Version 1.7 - As of: 03.08.2026

Privacy Policy for Project Prime

This privacy policy describes how personal data is processed when using the mobile app Project Prime, the coach area, and the nutrition, training, recipe, supplement and premium features.

It applies to the Project Prime app, the associated backend services, the public website and all features directly connected to the app.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Dennis Vollmer
Wiehenstraße 28
32289 Rödinghausen
Germany
Email: pt@dennis-vollmer.de

Wherever this privacy policy refers to "we", "us", "Project Prime" or "the app", this refers to the controller named above.

2. Scope

Project Prime is a coaching and tracking app for nutrition, training, body data, progress tracking, recipe management, supplement planning and optional premium features.

The app is aimed at users who want to document and evaluate their nutrition, training and progress data. Depending on usage, data may also be shown to a coach if a corresponding coach access or coach assignment exists.

This privacy policy applies to:

3. Brief overview

Project Prime processes in particular account, profile, body, nutrition, training, activity, recipe, supplement, payment status and technical usage data.

Some of this data may constitute health data within the meaning of Art. 9 GDPR or allow conclusions to be drawn about health, fitness, weight development, nutrition, training behavior and lifestyle.

Photos are only processed if users actively use a corresponding feature, for example for loose food items, dishes, meals, barcodes, packaging or nutrition tables.

Project Prime prioritizes its own database entries. External queries and AI analyses are only meant to take place when required for the respective feature.

Users can delete their account. In doing so, personal data is deleted unless legal retention obligations or legitimate reasons prevent this. General, non-personal food or recipe data may be retained if it is needed for the app's functionality and no longer contains any direct personal reference.

4. Definitions

Personal data is any information relating to an identified or identifiable natural person.

Health data is personal data relating to physical or mental health that can reveal information about a person's state of health.

Processing includes any handling of personal data, for example collecting, storing, displaying, calculating, evaluating, transmitting, deleting or providing.

Coach means an authorized person who, within the app or a coaching relationship, can gain insight into shared or assigned user information.

5. What data does Project Prime process?

5.1 Account and access data

5.2 Profile and coaching data

5.3 Body and goal data

5.4 Nutrition data

5.5 Beverages

Beverages may be processed like food if they are relevant for nutrition tracking, for example cola, juice, dairy drinks, smoothies or alcoholic beverages. Name, quantity, calories, macronutrients and, where applicable, barcode or product information may be recorded.

5.6 Training and activity data

5.7 Photo, camera and image data

Photos are generally only processed for analysis triggered by the user. Users should not upload photos that show uninvolved third parties, private documents, addresses or other unnecessary personal information.

5.8 Recipe, dish and community data

5.9 Supplement data

5.10 Health and activity data from the device

As far as users actively connect the feature, Project Prime can retrieve step counts or comparable activity data from Health Connect on Android or Apple Health/HealthKit on iOS. The connection is only established after explicit authorization within the operating system. Users can revoke this authorization at any time in their device settings.

5.11 Premium, subscription and payment status

Payment data such as complete credit card information is not processed by Project Prime itself, but through the respective app store providers, as far as in-app purchases or subscriptions are offered.

5.12 Technical data

5.13 Level, badge and streak data

Project Prime calculates an internal experience point total (XP) and a level derived from it based on activities already recorded (for example meals, training, weight, steps, water and supplements). Users can select an unlocked badge to be displayed on their profile picture.

Regular app use is likewise used to calculate and display a streak (number of consecutive active days), the status of any streak protection shields, and progress on weekly quests.

This does not involve collecting any additional personal data beyond what is already described elsewhere in this policy. XP total, level, selected badge, streak status and weekly quest progress are stored via the Supabase backend, like the other app data.

5.14 Creator code data

Users can redeem a partner's creator code once to receive a time-limited free premium period. In doing so, the redeemed code, the time of redemption and the end date of the trial period may be stored.

If the user takes out a genuine subscription after or during the trial period, it may be recorded internally that this purchase can be linked to a prior code redemption. This link is used exclusively to calculate revenue-share payments to the respective partner and to measure the performance of individual codes. Partners do not receive any individual personal data, only aggregated figures, for example the number of redemptions and the resulting purchases per code.

6. Purposes of processing

Processing takes place in particular for the following purposes:

7. Legal bases

We only process personal data if there is a legal basis for doing so. Depending on the feature, the following legal bases apply in particular:

Processing Legal basis
Account, login, app features, premium features and coaching services Art. 6(1)(b) GDPR, contract or pre-contractual measures
Health, fitness, nutrition, training and progress data Art. 9(2)(a) GDPR, explicit consent; additionally Art. 6(1)(a) or (b) GDPR
Camera, photo, barcode, packaging and dish analysis Art. 6(1)(a) GDPR; additionally Art. 9(2)(a) GDPR where health-related
Health Connect or Apple Health data Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR where health-related
Coach access to user progress Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR where health-related
Recipe moderation, abuse prevention and security checks Art. 6(1)(f) GDPR, legitimate interest in safe and lawful app use
Internal usage and conversion analysis, for example for premium notices Art. 6(1)(f) GDPR, legitimate interest in improving the product and offers
Redeeming creator codes and revenue-share reporting to partners Art. 6(1)(b) GDPR (granting the trial period) and Art. 6(1)(f) GDPR, legitimate interest in accounting for partnerships
Technical security data, update checks and error analysis Art. 6(1)(f) GDPR, legitimate interest in security and functionality
Statutory retention and documentation obligations Art. 6(1)(c) GDPR

8. Consent when the app is first launched

When the app is launched for the first time, the user is actively asked to consent to Project Prime processing health, fitness, nutrition, training, photo and progress data in order to provide the app.

Consent must not be pre-selected. The user must be able to open the privacy policy and must actively confirm the processing.

Without this consent, features that process health and fitness data cannot be used, or can only be used to a limited extent.

Example of the consent text in the app:

"I have read the privacy policy and consent to Project Prime processing my health, fitness, nutrition, training and progress data in order to provide me with the app features and coaching. I can withdraw my consent at any time with effect for the future."

9. Registration, login and password

A user account is required to use the app. Users register with an email address and a password. The password is not stored in plain text.

During registration, a password may need to be repeated to avoid input errors. To recover a forgotten password, users can use the email features of the authentication provider, where these are enabled.

Alternatively, users can log in with "Continue with Google" or "Continue with Apple". In this case, Google or Apple confirms the user's identity and transmits a technical login token as well as, where released by the user, email address and name to our authentication provider, so that it can create or recognize a user account. No password is stored with us in this case. Apple also allows a private relay email address to be used instead of the real email address.

Login sessions can be stored locally on the device so that users do not have to log in again every time they start the app.

10. Supabase as backend service

Project Prime uses Supabase as a backend service for authentication, database, access protection, role management and storage of app data.

Supabase may in particular process account, profile, nutrition, training, weight, role, premium, recipe, food, supplement, update and review data records.

Supabase may be used as a data processor. According to the current state of the project, the server region is Frankfurt, Germany, or the EU.

Access to data is restricted by technical rules, roles and access rights. Users should generally only be able to see their own personal data. Coach or admin access is to be restricted to authorized accounts.

11. In-house food and product database

Project Prime uses its own food and product database. When a user adds a food item, beverage or product, a data record with name, nutritional values, brand, barcode/EAN, portion information, search terms and source may be stored.

The goal is to answer future search queries faster, more reliably and with fewer external requests. If an entry is reliably found in the in-house database, it can be used without a renewed AI query.

General food items without a brand, for example "apple", "skyr", "iceberg lettuce" or "whole grain bread", may be stored as general baseline values. Branded products captured via barcode or packaging may additionally be stored with barcode and brand.

Such data records generally serve the general functionality of the app and are not intended to be permanently displayed publicly in association with a specific person. They may be retained after deletion of a user account if they no longer contain any personal reference.

12. Manual food search

Users can manually search for food and beverages. The app searches its own database first. If a matching general or saved entry exists, it is shown preferentially.

If no matching in-house entry is found and it is a general food item or beverage without a specific brand, the app may estimate nutritional values or supplement them from external sources. If a specific brand or product is searched for and is not available, the app may point to barcode scanning or a product photo.

Manual search may be limited in the free plan. Search queries may be counted in order to technically implement free and premium features.

13. Barcode scanning and packaged food

For packaged food, users can scan the barcode. The app first checks its own database. If a matching data record is found there, the product can be shown without AI analysis and without an external product search.

If the product is not known, the app may query OpenFoodFacts using the barcode. If plausible nutritional values are found there, they can be displayed and, after confirmation, stored in the in-house database.

If insufficient data is found, the app may ask the user to photograph the front of the package and the nutrition table. Product name, brand, nutritional values and, where applicable, portion information can be extracted from this.

If a portion, piece, bar or comparable unit is recognized, it may be shown as an additional selection option. By default, the value per 100 g should be shown unless something else is selected.

Barcode products that were not found or were entered manually may be stored in a review list so that the information can later be checked or corrected.

14. Loose food items

For loose food items, for example fruit, vegetables, meat, eggs, cheese, bread or salad without a barcode, users can take a photo. The AI can first recognize which food item is shown.

The app then searches its own database first. If a reliable match is found there, the nutritional values from the database are used. An additional AI nutrition estimate is then generally not required.

If no reliable match is found, the app may estimate nutritional values or supplement them from external sources and save the entry after confirmation. If a typical portion can reasonably be determined, for example for an apple, banana, egg, slice of bread or similar food items, a portion unit may additionally be saved.

15. Photographing a dish or meal

Users can photograph dishes or meals, for example plates, bowls, tartare rolls, döner, currywurst or filled bread rolls. Users can additionally enter a note, such as "the meat is venison" or "name: chili con carne".

The app can estimate the dish and show an overall figure for calories and macronutrients. Alternatively, recognized components can be entered individually.

In the background, the app can compare recognized components with its own database. If components are not available, general baseline values may be generated and saved so that future recognitions are cheaper and more consistent.

Users can optionally save an estimated dish for themselves. Saved dishes are generally personal entries of the respective account and are not automatically visible to all users.

Estimated dishes may additionally be saved as a review record so that the plausibility of the estimates can be checked and improved.

16. Capturing, dictating and saving recipes

Users can manually capture recipes or dictate ingredients by voice. Voice input uses the operating system's speech recognition, where available. Users can enter ingredients with quantities, grams, count or comparable units.

Required fields may in particular be the name of the dish and the number of servings. The app calculates the nutritional values of the overall recipe and the desired serving from the ingredients and quantities.

For ingredients, the app searches its own database first. If ingredients are not available, general nutritional values may be estimated and saved as a baseline value. Where appropriate, a typical portion, piece count or slice may additionally be saved.

Users can save their own recipes personally and select them again later. Personal recipes can be deleted again by the user.

Users can voluntarily make a recipe available to the community. In this case, preparation instructions must be provided. The recipe is first reviewed and only becomes visible to other users after approval.

17. Community recipes and moderation

Submitted community recipes may contain name, ingredients, preparation instructions, servings, calories, protein, categories, notes and other nutritional values.

Since community recipes may later be shown to other users, users may not submit personal data, insults, discriminatory content, unlawful content, confidential information belonging to others, or content that is problematic under copyright law.

New recipe ideas are first saved for review. The app may carry out an AI pre-check, in particular for grossly inappropriate, insulting, discriminatory, racist, sexist or otherwise unlawful content. In addition, a manual approval is carried out by the controller or an authorized person.

Community recipes are only intended to become generally visible after approval. Until then, users may be shown a note such as "submitted for review".

If a user account is deleted, approved recipe ideas may generally be retained if they no longer contain any personal reference. If recipe ideas contain personal data, this data is deleted or anonymized upon request.

18. Supplement features

Project Prime may contain a supplement area. Users can manually enter supplements or receive a non-binding suggestion based on voluntary answers.

Questions may be asked about diet, fish consumption, meat consumption, vegetarian or vegan diets, known deficiencies, individual notes and personal goals.

The information serves to create a structured overview or reminder for dietary supplements. It does not replace a medical diagnosis, laboratory test or medical advice.

Users can adjust, remove, manually add and check off suggested supplements daily, where this feature is used.

19. Health Connect and Apple Health

Project Prime can retrieve step counts or comparable activity data from Health Connect on Android or Apple Health on iOS if users actively connect this and grant permission.

The app may attempt to synchronize current step counts when opening relevant areas, for example the diary or statistics. Permanent background synchronization is only possible within the technical capabilities of the respective operating system.

Users can revoke this permission at any time in the settings of their device or the respective health app. Without permission, steps can still be entered manually.

20. AI analysis with Google Gemini

Project Prime uses Google Gemini for selected AI features, for example recognition of food items, dishes, meals, packaging, brands and product names, reading nutrition tables, estimating dishes, recipe and ingredient processing, moderation checks, as well as translating or normalizing search terms, where required.

For AI analysis, image data, product names, nutritional information, ingredient lists, user notes and technical context information may be transmitted to Google. Only the data required for the respective analysis is intended to be transmitted.

AI results may be inaccurate or incomplete. Users should review entries and can adjust recognized values in the app, as far as the feature allows for this.

The app is designed to prioritize confirmed in-house database entries in order to avoid unnecessary AI queries.

21. OpenFoodFacts and USDA

OpenFoodFacts may be used to retrieve product information and nutritional values, in particular for packaged food and barcodes.

USDA may serve as an additional data source for general food items, in particular if in-house or German data is not sufficient. The app is intended to use external data sources sparingly and to prioritize confirmed in-house data.

For external data sources, their own terms of use and privacy information may apply. OpenFoodFacts and USDA generally only receive the search query or the barcode, but no complete user profiles, unless implemented differently for technical reasons.

22. Nutrition, training, weight and statistics

Users can save food, beverages, meals, water, steps, activity calories, training days, notes, supplements and weight entries.

From this, the app creates daily overviews, statistics, progress displays, weight charts, meal targets, calorie trends, training evaluations and supplement status.

This data may be shown to the coach if the user is being supported in a coaching context and a corresponding assignment exists.

23. Coach area and coach access

The coach area allows authorized coach or admin accounts to view data of supervised users. This may include profile, body data, weight history, nutrition days, meals, training data, notes, supplement status and other progress data.

Access is to be restricted to authorized persons. Coach and admin accounts must be specially protected. Access follows the principle that only data required for supervision, evaluation and feedback should be visible.

If a coach export or comparable feature is temporarily not visible, the underlying technical tables or previous data may nevertheless continue to exist, as far as they are required for administration, evidence or later activation.

24. Premium, free plan and usage limits

Project Prime may offer a free use with a limited feature scope and a premium use. The app may count usage limits, for example manual search queries, photo analyses, recipe features or training plan features.

If a limit is reached, a notice about premium may be shown. Users can voluntarily purchase premium, as far as this feature is enabled in the App Store or on Google Play.

Individual accounts can be manually activated by the controller, for example for testing, coaching, support or goodwill purposes. In doing so, only the technical premium status required for activation is processed.

25. App Store, Google Play and payment processing

If the app is downloaded via the Apple App Store or Google Play, or a subscription is concluded there, Apple or Google process personal data under their own responsibility.

Project Prime generally only receives the information required to recognize and activate the premium status. Complete payment information such as credit card data is not stored by Project Prime.

Cancellation, plan changes, renewal and management of subscriptions generally take place via the respective app store, i.e. the Apple App Store or Google Play, as far as the subscription was concluded there.

26. Update check and forced update

The app may check at launch whether a new minimum version is required. For this, platform, app version and build number may be compared with a configuration in the backend.

If a version is no longer supported for security, functional or compatibility reasons, the app may restrict access until the update is completed. This check serves the security, error prevention and functionality of the app.

27. Local storage on the device

The app may store certain data locally on the device, for example login status, app settings, last selected values, caches and display states.

This local storage serves the usability, performance and offline availability of individual app features.

When the app is deleted, locally stored data may be removed. Data stored on the server is not automatically deleted as a result. Deleting the account within the app or a request to the controller is required for this.

28. App permissions

Permission Purpose
Camera Barcode scanning, photographing food items, dishes, meals, packaging and nutrition tables
Photos/media Selecting existing images, as far as this feature is enabled
Microphone/voice input Voice input for recipe ingredients, as far as the user uses this feature and the operating system provides it
Internet/network Login, Supabase backend, AI analysis, OpenFoodFacts/USDA queries, premium status and update check
Health Connect/Apple Health Steps and activity data, if users actively allow this connection
Notifications Only if reminders or push notices are enabled

29. Recipients and service providers

Personal data may be transmitted to the following recipients or categories of recipients, as far as this is required for the app, coaching, security or legal obligations:

30. Transfers to third countries

When using services from international providers, processing may take place outside the European Union or the European Economic Area.

In such cases, we ensure that appropriate safeguards within the meaning of the GDPR are in place, for example EU standard contractual clauses, adequacy decisions or additional protective measures.

31. Storage period

We only store personal data for as long as is necessary for the respective purposes or as long as legal obligations exist.

Account, profile, nutrition, training, weight, supplement and progress data is generally stored until account deletion or termination of use.

General, approved food, product and recipe data without a direct personal reference may continue to exist for longer so that the app database remains functional.

Review records, technical logs and security data are deleted or anonymized as soon as they are no longer required for error analysis, quality assurance, security or legal evidence.

32. Account deletion and deletion of personal data

Users can delete their account within the app, as far as this feature is provided. Alternatively, a deletion request can be sent to the contact address named above.

When an account is deleted, the user's personal data is deleted unless legal retention obligations, security reasons or legitimate interests prevent this.

In particular, the following is deleted:

General, non-personal data required for the functionality of the app database does not have to be automatically deleted, for example confirmed general food items, barcode/product data without a personal reference, or approved community recipes without a personal reference.

If such content contains personal data, users can request its deletion or anonymization.

33. Rights of data subjects

Under the GDPR, users have in particular the following rights:

Requests can be sent to pt@dennis-vollmer.de.

34. Withdrawal of consent

As far as processing is based on consent, users can withdraw this consent at any time with effect for the future.

Withdrawal may result in certain app features no longer being usable, in particular features for health, nutrition, training, health-app, photo and AI analysis.

35. Automated decisions and profiling

Project Prime creates evaluations, daily targets, meal guidelines, progress displays, AI estimates, training histories, supplement suggestions and recommendations.

These serve to support the user and the coaching. There is no exclusively automated decision with legal effect or similarly significant impact within the meaning of Art. 22 GDPR.

AI results and app evaluations may be inaccurate. They do not replace a medical diagnosis, therapy, medical advice or individual nutritional counseling by an appropriately qualified body.

36. Data security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.

These include in particular:

37. Minors

The app is generally not aimed at children. Should the app be used by minors, it should first be checked whether consent from a parent or legal guardian is required.

38. Google Play Data Safety and Apple Privacy Labels

For publication of the app in the Google Play Store and the Apple App Store, privacy information is provided in accordance with the actual data processing.

Based on the current feature scope, Project Prime in particular processes the following categories of data:

The information in the privacy details of the respective app stores is updated accordingly when the feature scope changes.

39. Website, support and contact

The public Project Prime website provides information on the app, support, privacy, terms of use and legal notice.

If users contact us by email, the information provided is processed in order to answer the inquiry. This may include email address, name, content of the inquiry and accompanying technical information.

40. Changes to this privacy policy

We may adapt this privacy policy if features, providers, the legal situation or technical processes change.

The current version is made available in the app or via a suitable link. In the event of material changes, a notice may be given in the app.

41. Contact for privacy questions

For questions about data protection, exercising rights or account deletion, users can contact the controller at the following address:

pt@dennis-vollmer.de

Appendix A: Overview of key processing activities

Area Data Purpose Storage/recipient
Account Email, login, session data Registration and access protection Supabase Auth, backend
Profile Name, goal, profile picture Personalization and coaching Supabase, coach view
Body data Weight, height, age, gender, target weight Daily targets, history and evaluation Supabase, coach view
Nutrition Food, beverages, grams, portions, nutritional values, meal Tracking and daily overview Supabase, in-house food database
Training Training day, exercises, sets, weights, duration, notes Training plan, training log and evaluation Supabase, coach view
Photos Food, packaging, nutrition, recipe and dish photos Recognition, estimation and quality assurance Temporary/AI provider, possibly backend review
Barcode EAN/barcode, product name, brand, nutritional values Product search and reuse In-house database, OpenFoodFacts
AI Image data, prompts, user notes, result data Recognition, estimation, moderation Google Gemini
Recipes Name, ingredients, preparation, categories, moderation status Personal recipes and community recipes Supabase, visible only after approval
Supplements Answers, suggestions, selected supplements, daily status Supplement overview and daily reminder/check-off function Supabase
Level/badges/streak XP total, level, selected badge, streak status, streak protection shields, weekly quest progress Motivation and progress display Supabase
Health data Steps and activity data Automatic daily update Health Connect/Apple Health, Supabase after saving
Premium Plan, term, premium status Activation of premium features Apple/Google, Supabase
Creator code Redeemed code, redemption time, trial end date, possibly a link to a later purchase Granting the trial period and aggregated revenue-share reporting Supabase, partners receive only aggregated figures per code
Login Login token, email, name (for Google/Apple login) Creating or recognizing an account Google, Apple, Supabase Auth
Usage analysis Trigger area and time of a premium notice Product and offer improvement Supabase
Coach User progress, daily data, notes Support and feedback Coach/admin access