Privacy policy
Effective October 11, 2026. Applies to the naparo app (Android and web).
1. Who is responsible
The data controller is DATANODE & ΣΙΑ Ε.Ε. (limited partnership), Navarchou Votsi 69 & Psaroudaki 5, 104 45 Athens, Greece, VAT ID 800479159, GEMI No. 124699901000. For data matters write to gdpr@naparo.gr.
2. What data we process
| Account | Email, name (optional), unique user ID. If you sign in with Google, we receive your email and name from your Google account. Your password is held by the authentication service (Firebase Authentication) and we cannot see it. |
| Content | Lists, products (name, quantity, price, weight, note), categories, aisles, your “My products” collection and the barcodes you link to products. |
| Settings | Theme, language, color, font and other preferences, on your device and in your account. |
| Sharing | When you share a list, its members see your name and email. |
| Technical | IP address and technical identifiers processed by Google/Firebase services to run the service and keep it secure. |
| Camera | Only when you choose to scan a barcode (Android). Images are not stored or sent; only the code number is read. |
We show no ads, we do not sell data and we do not build advertising profiles.
3. Why, and on what legal basis
To provide the service (performance of a contract, Art. 6(1)(b) GDPR), for security and abuse prevention (legitimate interests, 6(1)(f)), and, for the camera, with your permission on the device. If paid features are offered, we also keep data required for tax obligations (6(1)(c)).
4. Who we share data with
Google (Firebase): hosts the database, authentication and the web app, as a processor. Data may be transferred outside the EEA with the appropriate safeguards.
Open Food Facts: when a barcode is not among your products, its number is sent to the public openfoodfacts.org database to find the product name. We do not send account details.
Google Play: if payments are offered, Google handles them; we do not receive card details.
Members of shared lists: as described above.
Service administrators can access account details (email, name, usage limits) only for support and administration.
5. How long we keep data
As long as you have an account. When you delete it (see how), your account, profile, lists you own, product collection, categories and aisles are deleted. You are removed automatically from other people's lists. Any backups held by the infrastructure provider expire under their own lifecycle.
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability (e.g. CSV export in the app). Send a request to gdpr@naparo.gr; we reply within one month. You may also lodge a complaint with the Hellenic Data Protection Authority.
7. Security
Communication is encrypted (HTTPS), data access is protected by security rules, and each user sees only their own data and the lists shared with them.
8. Children
The app is not directed to children under 15 and we do not knowingly collect their data.
9. Changes
If this policy changes we will update this page and, for material changes, notify you in the app.