Privacy Policy
Version of 2026-09-08
Language
This English text is a convenience translation. The legally binding version is the German one, which you can read by switching the app language to German. In case of any discrepancy, the German version prevails.
Controller
The controller for the processing is Atahan Kiraz, Oberbettringer Straße 9, 73525 Schwäbisch Gmünd, Germany (aia.support@icloud.com).
For any privacy question, an email to the address above is all it takes.
The principle
AIA stores your health and training data exclusively on your device. It is not transferred to a server, not analyzed, not shared and not sold.
This is not a statement of intent but the way the app is built: there is no path through which we could receive this data. Only you can pass it on — for example via the data export, or by writing to us.
What data lives on the device
Profile (name, sex, year of birth, height), body weight and body measurements, workouts with exercises, sets, weights and repetitions, nutrition entries, water intake, goals and analyses.
Part of this is health data within the meaning of Art. 9(1) GDPR. It is processed exclusively on your device and under your sole control; we do not receive it and have no access to it at any time. To the extent any legal basis on our side is required for this processing at all, it is your explicit consent under Art. 9(2)(a) GDPR, which you give when completing the setup through the confirmation step named there, and which you can withdraw at any time with effect for the future by deleting the entries or removing the app.
Entering data is voluntary. There is no legal or contractual obligation to do so — without entries, the app simply cannot show any analyses.
AIA is reserved for persons aged 16 or older; the setup does not accept a lower age. From 16 you can give the consent yourself (Art. 8(1) GDPR in conjunction with German law); parental consent is not required. For users under 18 the app never calculates a calorie deficit — growth comes first.
Encryption
The app’s storage is encrypted with AES-256. The key lives in the iOS keychain, whose key material is protected by the device’s Secure Enclave.
This keeps the data unreadable even if someone obtains a backup of your device or the app’s file container.
Account — voluntary
The app works fully without an account. If you sign in, you do so via “Sign in with Apple”; Apple transmits an identifier and, depending on your choice, an email address — on request a forwarding address generated by Apple.
What is stored: the account identifier and the email address transmitted by Apple, your first name as a display name, your subscription status (details under “Subscription”) and the record of consents you have given. In addition there is technical sign-in data that operating the account requires: the times of your sign-ins and, per active session, IP address and device identifier. Short-lived technical logs also arise at the processor when the app accesses the server. Health data is expressly not part of any of this.
The server is operated by Supabase in Frankfurt am Main (EU). The legal basis is Art. 6(1)(b) GDPR — without an account, a subscription cannot be attributed across devices. A data processing agreement under Art. 28 GDPR is in place with the provider.
You can delete your account in the app at any time. This permanently removes the account, profile, subscription record and consent records from the server. Your training and nutrition data on the device is not affected.
Subscription
Purchases run through Apple. We never see payment data; it is processed exclusively by Apple.
If you are signed in to your account at the time of purchase, the app hands your account identifier to Apple so that Apple can attribute changes of your subscription to us. Apple then reports the state of the subscription to our server: the chosen product, the status (such as trial, active, billing issue, expired or refunded), the end of the current period and an Apple-internal transaction identifier. Only the most recent state is stored, no history. If you sign in only after a purchase, the app transmits the purchase confirmation signed by Apple to our server to attribute the subscription to your account. The legal basis is Art. 6(1)(b) GDPR.
Without an account, a purchase remains anonymous to us: Apple’s reports about it contain no account identifier and are discarded by our server without being stored.
Barcode search
When you scan a barcode, only the digit sequence of the barcode is sent to the open food database Open Food Facts (world.openfoodfacts.org) to retrieve the nutrition facts. For technical reasons, your IP address is visible to the operator in the process.
No image is transmitted and no image is stored; the camera reads the code on the device. The legal basis is Art. 6(1)(b) GDPR.
Found products are cached locally so the same item does not have to be looked up again.
Smart Scan (photo analysis)
When you photograph a dish with Smart Scan, the photo is transmitted to our server for the nutrition estimate and passed on to Anthropic, whose AI model estimates the components and amounts. The app language and a random device identifier are transmitted along with it; the identifier serves solely to limit the daily number of scans and has no link to your person or your account.
We do not store the photo — it is processed exclusively to answer your request. Anthropic does not use content submitted via the interface to train its models, as agreed by contract, and retains it only temporarily for abuse prevention. The result (components and nutrition facts) then lives only on your device, like any other entry.
Smart Scan is voluntary: if you do not use it, no photo leaves your device. Do not include people or things in the picture that do not belong there. The legal basis is Art. 6(1)(b) GDPR.
Reminders
Reminders are scheduled entirely on the device and triggered by iOS. No push token is registered and nothing is transmitted to a server.
No ads, no tracking
AIA contains no advertising, no analytics tools, no crash reports to third parties and no advertising identifiers. There is no tracking across app or website boundaries.
Recipients
Apple (Apple Distribution International Ltd., Ireland) — for “Sign in with Apple”, delivery of the app and handling of purchases.
Supabase — operation of the account database and the server functions (such as forwarding the Smart Scan photo), server location Frankfurt am Main. A data processing agreement under Art. 28 GDPR is in place.
Anthropic (Anthropic PBC, USA) — exclusively for Smart Scan: receiving the photo for the nutrition estimate. Use for AI training is contractually excluded.
Open Food Facts — exclusively when scanning a barcode, see above.
Beyond this, no data is transmitted to third parties. There is no sale and no sharing for advertising purposes.
Transfers to third countries
The account database is located in the EU. At Apple, processing may also take place in the United States; Apple bases this on the EU-US Data Privacy Framework or on standard contractual clauses under Art. 46 GDPR.
For Smart Scan, Anthropic processes the photo in the United States; Anthropic is certified under the EU-US Data Privacy Framework.
Storage periods
Data on the device stays until you delete it or remove the app. There is no outside access and no automatic deletion.
Account data, subscription status and consent records are deleted as soon as you delete your account.
Technical logs of the server operation are deleted automatically, at the latest after seven days. Session data (IP address, device identifier) exists until sign-out or session expiry, at most until account deletion; the sign-in log is cleared with the account deletion.
The daily Smart Scan counter (random device identifier, date, count) is deleted after seven days at the latest.
The local cache of scanned products can be cleared in the app.
No automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR takes place. The app calculates recommendations but makes no decisions with legal effect for you.
Contact by email
If you write to us, we process your message and your sender address solely to handle your request (Art. 6(1)(f) GDPR). The correspondence is deleted once it is no longer needed.
Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw any consent you have given at any time with effect for the future.
Since your health data lives on your device, you exercise these rights there directly: entries can be changed and deleted at any time.
For portability, the app offers the data export under “Account”: it writes all your data into a JSON file that you can pass on or use in another program. The file is deliberately unencrypted so that it is readable — store it accordingly.
You also have the right to lodge a complaint with a data protection supervisory authority. The one responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Postfach 10 29 32, 70025 Stuttgart, Germany, poststelle@lfdi.bwl.de.
Changes
If this policy changes in substance, its version number increases and the app points this out to you.
This website
This website is served via GitHub Pages, a service of GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you visit, GitHub processes technically necessary access data — in particular the IP address of your device — in server logs to deliver the page and secure its operation (legal basis: legitimate interest, Art. 6(1)(f) GDPR). We have no access to these logs. GitHub is certified under the EU-U.S. Data Privacy Framework; details are in GitHub’s privacy statement: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement
The website itself sets no cookies, uses no analytics or advertising services and loads nothing from third-party servers — fonts and images are hosted locally. We ourselves collect no personal data when you visit.