Privacy Policy
This is a convenience translation. Only the German version is legally binding.
Last updated: March 2026
1. Data Controller
Markus Köplin
Fehmarner Str. 1, 04159 Leipzig, Germany
Email: support@mkhub.de
2. What Data Is Processed?
- Nutrition data: Meals, calories, macronutrients (protein, carbohydrates, fat), water intake
- Body data: Weight, body fat, body measurements, height, age, gender
- Activity data: Steps, active calories, workouts (via Apple Health)
- Sleep data: Optional sleep duration and simple sleep-context insights from Apple Health
- Usage data: Subscription status, anonymous installation identifier (only when using AI features)
3. Storage Location
Your nutrition, body, activity, and settings data is stored locally on your device. Optionally, it is synced across your devices via iCloud.
AI coach chats are stored locally on the device for short-term continuation and are automatically limited. There is no dedicated persistent server for nutrition or health data; AI requests run through a Cloudflare Worker proxy, and online food search uses external food data services.
4. AI Processing (Plus/Pro)
When you use AI features (chat, photo analysis, text input), the entered text or photos are transmitted via an encrypted proxy service to OpenAI as the technical service provider.
- Transmission is encrypted.
- No account data such as name, email, or Apple ID is automatically transmitted. However, the content of your request may contain personal data if you enter or upload such information yourself.
- To protect against misuse and for technical provision, a pseudonymous random installation identifier may be processed. It is not IDFA, not cross-app tracking, and cannot be directly attributed to you.
- Continuable AI coach chats store only role, text, timestamp, and technical response pointers locally. Images, Base64 data, and nutrition-context snapshots are not stored in the chat history.
- For chat continuation, the app uses OpenAI Responses with stored application state. These responses may be retrieved for a limited time to continue context and for defensive recovery.
Your inputs for AI features are processed by our technical AI service provider OpenAI. Based on our current technical and contractual setup, the transmitted content is not used to improve or train general models. The applicable contractual and technical settings of the service provider apply.
AI recommendations are generated automatically but are not the basis of automated individual decisions within the meaning of Art. 22 GDPR. They serve solely as non-binding guidance.
5. Food Search
When searching for food items online, queries are sent directly from your device to Open Food Facts (France). In this process, your IP address is transmitted for technical reasons. Open Food Facts processes this data in accordance with its own privacy policy. Which additional data is technically processed as part of the request is determined by Open Food Facts under its own responsibility.
6. Apple Health
The app reads and writes health data via Apple Health. Access only occurs with your explicit permission and can be revoked at any time in the iOS or Health settings. Sleep data is optional, evaluated locally only for careful nutrition prompts, and is not sent to AI or external services. Apple Health data is not transmitted to external third parties by the app. Synchronization via Apple services you have activated, particularly iCloud, remains unaffected.
6a. Siri, Spotlight, and Shortcuts
NährWert provides local App Intents for Siri, Spotlight, and the Shortcuts app. They allow faster logging or querying of water, weight, and daily values. These intents access locally stored SwiftData in the App Group store and do not send nutrition or health data to our own servers. Write actions and sensitive queries require device authentication and use Apple's system dialogs. Apple Health is not written without an existing permission.
7. Recipients and Third-Country Transfers
We only share personal data to the extent necessary for the described features.
Apple / iCloud
Purpose: Optional synchronization of your app data via iCloud
Legal basis: Art. 6(1)(a) or (b) GDPR, depending on usage
Country / third-country aspect: Processing may occur across borders; Apple's privacy terms apply
OpenAI
Purpose: Processing your inputs when using AI features and continuable chat context
Legal basis: Art. 6(1)(a) GDPR; for health data additionally Art. 9(2)(a) GDPR
Country / third-country aspect: USA; safeguarded via the EU-US Data Privacy Framework adequacy decision and/or Standard Contractual Clauses
Cloudflare
Purpose: Secure AI proxy, App Attest verification, and rate limiting
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR
Country / third-country aspect: USA; safeguarded via the EU-US Data Privacy Framework adequacy decision and/or Standard Contractual Clauses
Open Food Facts
Purpose: Online food search and retrieval of product information
Legal basis: Art. 6(1)(b) GDPR or usage at your explicit request
Country / third-country aspect: Depends on the technical provision of the service
8. Storage Duration
Your data is stored as long as you use the app. You can delete all data at any time within the app (Settings → Delete All Data). Local AI coach chats are limited to 14 days and a maximum of 100 messages per active session and are removed locally by “Delete Chat” or “Delete All Data”. When the app is uninstalled, local data is generally removed by the operating system. iCloud data can be deleted via iCloud settings. AI content already transmitted to OpenAI is subject to OpenAI's application-state and privacy rules.
Technical log or abuse prevention data related to AI features is only stored for as long as necessary for secure provision and error prevention.
9. Your Rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection.
Right of withdrawal: You may withdraw any consent given at any time with effect for the future.
- AI features: You can withdraw consent within the app or by email to support@mkhub.de.
- Apple Health: You can additionally revoke access at any time in your device's Health or iOS settings.
The lawfulness of processing carried out prior to withdrawal remains unaffected.
For local data, you can delete all data directly in the app: Settings → Delete All Data.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is:
Sächsische Datenschutz- und Transparenzbeauftragte (SDTB)
Maternistraße 17, 01067 Dresden, Germany
11. Changes
This privacy policy may be updated with app updates or changes to data processing. The current version is always available in the app under Settings → Privacy Policy and at naehrwert-app.de/en/privacy.