Privacy Policy for Project Prime
This privacy policy describes how personal data is processed when using the mobile app Project Prime, the coach area, and the nutrition, training, recipe, supplement and premium features.
It applies to the Project Prime app, the associated backend services, the public website and all features directly connected to the app.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dennis Vollmer
Wiehenstraße 28
32289 Rödinghausen
Germany
Email: pt@dennis-vollmer.de
Wherever this privacy policy refers to "we", "us", "Project Prime" or "the app", this refers to the controller named above.
2. Scope
Project Prime is a coaching and tracking app for nutrition, training, body data, progress tracking, recipe management, supplement planning and optional premium features.
The app is aimed at users who want to document and evaluate their nutrition, training and progress data. Depending on usage, data may also be shown to a coach if a corresponding coach access or coach assignment exists.
This privacy policy applies to:
- the mobile Project Prime app for iOS and Android,
- registration, login and account management,
- the Supabase backend and the app data stored there,
- the coach and admin area, where used,
- food, barcode, photo, recipe and AI features,
- supplement features and daily overviews,
- premium, subscription and in-app purchase features, where offered,
- the public website with legal notice, privacy policy, terms of use and support.
3. Brief overview
Project Prime processes in particular account, profile, body, nutrition, training, activity, recipe, supplement, payment status and technical usage data.
Some of this data may constitute health data within the meaning of Art. 9 GDPR or allow conclusions to be drawn about health, fitness, weight development, nutrition, training behavior and lifestyle.
Photos are only processed if users actively use a corresponding feature, for example for loose food items, dishes, meals, barcodes, packaging or nutrition tables.
Project Prime prioritizes its own database entries. External queries and AI analyses are only meant to take place when required for the respective feature.
Users can delete their account. In doing so, personal data is deleted unless legal retention obligations or legitimate reasons prevent this. General, non-personal food or recipe data may be retained if it is needed for the app's functionality and no longer contains any direct personal reference.
4. Definitions
Personal data is any information relating to an identified or identifiable natural person.
Health data is personal data relating to physical or mental health that can reveal information about a person's state of health.
Processing includes any handling of personal data, for example collecting, storing, displaying, calculating, evaluating, transmitting, deleting or providing.
Coach means an authorized person who, within the app or a coaching relationship, can gain insight into shared or assigned user information.
5. What data does Project Prime process?
5.1 Account and access data
- email address,
- password in a technically protected form,
- login status and session data,
- times of registration and login,
- technical authentication information,
- role information, for example user, coach or admin, where applicable.
5.2 Profile and coaching data
- name or display name,
- profile picture, if voluntarily provided,
- coaching goal, for example losing weight, losing fat, building muscle, maintaining weight or gaining weight,
- coach assignment, if a coaching context exists,
- premium status or manually granted access, where required.
5.3 Body and goal data
- current weight, starting weight and target weight,
- weight history with date,
- height, age and gender,
- metabolic adjustment in kilocalories, if entered,
- automatically calculated daily targets for calories, protein, carbohydrates, fat, water and steps.
5.4 Nutrition data
- entered food, beverages and meals,
- meal category, for example breakfast, lunch, dinner or snack,
- grams, portions, pieces, bars, slices or other units, where available,
- calories, protein, fat, carbohydrates and other nutritional information,
- manually entered activity calories,
- daily notes in the diary,
- entries taken over from saved recipes or saved dishes.
5.5 Beverages
Beverages may be processed like food if they are relevant for nutrition tracking, for example cola, juice, dairy drinks, smoothies or alcoholic beverages. Name, quantity, calories, macronutrients and, where applicable, barcode or product information may be recorded.
5.6 Training and activity data
- training days and training notes,
- training plans, training units and exercises,
- sets, repetitions, weights and exercise performance,
- cardio training types, duration, intensity and calories burned, if entered,
- training duration via start/stop function,
- subjective information such as difficulty, energy, pump feeling, pain and comments,
- exercise progress and charts per exercise,
- evaluation of minutes and units trained over the last seven days.
5.7 Photo, camera and image data
- photos of loose food items, dishes, meals, packaging and nutrition tables,
- barcode and product images if a product is not found,
- information derived from photos, such as recognized food items, product names, brands, barcode/EAN, nutritional values and portions,
- user notes on photos, for example "the meat is venison" or "name: chili con carne".
Photos are generally only processed for analysis triggered by the user. Users should not upload photos that show uninvolved third parties, private documents, addresses or other unnecessary personal information.
5.8 Recipe, dish and community data
- own saved recipes and dishes,
- name, ingredients, quantities, units, portions and calculated nutritional values,
- preparation instructions, if a recipe is to be made available to the community,
- moderation status, AI review note, approval or rejection status,
- public display of approved recipe ideas within the app.
5.9 Supplement data
- voluntary information on diet and supplement goals,
- answers to questions about the supplement suggestion,
- additional notes voluntarily entered by users,
- selected or manually added supplements,
- daily check-off or intake status, where used.
5.10 Health and activity data from the device
As far as users actively connect the feature, Project Prime can retrieve step counts or comparable activity data from Health Connect on Android or Apple Health/HealthKit on iOS. The connection is only established after explicit authorization within the operating system. Users can revoke this authorization at any time in their device settings.
5.11 Premium, subscription and payment status
- selected plan, for example monthly or yearly,
- premium status and term information,
- store information from Apple or Google, where required for activation,
- information on whether an account was manually activated as premium.
Payment data such as complete credit card information is not processed by Project Prime itself, but through the respective app store providers, as far as in-app purchases or subscriptions are offered.
5.12 Technical data
- device and app information, where technically required,
- app version, build number and platform,
- update status and force-update configuration,
- IP address and connection data when communicating with backend, AI and database services,
- error and usage events that occur during operation of the app or backend services,
- internal, account-related usage statistics, for example from which app area a premium notice was opened,
- locally stored app states, settings and session information.
5.13 Level, badge and streak data
Project Prime calculates an internal experience point total (XP) and a level derived from it based on activities already recorded (for example meals, training, weight, steps, water and supplements). Users can select an unlocked badge to be displayed on their profile picture.
Regular app use is likewise used to calculate and display a streak (number of consecutive active days), the status of any streak protection shields, and progress on weekly quests.
This does not involve collecting any additional personal data beyond what is already described elsewhere in this policy. XP total, level, selected badge, streak status and weekly quest progress are stored via the Supabase backend, like the other app data.
5.14 Creator code data
Users can redeem a partner's creator code once to receive a time-limited free premium period. In doing so, the redeemed code, the time of redemption and the end date of the trial period may be stored.
If the user takes out a genuine subscription after or during the trial period, it may be recorded internally that this purchase can be linked to a prior code redemption. This link is used exclusively to calculate revenue-share payments to the respective partner and to measure the performance of individual codes. Partners do not receive any individual personal data, only aggregated figures, for example the number of redemptions and the resulting purchases per code.
6. Purposes of processing
Processing takes place in particular for the following purposes:
- providing the app and the user account,
- registration, login, session management and account security,
- displaying and calculating nutrition, training, water, step and weight data,
- calculating individual daily targets and meal guidelines,
- documenting progress and statistics,
- food, beverage, barcode, packaging, recipe and dish recognition,
- building and maintaining an in-house food and product database,
- reducing external AI and database queries by reusing confirmed data,
- storing personal recipes and dishes for later reuse,
- moderation and approval of community recipes,
- supplement suggestions and supplement tracking,
- calculating experience points (XP), level, streak and weekly quest progress, and displaying a selected badge,
- administering and evaluating creator codes for free trial periods, including aggregated revenue-share reporting to partners,
- coach evaluation and support, where a coaching relationship exists,
- providing premium features and managing usage limits,
- internal analysis of which app area a premium notice was opened from, in order to improve features and offers,
- troubleshooting, abuse prevention, security and technical stability,
- fulfilling legal obligations and asserting legal claims.
7. Legal bases
We only process personal data if there is a legal basis for doing so. Depending on the feature, the following legal bases apply in particular:
| Processing | Legal basis |
|---|---|
| Account, login, app features, premium features and coaching services | Art. 6(1)(b) GDPR, contract or pre-contractual measures |
| Health, fitness, nutrition, training and progress data | Art. 9(2)(a) GDPR, explicit consent; additionally Art. 6(1)(a) or (b) GDPR |
| Camera, photo, barcode, packaging and dish analysis | Art. 6(1)(a) GDPR; additionally Art. 9(2)(a) GDPR where health-related |
| Health Connect or Apple Health data | Art. 6(1)(a) GDPR; Art. 9(2)(a) GDPR where health-related |
| Coach access to user progress | Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR where health-related |
| Recipe moderation, abuse prevention and security checks | Art. 6(1)(f) GDPR, legitimate interest in safe and lawful app use |
| Internal usage and conversion analysis, for example for premium notices | Art. 6(1)(f) GDPR, legitimate interest in improving the product and offers |
| Redeeming creator codes and revenue-share reporting to partners | Art. 6(1)(b) GDPR (granting the trial period) and Art. 6(1)(f) GDPR, legitimate interest in accounting for partnerships |
| Technical security data, update checks and error analysis | Art. 6(1)(f) GDPR, legitimate interest in security and functionality |
| Statutory retention and documentation obligations | Art. 6(1)(c) GDPR |
8. Consent when the app is first launched
When the app is launched for the first time, the user is actively asked to consent to Project Prime processing health, fitness, nutrition, training, photo and progress data in order to provide the app.
Consent must not be pre-selected. The user must be able to open the privacy policy and must actively confirm the processing.
Without this consent, features that process health and fitness data cannot be used, or can only be used to a limited extent.
Example of the consent text in the app:
"I have read the privacy policy and consent to Project Prime processing my health, fitness, nutrition, training and progress data in order to provide me with the app features and coaching. I can withdraw my consent at any time with effect for the future."
9. Registration, login and password
A user account is required to use the app. Users register with an email address and a password. The password is not stored in plain text.
During registration, a password may need to be repeated to avoid input errors. To recover a forgotten password, users can use the email features of the authentication provider, where these are enabled.
Alternatively, users can log in with "Continue with Google" or "Continue with Apple". In this case, Google or Apple confirms the user's identity and transmits a technical login token as well as, where released by the user, email address and name to our authentication provider, so that it can create or recognize a user account. No password is stored with us in this case. Apple also allows a private relay email address to be used instead of the real email address.
Login sessions can be stored locally on the device so that users do not have to log in again every time they start the app.
10. Supabase as backend service
Project Prime uses Supabase as a backend service for authentication, database, access protection, role management and storage of app data.
Supabase may in particular process account, profile, nutrition, training, weight, role, premium, recipe, food, supplement, update and review data records.
Supabase may be used as a data processor. According to the current state of the project, the server region is Frankfurt, Germany, or the EU.
Access to data is restricted by technical rules, roles and access rights. Users should generally only be able to see their own personal data. Coach or admin access is to be restricted to authorized accounts.
11. In-house food and product database
Project Prime uses its own food and product database. When a user adds a food item, beverage or product, a data record with name, nutritional values, brand, barcode/EAN, portion information, search terms and source may be stored.
The goal is to answer future search queries faster, more reliably and with fewer external requests. If an entry is reliably found in the in-house database, it can be used without a renewed AI query.
General food items without a brand, for example "apple", "skyr", "iceberg lettuce" or "whole grain bread", may be stored as general baseline values. Branded products captured via barcode or packaging may additionally be stored with barcode and brand.
Such data records generally serve the general functionality of the app and are not intended to be permanently displayed publicly in association with a specific person. They may be retained after deletion of a user account if they no longer contain any personal reference.
12. Manual food search
Users can manually search for food and beverages. The app searches its own database first. If a matching general or saved entry exists, it is shown preferentially.
If no matching in-house entry is found and it is a general food item or beverage without a specific brand, the app may estimate nutritional values or supplement them from external sources. If a specific brand or product is searched for and is not available, the app may point to barcode scanning or a product photo.
Manual search may be limited in the free plan. Search queries may be counted in order to technically implement free and premium features.
13. Barcode scanning and packaged food
For packaged food, users can scan the barcode. The app first checks its own database. If a matching data record is found there, the product can be shown without AI analysis and without an external product search.
If the product is not known, the app may query OpenFoodFacts using the barcode. If plausible nutritional values are found there, they can be displayed and, after confirmation, stored in the in-house database.
If insufficient data is found, the app may ask the user to photograph the front of the package and the nutrition table. Product name, brand, nutritional values and, where applicable, portion information can be extracted from this.
If a portion, piece, bar or comparable unit is recognized, it may be shown as an additional selection option. By default, the value per 100 g should be shown unless something else is selected.
Barcode products that were not found or were entered manually may be stored in a review list so that the information can later be checked or corrected.
14. Loose food items
For loose food items, for example fruit, vegetables, meat, eggs, cheese, bread or salad without a barcode, users can take a photo. The AI can first recognize which food item is shown.
The app then searches its own database first. If a reliable match is found there, the nutritional values from the database are used. An additional AI nutrition estimate is then generally not required.
If no reliable match is found, the app may estimate nutritional values or supplement them from external sources and save the entry after confirmation. If a typical portion can reasonably be determined, for example for an apple, banana, egg, slice of bread or similar food items, a portion unit may additionally be saved.
15. Photographing a dish or meal
Users can photograph dishes or meals, for example plates, bowls, tartare rolls, döner, currywurst or filled bread rolls. Users can additionally enter a note, such as "the meat is venison" or "name: chili con carne".
The app can estimate the dish and show an overall figure for calories and macronutrients. Alternatively, recognized components can be entered individually.
In the background, the app can compare recognized components with its own database. If components are not available, general baseline values may be generated and saved so that future recognitions are cheaper and more consistent.
Users can optionally save an estimated dish for themselves. Saved dishes are generally personal entries of the respective account and are not automatically visible to all users.
Estimated dishes may additionally be saved as a review record so that the plausibility of the estimates can be checked and improved.
16. Capturing, dictating and saving recipes
Users can manually capture recipes or dictate ingredients by voice. Voice input uses the operating system's speech recognition, where available. Users can enter ingredients with quantities, grams, count or comparable units.
Required fields may in particular be the name of the dish and the number of servings. The app calculates the nutritional values of the overall recipe and the desired serving from the ingredients and quantities.
For ingredients, the app searches its own database first. If ingredients are not available, general nutritional values may be estimated and saved as a baseline value. Where appropriate, a typical portion, piece count or slice may additionally be saved.
Users can save their own recipes personally and select them again later. Personal recipes can be deleted again by the user.
Users can voluntarily make a recipe available to the community. In this case, preparation instructions must be provided. The recipe is first reviewed and only becomes visible to other users after approval.
17. Community recipes and moderation
Submitted community recipes may contain name, ingredients, preparation instructions, servings, calories, protein, categories, notes and other nutritional values.
Since community recipes may later be shown to other users, users may not submit personal data, insults, discriminatory content, unlawful content, confidential information belonging to others, or content that is problematic under copyright law.
New recipe ideas are first saved for review. The app may carry out an AI pre-check, in particular for grossly inappropriate, insulting, discriminatory, racist, sexist or otherwise unlawful content. In addition, a manual approval is carried out by the controller or an authorized person.
Community recipes are only intended to become generally visible after approval. Until then, users may be shown a note such as "submitted for review".
If a user account is deleted, approved recipe ideas may generally be retained if they no longer contain any personal reference. If recipe ideas contain personal data, this data is deleted or anonymized upon request.
18. Supplement features
Project Prime may contain a supplement area. Users can manually enter supplements or receive a non-binding suggestion based on voluntary answers.
Questions may be asked about diet, fish consumption, meat consumption, vegetarian or vegan diets, known deficiencies, individual notes and personal goals.
The information serves to create a structured overview or reminder for dietary supplements. It does not replace a medical diagnosis, laboratory test or medical advice.
Users can adjust, remove, manually add and check off suggested supplements daily, where this feature is used.
19. Health Connect and Apple Health
Project Prime can retrieve step counts or comparable activity data from Health Connect on Android or Apple Health on iOS if users actively connect this and grant permission.
The app may attempt to synchronize current step counts when opening relevant areas, for example the diary or statistics. Permanent background synchronization is only possible within the technical capabilities of the respective operating system.
Users can revoke this permission at any time in the settings of their device or the respective health app. Without permission, steps can still be entered manually.
20. AI analysis with Google Gemini
Project Prime uses Google Gemini for selected AI features, for example recognition of food items, dishes, meals, packaging, brands and product names, reading nutrition tables, estimating dishes, recipe and ingredient processing, moderation checks, as well as translating or normalizing search terms, where required.
For AI analysis, image data, product names, nutritional information, ingredient lists, user notes and technical context information may be transmitted to Google. Only the data required for the respective analysis is intended to be transmitted.
AI results may be inaccurate or incomplete. Users should review entries and can adjust recognized values in the app, as far as the feature allows for this.
The app is designed to prioritize confirmed in-house database entries in order to avoid unnecessary AI queries.
21. OpenFoodFacts and USDA
OpenFoodFacts may be used to retrieve product information and nutritional values, in particular for packaged food and barcodes.
USDA may serve as an additional data source for general food items, in particular if in-house or German data is not sufficient. The app is intended to use external data sources sparingly and to prioritize confirmed in-house data.
For external data sources, their own terms of use and privacy information may apply. OpenFoodFacts and USDA generally only receive the search query or the barcode, but no complete user profiles, unless implemented differently for technical reasons.
22. Nutrition, training, weight and statistics
Users can save food, beverages, meals, water, steps, activity calories, training days, notes, supplements and weight entries.
From this, the app creates daily overviews, statistics, progress displays, weight charts, meal targets, calorie trends, training evaluations and supplement status.
This data may be shown to the coach if the user is being supported in a coaching context and a corresponding assignment exists.
23. Coach area and coach access
The coach area allows authorized coach or admin accounts to view data of supervised users. This may include profile, body data, weight history, nutrition days, meals, training data, notes, supplement status and other progress data.
Access is to be restricted to authorized persons. Coach and admin accounts must be specially protected. Access follows the principle that only data required for supervision, evaluation and feedback should be visible.
If a coach export or comparable feature is temporarily not visible, the underlying technical tables or previous data may nevertheless continue to exist, as far as they are required for administration, evidence or later activation.
24. Premium, free plan and usage limits
Project Prime may offer a free use with a limited feature scope and a premium use. The app may count usage limits, for example manual search queries, photo analyses, recipe features or training plan features.
If a limit is reached, a notice about premium may be shown. Users can voluntarily purchase premium, as far as this feature is enabled in the App Store or on Google Play.
Individual accounts can be manually activated by the controller, for example for testing, coaching, support or goodwill purposes. In doing so, only the technical premium status required for activation is processed.
25. App Store, Google Play and payment processing
If the app is downloaded via the Apple App Store or Google Play, or a subscription is concluded there, Apple or Google process personal data under their own responsibility.
Project Prime generally only receives the information required to recognize and activate the premium status. Complete payment information such as credit card data is not stored by Project Prime.
Cancellation, plan changes, renewal and management of subscriptions generally take place via the respective app store, i.e. the Apple App Store or Google Play, as far as the subscription was concluded there.
26. Update check and forced update
The app may check at launch whether a new minimum version is required. For this, platform, app version and build number may be compared with a configuration in the backend.
If a version is no longer supported for security, functional or compatibility reasons, the app may restrict access until the update is completed. This check serves the security, error prevention and functionality of the app.
27. Local storage on the device
The app may store certain data locally on the device, for example login status, app settings, last selected values, caches and display states.
This local storage serves the usability, performance and offline availability of individual app features.
When the app is deleted, locally stored data may be removed. Data stored on the server is not automatically deleted as a result. Deleting the account within the app or a request to the controller is required for this.
28. App permissions
| Permission | Purpose |
|---|---|
| Camera | Barcode scanning, photographing food items, dishes, meals, packaging and nutrition tables |
| Photos/media | Selecting existing images, as far as this feature is enabled |
| Microphone/voice input | Voice input for recipe ingredients, as far as the user uses this feature and the operating system provides it |
| Internet/network | Login, Supabase backend, AI analysis, OpenFoodFacts/USDA queries, premium status and update check |
| Health Connect/Apple Health | Steps and activity data, if users actively allow this connection |
| Notifications | Only if reminders or push notices are enabled |
29. Recipients and service providers
Personal data may be transmitted to the following recipients or categories of recipients, as far as this is required for the app, coaching, security or legal obligations:
- Supabase as backend and authentication service,
- Google Gemini for AI analysis,
- OpenFoodFacts and USDA for food and product data,
- Apple App Store and Google Play for app distribution and subscriptions,
- Google and Apple as providers of the "Continue with Google" and "Continue with Apple" login options, as far as users choose this login method,
- coach and admin accounts, as far as authorization exists,
- hosting and IT service providers for the website, support and operation,
- legal advisors, tax advisors or authorities, as far as legally required.
30. Transfers to third countries
When using services from international providers, processing may take place outside the European Union or the European Economic Area.
In such cases, we ensure that appropriate safeguards within the meaning of the GDPR are in place, for example EU standard contractual clauses, adequacy decisions or additional protective measures.
31. Storage period
We only store personal data for as long as is necessary for the respective purposes or as long as legal obligations exist.
Account, profile, nutrition, training, weight, supplement and progress data is generally stored until account deletion or termination of use.
General, approved food, product and recipe data without a direct personal reference may continue to exist for longer so that the app database remains functional.
Review records, technical logs and security data are deleted or anonymized as soon as they are no longer required for error analysis, quality assurance, security or legal evidence.
32. Account deletion and deletion of personal data
Users can delete their account within the app, as far as this feature is provided. Alternatively, a deletion request can be sent to the contact address named above.
When an account is deleted, the user's personal data is deleted unless legal retention obligations, security reasons or legitimate interests prevent this.
In particular, the following is deleted:
- user account and authentication reference,
- app profile and body data,
- weight history, daily data and notes,
- nutrition and training days,
- personal saved recipes and saved dishes, as far as they are personal,
- supplement plan and daily supplement entries,
- role and access data, as far as it only relates to this account,
- personal review records, as far as technically attributable.
General, non-personal data required for the functionality of the app database does not have to be automatically deleted, for example confirmed general food items, barcode/product data without a personal reference, or approved community recipes without a personal reference.
If such content contains personal data, users can request its deletion or anonymization.
33. Rights of data subjects
Under the GDPR, users have in particular the following rights:
- right of access under Art. 15 GDPR,
- right to rectification under Art. 16 GDPR,
- right to erasure under Art. 17 GDPR,
- right to restriction of processing under Art. 18 GDPR,
- right to data portability under Art. 20 GDPR,
- right to object under Art. 21 GDPR,
- right to withdraw consent granted under Art. 7(3) GDPR,
- right to lodge a complaint with a data protection supervisory authority.
Requests can be sent to pt@dennis-vollmer.de.
34. Withdrawal of consent
As far as processing is based on consent, users can withdraw this consent at any time with effect for the future.
Withdrawal may result in certain app features no longer being usable, in particular features for health, nutrition, training, health-app, photo and AI analysis.
35. Automated decisions and profiling
Project Prime creates evaluations, daily targets, meal guidelines, progress displays, AI estimates, training histories, supplement suggestions and recommendations.
These serve to support the user and the coaching. There is no exclusively automated decision with legal effect or similarly significant impact within the meaning of Art. 22 GDPR.
AI results and app evaluations may be inaccurate. They do not replace a medical diagnosis, therapy, medical advice or individual nutritional counseling by an appropriately qualified body.
36. Data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.
These include in particular:
- HTTPS connections,
- authentication via user accounts,
- role-based access rights,
- backend security rules,
- separation of user, coach and admin access,
- limiting AI and third-party queries to required data,
- regular review and adjustment of the technical implementation.
37. Minors
The app is generally not aimed at children. Should the app be used by minors, it should first be checked whether consent from a parent or legal guardian is required.
38. Google Play Data Safety and Apple Privacy Labels
For publication of the app in the Google Play Store and the Apple App Store, privacy information is provided in accordance with the actual data processing.
Based on the current feature scope, Project Prime in particular processes the following categories of data:
- account data, for example email address,
- health and fitness data, for example weight, body data, nutrition, training and progress,
- app activity and usage status,
- photos and camera data exclusively for analysis triggered by the user,
- user content, for example recipes, dishes, notes and community submissions,
- technical identifiers, as far as required for operating the app,
- purchase or subscription status, as far as premium features are used.
The information in the privacy details of the respective app stores is updated accordingly when the feature scope changes.
39. Website, support and contact
The public Project Prime website provides information on the app, support, privacy, terms of use and legal notice.
If users contact us by email, the information provided is processed in order to answer the inquiry. This may include email address, name, content of the inquiry and accompanying technical information.
40. Changes to this privacy policy
We may adapt this privacy policy if features, providers, the legal situation or technical processes change.
The current version is made available in the app or via a suitable link. In the event of material changes, a notice may be given in the app.
41. Contact for privacy questions
For questions about data protection, exercising rights or account deletion, users can contact the controller at the following address:
Appendix A: Overview of key processing activities
| Area | Data | Purpose | Storage/recipient |
|---|---|---|---|
| Account | Email, login, session data | Registration and access protection | Supabase Auth, backend |
| Profile | Name, goal, profile picture | Personalization and coaching | Supabase, coach view |
| Body data | Weight, height, age, gender, target weight | Daily targets, history and evaluation | Supabase, coach view |
| Nutrition | Food, beverages, grams, portions, nutritional values, meal | Tracking and daily overview | Supabase, in-house food database |
| Training | Training day, exercises, sets, weights, duration, notes | Training plan, training log and evaluation | Supabase, coach view |
| Photos | Food, packaging, nutrition, recipe and dish photos | Recognition, estimation and quality assurance | Temporary/AI provider, possibly backend review |
| Barcode | EAN/barcode, product name, brand, nutritional values | Product search and reuse | In-house database, OpenFoodFacts |
| AI | Image data, prompts, user notes, result data | Recognition, estimation, moderation | Google Gemini |
| Recipes | Name, ingredients, preparation, categories, moderation status | Personal recipes and community recipes | Supabase, visible only after approval |
| Supplements | Answers, suggestions, selected supplements, daily status | Supplement overview and daily reminder/check-off function | Supabase |
| Level/badges/streak | XP total, level, selected badge, streak status, streak protection shields, weekly quest progress | Motivation and progress display | Supabase |
| Health data | Steps and activity data | Automatic daily update | Health Connect/Apple Health, Supabase after saving |
| Premium | Plan, term, premium status | Activation of premium features | Apple/Google, Supabase |
| Creator code | Redeemed code, redemption time, trial end date, possibly a link to a later purchase | Granting the trial period and aggregated revenue-share reporting | Supabase, partners receive only aggregated figures per code |
| Login | Login token, email, name (for Google/Apple login) | Creating or recognizing an account | Google, Apple, Supabase Auth |
| Usage analysis | Trigger area and time of a premium notice | Product and offer improvement | Supabase |
| Coach | User progress, daily data, notes | Support and feedback | Coach/admin access |