Legal
Privacy Policy
Last updated: 13 August 2026
This Privacy Policy explains how J.A.N.F. DESENVOLVIMENTO DE SOFTWARE LTDA, doing business as Glash Studios (“Glash,” “we,” “us”), collects, uses, and shares information when you use Klaus (the app, the website, and related services).
Klaus helps you cook with what you already have. You can send a photo, audio, or text of your fridge or pantry. We detect ingredients and suggest recipes.
If you do not agree with this policy, do not use Klaus.
1. Who is responsible
The controller of your personal data is:
J.A.N.F. DESENVOLVIMENTO DE SOFTWARE LTDA (Glash Studios)CNPJ 42.902.901/0001-19
Rua Minas Gerais, 1505, 1st floor, Jardim Atlântico, Alcobaça, Bahia, 45.910-000, Brazil
Privacy contact: support@glashstudios.com
2. Information we collect
You give us
- Account data, through Firebase Authentication (email/password or Google): email (required), display name, Google/Firebase profile photo URL (this is not a photo of your fridge), and a Firebase user id.
- Onboarding answers you choose to give: cooking level, dietary restrictions, how often you cook, who you cook for, gear, waste habits, and goal.
- Kitchen inputs: one photo, one audio clip, or text, sent for a scan. You may also use on-device speech-to-text (your operating system processes that audio on the device).
- Pantry items and movements you save in the app.
We do not currently take payments in the app. There is no in-app purchase.
We collect automatically
- A device id (`klaus_device_id`) for trial use before you log in, and after login we link it to your account id.
- Locale, region, and unit settings on a scan.
- Scan metadata: input type (photo, audio, or text), model/provider used, timestamps, and whether the scan is tied to a user or a trial device.
- Detected ingredients (name, quantity, notes, position in the photo).
- Crash and error data via Sentry (see below).
- Product events via PostHog: `install` (once per install) and `activation` (a real scan plus opening a recipe). We do not send your email, name, or kitchen photo to PostHog. Session replay and autocapture are off.
What we do with a kitchen photo or audio clip
The app sends exactly one of image, audio, or text to our API. We resize a photo in memory (or transcribe audio) and send it to OpenAI to detect ingredients and suggest recipes. Audio on the API is transcribed with OpenAI Whisper, then follows the same text path.
We do not store the photo or audio file. There is no image table and no cloud bucket for your kitchen media. What we keep is the scan row and the detected ingredients.
The audio transcript is returned in the API response. We do not save a transcript column.
Google Gemini is used only to generate a catalog sticker (an illustration of an ingredient). It does not receive your fridge photo.
OpenAI may retain what we send under its own policy. We do not control that retention.
We do not mean to collect
- Photos of people. Klaus is for food and kitchens. Do not upload images of children or of other people without their permission.
- Health diagnoses, payment card numbers, or government ID.
We do not currently offer a “freshness” feature. This policy will be updated before that feature goes live.
We do not currently run advertising pixels (Meta, TikTok, or similar).
3. How we use information
- Provide Klaus: detect ingredients, suggest recipes, keep your account, pantry, and scan history.
- Operate trial use on a device before you create an account.
- Debug crashes and keep the service secure.
- Measure install and first real use (PostHog events above).
- Comply with law and respond to valid legal requests.
- Communicate about the service and material changes to this policy.
4. Legal bases (LGPD and similar laws)
Where a legal basis is required, we rely on:
- Contract: to create your account and provide Klaus.
- Consent: for optional onboarding answers and any use we ask you to opt into.
- Legitimate interests: security, fraud prevention, crash debugging, and limited product analytics that do not override your rights.
- Legal obligation: tax, accounting, and binding official requests.
If you are in Brazil, you have the rights in Lei 13.709/2018 (LGPD). If you are in the United States, you may have state privacy rights (including California). We honor those rights as required.
5. How we share information
We do not sell your personal information and we do not share it for cross-context behavioral advertising as those terms are used in California law.
We share information with processors that help us run Klaus:
- OpenAI: kitchen photo, audio, or text, for ingredient detection, transcription (Whisper), and recipes.
- Google / Firebase Authentication and Google Sign-In: account creation and login. Passwords are not sent to our API.
- Google Gemini: catalog stickers only, not your fridge photo.
- Google Cloud (Cloud SQL / Postgres): we store accounts, profiles, pantry, and scan records.
- PostHog: `install` and `activation` events, with a device or account id, without email, name, or photo.
- Sentry: crash and error monitoring. Default PII is off; request bodies (including photos) are not sent; Flutter replay masks text and images; error screenshots are off.
- Your device OS: on-device speech-to-text, if you use it.
- Professional advisers and authorities when required by law or to protect rights, safety, and the service.
These providers may process data in the United States and other countries. When we transfer data out of Brazil, we do so under LGPD mechanisms (contractual clauses and related safeguards).
6. Retention
- Account and onboarding profile: while your account exists.
- Scan records and detected ingredients: until deleted. There is no automatic expiry (no TTL) today.
- Kitchen files: not retained by us. OpenAI’s retention is their policy.
- PostHog events and Sentry events: for a limited operational period on those services.
- Trial device id: while you use the app without an account, then linked to your user id after login.
The database has a soft-delete field. The app does not yet offer a delete-account button, and we do not purge scans on a schedule. To request deletion, email support@glashstudios.com. We will delete or anonymize personal data unless we must keep it (for example, a legal dispute).
7. Your rights
Subject to law, you can ask to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete data;
- export a copy (portability);
- restrict or object to certain processing;
- withdraw consent where we relied on consent;
- appeal a denial of a privacy request, where the law gives you that right.
Send requests to support@glashstudios.com. We may need to verify it is you. You can also complain to Brazil’s ANPD or to your local regulator.
If you are a California resident, you may request access, deletion, and correction, and you will not be discriminated against for exercising those rights. We do not sell or share personal information as defined in the CCPA/CPRA.
8. Children
Klaus is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
If you are in Brazil and under 18, a parent or guardian must agree to your use of Klaus.
9. Security
We use reasonable technical and organizational measures (access control, encryption in transit, least-privilege access, and limits on what crash tools may send). No method of transmission or storage is completely secure.
10. International use
We are based in Brazil. Klaus is offered first in the United States. Your information may be processed in Brazil, the United States, and other countries where our providers operate (including OpenAI and Google).
11. Changes
We will update this page when the policy changes. If a change is material, we will notify you in the app or by email. The “Last updated” date will change.
12. Contact
J.A.N.F. DESENVOLVIMENTO DE SOFTWARE LTDA (Glash Studios)Rua Minas Gerais, 1505, 1st floor, Jardim Atlântico, Alcobaça, Bahia, 45.910-000, Brazil
Email: support@glashstudios.com