GDPR rights
Effective 5 August 2026
1. Data controller
The data controller for ParseNutrition is Lucas Ekström, an individual developer operating from Sweden. All GDPR contact should go to support@parsenutrition.com. Please include the email address registered to your ParseNutrition account so we can identify the right record.
2. Why we process your data
ParseNutrition processes personal data only for the purposes explained here. The tracker and paid features use the data needed to deliver them; optional usage analytics is processed only after its separate opt-in. The purposes are:
- Creating and managing your account and preferences.
- Computing and adapting your calorie and macro targets from your body profile, weight trend, and logged workouts.
- Storing and syncing your food diary, recipes, and metrics.
- Looking up barcodes and, when enabled, branded products you search for.
- Producing AI estimates from photos or pasted recipe text you submit.
- Verifying purchases and the AI scan allowance.
- Serving one labeled Diary banner to eligible free users through Google Mobile Ads, only after any legally required UMP privacy choice.
- Measuring coarse setup, logging, AI, paywall, checkout, and restore steps only when you separately opt in, so we can understand retention and improve the product without receiving food text, nutrition/body values, photos, or account identity in Analytics.
- Keeping the service reliable and secure.
3. Legal bases (Articles 6 and 9 GDPR)
- Contract (Article 6(1)(b)): to deliver the app, sync your account, verify purchases, and provide support.
- Explicit consent for health data (Article 9(2)(a)): your food diary, weight and body metrics, pregnancy or breastfeeding status and due date when relevant, diet preset, fasting pattern, and logged workouts are health data. We process them only with the explicit consent you give in a dedicated onboarding step, never bundled into a general "I agree" checkbox. We record its timestamp and policy version, and require existing users to consent again before continuing when a new health-consent policy version requires re-consent. You may withdraw at any time at Settings → Account & data → Withdraw health-data consent. Active tracker processing stops immediately. The restricted screen still lets you export or delete local data, sign out or delete a signed-in account, and open the legal and support pages. Existing data is retained for those data-rights actions until you delete it; a signed-in cloud copy remains until account deletion or a verified deletion request.
- Consent (Article 6(1)(a), and Article 9(2)(a) where an analytics event can reveal use of a nutrition or health feature): for optional usage analytics through its separate, default-off switch; optional AI photo or recipe-text processing (with a separate 18+ attestation, recorded server-side before the first request); and separately for advertising processing where applicable law or Google's User Messaging Platform requires it. Analytics is not bundled with the health-data consent needed to operate the tracker. Analytics, advertising privacy, health-data consent, and AI consent are independent choices.
- Legitimate interest (Article 6(1)(f)): required, scrubbed crash reporting, server logs, abuse prevention, rate limiting, and purchase-fraud checks, each limited to what is needed and weighed against your rights.
- Legal obligation (Article 6(1)(c)): where we must retain data for tax, billing, or other legal requirements.
4. Categories of personal data
- Account data: email, display name, sign-in method.
- Support and request correspondence: sender address, name if supplied, subject, message body, attachments you choose, normal email-routing metadata, and only the account email or identifiers needed for early access, support, privacy, deletion, portability, or refund requests. Never send a password, payment-card details, or unrelated health information or photos.
- Body profile: birth year or age, biological sex, height, weight history, waist, neck and hip measurements, estimated body-fat percentage and FFMI, goal, activity level, pregnancy or breastfeeding status and due date when relevant, and diet preset. Body-fat and FFMI values are informational estimates and do not silently change calorie or macro targets.
- Food diary: meals, logged foods, portions, custom foods, recipes, calorie and macro totals.
- Activity and fasting: self-logged workouts, fasting sessions, water intake.
- AI inputs (AI tier): meal, nutrition-label, and recipe photos, and pasted recipe text. Our Cloud Function does not persist them, but the AI provider may retain them under its terms.
- AI usage accounting: monthly request count and remaining allowance associated with your account. The per-user record excludes photo or recipe contents, food names, barcodes, model details, token counts, and outcome telemetry.
- Preferences and recorded consents.
- Optional usage analytics, only after a separate opt-in: a pseudonymous Analytics app-instance identifier; coarse setup, food-log and logging-method, AI, paywall, checkout, and restore events; and app version, device category/model, operating-system version, language, session timing, acquisition source, and IP-derived country or region. No food/search text, diary or nutrition values, body measurements, health conditions, photos, account ID, email, barcode, notes, or raw errors are included.
- Purchase state: entitlement status, product identifier, scan allowance, verification timestamps.
- Advertising data for eligible free users: IP address and IP-derived approximate location, ad views and interactions, diagnostics, and a device or other identifier such as App Set ID. Google may collect and receive these categories for advertising, analytics, and fraud prevention or security. The Android Advertising ID permission is permanently removed and Advertising ID is not collected.
- Diagnostics: required scrubbed crash logs and technical metadata.
5. Where your data lives
The ParseNutrition repository configures Cloud Firestore and server functions for europe-west1 (Belgium, European Union). Production deployment and region checks remain release gates outside the repository. When account sync is active, your synced diary, profile, and metrics are scoped to your account. Transfers outside the EU are limited to the specific providers and purposes listed below.
6. Processors and service providers
ParseNutrition relies on the following providers. Each one only handles the data needed for its specific role.
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Functions, App Check, and optional Analytics) | Before sign-in, creating a Firebase installation identifier, performing App Check / Play Integrity attestation, and reading non-personal rollout configuration for security and abuse prevention. After sign-in, optional syncing of your diary, profile, and metrics between devices and running server code. Firebase Analytics uses a separate app-instance identifier and remains disabled until the separate device-level opt-in. It then receives only the coarse product events and basic technical information listed above; it is not linked to the ParseNutrition account or used for health-based advertising. | Cloud Firestore and Functions are configured for the European Union (europe-west1), with global Google infrastructure for sign-in. Optional Analytics may be processed in the European Union, United States, and other countries under Google's applicable data-processing and transfer terms. Region and retention settings are manual release checks. |
| Google Play | App distribution and, when offers are active, billing for optional AI access. | European Union and United States, under Google's own controller terms. |
| Google AdMob (Google Mobile Ads and its User Messaging Platform) | For eligible free users, presenting one labeled Diary banner and collecting an independent advertising privacy choice before an ad request where required. Google's European regulations message uses the IAB Europe Transparency and Consent Framework (TCF), communicates choices through TCF consent signals including the TCF string, and shows the current partner list and processing purposes. The configured partner set currently contains Google Advertising Products only; automatic inclusion of common or mediation partners is disabled. Any future partner or purpose change requires review of the message and this policy, with affected users re-prompted where applicable. Google may process IP-derived approximate location, ad views and interactions, diagnostics, and App Set ID for advertising, analytics, and fraud prevention or security. ParseNutrition does not provide diary, search, weight, fasting, pregnancy, profile, or other health data for ad targeting and does not collect Advertising ID. | Google infrastructure in the European Union, United States, and other countries under Google's applicable terms and transfer safeguards. |
| RevenueCat | When you open Plans, restore purchases, or the device has a local prior-purchaser marker, processing purchase and subscription status and linking the entitlement to your account. A non-buyer launch or sign-in does not by itself activate RevenueCat. It may receive your account identifier and email address as a subscriber attribute. Production offer and webhook readiness are operational release gates, not established by this policy. | United States, under a data processing agreement incorporating EU Standard Contractual Clauses. |
| Anthropic (Claude AI) | Estimating calories and macros from meal, recipe, and label photos or pasted recipe text you submit (AI tier, 18+, explicit consent). Inputs pass through our EU Cloud Function, which does not persist them. Anthropic may retain inputs under its terms; unless zero-data-retention is verified for the production account, we do not describe them as ephemeral. | United States, under Anthropic's Data Processing Addendum (EU Standard Contractual Clauses). |
| Sentry (Functional Software, Inc.) | Required crash and stability diagnostics with no in-app opt-out; personal and health fields are scrubbed before sending. | Configured for European Union data ingestion and residency; the production provider setting is a manual release check. |
| Porkbun email forwarding and Google Gmail | Delivering and retaining messages sent to support@parsenutrition.com for early access, support, privacy, deletion, portability, and refund requests. They process sender and recipient addresses, message content, attachments, and normal routing metadata; the private forwarding destination is not published. | Porkbun and Google's infrastructure may process data in the European Union, United States, or other countries under their applicable data-processing terms and transfer safeguards. |
| Open Food Facts | Not a processor: a public food database queried for barcode lookups and remote Store search. Barcode requests contain the barcode. Store-search requests use an HTTPS POST to the Open Food Facts Search-a-licious API and contain the text you choose plus locale-derived language preferences; they do not include a country parameter. Both identify the app through ParseNutrition's public User-Agent and expose your IP address to its servers; no account, body-profile, health-metric, or diary data is included. Open Food Facts may retain/use request IPs for security, technical analysis, and popularity or usage statistics and may infer an approximate country from the IP under its own privacy terms. | France (non-profit). Data licensed under ODbL. |
The 1.0.0+40 production candidate includes Google Mobile Ads and UMP but permits only one fixed Diary banner. Signed-out local use is free and may be ad-supported after UMP permits requests and every remote/runtime gate passes; signing in does not itself remove ads, while an active monthly/yearly subscription or historical lifetime ad-free entitlement does. It permanently removes Advertising ID and Privacy Sandbox AdServices permissions. No ad is requested while consent, server configuration, or app state is unresolved. Auth transitions, Firebase anonymous identities, and signed-in unknown or stale purchase, restore, or entitlement states also fail closed. Optional Firebase Analytics uses basic consent mode: native collection starts disabled, analytics storage is granted only after a separate opt-in, and ad storage, ad user data, and ad personalization stay denied. Withdrawing the choice disables future collection and resets the Analytics app-instance identifier and local Analytics data on that device; it does not erase events Google already received. Small local-only deduplication markers remain until Delete all local data, uninstall, or clearing app storage; they record only whether a one-time milestone was sent and the last logging day sent, not food, nutrition, body, or account content. Monthly AI request counts remain separate app activity for quota, abuse-prevention, and operational purposes. Sentry is used only for the required, scrubbed crash and stability diagnostics described above; its performance tracing and product-interaction breadcrumbs are disabled.
7. International data transfers
Where a provider above processes personal data outside the European Economic Area or the United Kingdom, we rely on that provider's data-processing terms and transfer safeguards: the European Commission Standard Contractual Clauses, the UK Addendum or IDTA where required, and adequacy decisions such as the EU-US Data Privacy Framework where the provider relies on one. Google Play processes billing and distribution data under Google's own controller terms rather than as our processor. Porkbun and Google process support correspondence as described in the provider table. For AI requests specifically, your submitted photo or recipe text is sent to Anthropic in the United States only after your explicit consent and 18+ attestation, under Anthropic's Commercial Terms and Data Processing Addendum. A copy or summary of the safeguards for any provider is available on request at support@parsenutrition.com.
8. Adult-only eligibility and legacy profiles
The closed-test app is for adults aged 18 or older. If an existing profile identifies its user as under 18, health tracking, targets, fasting, body composition and AI features are unavailable. That restriction does not erase the profile or remove access to export, account deletion, sign-out, support, or these legal notices. A legacy user can exercise the same privacy rights described below.
9. Your rights
If you live in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with equivalent protection, you have the following rights:
- Access (Article 15). Ask for a copy of the personal data we hold about you.
- Rectification (Article 16). Ask us to correct inaccurate or incomplete data — most of it you can edit directly in the app.
- Erasure (Article 17). Delete your account yourself from the app or request deletion by email; see the Delete your account page.
- Restriction (Article 18). Ask us to pause processing while a question about your data is resolved.
- Portability (Article 20). Receive your data in a structured, machine-readable format. Settings → Account & data → Export data (CSV) exports diary entries and weigh-ins. Contact support for a full access or portability copy of other account data.
- Object (Article 21). Object to processing that relies on legitimate interest.
- Withdraw consent (Article 7(3)). Future AI processing can be turned off at Settings → Account & data → Turn off AI processing. Core health-data consent can be withdrawn at Settings → Account & data → Withdraw health-data consent. Tracker processing then stops immediately without forcing deletion: the restricted screen still offers CSV export, local deletion, signed-in sign-out and account deletion, plus legal and support links. Required scrubbed crash reporting is not presented as a consent-controlled feature. Optional usage analytics can be changed independently under Settings → Account & data; turning it off stops collection and resets the Analytics app-instance identifier and local Analytics data on that device. Earlier event-level data remains subject to the retention period below. The same analytics control remains available from the restricted privacy screen. Where UMP requires it, advertising privacy choices can be reviewed or changed independently at Settings → Ad privacy choices; changing them does not grant or withdraw health-data or AI consent. Withdrawal does not affect processing that already happened lawfully.
- Automated decision-making (Article 22). ParseNutrition does not make decisions with legal or similarly significant effects using automated processing alone. The adaptive target engine adjusts calorie suggestions from your weight trend, but these are visible, editable suggestions inside a tracking app, not binding decisions.
We respond to every valid request within 30 days. If a request is complex we may extend this by another 60 days and will tell you why.
10. Retention periods
- Data on your device: until you uninstall, clear app storage, or use Settings → Account & data → Delete all local data. Account deletion erases cloud data but keeps the device copy unless you erase it separately. Delete all local data also removes the optional analytics choice and local event markers and resets Analytics on that device.
- Consent-withdrawal safety receipt: after Delete all local data, the app may retain only a Firebase account identifier, revoked state/server epoch and, while delivery is pending, a random request identifier and request time. This local-only receipt contains no diary, food, weight, body, or photo content and exists solely to keep processing off and retry an offline withdrawal. Confirmed account deletion, uninstall, or clearing app storage removes it.
- Synced account data: while your account is active; deleted within 30 days of account deletion.
- AI usage accounting: monthly request counts and the remaining allowance are kept with the account while it is active and deleted through the same account-deletion process.
- AI photos and pasted recipe text: not persisted by our Cloud Function, but Anthropic may retain them under its provider terms. They are not described as ephemeral unless zero-data-retention is verified for the production account.
- Deletion marker: a minimal record (account identifier and deletion time) kept after deletion so late billing events and sync attempts are safely rejected.
- Billing and tax records: kept by Google Play, RevenueCat, and our bookkeeping for up to 7 years where Swedish accounting law requires it.
- Diagnostic logs: our policy cap is 90 days; production provider enforcement is verified before release.
- Optional usage analytics: event-level data is limited by policy to 2 months. Verifying that the production Firebase Analytics property enforces that period is a release gate. Aggregate reports that no longer identify an individual app instance may remain. The app does not set an Analytics user ID, so account deletion cannot identify and erase earlier Analytics events; they remain subject to this retention limit.
- Support and rights-request correspondence: while the request is open and for up to 12 months after closure, for follow-up and resolution evidence. It is deleted sooner where appropriate, or retained longer only when a legal obligation or active dispute requires that.
11. Security
Sign-in is handled by Google's authentication system, traffic is encrypted in transit, and cloud data is access-controlled per user by database security rules. Server functions check app integrity and a valid session, and paid entitlements are verified server-side rather than trusted from the device. You help by keeping your credentials private and signing out on shared devices.
12. How to file a complaint
If you are not happy with how we have handled a request, please contact us first. If that does not resolve it, you have the right to file a complaint with a data protection supervisory authority. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): imy.se/en. Users in other EU member states can also file with their own national authority.
13. Contact
All GDPR requests, questions, and complaints: support@parsenutrition.com.