Legal

Privacy Notice

This notice explains what personal data Count Your Bites collects, why we use it, and the choices you have. It applies to visitors and registered users, and covers your rights under the GDPR and other data protection laws.

Last updated: 9 September 2026

The short version

  • We store your account details (name, email) and whatever food, exercise, weight, and target data you choose to log.
  • Your weight and dietary logs count as health data under EU law, so we only use them if you clearly and separately agree to it. Logging food, weight, and activity is the app's core function, so declining this consent means you can create an account but can't use the tracking features.
  • We use your data to run the app, keep your account secure, and send essential emails (like password resets). We never sell your data.
  • We share data only with the service providers who help us run the app (hosting, database, email), under contracts that require them to protect it.
  • You can ask to see, correct, export, or delete your data at any time, and you can withdraw consent by deleting your account.

The full details, including your legal rights, are below.

1. Who is responsible for your data?

The operator of this Count Your Bites deployment is legally responsible for your data (the "controller"). These details must be filled in before this notice is published:

  • Controller: Johannes Hernehult
  • Privacy contact: use the contact form below.

Use the contact form below if you have questions or want to exercise your rights.

Contact us about privacy

Use this form for privacy questions or requests about your personal data. Please do not include unnecessary health or other sensitive information.

2. What data do we collect?

  • Account data: your name, email address, password (stored securely, never in plain text), whether you've verified your email, and account dates.
  • Food and activity data: whatever you choose to record — food, exercise, weight, nutrition preferences, and daily targets.
  • Consent records: whether and when you agreed to the health-data processing described below, and if you later withdrew it.
  • Technical and security data: session information used to keep you signed in, stop abuse, and keep the service running.

Your weight, food, and activity entries can reveal things about your health — for example patterns that relate to weight management or dietary conditions. See Section 3 for how we handle this.

3. Health data and your consent

Your weight, food logs, and nutrition goals are treated as health data under Article 9 of the GDPR — a category the law protects more strictly than ordinary personal data, because it can reveal something about your physical or mental health.

Because of that, we only process this data if you give explicit consent — a clear, separate "yes" you give before you start logging this information, not something bundled into a general terms-of-service acceptance.

Logging food, weight, and activity is the core function of the app, so it isn't possible to use the tracking features without this data. If you don't give consent, you can still create an account and access account settings, but you won't be able to use the food, weight, or activity tracking itself.

You can withdraw consent at any time by deleting your account in the app, or by contacting us at the privacy contact above. Withdrawing doesn't undo processing that already happened before you withdrew.

4. Why do we use your data?

We use it to:

  • create and secure your account and sign you in;
  • save your entries and provide the tracking and calculations you ask for;
  • send essential account messages, like verification and password-reset emails;
  • keep the service secure and investigate technical problems; and
  • meet our legal obligations, including keeping records of your consent.

For your account and app usage, our legal basis is the contract we have with you (providing the service) and our legitimate interest in keeping the service secure and working. For your health data specifically, our only legal basis is your explicit consent, as explained in Section 3. You're never required to provide optional information, and you can withdraw consent using the privacy contact above.

5. Who do we share data with?

We use service providers to host the app, store data, send essential emails, and keep the service secure. These must be listed by name before this notice is published, along with what each one does and where it processes data:

  • [insert hosting provider and processing location]
  • [insert database provider and processing location]
  • [insert email provider and processing location, if used]
  • [insert security or other provider and processing location, if used]

These providers can only use your data to help us run the app, under contracts that require them to keep it confidential and secure. We do not sell your data.

If any data leaves the European Economic Area, we'll name the country and the safeguard used (such as an EU adequacy decision or Standard Contractual Clauses), and explain how to get more details: [insert the applicable transfer details].

6. How long do we keep your data?

These retention periods must be filled in with real figures before this notice is published:

  • Account data: while your account is active, then [insert period and deletion process].
  • Food, activity, and profile data: [insert retention period and deletion process].
  • Security and consent records: [insert retention period and reason].

We may keep limited information for longer if the law requires it, to resolve a dispute, or to prevent abuse. Otherwise, we delete or anonymise your data once the relevant period ends.

7. What are your rights?

Depending on where you live, you can typically ask to: see the data we hold on you, correct it, delete it, limit or object to how we use it, and get a copy to take elsewhere. If we're relying on your consent (like for health data), you can withdraw it at any time — this won't affect anything we did with your data before you withdrew.

To make a request, contact us at the privacy contact above. We may ask you to verify your identity first, and we'll respond within the timeframe the law requires. You can also complain to a data protection authority — usually the one where you live or work, or where you believe the issue happened.

8. How do we protect your data?

We use reasonable technical and organisational safeguards, including secure password storage, authenticated sessions, access controls, and rate limiting to prevent abuse. No online service is 100% secure, so please use a unique password and don't share it with anyone.

9. Changes to this notice

We may update this notice if the service or the law changes. The date at the top shows when it was last updated, and we'll let you know about important changes where the law requires it.