Legal information

FYG Privacy

This notice explains, as required by Art. 13 GDPR, what data the Feed Your Gut (“FYG”) iOS app processes, what leaves your device and what does not. FYG is a wellness and food journal, not a medical device.

Version 2.3 · 12 September 2026

In short: FYG has no user account. Meals, check-ins, notes and settings live on your iPhone. For an analysis exactly one leaves your device is the content you ask us to analyse: the compressed photo, the description you typed, or a barcode. No name, no contact details, none of your check-ins. No photo is stored on our side, and none of it is used for AI training. Usage counts are collected only if you agree to them first. There is no ad tracking, and we do not sell data.

01

Controller

Quiet Day Ventures UG (haftungsbeschränkt)
Sophienstraße 40
38118 Braunschweig
Germany
Represented by its managing director Felix Jähn
Email: [email protected]

We are the controller within the meaning of Art. 4(7) GDPR insofar as we decide on the purposes and means of a processing operation. Where Apple processes data for its own purposes, in connection with your Apple Account, the App Store, a purchase or your iCloud backup, Apple’s own notices apply in addition.

We have not appointed a data protection officer, because on the present scale the processing is not large-scale within the meaning of Art. 37(1)(c) GDPR and the conditions of § 38 BDSG are not met either. We reassess this as circumstances change, in particular as the number of users grows. Address data protection enquiries to the contact above, where they are handled directly by the management.

02

What stays on your device

FYG has no sign-in and no user accounts, so there is no user database your history could sit in. The following is stored on your iPhone, and the content itself never reaches us:

  • your meals, the analysis results you confirmed, plant lists, streaks and challenges,
  • your gut check-ins, meaning gut feeling, comfort, energy, stress and free-text notes,
  • your first name or form of address, and your onboarding answers,
  • settings, reminder times and your consent status.

One exception, stated plainly: if you agreed to the usage statistics, the token you tapped from the preset onboarding options also goes there, including your self-assessment of how your gut feels. That covers the preset options only, never your name and never free text. Without your agreement that does not happen either. Details in section 06.

iCloud backup

So that a new phone or a lost one does not wipe out your history, FYG writes this local data as an encrypted snapshot into your own iCloud container. Encryption happens on the device (AES-256-GCM). The key lives in your keychain, and iOS carries it to your own other devices through the end-to-end encrypted iCloud Keychain only, so that a new iPhone can open the backup at all. We have access to neither the container nor the key and cannot read the contents. How long iCloud keeps the backup is governed by your Apple settings.

System features

Reminders are scheduled locally on the device, which is what the notification permission is for. FYG uses no push notifications and no push service. Widgets, the Lock Screen display and the Live Activity only read values the app has stored on the same device. Shortcuts and Siri actions run on the device; if you use Siri by voice, Apple processes that voice input under its own terms. The camera and photo library open only after you grant access, and sharing and export only when you tap. A background gradient on the home screen follows the tilt of the device; those sensor readings stay in the app’s memory.

03

What leaves your device

Only the following operations send anything at all. The first two run when the app starts; every other one you trigger yourself.

TriggerWhat is sentTo whom
App start: checking your subscription status a random, pseudonymous purchase identifier RevenueCat
App start and further use: usage statistics, only once you agree see section 06 PostHog (EU)
Analyse a meal from a photo a photo compressed on the device, plus the language code FYG backend, and from there to OpenAI, see section 04
Analyse a meal from text your description, plus the language code FYG backend, and from there to OpenAI, see section 04
Scan a barcode the barcode digits, plus the language code FYG backend, and from there to Open Food Facts and OpenAI
Display the product image of a scanned item the image request itself, and with it your device’s technically necessary connection data including its IP address Open Food Facts
Report a missing product the barcode digits FYG backend
Unlocking analysis, and renewing it a genuineness check of the app installation (Apple App Attest) and the same random purchase identifier Apple, FYG backend, RevenueCat
Buying or restoring FYG Plus the purchase and its receipt under the same random purchase identifier Apple, RevenueCat

When Open Food Facts does not know a scanned barcode, our backend records those digits even if you do not report them. That is catalogue work meant to close the gap, and no link to your installation is stored with it.

What never travels

At none of these points do we transmit your name, an email address, your check-ins, your notes, your meal history, your location, contacts or Health app data. FYG itself uses no advertising identifier, builds no advertising profile and sets no cross-app identifier.

Photos

The photo is downsized on the device before it is sent, processed in memory on the backend, and discarded once the answer is returned. No photo is stored on our side and no image file is created. Nothing is left behind on the device either: the shot is deleted once the analysis is done. FYG deliberately keeps no meal photo gallery.

Identifiers

Requests to the FYG backend carry a short-lived access token bound to your app installation. Its only job is to protect the analysis against abuse and to keep a daily quota. It is not tied to a person and holds no contact details; for older installations a shared app key with no installation link still applies during the transition.

Links out of the app

When you tap a link, be it a cited study, the product page at Open Food Facts, the App Store or this legal page, your device connects to that provider itself. The provider learns your IP address in the process and handles it under its own terms.

Technical logs

For troubleshooting and abuse prevention the backend logs, in normal operation, the course of a request: a random request ID, language, duration, input size, and the recognised foods with the values calculated for them. Raw photos and your free-text input are not logged. When a daily quota is exhausted, the installation identifier concerned is written along with it. Where a genuineness check is rejected we additionally keep a security record with a hashed IP address and a hashed device browser identifier. The hosting provider records the technically necessary connection data on top of that. None of it is used for advertising or profiling.

04

The AI analysis

Recognising and rating a meal is FYG’s core function and the only operation in which content of yours goes to an AI provider. Because data under Art. 9 GDPR can be involved, we describe that path in full.

Who processes it

The only service used is the programming interface (API) of OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland. OpenAI acts as a processor under Art. 28 GDPR, exclusively on our instructions and under a data processing agreement. No other AI provider is integrated into FYG. This is the API, not ChatGPT: the consumer terms and the chat history there do not apply to us.

Exactly what is transmitted

Every request to OpenAI stands on its own: it carries no conversation reference to an earlier request. A logged meal usually takes two of them, one to recognise the food and one to rate the ingredients you confirmed; a failed request may be repeated. Each one holds our fixed evaluation text plus exactly one of the following:

  • your meal photo, compressed on the device,
  • the meal description you typed, or
  • the product details we previously fetched for a scanned barcode from the public Open Food Facts database.

Plus, inside that fixed text, which language to answer in. Nothing else. Our server makes the request, not your device, so OpenAI learns neither your IP address nor your device type. Downsizing re-encodes the photo, which drops the EXIF data of the shot, including the camera model and any GPS stamp. The request carries no identifier of your installation, no name, no contact details, no check-ins and no earlier meal as additional metadata. However, photos and free text may themselves contain identifying information.

Storage controls and training

We send store:false to avoid a retrievable response history. This does not mean Zero Data Retention. OpenAI may retain abuse-monitoring data for up to 30 days, or longer when legally required. Separate technical caching and image-safety exceptions may apply. API data is not used for training by default. See OpenAI’s data controls.

Third-country aspect

Our contracting party is the Irish entity, so a recipient inside the European Union. Processing may involve intra-group sub-processors in the United States. For that case we base the transfer on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the data processing agreement, and additionally, where the US entity is validly certified, on the adequacy decision for the EU-U.S. Data Privacy Framework. More in section 10.

Limits of the result

The model estimates. It can confuse foods, misjudge quantities and state nutrition values incorrectly. You see the result before it is saved, can edit it, and decide whether it goes into your journal. No automated decision with legal or similarly significant effect under Art. 22 GDPR is involved, and no health assessment of you as a person takes place.

What is in your hands

Photograph the plate and little else. Keep faces, other people, documents and screens out of the frame: what you do not capture cannot be transmitted. Instead of a photo you can always type the meal or scan a barcode, and you can skip the analysis entirely.

05

Health-related data and consent

In the context of a gut health app, a meal photo and a meal description can support inferences about your health and can therefore be data under Art. 9(1) GDPR. We treat them as such throughout, as a precaution, and process them only on the basis of your explicit consent under Art. 9(2)(a) GDPR. That consent expressly covers the transfer to OpenAI described in section 04, including the third-country aspect set out there.

You give that consent in the final step of onboarding, a screen of its own that explains nothing but the data processing. Onboarding cannot be completed without that confirmation, so no analysis can be started without it either. We store your confirmation together with the version of the text that was on screen at the time; if we change that text materially, we ask again. If the confirmation is missing when the camera or the photo library is opened, the app obtains it again there.

On freely given consent: the analysis is FYG’s core function; without it there is no service to receive. The consent therefore covers exactly what you got the app for, and no more. We tie no further purpose to it: the usage statistics are a separate question with their own answer, and advertising, profiling and any disclosure to third parties for their own purposes do not happen at all. You decide before your first scan, and you can withdraw at any time.

Your gut check-ins never reach us. Gut feeling, comfort, energy, stress and notes stay on the device; the note shown before your first check-in is there for transparency, not because anything is transmitted to us.

You can withdraw your consent at any time with effect for the future, and as easily as you gave it: in the app under Settings › Privacy & data › Withdraw analysis consent. Your meals are left untouched; the analysis asks again before it is next used. An email to us works just as well. This does not affect the lawfulness of processing carried out before the withdrawal.

FYG provides no diagnosis, no treatment and no medical advice. If you have symptoms, consult a healthcare professional; in an emergency, call your local emergency number.

06

Usage statistics, only with your agreement

To understand which features get used and where the app gets stuck, we collect usage events through PostHog in the EU region (Frankfurt). Only after you have agreed. Before that nothing is collected, nothing is sent and, above all, nothing is written to your device. The app asks you once; if you say no, we do not ask again.

We call these statistics pseudonymous rather than anonymous, even though no name and no account is attached. A random identifier travels with them, and while it does, a single installation could be singled out. That is the more honest word, and it is why this processing is measured against the GDPR at all.

What is transmitted is only an event name from a fixed list, such as “app opened”, “scan started” or “paywall viewed”, together with properties from an equally fixed list: platform, language code, scan type, number of items recognised, figures describing the result, details of a purchase such as plan, price, currency and free-week eligibility, and your picks from the preset onboarding answer options, including the self-assessment you gave there. Free text cannot travel with it: anything not on that list is dropped before sending.

Not transmitted: name, email address, photos, meal descriptions, food names and notes. Of a gut check-in we count that it happened, never what you entered.

The only identifier is a random ID created at the moment you agree, with no link to your Apple Account, your purchase or any device identifier. The IP address is not stored, and no location is derived from it, so no country, city, postcode or coordinates. No person profiles are built.

The FYG backend reports plain operational figures for an analysis into the same project: duration, success or error code, language code, input type, and the figures calculated for the result. These reports run under a fixed service identifier and carry neither an installation ID nor an IP address; food names, photos and text are not part of them either. The switch in Settings governs the events your device sends; these server-side figures have no link to your device.

The legal basis is your consent under Art. 6(1)(a) GDPR. For placing the identifier on your device, § 25(1) TDDDG applies on top, which requires consent for exactly that, regardless of whether the identifier itself is personal data. That is why we ask rather than leaving you to object. You can withdraw at any time: in the app under Settings › Privacy & data, switch off “Usage statistics”. Collection stops immediately, events not yet sent are discarded, and the random ID is deleted, so a later yes cannot be joined to the earlier data.

07

Recipients and processors

RecipientRoleFramework
Render Services, Inc. running the FYG backend processor, service region Frankfurt
Supabase, Inc. managed database for genuineness records, quotas, security logs and caches processor, project region Frankfurt
OpenAI Ireland Ltd. AI analysis of photo, description and product details, see section 04 processor under Art. 28 GDPR; storage switched off on request, no model training
Open Food Facts public product database for barcodes and product images query against a public database
RevenueCat, Inc. checking, managing and restoring FYG Plus performance of a contract; no health, photo or meal data
PostHog, Inc. pseudonymous usage statistics, only once you consent, see section 06 processor, EU region Frankfurt; switchable off in the app
Apple app distribution, payment, genuineness check of the installation, your personal iCloud backup Apple acts as its own controller

We have Art. 28 GDPR agreements in place with our processors. There are no further recipients: FYG embeds no ad network, no crash reporting service, no email sending service and no social media component. No data is passed to third parties for their own purposes, and we do not sell data.

This legal page itself is served through Cloudflare Pages. For that and for contacting us, see the website privacy notice.

09

Retention and deletion

  • Data on the device: until you delete individual entries, choose “Clear all local data” under Settings › Privacy & data, or remove the app;
  • iCloud backup: per the retention rules and settings of your Apple Account; the next backup overwrites the previous one;
  • Photo and description with us: in memory for the duration of the request only, with no storage afterwards;
  • Photo and description at OpenAI: response-history storage disabled; provider retention and exceptions are explained in section 04. This is not a guarantee of immediate deletion.
  • Cached analysis results: 72 hours, with no link whatsoever to an installation or a person, so the same meal does not have to be analysed twice;
  • Product data from Open Food Facts: cached for up to seven days, with no link to an installation;
  • Unknown barcodes: with no link to an installation, until the gap in the product catalogue is closed;
  • Genuineness record and quota: until you delete it, and at most 180 days after it was last used, after which an automatic clean-up removes it. Access tokens expire after 24 hours at the latest, and quota counters are deleted after 90 days;
  • Security and operational logs: security events held in the database are deleted automatically after 90 days; the hosting provider’s logs only for as long as troubleshooting and abuse prevention require;
  • Purchase status: for the term of the subscription, and afterwards for as long as a restore or a tax and commercial record requires;
  • Statutory records: for the duration of mandatory retention and limitation periods, then deleted or anonymised.

There is no account that would need deleting, and you can still get rid of everything: Settings › Privacy & data › Clear all local data removes the history on the device and asks our server to delete this installation’s identifier along with its tokens and quota counters. The app introduces itself as a stranger afterwards. Your iCloud backup is managed through your Apple settings; if it cannot be opened on a new device, the app offers “Start a new backup” there, which replaces the old one.

10

Transfers to third countries

We pick European regions throughout and, where possible, European contracting parties. Several of the providers named above nonetheless belong to US groups and may have access from outside the EEA through group companies or sub-processors.

Where no adequacy decision under Art. 45 GDPR applies, we base such transfers on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the respective data processing agreements, together with supplementary technical and organisational measures, in particular encryption in transit, data minimisation, and doing without identifiers that could establish a link to a person. Where a provider is validly certified under the EU-U.S. Data Privacy Framework, we additionally rely on the corresponding adequacy decision.

A copy of the Standard Contractual Clauses and details of the sub-processors used are available on request at [email protected].

11

Your rights

Subject to the statutory conditions you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR), and withdrawal of consent with effect for the future (Art. 7(3) GDPR).

To exercise them, write to [email protected]. Because FYG works without an account, we hold nothing under your name. You are identifiable to us only through two random identifiers: the one belonging to your app installation and, if you agreed to the usage statistics, the one belonging to those. Give us either, and we will disclose or delete what sits under it. You can also trigger the deletion yourself, see section 09. If even that does not let us identify you, the rights of access, rectification, erasure, restriction and portability do not apply to that extent under Art. 11(2) GDPR. We never ask for a copy of an identity document, and we advise against sending us more data than we would otherwise hold.

Your local data is therefore yours to handle, and completely so: in the app under Settings › Privacy & data you choose “Export local data”, which gives you a machine-readable file in the sense of Art. 20 GDPR, or “Clear all local data”. The same screen is where you withdraw consent: the “Usage statistics” switch for the statistics, and “Withdraw analysis consent” for the AI analysis.

Without prejudice to other remedies, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hannover, Germany, lfd.niedersachsen.de. You may also contact the supervisory authority of your habitual residence.

12

Security

We apply risk-based technical and organisational measures under Art. 32 GDPR: TLS-encrypted transfer throughout, an iCloud backup encrypted on the device, short-lived access tokens of which only hashes are held server-side, the genuineness check of the app installation, rate limits and daily quotas, locked-down database access, security records in which the IP address and the device browser identifier appear only as hashes, and data-minimising error output. Data minimisation is the most effective measure of all: what is never stored cannot leak. No system is entirely without risk; please also protect your device and your Apple Account.

13

Changes to this notice

We update this notice when features, recipients or the legal situation change. This version describes the iOS app. Material changes, such as a change of AI provider, server-side storage of your history, or an Android edition, will be made transparent in the app before they take effect. Where a new consent is needed, we will ask for it separately.