This is a translation for your convenience. The German version is legally binding. Read the German version
1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Lukas ZimmermannClara-Schumann-Str. 15
74889 Sinsheim
Germany
Email: [email protected]
2. Principles of data processing
Protecting your data matters to us. We process your data in accordance with the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
FastingFibi stores your data on your iPhone first. Without an account, your fasting, weight, journal and nutrition data stays there. The exceptions are the AI meal analysis, if you allow it (section 3.8), and product lookups at Open Food Facts (section 3.7). If you create an account, we also store the data listed in section 3.2 in our database in Frankfurt am Main (EU). We use service providers for subscription management and error reports (sections 3.4 and 3.6).
We don’t show ads, don’t use analytics or tracking services, don’t sell data and don’t build advertising profiles.
3. What data we process
3.1 Data on your device
The app stores this data on your iPhone:
- Fasting: the running timer, completed fasts, your fasting plan and fasting goals
- Body data: sex, age, height, weight and weight history, activity level, goal weight and desired pace
- Journal: mood, notes, tags, weight and water
- Nutrition: meals with foods, amounts and nutritional values, your notes and the photos of your meals
- Extended fasting: your water and symptom log
- Medications (section 3.5) and your safety answers (pregnancy or breastfeeding, eating disorder, blood-sugar-lowering medication)
- Settings, streaks, your display name, the time you consented to the AI analysis, cached product data and the last known subscription status
Storing and reading this data on your device is strictly necessary for the app to work (Section 25(2) no. 2 TDDDG). The data may be part of your device backup (e.g. iCloud Backup); we have no access to it. You can delete it in the app under Settings > “Delete local app data only” or by deleting the app.
3.2 Cloud sync (optional, with an account)
If you are signed in with an account, we also store the following data in our database. This lets you find it again on a new device and pick up where you left off after reinstalling via “Already have an account? Sign in”:
- Fasting: mode, start, planned goal, end, target duration, actual duration, success and label of every completed fast, plus your running timer
- Journal: date, mood, note, tags, weight and amount of water
- Nutrition: your meals with time, how you logged them (photo, voice, text, barcode, manual), foods, amounts, nutritional values, brand and barcode, the AI’s confidence and your note. For voice and text input, the note contains your description or the transcript of your recording. We don’t upload photos, only the location of the photo file on your device.
- Fasting plan and profile backup: weekly plan, fasting type, start time, auto-start, goals, body data (sex, age, height, weight, activity level, goal weight, pace), weight history (up to 1,000 entries), unit system and the time you confirmed the safety information
- Settings: time zone, settings for community notifications and quiet hours and, if you turn on push notifications, your push token (section 11)
The following are not transferred to the cloud: your display name, your medications, your safety answers, your water and symptom log for extended fasts and the weights the app reads from Apple Health. While Apple Health is connected, we leave weight and weight history out of the profile backup (section 10). Fasts, journal entries and meals you logged before signing in are moved into your account when you sign in.
Legal basis: We provide the account and sync under our user agreement with you (Art. 6(1)(b) GDPR). Fasting, weight, body data, meals and mood are health data. For this data, the legal basis is also your explicit consent (Art. 9(2)(a) GDPR). You can withdraw it at any time by deleting your account (section 7); the app then keeps working with the data on your device. Withdrawal does not affect the lawfulness of processing before it.
Hosting: Supabase, Inc. (USA) runs our database, sign-in and server functions for us as a processor (Art. 28 GDPR). The database is located in Frankfurt am Main (EU). Access from the USA, for example by Supabase support, cannot be ruled out; the EU Standard Contractual Clauses apply to it (section 5). Data between the app and the database is encrypted in transit (TLS).
3.3 Account and sign-in
You create an account with “Sign in with Apple”, “Sign in with Google” or a sign-in link sent by email; we don’t use passwords. For your account we store:
- your email address (with “Sign in with Apple”, possibly a relay address from Apple)
- your username, if you use the community
- your profile picture – a ready-made design, the mascot or an image of your initials (section 3.10); your own photos aren’t supported at the moment – and your bio, if you add one
- the time you registered and the time you accepted the community rules
Data from Apple and Google: With “Sign in with Apple”, Apple gives us your email address (or a relay address) and, the first time, your name; we store the name in your account data. With “Sign in with Google”, Google gives us your email address, your name and the address of your Google profile picture. Apple and Google process the sign-in as independent controllers under their own privacy policies.
Sign-in links and confirmation emails are sent by Supabase’s authentication service (section 3.2). The legal basis for the account and sign-in is our user agreement (Art. 6(1)(b) GDPR).
3.4 Technical data and error reports
So that we can find crashes and bugs, the app sends technical reports to the Sentry service (Functional Software, Inc., USA):
- app version, operating system and device model
- crash and error reports with the last steps before them (e.g. screens opened, network calls without content, technical app messages) and sampled performance measurements
- a random identifier for this installation and, if you are signed in, your user ID (no email address)
We use Sentry’s EU region; reports are stored in Germany. We don’t deliberately include the content of your entries, but in rare cases a technical error message may contain parts of an entry. The legal basis is our legitimate interest in a stable and secure app (Art. 6(1)(f) GDPR). For access from the USA, the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses apply (section 5).
3.5 Medications
If you add medications in the app (name, dose, dose times and your dose log), the app stores this data only on your device. It is not synced with our cloud and is not transferred to us or to third parties. The app schedules reminders as local notifications on your device. The same applies to your safety answers. The data is deleted when you remove it in the app, delete the local app data or delete the app. It may be part of your personal device backup (e.g. iCloud Backup), which we have no access to.
3.6 Subscription and purchases
Using the app requires a subscription, which you purchase through the Apple App Store. Apple processes the payment; we don’t receive your payment details. To manage and verify your subscription, we use RevenueCat (RevenueCat, Inc., USA). The following data is processed:
- a pseudonymous app user ID (if you are signed in: your account ID)
- your purchase history and subscription status (product, purchase and expiration date, trial period, renewal, App Store country and currency)
- technical data such as app version and operating system
The legal basis is the performance of our user agreement (Art. 6(1)(b) GDPR). The EU Standard Contractual Clauses apply to the transfer to the USA (section 5). So the app also works offline, we additionally store the last known subscription status in encrypted form on your device. If you delete your account, we disconnect it from RevenueCat; the pseudonymous purchase data remains with RevenueCat and Apple for as long as it is needed to handle your subscription and for statutory retention obligations.
3.7 Product data from Open Food Facts
When you scan a barcode with the camera or the AI analysis recognizes a branded product, the app requests that product’s nutritional values directly from the free food database Open Food Facts (Open Food Facts, a non-profit association under French law, France). Only the barcode or the brand and product name, an app identifier with our support address and, for technical reasons, your IP address are transmitted. No account, health or profile data is transmitted. The app stores the results on your device for later lookups. The legal basis is the performance of our user agreement (Art. 6(1)(b) GDPR). Open Food Facts is not our processor here but a controller in its own right. The product data is licensed under the Open Database License (ODbL).
3.8 AI meal analysis (Google Gemini)
When you log a meal by photo, voice recording or text description, the app sends this content through our server (a server function hosted by Supabase) to Google Gemini (Google LLC, USA). Gemini uses it to estimate foods, amounts and nutritional values. The app language, an optional note and the names of products you scanned by barcode beforehand are sent along. We don’t pass names, contact details, account IDs or IP addresses to Google. Photos, recordings and texts can still reveal things about you, so please photograph only your food.
This only happens after you have given your explicit consent in the app (Art. 6(1)(a) and Art. 9(2)(a) GDPR). You can withdraw your consent at any time in Settings under “AI analysis”; manual logging remains available. Google processes the content as our processor. For the transfer to the USA, the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses apply (section 5).
Usage log and subscription check: For each AI analysis, our server stores a log without content, i.e. without photos, recordings or texts: the feature used, the AI model, the amount of data processed (tokens), the duration, whether the analysis succeeded, and your RevenueCat app user ID (if you are signed in: your account ID). If this ID is missing, we store a hash of your IP address created with a secret key instead. This data is pseudonymous, not anonymous. In addition, our server asks RevenueCat whether your subscription is active and remembers the result for a short time. This serves the subscription check (Art. 6(1)(b) GDPR) as well as the daily limit, protection against misuse and cost control (Art. 6(1)(f) GDPR). The daily limit applies automatically but has no legal effect on you: you can always log meals yourself.
3.9 Community
The community is optional. It requires an account, a username and your acceptance of the community rules. We process:
- Profile: username, profile picture and bio. This information is public: other users can see it, and it is technically accessible without signing in.
- Groups: your memberships, roles and join requests; for groups you create, their name, description, language and settings
- Posts: messages, replies, reactions and check-ins. A check-in (“I’m fasting now”) shows the start, planned end and duration of your fast; when your fast ends, the app adds the end time and actual duration. Only members of the group can see posts and check-ins. Any signed-in user can join the official groups.
- Reporting and blocking: If you report content or a person, we store your account ID, what you reported, the reason and the time. If you block someone, we store that so you no longer see their content.
- Notifications: We store mentions, replies, invitations and decisions on join requests as notifications in your account (push delivery: section 11).
- The “… fasting now” number is an anonymous count of the running timers of all signed-in users.
Moderation: An automatic word filter checks new posts, replies, group texts, bios and usernames; if a text contains blocked terms, it is not saved. If three different people report the same content, the app hides it automatically until we have reviewed it. Our server notifies us of each new report without names and without the reported content (type of target, reason, content ID, time), through a Slack channel (Slack Technologies, LLC, USA) and/or by email via the delivery service Resend (Resend, Inc., USA).
The legal basis is our user agreement (Art. 6(1)(b) GDPR). You only share a check-in when you send it yourself; we base showing this health information in the group on your explicit consent (Art. 9(2)(a) GDPR). Moderation, the word filter and handling reports are based on our legitimate interest in a safe community and on our obligations under the Digital Services Act (Art. 6(1)(c) and (f) GDPR).
If you delete your account, we delete your posts, replies, reactions, check-ins, memberships, notifications and reports. Groups you created remain available to the other members, but no longer linked to you.
3.10 Initials profile picture (DiceBear)
If you tap “Create initials avatar” in your profile, the app saves an image address at the DiceBear service (api.dicebear.com) as your profile picture. This address contains your username (or, if you don’t have one yet, your user ID). Every device that shows your profile picture loads the image from DiceBear; DiceBear receives that device’s IP address and the image address. The app draws the ready-made designs and the mascot itself, without DiceBear.
3.11 Email support
If you write to [email protected], Cloudflare (Cloudflare, Inc., USA) forwards the email to our mailbox through its “Email Routing” service. We process your message and contact details to handle your request (Art. 6(1)(b) or (f) GDPR) and delete them once it is resolved and no retention obligation applies. Please only send us health information if your question requires it.
4. Legal bases for processing
We base the processing on these legal bases:
- Storing and reading data on your device: Section 25(2) no. 2 TDDDG (strictly necessary)
- Account, sign-in, sync, subscription, product lookups, community and support: Art. 6(1)(b) GDPR (user agreement)
- Health data in your account, in check-ins and in the AI analysis: additionally Art. 9(2)(a) GDPR (your explicit consent)
- AI analysis: Art. 6(1)(a) GDPR (your consent in the app)
- Push notifications and Apple Health, if you turn them on: Art. 6(1)(b) GDPR; for weight data additionally Art. 9(2)(a) GDPR
- Error reports, daily limit, protection against misuse and moderation: Art. 6(1)(f) GDPR (our legitimate interest in a stable, secure and affordable app and a safe community)
- Obligations under the Digital Services Act and statutory retention obligations: Art. 6(1)(c) GDPR
5. Recipients and transfers to third countries
We don’t sell data and don’t share data for advertising. Only the following service providers receive data, and only as far as needed for the purpose concerned. Processors act only on our instructions (Art. 28 GDPR). We also disclose data where the law requires us to, for example to authorities.
Processors:
- Supabase, Inc., USA – database, sign-in and server functions; database in Frankfurt am Main (EU)
- Functional Software, Inc. (Sentry), USA – error reports; stored in Germany
- RevenueCat, Inc., USA – subscription management
- Google LLC, USA – AI meal analysis (Gemini)
- 650 Industries, Inc. (Expo), USA – delivery of push notifications to Apple
- Cloudflare, Inc., USA – forwarding of emails to [email protected]
- Slack Technologies, LLC, USA, and Resend, Inc., USA – notifications about community reports
Independent controllers that process data under their own privacy policies:
- Apple (Apple Distribution International Ltd., Ireland, and Apple Inc., USA) – App Store, in-app purchase, push delivery (APNs), Apple Health, “Sign in with Apple” and iCloud backups
- Google (Google Ireland Ltd., Ireland, and Google LLC, USA) – “Sign in with Google”
- Open Food Facts, France – product data (section 3.7)
- DiceBear – initials profile picture (section 3.10)
Transfers to third countries: For recipients in the USA, the European Commission’s Standard Contractual Clauses apply (Art. 46(2)(c) GDPR). If a recipient is certified under the EU-U.S. Data Privacy Framework, we additionally rely on the European Commission’s adequacy decision (Art. 45 GDPR). You can request a copy of the safeguards at [email protected].
6. Storage period
This is how long we keep your data:
- Data on your device: until you delete it in the app, delete the local app data or delete the app
- Account and cloud data (fasting, journal, nutrition, profile backup, community): until you delete it or your account. If you delete your account in the app under Settings > “Delete account & cloud data”, your account and cloud data are deleted from the database immediately. They may still be contained in our database provider’s backups until these are automatically overwritten.
- AI analysis log and daily counters: 90 days; cached subscription status: at most 30 days. We delete these entries only when these periods expire, even after an account is deleted.
- Error reports at Sentry: at most 90 days
- Push token: until you delete your account
- Purchase data at Apple and RevenueCat: for as long as it is needed to handle your subscription and for statutory retention obligations (e.g. under tax law)
- Support requests: until your request is resolved, unless a retention obligation applies
7. Your rights
Under the GDPR, you have these rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): there is no export feature in the app yet; on request, we send you your cloud data in a common format (JSON).
- Objection (Art. 21 GDPR), see below
- Withdrawal of consent (Art. 7(3) GDPR) with effect for the future: AI analysis in Settings under “AI analysis”, cloud storage by deleting your account, push notifications and Apple Health in the iOS settings
Right to object (Art. 21 GDPR): Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. This mainly concerns error reports, the AI analysis log and moderation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defense of legal claims.
Write to us at [email protected] for any request. We reply within one month and free of charge. You can delete your local data yourself at any time under Settings > “Delete local app data only”, and your account under “Delete account & cloud data”.
8. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work or where the alleged infringement took place (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg):
Lautenschlagerstraße 2070173 Stuttgart
[email protected]
9. Data security
We protect your data with technical and organizational measures against loss, manipulation and unauthorized access. These include:
- encrypted transmission (TLS) between the app, our server and service providers
- access rules in the database that tie every record to your account (row level security)
- encrypted storage of the subscription status on the device; all other data on your iPhone is protected by iOS device encryption
- no AI keys in the app: the connection to Google runs only through our server, with a subscription check and a daily limit
- access to the database and service provider accounts is limited to the controller personally
10. Apple Health
If you connect Apple Health, FastingFibi reads your body weight from Apple Health and writes weights you log in FastingFibi to it. The app doesn’t read any other Health data. The app processes weights from Apple Health on your device; while the connection is active, we leave weight and weight history out of the profile backup (section 3.2). A weight you log yourself in the journal is part of your journal and is synced if you have an account, even if the app also writes it to Apple Health. If you disconnect, we back up weight and weight history in the profile backup again; this can include values the app previously took over from Apple Health.
We don’t share Health data with third parties or use it for advertising. You can revoke the permission at any time in the iOS settings. Weights the app wrote to Apple Health stay there until you delete them in the Health app.
11. Push notifications and reminders
The app schedules reminders (fast start, last meal, fasting phases, streak, medications, end of the trial) as local notifications on your device. No data is transferred for this.
Community push notifications (mentions, replies, invitations, join requests): If you turn them on in the community, the Expo service (650 Industries, Inc., USA) creates a push token for your device, which we store in your profile. The token is linked to your account and therefore not anonymous. For each notification, our server sends the title and text to Expo; Expo forwards them to the Apple Push Notification service (APNs). The text may contain the content of a post that mentions you. We respect the “Community” switch and quiet hours under Settings > Notifications when sending. You can turn off the display of all notifications in the iOS settings.
12. Changes to this privacy policy
We update this privacy policy when the app or the law changes. You can always find the current version in the app under Settings > Privacy Policy and at fastingfibi.com/en/privacy. We will let you know about significant changes. If we need your consent for something new, we will ask you first.
13. Further information
- No tracking, no ads: the app contains no analytics, advertising or tracking services and doesn’t use your device’s advertising ID.
- No automated decisions: we don’t make decisions with legal or similarly significant effects based solely on automated processing (Art. 22 GDPR). Calorie goals, weight projections and nutrition estimates are suggestions you can change at any time.
- Required information: we need the information from onboarding (goals, body data, safety questions) to create your plan and to protect you from unsuitable types of fasting. Without it, the app can’t be set up properly. Account, community, AI analysis, Apple Health and push notifications are optional.
- Minimum age: FastingFibi is intended only for people aged 18 and over. If we learn that a younger person has an account, we delete their data.
- Users outside the EU: this privacy policy applies to you as well. Any further rights under the data protection law of your country remain unaffected.
Additional information for this website (fastingfibi.com)
The sections above describe the FastingFibi app. When you visit this website, the following also applies:
- Hosting: The website is delivered via Cloudflare Pages (Cloudflare, Inc., USA). When you access it, Cloudflare processes technically necessary data such as your IP address, the date and time of access, the page accessed and information about your browser in order to deliver the website and protect it against attacks. The legal basis is our legitimate interest in a secure and stable website (Art. 6(1)(f) GDPR). Data is transferred to the USA on the basis of the EU-U.S. Data Privacy Framework or EU Standard Contractual Clauses.
- No cookies, no tracking: We do not use cookies or any analytics or tracking services on this website, and we do not embed content from third parties (e.g. fonts or videos).
- Contact by email: If you write to us, we process your details in order to answer your request (Art. 6(1)(b) or (f) GDPR).