1. Introduction and Data Controller
This Privacy Policy explains how personal data is collected, used, and protected in connection with Protelino (the "App"). The data controller responsible for this processing, within the meaning of the General Data Protection Regulation (GDPR), is: Julian Waluschyk, Graf-Starhemberg-Gasse 5, 1040 Vienna, Austria, reachable at support@protelino.com. Given the current scale of processing, the Developer is not required under GDPR Article 37 to appoint a Data Protection Officer; this will be reassessed as the App's user base grows.
2. Scope of This Policy
This Policy applies to all personal data processed through the App, including data entered directly by users, data generated through use of the App's features, and data received from integrated third-party services described below. It does not apply to third-party websites or services linked from within the App, which are governed by their own privacy policies.
3. Categories of Personal Data Collected
Depending on how the App is used, the following categories of data may be processed: (a) account data, such as an email address or an anonymous device-linked identifier, used to enable cloud sync for subscribers to Protelino Pro (see Section 9 for how this differs from the free plan); (b) profile data, such as a name or nickname, avatar selection, and the metabolic condition associated with a profile; (c) health and nutrition data, including tracked nutrients, daily targets, logged meals and portion sizes, and blood spot/lab values entered by the user; (d) photographs submitted for the AI-assisted food recognition feature, processed transiently and not retained by the Developer after a result is returned; (e) barcode numbers submitted when scanning a packaged product; (f) subscription and purchase data processed through Apple App Store, Google Play, and RevenueCat; and (g) limited technical data necessary for the App to function, such as device locale (used to determine an appropriate default region for available medical food products) and the device's IP address, which is inherently processed by each of the third-party service providers described in Section 7 (including a font-delivery network used to render the App's typeface) as a basic function of network communication, in the same way it is by any internet-connected service.
4. Special Category Data (Health Data)
Data about a user's or a managed profile's metabolic condition, tracked nutrients, logged meals, and lab values constitutes "special category data" under Article 9 of the GDPR. This data is processed only with the user's explicit consent, given by creating a profile and choosing to enter this information, and is used solely to provide the App's tracking, calculation, and reporting features. This data is never used for advertising, is never sold, and is never shared with third parties for any purpose other than the technical provision of the App's own features (see Section 7). Consent for this processing may be withdrawn at any time by deleting the relevant profile or the account, as described in Section 13.
5. Purposes and Legal Bases for Processing
Personal data is processed on the following legal bases: performance of a contract (GDPR Art. 6(1)(b)), for account creation, sync, and subscription management; explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)), for the collection and processing of health-related data described in Section 4 and for the optional use of AI-assisted food recognition; and legitimate interest (GDPR Art. 6(1)(f)), for maintaining the security, integrity, and proper functioning of the App, limited to what is necessary and balanced against the user's rights and interests.
6. Children and Family Profiles
The App is not directed at children, and account registration is restricted to individuals who are at least 18 years old (see Terms, Section 3). An account holder may create profiles for family members, including minors, for whom they are a parent or legal guardian, and is responsible for the accuracy and lawfulness of any data entered on that minor's behalf. The Developer does not knowingly collect personal data directly from a minor independent of a parent or guardian's account.
7. Third-Party Recipients and Processors
The following third parties may process personal data in connection with the App's features: Supabase, which provides the Developer's backend infrastructure and processes data across three distinct services - Supabase Auth (account authentication), the Supabase Postgres database (storage of synced account and profile data for users who enable cloud sync), and Supabase Edge Functions (server-side logic, including relaying AI Scan requests as described below and processing subscription-status webhooks); RevenueCat (subscription and purchase management), which processes purchase receipts and an anonymous purchaser identifier to validate and manage subscriptions; Google LLC / Google Ireland Limited (Gemini API), which processes photographs submitted through the App's AI Scan feature - a photograph is sent from the device to the Developer's own Supabase Edge Function, which relays it to Google's Gemini API either to identify food items and estimate nutrient content, or, for a photo of a food product's own printed nutrition label, to read the values already printed there; the photograph is not stored by the Developer at any point in that process and is not linked to a user's account; Google LLC (Google Fonts), which may deliver the App's typeface at runtime and, in doing so, receives the device's IP address, though no account, profile, or health data is included in that request; Google LLC / Google Play Services (on-device barcode and ML model delivery), used to keep the on-device barcode-scanning component up to date - barcode images themselves are analyzed on the device and are not transmitted to Google; Open Food Facts, which receives barcode numbers submitted when scanning a packaged product to return publicly available product information, with no account or health data included in that request; and Apple Inc. and Google LLC, which process payment and subscription data as the operators of the App Store and Google Play Store, under their own respective privacy policies. Each of these providers acts as an independent controller or processor for the data it receives and is contractually or legally required to implement appropriate technical and organizational safeguards. Links to each provider's own privacy policy are available in the App's Credits & Data Sources section.
8. International Data Transfers
Some of the providers listed in Section 7 are based in, or process data in, the United States or other countries outside the European Economic Area (EEA). Google LLC self-certifies under the EU-U.S. Data Privacy Framework (DPF), an adequacy mechanism recognized by the European Commission, for its relevant services including the Gemini API and Google Fonts. Where a provider is not, or not fully, covered by an adequacy decision, the transfer is instead safeguarded by the European Commission's Standard Contractual Clauses or another mechanism recognized under the GDPR, as implemented by that provider.
9. Data Retention
The App's data storage differs by plan. On the free plan, all profile, meal, and lab-value data is stored exclusively on the user's own device and is never transmitted to or stored on the Developer's backend; it is retained until deleted by the user or until the App is uninstalled. Because this data is stored using the device's standard local storage, it may also be included in that device's own operating-system-level backup (for example, Android's back-up-to-Google-account feature or Apple's iCloud device backup), a function controlled by the user's own device and account settings rather than by the Developer. Subscribing to Protelino Pro enables cloud sync: this same data is then also transmitted to and stored on the Developer's backend infrastructure, provided by Supabase and hosted on servers located within the European Union, so it can follow the user across devices. Synced data is retained for as long as the associated account remains active and is deleted, together with the account, within a reasonable period following account deletion, except where retention is required by law (for example, billing records). If a Pro subscription lapses, previously synced data already stored on the backend is not automatically deleted, but no further data is transmitted there until the subscription is renewed; it can be deleted at any time as described in Section 13. In line with the GDPR's storage limitation principle, synced data belonging to a subscription that has remained expired, with no renewal, for 48 consecutive months is automatically and permanently deleted from the backend; this does not affect the account itself (which a user can still sign in to) or any data stored only on the user's own device. Photographs submitted for AI-assisted food recognition are not retained by the Developer after processing regardless of plan. When a user exports a report (for example as a PDF) or otherwise shares data outside the App through a device's own share sheet, email, or messaging apps, that copy is no longer within the Developer's control, and its further handling is governed by the recipient service's own terms and the user's own choices.
10. Data Security
Appropriate technical and organizational measures are used to protect personal data, including encrypted transmission (TLS) for any data sent to or from the App's backend, encrypted local storage for sensitive on-device values, and access controls limiting who can access stored data. No method of electronic storage or transmission is completely secure, and while reasonable efforts are made to protect personal data, absolute security cannot be guaranteed.
11. Automated Processing and AI Features
The App's AI Scan feature uses an automated image-recognition service (Google's Gemini API) to suggest a food identification and estimated nutrient values from a photograph. This is a decision-support suggestion only: it is always presented to the user for review, correction, or rejection before being logged, and does not produce any automated decision with legal or similarly significant effects on the user within the meaning of GDPR Article 22.
12. Cookies and Tracking
The App does not use advertising cookies, third-party advertising SDKs, or cross-app/cross-site tracking technology, and does not sell personal data to third parties for any purpose, including for cross-context behavioral advertising.
13. Your Rights Under the GDPR
Subject to the conditions set out in the GDPR, users have the right to: access the personal data held about them (Art. 15); request rectification of inaccurate data (Art. 16); request erasure of their data (Art. 17); request restriction of processing (Art. 18); receive their data in a portable format (Art. 20); object to processing based on legitimate interest (Art. 21); and withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)). The rights to access, rectification, erasure, and consent withdrawal can generally be exercised directly within the App, by viewing, editing, or deleting profiles, entries, or the account. A structured export of a user's own data (for the right to data portability) and other requests can be made by contacting support@protelino.com. Users also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of their habitual residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for the Developer is the data protection authority of the German federal state in which the Developer is established.
14. Additional Rights for California and Other U.S. Residents
Residents of California and certain other U.S. states may have additional rights under applicable state privacy laws (such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act), including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. The Developer does not sell or share personal information as defined under these laws. Requests to exercise these rights may be sent to support@protelino.com.
15. Data Breach Notification
In the event of a personal data breach likely to result in a risk to users' rights and freedoms, the Developer will notify the competent supervisory authority without undue delay and, where required by applicable law, will notify affected users.
16. Changes to This Policy
This Policy may be updated from time to time to reflect changes to the App's features or applicable law. Material changes will be indicated by an updated "Last updated" date, and, where required by law, users will be notified through the App.
17. Contact and Complaints
Questions, requests, or complaints regarding this Policy or the processing of personal data may be directed to support@protelino.com.