Privacy notice
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Yedeni UG (haftungsbeschränkt)
Rodelbahn 12 a
85614 Kirchseeon
Deutschland
Managing director: Sepita Ansari Pir Seraei
Register court: Amtsgericht München, registration number: HRB 315154
Email for privacy enquiries: datenschutz@yedeni.com
2. Data protection officer
We are not currently required to appoint a data protection officer: fewer than 20 people are permanently engaged in the automated processing of personal data (§ 38(1) BDSG) and our core activity does not require large-scale regular and systematic monitoring within the meaning of Art. 37(1) GDPR. We have nonetheless carried out a data protection impact assessment under Art. 35 GDPR because we process health data. Please direct questions to datenschutz@yedeni.com.
3. What data we process
3.1 Account and sign-in data
- Email address
- Password (stored only as a cryptographic hash; we cannot read it)
- Display name and username
- When signing in with Apple or Google: the identifier and email address provided (with Apple, optionally an anonymised relay address)
- Sign-in timestamps and failed sign-in attempts
3.2 Health data (special category)
- Sex, date of birth and age (for the birthday greeting we use only the day and month; that greeting is not a processing of health data)
- Height, body weight and weight history, body fat percentage
- Nutrition goals (lose, maintain, gain) and target weight
- Allergies and food intolerances
- Diets and preferences (e.g. vegan, vegetarian, dislikes)
- Activity level and self-recorded activities
- All logged meals with nutrition values, plus water, caffeine and supplement entries
- Daily values imported from Apple Health or Health Connect (see section 8)
3.3 Content you create
- Recipes with ingredients, steps, photos and videos
- Reviews, comments and collections
- Profile picture and profile text
- Shopping lists and weekly plans
- Messages to the AI coach, including voice recordings and photos of meals and labels
- Photos of cooked dishes that you save to a diary entry (visible outside the app only if you share them yourself)
- Reports you submit about other content or accounts
3.4 Usage data
- Recipes viewed and saved, likes, follow relationships
- Progress in achievements, streaks and levels
- Feedback on suggestions (accepted, rejected, cooked)
- Invitation and referral codes
3.5 Technical data
- IP address and timestamp in server logs
- Device type, operating system, app and runtime version, language setting
- Push token, if you allow notifications
- Error and crash reports
- Device advertising ID, if you consent to personalised advertising
4. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Creating and managing an account | Providing the service, sign-in, support | Art. 6(1)(b) GDPR (performance of a contract) |
| Processing health data (body, nutrition, allergies, activity) | Calculating your calorie and nutrient needs, food diary, suggestions | Art. 9(2)(a) GDPR (explicit consent), additionally Art. 6(1)(b) GDPR |
| AI features (coach chat, photo estimation, recipe creation, transcription, translation) | Delivering the feature you requested | Art. 6(1)(b) GDPR; where health data is involved additionally Art. 9(2)(a) GDPR, and Art. 49(1)(a) GDPR for the transfer to the United States |
| Publishing recipes, reviews and profile | Community features you actively use | Art. 6(1)(b) GDPR |
| Achievements, streaks and levels | Motivation and engagement, part of the service | Art. 6(1)(b) GDPR |
| Push notifications | Reminders, notices about new content, birthday greeting (for which we use the day and month of your date of birth) | Art. 6(1)(a) GDPR (consent, withdrawable at any time) |
| Product analytics (PostHog) | Understanding which features are used in order to improve the app | Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG |
| Personalised advertising (AdMob) | Funding the free tier | Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG |
| Non-personalised advertising | Funding the free tier without profiling | Art. 6(1)(f) GDPR (legitimate interest in funding the free offering) |
| Subscriptions and purchases | Providing paid features, purchase validation | Art. 6(1)(b) GDPR; retention of receipts: Art. 6(1)(c) GDPR |
| Error and crash diagnostics (Sentry) | Stability and security of the app | Art. 6(1)(f) GDPR (legitimate interest in a functioning service) |
| Server logs, rate limiting, abuse detection | Security, defence against attacks and misuse | Art. 6(1)(f) GDPR (legitimate interest in system security) |
| Quality assurance of AI answers (per-turn diagnostic record) | Detecting and fixing faulty coach answers — in particular incorrect nutrition figures and diary entries that were silently not made | Art. 6(1)(f) GDPR (legitimate interest in a service that calculates correctly). The conversation content itself is stored only with your separate release — see section 6.5 |
| Accounting for AI usage and enforcing usage allowances | Attributing model cost, honouring the free tier's allowances, abuse prevention | Art. 6(1)(b) GDPR (providing the tiered service), additionally Art. 6(1)(f) GDPR (cost control and abuse prevention) |
| Measuring usage frequency (time of last app open, opens per day) | Understanding how regularly the app is used — a basis for product improvement and for coarse contact groups in the customer-relations system | Art. 6(1)(f) GDPR (legitimate interest in engagement measurement and product improvement). No information stored on your device is accessed, so no consent under § 25 TDDDG is required |
| Moderation of user-generated content | Protecting other users, complying with the Digital Services Act | Art. 6(1)(c) and (f) GDPR |
| Importing values from Apple Health / Health Connect | More accurate calculation of your energy needs | Art. 9(2)(a) GDPR (separate explicit consent, in addition to the operating-system permission) |
| System emails (account and subscription confirmations, payment problems, renewal announcements, security notices, invoices, support replies) | Performing the contract and answering your requests | Art. 6(1)(b) GDPR (performance of a contract) |
| Information and marketing emails including performance measurement (opens, clicks) | Informing you about news and offers, improving the content | Art. 6(1)(a) GDPR together with § 7(2) no. 3 UWG and § 25(1) TDDDG (consent) |
| Contact management and communication history (customer-relations system) | Supporting users and people who contact us through a support request, a notice or as business partners; answering enquiries; keeping our communication traceable. Contact details we did not receive from you directly (for example from a partner list) are processed only to get in touch, and we inform you of their source and purpose at the latest at that point (Art. 14 GDPR) | Art. 6(1)(b) GDPR, additionally (f) (legitimate interest in orderly support; for a plain record of contacts and correspondence no opposing interests prevail, since only contact and communication data is processed — health data is excluded) |
| Suppression list of undeliverable and unsubscribed addresses (digest only) | Making sure an objection is honoured permanently | Art. 6(1)(c) GDPR (fulfilling the obligation under Art. 21(3) GDPR), additionally (f) |
5. Your consents and how to withdraw them
We obtain every consent separately and record which version of which document you accepted and when (Art. 7(1) GDPR). Your consents to information and promotional emails, notifications and product analytics are listed in the app under "Settings" > "Other" > "My consents", where each can be withdrawn individually; the consent to personalised advertising is withdrawn under "Settings" > "Other" > "Ad settings" (the entry appears once the consent form has been shown). The consent to processing your health data is likewise withdrawn under "My consents" — because the app cannot work without that data, your account is deleted in the process (see table) — or by writing to us (the contact details are in section 2).
| Consent | Covers | Effect of withdrawal |
|---|---|---|
| Health data | Processing of body, nutrition and activity data | The core features can no longer be provided, so withdrawal has the effect of terminating the contract. We tell you this before you withdraw, and delete your data afterwards. |
| Product analytics | PostHog | No further analytics data is collected. The app works unchanged. |
| Personalised advertising | AdMob | You still see ads, but without personalisation. The app works unchanged. |
| Push notifications | Reminders, notices and greetings | No further notifications are sent. The app works unchanged. |
| Apple Health / Health Connect | Importing activity and weight values | No further values are imported. Values already imported can be deleted in the diary. |
| Information and marketing emails | News, tips and offers by email, including performance measurement (opens and clicks) | You receive no further marketing emails. System emails about your account continue. Withdrawal works without signing in, via the link in every email, and takes effect immediately. |
The lawfulness of processing carried out before withdrawal remains unaffected.
6. Artificial intelligence
Yedeni's central features rely on large language models from OpenAI. Because health data leaves the EU in the process, we set out exactly what happens.
6.1 What is transmitted
- Your message to the coach verbatim, including voice recordings for transcription
- Photos of meals, labels and foods that you take
- The slice of your profile needed for the answer: nutrition goals, remaining daily budget, allergies, preferences, the meals already logged today, and your activity and weight values — including the daily values imported from Apple Health or Health Connect (section 8)
- Recipe text when creating, importing and translating
6.2 What is not transmitted
- Your email address, your name and your password
- Your account identifier — no user identifier of any kind is transmitted
- Payment and subscription data
- Your full history; only the slice needed for the specific answer is sent
6.3 Training and retention
Data submitted through the API is contractually excluded from model training. OpenAI retains requests only for a limited period for abuse detection.
6.4 Labelling and limits
AI-generated content is labelled as such in the app. Nutrition values are matched against our food database wherever possible rather than invented by the model. Even so, estimates — particularly from photos — can deviate substantially from reality. Always verify figures that matter to your health.
6.5 Quality assurance of coach answers
An AI coach that miscalculates nutrition values, or silently fails to make an entry, is more dangerous than one that does not answer at all. So that such faults surface, we record a technical diagnostic trace for every coach turn.
- Always stored (30 days): the model used and its settings, which tools were available to the model and which it called, response time, token usage, the error code if a turn failed, and a purely arithmetic suspicion score. None of this contains conversation content or health values. Solely for test accounts of our own team — active administrator accounts we have explicitly enabled for this — we additionally store the context excerpt of the turn; user accounts are never affected.
- Only with your separate release: the excerpt of the conversation itself and the specific figures the audit flagged. Without that release we record only that an answer was conspicuous — not what it said.
- You grant the release case by case: if you report an answer using the thumbs function, we ask you explicitly whether we may also evaluate the wording of that one case. The box is not pre-ticked. A release covers the reported case only, not your history.
- Withdrawal: you can withdraw a release you have given at any time — in the app via the thumbs function on the same answer, or by writing to datenschutz@yedeni.com. A case not yet worked on is then deleted in full; one already worked on loses the wording and keeps only the lesson drawn from it.
Independently of this, we as the operator can view your coach conversation — see section 12.1. The diagnostic trace does not change that; it exists so that a fault surfaces without anyone having to read along.
7. Recipients of your data
We use the following providers. We have concluded data processing agreements under Art. 28 GDPR with all of them. An always-current version of this list is available at Sub-processors.
| Provider | Purpose | Data received | Location | Basis |
|---|---|---|---|---|
| Supabase, Inc. | Registration and sign-in (Auth), primary PostgreSQL database | Email address, password hash, sign-in timestamps, all content and health data stored in the app | EU (Frankfurt am Main, Germany) | Processed inside the EU/EEA — no third-country transfer The provider is US-based; data is stored exclusively in the EU region. Standard contractual clauses additionally cover support access from the US. |
| Vercel Inc. | Operating the backend API (serverless functions) and serving these legal pages | IP address, timestamp, requested endpoints and the full contents of each request while it is processed | EU (Frankfurt am Main, region fra1) | Processed inside the EU/EEA — no third-country transfer The execution region is pinned to Frankfurt. The provider is US-based; standard contractual clauses cover administrative access. |
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Storing media (Blob Storage), delivery via the content-delivery network (Front Door, cdn.yedeni.com), media processing (Azure Functions: audio and frame extraction, video transcoding) | Uploaded photos and videos, profile pictures, voice recordings; CDN requests additionally involve IP address and timestamp | EU (West Europe region, Netherlands) | Processed inside the EU/EEA — no third-country transfer |
| OpenAI Ireland Ltd. / OpenAI, L.L.C. | All AI features: coach chat, photo and label analysis, recipe generation and import, nutrition estimation, speech transcription, translation, semantic search (embeddings) and content moderation | The contents of each request: chat messages, meal and label photos, voice recordings, recipe text and the slice of nutrition goals, daily balance, allergies and preferences needed for the answer — including health data. No account or user identifier is transmitted. | United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses Data submitted through the API is contractually excluded from model training. This is the only processor handling health data outside the EU — the transfer therefore relies on your explicit consent under Art. 9(2)(a) in conjunction with Art. 49(1)(a) GDPR. |
| Upstash, Inc. | Technical cache: request rate limiting, usage allowances for AI features (daily or weekly), short-lived caching | Pseudonymous identifiers (user ID or IP address) and counters; no content or health data | EU | Standard contractual clauses (Art. 46(2)(c) GDPR) The provider is US-based; standard contractual clauses cover access from there. |
| Functional Software, Inc. (Sentry) | Crash and error diagnostics, performance regression detection | Error messages, stack traces, app and device version, pseudonymous user ID. Email addresses, passwords, tokens and comparable values are stripped automatically before transmission. | EU (German region, ingest.de.sentry.io) | Processed inside the EU/EEA — no third-country transfer |
| PostHog Ltd. | Product analytics and app improvement | Pseudonymous device/user identifier, screens viewed, actions triggered, device class, OS and app version. No screen recordings, no health data, no plain-text content. | EU (Frankfurt am Main, eu.i.posthog.com) | Processed inside the EU/EEA — no third-country transfer |
| RevenueCat, Inc. | Subscription management: purchase validation, term and cancellation status, purchase restoration | Pseudonymous user ID, app-store purchase receipts, product and term data, country. No payment details — those stay with Apple and Google. | United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses |
| Google Ireland Ltd. (AdMob, User Messaging Platform) | Serving ads on the free tier and obtaining the required consent | Device advertising ID, IP address, coarse location (country), ad interactions, consent status | EU and United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses Personalised ads only after explicit consent. Without consent only non-personalised ads are served. Health data is never used for or transmitted for advertising. |
| Google Ireland Ltd. (Anmeldung mit Google) | Sign-in via a Google account, if you choose that option | Email address, name, Google account identifier | EU and United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses |
| Apple Distribution International Ltd. | Sign in with Apple, App Store purchases, push delivery (APNs), access to Apple Health after you allow it | Apple account identifier, forwarded or anonymised email address where applicable, purchase receipts, push token | Ireland (EU) | Processed inside the EU/EEA — no third-country transfer Apple Health data is read on your device only and forwarded to our backend as aggregated daily values — we send no health data back to Apple. |
| Google Ireland Ltd. (Health Connect, Google Play) | Access to Health Connect after you allow it, Google Play purchases, push delivery (FCM) | Google account identifier, purchase receipts, push token. Health Connect data is read locally on the device only. | EU and United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses |
| 650 Industries, Inc. (Expo / EAS) | Sending push notifications and delivering app updates | Device push token, notification content, app and runtime version when fetching updates | United States | Standard contractual clauses (Art. 46(2)(c) GDPR) Notification texts contain reminders and may carry a meal suggestion with portion and calorie figure; your weight, goals and diary values are not transmitted. Delivery runs through Expo and the device vendor's service (Apple or Google). |
| Apify Technologies s.r.o. | Technically retrieving publicly available Instagram posts from partners who expressly permitted us to use their content | Public post content and the partner's handle. No Yedeni user data is transmitted. | Czech Republic (EU) | Processed inside the EU/EEA — no third-country transfer |
| Secret Industries Pty Ltd (FatSecret Platform API) | Supplementary food and barcode database when a product is found neither locally nor in Open Food Facts | Only the search term or barcode number. No user identifier, no health data. | Australia | No personal data transmitted |
| GitHub, Inc. | Running the nightly database backup (the backups themselves are stored in Azure's EU storage) and triggering internal load tests (control parameters only, no personal data) | The backup stream is processed during execution and not retained there. | United States | Adequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses |
| Brevo SAS | Delivery of system and information emails, plus performance measurement | Email address, salutation/name, subject and body of the message, delivery and open events, IP address when images are loaded | France and Germany (EU) | Processed inside the EU/EEA — no third-country transfer Health data is never processed by marketing email — this is enforced in code, not merely intended. The provider holds no contact list; it receives only the single recipient and the finished message per send. |
Beyond this we disclose personal data only where legally required (for example to law-enforcement authorities on a court order) or where you have expressly consented. We do not sell personal data.
8. Apple Health and Health Connect
If you explicitly allow it, Yedeni reads values from Apple Health (iOS) or Health Connect (Android) in order to determine your actual energy expenditure more accurately.
- What is read: active energy burned, steps and body weight.
- Processing: the raw data is read on your device and aggregated there into daily values. Only those daily values are transmitted to our backend and stored with your account.
- Purpose: calculating your energy needs, displaying them in the diary and the coach's advice built on them.
- Advertising: data from Apple Health and Health Connect is never used for advertising, marketing or advertising-related profiling, and is never transmitted to ad networks.
- Sharing with the AI services: your activity values for the current day — steps, active energy burned and the daily expenditure derived from them — are part of the context the coach receives with every request. They are therefore transmitted to OpenAI with every coach request, together with your weight history (section 6) — pseudonymised, i.e. without your account identifier, under a data-processing agreement and contractually excluded from model training. The legal basis is your separate consent under Art. 9(2)(a) GDPR and, for the transfer to the United States, Art. 49(1)(a) GDPR. These data are not shared with any other third party.
- Withdrawal: you can revoke the permission at any time in your device settings; Yedeni will then take over no further values.
By default Yedeni writes no data back to Apple Health. Should that option be offered in future, it will happen only at your separate instruction.
9. Advertising
On the free tier we show ads via Google AdMob. Before the first ad we ask, through Google's consent form (User Messaging Platform), whether you want personalised advertising. On iOS we additionally ask via the system "App Tracking Transparency" dialog before your device advertising ID is used.
- Without your consent you see only non-personalised ads.
- Your health and nutrition data is never analysed for advertising or transmitted to advertising partners.
- With an active subscription you see no ads; the advertising module is not even loaded.
- You can change your choice at any time under "Settings" > "Other" > "Ad settings".
10. Email communication
We distinguish two kinds of email. They run over separate sender addresses so that one cannot affect the other.
10.1 System emails
Confirmations about your account and subscription (registration, start and end of a trial or subscription), notices about payment problems, announcements of an automatic renewal, security notices, invoices and replies to your support requests. These are part of the contract (Art. 6(1)(b) GDPR); as long as the contract is running you cannot object to them. They contain no open tracking — that is enforced in code, not merely configured.
10.2 Information and marketing emails
News, tips and offers. Some of these emails are triggered by how you use the app — for example that you published a recipe, that an invitation was redeemed, or that you have not opened the app for a while. Values from your nutrition diary are not used for this. The legal basis is your consent (Art. 6(1)(a) GDPR together with § 7(2) no. 3 UWG). Every such email carries an unsubscribe link; one click is enough, no sign-in is needed, and it takes effect immediately. We also set the `List-Unsubscribe` headers so that your email client can show its own unsubscribe button.
10.2a Confirming your consent (double opt-in)
After you have given consent in the app, we send you a system email containing a confirmation link. Only once you click it do we send information and marketing emails; without confirmation you receive only the emails about your account. The link is valid for seven days. To evidence your consent (Art. 7(1) GDPR) we store the time of that click, your IP address, the identifier of your browser or email client, and a checksum of the link we sent. We process these details solely as evidence, never for advertising; the legal basis is Art. 6(1)(c) GDPR together with our accountability obligation under Art. 7(1) GDPR. The same applies when you change your selection via the preference centre in one of our emails or unsubscribe via the unsubscribe link.
10.3 Performance measurement
For information and marketing emails we measure whether the message was opened and whether a link was clicked. The email contains a small image whose retrieval tells us the time and IP address. Because that retrieval accesses your device, it is covered by your consent (§ 25(1) TDDDG) — the consent text names performance measurement explicitly. We use it to see which topics are read and to retire addresses that are permanently unreachable. If you do not want this, turn off automatic image loading in your email client, or unsubscribe.
10.4 No health data by marketing email
10.5 Suppression list
If your mailbox permanently reports an address as undeliverable, if you mark a message as spam, or if you unsubscribe, we record that in a suppression list. What is stored there is only a cryptographic digest of your address (SHA-256), not the address itself. These entries survive the deletion of your account — otherwise the next send would write to you again, which is exactly what you did not want. The digest cannot be turned back into your address; it can only answer whether an address entered again is blocked.
10.6 Sending provider
Sending runs through Brevo SAS (France), processed in France and Germany, so with no third-country transfer. Brevo holds no contact list from us; per message it receives only the single recipient and the finished text. Details in the list of sub-processors.
11. Product analytics
With your consent we record via PostHog (Frankfurt data centre) which features are used. Collected are a pseudonymous identifier, screens viewed, actions triggered and device and version details. The contents of your meals, health values and chat messages are not collected. Without consent the analytics module is not started. You can withdraw consent at any time in settings; data already collected is deleted along with your account.
12. Publicly visible content
Please note which details become visible to others once you use the community features:
| Content | Visibility |
|---|---|
| Username, display name, profile picture, profile text | Public to all users |
| Recipes you publish, including photos and videos | Public, including via shared links outside the app |
| Reviews and comments | Public, with your display name |
| Collections set to public | Public; collections set to private stay private |
| Follow relationships and feed activity | Visible to your followers |
| Shared shopping lists | Accessible to anyone with the link |
| Meals, weight, body data, goals, coach chat | Never public and not visible to other users — for access by us as the operator see section 12.1 |
12.1 Access by us as the operator
“Not public” does not mean “readable by no one”. We therefore state explicitly when we ourselves can look at your content — including your conversation with the coach.
- Who: only named members of our team holding administrative authorisation. There are three graduated roles; the lowest cannot reach your private content — diary, body data, coach conversation — at all.
- Always a re-authentication: any access that displays your conversation verbatim — regardless of which of the two paths it takes — and any access to your health data (body data, goals, diary and weight entries, allergies and diet) requires an additional authentication step.
- Two paths, of different reach: Access to one specific account presupposes that a reason already exists — someone got in touch or reported something. Separately there is a review of conspicuous coach answers across several accounts (section 6.5). The list for it shows technical metrics only; text appears only when an individual case is opened.
- For what: handling your support request or report; investigating reported abuse; investigating a technical fault; quality review of conspicuous coach answers (section 6.5); a legal obligation.
- Not for: advertising, profiling for advertising purposes, disclosure to third parties, or training our own models.
- Traceability: every access to your data is logged individually — not just the session, but each call. Administrative accounts are additionally protected by two-factor authentication.
- Your right: under Art. 15 GDPR you may ask whether and for what purpose your data was accessed.
For evaluations that are not tied to an individual case we use the content-free diagnostic trace described in section 6.5. If you wish to object to such access, contact datenschutz@yedeni.com; we will then examine whether the purpose can be achieved without your content.
13. Retention
| Data | Retention |
|---|---|
| Account, profile and health data | Until the account is deleted or consent is withdrawn |
| Meals, weight and other diary entries | Until the account is deleted |
| Recipes and media you created | Until you delete them or the account is deleted |
| Coach chat history | 180 days, then deleted automatically |
| Recipe view history | 30 days, then deleted automatically |
| Server logs containing IP addresses | at most 30 days |
| Failed sign-in attempts | 30 days, then deleted automatically |
| Error and crash reports | 90 days |
| Daily values imported from Apple Health or Health Connect | 180 days, then deleted automatically; sooner if you delete them in the diary |
| Coach insights about your history | 120 days |
| Feedback on suggestions (accepted, rejected, cooked) | 12 months |
| Deleted meals (recycle bin) | 30 days, then removed permanently |
| Device data and push tokens | Deactivated 90 days after the device was last used, deleted after 180 days |
| Log of administrative access (section 12.1) | 12 months — the basis of your right to information about access |
| Consent records | Until the account is deleted — the Art. 7(1) GDPR record is removed in full together with the account and is not kept beyond it |
| Diagnostic trace of coach turns (without conversation content) | 30 days, then deleted automatically |
| Released individual cases from quality review — the conversation content | 90 days, after which the wording is removed automatically. Sooner if you withdraw the release: a case not yet worked on is deleted entirely, one already worked on loses the wording. At the latest when the account is deleted. |
| Released individual cases — the lesson drawn from them (without conversation content) | 400 days. What remains then describes our product — what the coach should have done — no longer you |
| AI usage and cost records | Up to 180 days as cost evidence; the link to you is removed immediately when the account is deleted. A cost archive without any personal reference is kept longer |
| Daily app-open counters | 13 months, then deleted automatically |
| Reports and moderation decisions | Up to 6 months after the case is closed. For notices under the Digital Services Act, the notifier's name and email address are removed 6 months after the decision; the decision and its reasons are kept as evidence |
| Invoices and accounting records | 10 years (§ 257 HGB, § 147 AO) |
| Analytics data | Until consent is withdrawn, at the latest until the account is deleted |
| Email delivery logs (recipient, subject, delivery and open events) | 26 months, then deleted automatically |
| Suppression list (digest of the address only, not the address) | Indefinite — deleting a suppression would mean writing to that person again |
| Contact details and communication history in the customer-relations system | Until the account is deleted or you object; consent evidence as above. Contacts without an app account: three years after the last contact, then deleted automatically |
After you delete your account we irreversibly remove all personal data within 30 days, unless a statutory retention obligation applies. Recipes you published that others have added to their plans or collections are retained without any link to you; your name is removed. If you want that content deleted as well, please delete it before deleting your account or contact datenschutz@yedeni.com.
14. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR) at any time. Address requests to datenschutz@yedeni.com; we respond within one month.
- Access and portability: under "Profile" > "Settings" > "Export data" the app immediately gives you a complete, machine-readable copy in JSON format.
- Rectification: most details can be changed directly in the app.
- Erasure: under "Profile" > "Settings" > "Delete account" you delete your account and all data yourself — no support ticket required.
- Objection: you may object at any time to processing based on legitimate interests.
Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Deutschland
https://www.lda.bayern.de · poststelle@lda.bayern.de
You may also contact the supervisory authority where you habitually reside.
15. Automated decisions and profiling
Yedeni derives personalised nutrition suggestions from your goals, history and preferences, and personalises the content feed. That constitutes profiling within the meaning of Art. 4(4) GDPR.
No decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Art. 22(1) GDPR takes place: all suggestions are non-binding recommendations, you decide freely in every case, and no legal consequences arise. The suggestions are the core of the service and cannot be switched off; alongside the personalised “For you” feed, the non-personalised recipe search is available to you at any time.
We use automated checks to moderate user-generated content. If such a check results in content removal or account suspension, we tell you the reasons and you can have the decision reviewed by a human.
16. Children and young people
Yedeni is intended for people aged 16 and over. We check the minimum age when recording your date of birth; younger people cannot use the app. If we learn that data of a younger person is being processed, we delete the account without delay. Parents and guardians may contact datenschutz@yedeni.com.
17. Data security
We apply technical and organisational measures under Art. 32 GDPR, in particular:
- Encrypted transmission exclusively over TLS 1.2 or higher
- Encryption at rest for the database and media content
- Passwords stored only as cryptographic hashes and unreadable to us
- Every access to your data is checked server-side against ownership; row-level security policies apply additionally at database level
- The coach's AI-driven data access runs exclusively through a read-only, tightly scoped database role
- Rate limiting, protection against automated attacks and logging of security-relevant events
- Separated access roles, two-factor protection for administrative access and logging of administrative actions
- Encrypted daily backups stored in the EU
18. Whether provision is required
Registration requires an email address; without it no account can exist. Providing health data is voluntary but is a precondition for the core features (calorie budget, suggestions, coach) — without it we cannot perform the contract. All other details are voluntary and omitting them has no disadvantages.
19. Cookies and comparable technologies
The mobile app uses no cookies. Stored on your device are only: your sign-in token (in protected system storage), your language setting, your consent decisions and an encrypted cache for offline use. Any access to these that is not strictly necessary to provide the service — in particular analytics and advertising — occurs only after your consent under § 25(1) TDDDG.
The web pages at yedeni.com, including these legal texts, use no cookies and no tracking.
20. Changes to this notice
We adapt this notice when our processing or the legal situation changes. The version in force is always available in the app and at the address above; every version carries a date. For substantial changes we inform you in advance by email or in the app and, where required, obtain your consent again.