Privacy policy
This privacy policy explains which personal data is processed when you use forc – on forc.app and in the forc app. In short: forc stores your account, your recipes, variants, photos and “cooked it” entries. No tracking, no advertising, no selling of data.
As of 7 October 2026 · Nystart GmbH, Hamburg
1. Controller
The controller responsible for the processing of personal data by forc is: Nystart GmbH Leonore-Mau-Weg 2 22763 Hamburg Germany E-mail: info@nystart.digital Privacy matters: datenschutz@nystart.digital
2. Privacy contact
Please send questions about the processing of your data, requests for rectification or erasure and objections to datenschutz@nystart.digital.
3. Visiting the website and the app, hosting and security logs
When you open forc.app, and with every request the forc app makes to our interface, technically necessary connection data is processed. This includes in particular: • IP address • date and time of access • page, file or interface requested • amount of data transferred • browser type, operating system and device, or app version • referrer URL • technical error and security information This processing is necessary to provide the service, to detect attacks and misuse and to ensure stability and security. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure, reliable and economical operation of forc. forc runs entirely on services of Cloudflare, Inc., USA: delivery, protection and execution of the application (Workers), database (D1), photo storage (R2), the recipes' version history (Artifacts) and sending of sign-in e-mails (Email Service). Cloudflare processes data on our instructions under a data processing agreement. Cloudflare operates a worldwide network; a storage location exclusively within the European Union is not fixed for forc at present (see section 14). Log data is kept only as long as necessary for operation, troubleshooting and IT security.
4. No audience measurement, no advertising
forc uses no analytics or tracking services, builds no usage profiles and shows no advertising. We do not count who opens which pages.
5. Cookies and app storage
forc uses no cookies for advertising or profiling. We only use strictly necessary cookies and storage: • “forc_session”: keeps you signed in (90 days, does not renew by itself) • “forc_kitchen”: a random identifier of your kitchen while you save variants without an account (one year); when you sign in, its contents move into your account and the identifier is deleted • “forc_oauth”: protects a sign-in with Google in progress against tampering (10 minutes) In the forc app the session token is stored in the device's keychain. The legal basis for accessing the device is § 25(2) no. 2 TDDDG, as the storage is necessary for the function you requested. The subsequent processing is based on Art. 6(1)(b) GDPR. You can delete cookies in your browser; you are then signed out, or an anonymous kitchen is no longer reachable.
6. Reading without an account
You can read, search and cook public recipes and variants without signing in and without telling us anything about yourself. Only the connection data described in section 3 arises.
7. Account and sign-in
For your own recipes, photos and “cooked it” entries you need an account. For this we process: • e-mail address • display name • time the account was created and preferred language • sessions (only as a cryptographic hash of the session token, with an expiry time) There is no password. When you sign in by e-mail link, we send you a single-use link (15 minutes); only a hash of the link is stored. The e-mail is sent through the Cloudflare Email Service. The legal basis is Art. 6(1)(b) GDPR (provision of the account you requested).
8. Signing in with Google
Optionally you can sign in with your Google account. forc then requests only the “openid”, “email” and “profile” permissions from Google and receives your name, your e-mail address, the identifier of your Google account and whether the address is verified. We use this data solely to recognise you, to create your forc account the first time, or to link it to an existing account with the same e-mail address. forc does not retrieve any other Google data – no contacts, calendar or files. We do not share, sell or use the data received from Google for advertising. It is additionally subject to the Google API Services User Data Policy, including the Limited Use requirements. The legal basis is Art. 6(1)(b) GDPR. You can revoke the link at any time in your Google account under “Security → Third-party apps”; your forc account then remains reachable via the e-mail link, or you delete it under “Account”. Information on privacy at Google is available at policies.google.com/privacy.
9. Recipes, variants, photos and “cooked it”
What you create on forc is stored with your account: • recipes and variants with every saved version (recipe text and forc.json) and the record of what a variant was made from • photos you upload for recipes, steps or “cooked it” entries; the app or browser scales them down before uploading and strips camera data such as the location • “cooked it” entries (photo and/or comment, version cooked, time) • visibility (private or public) per recipe and variant Private recipes are seen only by the person they belong to. Public recipes, variants and “cooked it” entries are visible to everyone, together with your display name; your e-mail address and your Google identifier are never shown. Photos are served under a random, unguessable address; whoever knows the address can see the photo. If someone makes a variant of your public recipe, your display name stays on that variant as the origin. If the author of a recipe adopts a change from your variant, your name is mentioned in the version history of their recipe. The legal basis is Art. 6(1)(b) GDPR.
10. Substitution helper
Suggestions for replacing an ingredient currently come from alternatives stored with the recipe. No third-party service and no language model is used for this. Should that change, we will update this policy beforehand and name the provider, the data transmitted and the legal basis.
11. Support and other communication
If you contact us by e-mail, we process your contact details, the content of your message and the accompanying information needed to handle it. The legal basis is Art. 6(1)(b) GDPR where your request concerns your account, otherwise Art. 6(1)(f) GDPR (answering requests and operating the service). Communication data is deleted once the matter is closed and no statutory retention obligations apply.
12. Data export and account deletion
Under “Account” you can download all data of your account as a file at any time (account, every version of every recipe and variant, list of your photos and “cooked it” entries) and delete your account. On deletion, account, sessions, sign-in links, your recipes and variants with all versions, your “cooked it” entries and the entries others left at your recipes are removed from the database immediately. The associated version history in Artifacts and your photos are then deleted automatically, usually within a day. Photos still shown in another person's variant remain until that variant no longer refers to them. Variants others made of your recipes stay with them; your display name remains there as the origin and in version histories as the source of an adopted change.
13. Recipients and processors
Personal data is received only by parties that need it for the purposes described: • Cloudflare, Inc. as hosting, database, storage and e-mail provider (processor under Art. 28 GDPR) • Google Ireland Limited or Google LLC, if you sign in with Google (independent controller for the sign-in at Google) • authorities and courts where legally required Data is not passed on for advertising purposes or sold.
14. Transfers to third countries
Cloudflare is based in the USA and may process data outside the European Economic Area; a storage location restricted to the EU is not fixed for forc at present. Google may also process data in the USA. A transfer takes place only if the requirements of Art. 44 et seq. GDPR are met. We rely in particular on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, as well as on the European Commission's standard contractual clauses and additional technical and organisational safeguards. Information is available at cloudflare.com/privacypolicy and policies.google.com/privacy.
15. Retention
We keep personal data only as long as necessary for the respective purpose or as required by statutory retention obligations: • account data, recipes, variants, photos and “cooked it” entries: until you delete them (section 12) • sessions: 90 days or until you sign out • sign-in links: 15 minutes; the hash of a used link is deleted with the account • uploaded photos not used in any saved recipe or entry: 24 hours • connection and log data: as long as necessary for operation and security Data may linger for a limited time in the hosting provider's backups.
16. Legal bases at a glance
• Art. 6(1)(b) GDPR: provision of the account and the functions you request • Art. 6(1)(c) GDPR: compliance with legal obligations • Art. 6(1)(f) GDPR: operation, security and troubleshooting after balancing of interests We currently do not ask for consent for any processing.
17. Your rights
Where the legal requirements are met, you have the right to: • access to your personal data under Art. 15 GDPR • rectification of inaccurate data under Art. 16 GDPR • erasure under Art. 17 GDPR • restriction of processing under Art. 18 GDPR • data portability under Art. 20 GDPR • object to processing under Art. 21 GDPR You can exercise access, data portability and erasure directly under “Account” (forc.app/en/account). For everything else write to datenschutz@nystart.digital.
18. Special note on the right to object
Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.
19. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority generally responsible for Nystart GmbH is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit Ludwig-Erhard-Straße 22 20459 Hamburg, Germany Phone: +49 40 42854-4040 E-mail: mailbox@datenschutz.hamburg.de Website: datenschutz-hamburg.de You may also contact another supervisory authority competent under Art. 77 GDPR.
20. Data security
We take technical and organisational measures to protect personal data against loss, alteration, unauthorised disclosure and unauthorised access. These include encrypted transmission, session and sign-in tokens stored only as hashes, single-use sign-in links, access restrictions and regular review of our safeguards.
21. Changes to this privacy policy
We adapt this privacy policy when functions, service providers or legal requirements change. The current version date is stated above. We will make material changes known on forc in an appropriate way.