Privacy.
How we collect, store, and process your data. EU-hosted, DSGVO/GDPR-compliant.
Last updated · August 11, 2026
Summary
pinning treats your data as if your life depended on it — because your protocol might. We store everything in EU-Central (Frankfurt), encrypt it at rest and in transit, never sell it, never share it with advertisers, and let you export or delete all of it.
TL;DR: We store only what we need to run the service. You own your data. We do not sell or share it. You can download all of it, or erase your account, from Settings.
1. Who we are
Data controller within the meaning of Art. 4 (7) GDPR / § 5 DDG is:
Aleksander Chadzy — Einzelunternehmer, handelnd als „pinning“
Graf-Heinrich-Str. 1, 21698 Harsefeld, Deutschland
Email: privacy@pinning.info
Full provider details: Impressum. We have not appointed a data protection officer; we are below the threshold of § 38 BDSG.
2. Health data — the important part
Most of what pinning stores is health data within the meaning of Art. 4 (15) GDPR, and therefore a special category of personal data under Art. 9 (1) GDPR:
- Injection logs — compound, dose, site, time, how you felt, side effects
- Cycles and protocols, including planned dosing
- Body metrics — weight, height, year of birth, sex, goal, activity level
- Bloodwork values you upload or enter
- Meals, calories and macros, including photos of what you eat
Processing data of this kind is prohibited unless one of the exceptions in Art. 9 (2) applies. We rely on your explicit consent under Art. 9 (2) (a) GDPR, which you give when you create an account and which is the reason the app can store any of this at all.
You can withdraw that consent at any time, with effect for the future, by deleting your account in the app (Settings → Delete account) or by writing to privacy@pinning.info. Withdrawal does not affect the lawfulness of processing carried out beforehand. Because this consent is what the service runs on, withdrawing it means we can no longer provide the service.
3. What we collect
Account data
- Email address (login and account-essential notifications)
- Username / display name (chosen by you)
- Hashed password (via Supabase Auth)
Health and body data
See section 2 — this is the bulk of what the app stores, and it is consent-based.
Photos
- Meal photos you take or pick, in order to estimate calories and macros. The photo is sent to our server, analysed, and stored in your private folder so the entry keeps its picture. Camera and photo-library access is asked for in the app and can be revoked in iOS Settings at any time.
- Bloodwork and receipt images, if you choose to upload them.
Purchases and entitlements
- Whether a Pro subscription is active, from the App Store receipt via RevenueCat. We never receive your card details.
- A ledger of photo-analysis credits — one row per pack you buy and one per analysis you spend, each with the store transaction id and the product id of the pack. It is what tells the app how many scans you have left, and it is included in your data export and erased with your account.
Technical data
- Aggregate first-party analytics (page views, clicks) on the website — consent-based, off until you accept; no raw IP stored, country derived from edge headers, unique counts via a daily rotating salted hash
- Server logs (IP, user-agent) — retained 14 days for security
App usage data (iOS) — off unless you switch it on
The app can send product-usage events and crash reports to PostHog. This is off by default. Nothing is transmitted until you enable Settings → Privacy → Share usage data, and turning the switch back off stops it immediately.
- Events sent when enabled:
app_opened,pin_logged,cycle_created,food_analyzed,paywall_shown, paywall purchase events, and crash/error reports (message, type, stack trace). - Each event carries your user id, so it is not anonymous. The event names themselves reveal that you log injections and analyse meals, which makes them health data under Art. 9 GDPR. That is why the switch asks for explicit consent and why there is no legitimate-interest route for it.
- We do not send the contents of your logs: no compound, dose, site, note, meal or photo ever leaves the app as part of an event.
- No advertising identifiers, no cross-app tracking, ever.
4. Legal bases
- Art. 9 (2) (a) — explicit consent, for all health and body data (§ 2)
- Art. 6 (1) (b) — performance of contract: account, subscription entitlement, delivering the features you asked for
- Art. 6 (1) (f) — legitimate interest: security logs, abuse prevention, rate limiting
- Art. 6 (1) (a) — consent: website analytics, marketing email, push notifications
- Art. 9 (2) (a) together with Art. 6 (1) (a) — separate explicit consent, for the app-usage events and crash reports described in § 3. This is a second, independent consent: the one you give at signup covers storing your health data in your account, not sending usage events about it to a third party. Withdraw it with the same switch that granted it (Art. 7 (3)).
- Art. 6 (1) (c) — legal obligation: retention of billing records
5. Processors and recipients
- Supabase — database, authentication, file storage. Region: EU-Central (Frankfurt).
- Vercel — hosting of pinning.info and the API. Region: Frankfurt.
- Anthropic — analysis of meal photos (and, if you upload them, bloodwork images). The image is transmitted for the purpose of the estimate and is not used to train models. This applies to both the website and the iOS app: a photo taken in the app is uploaded to our API and passed on for the estimate in the same way. Only photos you deliberately take for the food tracker are sent — nothing else in the app is.
- Apple — App Store distribution and, for subscriptions bought in the app, the payment relationship. Apple is the seller of record and an independent controller for that transaction.
- RevenueCat — verification and management of App Store subscriptions, so the app knows whether your plan is active.
- Stripe — payment processing for subscriptions taken out on the website before web checkout closed. No new contracts are concluded this way.
- Resend — transactional email (account and billing mail).
- PostHog — product analytics and crash reports from the iOS app, only if you switched them on (see § 3). We use the EU region, hosted in Frankfurt. PostHog Inc. is a US company, so administrative access from outside the EU cannot be ruled out — see § 6.
- First-party analytics — the website pixel is self-hosted in our own EU database; no third-party analytics provider is involved on the website.
Each processor is bound by a data processing agreement under Art. 28 GDPR. We can provide copies on request.
6. International transfers
Supabase and Vercel hold your data in the EU (Frankfurt). PostHog's EU region is also in Frankfurt. The following recipients are US companies and may process data in the United States, or access EU-stored data from there:
- Anthropic — meal, bloodwork and receipt photos you submit for analysis
- Apple — the purchase relationship for anything bought in the app
- RevenueCat — subscription status
- Stripe — legacy website subscriptions
- PostHog Inc. — support and administrative access to the EU instance
These transfers are covered by the Standard Contractual Clauses under Art. 46 (2) (c) GDPR in each provider's data processing agreement, together with supplementary technical and organisational measures. Where a recipient additionally holds a current certification under the EU-US Data Privacy Framework, the Commission's adequacy decision of 10 July 2023 applies alongside. We rely on the Clauses as the primary basis rather than on a certification status that can be withdrawn.
Meal-photo analysis is a core function of the food tracker and cannot be performed without this transfer. If you would rather not have a photo leave the EU, log the meal by hand — manual entry is always available and always free.
7. Retention
- Account, health and body data: until you delete your account. Deletion cascades to cycles, pin logs, vials, meals, metrics and uploads.
- Uploaded images: with the entry they belong to; removed when you delete the entry or the account.
- Photo-credit ledger: for as long as the account exists — it is the record of what you bought and what you spent. Deleted with the account.
- App usage events and crash reports: only ever collected while the switch is on. Turning it off stops collection; to have events already sent deleted, write to us and we will have them removed from PostHog.
- Server logs: 14 days.
- Billing records: 10 years (§ 147 AO, § 14b UStG). For purchases made in the app, Apple is the seller and keeps these records under its own retention rules.
8. Your rights (Art. 15–22 GDPR)
- Access your data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (Art. 17) — in the app under Settings → Delete account, and on the website under Settings
- Restrict processing (Art. 18)
- Data portability (Art. 20) — download everything as JSON from Settings, including your purchase and photo-credit ledger. Free of charge, as required by Art. 12 (5). The export runs on the website; log in with the same account you use in the app.
- Object to processing (Art. 21)
- Withdraw consent at any time — the Art. 9 consent given at signup (see § 2), and, separately, the app-usage consent under Settings → Privacy → Share usage data (see § 3)
- Lodge a complaint with a supervisory authority (Art. 77) — the one competent for us is Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover. You may also complain to the authority where you live or work.
To exercise any right: privacy@pinning.info. We answer within one month (Art. 12 (3)).
9. Automated processing and AI
The calorie and macro figures next to a meal photo are produced by an AI model and are an estimate, not a measurement. They are labelled as such at the point they are shown, in the app and on the website — the transparency duty under Art. 50 of the AI Act (Regulation (EU) 2024/1689), applicable since 2 August 2026, is met by that visible label rather than by this sentence. We are the deployer of the model, not its provider.
There is no automated decision-making with legal or similarly significant effect within the meaning of Art. 22 GDPR, no profiling, and no emotion recognition or biometric categorisation of any kind (Art. 5 AI Act). Nothing in the app recommends a dose, a compound or a course of action.
10. Security
- TLS in transit, encryption at rest
- Row-Level Security on every database table — a row is readable only by its owner
- Private storage buckets, scoped per user
- Encrypted backups
11. Changes
We'll notify you by email at least 14 days before any material change to this policy. Where a change requires your consent, we will ask for it rather than assume it.