wiegemichnicht

Deutsch

Privacy Policy

Last updated: September 2026

1. Controller

Carsten Fregin
spielgestalt
Pracherdamm 106
25436 Tornesch
Germany
Email: wiegemichnicht@spielgestalt.de

2. Overview

wiegemichnicht is an app for tracking calories, activities, and weight. Using it requires an account. This policy describes what personal data is processed, for what purpose, on what legal basis, and what rights you have.

The app does not use advertising, tracking, or analytics software (e.g. Google Analytics). Only the data necessary to operate the app itself is processed.

3. Registration and sign-in

An account requires an email address and password, or you can sign in with your Google account (Google Sign-In) or, on iPhone and iPad, with your Apple ID ("Sign in with Apple", Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland). With Sign in with Apple we receive your email address or, if you choose "Hide My Email", a relay address generated by Apple. If you delete your account, we revoke the link to your Apple ID. Sign-in runs through Firebase Authentication (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; for users outside the EEA: Google LLC, USA). The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract).

4. Body and health data

To calculate a calorie target, we record, based on your input: height, weight, age, biological sex, activity level, and optionally a goal weight. Combined, this data may allow inferences about your health, so we treat it as health data within the meaning of Art. 9 GDPR.

The legal basis is therefore your explicit consent under Art. 9(2)(a) GDPR, given separately (distinct from the terms of use) the first time you use the app. You can withdraw this consent for the future at any time by deleting your account (see section 11).

5. Food, activity, and weight diary

Meals, activities, and weigh-ins you log (including their timestamp) and, if you connect Apple Health or Health Connect (section 6), your daily step totals are stored in Cloud Firestore to show you your history and balance. The legal basis is Art. 6(1)(b) GDPR.

6. Apple Health and Health Connect (optional)

On iPhone and iPad (Apple Health) or on Android devices (Health Connect) you can turn on the import under Profile → Connect Apple Health or Connect Health Connect. The app then reads, through Apple's HealthKit or Google's Health Connect interface, your weight, your workouts (type, time, calories burned), and your steps (daily totals) for the last 30 days, and afterwards newly added data whenever you open the app. The data is stored in Cloud Firestore as weight, activity, and step entries so it appears in your diary, balance, and weight history. We also store whether the import is turned on and up to which point data has already been imported, so that nothing is imported twice or again. On Android, Health Connect additionally requires read permission for total energy burned and distance in order to read workouts; the distance is not stored. The app does not write anything back to Apple Health or Health Connect.

This data is health data within the meaning of Art. 9 GDPR. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give by actively turning the switch on and granting access in the system dialog from Apple or Google. Granting access is voluntary; without it, all other functions of the app remain fully usable. You can withdraw your consent for the future at any time by turning the switch off and/or revoking access in iOS Settings under Health → Data Access & Devices or in Health Connect under App permissions. Entries already imported remain until you delete them or delete your account (see section 11).

Data from Apple Health and Health Connect is not used for advertising or marketing, is not sent to the AI analysis (section 7), and is not shared with third parties; the only recipients are the service providers named in section 12 (Google Cloud/Firebase) for storage.

7. Photo calorie estimation (AI analysis)

If you upload a photo of a meal, it is stored in Firebase Storage and sent to Google's Gemini API (Google Ireland Limited / Google LLC) for analysis, which produces a calorie and macronutrient estimate. The same applies if you describe a meal as text instead. A small preview copy (thumbnail) is additionally generated from the original photo. Both images are deleted when you delete the corresponding entry. The legal basis is Art. 6(1)(b) GDPR (core function of the app) combined with your consent under section 4, insofar as the photo allows inferences about your diet and thereby indirectly about your health.

8. Barcode scanning and food search

Scanning a barcode sends only the barcode number (no other personal data) to the free, open-source Open Food Facts database to retrieve nutritional information. In the food search, the search term you enter is forwarded through our server (Google Cloud, Frankfurt region) to Open Food Facts; Open Food Facts receives neither your user ID nor any other information about you. To speed things up, we cache search terms together with their result list for at most three days, without any link to your account. The search in basic foods and dishes (Bundeslebensmittelschlüssel of the Max Rubner-Institut) runs entirely on your device; no data is transmitted. Your recently logged foods for the suggestion list are read from your own diary. The legal basis is Art. 6(1)(b) GDPR.

9. Feedback

If you send us feedback through the app, we store your user ID, email address, and message text to evaluate it. These entries are not visible to you or other users within the app. Feedback may be retained for product improvement even after your account is deleted, since it can no longer be readily attributed to you personally afterward. The legal basis is Art. 6(1)(a) GDPR (you send feedback voluntarily).

10. App Check (abuse protection) and crash reports

To protect against automated abuse, the web version of the app uses Firebase App Check with reCAPTCHA Enterprise (Google). This evaluates technical signals from your browser to distinguish automated access from genuine use; no content of your inputs is transmitted. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protecting the app and its associated costs from abuse).

The iOS, Android and macOS apps use Firebase Crashlytics (Google) to detect and fix crashes and program errors. When an error occurs, technical details are transmitted: the error message and code location, device model, operating system and app version, free memory, and a random installation identifier. The content of your entries, health data, your email address or your user ID are not transmitted. Reports are deleted after 90 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable, error-free app). The web version does not use Crashlytics.

11. Retention and deletion

Your data is stored for as long as your account exists. You can delete your account directly in the app at any time (Profile → Delete account). This irrevocably deletes your profile, all food/activity/weight/step entries, your health import settings, uploaded photos, and your sign-in account. Feedback already submitted is excluded (see section 9). Alternatively, you can request deletion informally by email to the address above.

12. Recipients and international transfers

Processing runs on Google Cloud/Firebase. Cloud Functions servers are fixed to the europe-west3 (Frankfurt) region. For individual Firebase services (e.g. Authentication), processing cannot be fully restricted to the EU; insofar as data is transferred to the US as a result, this relies on the EU Standard Contractual Clauses with Google.

13. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to withdraw any consent given at any time with future effect (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority – among others, the Unabhängige Landeszentrum für Datenschutz Schleswig-Holstein (ULD) is competent.

You can exercise access and data portability directly in the app (Profile → Download my data): you receive a ZIP archive with all data stored for your account – profile, nutrition, activity and weight entries, photos, consent records and your feedback messages – in a structured, machine-readable format (JSON, plus CSV). For this, the archive is provided briefly (about 30 to 45 minutes) in our storage (Google Cloud Storage, europe-west3) and then deleted automatically; the download link is intended for you only. One export is possible per 24 hours. For further requests you can also reach us using the contact details in the legal notice.

14. Minimum age

The app is not directed at persons under 16 years of age.

15. Changes

We update this policy whenever data processing changes. For material changes (in particular new processing purposes for health data), we will ask for your renewed consent.

This English version is provided for convenience only. The German version is legally binding.

Back to home