Legal Notice
Information pursuant to § 5 TMG
Thomas Lorenz
Zur Plangemühle 5
47198 Duisburg
Germany
Contact
Email: [email protected]
Feel free to contact us in English.
Business represented by
Thomas Lorenz
Zur Plangemühle 5
47198 Duisburg
Germany
VAT identification number: 60/245/22693
Responsible for content pursuant to § 55 (2) RStV
Thomas Lorenz
Zur Plangemühle 5
47198 Duisburg
Dispute resolution
The European Commission provides a platform for online dispute resolution (OS): https://ec.europa.eu/consumers/odr
Privacy Policy
Last updated: 20 July 2026
1. Controller
Thomas Lorenz
Zur Plangemühle 5
47198 Duisburg
Email: [email protected]
2. Website spiesser.app
Provision and server log files
When you access the website, the hosting and security provider as well as our servers process technically necessary connection data. This may include your IP address, the time of access, the requested page, referrer, browser type and operating system. This processing serves the secure and error-free provision of the website and the prevention of misuse (Art. 6 (1) lit. f GDPR).
Contact
If you contact us by email, we process the information you provide to handle your request. The legal basis is Art. 6 (1) lit. b GDPR for pre-contractual or contractual matters and otherwise Art. 6 (1) lit. f GDPR.
Waiting list (beta registration)
When you register, we process the following information:
- Required information: email address, consent
- Optional information: name, preferred platform (iOS/Android)
- Collected automatically: IP address, approximate location (city/country), browser type, operating system, time zone, language setting, referrer URL
Registration and the associated emails are based on your consent (Art. 6 (1) lit. a GDPR). We process security and misuse data based on our legitimate interest in a secure service (Art. 6 (1) lit. f GDPR). You may withdraw your consent at any time by email.
Testing the receipt scanner
For the public OCR demo, we send the uploaded image to Microsoft Azure Document Intelligence and the recognized shopping list to your email address via Brevo. We do not store the image in our own database. According to its own information, Microsoft temporarily retains input data and analysis results and generally deletes them within 24 hours.
To provide the service and prevent misuse, we store your email address, the time of the request, a hashed IP address, approximate location, browser data and scan metadata such as the recognized store, receipt total, item count and status. The legal basis is Art. 6 (1) lit. b GDPR for the requested scan and Art. 6 (1) lit. f GDPR for security. The demo does not automatically register you for the waiting list or advertising emails.
3. Data processing in the Spießer app
Account and sign-in
For registration and sign-in, we process in particular your user ID, name, email address, authentication data and, optionally, telephone number, profile picture and PayPal information. When you sign in with Apple or Google, we receive the account data released by the respective provider. Passwords are processed by Firebase Authentication and are not shown to us in plain text. The legal basis is Art. 6 (1) lit. b GDPR.
Shared-apartment, purchase and payment data
We process shared-apartment assignments, invitation and join codes, purchases, items, participants, splits, balances, settlement payments, comments and timestamps to provide shared accounting (Art. 6 (1) lit. b GDPR). Spießer does not execute bank or PayPal payments itself; it only documents the settlement entered by users.
Data relating to a shared purchase is visible to the members of the relevant shared apartment. This may include names, amounts, items, receipt information and payment status. Please do not upload receipts containing health data or other particularly sensitive information.
Receipt scanning and AI analysis
When you scan a receipt, the image may be stored in Firebase Storage and displayed within the shared apartment. The image and the content read from it are transmitted to Microsoft Azure Document Intelligence. Recognized receipt text, items, prices, store and other scan results are stored in the associated purchase history.
To correct receipts that are difficult to read, OCR text, structured item data and, when a repeat image analysis is explicitly initiated, the receipt image may be transmitted to the OpenAI API. According to its own information, OpenAI does not use API content to train its models by default; however, content may generally be stored for up to 30 days for abuse prevention. The legal basis is Art. 6 (1) lit. b GDPR.
Push notifications
If you allow notifications, we process a device or installation identifier (FCM token) to deliver shared-apartment-related notices. The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR. You can withdraw this permission at any time in your system settings.
Analytics, crash and performance diagnostics
Firebase Analytics, Crashlytics and Performance Monitoring are disabled by default in the public V1. If these services are enabled later with your consent, we will update this policy and provide a corresponding choice.
4. Recipients and processors
Firebase (Google Ireland Limited)
We use Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging and Remote Config. Where a region can be selected, we primarily use European locations for central app data and functions, especially europe-west3. Not all Firebase services are regionally restricted: according to Google, Firebase Authentication is operated in the United States; other services may be processed on Google's global infrastructure. Firebase privacy information
Microsoft Azure Document Intelligence
We use Azure to analyze receipts using OCR. Our resource processes requests in the Germany West Central region. Microsoft temporarily stores input data and results in encrypted form and generally deletes them within 24 hours. Privacy and security
OpenAI Ireland Limited
We use the OpenAI API to correct and optionally re-analyze OCR results. Receipt text, item data and, for image analysis, the receipt photo may be processed. API data is not used for model training by default. OpenAI API data controls
Brevo
Brevo SAS, Paris, France, sends transactional emails, waiting-list confirmations and OCR demo results. In particular, the email address, name and message content are processed. Privacy policy
Mapbox
Mapbox, Inc. provides map images and location-based search functions. When requested, IP address, technical connection data, map area and search terms may be transmitted to Mapbox. Spießer does not use background location tracking. Privacy policy
Apple and Google
If you use “Sign in with Apple” or “Sign in with Google”, Apple or Google process the data required for sign-in and account linking in accordance with their own privacy policies.
ipapi.co
For the waiting list and OCR demo, we use ipapi.co for approximate IP geolocation to prevent misuse. The city, region and country are determined, but not the exact address. Privacy policy
Cloudflare
Cloudflare, Inc. provides the website, protects it against attacks and delivers cookieless web statistics. Technical connection and security data are processed for this purpose. Privacy policy
5. Processing outside the EEA
Some providers also process data in the United States or other countries outside the European Economic Area. Where required, transfers are based on an adequacy decision, in particular the EU-US Data Privacy Framework, or on EU Standard Contractual Clauses and supplementary safeguards.
6. Storage period and deletion
- We generally store account, profile and shared-apartment data for the duration of your use.
- Receipt images, OCR text and purchase data remain stored for as long as the associated purchase or shared-apartment history is needed or until they are deleted.
- Shared financial data that has already been settled may remain in anonymized form after account deletion so that the accounting of the remaining shared-apartment members remains comprehensible. Personal profile data, authentication, push tokens, scan quotas and personal files that are no longer needed are deleted.
- We store waiting-list and contact data until consent is withdrawn, the request has been handled or the respective purpose no longer applies. Statutory retention obligations remain unaffected.
7. Deleting your account and data
You can delete your account directly in the app under the account settings. Alternatively, you can request deletion via [email protected]. Open, not yet settled shared-apartment matters must be clarified beforehand so that no incorrect balances are created for other members. After deletion, you can no longer sign in with the previous account.
8. Your rights
Subject to the statutory requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent with effect for the future. You may also lodge a complaint with a data protection supervisory authority. Contact for data protection requests: [email protected].
9. Minors
Spießer is intended for people aged 18 and over. We do not knowingly collect data from children.
10. Changes
We update this policy when functions, providers or the legal situation change. The version published on this page applies.
Terms of Use
Last updated: November 2025
1. Scope
These Terms of Use apply to the use of the Spießer app and the website spiesser.app, operated by Thomas Lorenz.
2. Subject matter
Spießer is an app for managing shared-apartment expenses. Status: Beta (free of charge).
3. Beta status and liability
Important: Errors, outages and data loss may occur. We accept no liability for data loss, incorrect calculations or technical failures. Liability is limited to intent and gross negligence.
4. Requirements for use
Creating an account is required. Minimum age: 18. Required data: name, email, password.
5. Rights of use
A simple, non-exclusive, non-transferable right of use for the beta phase. Prohibited: reverse engineering, commercial use, scraping and illegal purposes.
6. Shared data
When you share an expense with the shared apartment, all group members can see, edit and delete it. You decide with whom you share data.
7. Feedback from beta testers
As a beta tester, you agree to provide feedback (bugs, feature requests). Feedback will be treated confidentially.
8. Termination
You can delete your account at any time in the settings or by email. After deletion, personal data will be removed; shared expenses will remain anonymized.
9. Future monetization
Currently: Spießer is available free of charge. If the pricing model changes later, we will inform you transparently and in good time.
10. Changes
Changes to the Terms of Use will be communicated by email 30 days before they take effect.
11. Applicable law
German law. Place of jurisdiction: Bremen (for merchants).
12. Contact
Thomas Lorenz
Email: [email protected]