Privacy Policy
At Expirio we take privacy very seriously. This policy explains what data we collect, how we use it, how we protect it and what your rights are.
1. Who we are
Expirio is a mobile application for tracking food expiry dates, operated by Expirio SL, Madrid, Spain. Privacy contact: privacy@expirio.app. privacy@expirio.app.
2. Data we collect
- Account data: Email, first and last name (if you use Google or Apple Sign-In, we receive what you authorise). We also store the authentication provider used.
- Inventory data: Products you add: name, brand, expiry date, place of purchase and storage location.
- OCR images: When you photograph a product, the image is sent to Google Vision API to extract the expiry date. We retain processing metadata (URL, detected text, detected date, confidence level) for 90 days.
- Device token: To send push notifications via Firebase Cloud Messaging, we store your device token along with the platform (iOS/Android) and last activity date.
- Usage data: We record app usage events (screens visited, actions taken) linked to your user identifier. After 30 days these are irreversibly anonymised by removing all identifiers.
- Subscription data: Your plan status (FREE/PREMIUM), payment provider and billing event history.
- Support messages: The content of tickets and messages you send us.
- Invited email addresses: If you invite someone to a shared household, we temporarily store their email until they accept, decline or the invitation expires (maximum 7 days).
3. Legal bases for processing (GDPR art. 6)
- Performance of contract (art. 6.1.b): Account data, inventory, OCR images, device tokens, notifications, support messages, household invitations.
- Legitimate interest (art. 6.1.f): Usage data (before anonymisation) to improve the product and detect errors.
- Legal obligation (art. 6.1.c): Subscription and billing data, retained for 7 years (Spanish tax obligation).
- Explicit consent (art. 6.1.a): Marketing communications — only if you authorise this from Settings → Privacy.
4. How we use your data
- To provide the expiry tracking service.
- To send push notifications about products nearing expiry.
- To sync your data across devices and shared households.
- To improve OCR and app performance.
- To respond to support requests.
- To manage your subscription and billing.
- With your consent: To send you marketing communications about new features or promotions.
5. Anonymous statistics and data sharing
We generate aggregated and anonymous statistics about product consumption behaviour (for example: which food categories are wasted most, which products are not found in store, expiry trends). This data contains no personal identifiers — no email, name or user ID — and therefore does not constitute personal data under GDPR.
These anonymous statistics may be shared or sold to third parties (researchers, manufacturers, distributors) without your consent, as they are truly anonymous and irreversible.
We never share identifiable personal data with third parties, such as your name, email, personal inventory or support history.
6. Retention periods
- Account and inventory data: While your account is active. Deleted in cascade within 30 days of account deletion.
- OCR images: 90 days in AWS S3. Metadata is deleted when the account is deleted.
- Usage data: 30 days with identifier; then anonymised and the original deleted.
- Device tokens: Up to 90 days of inactivity.
- Support messages: 2 years from ticket closure.
- Billing data: 7 years (tax obligation).
- Invitation emails: Maximum 7 days.
- Anonymous statistics: Indefinitely — they are no longer personal data.
7. Storage and security
- Servers in the European Union.
- Communications encrypted with HTTPS/TLS.
- Data at rest encrypted with AES-256.
- Principle of least privilege for internal access.
8. Service providers (data processors)
We have signed data processing agreements (DPA) in accordance with GDPR art. 28:
- Firebase / Google (USA): Authentication, push notifications. Transfer under Standard Contractual Clauses (SCCs).
- Amazon Web Services / AWS (USA): Image storage. Transfer under SCCs.
- Google Vision API (USA): OCR processing. Transfer under SCCs.
9. Your rights (GDPR)
- Access: Request what data we hold about you.
- Rectification: Correct inaccurate data.
- Erasure: Delete your account from Settings → Delete account.
- Portability: Export your inventory from Settings → Export data.
- Objection: Object to processing based on legitimate interest.
- Withdrawal of marketing consent: At any time from Settings → Privacy, without penalty.
To exercise any right: privacy@expirio.app. Response within 30 days. privacy@expirio.app
You may also lodge a complaint with the relevant data protection authority in your country. www.aepd.es.
10. Minors
Expirio is not intended for users under 16. If you are the parent or guardian of a minor who has created an account, please contact us at privacy@expirio.app. privacy@expirio.app.
11. Changes to this policy
Significant changes will be notified by email and in the app at least 15 days in advance.
12. Contact
privacy@expirio.app — Expirio SL, Madrid, España.