Privacy policy
Last updated .
Snapkin is a calorie tracker. You photograph a meal and it works out what was on the plate. Doing that means handling food photographs, your weight and your body details, which is about as personal as ordinary software data gets. This page says exactly what is stored, who else sees it, and how to make it stop.
Who is responsible
The controller for everything below is Robot Studios IT Consultancy BV, Hemelshoek 277, 2590 Berlaar, Belgium, enterprise number 0732.991.584. Questions, requests and complaints: [email protected].
There is no data protection officer, because the law does not require one at this size.
What is stored, and why
| What | Why |
|---|---|
| Your name, email address, password, language and time zone | To have an account at all, and to show your day in the right language and the right day boundary. The password is stored hashed and cannot be read back. |
| Sex, year of birth, height, activity level, goal, diet and any dietary note you write | To compute your calorie and protein targets. The dietary note is free text and is sent to the analyser along with the photo, so anything you type there goes with it. |
| Your weight, over time | The trend is the point of the app. Entered by hand, or read from Apple Health or Health Connect if you switch that on. A weight you type always wins over an imported one. |
| Every meal: photographs, the ingredients found, grams, calories and macros, the assumptions behind each, questions asked and your answers, and any chat about the meal | This is the food diary. It is what the app is for. |
| Recipes you save | So the coach can suggest what you can actually cook. |
| Things it has learned about how you eat, stored as short sentences | So it stops asking the same question. Every one of these is visible in the app under Memory, where you can correct any of them or delete it. |
| Coach messages | Only generated when you ask for one. |
| Devices you have signed in on: a hashed sign-in token, a label, the platform, when it was last used, and a push notification token if the app registered one | To keep you signed in, to let you sign a lost device out, and to tell the phone an estimate is ready. |
| If you sign in with Apple or Google: the identifier that provider gives us for you and the email address it shares. For Apple, also the token Apple needs to revoke the sign-in when you delete your account | To recognise you next time without a password. |
| If you switch on Apple Health or Health Connect: the weight readings, and your height if you let it fill that in during setup | There is no account to link and no token to hold. Your phone reads your health store and sends us those two numbers; permission lives in the phone's own settings, not here. Your height is read once, during setup, because it does not change. |
| Short-lived codes we email you to confirm an address or reset a password | Stored hashed, and expire within an hour. |
| If somebody gave you Snapkin rather than you paying for it: the email address and first name they invited you under, and the hashed link we sent | So the invitation can be accepted once and not twice. It stops working after 30 days, and once you have an account it is deleted along with the account. |
| Subscription status, the store it came from, and the receipt identifiers the store returns | To know whether the app is paid for. Card details are never sent to us and we could not see them. |
| A record of each analyser call: how much computing it used, what it cost, and the analyser's answer | Cost control, abuse limits and debugging a bad estimate. The answer is wiped when you delete your account. |
| Your IP address, in the web server's access log and in the check that limits sign-in attempts | To keep somebody from guessing passwords, and to diagnose a fault. Not tied to your account anywhere else. |
| A note that a meal or weight was deleted, kept for 30 days | So a phone that was offline learns the deletion when it comes back, instead of showing a meal that no longer exists. It carries the item's id and nothing about the meal. |
Photographs are stored privately. They are not on a public URL and not in a public bucket. Where the app shows one back to you it does so through a short-lived signed link. Photographs are re-encoded on your phone before they are uploaded, which strips the metadata a camera writes into a file, so no location is stored with a picture of your lunch.
The legal bases
Your account, your subscription and the actual analysis of your meals are processed because we have a contract with you and cannot deliver the app without them (Article 6(1)(b) GDPR). Your name, email address and body details are therefore required: without them there is no account and no target to compute.
Your weight, your body details and what you eat are health data under Article 9 GDPR. That category cannot be processed on the basis of a contract, so it is processed on your explicit consent under Article 9(2)(a), which the app asks for in its own words, separately, before your body details are saved. You can withdraw that consent at any time. Because the app cannot work without those details, withdrawing is the same action as deleting your account. Withdrawing does not make the processing before it unlawful.
Switching on Apple Health or Health Connect is your choice and your consent; switching it off, or withdrawing the permission in your phone's own settings, withdraws that consent (Article 6(1)(a)).
Server logs, the sign-in attempt check and the analyser cost record are kept on our legitimate interest in keeping the service secure and paid for (Article 6(1)(f)). Nothing in that set is used to profile you.
Snapkin makes no decision about you that has a legal or similarly significant effect. The estimates are automated, and every one of them can be corrected by you.
Who else sees it
- Anthropic, the analyser
-
Every estimate, question, meal chat, coach answer and learned sentence is produced
by a Claude model from Anthropic. What goes to it depends on the feature:
- Analysing a meal: the photograph, your diet and dietary note, and the short sentences the app has learned about how you eat.
- Chatting about a meal: the photograph, your diet and dietary note, the meal as it stands, the questions it asked, your answers and your messages.
- The coach: your calorie and protein targets, what you have eaten today, your latest weight, your diet and dietary note, the recipes you saved, and the conversation.
- Learning how you eat: once a night, the previous day's meals as text, and what it already knows about you. No photographs.
- Apple Health and Health Connect, only if you switch them on
- These are not third parties we send anything to. They are stores on your own phone, and the traffic goes one way: we read, and we never write. Your phone reads your weight, and your height once during setup, and sends them here, the same as if you had typed them. Your steps and your active energy are read too, and they stay on the phone. They are drawn under your day. During setup, averages from the previous 14 completed days can suggest an activity level; only the level you confirm is saved to your account. The step and active-energy readings are never sent to us, never stored on our server, and never included in anything sent to the analyser. Switching it off stops the reading; there is no token to discard because there was never one to hold.
- Apple and Google: payments, sign-in and push notifications
- If you subscribe, the store handles the payment and tells us only whether the subscription is live and until when. If you sign in with Apple or Google, we receive a verified identifier and your email address. For the purchase itself Apple and Google are the seller and act as their own controllers, not ours. When the app tells your phone an estimate is ready, that message travels through Apple's or Google's push service. It carries only the meal's id, its status and the day it belongs to, never the meal itself.
- Cloudflare
- This website and the app's connection to it pass through Cloudflare, which protects the server and caches the public pages. Cloudflare sees the IP address and the traffic of every request, as anything sitting between you and the server must, and acts as our processor.
- Hosting and email
- The server that runs the app and holds your data is in Amsterdam, in the European Union, with DigitalOcean. The few emails the app sends, to confirm an address, reset a password or deliver an export, go out through an email delivery provider, which sees your address and the message.
Nothing here shows you an advertisement, and there is no tracking pixel, no advertising network and no data broker. Your food diary is not sold, shared for advertising, or used to train anybody's model. We do buy advertising elsewhere, and we measure how well it worked ourselves; "Measuring our own advertising" below says exactly how.
Data leaving the EU
Your data is stored in the EU. The analyser runs in the United States, so your meal photographs and the context listed above are transferred there for the time it takes to answer, and are deleted by Anthropic within 30 days. That transfer is covered by the European Commission's Standard Contractual Clauses in the data processing agreement with Anthropic. Cloudflare, Apple and Google are US companies and rely on the Standard Contractual Clauses or the EU-US Data Privacy Framework for what passes through them. You can ask us for a copy of the clauses at [email protected] and we will send it.
How long it is kept
- Meals, photographs and weights: until you delete them, or until you delete your account. Deleting a meal deletes its photograph.
- Your account: until you delete it. Deletion is immediate, and the data is removed rather than hidden. The subscription record goes with it; the store keeps its own record of what you paid it.
- What survives deletion: a record of how much computing each analyser call used and what it cost, with nothing left that points at you. Nothing else.
- A data export you asked for: the zip is deleted from the server after seven days, whether or not you downloaded it.
- Device sessions and push tokens: dropped when you sign out or remove the device.
- Database backups: a deleted account can remain in a backup until that backup is deleted in its turn. Photographs are not backed up.
- Server access logs: deleted within 90 days.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to how it is used, or receive it in a portable form. Two of those need nobody's permission and happen immediately, from Menu → Profile in the app: Email me my data sends you a link to a zip holding every meal, photograph and number this app holds about you, and Delete your account removes all of it (how to delete your account). For anything else, email [email protected] and you will get an answer within a month.
If you think this is being handled badly you can complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be. You may also complain to the authority in the EU country you live in.
The app emails you to confirm an address, reset a password and deliver a data export. Those always arrive. It may also email you about days you have not logged; that one you can switch off in Profile, and every such email carries an unsubscribe link that works in one click. There is no newsletter.
Measuring our own advertising
We buy advertising, and we would rather buy less of it badly. When you arrive here from one of our advertisements, the link carries parameters naming the campaign, and our own server writes down that a visit happened: the campaign, the page you landed on, the country Cloudflare resolved from your connection, and the click identifier the advertising platform put on the link. If you then tap App Store or Google Play, we write that down too.
There is no identifier for you in any of it. A row says that somebody came from a campaign and what they did next. It does not say who, it is not joined to your account, and none of it is sent to the advertising platform or to anybody else. That much happens whether or not you answer the cookie question, on the basis of our legitimate interest in knowing which advertising is worth paying for (Article 6(1)(f)). The click identifier is deleted after 90 days and the row itself after 24 months.
One exception, and it is deliberate: tapping the Google Play button carries the campaign name to Google Play, because Play is the only thing that can tell us whether a tap became an install. It carries the campaign, not the click identifier and nothing about you.
You can object to this at any time under Article 21. Email [email protected] and it stops.
Cookies
If you reached this site from one of our own advertisements, you will have been asked about one cookie, and it is the only one this website ever sets. Everybody who arrives any other way is asked nothing and given nothing: no cookie, no banner, no script. There are no analytics, advertising or third-party cookies anywhere, and there never have been.
Accepting stores two things: a random string that points at the click you arrived on, for thirty days, and the fact that you accepted, for six months. Declining stores only the fact that you declined, for the same six months, so you are not asked again. Neither carries your name, your email address or anything else about you, and the random string stops meaning anything once the row it points at is deleted.
The cookie buys one thing: if you come back a week later and install the app then, we can tell it was the same visit rather than a new one out of nowhere. Declining costs you nothing and breaks nothing.
The app keeps your sign-in token, your language and a small offline copy of your day on your own device, and nowhere else.
Fonts are served from this domain rather than from Google, so loading a page here involves no third party other than Cloudflare, described above.
Children
Snapkin is not for children and you must be at least 16 to have an account. Do not create an account for a child, and do not use it to set a calorie target for one.
Changes
If this policy changes in a way that affects you, you will be emailed before the change takes effect, not told by a silent edit to this page. The date at the top is the date of the last change.