Vesla

Privacy Policy

Last updated: July 25, 2026

Protecting your data matters to us. This policy explains which personal data Vesla processes and what rights you have.

1. Controller

The controller responsible for data processing in the Vesla app is: Nick Algner, Schlegelstraße 13, 10115 Berlin, email: nick@algner.de.

2. Overview

Vesla is an app that lets you import recipes from the internet (e.g. Instagram Reels, TikTok, YouTube, food blogs, photos) and save them as structured, cookable recipes, including a shopping list and weekly meal plan. We process as little data as possible and never share it for advertising.

3. What data we process

a) Account & sign-in data. To save and sync your recipes you sign in — via Sign in with Apple or an email one-time code. We process: • a unique user identifier (user ID), • your email address (with Sign in with Apple this may be an anonymized Apple relay address, depending on your choice), • your name, if you share it during Apple sign-in (otherwise the part before the @ in your email is used as your display name). b) Profile & app settings. Display name, units (metric/imperial), dietary preferences, household size, and notification preference. c) Your content. The recipes you import or create (title, ingredients, steps, notes, categories, ratings), your shopping list, your meal plan, and any uploaded or imported recipe images. d) Import data. When you start an import, we process the link, text, video or image you share in order to extract a recipe from it (see section 5). e) Technical processing data. For cost control and quality assurance of the import, we log technical metadata of the import process (e.g. source used, duration, cost, model). These logs are used for operation and debugging. f) Usage data (product analytics). To understand which features are used and where the app gets stuck, we record app usage events — such as: app opened, onboarding started/completed, import started, import succeeded or failed (with a technical error code), recipe saved, cook mode started/completed, recipe added to the shopping list, sign-in. Alongside these we record technical attributes such as the import source chosen, how long an import took, and the number of ingredients and steps. These events are linked to your user identifier (see section 5a). Your content is not part of this: no recipe titles, ingredient text, notes, links or text you typed, and no screen recordings. No data is processed for advertising, and we do no cross-app tracking for advertising purposes.

4. Purpose and legal basis

We process this data to provide the app's functions (sign-in, saving, cross-device sync, recipe import). The legal basis is performance of the usage contract (Art. 6(1)(b) GDPR) and our legitimate interest in secure, cost-controlled operation (Art. 6(1)(f) GDPR). The product analytics described in section 3f rely on our legitimate interest in improving and debugging the app (Art. 6(1)(f) GDPR); you may object under Art. 21 GDPR (contact details in section 12).

5. Import processing by service providers (processors)

The recipe import runs through our server-side service. Depending on the source, we forward the import content you provide (link/text/video/image) to the following services so the recipe can be extracted: • Apify — retrieval of publicly shared social-media content (e.g. Instagram), • OpenAI, Google (Gemini) and/or Anthropic — converting the content into a structured recipe (text or video analysis), • Langfuse — technical tracing and cost control of imports. Only the content needed for each import is transmitted. Some of these providers may process data outside the EU (including the USA). Product analytics. For the usage data described in section 3f we use PostHog as a processor. Processing takes place on PostHog's EU infrastructure (data centre in the EU). The events listed there are transmitted together with your user identifier — no recipe content.

6. Storage and hosting

Account, profile and content data are stored with our backend provider Supabase. Access to your data is technically restricted to your account (row-level security): other users cannot see your recipes, list or plans. Note on recipe images: recipe images are stored with publicly accessible links (so they load quickly and offline); therefore do not upload images containing confidential information.

7. Sharing

We do not sell your data and do not share it for advertising. Data is shared only with the service providers named in sections 5 and 6 to provide the app's functions, and where legally required.

8. Retention

We store your data for as long as your account exists. If you delete your account (see section 9), your data is deleted.

9. Your rights, in particular deletion

You can delete your account at any time directly in the app (Profile → "Delete account"). This deletes your user account and the associated data — recipes, ingredients, steps, cookbooks, shopping list, meal plan, profile, and your recipe images. In addition, under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. To exercise these rights, contact nick@algner.de.

10. Children

Vesla is not directed at children under 16.

11. Changes

We may update this privacy policy when the app or the legal situation changes. The current version is always available at this address.

12. Contact

Privacy questions: nick@algner.de.