Skip to content

Privacy Policy

Last updated: June 1, 2026

1. Data Controller

The data controller is lewosilimo, operating the Neodeal service at neodeals.pl. Contact: kontakt@neodeal.pl.

2. What Data We Process

Neodeal does not require account registration or login. We process only the following data:

  • Device UUID — stored in browser localStorage, used to identify your device without requiring login.
  • Push subscription endpoint — a URL provided by your browser when you subscribe to push notifications, enabling us to send promotional alerts.
  • Product preferences — items added to your shopping list, stored locally in your browser.

3. Legal Bases for Processing

  • Art. 6(1)(a) GDPR (consent) — we process push notification subscriptions and the localStorage device UUID based on consent given through browser interaction (clicking "Allow" on notifications) and using the service.
  • Art. 6(1)(f) GDPR (legitimate interest) — we process data to improve the service, analyze platform usage patterns, and ensure security.

4. Artificial Intelligence

Neodeal uses AI models (SigLIP for image embeddings and LLM for text analysis) for automatic product categorization from store leaflets. This process is fully automated, and product data comes from publicly available promotional materials. We do not use user data to train AI models.

5. Data Retention

Push subscriptions are stored until the device remains inactive for 12 months, after which the subscription is deleted. The localStorage device UUID remains on your device until manually cleared.

6. Data Processors

We use the following data processors:

  • Supabase — database (US/EU)
  • Vercel — application hosting (US/EU)
  • Cloudflare — CDN, WAF, tunnel (global)

All processors operate under Data Processing Agreements (DPAs) and provide adequate data protection guarantees.

7. Your Rights

You have the right to:

  • access your data (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure ("right to be forgotten", Art. 17 GDPR),
  • data portability (Art. 20 GDPR),
  • withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise these rights, contact us at: kontakt@neodeal.pl.

8. Cookies and localStorage

Neodeal does not use commercial cookies for marketing or cross-site tracking. We only use browser localStorage to store the device UUID and shopping list. This data is not shared with third parties.

9. Privacy Contact

For all matters related to personal data processing, please contact us at: kontakt@neodeal.pl.

10. Changes to This Policy

We reserve the right to update this privacy policy. Any changes will be reflected by the updated date at the top of this document. We encourage you to review this page periodically.