Crema

Datenschutzerklärung

1. Allgemeines

Diese Datenschutzerklärung erklärt, wie in der App und auf der Website "Crema" personenbezogene Daten erhoben, verwendet und verarbeitet werden. Der Schutz deiner Daten ist mir wichtig; die Verarbeitung erfolgt im Einklang mit der Datenschutz-Grundverordnung (DSGVO) und dem Bundesdatenschutzgesetz (BDSG).

2. Verantwortlicher

Magnus Hornstein
Autenriethstraße 12
72072 Tübingen, Deutschland
E-Mail: hello@crema-app.com

3. Welche Daten verarbeitet werden

Bei der Nutzung von Crema werden folgende Daten verarbeitet:

  • Konto- und Zugangsdaten: E-Mail-Adresse und Passwort (als Hash gespeichert) bei Registrierung und Anmeldung.
  • Profildaten: Name, Nutzername, Bio, Stadt, bevorzugte Milch/Maschine und optional ein Profilfoto.
  • Inhalte, die du erstellst: Beiträge, Fotos, Rezepte, Kaffee-Logs, Kommentare, Likes, Follows, Challenge-Teilnahmen sowie Bewertungen von Cafés.
  • Nutzungs- und Gerätedaten: technische Informationen (z. B. Browsertyp), soweit für Betrieb und Fehlerbehebung der App notwendig.
  • Push-Benachrichtigungen: falls du Benachrichtigungen aktivierst, wird ein Push-Abonnement (Endpunkt-URL) gespeichert, über das dein Browser bzw. Betriebssystem (z. B. Google, Apple oder Mozilla, je nach verwendetem Browser) Benachrichtigungen zustellt.
  • Moderationsdaten: Meldungen, die du absendest, sowie Entscheidungen über gemeldete Inhalte — einschließlich der Begründung, die der betroffenen Person mitgeteilt wird, und einer Kopie des entfernten Inhalts. Diese Aufzeichnungen sind zur Erfüllung der Pflichten aus Art. 16 und 17 des Digital Services Act erforderlich.
  • Wochenkarte: wenn du deine „Woche in Kaffee“ teilst oder speicherst, wird ein Eintrag mit Zeitpunkt und der betreffenden Woche gespeichert — nicht der Inhalt der Karte.

Crema zeigt keine Werbung und setzt keine Analyse- oder Tracking-Dienste Dritter ein.

4. Zweck und Rechtsgrundlage der Verarbeitung

  • Bereitstellung der App-Funktionen (Konto, Feed, Beiträge, soziale Funktionen): Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung).
  • Sicherheit, Fehlerbehebung und Missbrauchsprävention: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse).
  • Zustellung von Push-Benachrichtigungen, sofern aktiviert: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung).
  • Bearbeitung von Meldungen und Dokumentation der getroffenen Entscheidungen: Art. 6 Abs. 1 lit. c DSGVO (rechtliche Verpflichtung, Art. 16 und 17 Digital Services Act).

5. Eingesetzte Dienstleister (Auftragsverarbeitung)

Ich nutze folgende externe Dienstleister, die Daten in meinem Auftrag verarbeiten. Mit allen Anbietern bestehen, soweit erforderlich, Auftragsverarbeitungsverträge.

  • Supabase (Supabase Inc.) — Datenbank, Authentifizierung und Backend-Infrastruktur. Speichert Konto-, Profil- und Inhaltsdaten. Das genutzte Supabase-Projekt ist auf eine EU-Region eingestellt; die Datenverarbeitung findet auf Servern innerhalb der EU statt.
  • Cloudflare (Cloudflare, Inc.) — Speicherung und Auslieferung von hochgeladenen Fotos (Cloudflare R2 und Bild-CDN unter media.crema-app.com). Cloudflare betreibt ein globales Netzwerk; bei Datenübermittlung in Drittländer (insbesondere USA) stützt sich dies auf EU-Standardvertragsklauseln.

6. Speicherdauer

Deine Daten werden gespeichert, solange dein Konto besteht.

Du kannst dein Konto jederzeit selbst löschen: Einstellungen → Deine Daten → Konto löschen. Damit werden dein Profil, deine Kaffees, Fotos, Kommentare, Likes, Follows, Benachrichtigungen und Einstellungen sofort und endgültig gelöscht — die Fotos auch aus dem Bildspeicher, nicht nur der Datenbankeintrag. Kommentare, die andere unter deinen Kaffees hinterlassen haben, werden mit diesen gelöscht.

Unter Einstellungen → Deine Daten kannst du außerdem jederzeit eine vollständige Kopie deiner Daten als Datei herunterladen.

Was nach einer Löschung bleibt: Fehlerberichte aus der App werden nach 30 Tagen automatisch gelöscht und verlieren bei der Kontolöschung sofort den Bezug zu dir. Moderationsentscheidungen bewahren wir ohne deinen Namen auf, weil wir nachweisen können müssen, warum ein Inhalt entfernt wurde (Art. 17 Abs. 3 DSGVO). In Sicherungskopien der Datenbank können deine Daten noch bis zu 7 Tage enthalten sein. Gesetzliche Aufbewahrungspflichten bleiben unberührt.

7. Deine Rechte

  • Auskunft (Art. 15 DSGVO) — jederzeit als Datei herunterladbar unter Einstellungen → Deine Daten
  • Berichtigung (Art. 16 DSGVO)
  • Löschung (Art. 17 DSGVO) — jederzeit selbst möglich unter Einstellungen → Deine Daten
  • Einschränkung der Verarbeitung (Art. 18 DSGVO)
  • Datenübertragbarkeit (Art. 20 DSGVO)
  • Widerspruch gegen Verarbeitung auf Grundlage berechtigter Interessen (Art. 21 DSGVO)
  • Widerruf einer erteilten Einwilligung (Art. 7 Abs. 3 DSGVO)
  • Beschwerde bei einer Aufsichtsbehörde (Art. 77 DSGVO)

Für alle anderen Rechte aus dieser Liste: hello@crema-app.com

8. Datensicherheit

Die Übertragung erfolgt verschlüsselt (TLS/SSL). Zugriff auf deine Daten ist über Zugriffskontrollen (Row Level Security) der Datenbank auf dein eigenes Konto beschränkt.

9. Kontakt

Bei Fragen zum Datenschutz: hello@crema-app.com

Siehe auch das Impressum.

Privacy Policy

1. General information

This privacy policy explains how personal data is collected, used, and processed in the Crema app and website. I take the protection of your data seriously and process it in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).

2. Data controller

Magnus Hornstein
Autenriethstraße 12
72072 Tübingen, Germany
Email: hello@crema-app.com

3. What data is processed

Using Crema involves processing the following data:

  • Account and login data: email address and password (stored as a hash) when you register and sign in.
  • Profile data: name, username, bio, city, preferred milk/machine, and an optional profile photo.
  • Content you create: posts, photos, recipes, coffee logs, comments, likes, follows, challenge entries, and café reviews.
  • Usage and device data: technical information (e.g. browser type) needed to run and troubleshoot the app.
  • Push notifications: if you enable notifications, a push subscription (endpoint URL) is stored so that your browser or OS push service (e.g. Google, Apple, or Mozilla, depending on your browser) can deliver notifications.
  • Moderation records: reports you file, and decisions about reported content — including the statement of reasons sent to the person affected, and a copy of any content that was removed. These records are required to meet the obligations in Articles 16 and 17 of the Digital Services Act.
  • Week card: when you share or save your “week in coffee”, one entry is stored with the time and which week it was — not the contents of the card.

Crema shows no advertising and does not use third-party analytics or tracking services.

4. Purpose and legal basis

  • Providing app functionality (account, feed, posts, social features): Art. 6(1)(b) GDPR (performance of a contract).
  • Security, troubleshooting, and abuse prevention: Art. 6(1)(f) GDPR (legitimate interest).
  • Delivering push notifications, where enabled: Art. 6(1)(a) GDPR (consent).
  • Handling reports and documenting the decisions taken: Art. 6(1)(c) GDPR (legal obligation, Articles 16 and 17 of the Digital Services Act).

5. Service providers (data processors)

I use the following external providers, which process data on my behalf. Where required, data processing agreements are in place.

  • Supabase (Supabase Inc.) — database, authentication, and backend infrastructure. Stores account, profile, and content data. The Supabase project used is configured for an EU region; processing takes place on servers located within the EU.
  • Cloudflare (Cloudflare, Inc.) — storage and delivery of uploaded photos (Cloudflare R2 and the image CDN at media.crema-app.com). Cloudflare operates a global network; transfers to third countries (in particular the USA) rely on the EU Standard Contractual Clauses.

6. Data retention

Your data is stored for as long as your account exists.

You can delete your account yourself at any time: Settings → Your data → Delete your account. That deletes your profile, pours, photos, comments, likes, follows, notifications and settings immediately and permanently — photos are removed from image storage too, not just the database record. Comments other people left on your pours are deleted with them.

Settings → Your data also lets you download a complete copy of your data as a file at any time.

What remains after a deletion: error reports from the app are deleted automatically after 30 days, and lose their link to you the moment your account goes. Moderation decisions are kept without your name, because we have to be able to show why something was removed (GDPR Art. 17(3)). Your data may still be present in database backups for up to 7 days. Statutory retention obligations remain unaffected.

7. Your rights

  • Right of access (Art. 15 GDPR) — downloadable as a file at any time under Settings → Your data
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR) — available to you directly under Settings → Your data
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interests (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

For any of the other rights on this list: hello@crema-app.com

8. Data security

Data in transit is encrypted (TLS/SSL). Access to your data is restricted to your own account via the database's row-level access controls.

9. Contact

For privacy questions: hello@crema-app.com

See also the Imprint.

← Back to Crema