Privacybeleid

Laatst bijgewerkt: 5 september 2026

Salux hecht veel waarde aan jouw privacy. In dit privacybeleid leggen we uit welke gegevens we verzamelen, waarom, en hoe we deze beschermen. We verkopen jouw gegevens nooit aan derden.

1. Wie zijn wij?

Salux is een mobiele applicatie voor het plannen van boodschappen en recepten, ontwikkeld door Rope IT Solutions voor gebruik in Nederland. Voor vragen over dit privacybeleid kun je contact opnemen via de contactgegevens onderaan dit document.

2. Welke gegevens verzamelen we?

2.1 Accountgegevens

Bij het aanmaken van een account verzamelen we:

  • E-mailadres (voor aanmelding en communicatie)
  • Wachtwoord (opgeslagen als versleutelde hash, nooit in leesbare tekst)
  • Abonnementsstatus (gratis of premium)

2.2 App-gebruiksgegevens

Om de app goed te laten werken slaan we op:

  • Recepten die je aanmaakt, inclusief ingrediënten en instructies
  • Boodschappenlijsten en winkelvoorkeuren per product
  • "Altijd thuis"-instellingen en winkelvoorkeuren per ingrediënt
  • Favoriete producten en recepten
  • Weekplanning en terugkerende producten (hoe vaak je iets koopt)

2.3 Analytische gegevens

We verzamelen geanonimiseerde gebruiksstatistieken om de app te verbeteren, zoals:

  • Welke functies je gebruikt (bijv. receptimport, boodschappenlijst aanmaken)
  • App-versie en platform (Android of iOS)
  • Sessie-informatie (start- en eindtijd van een sessie)

Deze gegevens zijn gekoppeld aan jouw account maar worden niet gedeeld met derden en worden alleen intern gebruikt voor productontwikkeling.

2.4 Afbeeldingen (camera en fotobibliotheek)

Salux vraagt toegang tot je camera en fotobibliotheek uitsluitend voor de functie "recept importeren via foto". Wanneer je een foto maakt of selecteert:

  • Wordt de afbeelding tijdelijk naar onze server gestuurd voor tekstherkenning (OCR) en receptanalyse via een AI-dienst.
  • De afbeelding wordt niet permanent opgeslagen op onze servers na verwerking.
  • De afbeelding wordt nooit gedeeld met andere gebruikers of derde partijen, anders dan de AI-dienst die de analyse uitvoert.

Je kunt de app volledig gebruiken zonder ooit toestemming te geven voor camera- of fototoegang. Deze toestemming is optioneel en alleen nodig als je de importfunctie wilt gebruiken.

2.5 Bijzondere persoonsgegevens: je voedingsprofiel

In de app kun je een voedingsprofiel instellen: hoe vaak je vlees, gevogelte, vis, gluten, zuivel, kaas, eieren, biologische en ultrabewerkte producten wilt eten (schuifregelaars van 0 tot 5), en voedingsdoelen zoals een aantal plantaardige producten per week of een dagelijks doel voor calorieën en macronutriënten.

Deze gegevens kunnen iets zeggen over een overtuiging of over je gezondheid — vlees, zuivel en eieren op 0 leest als veganisme, gluten op 0 als coeliakie, een caloriedoel als gezondheidsinformatie. Daarom behandelen we het hele voedingsprofiel als bijzondere persoonsgegevens in de zin van artikel 9 AVG, ook als jouw instellingen dat zelf niet zijn.

  • We slaan het voedingsprofiel alleen op met jouw uitdrukkelijke toestemming, die we in de app apart vragen vóór je de instellingen ziet — los van het aanmaken van je account. We leggen vast wanneer je toestemming gaf en op welke versie van deze tekst.
  • We gebruiken het voor één doel: recepten, productsuggesties en de assistent afstemmen op hoe jij wilt eten. Daarvoor sturen we het, samen met je verzoek, mee naar de AI-dienst uit 2.6.
  • Je kunt de toestemming op elk moment intrekken via Instellingen → Voedingsvoorkeuren → Toestemming intrekken. Je voedingsprofiel wordt dan direct teruggezet naar neutraal en niet meer gebruikt; het moment van intrekken bewaren we.
  • Zonder toestemming werkt de rest van de app volledig; alleen de voorkeuren en doelen zijn dan niet beschikbaar.

2.6 Wat er naar de AI-dienst gaat

Een aantal functies gebruikt een taalmodel bij een externe AI-dienst: recepten importeren (uit een link, tekst of foto), recepten genereren, producten van je lijst matchen met het assortiment van een supermarkt, en de assistent. Daarvoor sturen we alleen wat die ene functie nodig heeft: de recepttekst of foto die je importeert, je beschrijving bij het genereren, de productnamen op je lijst bij het matchen, je bericht aan de assistent en — alleen met je toestemming uit 2.5 — je voedingsprofiel. Je e-mailadres en wachtwoord gaan er nooit heen.

We bewaren de inhoud van deze verzoeken en antwoorden niet. We houden per aanroep alleen de vorm bij (welke functie, hoeveel tekst, hoe lang het duurde, wat het kostte) om de kosten te bewaken.

3. Waarom verwerken we deze gegevens?

  • Accountbeheer: Om je te kunnen laten inloggen en je gegevens te bewaren (grondslag: uitvoering van de overeenkomst)
  • App-functionaliteit: Om recepten, boodschappenlijsten en voorkeuren op te slaan (grondslag: uitvoering van de overeenkomst)
  • AI-functies (importeren, genereren, matchen, assistent): Om de tekst of foto die je aanlevert om te zetten in een recept, lijst of antwoord (grondslag: uitvoering van de overeenkomst; voor een foto: toestemming)
  • Voedingsprofiel: Om recepten, suggesties en de assistent af te stemmen op hoe jij wilt eten (grondslag: jouw uitdrukkelijke toestemming, artikel 9 lid 2 onder a AVG, in te trekken in de app)
  • Productontwikkeling: Om de app te verbeteren op basis van geanonimiseerd gebruik (grondslag: gerechtvaardigd belang)

4. Hoe lang bewaren we jouw gegevens?

  • Accountgegevens en app-inhoud: Zolang je account actief is.
  • Voedingsprofiel: Zolang je toestemming geldt. Trek je die in, dan wordt het profiel direct teruggezet naar neutraal.
  • Afbeeldingen voor receptimport: Worden na verwerking direct verwijderd en niet bewaard.
  • Verzoeken aan de AI-dienst: De inhoud wordt niet bewaard; alleen de vorm van de aanroep (zie 2.6), maximaal 2 jaar.
  • Analytische gegevens: Maximaal 2 jaar, daarna geanonimiseerd of verwijderd.

Wanneer je je account verwijdert, worden al je persoonlijke gegevens binnen 30 dagen gewist.

5. Delen we jouw gegevens?

We verkopen of verhuren jouw gegevens nooit. We kunnen gegevens delen met:

  • AI-dienstverlener: Alleen wat in 2.6 staat, tijdelijk en alleen om ons antwoord te leveren. De dienstverlener treedt op als verwerker en is contractueel verplicht de gegevens niet voor eigen doeleinden te gebruiken.
  • Hostingprovider: De server waarop de app draait verwerkt alle gegevens. Deze provider is gebonden aan verwerkersovereenkomsten.

Alle verwerking vindt plaats binnen de Europese Economische Ruimte (EER), of met dienstverleners die voldoen aan de AVG (GDPR).

6. Beveiliging

  • Wachtwoorden worden opgeslagen als bcrypt-hash (nooit leesbaar).
  • Communicatie tussen app en server verloopt via HTTPS (TLS-versleuteling).
  • Toegang tot de database is beperkt tot geautoriseerde systemen.
  • JWT-tokens worden veilig opgeslagen op je apparaat.

7. Jouw rechten (AVG)

Op grond van de Algemene Verordening Gegevensbescherming (AVG) heb je de volgende rechten:

  • Inzage: Je kunt opvragen welke gegevens we van je hebben.
  • Rectificatie: Je kunt onjuiste gegevens laten corrigeren.
  • Verwijdering: Je kunt verzoeken om je account en alle bijbehorende gegevens te verwijderen.
  • Beperking: Je kunt vragen de verwerking te beperken in bepaalde omstandigheden.
  • Bezwaar: Je kunt bezwaar maken tegen verwerking op basis van gerechtvaardigd belang.
  • Gegevensoverdraagbaarheid: Je kunt een export van je gegevens opvragen.
  • Toestemming intrekken: De toestemming voor je voedingsprofiel trek je in via Instellingen → Voedingsvoorkeuren → Toestemming intrekken; je profiel wordt dan direct gewist. Toestemmingen zoals cameratoegang trek je in via de instellingen van je telefoon.

Om een verzoek in te dienen, kun je contact met ons opnemen via het contactadres onderaan dit beleid. We reageren binnen 30 dagen.

Je hebt ook het recht om een klacht in te dienen bij de Autoriteit Persoonsgegevens: www.autoriteitpersoonsgegevens.nl

8. Cookies en lokale opslag

De Salux-app maakt geen gebruik van tracking cookies. De app slaat je inlogtoken (JWT) en taalvoorkeur lokaal op je apparaat op via SharedPreferences. Dit is puur functioneel en vereist geen toestemming.

Deze website (salux.app) gebruikt geen tracking cookies of analytics van derden.

9. Kinderen

Salux is niet gericht op kinderen onder de 16 jaar. We verzamelen niet bewust persoonsgegevens van kinderen. Als je denkt dat we per ongeluk gegevens van een minderjarige hebben opgeslagen, neem dan contact met ons op.

10. Wijzigingen in dit beleid

We kunnen dit privacybeleid van tijd tot tijd bijwerken. Bij ingrijpende wijzigingen informeren we je via een melding in de app of per e-mail. De datum bovenaan dit document geeft aan wanneer het beleid voor het laatst is bijgewerkt.

11. Contact

Heb je vragen of verzoeken over dit privacybeleid? Neem dan contact met ons op:

Privacy Policy

Last updated: September 5, 2026

Salux takes your privacy seriously. This privacy policy explains what data we collect, why, and how we protect it. We never sell your data to third parties.

1. Who are we?

Salux is a mobile application for grocery planning and recipe management, developed by Rope IT Solutions for use in the Netherlands. For questions about this privacy policy, please contact us using the details at the bottom of this document.

2. What data do we collect?

2.1 Account data

When you create an account, we collect:

  • Email address (for login and communication)
  • Password (stored as a bcrypt hash — never in plain text)
  • Subscription status (free or premium)

2.2 App usage data

To provide app functionality, we store:

  • Recipes you create, including ingredients and instructions
  • Shopping lists and per-product store preferences
  • "Usually at home" settings and store preferences per ingredient
  • Favourite products and recipes
  • Meal plans and recurring products (how often you buy something)

2.3 Analytics data

We collect anonymised usage statistics to improve the app, such as:

  • Which features you use (e.g. recipe import, shopping list creation)
  • App version and platform (Android or iOS)
  • Session information (start and end time)

This data is linked to your account but is not shared with third parties and is used solely for internal product development.

2.4 Images (camera and photo library)

Salux requests access to your camera and photo library exclusively for the "import recipe from photo" feature. When you take or select a photo:

  • The image is temporarily sent to our server for text recognition (OCR) and recipe analysis via an AI service.
  • The image is not permanently stored on our servers after processing.
  • The image is never shared with other users or third parties other than the AI service performing the analysis.

You can use the app fully without ever granting camera or photo access. This permission is optional and only needed if you want to use the import feature.

2.5 Special-category data: your dietary profile

In the app you can set up a dietary profile: how often you want to eat meat, poultry, fish, gluten, dairy, cheese, eggs, organic and ultra-processed products (sliders from 0 to 5), and nutrition goals such as a number of plant foods per week or a daily target for calories and macronutrients.

This data can reveal a conviction or something about your health — meat, dairy and eggs at 0 reads as veganism, gluten at 0 as coeliac disease, a calorie target as health information. We therefore treat the whole dietary profile as special-category data under Article 9 GDPR, even where your own settings are not.

  • We store the dietary profile only with your explicit consent, which the app asks for separately before showing the settings — apart from creating your account. We record when you consented and to which version of this text.
  • We use it for one purpose: tailoring recipes, product suggestions and the assistant to how you want to eat. For that we send it, together with your request, to the AI service described in 2.6.
  • You can withdraw consent at any time via Settings → Dietary Preferences → Withdraw consent. Your dietary profile is then immediately reset to neutral and no longer used; we keep the moment of withdrawal.
  • Without consent the rest of the app works fully; only the preferences and goals are unavailable.

2.6 What is sent to the AI service

Several features use a language model at an external AI service: importing recipes (from a link, text or photo), generating recipes, matching the products on your list to a supermarket's range, and the assistant. For these we send only what that one feature needs: the recipe text or photo you import, your description when generating, the product names on your list when matching, your message to the assistant and — only with your consent under 2.5 — your dietary profile. Your email address and password are never sent.

We do not retain the content of these requests and responses. Per call we keep only its shape (which feature, how much text, how long it took, what it cost) to monitor costs.

3. Why do we process this data?

  • Account management: To allow you to log in and save your data (legal basis: performance of a contract)
  • App functionality: To store recipes, shopping lists and preferences (legal basis: performance of a contract)
  • AI features (import, generate, match, assistant): To turn the text or photo you provide into a recipe, list or answer (legal basis: performance of a contract; for a photo: consent)
  • Dietary profile: To tailor recipes, suggestions and the assistant to how you want to eat (legal basis: your explicit consent, Article 9(2)(a) GDPR, withdrawable in the app)
  • Product development: To improve the app based on anonymised usage (legal basis: legitimate interest)

4. How long do we retain your data?

  • Account data and app content: For as long as your account is active.
  • Dietary profile: For as long as your consent stands. If you withdraw it, the profile is reset to neutral immediately.
  • Images for recipe import: Deleted immediately after processing; not retained.
  • Requests to the AI service: Content is not retained; only the shape of the call (see 2.6), for up to 2 years.
  • Analytics data: Up to 2 years, then anonymised or deleted.

When you delete your account, all your personal data is erased within 30 days.

5. Do we share your data?

We never sell or rent your data. We may share data with:

  • AI service provider: Only what is listed in 2.6, temporarily and only to deliver our response. The provider acts as a processor and is contractually prohibited from using the data for its own purposes.
  • Hosting provider: The server running the app processes all data. This provider is bound by data processing agreements.

All processing takes place within the European Economic Area (EEA), or with providers that comply with GDPR.

6. Security

  • Passwords are stored as bcrypt hashes (never readable).
  • Communication between the app and server uses HTTPS (TLS encryption).
  • Database access is restricted to authorised systems.
  • JWT tokens are stored securely on your device.

7. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR) you have the following rights:

  • Access: You can request to see the data we hold about you.
  • Rectification: You can have inaccurate data corrected.
  • Erasure: You can request deletion of your account and all associated data.
  • Restriction: You can ask us to restrict processing in certain circumstances.
  • Objection: You can object to processing based on legitimate interest.
  • Data portability: You can request an export of your data.
  • Withdraw consent: Consent for your dietary profile is withdrawn via Settings → Dietary Preferences → Withdraw consent; your profile is then erased immediately. Permissions such as camera access can be revoked through your phone's settings.

To make a request, contact us at the address below. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands: www.autoriteitpersoonsgegevens.nl

8. Cookies and local storage

The Salux app does not use tracking cookies. The app stores your login token (JWT) and language preference locally on your device via SharedPreferences. This is purely functional and requires no consent.

This website (salux.app) does not use tracking cookies or third-party analytics.

9. Children

Salux is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently stored data from a minor, please contact us.

10. Changes to this policy

We may update this privacy policy from time to time. For significant changes, we will notify you via an in-app message or email. The date at the top of this document reflects when it was last updated.

11. Contact

Questions or requests about this privacy policy? Please contact us: