← Back to Fuelbit

Privacy Policy

Last updated: [Publication date — set when deployed]

Deutsche Version

1. Controller

Fuelbit is an AI-powered food and nutrition tracking application operated by a sole proprietor established in Germany.

The controller within the meaning of Article 4(7) of the General Data Protection Regulation ("GDPR") is:

[First and last name — set before publication]

trading as Fuelbit

[Street and house number — set before publication]

[Postcode — set before publication] Weimar

Germany

Email: privacy@fuelbit.app

For privacy-related requests, please use the subject line "Privacy Request".

In this Privacy Policy, "Fuelbit", "we", "us" and "our" refer to the controller identified above.

2. Scope of this Privacy Policy

This Privacy Policy applies to the processing of personal data in connection with:

  • the Fuelbit mobile application;
  • the Fuelbit website;
  • Fuelbit user accounts;
  • AI-based food-photo analysis;
  • subscriptions and purchases;
  • customer-support communications;
  • related services that link to this Privacy Policy.

This Privacy Policy does not apply to independently operated third-party services that have their own privacy policies, including app stores and payment providers acting as independent controllers.

3. Categories of personal data we process

The personal data we process depends on how you use Fuelbit.

3.1 Website and technical access data

When you visit our website or connect to our Services, our hosting and infrastructure providers may automatically process:

  • IP address;
  • date and time of access;
  • requested page or resource;
  • referring website;
  • browser type and version;
  • operating system;
  • device type;
  • language settings;
  • HTTP status and error information;
  • limited server, security and diagnostic logs.

We process this information to deliver the website and app, ensure technical stability, detect misuse and protect our systems.

3.2 Account and authentication data

When you register for or use a Fuelbit account, we process:

  • your email address;
  • a unique user and account identifier;
  • authentication status;
  • account creation date;
  • sign-in and sign-out events;
  • password-reset and email-verification status;
  • session and security information.

Authentication is provided through Supabase Auth.

We do not have access to your password in readable form.

3.3 Nutrition and health-related data

Depending on the features you use, you may provide or generate:

  • meal and food entries;
  • food labels and descriptions;
  • calorie and nutrient information;
  • dietary and nutrition goals;
  • weight information;
  • water-consumption logs;
  • fasting start and end times;
  • meal times;
  • food preferences;
  • calorie history;
  • calculated nutrition values;
  • other information you voluntarily enter into the app.

Some of this information, individually or in combination, may constitute data concerning health within the meaning of Article 9 GDPR.

Please do not enter medical diagnoses, medication information, genetic data or other sensitive information that is not necessary to use Fuelbit.

3.4 Food photos

When you use the photo-analysis feature, we process:

  • the food photo you upload;
  • the visual content appearing in the photo;
  • technical image information transmitted by your device;
  • the connection between the photo and your meal entry;
  • the nutritional description and estimates generated from the photo.

Fuelbit is intended to analyse photos of food. Please avoid uploading photos containing:

  • identifiable persons or faces;
  • identity documents;
  • payment cards;
  • home addresses;
  • medical documents;
  • screens containing personal information;
  • other information unrelated to food analysis.

We do not use facial-recognition technology.

3.5 AI-generated results

Based on an uploaded food photo, Fuelbit may generate estimates concerning:

  • the food or meal shown;
  • portion size;
  • calories;
  • macronutrients;
  • other nutritional values.

These results are estimates and may be inaccurate. You can review and correct the generated result before or after saving it.

3.6 Analytics information

If you give your consent, we use PostHog Cloud EU to understand how Fuelbit is used. See PostHog's privacy policy.

The analytics data may include:

  • the name of the in-app action performed, drawn from a fixed, predefined set of event names (for example, that a meal was scanned — never its content);
  • the time of the event;
  • the application version;
  • the operating system and device model;
  • language and region settings;
  • a randomly generated device identifier.

We configure PostHog so that it does not intentionally receive:

  • your name;
  • your email address;
  • meal photos;
  • food descriptions;
  • weight;
  • nutrition goals;
  • water logs;
  • fasting data;
  • other health-related content.

We never call an identification function that would link analytics data to your account; analytics remain tied to a random device identifier, and no person profiles are created. Session recording is disabled. IP-based location enrichment is disabled at the project level, and the app additionally strips disallowed data fields before any event is sent.

Although we do not intentionally send directly identifying information to PostHog, analytics identifiers and technical information may still constitute personal data. We therefore describe this processing as pseudonymous analytics rather than claiming that it is completely anonymous.

PostHog analytics are activated only after you have given the required consent. Declining or withdrawing consent does not prevent you from using Fuelbit's core features.

3.7 Local notifications

You may configure local reminders, for example for water intake, fasting or meal tracking.

Local notifications are generated on your device using the settings you select. You can disable them through the app or your device settings.

We do not use remote push notifications for these reminders.

3.8 Subscription and transaction information

If you purchase a paid subscription or premium feature, we may process:

  • your account identifier;
  • the product or subscription selected;
  • transaction identifier;
  • purchase date;
  • subscription status;
  • renewal and expiry date;
  • cancellation or refund status;
  • country, currency and limited tax information;
  • confirmation that a payment was successful.

Payments are processed by:

Stripe (Stripe Payments Europe, Ltd.)

Where you choose to pay using Apple Pay or Google Pay, the payment is initiated through that wallet and processed by Stripe. Apple or Google act as independent controllers for the wallet itself under their own privacy policies (Apple, Google). We receive confirmation of the payment and the limited transaction details listed above, not your full card number.

If Fuelbit is distributed via Google Play with Google Play Billing in the future, Google will be added as a payment provider.

We do not normally receive your complete payment-card number.

The relevant app store or payment provider may process payment and account information as an independent controller under its own privacy policy.

3.9 Support communications

If you contact us, we process:

  • your name, if provided;
  • your email address;
  • the content of your request;
  • any attachments you voluntarily provide;
  • relevant account and technical information;
  • our correspondence with you.

Please do not send passwords, complete payment-card information or unnecessary health data through email.

4. Purposes and legal bases

Where the GDPR applies, we process personal data on the following legal bases.

4.1 Account creation and provision of Fuelbit

We process account data, meal records, goals, water logs, fasting records, photos and nutrition information to:

  • create and administer your account;
  • authenticate you;
  • provide meal and nutrition tracking;
  • store your history;
  • calculate nutrition information;
  • provide AI-based photo analysis;
  • allow you to export or delete your information;
  • provide paid features.

Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps taken at your request before entering into a contract.

4.2 Health-related information

To the extent that weight, nutrition goals, food logs, fasting information, photos or calculated results constitute data concerning health, we process them on the basis of your explicit consent.

Additional condition: Article 9(2)(a) GDPR — explicit consent to the processing of data concerning health for the specified Fuelbit purposes.

You may withdraw your consent at any time. Because the relevant health-related information is necessary for Fuelbit's core nutrition-tracking functionality, withdrawal may mean that we can no longer provide some or all account-based features. You may still exercise your rights concerning information already processed.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4.3 AI food-photo analysis

We send a food photo to Groq Cloud to identify food and estimate nutritional information. See Groq's privacy policy.

Legal basis: Article 6(1)(b) GDPR.

To the extent that a photo or the resulting analysis constitutes or reveals health data, the additional legal basis is your explicit consent under Article 9(2)(a) GDPR.

4.4 Optional analytics

We use PostHog analytics only after you provide consent.

Legal basis: Article 6(1)(a) GDPR.

Where the analytics technology stores information on or accesses information from your device, consent is also obtained in accordance with Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), unless a statutory exception applies.

You may withdraw analytics consent at any time. On this website, use to change or withdraw your decision. In the mobile app, use Profile → Data & Privacy → Product analytics. Withdrawal is as easy as giving consent and takes effect immediately.

4.5 Security, fraud prevention and technical operation

We process server logs, authentication logs, IP addresses and security information to:

  • protect user accounts;
  • prevent fraud and unauthorised access;
  • detect and investigate security incidents;
  • maintain the availability and integrity of Fuelbit;
  • diagnose technical errors.

Legal basis: Article 6(1)(f) GDPR.

Our legitimate interests are the secure, stable and abuse-resistant operation of Fuelbit. We limit this processing to what is reasonably necessary and balance our interests against your rights and freedoms.

4.6 Support

We process support requests to respond to you and resolve problems.

Legal basis:

  • Article 6(1)(b) GDPR where your request relates to your account or use of Fuelbit;
  • Article 6(1)(f) GDPR for general enquiries and the efficient administration of our business.

4.7 Payments and subscriptions

We process subscription and transaction information to activate, administer and verify paid features.

Legal basis: Article 6(1)(b) GDPR.

We retain information required for tax, accounting and legal compliance.

Legal basis: Article 6(1)(c) GDPR.

4.8 Legal claims and compliance

We may process relevant information to comply with legal obligations or to establish, exercise or defend legal claims.

Legal bases:

  • Article 6(1)(c) GDPR — compliance with legal obligations;
  • Article 6(1)(f) GDPR — our legitimate interest in protecting and enforcing our legal rights.

5. Is providing the information mandatory?

Creating an online account requires an email address and authentication information.

Using nutrition-tracking features requires the relevant meal, nutrition or goal information. Using AI photo analysis requires the transmission of the selected photo.

You are not legally required to provide this information. However, without the information required for a feature, we cannot provide that feature.

Analytics consent is optional. Refusing analytics does not affect access to Fuelbit's core functionality.

6. Food photos and Groq AI processing

6.1 Storage in Fuelbit

Food photos linked to saved meal entries are stored in Supabase Storage in the West EU region in Ireland (eu-west-1). See Supabase's privacy policy.

A stored photo remains associated with the relevant meal until:

  • you delete the meal;
  • you delete the photo, where that option is available;
  • you delete your account;
  • the relevant retention period otherwise expires.

Deleting a meal through the app is intended to delete the associated active-storage photo.

Residual technical copies may remain temporarily in logs or caches until they are overwritten in accordance with the applicable retention cycle.

6.2 Transmission to Groq

To analyse a photo, Fuelbit sends the image to Groq Cloud in the United States over an encrypted connection.

Groq processes the image on our behalf to generate an analysis. We do not authorise Groq to use your food photos or generated results to train or fine-tune AI models.

A second transmission to Groq occurs only if you use the AI buddy chat. In that case the message you write is sent together with the buddy's name and a snapshot of the current day — calories consumed and your calorie goal, protein, carbohydrates, fat, water intake against your water goal, and whether a fast is currently running — so that the reply can refer to your actual figures. This snapshot is nutrition and therefore health-related data, and it is transmitted as text rather than as an image. Your email address and your account identifier are not included. The same Zero Data Retention setting and the same transfer safeguards described below apply.

6.3 Groq retention

We have enabled Groq's Zero Data Retention setting for the relevant organisation and endpoints. According to Groq's applicable service documentation, customer input and output are not retained for system-reliability and abuse-monitoring purposes when Zero Data Retention is enabled. Groq may still process limited usage metadata that does not contain the submitted customer content.

7. Recipients and service providers

We disclose personal data only where necessary to provide and secure Fuelbit, comply with the law or protect legal rights.

7.1 Supabase

We use Supabase for:

  • account authentication;
  • database hosting;
  • storage of meal photos;
  • storage of account and nutrition information;
  • related infrastructure functions.

Our primary Supabase project is hosted in the West EU region in Ireland (eu-west-1).

Supabase processes personal data on our behalf as a processor. Certain account, billing, security, support or operational data may be processed by Supabase and its subprocessors outside the EEA.

7.2 Groq

We use Groq Cloud for AI-based analysis of food photos.

Groq receives:

  • the selected food photo;
  • instructions necessary to perform the analysis;
  • technical request information;
  • the generated output.

Groq acts as our processor for this processing.

7.3a Food-data reference sources

To identify packaged products and look up nutrition values, our server functions query the following public reference databases. These requests contain the barcode or the food name you entered, together with our technical contact details. They do not contain your account identifier, email address or any other data that identifies you.

  • Open Food Facts (non-profit, France) — barcode and product lookup. Privacy policy
  • USDA FoodData Central (United States Department of Agriculture) — nutrition reference values. Service information

7.3b Password-breach check

When you choose a password, the app checks it against the Have I Been Pwned breach database using the k-anonymity method: only the first five characters of a SHA-1 hash of the password leave your device, and the comparison is completed locally. Your password, the full hash, your email address and your account identifier are never transmitted. Privacy policy

7.3c Email delivery

Where a message from the contact form is forwarded to us by email, delivery is carried out by Resend (Resend, Inc., United States). Resend receives the name, email address and message text you submitted. This forwarding is only active when configured; the message is stored in our own database in either case. Privacy policy

7.3 PostHog

With your consent, we use PostHog Cloud EU for product analytics.

PostHog's EU cloud infrastructure is hosted in Frankfurt, Germany.

PostHog receives only the analytics events and technical fields described in this Privacy Policy. We do not intentionally send meal content, photos, weight, goals or other health-related information to PostHog.

7.4 App stores and payment providers

Apple, Google and any other payment provider used for subscriptions may receive transaction, account, device and payment information.

Depending on the processing activity, these providers may act as independent controllers or processors.

7.5 Hosting and technical contractors

Our website hosting provider and authorised technical contractors may access limited data where necessary to:

  • host the website;
  • maintain the app;
  • resolve technical issues;
  • investigate security incidents;
  • implement updates.

Such access is restricted to authorised persons and is subject to confidentiality, security and data-processing obligations.

Current website hosting and content-delivery providers:

  • Vercel Inc., USA (website hosting). Server-side processing for this site is configured to run in Vercel's Frankfurt region (fra1), so the personal data handled by our server routes is processed in the EU. Vercel Inc. remains a US company, so this is a data-residency measure rather than a change of jurisdiction; the transfer safeguards described in Section 8 continue to apply.
  • DNS for fuelbit.app is operated by Vercel (ns1/ns2.vercel-dns.com). We do not currently use a separate CDN or DNS provider.

7.6 Authorities and professional advisers

We may disclose information to:

  • courts and competent public authorities where legally required;
  • tax authorities;
  • lawyers;
  • accountants and tax advisers;
  • insurers;
  • other professional advisers.

8. International data transfers

Fuelbit is operated from Germany.

Some processing takes place outside the European Economic Area, particularly when food photos are transmitted to Groq in the United States or where a provider or subprocessor outside the EEA has authorised access to service data.

Where required, we use appropriate safeguards for international transfers, including:

  • an adequacy decision of the European Commission;
  • the EU–U.S. Data Privacy Framework where the relevant recipient validly participates in it;
  • the European Commission's Standard Contractual Clauses;
  • supplementary technical, contractual and organisational measures;
  • another legally recognised transfer mechanism.

For transfers connected with Groq: our contract for Groq Cloud is with Groq UK Limited, the contracting entity for EEA-domiciled customers under the Groq Services Agreement. Transfers to the United Kingdom are covered by the European Commission's UK adequacy decision. Processing involving Groq's United States infrastructure is safeguarded by the EU Standard Contractual Clauses incorporated in Groq's Data Processing Addendum, which is binding by incorporation into the Services Agreement.

For Supabase, PostHog and other processors, we use the applicable data-processing and transfer arrangements required by data-protection law.

You may contact us to request additional information about the safeguards used for an international transfer. Confidential or security-sensitive parts of contractual documents may be redacted.

9. Data retention

We retain personal data only for as long as necessary for the relevant purpose, subject to legal and security obligations.

9.1 Account and nutrition information

Your account, meal records, nutrition data, goals, water logs and fasting information are retained while your account is active.

When you delete your account, active account data is deleted without undue delay, normally within 30 days, unless retention is required by law or necessary for legal claims or security purposes.

9.2 Food photos

A photo stored as part of a meal entry is retained until:

  • you delete the relevant meal or photo;
  • you delete your account;
  • the entry otherwise expires under the applicable retention rules.

Groq's separate processing and retention are described in Section 6.3.

9.3 Backups

Fuelbit currently operates without automated database backups. Deleted data is therefore not retained in backup copies beyond the deletion process described above. Residual technical copies may persist briefly in logs or caches until they are overwritten.

9.4 Analytics data

PostHog analytics information is retained for:

12 months

After this period, the information is deleted or aggregated in accordance with our configuration and the provider's applicable procedures.

Withdrawal of consent prevents future analytics collection but does not necessarily require immediate deletion of lawfully collected aggregated statistics that can no longer be associated with you.

9.5 Security and authentication logs

Ordinary server, sign-in and security logs are normally retained for between 7 and 30 days.

Information connected with suspected fraud, unauthorised access, abuse or a security incident may be retained longer where necessary to investigate and document the incident.

9.6 Support communications

Support correspondence is normally retained for up to three years after the request has been closed, unless a shorter or longer period is necessary because of the nature of the matter or a legal obligation.

9.7 Transaction, tax and accounting records

Transaction, invoice, payment and accounting records are retained for the statutory periods applicable in Germany.

Depending on the category of document, the applicable period may generally be six, eight or ten years.

9.8 Consent and compliance records

Records demonstrating consent, withdrawal, legal notices, account deletion and privacy requests may be retained for the period necessary to demonstrate compliance and defend legal claims.

10. Security

We implement technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.

These measures include, where appropriate:

  • encryption in transit using HTTPS/TLS;
  • encryption at rest provided by our infrastructure providers;
  • account authentication;
  • access controls;
  • Row-Level Security within Supabase;
  • restriction of administrative access;
  • separation of user records;
  • logging and security monitoring;
  • confidentiality obligations;
  • review of processor and contractor access.

Row-Level Security is designed to prevent users from accessing other users' records. It does not exclude limited access by authorised administrators, infrastructure providers or technical personnel where such access is necessary and legally permitted.

No internet-based service can guarantee absolute security.

You should use a strong, unique password and protect access to your email account and device.

11. Your rights under the GDPR

Where the GDPR applies, you may have the following rights, subject to the applicable statutory conditions and exceptions.

11.1 Access

You may request confirmation as to whether we process your personal data and obtain access to that data and related processing information under Article 15 GDPR.

11.2 Rectification

You may request correction of inaccurate information and completion of incomplete information under Article 16 GDPR.

11.3 Erasure

You may request deletion of your personal data under Article 17 GDPR.

This right may be limited where retention is required by law or necessary for legal claims.

11.4 Restriction

You may request restriction of processing under Article 18 GDPR.

11.5 Data portability

Where processing is based on consent or contract and is carried out by automated means, you may receive the personal data you provided in a structured, commonly used and machine-readable format under Article 20 GDPR.

You may also use the "Export my data" function in the Profile section of the app.

11.6 Objection

You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR under Article 21 GDPR.

We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required for legal claims.

11.7 Withdrawal of consent

Where processing is based on consent, you may withdraw it at any time.

You may withdraw analytics consent through:

On this website: .

In the mobile app: Profile → Data & Privacy → Product analytics

You may withdraw consent for account-based processing of health-related information by:

  • deleting your account;
  • using the relevant privacy setting, where available;
  • contacting us at privacy@fuelbit.app.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11.8 Complaint

You have the right to lodge a complaint with a data-protection supervisory authority.

The supervisory authority responsible for our establishment is:

Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)

Häßlerstraße 8

99096 Erfurt

Germany

You may also contact the supervisory authority in the EU or EEA country of your habitual residence, place of work or place of the alleged infringement.

11.9 Exercising your rights

You can exercise certain rights through the "Export my data" and "Delete account" options in the Profile section of the app.

You may also contact:

privacy@fuelbit.app

We may request information reasonably necessary to verify your identity. If you are already authenticated in your account, we will generally use the existing account authentication rather than requesting an identity document.

We normally respond within one month. Where permitted by law, this period may be extended by up to two further months because of the complexity or number of requests.

12. Account deletion

You can delete your account through:

Profile → Data & Privacy → Delete account

Public account-deletion page:

https://fuelbit.app/delete-account

Account deletion removes or schedules for deletion:

  • your account;
  • meal entries;
  • nutrition and health-related information;
  • water and fasting logs;
  • stored food photos;
  • other information associated with your account.

Deleting the app from your device does not automatically delete your online account.

Information required for tax, legal or security purposes may be retained for the applicable period.

13. Automated processing and AI analysis

Food photos are analysed through an automated AI system to identify food and estimate nutritional values.

The process generally works as follows:

  1. You select or take a food photo.
  2. The photo is transmitted to Groq.
  3. The AI system analyses visible food and portions.
  4. Fuelbit receives estimated nutritional information.
  5. You can review and change the result.

The estimates may be inaccurate and do not constitute medical, nutritional or dietary advice.

Fuelbit does not use the results to make decisions producing legal effects or similarly significant effects concerning you.

The photo analysis therefore does not constitute solely automated decision-making within the meaning of Article 22(1) GDPR.

14. Local storage and device permissions

Fuelbit may store information on your device where necessary to:

  • maintain app settings;
  • remember your notification preferences;
  • maintain authentication state;
  • provide local reminders;
  • provide requested app functionality.

Where storage or access is strictly necessary to provide a function you requested, no separate consent is required under Section 25(2) TDDDG.

Optional analytics or other non-essential device access is used only after consent where required.

Fuelbit may request access to:

  • the camera, when you choose to take a food photo;
  • the photo library, when you choose an existing photo;
  • notifications, when you activate reminders.

Access is used only for the function you select. You can withdraw device permissions through your operating-system settings.

15. Children

Fuelbit is not directed to children under 16 years of age.

Persons under 16 may not create a Fuelbit account or provide health-related information through the app.

We do not knowingly collect personal data from children under 16.

If we learn that a child under 16 has created an account or provided personal data, we will take reasonable steps to delete the information and close the account.

A parent or guardian who believes that a child has provided personal data may contact us at privacy@fuelbit.app.

16. Users outside the European Union

Fuelbit is operated by a controller established in Germany. We apply the protections described in this Privacy Policy to users regardless of location, subject to mandatory local law.

Depending on your place of residence, you may have additional rights, including rights to:

  • access personal information;
  • correct inaccurate information;
  • request deletion;
  • obtain a portable copy;
  • withdraw consent;
  • object to or opt out of certain processing;
  • appeal a refusal of a privacy request;
  • complain to a local privacy regulator.

You may submit a request without identifying a particular privacy law.

California and other United States users

Fuelbit does not:

  • sell personal information;
  • share personal information for cross-context behavioural advertising;
  • use personal information for targeted advertising;
  • provide personal information in exchange for financial incentives;
  • use health-related information for advertising.

Third-party processors may collect information only to provide the services described in this Privacy Policy, subject to the applicable contractual arrangements.

Some browsers offer a "Do Not Track" signal. Because there is no universally accepted standard for interpreting all Do Not Track signals, Fuelbit does not currently respond separately to general Do Not Track signals.

This does not change the fact that optional analytics are used only after the applicable consent where required.

If a legally recognised opt-out preference signal applies to Fuelbit in the future, we will process it as required by the relevant law.

17. No sale or advertising use

We do not sell or rent personal data.

We do not disclose personal data for cross-context behavioural advertising.

We do not use food photos, nutrition data, weight, goals, water logs or fasting information for advertising.

We do not permit our processors to use Fuelbit user data for their own advertising purposes.

18. Changes to this Privacy Policy

We may update this Privacy Policy when:

  • Fuelbit features change;
  • our providers change;
  • our processing changes;
  • legal requirements change;
  • security or retention practices change.

The current version will be published with a revised "Last updated" date.

If a change materially affects how we process personal data, we will provide an additional notice through the app, website or email where appropriate.

Where a new purpose or processing activity requires consent, we will request consent separately. Continued use of Fuelbit is not treated as consent where applicable law requires a specific affirmative action.

19. Contact

For questions, complaints or privacy requests, contact:

[First and last name — set before publication]

trading as Fuelbit

[Street and house number — set before publication]

[Postcode — set before publication] Weimar

Germany

Email: privacy@fuelbit.app

Please use the subject line "Privacy Request".