Version 2026-08-16 · Last updated: 2026-08-16
The controller responsible for your personal data is David Nolde, Konrad-Zuse-Straße 28B, 60438 Frankfurt am Main, Germany. For any privacy question or request, contact privacy@gromdev.app.
No Data Protection Officer is appointed. Art. 37 GDPR requires one where large-scale monitoring or large-scale processing of special-category data is a core activity; at our scale neither applies. We re-check this whenever the service grows materially.
We only collect data you provide, generate by using the app, or choose to share from a source you connect yourself (see Health Connect below). We do not buy data, run third-party ad/analytics trackers, or collect location.
| Data | Notes |
|---|---|
| Email address | Sign-in identifier; cannot be changed after registration |
| First name (and optional last name) | To personalize the app |
| Password | Stored only as a hash by AWS Cognito; we never see it |
| Data | Notes |
|---|---|
| Height, date of birth, sex, activity level | To compute calorie/macro targets |
| Body weight and BMI over time | Logged measurements |
| Body measurements | Waist, hip, chest, arm, thigh, neck, calf (all optional) |
| Meal / food logs | What you eat, with calories and macros, by day |
| Dietary restrictions and allergies | Optional, to tailor coaching |
| Your goal & coaching preferences | e.g. cut/bulk/maintain, pace, coaching tone |
| Workout sessions | Sport, duration, energy burned, start time, whether you entered the session yourself or it came from a connected source, and that source's own id for the session (so a repeat sync updates it instead of duplicating it) |
| Daily step count | One total per calendar day |
| Connected health sources | Whether Health Connect is connected, when you connected it, what it is allowed to read, and when it last synced |
| AI-generated coaching text | Daily "daybook", weekly insights and reviews derived from the above |
You can enter workouts by hand, or connect Health Connect — the health data store built into your Android device — so that sessions your fitness tracker or watch app records are picked up automatically. Health Connect is on your own device; your tracker's app writes into it under your agreement with that vendor, and we are not a party to it.
We ask Health Connect for four read permissions and no write permission: steps, exercise sessions, active energy burned, and total energy burned. Energy records are read to give a training session its calorie figure. The app only reads — it never writes anything back into Health Connect, and it is not a data source for any other app.
Activity data read this way goes from your device to our backend and nowhere else. It is not shared with your tracker's vendor, and it is not sold or shared with anyone. Like your other logged data, the day's training and step count are part of what the AI coach is given when it generates your daybook (§4, §6).
You can revoke the Health Connect permissions at any time in your device's Health Connect settings, or disconnect the source in the app, without deleting your account. Be aware that this stops any further data being read — it does not delete activity data that has already been synced. To erase that, delete your account (§8) or contact us.
| Data | Notes |
|---|---|
| Push notification token + device id | To deliver notifications; only if you enable them |
| Time zone | So coaching reflects your local time of day |
| Purpose | Lawful basis |
|---|---|
| Create and run your account; deliver the core service | Performance of a contract (Art. 6(1)(b)) |
| Process your health & body data to compute targets and generate coaching | Your explicit consent (Art. 9(2)(a)), withdrawable at any time. You give it during signup as two separate agreements — accepting this policy and the Terms, and consenting to health-data processing — and we record which version of this policy you agreed to and when. Accounts created before that step existed carry no such record; for those, consent was given by choosing to enter the data and use the coaching. |
| Read workouts, steps and energy from Health Connect on your device | Your explicit consent (Art. 9(2)(a)) — the Health Connect permission grant is that consent: each of the four permissions is granted separately and can be revoked at any time in your device settings |
| Send push notifications | Consent — you choose whether to enable them and can turn them off |
| Keep the service secure and reliable | Our legitimate interests (Art. 6(1)(f)) |
To generate your daybook, insights and weekly reviews, your logged data — including the day's training (sport, duration, energy burned) and step count — is processed by an AI model (Anthropic Claude, run inside AWS Bedrock — see §6). This produces advisory coaching content only. It does not make any decision that has legal or similarly significant effects on you, so it is not "solely automated decision-making" under Art. 22 GDPR. You can disable the coach and daybook in the app.
We keep your data for as long as your account is active. When your account is deleted — by you, or by us if we terminate it under the Terms of Service — all of your personal data is erased immediately and your authentication identity is removed. The only record we keep afterwards is a privacy-preserving erasure log entry — a one-way hash of your user id plus a timestamp, containing no personal data — retained for 2 years to prove the erasure happened. Operational server logs contain no personal profile data and are retained for up to 30 days. Encrypted database backups roll over on a 35-day window, so a copy of deleted rows sits in them until it is overwritten; they are never used to restore an individual account. How to request deletion.
We process your data in the European Union (AWS Europe, Frankfurt region). We use the following processors:
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (database, compute, authentication, email, content hosting, AI inference) | Core hosting & processing | EU (Frankfurt); some AWS control-plane services are global |
| Anthropic (Claude), accessed only via AWS Bedrock | AI coaching generation; runs in-AWS via EU inference profiles — we do not call Anthropic directly | EU |
| Google Ireland Ltd. (Firebase Cloud Messaging) | Push notification delivery. Payloads identify your device by a pseudonymous token only — never your name, email or account id — and the notifications say only that something is ready to read. The coaching text itself is fetched by the app from us directly, so it does not travel through Google. | Google-controlled |
| Open Food Facts | Food database lookups; no personal data is sent | EU (non-profit) |
A Data Processing Agreement is in place with each processor. Both AWS and Google incorporate theirs automatically into the terms we accepted, and we keep dated copies of each as evidence.
Your data is processed in the EU. Where a sub-processor relies on a global control plane (e.g. certain AWS or Google services), transfers are covered by the transfer terms of that provider's Data Processing Agreement, which we hold a dated copy of.
Under the GDPR you have the right to:
To exercise any right, use the in-app controls or contact privacy@gromdev.app. You also have the right to lodge a complaint with a data protection supervisory authority. Ours is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de); you may also complain to the authority where you live or work.
NutritionCoach is intended for adults. You must be at least 18 years old to use it; we do not knowingly collect data from anyone under 18.
If we make material changes we will update the version above and publish the new text at this address. Re-asking existing users to agree, where a change affects how we process your health data, is not automated yet — the version you agreed to is recorded, which is what makes it possible.