Privacy.
How we collect, store, and process your data. EU-hosted, DSGVO/GDPR-compliant.
Last updated · July 29, 2026
Summary
pinning treats your data as if your life depended on it — because your protocol might. We store everything in EU-Central (Frankfurt), encrypt it at rest and in transit, never sell it, never share it with advertisers, and let you export or delete all of it.
TL;DR: We store only what we need to run the service. You own your data. We do not sell or share it. You can download all of it, or erase your account, from Settings.
1. Who we are
Data controller within the meaning of Art. 4 (7) GDPR / § 5 DDG is:
Aleksander Chadzy — Einzelunternehmer, handelnd als „pinning“
Graf-Heinrich-Str. 1, 21698 Harsefeld, Deutschland
Email: privacy@pinning.info
Full provider details: Impressum. We have not appointed a data protection officer; we are below the threshold of § 38 BDSG.
2. Health data — the important part
Most of what pinning stores is health data within the meaning of Art. 4 (15) GDPR, and therefore a special category of personal data under Art. 9 (1) GDPR:
- Injection logs — compound, dose, site, time, how you felt, side effects
- Cycles and protocols, including planned dosing
- Body metrics — weight, height, year of birth, sex, goal, activity level
- Bloodwork values you upload or enter
- Meals, calories and macros, including photos of what you eat
Processing data of this kind is prohibited unless one of the exceptions in Art. 9 (2) applies. We rely on your explicit consent under Art. 9 (2) (a) GDPR, which you give when you create an account and which is the reason the app can store any of this at all.
You can withdraw that consent at any time, with effect for the future, by deleting your account in the app (Settings → Delete account) or by writing to privacy@pinning.info. Withdrawal does not affect the lawfulness of processing carried out beforehand. Because this consent is what the service runs on, withdrawing it means we can no longer provide the service.
3. What we collect
Account data
- Email address (login and account-essential notifications)
- Username / display name (chosen by you)
- Hashed password (via Supabase Auth)
Health and body data
See section 2 — this is the bulk of what the app stores, and it is consent-based.
Photos
- Meal photos you take or pick, in order to estimate calories and macros. The photo is sent to our server, analysed, and stored in your private folder so the entry keeps its picture. Camera and photo-library access is asked for in the app and can be revoked in iOS Settings at any time.
- Bloodwork and receipt images, if you choose to upload them.
Technical data
- Aggregate first-party analytics (page views, clicks) on the website — consent-based, off until you accept; no raw IP stored, country derived from edge headers, unique counts via a daily rotating salted hash
- Server logs (IP, user-agent) — retained 14 days for security
- In the iOS app: crash and error diagnostics, only if a diagnostics key is configured for the build. No advertising identifiers, ever.
4. Legal bases
- Art. 9 (2) (a) — explicit consent, for all health and body data (§ 2)
- Art. 6 (1) (b) — performance of contract: account, subscription entitlement, delivering the features you asked for
- Art. 6 (1) (f) — legitimate interest: security logs, abuse prevention, rate limiting
- Art. 6 (1) (a) — consent: website analytics, marketing email, push notifications
- Art. 6 (1) (c) — legal obligation: retention of billing records
5. Processors and recipients
- Supabase — database, authentication, file storage. Region: EU-Central (Frankfurt).
- Vercel — hosting of pinning.info and the API. Region: Frankfurt.
- Anthropic — analysis of meal photos (and, if you upload them, bloodwork and receipt images). The image is transmitted for the purpose of the estimate. This is a core function of the food tracker, not an optional extra.
- Apple — App Store distribution and, for subscriptions bought in the app, the payment relationship. Apple is the seller of record and an independent controller for that transaction.
- RevenueCat — verification and management of App Store subscriptions, so the app knows whether your plan is active.
- Stripe — payment processing for subscriptions taken out on the website before web checkout closed. No new contracts are concluded this way.
- Resend — transactional email (reminders, account mail).
- First-party analytics — self-hosted in our own EU database; no third-party analytics provider.
Each processor is bound by a data processing agreement under Art. 28 GDPR. We can provide copies on request.
6. International transfers
Anthropic, Apple, RevenueCat and Stripe may process data in the United States. Transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses under Art. 46 (2) (c) GDPR, together with supplementary measures.
7. Retention
- Account, health and body data: until you delete your account. Deletion cascades to cycles, pin logs, vials, meals, metrics and uploads.
- Uploaded images: with the entry they belong to; removed when you delete the entry or the account.
- Server logs: 14 days.
- Billing records: 10 years (§ 147 AO, § 14b UStG).
8. Your rights (Art. 15–22 GDPR)
- Access your data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (Art. 17) — in the app under Settings → Delete account, and on the website under Settings
- Restrict processing (Art. 18)
- Data portability (Art. 20) — download everything as JSON from Settings. Free of charge, as required by Art. 12 (5).
- Object to processing (Art. 21)
- Withdraw consent at any time, including the Art. 9 consent (see § 2)
- Lodge a complaint with a supervisory authority — for us, the Berliner Beauftragte für Datenschutz und Informationsfreiheit
To exercise any right: privacy@pinning.info. We answer within one month (Art. 12 (3)).
9. Automated processing
The calorie and macro figures next to a meal photo are produced by an AI model and are an estimate, not a measurement. They are labelled as such in the app. There is no automated decision-making with legal or similarly significant effect within the meaning of Art. 22 GDPR, and no profiling.
10. Security
- TLS in transit, encryption at rest
- Row-Level Security on every database table — a row is readable only by its owner
- Private storage buckets, scoped per user
- Encrypted backups
11. Changes
We'll notify you by email at least 14 days before any material change to this policy. Where a change requires your consent, we will ask for it rather than assume it.