Privacy Policy

Last updated: July 31, 2026 (version 2026-07-31)

1. Who is responsible (data controller)

Nutrition-App is a paid, subscription-based nutrition tracking service. The data controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:

Mirza Herdic, Louise-Martini-Weg 3/4, 1030 Vienna, Austria.

Full provider details are in our Impressum. Our lead supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde, DSB). For any privacy question or to exercise your rights, contact us at (contact address to be confirmed).

2. Data we collect

When you create an account and use the app, we process the following categories of data:

  • Account information — email address and password (hashed by Supabase Auth)
  • Profile and health data — date of birth, sex, height, weight, body fat percentage, activity level, weight goals, and (optionally) pregnancy or lactation status
  • Dietary preferences — diet type and dietary restrictions (optional)
  • Meal and nutrition data — meals you log, meal plans, food items, quantities, and recipes you import
  • Consented food-search selections — for logged-in users who accept analytics, a keyed search fingerprint, selected food or concept, pre-sort relevance position, search context, ranking version, and timestamp. We do not store the plaintext search.
  • Payment data — handled by Stripe (see processors below). We receive your billing email and subscription status; we never see or store your full card number.
  • Push notification data — if you opt in to push notifications, a push subscription (a device identifier issued by your browser's push service) and your notification preferences (which notification types you have enabled). The notification content we send is encrypted in transit.
  • Product-test participation — if you join a time-bounded product test, the campaign, signup and test dates, and your versioned permission to receive test-specific follow-up. If you use the linked Google Form, Google also stores your responder email, product-feedback answers, interview preference, and optional timezone or availability. The form asks you not to submit health data or detailed diary entries.

Body metrics, date of birth, sex, activity level, and any pregnancy or lactation status are health-related data and count as a special category of personal data under Article 9 GDPR.

3. Why we process it (lawful bases)

  • Performance of our contract with you (Art. 6(1)(b)) — to deliver the service: calculate your personalized nutrition targets, score foods and meals, store your meal history and plans, and import recipes you submit.
  • Your explicit consent for health data (Art. 9(2)(a)) — processing the required body metrics, date of birth, sex, and activity level needed to compute your targets is anchored on a separate, explicit health-processing consent you give at signup.
  • Separate, revocable consent for pregnancy / lactation (Art. 9(2)(a)) — these optional fields are only processed if you switch on a dedicated consent in your profile. You can revoke it at any time with one click, which clears those fields; the rest of the app keeps working.
  • Your consent for push notifications (Art. 6(1)(a)), and Art. 49(1)(a) consent for the international transfer — push notifications are off until you opt in. Apple Safari and Firefox route push delivery through US-based services for which the usual transfer safeguards (Standard Contractual Clauses) are not available, so before we enable notifications we ask for your explicit, specific consent to that transfer under the Art. 49(1)(a) derogation. Google FCM and Microsoft WNS use the EU-US Data Privacy Framework safeguard instead. You can withdraw push consent at any time (see below).
  • Your consent for product-test follow-up (Art. 6(1)(a)) — if you join a time-bounded test, we use your account email only for that test's check-in and optional interview invitation. You can withdraw by replying to a research email or contacting us.
  • Your analytics consent (Art. 6(1)(a)) — for PostHog, client-side Sentry, and first-party food-search selection learning. Search learning uses Supabase in the EU, stores no plaintext query, and is separate from PostHog.
  • Legitimate interests / legal obligation — keeping the service stable (server-side error monitoring) and retaining billing records for the period required by law.

We do not use your data for advertising, for selling to third parties, or beyond the app's core functionality and any time-bounded product research you explicitly join.

4. Third-party processors

We use the following processors. Providers in the EU involve no international data transfer. The US-based providers below are covered either by their data processing agreements (EU-US Data Privacy Framework certification and/or Standard Contractual Clauses) or, for the browser push services where those safeguards are not available, by your explicit consent to the transfer (see lawful bases above).

  • Supabase — database hosting and authentication, in Frankfurt (EU). Your data is stored in a PostgreSQL database with row-level security so you can only access your own data.
  • Vercel — application hosting, with functions pinned to Frankfurt (fra1, EU). The platform data processing agreement plus DPF cover residual control-plane and request logs (which may include IP addresses).
  • Google Forms and Google Sheets — used for the optional seven-day beta check-in and interview request. Google receives your responder email and the answers you choose to submit. Processing may involve the United States and is covered by Google's Workspace data-processing terms and transfer safeguards.
  • OpenAI (US) — used server-side only to parse recipe text when you import a recipe. Only the recipe text is sent; no profile, health, or account data. OpenAI does not train on data sent through its API. Covered by DPF/SCCs.
  • PostHog — product analytics, on EU cloud. Captures usage events only after you grant analytics consent (see below); sets no cookies and captures no events until then.
  • Sentry — error monitoring, in the EU. Client-side (in-browser) error reports are only sent after you grant consent. Server-side and edge monitoring runs on a legitimate-interest basis with no browser cookies or identifiers.
  • Stripe (US) — payment processing. Stripe receives your billing email and subscription details to take payment. Covered by DPF/SCCs.
  • Browser push services — if you enable push notifications, your browser routes delivery through its own push service: Google (Firebase Cloud Messaging, US) for Chrome/Chromium/Android, Microsoft (Windows Push Notification Service, with Microsoft Corporation as the US recipient, for Windows Edge), Apple (APNs, US) for Safari and installed iOS apps, or Mozilla (US) for Firefox. They receive your push subscription endpoint (a device identifier), delivery metadata, and the encrypted notification needed for delivery. Google and Microsoft rely on the EU-US Data Privacy Framework; transfers to Apple and Mozilla rest on your explicit consent under Art. 49(1)(a), because Standard Contractual Clauses are not available for these browser-determined services. Microsoft does not publish a WNS-specific EU data-residency commitment. We will not activate WNS until an external release review confirms its notifications exclude confidential, sensitive, directly identifying, and detailed diary content.

Grocery prices shown in the app are entered by users. No personal data is sent to any retailer, and no retailer is a processor of your data.

5. Analytics and error-monitoring consent

Product analytics (PostHog), client-side error monitoring (Sentry), and first-party food-search selection learning are non-essential and off by default. A banner asks you to accept or reject them with equal prominence. Until you accept, no analytics cookies, usage events, in-browser error reports, or selection records are sent.

Food-search requests transit our Vercel gateway in Frankfurt before reaching Supabase in the EU. After you deliberately select a food, we may store a keyed search fingerprint, selected food or concept, pre-sort relevance position, search context, ranking version, and timestamp. The plaintext search is request-ephemeral: never stored or sent to PostHog. Derived popularity appears only after five consenting users and exposes no counts or identities.

Your choice is stored in a single first-party preference cookie and, if you are logged in, on your profile so it follows you across devices. You can change it at any time:

  • Logged in: the Privacy section under Account Settings in your profile.
  • Logged out: the "Cookie preferences" link in the page footer.

6. Push notifications

Push notifications are optional and off by default. Before your browser asks for permission, we show a short prompt explaining what you will receive and that enabling notifications sends a device identifier to your browser's push service. For Windows Edge, this is Microsoft's Windows Push Notification Service, for which Microsoft Corporation is the US recipient. It relies on the EU-US Data Privacy Framework and has no published WNS-specific EU data-residency commitment. Safari and Firefox use US services that may not offer EU-equivalent data protection or legal redress, so their transfer relies on your explicit consent under Art. 49(1)(a). We only enable notifications after you give the applicable explicit consent. We will not activate WNS until an external release review confirms its notifications exclude confidential, sensitive, directly identifying, and detailed diary content.

Once enabled, all notification types are on, and you can switch any of them off individually, or turn off push entirely, in the Privacy section under Account Settings. Turning off push deletes your push subscription, and withdrawing the transfer consent both stops delivery and erases the stored subscription, so nothing further is transferred.

7. Cookies

The app uses an authentication cookie to maintain your login session and a single first-party preference cookie that remembers your analytics/error-monitoring consent choice. Signup may also use a short-lived first-party cookie to carry your recorded acceptance and beta-test attribution through a Google sign-in redirect; it is deleted by the callback. No advertising cookies or third-party tracking cookies are used. Analytics (PostHog) sets no cookies unless and until you grant consent.

8. Data retention and deletion

Your data is retained for as long as your account exists. When you delete your account:

  • Your user-authored content — saved meals, recipes, and your profile — is hard-deleted.
  • Your activity history is retained only in an irreversibly anonymized form that can never be linked back to you. We keep no mapping that would let us re-identify it, so this is genuine anonymization, not pseudonymization.
  • Any push subscription and notification preferences are hard-deleted. They are also deleted as soon as you turn off push or withdraw the transfer consent, without waiting for account deletion.
  • A product-test roster entry is deleted when you delete your account. The roster entry and its Google Form/linked-Sheet response are otherwise scheduled for deletion 90 days after that test ends.
  • Consented food-search selection records are retained for the account lifetime, included in your data export, and hard-deleted with your account. Withdrawing analytics consent stops new records immediately.

Deleted data may persist for a short period in our infrastructure provider's encrypted backups before those backups roll off (currently up to 7 days). Billing records are kept for the period required by law.

9. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data via your profile settings
  • Erase your account and data (see retention above)
  • Receive your data in a portable format
  • Withdraw consent at any time — analytics/error-monitoring consent via account settings or the "Cookie preferences" footer link (also stopping food-search selection learning), optional pregnancy/lactation health consent via your profile, and push notifications, including transfer consent, via account settings. Withdraw product-test follow-up consent by replying to a research email or contacting us
  • Lodge a complaint with a supervisory authority (for us, the Austrian DSB)

To exercise any of these rights, use the account settings within the app or contact us at (contact address to be confirmed).

10. Children and minimum age

This service is not intended for anyone under 16 years of age. You must confirm you are at least 16 when you sign up, and your date of birth is validated again during onboarding and on profile edits. We do not knowingly collect data from children under 16.

11. Changes to this policy

This policy may be updated as the service evolves. The version and "last updated" date at the top reflect the most recent revision.

12. Contact

For privacy-related questions or requests, contact us at (contact address to be confirmed). Provider details are in our Impressum.