Privacy Policy
Last updated:
We keep data collection to the minimum needed to run a calorie & macro tracker. No ads, no third-party trackers, nothing sold.
Controller
Nikolai Rybalkin, Franz-Schubert-Straße 13, 79331 Teningen, Deutschland. Contact: nikolai@dzvene.com.
What we collect
Account: your email address and a hashed password (we never store the plaintext password).
Profile & logs you enter: sex, age, height, weight, activity, goal, food diary entries, weigh-ins and the targets/calibration derived from them.
Technical: standard server logs (IP, timestamp, request) kept briefly for security and operation.
Why (legal basis)
To provide the service you signed up for — performance of a contract (Art. 6 (1)(b) GDPR).
To keep the service secure and working — our legitimate interest (Art. 6 (1)(f) GDPR).
Local storage (no cookies for tracking)
Your browser stores a login token and your language/theme preferences locally. These are essential for the app to work and are not used to track you across sites.
Sharing & hosting
We do not sell your data and do not share it with advertisers. Data is processed on hosting infrastructure located in the European Union (${HOSTING}).
Retention
We keep your data while your account exists. Delete your account at any time (Settings → Data & account) and all your data is erased.
Your rights (GDPR)
You can access, rectify, export and erase your data, and object to or restrict processing. The app gives you self-service export and deletion under Settings → Data & account.
For any request, contact nikolai@dzvene.com. You also have the right to lodge a complaint with a supervisory authority.
Processors we use
Two things leave our own server, each for one purpose, and neither of them to advertise to you.
Google Ireland Ltd. — the language model that reads a meal you typed in plain words and turns it into food entries (Gemini API): the sentence you wrote is sent, no account data. Also Google Sign-In, if you choose it.
one.com A/S (Denmark) — the mail server that sends sign-in and password e-mails.
Both act on our instructions under a data processing agreement (Art. 28 GDPR). Our usage statistics run on our own server (Umami, no cookies, no third party).
Transfers outside the EU
Google is contracted in Ireland but may process data in the United States, on the basis of the EU-US Data Privacy Framework and the EU standard contractual clauses. Everything else stays on the German server.
Push notifications
If you switch on reminders, your browser's push service (Google, Mozilla or Apple, depending on the browser) receives an address to deliver the message to. The message itself contains no food or weight data.
Right to object (Art. 21 GDPR)
Where we rely on our legitimate interest — keeping the service secure — you may object at any time, giving reasons arising from your particular situation.
Data protection officer
We have not appointed one: we are a small company and our processing does not meet the thresholds of Art. 37 GDPR. Data protection questions are answered by us, at the address above.
Supervisory authority
You may complain to a supervisory authority. You may contact the competent supervisory authority where you live.
Changes
We may update this policy; the date above reflects the latest version.



