Controller
Quiet Day Ventures UG (haftungsbeschränkt)
Sophienstraße 40
38118 Braunschweig
Germany
Represented by its managing director Felix Jähn
Email:
[email protected]
We are the controller within the meaning of Art. 4(7) GDPR insofar as we decide on the purposes and means of a processing operation. Where Apple processes data for its own purposes, in connection with your Apple Account, the App Store, a purchase or your iCloud backup, Apple’s own notices apply in addition.
We have not appointed a data protection officer, because on the present scale the processing is not large-scale within the meaning of Art. 37(1)(c) GDPR and the conditions of § 38 BDSG are not met either. We reassess this as circumstances change, in particular as the number of users grows. Address data protection enquiries to the contact above, where they are handled directly by the management.
What stays on your device
FYG has no sign-in and no user accounts, so there is no user database your history could sit in. The following is stored on your iPhone, and the content itself never reaches us:
- your meals, the analysis results you confirmed, plant lists, streaks and challenges,
- your gut check-ins, meaning gut feeling, comfort, energy, stress and free-text notes,
- your first name or form of address, and your onboarding answers,
- settings, reminder times and your consent status.
One exception, stated plainly: if you agreed to the usage statistics, the token you tapped from the preset onboarding options also goes there, including your self-assessment of how your gut feels. That covers the preset options only, never your name and never free text. Without your agreement that does not happen either. Details in section 06.
iCloud backup
So that a new phone or a lost one does not wipe out your history, FYG writes this local data as an encrypted snapshot into your own iCloud container. Encryption happens on the device (AES-256-GCM). The key lives in your keychain, and iOS carries it to your own other devices through the end-to-end encrypted iCloud Keychain only, so that a new iPhone can open the backup at all. We have access to neither the container nor the key and cannot read the contents. How long iCloud keeps the backup is governed by your Apple settings.
System features
Reminders are scheduled locally on the device, which is what the notification permission is for. FYG uses no push notifications and no push service. Widgets, the Lock Screen display and the Live Activity only read values the app has stored on the same device. Shortcuts and Siri actions run on the device; if you use Siri by voice, Apple processes that voice input under its own terms. The camera and photo library open only after you grant access, and sharing and export only when you tap. A background gradient on the home screen follows the tilt of the device; those sensor readings stay in the app’s memory.
What leaves your device
Only the following operations send anything at all. The first two run when the app starts; every other one you trigger yourself.
| Trigger | What is sent | To whom |
|---|---|---|
| App start: checking your subscription status | a random, pseudonymous purchase identifier | RevenueCat |
| App start and further use: usage statistics, only once you agree | see section 06 | PostHog (EU) |
| Analyse a meal from a photo | a photo compressed on the device, plus the language code | FYG backend, and from there to OpenAI, see section 04 |
| Analyse a meal from text | your description, plus the language code | FYG backend, and from there to OpenAI, see section 04 |
| Scan a barcode | the barcode digits, plus the language code | FYG backend, and from there to Open Food Facts and OpenAI |
| Display the product image of a scanned item | the image request itself, and with it your device’s technically necessary connection data including its IP address | Open Food Facts |
| Report a missing product | the barcode digits | FYG backend |
| Unlocking analysis, and renewing it | a genuineness check of the app installation (Apple App Attest) and the same random purchase identifier | Apple, FYG backend, RevenueCat |
| Buying or restoring FYG Plus | the purchase and its receipt under the same random purchase identifier | Apple, RevenueCat |
When Open Food Facts does not know a scanned barcode, our backend records those digits even if you do not report them. That is catalogue work meant to close the gap, and no link to your installation is stored with it.
What never travels
At none of these points do we transmit your name, an email address, your check-ins, your notes, your meal history, your location, contacts or Health app data. FYG itself uses no advertising identifier, builds no advertising profile and sets no cross-app identifier.
Photos
The photo is downsized on the device before it is sent, processed in memory on the backend, and discarded once the answer is returned. No photo is stored on our side and no image file is created. Nothing is left behind on the device either: the shot is deleted once the analysis is done. FYG deliberately keeps no meal photo gallery.
Identifiers
Requests to the FYG backend carry a short-lived access token bound to your app installation. Its only job is to protect the analysis against abuse and to keep a daily quota. It is not tied to a person and holds no contact details; for older installations a shared app key with no installation link still applies during the transition.
Links out of the app
When you tap a link, be it a cited study, the product page at Open Food Facts, the App Store or this legal page, your device connects to that provider itself. The provider learns your IP address in the process and handles it under its own terms.
Technical logs
For troubleshooting and abuse prevention the backend logs, in normal operation, the course of a request: a random request ID, language, duration, input size, and the recognised foods with the values calculated for them. Raw photos and your free-text input are not logged. When a daily quota is exhausted, the installation identifier concerned is written along with it. Where a genuineness check is rejected we additionally keep a security record with a hashed IP address and a hashed device browser identifier. The hosting provider records the technically necessary connection data on top of that. None of it is used for advertising or profiling.
The AI analysis
Recognising and rating a meal is FYG’s core function and the only operation in which content of yours goes to an AI provider. Because data under Art. 9 GDPR can be involved, we describe that path in full.
Who processes it
The only service used is the programming interface (API) of OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland. OpenAI acts as a processor under Art. 28 GDPR, exclusively on our instructions and under a data processing agreement. No other AI provider is integrated into FYG. This is the API, not ChatGPT: the consumer terms and the chat history there do not apply to us.
Exactly what is transmitted
Every request to OpenAI stands on its own: it carries no conversation reference to an earlier request. A logged meal usually takes two of them, one to recognise the food and one to rate the ingredients you confirmed; a failed request may be repeated. Each one holds our fixed evaluation text plus exactly one of the following:
- your meal photo, compressed on the device,
- the meal description you typed, or
- the product details we previously fetched for a scanned barcode from the public Open Food Facts database.
Plus, inside that fixed text, which language to answer in. Nothing else. Our server makes the request, not your device, so OpenAI learns neither your IP address nor your device type. Downsizing re-encodes the photo, which drops the EXIF data of the shot, including the camera model and any GPS stamp. The request carries no identifier of your installation, no name, no contact details, no check-ins and no earlier meal as additional metadata. However, photos and free text may themselves contain identifying information.
Storage controls and training
We send store:false to avoid a retrievable response history. This does not mean Zero Data Retention. OpenAI may retain abuse-monitoring data for up to 30 days, or longer when legally required. Separate technical caching and image-safety exceptions may apply. API data is not used for training by default.
See OpenAI’s data controls.
Third-country aspect
Our contracting party is the Irish entity, so a recipient inside the European Union. Processing may involve intra-group sub-processors in the United States. For that case we base the transfer on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the data processing agreement, and additionally, where the US entity is validly certified, on the adequacy decision for the EU-U.S. Data Privacy Framework. More in section 10.
Limits of the result
The model estimates. It can confuse foods, misjudge quantities and state nutrition values incorrectly. You see the result before it is saved, can edit it, and decide whether it goes into your journal. No automated decision with legal or similarly significant effect under Art. 22 GDPR is involved, and no health assessment of you as a person takes place.
What is in your hands
Photograph the plate and little else. Keep faces, other people, documents and screens out of the frame: what you do not capture cannot be transmitted. Instead of a photo you can always type the meal or scan a barcode, and you can skip the analysis entirely.
Health-related data and consent
In the context of a gut health app, a meal photo and a meal description can support inferences about your health and can therefore be data under Art. 9(1) GDPR. We treat them as such throughout, as a precaution, and process them only on the basis of your explicit consent under Art. 9(2)(a) GDPR. That consent expressly covers the transfer to OpenAI described in section 04, including the third-country aspect set out there.
You give that consent in the final step of onboarding, a screen of its own that explains nothing but the data processing. Onboarding cannot be completed without that confirmation, so no analysis can be started without it either. We store your confirmation together with the version of the text that was on screen at the time; if we change that text materially, we ask again. If the confirmation is missing when the camera or the photo library is opened, the app obtains it again there.
On freely given consent: the analysis is FYG’s core function; without it there is no service to receive. The consent therefore covers exactly what you got the app for, and no more. We tie no further purpose to it: the usage statistics are a separate question with their own answer, and advertising, profiling and any disclosure to third parties for their own purposes do not happen at all. You decide before your first scan, and you can withdraw at any time.
Your gut check-ins never reach us. Gut feeling, comfort, energy, stress and notes stay on the device; the note shown before your first check-in is there for transparency, not because anything is transmitted to us.
You can withdraw your consent at any time with effect for the future, and as easily as you gave it: in the app under Settings › Privacy & data › Withdraw analysis consent. Your meals are left untouched; the analysis asks again before it is next used. An email to us works just as well. This does not affect the lawfulness of processing carried out before the withdrawal.
FYG provides no diagnosis, no treatment and no medical advice. If you have symptoms, consult a healthcare professional; in an emergency, call your local emergency number.
Usage statistics, only with your agreement
To understand which features get used and where the app gets stuck, we collect usage events through PostHog in the EU region (Frankfurt). Only after you have agreed. Before that nothing is collected, nothing is sent and, above all, nothing is written to your device. The app asks you once; if you say no, we do not ask again.
We call these statistics pseudonymous rather than anonymous, even though no name and no account is attached. A random identifier travels with them, and while it does, a single installation could be singled out. That is the more honest word, and it is why this processing is measured against the GDPR at all.
What is transmitted is only an event name from a fixed list, such as “app opened”, “scan started” or “paywall viewed”, together with properties from an equally fixed list: platform, language code, scan type, number of items recognised, figures describing the result, details of a purchase such as plan, price, currency and free-week eligibility, and your picks from the preset onboarding answer options, including the self-assessment you gave there. Free text cannot travel with it: anything not on that list is dropped before sending.
Not transmitted: name, email address, photos, meal descriptions, food names and notes. Of a gut check-in we count that it happened, never what you entered.
The only identifier is a random ID created at the moment you agree, with no link to your Apple Account, your purchase or any device identifier. The IP address is not stored, and no location is derived from it, so no country, city, postcode or coordinates. No person profiles are built.
The FYG backend reports plain operational figures for an analysis into the same project: duration, success or error code, language code, input type, and the figures calculated for the result. These reports run under a fixed service identifier and carry neither an installation ID nor an IP address; food names, photos and text are not part of them either. The switch in Settings governs the events your device sends; these server-side figures have no link to your device.
The legal basis is your consent under Art. 6(1)(a) GDPR. For placing the identifier on your device, § 25(1) TDDDG applies on top, which requires consent for exactly that, regardless of whether the identifier itself is personal data. That is why we ask rather than leaving you to object. You can withdraw at any time: in the app under Settings › Privacy & data, switch off “Usage statistics”. Collection stops immediately, events not yet sent are discarded, and the random ID is deleted, so a later yes cannot be joined to the earlier data.
Recipients and processors
| Recipient | Role | Framework |
|---|---|---|
| Render Services, Inc. | running the FYG backend | processor, service region Frankfurt |
| Supabase, Inc. | managed database for genuineness records, quotas, security logs and caches | processor, project region Frankfurt |
| OpenAI Ireland Ltd. | AI analysis of photo, description and product details, see section 04 | processor under Art. 28 GDPR; storage switched off on request, no model training |
| Open Food Facts | public product database for barcodes and product images | query against a public database |
| RevenueCat, Inc. | checking, managing and restoring FYG Plus | performance of a contract; no health, photo or meal data |
| PostHog, Inc. | pseudonymous usage statistics, only once you consent, see section 06 | processor, EU region Frankfurt; switchable off in the app |
| Apple | app distribution, payment, genuineness check of the installation, your personal iCloud backup | Apple acts as its own controller |
We have Art. 28 GDPR agreements in place with our processors. There are no further recipients: FYG embeds no ad network, no crash reporting service, no email sending service and no social media component. No data is passed to third parties for their own purposes, and we do not sell data.
This legal page itself is served through Cloudflare Pages. For that and for contacting us, see the website privacy notice.
Purposes and legal bases
- Art. 9(2)(a) GDPR, explicit consent: analysing meal photos, meal descriptions and the product details fetched for a scanned barcode, and the results derived from them;
- Art. 6(1)(a) GDPR and § 25(1) TDDDG, consent: the usage statistics and placing their identifier on your device;
- Art. 6(1)(b) GDPR, performance of a contract: providing the analysis and product features, checking, handling and restoring FYG Plus, support;
- Art. 6(1)(f) GDPR, legitimate interests: the genuineness check of the installation, quotas, rate limits, security and error logs, and completing the product catalogue; our interest lies in running the app securely and affordably;
- Art. 6(1)(c) GDPR, legal obligations: commercial, tax and data protection records.
Do you have to provide this data?
No. There is neither a statutory nor a contractual obligation to give us data, and there is no registration at which you would have to enter anything. Without the consent described in section 05 we cannot provide the analysis, however, and therefore not the service FYG exists for. Everything further, such as your first name, a check-in or a note, is voluntary; without it only the corresponding display in the app does not work.
Minimum age
FYG is for people aged 16 and over; minors additionally need their legal guardians’ agreement, see section 02 of the terms. We do not knowingly process data from children under 16 and do not direct the app at them. If we learn that such data has reached us anyway, we delete it.
Automated decisions
There is no automated decision in an individual case, including profiling, with legal or similarly significant effect within the meaning of Art. 22 GDPR. A meal’s rating is an estimate you can review and correct before saving it; see section 04.
Retention and deletion
- Data on the device: until you delete individual entries, choose “Clear all local data” under Settings › Privacy & data, or remove the app;
- iCloud backup: per the retention rules and settings of your Apple Account; the next backup overwrites the previous one;
- Photo and description with us: in memory for the duration of the request only, with no storage afterwards;
- Photo and description at OpenAI: response-history storage disabled; provider retention and exceptions are explained in section 04. This is not a guarantee of immediate deletion.
- Cached analysis results: 72 hours, with no link whatsoever to an installation or a person, so the same meal does not have to be analysed twice;
- Product data from Open Food Facts: cached for up to seven days, with no link to an installation;
- Unknown barcodes: with no link to an installation, until the gap in the product catalogue is closed;
- Genuineness record and quota: until you delete it, and at most 180 days after it was last used, after which an automatic clean-up removes it. Access tokens expire after 24 hours at the latest, and quota counters are deleted after 90 days;
- Security and operational logs: security events held in the database are deleted automatically after 90 days; the hosting provider’s logs only for as long as troubleshooting and abuse prevention require;
- Purchase status: for the term of the subscription, and afterwards for as long as a restore or a tax and commercial record requires;
- Statutory records: for the duration of mandatory retention and limitation periods, then deleted or anonymised.
There is no account that would need deleting, and you can still get rid of everything: Settings › Privacy & data › Clear all local data removes the history on the device and asks our server to delete this installation’s identifier along with its tokens and quota counters. The app introduces itself as a stranger afterwards. Your iCloud backup is managed through your Apple settings; if it cannot be opened on a new device, the app offers “Start a new backup” there, which replaces the old one.
Transfers to third countries
We pick European regions throughout and, where possible, European contracting parties. Several of the providers named above nonetheless belong to US groups and may have access from outside the EEA through group companies or sub-processors.
Where no adequacy decision under Art. 45 GDPR applies, we base such transfers on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, which form part of the respective data processing agreements, together with supplementary technical and organisational measures, in particular encryption in transit, data minimisation, and doing without identifiers that could establish a link to a person. Where a provider is validly certified under the EU-U.S. Data Privacy Framework, we additionally rely on the corresponding adequacy decision.
A copy of the Standard Contractual Clauses and details of the sub-processors used are available on request at [email protected].
Your rights
Subject to the statutory conditions you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR), and withdrawal of consent with effect for the future (Art. 7(3) GDPR).
To exercise them, write to [email protected]. Because FYG works without an account, we hold nothing under your name. You are identifiable to us only through two random identifiers: the one belonging to your app installation and, if you agreed to the usage statistics, the one belonging to those. Give us either, and we will disclose or delete what sits under it. You can also trigger the deletion yourself, see section 09. If even that does not let us identify you, the rights of access, rectification, erasure, restriction and portability do not apply to that extent under Art. 11(2) GDPR. We never ask for a copy of an identity document, and we advise against sending us more data than we would otherwise hold.
Your local data is therefore yours to handle, and completely so: in the app under Settings › Privacy & data you choose “Export local data”, which gives you a machine-readable file in the sense of Art. 20 GDPR, or “Clear all local data”. The same screen is where you withdraw consent: the “Usage statistics” switch for the statistics, and “Withdraw analysis consent” for the AI analysis.
Without prejudice to other remedies, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hannover, Germany, lfd.niedersachsen.de. You may also contact the supervisory authority of your habitual residence.
Security
We apply risk-based technical and organisational measures under Art. 32 GDPR: TLS-encrypted transfer throughout, an iCloud backup encrypted on the device, short-lived access tokens of which only hashes are held server-side, the genuineness check of the app installation, rate limits and daily quotas, locked-down database access, security records in which the IP address and the device browser identifier appear only as hashes, and data-minimising error output. Data minimisation is the most effective measure of all: what is never stored cannot leak. No system is entirely without risk; please also protect your device and your Apple Account.
Changes to this notice
We update this notice when features, recipients or the legal situation change. This version describes the iOS app. Material changes, such as a change of AI provider, server-side storage of your history, or an Android edition, will be made transparent in the app before they take effect. Where a new consent is needed, we will ask for it separately.