Home / Privacy Policy
Legal
Privacy Policy. In plain English.
The short version: Bloatless works with meal photos, assessment answers, and after-meal check-ins, so some health-related information leaves your phone. Meal photos are uploaded to our private backend and sent through OpenRouter to the configured AI provider for analysis. There is no account or login: records are tied to a random install ID, plus the first name you choose to enter. Settings includes a data-deletion flow. The separate creator affiliate program collects applicant and payout details only from people who choose to apply, and its secure dashboards use an essential sign-in cookie.
1. Controller (Art. 13(1)(a) GDPR)
Dr. Jan Philip WahleSiedlungsweg 24, 37124 Rosdorf, Germany
Email: [email protected]
A Data Protection Officer is not required under Art. 37 GDPR and Section 38 BDSG. Questions are routed to the contact email above.
2. Overview of data processing
Processing of personal data is limited to what is needed to run the app, produce your trigger analysis, improve the product, measure acquisition, operate the website and creator affiliate program, and respond when you write in. We do not sell your data and Bloatless contains no third-party advertising. For each activity below we name the purpose, legal basis, recipients, and retention approach.
3. No account — a random install ID and your chosen first name
The consumer app has no sign-up. When you first launch the app, it generates a random identifier (the install ID) and stores it in your device’s Keychain. Server records, purchase status, and analytics are keyed to that ID. During onboarding, the first name you choose and your assessment answers are also synced to the record so the app can personalize the plan and measure funnel completion. We do not receive your email address, phone number, Apple ID, or payment-card details from the app. If you email support, we of course receive the contact details and message you send. Affiliate applicants separately provide identity and contact details through the website as described in Section 9.
4. Meal photos and AI analysis
What happens to a snap:when you photograph a meal, the app resizes the image (max 1024 px) and uploads it to our backend, where it is stored in a private storage bucket that only our server code can read. The image is passed through OpenRouter, Inc. (San Francisco, USA) to the configured vision provider — currently Google’s Gemini API — which returns a dish name, likely ingredients, FODMAP levels, and a bloating-risk estimate. A separate copy stays on your device for meal history.
Processor controls:Bloatless restricts each OpenRouter request to providers that OpenRouter marks as not collecting user data. OpenRouter states that it does not use API inputs or outputs for its own model training; the upstream model provider’s current handling terms still apply. See the OpenRouter Privacy Policy and Gemini API terms. We do not use photos for advertising, sell them, or use them to train our own models. Photos are never included in analytics events.
Retention: the backend copy and analysis are kept so the app can show meal history and compute reports. They are deleted when you delete the meal or complete Delete my data. OpenRouter and the model provider may retain limited request or security metadata according to their current terms and legal obligations.
Legal basis: Art. 6(1)(b) GDPR (performing the analysis you request) and, where a meal photo or accompanying information reveals health data, your consent under Art. 9(2)(a) GDPR. Before the first AI transfer, the app explains the recipients and asks you to allow it. International transfers use the safeguards provided by the relevant processor terms, including standard contractual clauses where applicable.
5. Check-ins, survey answers, and trigger reports
What is synced: onboarding can collect your first name, sex, age range, height and weight, symptoms, suspected triggers, diet, diagnosis answer, habits, goal, plan choice, meal times, and notification choice. Check-ins contain a 0–4 severity rating and may include an optional note. Voice input is transcribed on your device; only the resulting text is uploaded, not the recording.
Why: these values personalize the plan, schedule reminders, correlate meals with how you felt, and let us understand where people complete or leave onboarding. Health-related inputs are voluntary. Legal bases are Art. 6(1)(b) GDPR for the requested tracking and report service, and consent under Art. 9(2)(a) GDPR where the information is special-category health data. You may withdraw consent for future processing by deleting your data or contacting us; this does not affect processing that was lawful before withdrawal.
Trigger reports: your meal analyses and check-ins are combined into per-ingredient statistics. The numbers are computed by our own code; an AI text model only phrases the summary around them. Reports are informational predictions, not diagnoses, and are stored with your other data until you delete it.
Storage: this information is stored in the backend database and private object storage operated through Supabase, Inc. Access is restricted to server-side functions; the app has no direct database access. App records remain until you delete the relevant meal or complete Delete my data, except for the narrow anti-abuse record described in Section 8 and records we must keep by law.
6. Purchases and subscriptions
Billing is handled by Apple through the App Store — Apple is the merchant of record. RevenueCat, Inc. (San Francisco, USA) processes the random install ID, product, subscription status, transaction identifiers, country, price, estimated tax, and Apple commission so the app can unlock your plan, restore purchases, and measure revenue. We never receive your card details, Apple ID, name, or address. See Apple’s privacy policy for their side. Legal basis: Art. 6(1)(b) GDPR. Purchase and accounting records are retained for the applicable statutory periods.
7. Product analytics and attribution
PostHog:we use PostHog for product analytics, on PostHog’s EU cloud, so event data is stored in the European Union. Events carry the random install ID, device and app information, and product actions such as onboarding progress, paywall views, check-in severity, and purchases. The completed assessment event also contains the stable option values you chose, including body metrics and symptom-related answers. We do not send meal photos, check-in note text, or voice recordings to PostHog. If you were assigned a pricing variant, events carry that random assignment so we can compare offers. RevenueCat additionally forwards subscription events such as renewals, cancellations, and billing issues to the same random ID.
AppsFlyer: to understand which campaigns bring people to Bloatless, AppsFlyer Ltd. processes the random install ID, device and app information, advertising or vendor identifiers available under your iOS privacy settings, and campaign or deep-link values, and shares attribution with RevenueCat. This can be used for advertising measurement. Crash data:if you opt in to share diagnostics with developers in iOS Settings, Apple may provide crash and performance reports; you can change that choice in Settings → Privacy & Security → Analytics & Improvements.
Legal basis: Art. 6(1)(f) GDPR for product improvement, reliability, and aggregate acquisition measurement; consent applies where platform rules or applicable law require it. You can object at any time (Section 11).
8. Deleting your data, and the referral program
Delete my data:Settings → “Delete my data” erases your meal photos, analyses, check-ins, survey answers, trigger reports, referral records, and the install record itself from our servers, and clears the app on your device. Deleting the app alone does not reach the server copy — use the button or contact us. Data deletion does not cancel an App Store subscription.
Invites: if you invite friends, we store your invite code and which installs redeemed it, so unlocks can be granted. To stop a deleted install from farming referral rewards by re-registering, deletion leaves a minimal tombstone containing the random install ID, whether it was referred, whether it qualified, and the deletion time. The Keychain copy of the random install ID also remains on the device. These narrow anti-abuse records are not used for personalization or marketing.
Reminders:meal reminders and check-in pings are scheduled locally on your device. If you grant notification permission, your device’s push token may be stored with your install record so we can deliver server-sent notifications; it is deleted with everything else.
9. The website, download attribution, and creator partners
bloatless.app is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA), acting as our processor under Art. 28 GDPR. Every request produces a temporary log entry — IP address, date and time, URL, status code, browser and operating system, referrer — used to keep the site online, prevent abuse, and investigate bugs. Legal basis: Art. 6(1)(f) GDPR. Logs are retained only as long as needed for operations, security, troubleshooting, and legal obligations under the hosting configuration in use.
Ordinary public-site use: the public landing page and free tools do not use a web-analytics script or tracking pixel. The free tools (FODMAP checker, quiz, swap finder, and diary) run in your browser and do not send their inputs to us.
App Store buttons:when you click an App Store download link, the outbound AppsFlyer URL may carry the current page and button placement, campaign parameters, a Google or Meta click ID already present in the inbound URL, and the referring site’s host name. AppsFlyer records that click so it can be matched to an app install and first open as described in Section 7. This does not store anything in your browser.
Affiliate applications and dashboards: if you apply to become a creator partner, we process your name, email, public channel, audience and promotion description, postal address, tax ID if supplied, PayPal email, terms acceptance, and optional marketing consent to review the application, administer the agreement, prevent abuse, meet accounting duties, and pay commission. Approved partners sign in through single-use email links; an essential, HTTP-only session cookie keeps that dashboard signed in for up to 30 days. Rejected applications are deleted after 12 months. Approved partner, commission, payout, and accounting records are kept for the agreement and applicable statutory retention periods. Legal basis: Art. 6(1)(b), Art. 6(1)(c), and Art. 6(1)(f) GDPR.
Tracked creator links: opening an approved affiliate link records the partner, time, destination, and privacy-protected hashes of IP address and user agent. AppsFlyer carries the partner code and a random click ID through the App Store so RevenueCat purchases can be attributed for 60 days. We anonymise request metadata after 24 months; commission and payout records remain for accounting. Affiliate attribution never includes meal photos, check-ins, survey answers, or trigger reports.
10. Contact by email
When you email us at [email protected], we process your email address, your name (if you provide one), and the content of your message to answer you. Legal basis: Art. 6(1)(b) GDPR (pre-contractual or support) or Art. 6(1)(f) GDPR (legitimate interest in responding to correspondence). Retention: we keep the thread until the matter is resolved, then delete it unless we are required by law to retain it.
11. Your rights under the GDPR
You can reach us about any of these rights at [email protected]:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7(3))
Because app data is keyed primarily to a random install ID rather than an account, we may need information from the affected installation to locate the correct record. We will never ask for your Apple password or payment-card details.
12. Right to lodge a complaint
You may file a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Our competent authority is:
Die Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5, 30159 Hannover, Germany
Phone: +49 511 120-4500
Email: [email protected]
Web: lfd.niedersachsen.de
13. Data security
We use industry-standard measures to protect data: TLS-encrypted connections (HTTPS) for everything in transit, a private storage bucket for photos with no public access, database access restricted to server-side functions, and routine security updates. No system is perfectly secure, but the design keeps the sensitive parts — your photos and how-you-feel data — behind the narrowest possible door.
14. Automated decision-making
The AI meal analysis and the trigger report are automated, but they are suggestions with no legal or similarly significant effect in the sense of Art. 22 GDPR — they inform what you might test next, and every decision about what you eat is yours. Bloatless makes predictions, not diagnoses, and does not replace medical advice.
15. Changes to this policy
We update this policy when the law, our tools, or our practices change. The current version is always available at this URL. Material changes are noted at the top by updating the date.