Privacy Policy
For the website bellybuddy.com and the BellyBuddy app · Last updated: 28 August 2026
1. Controller
- The controller within the meaning of the General Data Protection Regulation (GDPR) for the website bellybuddy.com and the mobile application “BellyBuddy” for iOS and Android (hereinafter the “App”) is:
Marc Lüerssen
Eschenstr. 9
28203 Bremen
Germany
Email: support@bellybuddy.com
Phone: +49 421 40895722 (hereinafter “we” or “us”). - No data protection officer has been appointed, as the legal requirements for doing so are not met. Please direct any questions about data protection to the email address above.
2. Overview
- This Privacy Policy explains which personal data we process when you visit the website and use the App, for which purposes and on which legal basis, who receives the data, how long we keep it and which rights you have.
- The principles in brief:
- We show no advertising, use no tracking or analytics services and do not sell data.
- Your diary data (meals, symptoms, body profile) is health data. We process it only with your explicit consent and only to provide the App's features to you.
- Your data is stored on a server operated by us in Germany. Data is transmitted to an external AI provider only for the AI analysis (Section 6).
- You can delete your account together with all its data yourself at any time in the App.
- This Privacy Policy is written in German. Translations, including this English version, are provided for information only; in case of doubt the German version prevails.
3. Website
- Server log files. When you visit the website, your browser automatically transmits data that our web server stores in log files: IP address, date and time of access, page requested, HTTP status, amount of data transferred, browser type and version, operating system and the previously visited page (referrer). This processing serves the secure and stable operation of the website and the defence against attacks. The legal basis is Art. 6(1)(f) GDPR. Log files are deleted after 14 days at the latest.
- Language cookie. The website is available in five languages. When you visit, we forward you to the matching language version based on your browser's language setting (the Accept-Language header); no cookie is set for this. Only if you choose a language via the flag menu does our server set a cookie named “lang” (lifetime: one year) so that your choice takes precedence over the automatic detection on your next visit. The cookie contains only the language code and is necessary for the function you requested (Section 25(2) no. 2 of the German TDDDG; Art. 6(1)(f) GDPR). We use no other cookies.
- No third-party content. Fonts, images and scripts are loaded from our own server. The website embeds no content from external providers and uses no analytics, tracking or social media services.
- Links to the app stores. The website links to the Apple App Store and Google Play. Data is transmitted to the respective store operator only once you follow such a link; the store operator's privacy policy then applies.
4. App: Account and Registration
- A user account is required to use the App. During registration we collect your first name, last name, email address and password. The password is stored exclusively in encrypted form (as a hash). To verify your email address we send you a confirmation code.
- During registration the App also transmits the language setting, region and time zone of your device so that entries are displayed in your language and local time. Each time the App is started, the App version, the operating system (iOS or Android) and the time of last use are also recorded in your account, so that we can inform you about required updates and detect compatibility problems.
- For password resets and email address changes we send you a confirmation code by email. Only a login token is stored on your device, in the operating system's protected storage; diary data is not stored permanently on the device.
- The legal basis for processing account data is Art. 6(1)(b) GDPR (performance of the user contract). Account data is stored until the account is deleted.
5. App: Diary and Health Data
- The core of the App is a diary that you keep yourself. In doing so we process the data you enter or record:
- Meals: photo, voice note or text description of a meal; the dish recognised from it, the ingredients and the estimated 13 nutritional values (including calories, fat, carbohydrates, protein, fibre, sugar, iron, gluten, histamine, fluid, caffeine, alcohol); time of the meal; your corrections.
- Symptoms: symptoms named freely by you (e.g. bloating, headache, stool consistency), their intensity on a scale you choose and the time.
- Body profile (optional): gender, date of birth, height, weight, values derived from them (age, BMI) and your daily nutrition goals.
- Allergies and diet (optional): allergens, intolerances (e.g. lactose, gluten, fructose, histamine) and dietary preferences (e.g. vegetarian, vegan, low-FODMAP, halal, kosher). Entries such as “halal” or “kosher” may allow conclusions about a religious belief.
- Favourites: meal and symptom templates saved by you.
- AI assistant: your questions and the assistant's answers (chat history).
- Symptoms, body profile, allergies, intolerances and, as a rule, meal data are health data within the meaning of Art. 9(1) GDPR. We process them exclusively on the basis of your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), which you give during registration by confirming the notice. The consent covers storage on our server, display and evaluation in the App, the AI analysis under Section 6 and the export under Section 7.
- You may withdraw your consent at any time with effect for the future by deleting your account in the App under “Settings → Account”. Without this consent the App cannot be used, as the diary is its core function. You can change or remove individual optional entries (body profile, allergies, diet) in the App at any time.
- The App displays your data and calculates nutritional values and goals; it makes no diagnoses and takes no automated decisions with legal or similarly significant effect (Art. 22 GDPR).
- Photos and voice notes are stored in a non-public storage area that only you can access via your account. Photos are downscaled and re-encoded before upload; camera metadata (e.g. location) is removed in the process. Voice recordings are deleted from your device after transmission.
- Diary data is stored until the respective entry or the account is deleted.
6. AI Analysis by an External Provider
- Dish recognition, estimation of nutritional values, conversion of voice notes into text and the AI assistant are provided by an external provider of AI language models (hereinafter the “AI provider”), which acts on our behalf as a processor under Art. 28 GDPR. Requests are made from our server; the App itself does not communicate with the AI provider.
- Depending on the feature, the following data is transmitted to the AI provider:
- Logging a meal: the photo, voice note or text of the meal and – so that ingredients and nutritional values match you – your country, your language and your entries on allergens, intolerances and dietary preferences;
- Correcting a meal: additionally the previously recognised dish and ingredients;
- AI assistant: your question, the conversation so far and – so that answers can refer to your entries – your first name, your body profile (gender, age, height, weight, nutrition goals), your entries on allergies and diet, and your meals and symptoms of the last 14 days.
- The AI provider processes the data exclusively to answer our request. We only use providers that contractually undertake not to use the data to train their models or for their own purposes. The provider may retain requests for a short period – generally up to 30 days – for abuse monitoring and deletes them afterwards.
- The AI provider may be established outside the European Union or the European Economic Area, currently in the USA. In that case the transfer is based on an adequacy decision of the European Commission (Art. 45 GDPR, e.g. the EU-US Data Privacy Framework) or on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). We reserve the right to change the AI provider; we only select providers that meet these requirements.
- We log every AI request with input, result, model used and volume (tokens) in your account. This serves the traceability of the estimates, error analysis, cost control and abuse detection (Art. 6(1)(f) GDPR; for health data Art. 9(2)(a) GDPR). The logs are deleted together with the account.
- The legal basis for the AI analysis is your consent under Section 5(2). Nutritional values and the assistant's answers are estimates, not medical statements.
7. Data Export (PDF Report)
- Under “Share/Export My Data” you can create a PDF report for a period of your choice. You decide which content the report contains (meals, symptoms and optionally name, body profile, nutrition goals, allergies and dietary preferences).
- The report is generated on our server and sent exclusively to the email address of your account. We do not send it to any other recipient. Whether you pass the report on, for example to doctors or nutrition professionals, is entirely your decision.
- The report is sent via our own mail server and an email delivery service provider with servers located in the European Union (processor under Art. 28 GDPR). The email is only cached briefly on our mail server. Please note that email attachments may be stored unencrypted at the recipient's end.
- The legal basis is Art. 6(1)(b) GDPR and your consent under Section 5(2).
8. Support
- If you contact us by email, we process your email address, the content of your message and the data you provide in order to handle your request.
- Via the support feature in the App you can create a ticket with category, subject, description and optional screenshots. Screenshots are uploaded unchanged; please make sure not to capture information you do not wish to transmit. Tickets are linked to your account and are deleted together with it.
- The App additionally links to a WhatsApp contact. If you choose this channel, WhatsApp (Meta Platforms Ireland Ltd.) processes your data under its own privacy policy; its use is voluntary.
- The legal basis is Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). We delete support emails no later than twelve months after the matter has been resolved, unless statutory retention obligations apply.
9. Error Reports
- If the App crashes or a technical error occurs, the App sends an error report to a server operated by us; no external service provider is involved. The report contains the error message, the affected program component, device model, operating system version, App version, language setting and the IP address from which the report was sent. Error reports contain neither your name nor your email address nor diary content; they are not linked to your account.
- To detect performance problems, a small share of App operations (about 20 %) is additionally transmitted to the same server with timing information.
- The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable and error-free App). Error reports are deleted automatically after 90 days.
10. Subscription and Payment
- Subscriptions are purchased via the Apple App Store or Google Play. Payment data (e.g. credit card) is processed exclusively by the respective store operator; we receive no payment data. The privacy policies of Apple and Google apply.
- To check whether a valid subscription exists, we use the service provider RevenueCat, Inc. (USA) as a processor. RevenueCat receives the store's purchase receipt, a pseudonymous user identifier, the subscription status, the App version and the device type. The transfer to the USA is based on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
- The legal basis is Art. 6(1)(b) GDPR. Subscription data is stored until the account is deleted; the store operator's receipts according to its own rules.
11. Hosting, Security and Backups
- All App data is stored on a server managed by us, which we operate at a hosting provider with a data centre in Germany. The hosting provider supplies only the infrastructure (virtual machine, network connection); a data processing agreement under Art. 28 GDPR is in place with it.
- Transmission between the App, the website and the server is encrypted (TLS). Access to your diary data is technically restricted to your account; photos and voice notes are kept in non-public storage areas. Administrative access is restricted to us and secured.
- We create encrypted backups of the server daily to prevent data loss (Art. 6(1)(f), Art. 32 GDPR). Backups are deleted after 30 days at the latest. Deleted accounts are not restored from a backup.
12. Recipients and Transfers to Third Countries
- We pass personal data on only to the following categories of recipients, and only insofar as this is necessary for the purposes described:
- Hosting provider (data centre in Germany) – operation of our server, Section 11;
- Email delivery service provider (servers in the EU) – delivery of confirmation codes and PDF reports, Sections 4 and 7;
- AI provider (possibly outside the EU/EEA) – dish recognition, nutrient estimation, transcription, AI assistant, Section 6;
- Apple App Store, Google Play and RevenueCat – subscription and payment, Section 10;
- Authorities and courts, insofar as we are legally obliged to do so.
- Processors are contractually bound to our instructions under Art. 28 GDPR. Transfers to countries outside the EU/EEA take place only to the AI provider (Section 6(4)), on the basis of an adequacy decision or the European Commission's standard contractual clauses, and to RevenueCat (Section 10(2)), on the basis of those standard contractual clauses. We provide a copy of the respective safeguards on request.
- We do not sell data and do not pass it on for advertising purposes.
13. Retention Periods
- We store personal data only for as long as necessary for the purposes stated. In summary:
- Account, profile and diary data, photos, voice notes, chat histories, AI logs, support tickets: until the account (or the individual entry) is deleted;
- Website server log files: 14 days at most;
- Error reports: 90 days;
- Backups: 30 days at most;
- Requests at the AI provider: generally 30 days at most at the provider;
- Support emails: twelve months at most after the matter has been resolved.
- When you delete your account in the App, your account and all associated data are deleted from our server immediately and irrevocably. Statutory retention obligations remain unaffected.
14. Your Rights
- You have the following rights vis-à-vis us with regard to your personal data:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).
- You can exercise many of these rights directly in the App: change or delete profile and diary data, request a PDF report of your data (Section 7) and delete the account completely under “Settings → Account”. For all other requests, in particular a copy of your data in a machine-readable format, write to support@bellybuddy.com. For your protection we may ask you to confirm your identity, for example via the email address of your account. These steps, and how to request deletion without the App, are also summarised on our account deletion page.
- You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence or of the alleged infringement. The supervisory authority responsible for us is: Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen, Arndtstraße 1, 27570 Bremerhaven, Germany, www.datenschutz.bremen.de.
15. Minimum Age
The App is intended exclusively for persons aged 18 and over. We do not knowingly collect data from minors. If we learn that an account has been created by a minor, we delete it.
16. Changes to this Privacy Policy
We update this Privacy Policy when our services, the service providers we use or the legal situation change. The current version is always available at bellybuddy.com and in the App. We will inform you of material changes, in particular a change of AI provider or new processing purposes, in the App or by email. The date of the last update is shown at the top of this policy.