Privacy Policy
What data Cal 3D processes, where it goes, and what never leaves your device. Written from what the code actually does — not from a template.
On this page
- The short version
- Controller
- What stays on your device
- Account and sync
- What happens when you scan a meal
- Processing by artificial intelligence
- Recipients at a glance
- Transfers to the United States
- Barcode lookup
- Apple Health
- Reporting a wrong estimate
- The summary report you mail yourself
- Subscriptions and payment
- The referral programme and its notification
- Usage statistics and crash reports
- Security in transit
- This website
- When you write to us
- Retention and deletion
- Do you have to provide this data at all?
- Your rights
- When the data is not yours
- Children and young people
- If you are in the United States
- Changes to this policy
The short version
Auf Deutsch: Diese Erklärung gibt es auch auf Deutsch — Datenschutzerklärung. Für Verbraucher in Deutschland ist sie die maßgebliche Fassung.
A German version of this policy is available at /datenschutz/. For consumers in Germany, that version governs.
The app is not published yet. This policy describes the processing that begins with its first release — so you can read before you install what will happen, rather than afterwards. This website itself processes nothing beyond what is described under Using this website.
Cal 3D is built so that as little as possible leaves your device, and nothing at all unless you ask for it. So that you do not have to read the whole thing first, here is the summary:
- An account is optional. The app works without one, and without one nothing is synced and nothing is kept for you. A few small things still reach us when you ask for them — a reported wrong estimate, the summary report you mail yourself, and three one-way hashes that stop the free endpoints being flooded. Each of them is listed under Retention and deletion with its own period. If you want your diary on more than one device, you can sign in — then, and only then, we store what is listed under Account and sync.
- Your food diary lives on your device. Meals, weight, goals, history — all of it is kept in the app’s local storage. We store it only if you sign in, and only to sync it to your own devices.
- Three things go to the AI model, and only when you ask for them: a photo of your meal, a food name you type into the search, or a workout you describe in your own words. Each goes through our own endpoint to OpenRouter and from there to Google Gemini. We do not store any of them.
- Three more can leave your device, and two of them we keep. Scanning a barcode asks Open Food Facts about that product. Reporting a wrong estimate sends us what you report, including anything you type into the note — we store that, and it is deleted automatically. Tapping Export PDF Summary Report mails you a summary through our mail provider. None of the three needs an account, and none of them happens unless you do it.
- The measurement never leaves your device. Volume and portion size are computed on your iPhone. Our endpoint never sees them — and neither does your body weight, which the app uses only locally to turn a workout into calories.
- This website sets no cookies and loads nothing from third-party servers. That is why there is no consent banner — there would be nothing to consent to.
Everything below is the detailed version that the GDPR requires.
Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Noah Sioly UG (haftungsbeschränkt)Hoheluftchaussee 139
20253 Hamburg
Germany
Email: support@cal3d.app
Phone: +49 163 1482383
Data protection enquiries are answered by the management directly, at the address above. You will get an answer within one month, as Art. 12 (3) GDPR provides — usually within two working days.
What stays on your device
Most of what the app knows about you never reaches us. This data lives exclusively in the app’s local storage on your device:
- your food diary — every logged meal with its ingredients and nutrition values,
- your profile — height, weight, age, activity level and the goals derived from them,
- progress, streaks and badges,
- the measured volume and the portion size derived from it,
- your photos — the profile picture, progress photos attached to individual weigh-ins, and the thumbnails of logged meals,
- your meal reminders and your settings.
Without an account none of this is transmitted to us or synchronised between devices by us. The few things that can reach us without an account are named under Your rights, and none of them is in the list above.
One thing does leave the phone even so, and it is worth saying plainly because it sounds like a contradiction: if you have iCloud Backup switched on, the app’s storage is part of that backup — the diary, the progress photos, everything in the list above. That is how iOS backs up every app unless the app opts out, and Cal 3D does not opt out, because opting out would mean a new phone starts empty. The backup is between you and Apple: it is encrypted, it sits under your Apple Account, and we have no way to reach it. Switch it off for Cal 3D under Settings → your name → iCloud → Manage Account Storage → Backups.
If you sign in, everything in the list above except the photos is stored for you at our processor so that your own devices stay in step. What that covers, on what legal basis and how to get rid of it is set out under Account and sync.
Without an account this has a downside, stated rather than hidden: if you delete the app or lose the device, the data is gone. Two things preserve it — a device backup (iCloud or computer), and signing in, which keeps a copy for you at our processor.
Account and sync
The syncing described here happens only if you sign in. Without an account none of it applies, and the app itself works without one — the single exception is rewards for referring a friend, which need an account because a reward has to be paid to somebody. The last part of this section, getting a copy of your data, applies either way.
How you sign in
Three ways, all optional: Sign in with Apple, Sign in with Google, or a one-time code we send to your email address. There is no password. We store your email address, the identifier our processor assigns you, and the times the account was created and last used.
The two provider routes are no exception to that. With Apple, the app asks for your name and your email address — so if you pick Apple’s private relay address, the relay address is what reaches us. With Google, you are sent to Google’s own sign-in page: what happens there is between you and Google under their terms, and what comes back to us is your Google account identifier, your name and your email address. Google LLC is in the United States; the transfer is covered by standard contractual clauses and is listed under Recipients at a glance.
What is synced
- your profile: goals, settings, body data, name and username, badges, streak record,
- your food diary, as one document per month — plus one extra document for any entry whose date cannot be read,
- your saved foods, your own foods, your meals and the list of what you logged most recently,
- your water intake per day,
- your workouts, as one document per month,
- your weight history, as one document per year.
This includes health data within the meaning of Art. 9 GDPR: weight, height, goals, what you eat and what you train.
What is never synced
Photos are not transmitted — neither the images themselves nor their file paths. Leaving out the paths is a deliberate measure rather than an oversight: an iOS file path contains an identifier of the device. Also excluded are your purchase status (the store is the source of truth for that), your daily scan quota, feature requests and the app’s internal bookkeeping.
Who processes it, and where
Supabase, Inc. as our processor under Art. 28 GDPR, in the region EU (Frankfurt, eu-central-1). The data itself does not leave the EU; the transfer that can arise from the company’s seat is set out under Transfers to the United States.
On what legal basis
For the sync itself: Art. 6 (1) (b) GDPR — it is the service you asked for. For the health data within it: your explicit consent under Art. 9 (2) (a) GDPR.
You give it by signing in — on one of two routes, depending on where you do it. Sign in while setting the app up and the declaration stands in plain words above the buttons; tapping one gives it. Sign in later from your profile and the same sheet carries a box you have to tick — without the tick, no sign-in starts there. Either way the declaration names the data by name: that your health and fitness data — weight, goals, meals and workouts will be stored in your account and synced between your devices. It is a separate line from the one that accepts these terms, and tapping a sign-in button is the affirmative act that gives both. Nothing is bundled in that you cannot decline: the marketing option stays off unless you switch it on yourself.
You withdraw it by deleting the account; nothing is uploaded before you sign in.
How long
Until you delete the account. Your diary, your profile, your progress and the account record itself go the moment the account goes, and no backup outlives them.
Two things are deliberately kept longer, and only if you took part in the referral programme.
- If you entered a friend’s code when you set the app up, the row recording it stays after you delete your account — otherwise your friend’s reward would quietly disappear for something they did nothing wrong in. What stays is the code, the amount, the status and the date. Your email address and everything you logged are gone, and the identifier in that row is a random number that no longer points at anybody once the account is deleted.
- If a reward was ever paid out to you in money or a voucher — possible only before 24 August 2026, see Referral programme terms — we have to keep the record of that payment, and it does name you: the amount, the method, the date, and the name and address we had to ask you for. § 147 (3) AO and § 257 (4) HGB set the period at eight years from the end of the year the record was made, and § 160 AO lets the tax office demand exactly who received a business expense. The legal basis is Art. 6 (1) (c) GDPR, and this is the one case where a deletion request cannot reach us.
How to delete it
In the app under Profile → Account Actions → Delete Account. That deletes the account itself, and every document belonging to it goes with it. It takes effect immediately and cannot be undone. If you signed in with Apple, you may also want to remove the app under Settings → your name → Sign in with Apple; the app cannot do that for you, and it says so after deleting.
Getting a copy of it
The app has an Export PDF Summary Report under Profile, and it mails you a summary of your days, your goals and your weigh-ins. It works without an account, and it is a summary rather than a full export — it does not contain every entry you ever made. Where that mail goes is set out under Recipients.
For the complete copy that Art. 15 and Art. 20 GDPR give you, write to support@cal3d.app and we will send you what is stored under your account, within one month as Art. 12 (3) GDPR provides.
What happens when you scan a meal
A scan consists of two parts that run separately. The difference matters for privacy:
The measurement — stays on the device
While you sweep around the plate, the app reads the camera’s depth data and computes the volume of the food in millilitres. This happens entirely on your iPhone. The depth data and the volume are not transmitted.
The recognition — this is what leaves the device
To determine what is on the plate, a vision model is needed, and it does not run on the device. The same model also answers two other questions you can ask the app, so there are three ways — and only three — for something you provide to reach it:
| When | What is transmitted | What is not |
|---|---|---|
| You photograph a meal | What is transmittedexactly one compressed image, together with the text instruction that directs the model | What is notthe measured volume, the portion size, your diary |
| You type a food into the search | What is transmittedthe words you typed, together with the same kind of instruction — no image | What is notyour profile, your goals, anything you typed earlier |
| You describe a workout in your own words | What is transmittedthe description you typed — no image | What is notyour body weight; the calories are worked out on your iPhone afterwards |
For all three of them the following applies:
- Our endpoint stores nothing and writes nothing to a log. It passes the request through and returns the answer.
- No device identifier, no advertising ID and no user name goes to this endpoint.
- Nothing is sent unless you start that one action. The app transmits nothing in the background and nothing on a schedule.
Worth spelling out, because it would be the obvious thing to send: your body weight is not transmitted when you describe a workout. The model is asked for the intensity of the activity, never for calories — those are worked out on your iPhone from a weight that stays there.
The identifier that checks your subscription is not this one, and it is not sent along when you scan. While you are not signed in it is a random one; once you are, it is the identifier of your account. Both are described under Subscriptions and payment.
Why there is an endpoint of ours in between at all
So that the access key to the model provider is not inside the app. If it were, anyone could extract it and spend our money. The endpoint is a doorman, not another collector of data.
The IP address, and why we hash it
To stop anyone from draining the endpoint there is a daily limit of 120 analyses. Counting requires something to tell requests apart. We use the IP address for that — but we do not store it: it is passed through a one-way function together with a secret value, and only the result is stored. The IP address cannot be recovered from that result, and without the secret value it is worthless outside this project.
- Purpose
- Recognising what you logged; protecting the service against abuse
- Legal basis
- Art. 9 (2) (a) GDPR — your explicit consent. A photo of your meal, read together with your calorie target and your weight history, can say something about your health, so we treat it under the stricter rule rather than argue about whether it falls under it. Art. 6 (1) (a) applies alongside it. For the abuse limit, and only for that, Art. 6 (1) (f) GDPR; our legitimate interest is running a service we can afford.
- If you would rather transmit nothing
- Then simply do not use the recognition. Logging by hand, the barcode scanner, the food database, the diary, goals and weight history all work without anything going to the model — it is sent only when you take a photo or type into the search.
- Withdrawing consent
- At any time, with effect for the future (Art. 7 (3) GDPR). The route that exists is deleting the account — it ends the processing immediately and completely. We say that plainly rather than promise a switch you would not find in the app. What you logged on your device is untouched by it, as long as you keep the app.
No automated decision within the meaning of Art. 22 GDPR is made here. The model proposes; you can change every value before you save it, and nothing is decided about you on that basis.
Processing by artificial intelligence
This section stands on its own deliberately. The App Store guidelines require two things: that sharing with third parties be clearly disclosed — “including with third-party AI” — and that explicit permission be obtained before it happens. This section is the disclosure.
You gave the consent for this when you signed in — the same one described under Account and sync. Above the sign-in buttons the declaration stands in plain words and names the data by name. There is no second dialog in front of the first scan: it is the same processing of the same health data, and two consents for one thing would be confusion rather than extra protection.
You still start it every time: you take the photo and send it, or you type an entry and search. Without that step nothing leaves. The volume measurement is not affected either way; it runs on your iPhone and sends nothing.
Whatever you hand over is analysed by a third party’s AI model:
- Intermediary
- OpenRouter, Inc., USA — privacy notice
- Model
google/gemini-3.5-flashby Google, withgoogle/gemini-3-flash-previewas fallback. Other models are blocked on the server and rejected.- What the model receives
- one of three things, never more than one at a time: a photo of your meal, the food name you typed, or the workout you described — each with the text instruction that directs the model, and nothing else
- What the model returns
- for a meal, a list of suspected ingredients with estimated proportions; for a workout, how strenuous the activity is and how long it lasted
What we are not claiming here
We cannot assure you that what is transmitted is not used for training at the model provider. Whether and for how long it is processed there is governed by the terms of OpenRouter and Google, linked above. We write this down instead of making a promise we do not control.
And one difference we would rather name than smooth over: the intermediary’s own notice promises not to keep image files longer than a request needs. For typed text there is no equivalent promise. So treat the two free-text fields as what they are — text that leaves your device.
The practical advice that follows: photograph the plate, not the table, and type the food or the workout — not a diagnosis, a medication or anything about someone else. What is not in the frame and not in the field cannot be transmitted.
No model decides on its own what ends up in your diary: the amounts are corrected on your device using the measurement, and you can change every value before saving. How exactly that works is described on the method page.
Recipients at a glance
The table below names every service that gets to see any of your data. These are all of them — the list is not abridged.
| Recipient | What it sees | Purpose | Location |
|---|---|---|---|
| Supabase, Inc. | What it seesthe photo or the text you typed while it passes through, the hash of your IP address, a mis-estimate you report to us including anything you type into it, and — only if you sign in — your account and the documents synced to it | PurposeRunning our analysis endpoint, taking your reports about wrong estimates, and storing your synced data if you have an account | LocationEU (Frankfurt, eu-central-1) |
| OpenRouter, Inc. | What it seesthe photo or the typed text, together with the instruction that goes with it | PurposeRouting the request to the model | LocationUnited States |
| Google LLC (Sign in with Google) | What it seesyour Google account identifier, your name and your email address — only if you choose this way of signing in | PurposeSigning you in | LocationUnited States |
| Google LLC (Gemini) | What it seesthe photo or the typed text | PurposeRecognising the dish or the entry | LocationUnited States |
| Open Food Facts | What it seesthe scanned barcode number and your IP address | PurposeNutrition data for packaged products | LocationFrance |
| Resend, Inc. | What it seesyour name and email address, and the summary you asked for: your goals, your daily totals and your weigh-ins | PurposeMailing you the summary report you requested | LocationUnited States |
| Apple Distribution International Ltd. | What it seespurchase and billing data, and — if you use Sign in with Apple — that you signed in | PurposeSelling and billing the app, and verifying your Apple sign-in | LocationCork, Ireland |
| Google Commerce Limited | What it seespurchase and billing data — your payment method never reaches us | PurposeSelling and billing the app on Android | LocationDublin, Ireland |
| RevenueCat, Inc. | What it seesthe purchase status, and an identifier: a random one while you are not signed in, and the identifier of your account once you are | PurposeChecking whether a subscription is active | LocationUnited States |
| 650 Industries, Inc. (Expo) | What it seesyour device's push token, which it stores, and the text of the message itself — “You earned $5” — which it only holds for as long as passing it on to Apple takes | PurposeDelivering the notification that a referral reward was earned | LocationUnited States |
| Google LLC (Firebase Analytics and Crashlytics) | What it seeswhich screens you use, by which route you logged a meal and whether a scan succeeded — as event names without any values — and, when the app crashes, the technical crash report; never what you eat, your weight, your name or your email address | PurposeAnonymous usage statistics (only if you allow it) and crash reports | LocationUnited States |
| Vercel Inc. | What it seesthe server logs of this website | PurposeRunning the website | LocationVercel's global edge network |
| IONOS SE | What it seeseverything you send us by email | PurposeRunning our mailbox | LocationGermany |
Where a provider processes on our behalf, data processing agreements under Art. 28 GDPR are in place to the extent the processing falls under that provision. They bind the providers to confidentiality, to acting on our instructions, and to using the data solely for the purpose named here.
Every third party named here is therefore held to the level of protection this policy describes — including the limitation stated explicitly in the next paragraph. A promise reaching beyond what we can enforce would be no promise at all.
We name one exception explicitly: for the model provider this assurance only holds within its own terms. What happens there to a transmitted image — in particular whether it is used for training — is something we cannot guarantee. The section Processing by artificial intelligence says exactly that, and we repeat it here rather than promising something in one place and withdrawing it in another.
We do not sell data. There is no advertising network and no cross-provider tracking, in the app or on this website. This website uses Vercel Web Analytics for aggregated visitor statistics (see This website). The app can send anonymous usage statistics and crash reports to Google — the section Usage statistics and crash reports says what exactly, when, and how you switch it off.
One thing is advertising, and you switch it on yourself. The app offers to send you tips, new features and offers by email. It is off unless you turn it on — when you set the app up, or later under Profile → Preferences → Marketing emails, where the same switch turns it off again. The legal basis is your consent, Art. 6 (1) (a) GDPR, and you can withdraw it at any time under Art. 7 (3) without giving a reason; withdrawing does not affect what was sent before. If you have an account, this setting is part of your synced profile.
Note on Apple and Google: their privacy notices are available from Apple and Google. We have no influence over their processing.
Transfers to the United States
Some of the recipients above are based in the United States. Below is what applies to each of them individually — because the routes are genuinely different, and a single blanket sentence would have hidden that.
| Recipient | Country | On what basis |
|---|---|---|
| Supabase, Inc. | CountryUnited States (company seat) | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| OpenRouter, Inc. | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| Google LLC (Sign in with Google) | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| Google LLC (Gemini) | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — onward transfer under the same clauses |
| Resend, Inc. | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| RevenueCat, Inc. | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| 650 Industries, Inc. (Expo) | CountryUnited States | On what basisArt. 46 (2) (c) GDPR — standard contractual clauses |
| Google LLC (Firebase Analytics and Crashlytics) | CountryUnited States | On what basisArt. 45 GDPR — EU-US Data Privacy Framework |
| Vercel Inc. | CountryUnited States | On what basisArt. 45 GDPR — EU-US Data Privacy Framework |
What that means in each case
- Supabase, Inc.
- The data itself stays in Frankfurt. A transfer only happens if Supabase reaches into the project from the United States for administration. Supabase is not certified under the EU-US Data Privacy Framework.
- OpenRouter, Inc.
- Not certified under the EU-US Data Privacy Framework. OpenRouter commits to the standard contractual clauses in its own privacy policy, and its data processing agreement applies to commercial users under section 10.2 of its terms.
- Google LLC (Sign in with Google)
- You reach Google directly from your device when you tap the button, so what Google learns at that moment is between you and Google under their own terms. What reaches us afterwards is the identifier, your name and your email address.
- Google LLC (Gemini)
- Google LLC is certified under the EU-US Data Privacy Framework, but that certification does not carry this transfer: we do not send anything to Google ourselves. The data reaches Google through OpenRouter, so what applies is the onward-transfer clause of the standard contractual clauses.
- Resend, Inc.
- Resend binds the EU standard contractual clauses (Commission Decision 2021/914) in its data processing addendum. Nothing is sent there unless you tap Export PDF Summary Report, and the address it goes to is the one you type in.
- RevenueCat, Inc.
- Not certified under the EU-US Data Privacy Framework.
- 650 Industries, Inc. (Expo)
- Expo also states that it complies with the EU-US Data Privacy Framework. The clauses are named here because a certification can lapse and they carry on either way. Nothing is sent unless you allowed notifications and someone used your invite code.
- Google LLC (Firebase Analytics and Crashlytics)
- Google LLC is certified under the framework, and Google’s data processing terms additionally bind it to the standard contractual clauses under Art. 46 (2) (c). Usage data is collected on Google servers in the EU and then processed on Google’s Analytics servers; crash reports go to Google in the United States directly.
- Vercel Inc.
- Vercel Inc. is certified under the framework and additionally relies on standard contractual clauses under Art. 46 (2) (c).
For every one of them we have also assessed whether those clauses can actually be effective in the country concerned. You can obtain a copy of the clauses free of charge by asking us at support@cal3d.app.
Where the table says standard contractual clauses, that is the mechanism the provider commits to in its own terms and data processing agreement — for OpenRouter, its terms apply that agreement to commercial users like us automatically. We name the mechanism that is actually in force rather than describing a contract we have not signed.
For the image analysis the transfer is also strictly necessary for us to provide the service you requested — an equivalent model hosted in the EU is not available to us.
What this means for you, stated plainly: the United States does not provide a level of data protection equivalent to the European one. Authorities there may under certain conditions access data, and the legal remedies available to people in the EU are limited. If you do not want that, there are exactly two things to avoid: the scan function, and asking the app to mail you a summary report. Everything else either stays on your iPhone or stays inside the EU — the barcode lookup goes to Open Food Facts in France, and your synced account data is held in Frankfurt.
Barcode lookup
If you scan the barcode of a packaged product, the app looks up its nutrition data at Open Food Facts — a non-profit open food database based in France.
What is transmitted is the barcode number. For technical reasons the service also learns your IP address, because without it no answer could come back. No photos and no diary data are transmitted.
- Legal basis
- Art. 6 (1) (b) GDPR — without the lookup there would be no nutrition data for the scanned product
- Provider’s privacy notice
- Open Food Facts
Apple Health
Cal 3D can read two values from Apple Health, and only those two: your step count and the active energy you burned. They appear on the activity card next to what you logged. Nothing else is read — not workouts, not heart rate, not weight, not sleep.
Cal 3D never writes to Apple Health. What you log here does not appear there. The connection runs one way.
You are asked for it once, and iOS asks — not us. You can withdraw it at any time in the Health app under Sharing → Apps, or in Settings → Privacy & Security → Health. The app keeps working; the activity card then shows that it is not connected.
The two values stay on the device. They are read fresh for the day you are looking at, shown, and not stored. They are not transmitted to us, not part of the account sync, and never sent to the recognition model. Whether you connected at all is remembered per device and is deliberately excluded from the sync — a permission granted on one phone says nothing about another.
If you also use the Apple Watch app, the watch reads the same two values from Apple Health on the watch itself, and asks you separately for that. A permission you gave on the phone does not carry over.
- Legal basis
- Art. 9 (2) (a) GDPR — your explicit consent, given in Apple’s own permission sheet for exactly these two data types. Art. 6 (1) (a) applies alongside it. Withdrawing it in the Health app ends the reading immediately.
- Recipients
- None. The values do not leave the device.
- How long
- Not stored. Read for the day on screen, gone when you leave it.
Reporting a wrong estimate
If a recognition is wrong, you can tell us. It is entirely voluntary, and nothing is sent unless you tap it.
What reaches us is the entry you are reporting — the item, the values we showed, and whatever you type into the note. Two more things are stored with it, and neither is a name: a one-way hash of your device and, separately, a counter that limits how many reports one device can send per day. They exist so that the endpoint cannot be flooded; they are not used to recognise you.
What we do with it, plainly: we read the reports to find where the recognition is wrong, and we keep them in three groups — one to learn from, one to test against, and one held back so a later measurement is honest. That is how a recognition gets better. It means your report can end up in material that is used to improve the model we use.
- Purpose
- Finding and fixing wrong recognitions, and measuring whether a change helped
- Legal basis
- Art. 6 (1) (f) GDPR for the operational part — our legitimate interest is a recognition that gets better rather than worse. For the health data in a report, Art. 9 (2) (a) GDPR: the explicit consent you gave when you signed in, which covers the health data we process for you. Sending a report is always your own deliberate act — nothing is sent unless you tap it.
- How long
- One year. The date sits in the row itself, not only in the clean-up job, so a forgotten job cannot quietly extend it. The daily counter goes after two days.
- Recipients
- Supabase, Frankfurt. Nothing goes further.
The summary report you mail yourself
Tapping Export PDF Summary Report sends a summary of your days, your goals and your weigh-ins to an email address you type in. It only happens when you ask for it.
Two things happen then, and the second one is easy to miss, so it is spelled out. First, the mail goes out through our mail provider, Resend, Inc. in the United States. Second, the report itself is kept on our server for three days so that the download link in the mail works. The link is a random, unguessable address, and it is the whole permission: whoever has it can open the report. Treat it like a password, and do not forward the mail.
Your email address is not stored with it — only a one-way hash of it, which exists so that nobody can mail-bomb one inbox from many devices. There are two daily limits for the same reason: twenty sends per caller and ten per recipient.
- Purpose
- Sending you the report you asked for, and letting you download it afterwards
- Legal basis
- Art. 6 (1) (b) GDPR — you asked for it. For the health data in it, Art. 9 (2) (a) GDPR: the explicit consent you gave when you signed in. The daily limits rest on Art. 6 (1) (f): a public endpoint that sends mail is a spam relay without them.
- How long
- Three days, then deleted an hour later by a scheduled job. The expiry sits in the row itself, and the function that serves the download checks it — not the calendar. The mail in your inbox is yours and outside our reach.
- Recipients
- Resend, Inc. (United States) for the delivery; the stored copy stays at Supabase in Frankfurt.
Subscriptions and payment
If you take out a subscription, payment runs entirely through Apple’s App Store. We never see payment data. Your card number, your billing address and your name do not reach us.
So that the app knows whether your subscription is active, we use RevenueCat. What goes there is the purchase status and one identifier — a random one while you are not signed in, and the identifier of your account once you are. No name and no email address.
We also keep a record of each purchase message on our own side. It carries that same identifier and the message as the store sent it. It exists for one reason: the store may deliver the same message twice, and without this record the second delivery would pay out a referral reward a second time. That is also why it outlives the account — deleting it would reopen exactly that gap. It is not deleted with your account — it is listed under Retention and deletion and on the delete your data page. We do not delete your record at RevenueCat automatically either; write to us and we will do it.
- Purpose
- Unlocking the paid features, and not paying a reward twice
- Legal basis
- Art. 6 (1) (b) GDPR for checking the subscription; Art. 6 (1) (f) GDPR for the record of the purchase message, our legitimate interest being not to pay the same reward twice
- Privacy notice
- RevenueCat
You cancel a running subscription in the store itself: manage Apple subscriptions. We cannot technically do it for you.
The referral programme and its notification
If someone enters your invite code when they set up the app, both of you are recorded against that code: you as the one who invited, they as the one who came. That is the whole point of the programme, and it is what earns you the reward.
The other person’s side is deliberately weaker. Their entry is tied to your account, but not the other way round — if they delete their account, your reward stays. Yours works differently: rewards belong to your account, so deleting it takes the balance with it. That is said here and not only on the deletion page, because it is the one condition that costs you something.
The notification. If you allowed notifications, we send one when a reward is actually earned — never before, and never for nothing: a reward of zero sends no message at all. To deliver it we store a push token, the identifier Apple gives your installation. It goes to Expo, which passes it on to Apple. It is not an advertisement: it reports something that already happened under our agreement with you, which is why it does not sit behind the marketing tick-box.
- Purpose
- Running the programme, and telling you when a reward is earned
- Legal basis
- Art. 6 (1) (b) GDPR — the programme and its notification are part of what you signed up for. Recording which purchase already triggered a reward rests on Art. 6 (1) (f): our legitimate interest is not paying the same reward twice.
- How long
- The push token goes when the account goes, and so does every reward you earned for inviting someone — the database removes them with it. One line is deliberately kept: the record that you once used someone else’s invite code. It has to stay, because otherwise the person who invited you would lose their reward when you leave. It no longer points at an account that exists.
- Recipients
- Supabase (Frankfurt), and 650 Industries, Inc. (Expo) in the United States
Usage statistics and crash reports
The app can tell us how it is used — and it can tell us when it breaks. Both go to Google (Firebase Analytics and Firebase Crashlytics), and both are built so that what you eat, what you weigh and who you are never leave the device.
What is sent
Usage statistics: event names without values. That a meal was logged, and by which route (scan, search, barcode, voice, manual); which step of the setup you were on; whether a scan succeeded; that a streak grew or broke; that a purchase was started or completed. Not the meal, not the calories, not your weight, not the search text, not the photo. The app’s own catalogue admits only a fixed list of names and refuses any value that looks like a number, a food, a weight, a name or an email address — that refusal is tested in the code, not promised in a text.
Crash reports: when the app crashes, the technical stack trace, the app version, the device model and operating-system version, and the app’s state at that moment. No diary data, no account.
Both carry a random installation identifier that Google generates on the device. It is not linked to your account, your name or your email address — we pass no user identifier to Google — and it is not the advertising identifier: the app is built without advertising-identifier support, so Apple’s tracking prompt does not apply.
Every single event, in full
There are 39 of them, and none is a secret: see the complete list — each event, what travels with it, and an explicit list of what never does. That page is generated from the app’s own source, so it cannot drift from what the app does.
On what legal basis, and how you switch it off
Usage statistics need your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). The app asks once, on its first screen; nothing is collected before you agree, and nothing that happened earlier is sent later. You withdraw it under Profile → Manage Personalization Preferences, at any time and without giving a reason (Art. 7 (3)). On that same screen, What you share holds five separate switches — getting started, logging food, using the app, subscription, errors — so you can stop one group and leave the rest running (recital 32 GDPR: consent “for specific purposes”). Withdrawing stops the collection; it does not affect what was sent before.
Crash reports rest on our legitimate interest in an app that does not crash (Art. 6 (1) (f) GDPR, § 25 (2) No. 2 TDDDG): a crash is a defect we cannot find without the report, and the report holds nothing from your diary. You may object at any time under Profile → Manage Personalization Preferences; the switch takes effect immediately.
Who processes it, and where
Google LLC as our processor under Google’s data processing terms. Usage data is collected on Google servers in the EU and then processed on Google’s Analytics servers; crash reports go to Google in the United States. The transfer is set out under Transfers to the United States.
How long
Usage data at event level: 14 months at Google, after that only aggregated reports without the installation identifier. Crash reports: 90 days. We keep no copy of either beyond what Google shows us.
What we do with it
Retention curves (how many people come back after a week), where people leave the setup, which way of logging is used, and which crashes affect how many installs. Nothing individual: the questions are about the app, not about you.
Security in transit
Everything that travels between your device and us is encrypted in transit: both the request for this website and every request the app makes to our analysis endpoint. We use TLS (HTTPS) to current standards; unencrypted connections are not accepted.
The access key to the model provider is not in the app but on the server alone — that is why the endpoint exists in the first place. The IP address is put through a one-way function with a secret value before storage; only the result is kept.
Logs of the analysis endpoint
The endpoint keeps logs too — every server does, and leaving that out here would be the more convenient but incomplete answer. What is logged is technical: timestamp, outcome of the request, and error messages. The photo appears in no log. The calling IP address is read for the daily limit and stored only as a hash.
- Where
- Supabase, EU (Frankfurt, eu-central-1)
- Legal basis
- Art. 6 (1) (f) GDPR — legitimate interest in a secure, functioning and affordable service
- Retention
- a few days, then deleted automatically by the platform
This website
Different rules apply to cal3d.app than to the app — considerably less happens here.
Website analytics without cookies
This website uses Vercel Web Analytics to count visitors and page views and understand which pages are useful. It collects page addresses, referrers, timestamps, approximate location, and device, browser and operating-system information for aggregated statistics. We do not send custom events or app account details to this service.
Vercel identifies visitors using a hash derived from the incoming request; the visitor session is discarded after 24 hours. It does not use cookies or cross-site identifiers. The typeface is served from our own server. For details about the analytics service, see Vercel’s Web Analytics privacy documentation.
Server logs
This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, CA 91723 Covina, United States (privacy notice); the servers are located in Vercel's global edge network. When a page is requested, your browser transmits technically necessary information that the host logs briefly: IP address, timestamp, requested address, amount of data transferred, browser type and operating system. These logs serve secure operation and troubleshooting. They are not combined with other data and not used to build usage profiles.
- Legal basis
- Art. 6 (1) (f) GDPR — legitimate interest in technically sound and secure operation
- Retention
- usually a few days, then deleted automatically
When you write to us
If you send us an email, we process your address and the content of your message in order to answer it. That is unavoidable — no address, no reply.
- Legal basis
- Art. 6 (1) (b) GDPR for enquiries relating to the contract, otherwise Art. 6 (1) (f) GDPR — legitimate interest in answering enquiries
- Retention
- until your matter is settled, then at most six months for follow-up questions. Where commercial or tax law requires retention, the statutory periods apply instead.
Our mailbox is operated by IONOS SE, Montabaur, Germany (privacy notice). Technically, that provider sees everything you write to us — which is why it appears in the recipients table. Do not send us anything you would not want sitting there; for particularly confidential matters you can also reach us by post at the address in the imprint.
What happens to your message afterwards
So that an urgent matter does not sit unread, a program looks into the mailbox every hour and sorts new messages — by fixed rules, not by feel: letters from lawyers, access requests, bug reports, advertising. We then get a short notification on the phone.
That notification travels through a messenger operated outside the EU. This is why it contains nothing from your message: not the text, not the subject, not your address. All that leaves is the classification and a short code that only we can match to your message. Your message itself is read in our mailbox, by us.
A language model never gets to see your message. It only judges mail from companies — from Apple, say, or from our technical providers. The reason is simple: a message to a nutrition app often carries information about someone’s health, and Art. 9 GDPR puts that under special protection. This is not a statement of intent but a rule inside the program: mail from private individuals is never handed over in the first place.
Job applications
If you apply to us, we process your application solely for the selection procedure: covering letter, CV, references and anything else you choose to send.
- Legal basis
- § 26 (1) German Federal Data Protection Act in conjunction with Art. 6 (1) (b) GDPR — deciding on the establishment of an employment relationship
- Recipients
- nobody outside the company; technically the operator of our mailbox (IONOS SE)
- Retention
- six months after the procedure ends, then deleted. If you would like us to keep you in mind for longer, say so — we will ask you first.
You may object to this storage at any time; we will then delete the correspondence unless a retention obligation prevents it.
Retention and deletion
What is kept for how long, at a glance:
| Data | Where | How long |
|---|---|---|
| Diary, profile, progress | Whereon your device; with an account also at Supabase, EU (Frankfurt, eu-central-1) | How longuntil you delete it in the app, remove the app, or delete the account |
| Referral row, if you entered a friend’s code | WhereSupabase, EU (Frankfurt, eu-central-1) | How longstays after you delete the account — otherwise your friend’s reward would vanish. What stays is the code, the amount, the status and the date; the identifier in it points at nobody once the account is gone |
| Record of a reward paid out to you | WhereSupabase, EU (Frankfurt, eu-central-1) | How longeight years from the end of the year the record was made (§ 147 (3) AO, § 257 (4) HGB) — this is the one case a deletion request cannot reach |
| Photo of a meal | Wherepassed through, not stored | How longnot at all with us; at the model provider per its terms |
| A wrong estimate you reported | WhereSupabase, EU (Frankfurt, eu-central-1) | How longdeleted automatically one year after you send it, including anything you typed into the note |
| Hash of the IP address (photo analysis limit) | Wherequota table at Supabase, EU (Frankfurt, eu-central-1) | How longat most seven days — the clean-up runs inside the limit check itself, on every call, so it does not depend on a scheduled job |
| Hash of your device (wrong-estimate limit) | Wherewith the report, at Supabase, EU (Frankfurt, eu-central-1) | How longthe counter goes after two days; the hash goes with the report after one year |
| Hash of the address a report was mailed to | Wherewith the download link, at Supabase, EU (Frankfurt, eu-central-1) | How longthree days, then deleted an hour after the link expires |
| Website server logs | Whereat the host (Vercel Inc.) | How longa few days |
| Logs of the analysis endpoint | WhereSupabase, EU (Frankfurt, eu-central-1) | How longa few days |
| Purchase and billing data | WhereApple Distribution International Ltd. | How longstatutory retention at the store — we never see it and have no access to it, so we can neither read nor delete it for you |
| Subscription identifier | WhereRevenueCat, USA | How longas long as the subscription is on record there. Deleting your account does not reach it — write to us and we will delete it |
| Record of a purchase message | WhereSupabase, EU (Frankfurt, eu-central-1) | How longstays after you delete the account — deleting it would let the same message pay a referral reward a second time |
| Notification token for your device | WhereSupabase, EU (Frankfurt, eu-central-1); sent to Expo, USA, when a reward is earned | How longuntil you delete the account, which takes it with it — only stored at all if you allowed notifications |
| Usage statistics (event names, only with your consent) | WhereGoogle (Firebase Analytics): collected in the EU, processed on Google’s Analytics servers | How long14 months at event level, afterwards only aggregated reports |
| Crash reports | WhereGoogle (Firebase Crashlytics), United States | How long90 days |
| Job applications | Wheremailbox | How longsix months after the procedure ends |
| Emails to us | Wheremailbox | How longuntil settled, at most six months |
How to delete everything, step by step, is on the delete your data page.
Do you have to provide this data at all?
Short answer: no. There is no statutory and no contractual obligation to give us anything. You need not create an account, give a name or leave an email address — logging, scanning, the barcode reader, the database, workouts and the summary report all work without one. An account adds syncing between your devices and getting your diary back after a reinstall.
One thing does need an account, and it is not part of tracking your food: rewards for referring a friend are tied to one, because a reward has to be paid to somebody.
What actually governs this is a technical necessity, not an obligation:
- Photo of a meal: no transfer, no recognition. If you do not want that, do not use recognition — the diary, the volume measurement, goals and progress carry on with no transfer at all.
- Barcode lookup: sends the barcode number, nothing else about you. If you would rather not, enter packaged food by hand.
- IP address at the endpoint: technically unavoidable; without it no answer can come back. Only its hash is stored, and only for the daily limit.
- Email address: only needed if you want a reply. Post works too.
So withholding data has one consequence only: the feature in question is not available to you. Nothing beyond that follows from it, and no contract fails because of it.
Your rights
You have the following rights in relation to us:
- Access (Art. 15 GDPR) — what data we process about you
- Rectification (Art. 16 GDPR) — correction of inaccurate data
- Erasure (Art. 17 GDPR) — the “right to be forgotten”
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — a copy in a common format
- Withdrawal of consent (Art. 7 (3) GDPR) — with effect for the future
What we actually hold
Without an account: little, and only if you did something that sends it. Your diary sits on your device. What can be here:
- a wrong estimate you reported, including anything you typed into the note — deleted a year after you sent it
- the summary report you mailed yourself, kept three days so the download link works, then deleted an hour after it expires
- a one-way hash of your IP address (photo limit, at most seven days) and one of your device (report limit, two days)
- a one-way hash of the address a report was mailed to, three days
None of the hashes can be turned back into what they were made from. Ask anyway, and we will tell you exactly what is there.
With an account: your email address (or the identifier Apple gives us), the documents listed under Account and sync, your personal referral code, and — if you took part in the referral programme — the row recording it. Every one of these rights applies in full. Erasure you can exercise yourself, immediately, in the app: delete the account and the documents synced to it go with it. The two exceptions, and why they exist, are named under Account and sync. For a copy, write to us and we will send it.
Requests to support@cal3d.app. We reply within one month, as Art. 12 (3) GDPR provides.
Right to object
You can object
You have the right to object at any time, on grounds relating to your particular situation, to processing of your data that we base on Art. 6 (1) (f) GDPR (Art. 21 (1) GDPR). The following fall under that: the abuse limit at the analysis endpoint, the logs of that endpoint, the server logs of this website, answering your emails, the record we keep of a purchase message so that one is not paid out twice, and the crash reports the app sends — those you can also switch off directly under Profile → Manage Personalization Preferences.
If you object, we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims. A plain sentence to support@cal3d.app is enough; a reason helps us but is not a condition.
Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority if you believe we are infringing the GDPR. The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Str. 22
20459 Hamburg, Germany
datenschutz-hamburg.de
You may equally contact the supervisory authority of your habitual residence or place of work.
When the data is not yours
Almost everything here comes from you. Two things do not, and the law treats those differently (Art. 14 GDPR instead of Art. 13). We would rather name them than let them sit unnamed between the other sections.
If you appear in someone else’s photo
When someone photographs a meal, other people can end up in the picture — a hand across the table, a face in the background. That photo is sent for recognition and passes through OpenRouter, Inc. and Google LLC in the United States. It is not stored on our side.
We cannot tell you personally, and we will not pretend otherwise. We do not know who is in a picture, and we do not try to find out — no face is detected, named or matched against anything. That makes informing you individually impossible in the sense of Art. 14 (5) (b) GDPR, and the law then asks us to make the information public instead. This paragraph is that.
What you can do: the rights under Your rights are yours too. Write to us and we will tell you what we can — which, for a photo that was never stored, is usually that there is nothing left to give you. Our terms oblige every user not to photograph other people, and we are building the stronger measure: blurring faces on the device before anything is sent. Until that ships, this paragraph is the honest state of affairs rather than a promise.
If a friend used your invite code
When someone enters an invite code, a line is created that ties them to the person who invited them. That person then learns that an invitation was taken up and, later, that a subscription was paid for — never who you are, never your email address, never anything you logged. What they see is a count and an amount.
The source is the person who invited you: the code came from them. You can object at any time under Your rights; the line is then removed, and it takes the reward with it.
Children and young people
Cal 3D is intended for people aged 16 and over. We do not knowingly collect data from children under 16. If we learn that such data has reached us, we delete it. Parents and guardians can contact us at support@cal3d.app.
If you are in the United States
The rules below apply in addition to everything above, not instead of it. Cal 3D is built to European standards, and those are the stricter ones — you keep every right from this policy wherever you live.
Washington
The My Health My Data Act gives residents of Washington their own set of rights over consumer health data, and it requires a separate policy for them. Ours is here: Washington Consumer Health Data Privacy Policy.
California
Under the CCPA you may ask what personal information we collected about you in the past twelve months, ask for a copy, ask us to correct it, and ask us to delete it. You may also ask whether we sold or shared it.
We have not sold or shared personal information, and we do not intend to. There is no advertising network, no cross-context behavioural advertising and no data broker in this app — so there is nothing to opt out of, and no Do Not Sell link, because such a link would suggest a practice that does not exist.
We will not treat you differently for exercising any of these rights. Write to support@cal3d.app; we answer within 45 days and may extend once by another 45 where a request is complex.
Other states
Connecticut, Texas, Colorado, Virginia, Oregon and Utah give comparable rights — access, correction, deletion, a copy of your data, and an appeal if we say no. Nevada is different: its law (NRS 603A) gives you a right to opt out of the sale of certain data and nothing beyond that.
It makes no difference in practice. Use the same address; we apply the same process to every request regardless of which state you write from, because sorting people by postcode would be the more error-prone approach.
For the sale of consumer health data, Washington requires a separate signed authorisation. We have never asked for one and will not, because we do not sell it.
Changes to this policy
When the app changes, this policy changes with it. The version published here is always the applicable one; the date of its last change is shown at the top of this page.
For changes that materially affect you — a new recipient or a new purpose, for instance — we additionally point them out inside the app rather than folding them in here quietly.
What has changed
- Cal 3D is now also available on Google Play, and purchases made there go through Google Commerce Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. That company is therefore new in the list of recipients: it is the seller and it handles the payment. Your payment method never reaches us — for a purchase on Android we only receive the country, an order number, a purchase token, the time and the amount, so neither your name nor your address nor your card details. Nothing changes for App Store purchases. Withdrawal and refunds follow the terms of whichever store you bought from; both routes are now on the “Cancellation and refunds” page.
- The app now contains Firebase Analytics and Firebase Crashlytics from Google. Usage statistics are sent only if you allow it: the app asks once, on its first screen, and you can change your answer at any time under Preferences. What is sent are event names without values, such as which screens you use, by which route you logged a meal and whether a scan succeeded, and never what you eat, your weight, your name or your email address. Crash reports are sent automatically so that we can fix defects; you can switch them off under Preferences as well. A new section, “Usage statistics and crash reports”, says what exactly is sent, on which legal basis, for how long (14 months for usage statistics, 90 days for crash reports) and how to object. Google LLC has been added to the list of recipients and to the transfers outside the EU.
- A new section says what happens to your message after it reaches us. From today a program looks into our mailbox every hour and sorts new messages by fixed rules, so that an urgent matter does not sit unread. We then get a short notification on the phone. That notification contains nothing from your message: not the text, not the subject, not your address — only the classification and a short code that only we can match to your message. The reason is that the notification travels through a messenger operated outside the EU. A language model never gets to see your message at all; it only judges mail from companies. This is not a statement of intent but a rule inside the program: mail from private individuals is never handed over in the first place, and nothing about it is stored either, beyond the code and the classification.
- How you give consent for your health data has changed, and this policy has been corrected to describe what the app now does. Until today the app put a separate step in front of the first sign-in, with tick boxes that had to be filled in before anything happened, and this policy said so. That step is gone. The declaration now stands in plain words above the sign-in buttons: it names the data by name — your health and fitness data, meaning weight, goals, meals and workouts — and says that it will be stored in your account and synced between your devices. It is a separate line from the one that accepts the terms, and tapping a sign-in button is the act that gives both. Nothing you cannot decline is bundled into it: the marketing option stays off unless you switch it on yourself. What is processed did not change — only the moment and the manner in which you agree to it. The sentence that described the old tick box had become untrue on the day the app changed, which is why it was replaced rather than left standing. In the same step three contradictions were removed that had crept in with it. The scan section said there was no consent dialog before the first scan while naming your explicit consent as its legal basis — it now points at the one consent you give when you sign in, because that is the same processing of the same data. The report and the wrong-estimate sections said they need no account and, three paragraphs on, rested on the consent given at sign-in; the first half was the outdated one and is gone. And the line about withdrawing consent promised a switch in the app settings: there is none, so it now names the route that exists, which is deleting the account.
- This policy is now available in German as well, at /datenschutz/, and that version is the one that governs for consumers in Germany. Nothing about the processing changed with it — what changed is that the people it is written for can read it in the language the app speaks to them in. Art. 12 (1) GDPR asks for information that is intelligible and in clear and plain language, and recital 58 says the same; for an app offered in German, an English-only notice does not meet that. The recipients table and the transfer mechanisms are rendered from the same source in both languages, so neither can quietly gain or lose an entry the other does not have. The German terms, withdrawal page and referral terms were published on the same day for the same reason.
- Six things were added that were missing, and four sentences were corrected that were not true. Added: a section on Apple Health, which the app can read two values from — your step count and the active energy you burned, read-only, never written back, and they stay on the device; a paragraph saying that the app’s storage is part of your iCloud backup unless you switch that off, which is between you and Apple and out of our reach; Sign in with Google as a third way to sign in, together with Google LLC as a recipient in the United States; a section on reporting a wrong estimate, which says plainly that reports are kept in three groups so the recognition can be improved; a section on the summary report you mail yourself, which is kept on our server for three days so the download link works; a section on the referral programme and the notification it sends; and a section on data that is not yours — people who end up in someone else’s photo, and friends who used an invite code (Art. 14 GDPR, which was missing entirely). Corrected: the summary no longer says we hold nothing about you without an account, because a reported estimate, the summary report and two one-way hashes do reach us; the retention period for a payment record is eight years, not ten (§ 147 (3) in conjunction with (1) no. 4 AO and § 257 (4) HGB set eight years for accounting vouchers — ten applies to ledgers and annual accounts); the quota hash is kept at most seven days rather than “until the table is next cleaned up”, and all three hashes are now listed separately with their own period; and Nevada was taken out of the list of states granting access and correction rights, because its law (NRS 603A) grants only a right to opt out of the sale of certain data.
- Accounts and sync are now described. Signing in is optional and creates an account; with one, your profile, diary, foods, water, workouts and weight history are stored for you at Supabase in Frankfurt and synced between your own devices. The new section “Account and sync” names what is uploaded, what never is (photos and their file paths), the legal bases — Art. 6 (1) (b) GDPR for the sync and your explicit consent under Art. 9 (2) (a) for the health data within it — and how to delete the account from inside the app. The previous version said there was no account at all, which stopped being true when the sync was introduced. Five further corrections were made in the same step, all of them things the earlier text got wrong rather than new processing: our mail provider Resend, Inc. is now named as a recipient of the summary report you can ask the app to send you; the report that reaches it (your name, your address, your goals, your daily totals and your weigh-ins) is described instead of the earlier claim that the app had no export at all; reporting a wrong estimate is named as something that reaches us and is stored, including anything you type into it, and it works without an account; the retention section now says which two records survive deleting your account and why (a referral you redeemed, so your friend keeps their reward, and a reward actually paid out, which § 147 AO and § 257 HGB require us to keep for eight years); and the sentence “no feature is locked behind an account” has been corrected, because rewards for referring a friend are. The overview table under “Retention and deletion” now lists those two records itself, together with the wrong estimate you can report — they were described in the text but missing from the table, which is the half a reader is most likely to take for the whole answer. Finally, subscriptions have gone live, and with them a new recipient: RevenueCat, Inc. in the United States checks whether your subscription is active. What reaches it is the purchase status and one identifier — a random one while you are not signed in, the identifier of your account once you are. We also keep a record of each purchase message on our own side, and that record is not deleted with your account; it is listed under “Retention and deletion” and on the delete-your-data page, together with the fact that deleting your account does not reach your record at RevenueCat either.
- The hosting section now names Vercel Inc. in the United States as the company that runs the servers of this website, along with the transfer mechanism that applies to it: Art. 45 GDPR under the EU-US Data Privacy Framework, backed by standard contractual clauses under Art. 46 (2) (c). The previous version named a German provider, which was wrong — this website has been served from Vercel since its first day online.
- Initial version. It describes all three ways something reaches the AI model (a photo of a meal, a food name you type, a workout you describe), names your explicit consent under Art. 9 (2) (a) GDPR as the legal basis for them, gives every recipient outside the EEA its own transfer mechanism instead of one collective clause, and names the provider of our mailbox as a controller in its own right.
The list starts on 2026-08-15, the day this policy was first published. There is no earlier version that it could differ from.