Privacy Policy
1. Introduction
Loafly Day is operated by Arne Tempelhof. This privacy policy explains what personal data we collect, how we use it, and your rights regarding your data. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR).
If you have any questions about this policy, you can contact us at info@loaflyday.com.
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, name, username, password (stored securely using bcrypt hashing), bio, and profile image.
- User content: recipes, bake logs and comments, ratings, bookmarks, and uploaded images (up to 3 per recipe or comment).
- Usage data: pages visited, interactions with the site, and device/browser information collected through Google Analytics.
- Mobile app usage data: in the Loafly Day app for iOS and Android, which screens you open and which features you use, together with device model, operating system version and app version. This is only collected if you agree to it when asked, and you can turn it off at any time under Profile → Privacy.
- Crash diagnostics (mobile app only): if the app stops unexpectedly, a diagnostic report containing the error, a stack trace, and the device and app version. Also optional, with its own separate switch under Profile → Privacy.
3. How We Use Your Data
- Service operation: to create and manage your account, display your recipes and profile, and enable community features like comments and ratings.
- Analytics: to understand how visitors use the site and the app, and to improve the user experience.
- Stability: to find and fix crashes in the mobile app.
Analytics and crash diagnostics are processed on the basis of your consent (Art. 6(1)(a) GDPR). Everything else on this list is necessary to provide the service you asked for (Art. 6(1)(b) GDPR). Withdrawing your consent does not affect your ability to use Loafly Day: nothing in the app or on the site is gated on it.
4. Third-Party Services
We use the following third-party services that may process your data:
- Google Analytics (GA4): collects anonymized usage data such as pages visited, session duration, and device information. Google may process this data on servers outside the EU. Google Privacy Policy.
- Google Firebase (mobile app): the app uses Firebase Authentication to sign you in, and — only with your consent — Firebase Analytics and Firebase Crashlytics for the usage data and crash reports described above. For analytics and crash reports, Firebase stores a randomly generated app instance identifier on your device; it is not your name, your email, or an advertising identifier. If you withdraw your consent, that identifier is deleted and collection stops. The app contains no advertising and no advertising identifier (on iOS it therefore shows no “Allow tracking” prompt), and we share nothing with advertising networks or data brokers. Google may process this data on servers outside the EU. Firebase Privacy and Security.
- Apple App Store and Google Play: if you take out a subscription in the app, the purchase itself is handled by the store, which tells us only that a valid subscription exists. We never receive your payment details.
- Cloudinary: hosts images you upload (profile pictures, recipe images, comment images). Uploaded images are stored on Cloudinary's servers. Cloudinary Privacy Policy.
- Sign in with Apple: if you choose this sign-in option, Apple confirms your identity to us and shares your name and email address. You can ask Apple to hide your real address, in which case we only ever see a private relay address. Apple Privacy Policy.
5. Cookies & Local Storage
This site uses the following storage mechanisms:
- Google Analytics cookies: used to distinguish users and track sessions.
- Local storage (JWT tokens): your authentication tokens (access and refresh tokens) are stored in your browser's local storage to keep you signed in.
- On-device storage in the mobile app: your sign-in session, your settings, your privacy choices, and any running bake timers are stored on your device. The Firebase app instance identifier is stored there too, but only once you have consented to analytics or crash reports.
You can manage cookies through your browser settings. Disabling cookies may affect the functionality of the site.
In the mobile app, analytics and crash reporting are switched off until you agree to them. You are asked once, after the introduction, and you can change either answer at any time under Profile → Privacy.
6. Data Retention
We retain your personal data for as long as your account is active. If you delete your account or request data deletion, we will remove your personal data within 30 days, except where we are legally required to retain it. Uploaded images will be removed from Cloudinary upon account deletion.
7. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to the processing of your personal data for certain purposes, including direct marketing.
- Right to restrict processing: request that we limit how we use your data.
- Right to withdraw consent: where we rely on your consent, you can withdraw it at any time. For analytics and crash reports in the mobile app you can do this yourself under Profile → Privacy; on the website, through the cookie settings.
- Right to lodge a complaint: you can complain to your national data protection authority. In Luxembourg this is the Commission nationale pour la protection des données (CNPD).
To exercise any of these rights, please contact us at info@loaflyday.com.
8. Contact
If you have any questions or concerns about this privacy policy or how we handle your data, please contact us:
Arne Tempelhof
Last updated: August 2026