Version 1.0 — updated: 1 October 2026
This Privacy Policy describes how personal data is processed when using the RistoBoost app and features directly connected to the service.
1. Data Controller
The data controller is:
CDR APPS DI RUSU COSMIN DUMITRU
VAT No.: 18569901004
REA: RM-1793518
Italy
Contacts:
Privacy: [email protected]
Support: [email protected]
Website: www.cdrapps.com
2. Who this Policy applies to
This Policy applies to RistoBoost users and, where relevant, to people who submit feedback through a RistoBoost link or QR code without creating an account.
Processing relating solely to browsing cdrapps.com is governed separately by the website's privacy information.
3. Account data
To create and use a RistoBoost account, data such as the following is processed:
- email address;
- technical Firebase account identifier;
- technical information required for authentication and security.
Current authentication uses email and password through Firebase Authentication.
RistoBoost does not store the user's password in plain text in its application databases.
4. Restaurant profile and business information
The user may enter and save information relating to their business, such as:
- restaurant or business name;
- category;
- country;
- city;
- description;
- contact or online-presence information voluntarily provided by the user.
This information is used to provide app functionality and, limited to the fields described in the following section, to provide context for certain AI-generation requests.
5. Content created or entered in the app
RistoBoost may process and store content such as:
- prompts and instructions entered for post generation;
- AI-generated text;
- saved posts;
- reviews entered by the user;
- names that may be associated with reviews;
- AI-generated replies;
- weekly plans;
- preferences and operational data connected to app functionality.
When a user enters personal data concerning customers or other people, the user is responsible for ensuring that they have an appropriate legal basis for using that information.
6. Artificial intelligence features
RistoBoost's AI features use the OpenAI API through the RistoBoost backend. The API key is not embedded directly in the client app.
For post generation, the following may be sent to OpenAI:
- the user's prompt;
- parameters required for generation;
- business name;
- category;
- country;
- city;
- business description.
Contact details such as email address, telephone number, website and Instagram account are not included in the restaurant context sent to the post-generation function.
To generate a reply to a review or feedback, the following may be sent:
- review or feedback text;
- any associated name;
- rating.
Images selected by the user are not sent to OpenAI.
AI results may contain errors, incomplete information or content that is not suitable for the specific context. The user must always review the result before publishing or using it.
7. Images
Images selected by the user when preparing social content remain on the device and are used through the operating system's sharing workflow.
RistoBoost does not use Firebase Storage and, in the current version of the service, these images are not uploaded to RistoBoost servers or sent to OpenAI.
8. QR Feedback
RistoBoost allows a restaurant to create a link or QR code through which a person may submit feedback without creating an account.
The following may be collected:
- name, if voluntarily provided;
- rating, where provided;
- feedback message;
- technical information required to prevent abuse.
A message is required in order to submit feedback.
To protect the service from automated or abusive submissions, IP address and User-Agent information may be used to generate cryptographic identifiers through hashing. The original values are not stored in the RistoBoost database for this purpose.
Feedback is made available to the owner of the RistoBoost account associated with the relevant QR link.
9. Usage and security data
RistoBoost may process technical information required to:
- apply usage limits;
- prevent abuse;
- verify request integrity;
- protect accounts and backend systems;
- diagnose technical issues.
RistoBoost uses Firebase App Check and, on Android where applicable, Google Play Integrity to protect access to backend services.
RistoBoost currently does not use Firebase Analytics, Google Sign-In or Firebase Crashlytics.
10. RistoBoost Pro, Google Play and RevenueCat
RistoBoost Pro subscriptions are purchased and managed through Google Play.
RevenueCat is used to verify subscription status and access to Pro functionality. The user's Firebase identifier is used as the RistoBoost user identifier with RevenueCat.
RistoBoost does not directly receive the complete card or payment-method details used in Google Play.
The applicable price, billing period, any free trial, renewal conditions and other relevant information are shown by Google Play before purchase.
11. Service providers and recipients
Depending on the relevant function, RistoBoost uses:
Google / Firebase
- Firebase Authentication;
- Cloud Firestore;
- Cloud Functions;
- Firebase App Check;
- Google Play Integrity.
OpenAI
- processing of AI requests.
RevenueCat
- technical management and verification of RistoBoost Pro entitlements.
Google Play
- Android subscription purchasing, billing and management.
Providers process data according to their respective agreements, legal obligations and applicable safeguards.
12. Purposes and legal bases
Depending on the circumstances, data is processed for:
Performance of a contract or pre-contractual measures
- registration and authentication;
- operation of the app;
- creation and storage of content;
- provision of AI functionality;
- management of Pro functionality.
Legitimate interests
- service security;
- prevention of fraud and abuse;
- protection of infrastructure;
- technical management and diagnostics;
- protection of the controller's rights.
Legal obligations
- tax, accounting, administrative obligations or lawful requests from authorities, where applicable.
Consent
- where required by law for a specific optional processing activity.
13. Retention
Data is retained for as long as necessary for the purposes for which it was collected.
In particular:
- account and profile data is normally retained while the account remains active;
- saved content is retained while necessary for the requested functionality, until the user deletes it where such functionality is available, or until account deletion;
- QR feedback and associated data may be retained while the restaurant account remains active and for as long as necessary to provide and secure the service;
- technical anti-abuse data is retained for as long as necessary for security purposes and may be removed when no longer required or when the account is deleted, where it can be attributed to that account;
- information that must be retained to comply with legal obligations or protect legal rights may be kept for the period required by applicable law.
OpenAI states that, under standard API usage, certain abuse-monitoring logs may be retained for up to 30 days, subject to different legal or security requirements.
Google Play and RevenueCat may apply their own retention periods to purchase, subscription and transaction information.
14. Account deletion
RistoBoost provides an account-deletion procedure.
When account deletion is successfully completed, RistoBoost deletes account data directly attributable to the user from its application systems, including, where applicable:
- Firebase Authentication account;
- user profile;
- usage data associated with the account;
- posts;
- generated content;
- reviews;
- weekly plans;
- QR links;
- feedback associated with the relevant account;
- anti-abuse data that can be deterministically attributed to the account.
Global information and information that cannot be attributed to a specific account is not deleted as part of this procedure.
The dedicated public account-deletion page remains available on the CDR Apps website.
Deleting a RistoBoost account does not automatically cancel an existing RistoBoost Pro subscription. The subscription must be managed or cancelled separately through Google Play.
Transaction or subscription data retained by Google Play, RevenueCat or other providers may remain subject to their respective retention obligations and applicable deletion-request procedures.
15. International transfers
Some technology providers used by RistoBoost may process data outside the European Economic Area.
Where required by applicable law, such transfers are carried out using mechanisms and safeguards recognized by the GDPR or through safeguards made available by the relevant provider.
16. Data-subject rights
Where provided for under the GDPR, individuals may request:
- access to personal data;
- rectification;
- erasure;
- restriction of processing;
- objection;
- data portability;
- withdrawal of consent where processing is based on consent.
Individuals may also lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority where applicable.
17. Children
RistoBoost is designed for owners, managers and operators of commercial businesses and is not specifically intended for children.
18. Changes
This Privacy Policy may be updated when features, providers, processing activities or legal obligations change.
The updated version will be published on the CDR Apps website with the relevant date.
19. Contacts
Privacy matters:
RistoBoost support: