Privacy notice

Version 2026-09-02 · Yedeni app. The German version is authoritative.

Deutsch

The short version Yedeni processes health data — your weight, body measurements, allergies and everything you eat. That data is yours. We do not sell it, we do not use it for advertising, and we share it only with the providers strictly required to run the app. The AI features send your input to OpenAI in the United States — that only happens with your explicit consent, which you can withdraw at any time.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Yedeni UG (haftungsbeschränkt)

Rodelbahn 12 a

85614 Kirchseeon

Deutschland

Managing director: Sepita Ansari Pir Seraei
Register court: Amtsgericht München, registration number: HRB 315154
Email for privacy enquiries: datenschutz@yedeni.com

2. Data protection officer

We are not currently required to appoint a data protection officer: fewer than 20 people are permanently engaged in the automated processing of personal data (§ 38(1) BDSG) and our core activity does not require large-scale regular and systematic monitoring within the meaning of Art. 37(1) GDPR. We have nonetheless carried out a data protection impact assessment under Art. 35 GDPR because we process health data. Please direct questions to datenschutz@yedeni.com.

3. What data we process

3.1 Account and sign-in data

3.2 Health data (special category)

Special category The following are health data within the meaning of Art. 9 GDPR. We process them solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give separately during onboarding — not bundled with the terms of service — and can withdraw at any time.

3.3 Content you create

3.4 Usage data

3.5 Technical data

ProcessingPurposeLegal basis
Creating and managing an accountProviding the service, sign-in, supportArt. 6(1)(b) GDPR (performance of a contract)
Processing health data (body, nutrition, allergies, activity)Calculating your calorie and nutrient needs, food diary, suggestionsArt. 9(2)(a) GDPR (explicit consent), additionally Art. 6(1)(b) GDPR
AI features (coach chat, photo estimation, recipe creation, transcription, translation)Delivering the feature you requestedArt. 6(1)(b) GDPR; where health data is involved additionally Art. 9(2)(a) GDPR, and Art. 49(1)(a) GDPR for the transfer to the United States
Publishing recipes, reviews and profileCommunity features you actively useArt. 6(1)(b) GDPR
Achievements, streaks and levelsMotivation and engagement, part of the serviceArt. 6(1)(b) GDPR
Push notificationsReminders, notices about new content, birthday greeting (for which we use the day and month of your date of birth)Art. 6(1)(a) GDPR (consent, withdrawable at any time)
Product analytics (PostHog)Understanding which features are used in order to improve the appArt. 6(1)(a) GDPR (consent), § 25(1) TDDDG
Personalised advertising (AdMob)Funding the free tierArt. 6(1)(a) GDPR (consent), § 25(1) TDDDG
Non-personalised advertisingFunding the free tier without profilingArt. 6(1)(f) GDPR (legitimate interest in funding the free offering)
Subscriptions and purchasesProviding paid features, purchase validationArt. 6(1)(b) GDPR; retention of receipts: Art. 6(1)(c) GDPR
Error and crash diagnostics (Sentry)Stability and security of the appArt. 6(1)(f) GDPR (legitimate interest in a functioning service)
Server logs, rate limiting, abuse detectionSecurity, defence against attacks and misuseArt. 6(1)(f) GDPR (legitimate interest in system security)
Quality assurance of AI answers (per-turn diagnostic record)Detecting and fixing faulty coach answers — in particular incorrect nutrition figures and diary entries that were silently not madeArt. 6(1)(f) GDPR (legitimate interest in a service that calculates correctly). The conversation content itself is stored only with your separate release — see section 6.5
Accounting for AI usage and enforcing usage allowancesAttributing model cost, honouring the free tier's allowances, abuse preventionArt. 6(1)(b) GDPR (providing the tiered service), additionally Art. 6(1)(f) GDPR (cost control and abuse prevention)
Measuring usage frequency (time of last app open, opens per day)Understanding how regularly the app is used — a basis for product improvement and for coarse contact groups in the customer-relations systemArt. 6(1)(f) GDPR (legitimate interest in engagement measurement and product improvement). No information stored on your device is accessed, so no consent under § 25 TDDDG is required
Moderation of user-generated contentProtecting other users, complying with the Digital Services ActArt. 6(1)(c) and (f) GDPR
Importing values from Apple Health / Health ConnectMore accurate calculation of your energy needsArt. 9(2)(a) GDPR (separate explicit consent, in addition to the operating-system permission)
System emails (account and subscription confirmations, payment problems, renewal announcements, security notices, invoices, support replies)Performing the contract and answering your requestsArt. 6(1)(b) GDPR (performance of a contract)
Information and marketing emails including performance measurement (opens, clicks)Informing you about news and offers, improving the contentArt. 6(1)(a) GDPR together with § 7(2) no. 3 UWG and § 25(1) TDDDG (consent)
Contact management and communication history (customer-relations system)Supporting users and people who contact us through a support request, a notice or as business partners; answering enquiries; keeping our communication traceable. Contact details we did not receive from you directly (for example from a partner list) are processed only to get in touch, and we inform you of their source and purpose at the latest at that point (Art. 14 GDPR)Art. 6(1)(b) GDPR, additionally (f) (legitimate interest in orderly support; for a plain record of contacts and correspondence no opposing interests prevail, since only contact and communication data is processed — health data is excluded)
Suppression list of undeliverable and unsubscribed addresses (digest only)Making sure an objection is honoured permanentlyArt. 6(1)(c) GDPR (fulfilling the obligation under Art. 21(3) GDPR), additionally (f)

5. Your consents and how to withdraw them

We obtain every consent separately and record which version of which document you accepted and when (Art. 7(1) GDPR). Your consents to information and promotional emails, notifications and product analytics are listed in the app under "Settings" > "Other" > "My consents", where each can be withdrawn individually; the consent to personalised advertising is withdrawn under "Settings" > "Other" > "Ad settings" (the entry appears once the consent form has been shown). The consent to processing your health data is likewise withdrawn under "My consents" — because the app cannot work without that data, your account is deleted in the process (see table) — or by writing to us (the contact details are in section 2).

ConsentCoversEffect of withdrawal
Health dataProcessing of body, nutrition and activity dataThe core features can no longer be provided, so withdrawal has the effect of terminating the contract. We tell you this before you withdraw, and delete your data afterwards.
Product analyticsPostHogNo further analytics data is collected. The app works unchanged.
Personalised advertisingAdMobYou still see ads, but without personalisation. The app works unchanged.
Push notificationsReminders, notices and greetingsNo further notifications are sent. The app works unchanged.
Apple Health / Health ConnectImporting activity and weight valuesNo further values are imported. Values already imported can be deleted in the diary.
Information and marketing emailsNews, tips and offers by email, including performance measurement (opens and clicks)You receive no further marketing emails. System emails about your account continue. Withdrawal works without signing in, via the link in every email, and takes effect immediately.

The lawfulness of processing carried out before withdrawal remains unaffected.

6. Artificial intelligence

Yedeni's central features rely on large language models from OpenAI. Because health data leaves the EU in the process, we set out exactly what happens.

6.1 What is transmitted

6.2 What is not transmitted

6.3 Training and retention

Data submitted through the API is contractually excluded from model training. OpenAI retains requests only for a limited period for abuse detection.

6.4 Labelling and limits

AI-generated content is labelled as such in the app. Nutrition values are matched against our food database wherever possible rather than invented by the model. Even so, estimates — particularly from photos — can deviate substantially from reality. Always verify figures that matter to your health.

6.5 Quality assurance of coach answers

An AI coach that miscalculates nutrition values, or silently fails to make an entry, is more dangerous than one that does not answer at all. So that such faults surface, we record a technical diagnostic trace for every coach turn.

Independently of this, we as the operator can view your coach conversation — see section 12.1. The diagnostic trace does not change that; it exists so that a fault surfaces without anyone having to read along.

7. Recipients of your data

We use the following providers. We have concluded data processing agreements under Art. 28 GDPR with all of them. An always-current version of this list is available at Sub-processors.

ProviderPurposeData receivedLocationBasis
Supabase, Inc.Registration and sign-in (Auth), primary PostgreSQL databaseEmail address, password hash, sign-in timestamps, all content and health data stored in the appEU (Frankfurt am Main, Germany)Processed inside the EU/EEA — no third-country transfer The provider is US-based; data is stored exclusively in the EU region. Standard contractual clauses additionally cover support access from the US.
Vercel Inc.Operating the backend API (serverless functions) and serving these legal pagesIP address, timestamp, requested endpoints and the full contents of each request while it is processedEU (Frankfurt am Main, region fra1)Processed inside the EU/EEA — no third-country transfer The execution region is pinned to Frankfurt. The provider is US-based; standard contractual clauses cover administrative access.
Microsoft Ireland Operations Ltd. (Microsoft Azure)Storing media (Blob Storage), delivery via the content-delivery network (Front Door, cdn.yedeni.com), media processing (Azure Functions: audio and frame extraction, video transcoding)Uploaded photos and videos, profile pictures, voice recordings; CDN requests additionally involve IP address and timestampEU (West Europe region, Netherlands)Processed inside the EU/EEA — no third-country transfer
OpenAI Ireland Ltd. / OpenAI, L.L.C.All AI features: coach chat, photo and label analysis, recipe generation and import, nutrition estimation, speech transcription, translation, semantic search (embeddings) and content moderationThe contents of each request: chat messages, meal and label photos, voice recordings, recipe text and the slice of nutrition goals, daily balance, allergies and preferences needed for the answer — including health data. No account or user identifier is transmitted.United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses Data submitted through the API is contractually excluded from model training. This is the only processor handling health data outside the EU — the transfer therefore relies on your explicit consent under Art. 9(2)(a) in conjunction with Art. 49(1)(a) GDPR.
Upstash, Inc.Technical cache: request rate limiting, usage allowances for AI features (daily or weekly), short-lived cachingPseudonymous identifiers (user ID or IP address) and counters; no content or health dataEUStandard contractual clauses (Art. 46(2)(c) GDPR) The provider is US-based; standard contractual clauses cover access from there.
Functional Software, Inc. (Sentry)Crash and error diagnostics, performance regression detectionError messages, stack traces, app and device version, pseudonymous user ID. Email addresses, passwords, tokens and comparable values are stripped automatically before transmission.EU (German region, ingest.de.sentry.io)Processed inside the EU/EEA — no third-country transfer
PostHog Ltd.Product analytics and app improvementPseudonymous device/user identifier, screens viewed, actions triggered, device class, OS and app version. No screen recordings, no health data, no plain-text content.EU (Frankfurt am Main, eu.i.posthog.com)Processed inside the EU/EEA — no third-country transfer
RevenueCat, Inc.Subscription management: purchase validation, term and cancellation status, purchase restorationPseudonymous user ID, app-store purchase receipts, product and term data, country. No payment details — those stay with Apple and Google.United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses
Google Ireland Ltd. (AdMob, User Messaging Platform)Serving ads on the free tier and obtaining the required consentDevice advertising ID, IP address, coarse location (country), ad interactions, consent statusEU and United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses Personalised ads only after explicit consent. Without consent only non-personalised ads are served. Health data is never used for or transmitted for advertising.
Google Ireland Ltd. (Anmeldung mit Google)Sign-in via a Google account, if you choose that optionEmail address, name, Google account identifierEU and United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses
Apple Distribution International Ltd.Sign in with Apple, App Store purchases, push delivery (APNs), access to Apple Health after you allow itApple account identifier, forwarded or anonymised email address where applicable, purchase receipts, push tokenIreland (EU)Processed inside the EU/EEA — no third-country transfer Apple Health data is read on your device only and forwarded to our backend as aggregated daily values — we send no health data back to Apple.
Google Ireland Ltd. (Health Connect, Google Play)Access to Health Connect after you allow it, Google Play purchases, push delivery (FCM)Google account identifier, purchase receipts, push token. Health Connect data is read locally on the device only.EU and United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses
650 Industries, Inc. (Expo / EAS)Sending push notifications and delivering app updatesDevice push token, notification content, app and runtime version when fetching updatesUnited StatesStandard contractual clauses (Art. 46(2)(c) GDPR) Notification texts contain reminders and may carry a meal suggestion with portion and calorie figure; your weight, goals and diary values are not transmitted. Delivery runs through Expo and the device vendor's service (Apple or Google).
Apify Technologies s.r.o.Technically retrieving publicly available Instagram posts from partners who expressly permitted us to use their contentPublic post content and the partner's handle. No Yedeni user data is transmitted.Czech Republic (EU)Processed inside the EU/EEA — no third-country transfer
Secret Industries Pty Ltd (FatSecret Platform API)Supplementary food and barcode database when a product is found neither locally nor in Open Food FactsOnly the search term or barcode number. No user identifier, no health data.AustraliaNo personal data transmitted
GitHub, Inc.Running the nightly database backup (the backups themselves are stored in Azure's EU storage) and triggering internal load tests (control parameters only, no personal data)The backup stream is processed during execution and not retained there.United StatesAdequacy decision (Art. 45 GDPR, EU-U.S. Data Privacy Framework) plus standard contractual clauses
Brevo SASDelivery of system and information emails, plus performance measurementEmail address, salutation/name, subject and body of the message, delivery and open events, IP address when images are loadedFrance and Germany (EU)Processed inside the EU/EEA — no third-country transfer Health data is never processed by marketing email — this is enforced in code, not merely intended. The provider holds no contact list; it receives only the single recipient and the finished message per send.

Beyond this we disclose personal data only where legally required (for example to law-enforcement authorities on a court order) or where you have expressly consented. We do not sell personal data.

8. Apple Health and Health Connect

If you explicitly allow it, Yedeni reads values from Apple Health (iOS) or Health Connect (Android) in order to determine your actual energy expenditure more accurately.

By default Yedeni writes no data back to Apple Health. Should that option be offered in future, it will happen only at your separate instruction.

9. Advertising

On the free tier we show ads via Google AdMob. Before the first ad we ask, through Google's consent form (User Messaging Platform), whether you want personalised advertising. On iOS we additionally ask via the system "App Tracking Transparency" dialog before your device advertising ID is used.

10. Email communication

We distinguish two kinds of email. They run over separate sender addresses so that one cannot affect the other.

10.1 System emails

Confirmations about your account and subscription (registration, start and end of a trial or subscription), notices about payment problems, announcements of an automatic renewal, security notices, invoices and replies to your support requests. These are part of the contract (Art. 6(1)(b) GDPR); as long as the contract is running you cannot object to them. They contain no open tracking — that is enforced in code, not merely configured.

10.2 Information and marketing emails

News, tips and offers. Some of these emails are triggered by how you use the app — for example that you published a recipe, that an invitation was redeemed, or that you have not opened the app for a while. Values from your nutrition diary are not used for this. The legal basis is your consent (Art. 6(1)(a) GDPR together with § 7(2) no. 3 UWG). Every such email carries an unsubscribe link; one click is enough, no sign-in is needed, and it takes effect immediately. We also set the `List-Unsubscribe` headers so that your email client can show its own unsubscribe button.

10.2a Confirming your consent (double opt-in)

After you have given consent in the app, we send you a system email containing a confirmation link. Only once you click it do we send information and marketing emails; without confirmation you receive only the emails about your account. The link is valid for seven days. To evidence your consent (Art. 7(1) GDPR) we store the time of that click, your IP address, the identifier of your browser or email client, and a checksum of the link we sent. We process these details solely as evidence, never for advertising; the legal basis is Art. 6(1)(c) GDPR together with our accountability obligation under Art. 7(1) GDPR. The same applies when you change your selection via the preference centre in one of our emails or unsubscribe via the unsubscribe link.

10.3 Performance measurement

For information and marketing emails we measure whether the message was opened and whether a link was clicked. The email contains a small image whose retrieval tells us the time and IP address. Because that retrieval accesses your device, it is covered by your consent (§ 25(1) TDDDG) — the consent text names performance measurement explicitly. We use it to see which topics are read and to retire addresses that are permanently unreachable. If you do not want this, turn off automatic image loading in your email client, or unsubscribe.

10.4 No health data by marketing email

Commitment Information and marketing emails process no health data. Neither your weight nor your calorie target, your diet, your meals or your activity values appear in such emails or in the logs of the sending provider. This is enforced technically: a marketing template that uses such a value can be neither saved nor sent. Personal nutrition guidance reaches you only inside the app or as a push notification. A push notification may contain a meal suggestion with a calorie figure and is delivered through Expo and your device vendor's service (section 7); it never contains your weight, goals or diary values.

10.5 Suppression list

If your mailbox permanently reports an address as undeliverable, if you mark a message as spam, or if you unsubscribe, we record that in a suppression list. What is stored there is only a cryptographic digest of your address (SHA-256), not the address itself. These entries survive the deletion of your account — otherwise the next send would write to you again, which is exactly what you did not want. The digest cannot be turned back into your address; it can only answer whether an address entered again is blocked.

10.6 Sending provider

Sending runs through Brevo SAS (France), processed in France and Germany, so with no third-country transfer. Brevo holds no contact list from us; per message it receives only the single recipient and the finished text. Details in the list of sub-processors.

11. Product analytics

With your consent we record via PostHog (Frankfurt data centre) which features are used. Collected are a pseudonymous identifier, screens viewed, actions triggered and device and version details. The contents of your meals, health values and chat messages are not collected. Without consent the analytics module is not started. You can withdraw consent at any time in settings; data already collected is deleted along with your account.

12. Publicly visible content

Please note which details become visible to others once you use the community features:

ContentVisibility
Username, display name, profile picture, profile textPublic to all users
Recipes you publish, including photos and videosPublic, including via shared links outside the app
Reviews and commentsPublic, with your display name
Collections set to publicPublic; collections set to private stay private
Follow relationships and feed activityVisible to your followers
Shared shopping listsAccessible to anyone with the link
Meals, weight, body data, goals, coach chatNever public and not visible to other users — for access by us as the operator see section 12.1

12.1 Access by us as the operator

“Not public” does not mean “readable by no one”. We therefore state explicitly when we ourselves can look at your content — including your conversation with the coach.

For evaluations that are not tied to an individual case we use the content-free diagnostic trace described in section 6.5. If you wish to object to such access, contact datenschutz@yedeni.com; we will then examine whether the purpose can be achieved without your content.

13. Retention

DataRetention
Account, profile and health dataUntil the account is deleted or consent is withdrawn
Meals, weight and other diary entriesUntil the account is deleted
Recipes and media you createdUntil you delete them or the account is deleted
Coach chat history180 days, then deleted automatically
Recipe view history30 days, then deleted automatically
Server logs containing IP addressesat most 30 days
Failed sign-in attempts30 days, then deleted automatically
Error and crash reports90 days
Daily values imported from Apple Health or Health Connect180 days, then deleted automatically; sooner if you delete them in the diary
Coach insights about your history120 days
Feedback on suggestions (accepted, rejected, cooked)12 months
Deleted meals (recycle bin)30 days, then removed permanently
Device data and push tokensDeactivated 90 days after the device was last used, deleted after 180 days
Log of administrative access (section 12.1)12 months — the basis of your right to information about access
Consent recordsUntil the account is deleted — the Art. 7(1) GDPR record is removed in full together with the account and is not kept beyond it
Diagnostic trace of coach turns (without conversation content)30 days, then deleted automatically
Released individual cases from quality review — the conversation content90 days, after which the wording is removed automatically. Sooner if you withdraw the release: a case not yet worked on is deleted entirely, one already worked on loses the wording. At the latest when the account is deleted.
Released individual cases — the lesson drawn from them (without conversation content)400 days. What remains then describes our product — what the coach should have done — no longer you
AI usage and cost recordsUp to 180 days as cost evidence; the link to you is removed immediately when the account is deleted. A cost archive without any personal reference is kept longer
Daily app-open counters13 months, then deleted automatically
Reports and moderation decisionsUp to 6 months after the case is closed. For notices under the Digital Services Act, the notifier's name and email address are removed 6 months after the decision; the decision and its reasons are kept as evidence
Invoices and accounting records10 years (§ 257 HGB, § 147 AO)
Analytics dataUntil consent is withdrawn, at the latest until the account is deleted
Email delivery logs (recipient, subject, delivery and open events)26 months, then deleted automatically
Suppression list (digest of the address only, not the address)Indefinite — deleting a suppression would mean writing to that person again
Contact details and communication history in the customer-relations systemUntil the account is deleted or you object; consent evidence as above. Contacts without an app account: three years after the last contact, then deleted automatically

After you delete your account we irreversibly remove all personal data within 30 days, unless a statutory retention obligation applies. Recipes you published that others have added to their plans or collections are retained without any link to you; your name is removed. If you want that content deleted as well, please delete it before deleting your account or contact datenschutz@yedeni.com.

14. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR) at any time. Address requests to datenschutz@yedeni.com; we respond within one month.

Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 18

91522 Ansbach

Deutschland

https://www.lda.bayern.de · poststelle@lda.bayern.de

You may also contact the supervisory authority where you habitually reside.

15. Automated decisions and profiling

Yedeni derives personalised nutrition suggestions from your goals, history and preferences, and personalises the content feed. That constitutes profiling within the meaning of Art. 4(4) GDPR.

No decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Art. 22(1) GDPR takes place: all suggestions are non-binding recommendations, you decide freely in every case, and no legal consequences arise. The suggestions are the core of the service and cannot be switched off; alongside the personalised “For you” feed, the non-personalised recipe search is available to you at any time.

We use automated checks to moderate user-generated content. If such a check results in content removal or account suspension, we tell you the reasons and you can have the decision reviewed by a human.

16. Children and young people

Yedeni is intended for people aged 16 and over. We check the minimum age when recording your date of birth; younger people cannot use the app. If we learn that data of a younger person is being processed, we delete the account without delay. Parents and guardians may contact datenschutz@yedeni.com.

17. Data security

We apply technical and organisational measures under Art. 32 GDPR, in particular:

18. Whether provision is required

Registration requires an email address; without it no account can exist. Providing health data is voluntary but is a precondition for the core features (calorie budget, suggestions, coach) — without it we cannot perform the contract. All other details are voluntary and omitting them has no disadvantages.

19. Cookies and comparable technologies

The mobile app uses no cookies. Stored on your device are only: your sign-in token (in protected system storage), your language setting, your consent decisions and an encrypted cache for offline use. Any access to these that is not strictly necessary to provide the service — in particular analytics and advertising — occurs only after your consent under § 25(1) TDDDG.

The web pages at yedeni.com, including these legal texts, use no cookies and no tracking.

20. Changes to this notice

We adapt this notice when our processing or the legal situation changes. The version in force is always available in the app and at the address above; every version carries a date. For substantial changes we inform you in advance by email or in the app and, where required, obtain your consent again.