Last updated: 27 July 2026 Applies to: the Alkadiet iOS app and the photo-scan relay operated for it.
| Data controller | Bred Applications, enkeltmandsvirksomhed |
| Registered address | Doritshave 24, 6040 Egtved, Denmark |
| CVR / company no. | 45915905 |
| Privacy contact | contact@bredapplications.com |
| Data protection officer | Not appointed. Alkadiet does not carry out large-scale processing of special-category data, so GDPR Art. 37 does not require one. |
| EU representative | Not required — the controller is established in the EU. |
If you are in the EU/EEA and you think we handle your data wrongly, you can complain to your national supervisory authority. In Denmark that is Datatilsynet (datatilsynet.dk).
Alkadiet is built local-first. There is no Alkadiet account, no Alkadiet user database, and no server that holds your food log.
The following never reaches us, and never leaves your device except into your own private iCloud:
| Data | Where it is stored |
|---|---|
| Your meal log: foods, portion weights in grams, timestamps, meal slots, computed PRAL and calorie/macro values | SwiftData database in the app's container, synced to your private iCloud database (CloudKit) |
| Meal photos you attach or scan (downscaled JPEG, max 800 px on the long side) | Same — stored as an iCloud asset in your own account |
| Recipe notes and saved recipes | Same |
| Your daily targets (calories, protein, fat, carbohydrate) and whether you set targets at all | Device settings (UserDefaults) |
| Your onboarding answers, kept only until onboarding finishes (so closing the app on the paywall doesn't restart the quiz) | Device settings, deleted when onboarding completes |
| Weight unit preference, remaining daily scan budget | Device settings |
| A random identifier used only to count installs (see §5.2) | Device settings |
Your body details are not in that table, because they are not stored. If you choose to set daily targets, the app asks for your age, sex, height, weight and activity level. Those numbers are used once, on your device, to calculate your calorie and macronutrient targets — and then they are gone. Only the resulting targets are kept. Declining the weight-goal question skips the questions entirely, and the app works the same without them.
The food database itself — roughly 5–10,000 foods with nutrient values derived from USDA FoodData Central — is bundled inside the app. Searching it is entirely offline: no lookup you type is ever transmitted, and no product database is queried over the network.
PRAL is calculated on your device. It is arithmetic on the nutrient values already in the app.
iCloud: if iCloud is signed in and iCloud Drive is on for Alkadiet, your log syncs through Apple's CloudKit into the private database of your Apple Account. That storage is governed by Apple's Privacy Policy. Apple acts as processor for your own data there; we, as the app developer, have no read access to any user's private database. If you sign out of iCloud, the app keeps working locally.
Exactly three flows. Two of them only happen when you deliberately start them.
| What is sent | The photo, downscaled to max 1024 px on the long side and re-encoded as JPEG, plus an anonymous App Attest proof from Apple that the request comes from the genuine, unmodified Alkadiet app on a real Apple device — it contains a random key created for this install and Apple-issued certificates, nothing about you, your Apple Account or your device's identity. Beyond that, nothing. No name, no device id, no log data. |
| Where it goes | First to our own relay (alkadiet-scan-proxy-production.up.railway.app, hosted on Railway), which does one job: attach the vision-API key so the key never ships inside the app. The relay then forwards the image to Google's Gemini API (generativelanguage.googleapis.com), model gemini-3.1-flash-lite. |
| What comes back | A list of recognised food names with estimated gram weights and a confidence value per item, plus a suggested dish name. You review and correct it before anything is logged. |
| What the relay stores | Nothing. It has no database, no key-value store and no request logging. The image exists only in memory for the seconds the request takes. |
| What the relay processes about you | To stop scripted abuse, the relay counts requests per IP address for one minute at a time (5 scans per minute). These counters live in memory only, are keyed on your IP address, and are discarded when the window passes or the service restarts. They are never written to disk and never associated with anything else. |
| Purpose | To recognise foods in a photo you asked us to read. |
| Legal basis | Performance of the contract, GDPR Art. 6(1)(b) — you asked for the scan; the IP counter rests on our legitimate interest in keeping the service available, Art. 6(1)(f). |
| Retention | Image: not retained by us. IP counter: at most 60 seconds. |
Your device also limits itself to 20 scans per day, counted locally.
What Google does with the image: it is not used to train or improve Google's models. Alkadiet is operated from Denmark, and Google's Gemini API terms state that for users in the European Economic Area, Switzerland and the UK, the paid-service data terms apply to all use of the API: prompts and responses are not used to improve Google's products. Google logs them for a limited period solely to detect abuse of its prohibited-use policy, and processes them as our data processor under Google's Data Processing Addendum. We retain nothing.
| What is sent | The name of a screen or onboarding step you reached (for example Onboarding.Reached.paywall); if you answer the "what made you stop?" question, which of the four fixed answers you tapped; the app version, the iOS version, your locale, a per-launch session id, and a random identifier created on first launch that exists only so distinct installs can be counted. |
| What is never sent | Your name, email, Apple Account, IDFA, any device identifier issued by Apple, anything from your food log, and any free text you typed. |
| Where it goes | TelemetryDeck (Wanderwege GmbH, Germany), an EU-based analytics provider, over a plain HTTPS request. |
| Purpose | To see where people give up, and why, so we can fix that part of the app. |
| Legal basis | Legitimate interest, GDPR Art. 6(1)(f) — improving the app with the least data that answers the question. You can switch it off at any time: the switch sits in Settings → Privacy, and the same switch is offered behind the Privacy link on the app's very first screen, before any purchase. Off means nothing is sent at all. |
| Retention | As kept by TelemetryDeck under our agreement with them. We keep no separate copy. |
| Identifier | The random install identifier is stored on your device. Deleting the app deletes it; a reinstall gets a new one, so it cannot follow you across installs. |
Alkadiet Plus is sold through Apple's In-App Purchase. Apple processes the payment; we receive no card details, no billing address and no name. The app asks Apple's StoreKit whether an active subscription exists and stores nothing about it except what iOS itself keeps. Apple's handling of your purchase is governed by Apple's own privacy policy and the Apple Media Services Terms.
| Recipient | What they get | Where | Basis for transfer outside the EU/EEA |
|---|---|---|---|
| Apple (Apple Inc. / Apple Distribution International) | App distribution, payment, iCloud storage of your own data, and the App Attest check that certifies the app is genuine when you scan | Ireland / USA | Apple is certified under the EU–US Data Privacy Framework; Apple's SCCs apply |
| Google (Gemini API) | Meal photos you scan | USA / global | Google Cloud/Gemini standard contractual clauses; Google LLC is DPF-certified |
| Railway (Railway Corp.) | Hosts our stateless relay; sees the image in transit and your IP | USA | Standard contractual clauses per Railway's DPA |
| TelemetryDeck (Wanderwege GmbH) | Anonymous event counts, install identifier, IP at ingest | Germany (EU) | No transfer — processing stays in the EU |
We use no other processors. There is no advertising partner, no CRM, no email marketing tool, and no data broker in this list because there are none.
We hold almost nothing, so there is little to keep:
Under the GDPR you have the right to access, rectify, erase and port your personal data, to restrict or object to processing, and to complain to a supervisory authority. Because of how Alkadiet is built, most of these you can exercise yourself, immediately, without asking us:
| You want to | How |
|---|---|
| See your data | It is in the app. All of it. |
| Correct it | Edit or delete any meal or food in the app. |
| Erase it | Settings → Privacy → Delete all my data. One action removes every meal, food, photo and note from this device and from your iCloud, along with your daily targets, the anonymous install identifier and the anonymous key the scanner's App Attest proof uses. Your subscription and your analytics choice are left alone. You can also delete individual meals, or delete the app and remove its iCloud data. We hold no copy to erase. |
| Take it elsewhere | Settings → Privacy → Export my log. You get two files: a JSON file — structured, commonly used and machine-readable, as Art. 20 requires — and a CSV that opens in a spreadsheet. Meal photos are not in the export; they stay on your device and in your iCloud. |
| Object to analytics | Turn Anonymous usage counts off — in Settings → Privacy, or behind the Privacy link on the app's first screen. Nothing is sent from that moment on. |
| Ask us something | Write to the privacy contact in §1. We answer within one month, as Art. 12(3) requires. |
We do not need to verify your identity for a request, because we hold no account to match you against — which also means we cannot produce data about you on request: we do not have any.
Alkadiet is not directed at children. You must be at least 16 years old to use it. We do not knowingly process data from anyone below that age, and 16 is at or above the age of consent for data processing everywhere in the EU/EEA (it is 13 in Denmark under GDPR Art. 8 as implemented by the Danish Data Protection Act, and higher in some member states — 16 clears all of them). Since we hold no accounts, we have no technical way to detect a younger user; if you believe a child has used the app, the data is on that child's device and can be deleted there.
If a breach ever occurred that affected personal data, we would notify Datatilsynet within 72 hours as Art. 33 requires. Given the architecture, the realistic worst case is limited to data in transit.
Photo scanning uses an AI model to recognise foods. It does not make any decision about you: it proposes food names and weights, which you review and correct before anything is logged. There is no automated decision-making with legal or similarly significant effect for you within the meaning of GDPR Art. 22.
The photo scan is the only AI in Alkadiet. It runs only when you start it, it returns suggestions you can change or reject, and it is never used to evaluate you. We keep a written assessment of it under the EU AI Act — if you want to see how we reached our conclusions, write to contact@bredapplications.com and we will send it to you.
If we change how the app handles data, we update this policy and the "last updated" date, and we describe what changed. For a change that materially reduces your privacy, we will tell you in the app before it takes effect.
contact@bredapplications.com Bred Applications, enkeltmandsvirksomhed · CVR 45915905 · Doritshave 24, 6040 Egtved, Denmark