Back home

Privacy Policy

Last updated: May 2, 2026

Filoxia ("the Service") is operated by Codivers Group ("Codivers Group", "we", "us", or "our"). Codivers Group is the data controller for personal data processed through Filoxia. This policy explains what we collect, why we collect it, the legal bases we rely on, and the choices you have.

Who we are

Codivers Group is the legal entity that provides Filoxia, a family grocery and meal planning app. If you have questions about this policy, contact us at support@filoxia.com.

Information we collect

  • Account details: name, email or phone number, and username you choose during sign-up.
  • Family and party content: meal plans, shopping lists, pantry items, calendar events, messages, RSVPs, allergies, and meal preferences you add.
  • Usage and device data: basic information about how the app is used, device type, operating system, and IP address, used to keep the service running and prevent abuse.
  • Billing information: when you subscribe to a paid plan, our payment processor (see below) collects your payment and billing details directly. We receive only the subscription status, plan, renewal date, and a customer reference.

How we use your information

  • To provide, maintain, and improve the Service.
  • To sync your meal plans, lists, and messages across the people in your family or party group.
  • To process subscriptions, renewals, and refunds.
  • To keep your account secure and prevent fraud and abuse.
  • To respond to your support requests.
  • To comply with our legal obligations.

Legal basis for processing (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, Codivers Group relies on the following legal bases:

  • Performance of a contract: to create your account, deliver the Service, and process your subscription.
  • Legitimate interests: to keep the Service secure, prevent fraud, debug issues, and improve the product - balanced against your rights and expectations.
  • Legal obligation: to meet tax, accounting, and regulatory requirements.
  • Consent: for optional communications such as product updates, where required. You may withdraw consent at any time.

Payments and Merchant of Record

Subscription payments for Filoxia are processed by Paddle.com Market Limited ("Paddle"), who acts as the Merchant of Record for all orders. This means Paddle handles the transaction, sales tax / VAT, invoicing, and customer billing inquiries on our behalf. When you check out, Paddle collects your name, email, billing address, and payment details directly. Paddle's handling of that data is governed by its own Privacy Notice and Checkout Buyer Terms. For refund requests and billing questions, you can also contact Paddle directly via paddle.net.

Sharing

We do not sell your personal information. We share data only with:

  • Service providers and subprocessors that help us run the app (cloud hosting and database providers, email and notification providers, error and analytics tooling).
  • Paddle, our Merchant of Record, for payment processing, subscription management, tax compliance, and invoicing.
  • Professional advisers (legal, accounting) as needed.
  • Authorities where required by applicable law.
  • Members of your family or party group can see the content you post in those shared spaces.

Data retention

  • Account data: kept for as long as your account is active. After account deletion, we remove or anonymise your personal data within 30 days, except where we are required to retain it (for example, billing records kept for up to 7 years to satisfy tax and accounting obligations).
  • Family, party, and pantry content: kept while your account is active and deleted with your account.
  • Chat messages in family and party chats are automatically deleted within 3 hours of being sent.
  • Logs and security data: kept for up to 90 days for debugging, abuse prevention, and incident response.
  • Backups: rotated and overwritten on a rolling schedule of up to 35 days.

International transfers

Your information may be processed in countries outside your own, including in the United States and the European Economic Area. Where personal data is transferred out of the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

Data security

We use industry-standard technical and organisational measures including encryption in transit, access controls, and least- privilege permissions. No system is ever 100% secure, but we work hard to protect your information.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. Users in the UK and EEA also have the right to lodge a complaint with their local data protection authority. To exercise any of these rights, email support@filoxia.com. We respond within 30 days.

Cookies

Filoxia uses essential cookies and similar technologies to keep you signed in and to remember your preferences. We do not use advertising cookies. The Paddle checkout may set its own cookies to operate the payment flow.

Children

Filoxia is intended for use by adults managing a household. If a child uses the app, it should be under the supervision of a parent or guardian who controls the account.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top and, if the changes are significant, let you know inside the app.

Contact

Questions, requests, or concerns? Email Codivers Group at support@filoxia.com.