to our inbox; and
- infrastructure, security, and professional advisers where reasonably needed.
We may disclose information when required by law, to protect rights and safety, in connection with a merger or transfer of the Service, or at your direction. We do not sell personal information, share personal information with advertising companies, or use personal information for targeted advertising.
Providers may process data in countries other than yours, including the United States. Where required, we rely on provider contractual safeguards and lawful transfer mechanisms.
Retention
We keep account and business data while your account is active and until it is deleted or no longer needed for the Service. Subscription and security records may be retained as necessary for accounting, fraud prevention, dispute resolution, and legal compliance. Support records are retained only as long as reasonably necessary. Provider data follows the applicable provider retention settings and policies.
When you delete your account in the app, Flourtune deletes the account document, known user subcollections, and user files, then deletes the Firebase Authentication account. Backend cleanup also removes private AI, quota, receipt-import, feedback, feedback-rate, and subscription records. Some information may remain temporarily in backups, logs, or records we must retain by law.
Your choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, withdraw consent, and complain to a data-protection authority. Flourtune provides in-app business-data export and account deletion. You may also contact us from your registered email at support@flourtune.com.
You can manage subscription cancellation through Google Play or Apple. Deleting the app or your Flourtune account does not automatically cancel a store subscription.
Age requirement
The Service is intended only for people aged 18 or older and is not directed to children. Contact us if you believe a person under 18 provided personal data.
Security
We use technical and organizational safeguards such as authenticated access, Firebase Security Rules, App Check, encrypted network transport, secret management, rate limits, and restricted private collections. No system is completely secure, and we cannot guarantee absolute security.
Changes
We may update this policy when the Service or law changes. We will update the date above and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.