This is a courtesy translation. The legally binding version is the German original.
Privacy Policy
Effective: October 7, 2026
1. Data Controller
kerntrack is operated by:
Umekulsum Basuwala
MindDev53
Emmastraße 25
45130 Essen
Germany
Email: support@kerntrack.de
We are currently not required to appoint a Data Protection Officer (Art. 37 GDPR, § 38 BDSG): far fewer than 20 people here work with personal data, we do not process health data on a large scale, and none of our processing requires a data protection impact assessment. Section 3 says where your data is processed. Please direct privacy inquiries to: support@kerntrack.de
2. Overview: Your Data Belongs to You
kerntrack stores all health and nutrition data exclusively on your device. We have no access to this data. The app database is also kept out of the automatic device backups: on Android the app's backup is switched off, on iPhone the database is excluded from iCloud Backup. A copy exists only when you export it yourself: as an encrypted backup file or as a report in PDF or CSV format (section 6). If you use AI photo recognition, your photo leaves the device for analysis (section 3d).
We do not use any advertising SDKs, no Facebook SDK, no Google Analytics, and no other tracking services that process your health data.
3. What Data Is Processed?
a) Locally on your device (SQLite database):
- Name and age
- Height and weight
- Nutrition goal (lose / maintain / gain)
- Daily calorie target
- Food entries (meals, calories, macronutrients)
- Weight history (entered by you or, if connected, imported automatically from a smart scale)
- Water intake
- Activity level and the weekly plan for your daily target (calculated from your answers and, if connected, from wearable data)
- Reminder settings (enabled reminders, times, contents of the daily check)
If you use COACH mode, additionally, also exclusively local:
- GLP-1 companion mode: medication name, dose in mg, date and injection site of every logged injection, and your notes on it
- GLP-1 side effects: your daily entries for nausea, constipation, fatigue, headache, vomiting, diarrhoea and heartburn, plus free-text notes
- Tolerance markers on individual foods (“tolerated” / “problematic”)
- Intermittent fasting: start and end times of your fasting periods, the chosen protocol and the history
- Coach mode settings (e.g. protein and water targets, eating window, calorie cycling)
- Locally computed analyses derived from this data (weekly insights)
This list is not exhaustive: if further features are added, the data they require will likewise be stored exclusively on your device.
Information about medication and side effects is particularly sensitive health data within the meaning of Art. 9 GDPR. That is precisely why it leaves your device only when you export it yourself: kerntrack transmits it to no server, no processor and no health insurer. You alone decide whether to share it via the PDF/CSV export or as an encrypted backup file; in which case the file is passed on by you, not by us.
This data is NOT transmitted to our servers. It leaves your device only in a file that you export yourself (PDF/CSV or the encrypted backup file, section 6).
Reminder notifications are scheduled and displayed exclusively locally on your device; no data is transmitted to servers. Optionally, you can enable discreet notification texts so that no health-related terms appear on your lock screen.
b) Optional user account (Supabase, EU / Frankfurt):
- Email address
- if you sign in with Google, also: your name and the link to your Google profile photo
- if you sign in with Apple, also: an identifier of your Apple account for kerntrack
- Authentication tokens (encrypted)
If you create an account, your email address is stored on servers in the EU (Frankfurt, Germany). If you sign in with Google, Google also sends us your name and the link to your profile photo. Both are stored with your account and updated every time you sign in with Google. We attach the name to your support requests (section h); we do not use the photo link and do not fetch the photo. Signing in with Google itself is governed by Google's privacy policy.
If you sign in with Apple, Apple sends us your email address and an identifier that Apple uses for your account with kerntrack. If you chose "Hide My Email" at Apple, the email address is a forwarding address from Apple, through which our emails still reach you. Apple gives your name only to the app on your device: at most it ends up in your local profile and is not transmitted to our servers. Signing in with Apple itself is governed by Apple's privacy policy.
Processing is based on Art. 6(1)(b) GDPR (performance of a contract).
You can delete your account at any time directly in the app (Profile → Account → "Delete account") or request deletion at kerntrack.de/konto-loeschen. This permanently removes your account with all account data (the email address and, where applicable, the details from Google or Apple), your support requests and the AI usage counter from our servers. Active subscriptions are not cancelled by this; manage and cancel them via Google Play or the App Store. If you signed in with Apple, you confirm the deletion on the iPhone once with Apple; our server then also ends Sign in with Apple for kerntrack. That is not possible when the account is deleted by email request or on an Android device; in that case remove kerntrack yourself in your Apple Account settings under "Sign in with Apple". The email copy of your support requests in our support mailbox is not technically covered by this; we delete it on request, at the latest 90 days after the matter is closed, and in any case no later than 365 days after receipt.
c) API requests to Open Food Facts:
When you search for foods, open a search result, scan a barcode or open a food you have already logged that has a barcode (the app then reads its portion size), a request is sent to the Open Food Facts API (https://world.openfoodfacts.org, for search https://search.openfoodfacts.org). Your search term or barcode is transmitted, along with your IP address, technically required for every internet request. No other personal data is transmitted. Open Food Facts is an open, non-profit project (ODbL license).
d) AI Photo Recognition (Google Gemini API, PRO only):
When you use AI photo recognition (PRO feature), your photo is forwarded via a kerntrack server (Supabase Edge Function, EU / Frankfurt) to the Google Gemini API (Google LLC, Mountain View, USA). The photo is sent solely for the purpose of food recognition and is not stored on our server; for abuse and cost control we store only the number of your daily AI requests (user identifier, date, counter). Further data processing by Google is governed by Google Gemini API terms of service. Your photo leaves your device storage and is transferred to servers outside the EU/EEA.
Processing is based on your explicit consent (Art. 6(1)(a) GDPR), obtained in the app before the feature is first used; without it no photo is sent. The transfer to the USA relies on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795); Google LLC is certified under that framework. You can withdraw consent at any time by no longer using the feature or by clearing the app’s data. For more information on data processing by Google, see https://policies.google.com/privacy.
If you do not wish to use this feature, simply don't use AI photo recognition. All other app functions are unaffected.
e) Payment Processing and Subscription Management (RevenueCat):
For managing in-app subscriptions, we use RevenueCat, Inc. (San Francisco, USA). RevenueCat processes purchase data (transaction IDs, subscription status, device type) and a user identifier that links your subscription to your account: the ID of your kerntrack account, or without an account a random identifier assigned by RevenueCat. RevenueCat receives no health data, not your name and not your email address. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). We also evaluate the purchase data in RevenueCat statistically, for example how many subscriptions are taken out or cancelled, to improve our offer. Legal basis for this: Art. 6(1)(f) GDPR (legitimate interest). Data transfer: USA, secured by EU Standard Contractual Clauses (SCCs). For more information: https://www.revenuecat.com/privacy The payment itself is handled by the respective store under its own privacy policy: Google Commerce Limited (Ireland) for Google Play, Apple Distribution International Ltd. (Ireland) for the App Store. kerntrack receives no payment data (no card number, no bank account). At start-up the app on Android connects to Google Play Billing to check your plan and show prices, and Google's library for this sends technical usage data about that connection to Google. According to Google, this data shows how the interface is used, such as success and failure, and connection issues; Google uses it to improve the library's performance and to provide better support for errors (https://developer.android.com/google/play/billing/release-notes).
f) Crash and error reports (Sentry):
To detect and fix app crashes and errors, we use Sentry (Functional Software, Inc.) with data processing in the EU. When the app crashes, stops responding or a technical error occurs, only technical details are transmitted: device model, operating system version, app version, error message, stack trace and a random installation ID that Sentry creates once per installation. This ID is not linked to your account; it only tells us whether several reports come from the same installation, and a reinstall creates a new one. "Stops responding" means the app is blocked for a few seconds, or Android reports that it is not responding. A technical error also includes an error that does not close the app (for example a failed background task) and an internal notice when the app's reading direction (left to right or right to left) does not match the chosen language. If none of this happens, nothing is sent to Sentry. Health and nutrition data are never included; network and console contents are removed before sending. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable app). Crash and error reports are automatically deleted after 90 days. For more information: https://sentry.io/privacy/
g) Wearable sync (PRO only, optional):
When you connect a wearable, kerntrack reads health data. This is health data within the meaning of Art. 9 GDPR. The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time by disconnecting in the app or revoking the permission.
Health Connect (Android): Health Connect is an interface on your Android device. kerntrack reads the data directly on the device; there is no transfer to Google or to us, and no account and no access token are required. The following are read: steps, active calories, heart rate, sleep duration and weight. The data is stored exclusively locally in the app database; it leaves your device only in a backup file or a report that you export yourself (section 6). You can revoke access at any time in your device's Health Connect app, individually per data type.
Oura Ring: Oura requires a connection to the servers of Oura Health Oy (Finland, EU). Credentials are exchanged via a kerntrack server (Supabase Edge Function, EU) but are not stored there; on your device they are stored encrypted. The retrieved values are likewise stored only locally. Processing by Oura is governed by its own privacy policy.
Use: From this data kerntrack calculates your activity level, your daily target and your insights. The calculation happens entirely on your device. Health data from wearables is never transmitted to our servers, to analytics services or to third parties.
Deletion: Disconnecting deletes the credentials. “Permanently delete all data” and account deletion remove all wearable data from your device.
h) Support requests:
If you use the contact form in the app, your details (category, email address, message, device information, your user ID if you are signed in and, only if you sign in with Google, the name from your Google account) are stored on servers in the EU (Supabase, Frankfurt) to process your request. Legal basis: Art. 6(1)(b) or (f) GDPR. The data is deleted automatically 30 days after your request is resolved (the window covers follow-up questions and refund disputes); unresolved requests are deleted after 365 days at the latest. If you delete your account, your requests are removed immediately. In addition, the content of your request is forwarded by email to our support mailbox (support@kerntrack.de, Zoho Mail, EU) so that we can reply to you. For this we use Resend, Inc. (USA) as a processor; the same basis described in section 3i, secured by EU Standard Contractual Clauses (SCCs). Your sender address is set as the reply address. The email copy remains in the support mailbox until the matter is closed and is deleted at the latest 90 days thereafter, and in any case no later than 365 days after receipt. We delete it earlier on request.
i) Announcements and service emails:
We display important product announcements in the app. If you have an account, we may additionally inform you by email about material changes. For sending, we use Resend, Inc. (USA) as a data processor; recipient addresses are always hidden (BCC). Data transfer to the USA is secured by EU Standard Contractual Clauses (SCCs). Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or (f) GDPR (legitimate interest in informing you about material changes). For more information: https://resend.com/legal/privacy-policy These emails are purely service messages about material changes, not advertising; we do not collect a marketing consent. Where sending is based on Art. 6(1)(f) GDPR, you may object at any time under Art. 21 GDPR, informally by email to support@kerntrack.de. We will then stop emailing you; important notices remain visible in the app. Alternatively you can delete your account, which removes your email address entirely.
j) Photo contributions to Open Food Facts (optional):
If a scanned barcode is not found in the database, you can photograph the product and voluntarily contribute it to the public Open Food Facts database (Open Food Facts, non-profit association, France). What is transmitted: your product photos, the barcode, the app version and a randomly generated device identifier (no link to your name or account). The purpose is to expand the public food database. Legal basis: your consent for each transfer (Art. 6(1)(a) GDPR).
Important: the photos are published on Open Food Facts under an open license (ODbL) and become part of a globally public database; later deletion there is de facto no longer fully possible. Therefore, photograph only the product packaging, no people or private objects. Before transfer, an automatic pre-check (Google Gemini, via our EU server as described in section d) verifies that the image shows product packaging; unsuitable images are rejected and not forwarded to Open Food Facts. For the photo of the nutrition table, Google Gemini also reads the nutrition values. They go back to the app only and prefill your own food, which you then check and save; they are not sent to Open Food Facts. The transfer to Open Food Facts is routed through a kerntrack server; your IP address is not transmitted to Open Food Facts. For abuse control, we store the number of your daily contributions (device identifier, date, counter) and, for a daily limit per internet connection, your IP address with date and counter; no photos. We delete the counter per device identifier and the IP address after 7 days. If we block a device identifier from further photo contributions for abuse, we store it with the date and a reason; we delete the block automatically 12 months later. Legal basis for the counters and the block: Art. 6(1)(f) GDPR (legitimate interest in limiting abuse and costs). For assistance with deletion requests for already-published photos, contact support@kerntrack.de.
k) Barcode scanner on Android (Google ML Kit):
The app reads the barcode on your device; the camera image does not leave the device. On Android the scanner uses ML Kit, a library from Google, to do this. As soon as the scanner runs, ML Kit creates an identifier for this installation on your device and sends technical usage and diagnostic data to Google: device information such as manufacturer, model and operating system version, the app's package name and version, this installation identifier, performance metrics such as how long a detection takes, scanner settings such as image format and resolution, the size of input and output, the feature version, events such as start and detection, and error codes. Google's list does not name the camera image or the barcode read. Google says it uses the data for diagnostics and usage statistics and does not share it with third parties (https://developers.google.com/ml-kit/android-data-disclosure), and also to maintain and improve ML Kit and to detect misuse (https://developers.google.com/ml-kit/terms); Google's privacy policy applies to this: https://policies.google.com/privacy
From version 1.1.0 the app asks you on Android before the first scan whether you agree; only then does ML Kit start. If you say no (“Back to search”), ML Kit does not start, and you add foods through the search. We store your choice on your device with its date and the version of the text; if the text changes, we ask you again. Legal basis: your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can withdraw it at any time in Profile under “Barcode scanner with Google ML Kit”; we then ask you again before your next scan. A withdrawal applies to the future. A withdrawal stops ML Kit at once. Data ML Kit collected before can still go to Google afterwards. The identifier for this installation stays on your device until you uninstall the app or clear its data in the Android settings.
Versions before 1.1.0 do not ask: there ML Kit starts as soon as the scanner opens the camera, based on our legitimate interest in a working barcode scanner (Art. 6(1)(f) GDPR). With the update to version 1.1.0 you decide yourself.
On iPhone, a library that needs no internet connection reads the barcode, and none of this is sent.
l) This website (kerntrack.de):
This website is delivered via Cloudflare Pages (Cloudflare, Inc., USA). When you visit, Cloudflare processes technically necessary connection data (in particular your IP address) to deliver the site and protect against attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, performant delivery); third-country transfer secured by EU Standard Contractual Clauses (SCCs). This website does not set cookies and uses no tracking or analytics services. It only stores your chosen display setting (light or dark mode) locally in your browser (localStorage). This access is strictly necessary for the function you asked for and therefore needs no consent under § 25(2) no. 2 TDDDG; the setting is not sent to any server, and you can delete it through your browser's storage settings. For more information: https://www.cloudflare.com/privacypolicy/
4. Legal Basis (GDPR)
- Art. 6(1)(a) GDPR (Consent): You consent to local processing of your health data during initial setup. From version 1.1.0, on Android, you consent to the barcode scanner's diagnostic data before the first scan (Google ML Kit, together with § 25(1) TDDDG).
- Art. 6(1)(b) GDPR (Performance of a contract): For providing app functionality.
- Art. 6(1)(f) GDPR (Legitimate interest): For crash and error reports (Sentry), the statistical evaluation of purchase data (RevenueCat), service notifications, abuse control for photo contributions, in versions before 1.1.0 the diagnostic data of the barcode scanner on Android (Google ML Kit), and the technical delivery of this website.
- Art. 9(2)(a) GDPR (Explicit consent): Health data is a special category of personal data. You provide explicit consent during onboarding (step 5) or when connecting a wearable.
5. Data Storage and Deletion
Local data:
You can permanently delete all data at any time via Profile → “Permanently delete all data”. Uninstalling the app also deletes all locally stored data.
Retention periods at a glance:
| Data | Retention |
|---|---|
| Health & nutrition data (locally on your device) | Until you delete it (app UI or uninstall) |
| Wearable data & calculated weekly plan (locally on your device) | Until you delete it; no copy exists on any server, so there is no server-side retention period for this |
| Backup file (encrypted, app storage) | When sharing, only the most recently created backup file stays, encrypted, in app storage: each new export replaces the previous file there, and deleting all data removes it as well. Your own copies outside the app are unaffected |
| Doctor's reports (PDF/CSV, app storage) | Only the most recently created export of each type; removed at the next export and when all data is deleted |
| Account data (Supabase, EU: email address, and with Google sign-in also the name and the profile photo link, with Apple sign-in the Apple identifier) | Until account deletion: directly in the app (immediate, Profile → Account) or via a request at kerntrack.de/konto-loeschen (within 30 days) |
| Support requests (Supabase, EU) | Deleted automatically 30 days after your request is resolved; unresolved requests after 365 days at the latest. Immediately if you delete your account |
| Support requests (email copy, support mailbox) | Until the matter is closed, deleted at the latest 90 days thereafter; requests that were never processed no later than 365 days after receipt. Earlier on request |
| Crash and error reports (Sentry, EU) | Automatically deleted after 90 days |
| AI usage counter (Supabase, EU) | Automatically deleted after 30 days |
| IP address for the daily limit on photo contributions (Supabase, EU) | Automatically deleted after 7 days |
| Counter of your photo contributions per device identifier (Supabase, EU) | Automatically deleted after 7 days |
| Block of a device identifier for abusing photo contributions (Supabase, EU) | Automatically deleted 12 months after the block |
| Usage and diagnostic data of the barcode scanner on Android (Google ML Kit) | According to Google's retention periods |
| Subscription/purchase data (RevenueCat / app store) | Per the payment provider's retention periods and statutory retention obligations |
6. Data Export
You have the right to data portability (Art. 20 GDPR). Data export in CSV and PDF format is available directly in the app (Coach → Export; included in the COACH plan). Independently of that, you can request a copy of the data we hold (essentially the account data from section 3b) informally by email at any time.
Backup file: You can additionally export your data manually as a backup file (Profile → Data & Privacy). The file is encrypted on your device with a password only you know; we have no access to it and can neither reset it nor restore the file without it. Where the file goes is your decision (for example a cloud storage of your choice, or a folder on your device); where a cloud provider is involved, that provider is responsible for the processing there.
7. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
Since your health data is stored exclusively on your device, you can exercise most rights yourself (view, modify, delete data).
For requests regarding your account or other privacy concerns, contact: support@kerntrack.de
8. Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The responsible authority is typically the authority in your German federal state.
9. Minors
kerntrack is intended exclusively for persons aged 18 and older. The app is not intended for minors; only adults may create an account. Age is requested during sign-up and use below 18 is refused.
10. Changes to This Privacy Policy
We reserve the right to update this privacy policy when app functionality or legal requirements change. The current version is always available in the app under Profile → Privacy.
11. Not a Medical Device
kerntrack is not a medical product and not a medical device within the meaning of Regulation (EU) 2017/745 (MDR). The calculated calorie targets do not replace medical or nutritional advice.