Legal
Privacy Policy
Effective 1 August 2026 · Updated 3 September 2026
Who we are
Corementis FZE LLC is the company behind Juice Factory. It is a consulting and software company that designs, builds and operates digital, physical and phygital products and services end to end, from the first idea, to the thing itself, to running it day after day. It is registered in the United Arab Emirates, and Juice Factory is one of its products: we design it, build it, run it and answer for it. It is free, works without an account, and is anonymous by default. We do not show advertising and we do not sell your data.
Why we make it. We build products like Juice Factory to learn: to explore new technology and what can be understood from how it is used, and to put working ideas in front of real people and businesses to see how they respond. Where a project like this earns, that goes back into the app, into Corementis, and into the people behind it.
Corementis FZE LLC, AMC, Boulevard-A Building, BLA-BR3-411, Ajman Media City, Ajman, United Arab Emirates (“we”, “us”) is the data controller for Juice Factory (juicefactory.dk).
Privacy contact: amir.mortezaie@corementis.se
Because the Service is offered to people in the European Economic Area, we are in the process of appointing an EU representative under Article 27 GDPR. Their details will be published here once appointed.
What we collect, and why
Anonymous identity. On your first visit we create a random identifier for you (via Supabase anonymous authentication) so your creations and pins persist across visits. No name, email or phone number is required. This identifier is personal data under the GDPR, and this policy applies to it.
Legal basis: performance of a contract (providing the Service).
Your creations, pins and remixes. Drinks you create (ingredients, name, generated image, hashtags), drinks you pin, and remixes you make of other users’ published creations. Published creations are public: anyone can view, pin and remix them in the app, and a remix may reference the creation it was based on.
Legal basis: performance of a contract.
Usage events. Actions such as view, create, mix, pin and share, together with a coarse region (country/area level, derived from your IP address; we do not store your full IP with events). We use these to power the public Trends statistics, keep the Service secure, and understand what to improve.
Legal basis: legitimate interests (running, securing and improving a free service). You can object. See Your rights.
Camera frames (fridge-scan only). If you use fridge-scan, the photo you capture is sent to our ingredient-detection provider (Roboflow) solely to identify ingredients, and is then discarded. We do not keep the photo, and we do not permit our providers to use it to train their models. Avoid capturing people or documents in the frame.
Legal basis: performance of a contract (you actively trigger the feature).
Analytics. Google Analytics data, only if you consent via the cookie banner. See our Cookie Policy.
Legal basis: consent, withdrawable at any time via “Cookie settings” in the footer.
Email address. Only if you choose to register, to secure your account and let you sign in from other devices.
Legal basis: performance of a contract.
We do not use your data for automated decision-making that has legal or similarly significant effects on you.
Who we share data with
We use trusted service providers (“processors”) who handle data only on our instructions:
- Supabase: database, authentication and image storage. Data region: EU-West (Frankfurt, Germany).
- Vercel: website hosting and delivery.
- OpenAI: generates the cocktail images from your ingredient list. Prompts are processed via the API and are not used to train OpenAI’s models.
- Roboflow: fridge-scan ingredient detection. Frames are processed transiently and discarded.
- Google: Analytics and Tag Manager, loaded only after your consent (Consent Mode v2, default: denied).
- Cloudflare Turnstile: invisible bot protection (see Cloudflare’s Turnstile Privacy Addendum).
- Pexels: source of some seed imagery (no user data shared).
We do not sell your personal data, and we do not share it with advertisers.
International transfers
Some providers process data outside the EEA (including the US and UAE). Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, for US providers where applicable, the EU-US Data Privacy Framework. You can contact us for more information about a specific transfer.
How long we keep data
- Anonymous identity, creations, pins, remixes: kept while your identity is active. If your anonymous identity is inactive for 24 months, we may delete or anonymise it.
- Usage events: kept in identifiable form for up to 14 months, then aggregated or deleted. Aggregated Trends statistics contain no personal data.
- Camera frames: not stored. Processed and discarded.
- Consent records: kept as long as needed to demonstrate consent, then deleted.
- Email (registered accounts): kept until you delete your account.
To delete your identity, account and creations, email amir.mortezaie@corementis.se. Note that published creations that others have already remixed, and anonymised/aggregated statistics, may persist without any link to you.
Your rights
If you are in the EEA or UK (and in many other places), you have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time (footer → “Cookie settings” for cookies). We will respond within one month.
You can also complain to your local data-protection authority, for example, Datatilsynet in Denmark (datatilsynet.dk), though we would appreciate the chance to help first.
Requests: amir.mortezaie@corementis.se
Children
The Service is not directed at children under 16 (or the higher minimum digital-consent age that applies where you live). We do not knowingly collect personal data from children below that age. If you believe we hold such data, contact us and we will delete it.
Security
We use technical and organisational measures appropriate to the risk, including row-level security on the database, encrypted connections (TLS), and secret management. No system is 100% secure; use the Service accordingly.
Changes to this policy
We will post updates here with a new “Updated” date. For material changes, we will show a notice in the app.