Privacy Policy
This policy explains what data the Teller mobile app processes, why, and who else is involved. It covers the app only. This website itself sets no cookies and runs no analytics.
1. Who is responsible
Gregor Jan Rolka
[street and number]
[postcode and city]
Germany
E-mail: hello@heyteller.app
Teller is developed by an individual, not a company. There is no data protection officer, as the legal thresholds for appointing one are not met.
2. What Teller does
Teller is a diet tracker. You record what you eat, your weight, and some basic body data; the app calculates calorie and macronutrient targets from that and shows your progress. All of this data is entered by you, voluntarily.
You can use Teller with an anonymous account, which requires no e-mail address, no name and no other identifying information. Signing in with an e-mail address, Google or Apple is optional and exists so your data survives a lost or replaced phone.
3. What data is processed
| Data | Purpose | Legal basis |
|---|---|---|
| Account: a randomly generated user ID; if you sign in, your e-mail address, and with Google or Apple sign-in the identifier and e-mail address supplied by that provider (with Apple, this may be a relay address). | Creating your account, syncing your data across devices and restoring it. | Art. 6(1)(b) GDPR (performance of a contract). |
| Body and health data: sex, year of birth, height, weight over time, activity level, goal, calorie and macronutrient targets. | Calculating your energy requirement and your targets, and showing progress. | Art. 9(2)(a) GDPR: your explicit consent, given by entering the data. See section 4. |
| Food log: foods and dishes you save (name, brand, barcode, nutritional values, portions), your entries per day and meal, days you marked as untracked. | The core function of the app. | Art. 9(2)(a) GDPR: your explicit consent. |
| Time zone: the time zone of your device. | So that a "day" in the app matches your local calendar day. | Art. 6(1)(b) GDPR. |
| AI usage counters: your user ID, the date, which AI function was used and how often. | Enforcing a daily limit per user, so the service cannot be drained by automated abuse. | Art. 6(1)(f) GDPR: our legitimate interest in keeping the service available. |
| Connection data: IP address, time of request, app version, processed transiently by our hosting providers. | Delivering the service, security, defending against attacks. | Art. 6(1)(f) GDPR. |
Teller contains no advertising, no tracking pixels and no analytics SDKs. Your data is never sold, and never shared for advertising or marketing purposes.
4. Health data and your consent
Weight, body measurements and a food diary are data concerning health under Art. 9 GDPR, which enjoys special protection. Teller processes this data solely to provide the functions you asked for, and solely because you chose to enter it. By entering this data you give your explicit consent to it being processed for this purpose.
You may withdraw that consent at any time by deleting the data or your account in the app. Withdrawal does not affect the lawfulness of processing carried out before it.
5. Photos and AI analysis
Teller can read a nutrition label from a photo, and can estimate a meal from a photo, so you do not have to type the values yourself. When you use one of these functions, the photo is sent to our server and forwarded to Google's Gemini API for analysis. The returned nutritional values are shown to you.
- The photo is processed in memory and discarded immediately afterwards. It is not saved in our database, not stored in any file storage, and not linked to your account.
- Google processes the image on its own infrastructure, which may be located outside the European Union, including in the USA. The transfer is based on EU standard contractual clauses and Google's certification under the EU-US Data Privacy Framework.
- Under the paid tier of the Gemini API that Teller uses, Google states that content submitted through the API is not used to train or improve its models. Google retains it for a limited period (currently stated as up to 55 days) purely to detect misuse, then deletes it.
- Barcode scanning is different: the barcode is recognised on your device, so no image leaves your phone for that.
These functions are optional. If you never photograph a label or a meal, no image data is ever transmitted. Please avoid capturing other people or unrelated personal information in these photos.
6. Barcode lookups (Open Food Facts)
When you scan a barcode, your device queries the free product database Open Food Facts (operated by the non-profit association Open Food Facts, France). This request goes directly from your device to Open Food Facts, which means Open Food Facts receives your IP address and the scanned barcode. No account data, no name and no health data is transmitted.
Legal basis: Art. 6(1)(b) GDPR, as the lookup is the function you requested. The product data returned is then saved to your own food library so that the same product does not have to be looked up again.
7. Data on your device
Teller stores your login session and your settings locally on your device, so the app works offline and does not have to ask you to sign in every time. This is ordinary app storage, not a cookie, and it is removed when you uninstall the app.
8. App updates
Teller uses Expo's update service (Expo, Inc., USA) to deliver corrections without a full store release. When the app starts it checks for an update; Expo thereby receives your IP address, your device platform and the app version. No account data or health data is transmitted. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in distributing fixes quickly. The transfer is covered by standard contractual clauses.
9. Purchases and subscriptions
Teller is currently free of charge. Should paid subscriptions be introduced, payment is handled entirely by the Apple App Store or Google Play. We never receive your payment details, card number or billing address. We only ever learn whether an active subscription exists for your account. This policy will be updated before any such function goes live.
10. Processors
The following providers process data on our behalf, each under a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. (USA) | Database, account management, server functions | Servers in Frankfurt am Main, Germany (AWS eu-central-1). The provider is based in the USA, covered by standard contractual clauses. |
| Google Ireland Ltd. / Google LLC | Gemini API, analysis of label and meal photos (section 5) | May be processed outside the EU, including the USA. |
| Expo, Inc. (USA) | App updates (section 8) | USA |
| Cloudflare, Inc. (USA) | Hosting of this website only, not of app data | Global content network |
Apple and Google additionally act as independent controllers for the distribution of the app and, if you use them, for sign-in. Their own privacy policies apply to that.
11. How long data is kept, and deletion
Your data is kept for as long as your account exists. There is no automatic expiry, because a food diary is only useful with its history.
You can delete your account at any time in the app under Profile → Delete account. Deletion is immediate and permanent. Your account and all data attached to it (food log, foods, dishes, weights, settings, target history and usage counters) is removed together. There is no undo and no backup we could restore it from.
Further details, and what to do if you have already uninstalled the app, are on the account deletion page.
12. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time.
To exercise any of these, write to hello@heyteller.app. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence or place of work.
13. Children
Teller is not directed at children. If you are under 16, please only use the app with the consent of a parent or guardian.
14. Changes to this policy
If the app changes, this policy changes with it. The date at the top always shows the current version. For significant changes affecting your data, you will be informed in the app.
Datenschutzerklärung
Diese Erklärung beschreibt, welche Daten die Teller-App verarbeitet, wozu und wer sonst daran beteiligt ist. Sie betrifft die App. Diese Website selbst setzt keine Cookies und verwendet keine Analysedienste.
1. Verantwortlicher
Gregor Jan Rolka
[Straße und Hausnummer]
[PLZ und Ort]
Deutschland
E-Mail: hello@heyteller.app
Teller wird von einer Einzelperson entwickelt, nicht von einem Unternehmen. Ein Datenschutzbeauftragter ist nicht bestellt, da die gesetzlichen Voraussetzungen dafür nicht vorliegen.
2. Was Teller macht
Teller ist ein Ernährungstagebuch. Sie erfassen, was Sie essen, Ihr Gewicht und einige Körperdaten; daraus berechnet die App Kalorien- und Makroziele und zeigt Ihren Verlauf. Alle diese Daten geben Sie freiwillig selbst ein.
Sie können Teller mit einem anonymen Konto nutzen, das weder E-Mail-Adresse noch Namen noch sonstige identifizierende Angaben erfordert. Die Anmeldung per E-Mail, Google oder Apple ist optional und dient dazu, dass Ihre Daten einen Gerätewechsel oder Verlust überstehen.
3. Welche Daten verarbeitet werden
| Daten | Zweck | Rechtsgrundlage |
|---|---|---|
| Konto: eine zufällig erzeugte Nutzer-ID; bei Anmeldung Ihre E-Mail-Adresse, bei Google- oder Apple-Anmeldung die vom Anbieter übermittelte Kennung und E-Mail-Adresse (bei Apple ggf. eine Weiterleitungsadresse). | Anlegen des Kontos, Synchronisierung und Wiederherstellung Ihrer Daten. | Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung). |
| Körper- und Gesundheitsdaten: Geschlecht, Geburtsjahr, Körpergröße, Gewichtsverlauf, Aktivitätsniveau, Ziel, Kalorien- und Makroziele. | Berechnung Ihres Energiebedarfs und Ihrer Ziele sowie Anzeige des Verlaufs. | Art. 9 Abs. 2 lit. a DSGVO: Ihre ausdrückliche Einwilligung, erteilt durch die Eingabe. Siehe Abschnitt 4. |
| Ernährungstagebuch: gespeicherte Lebensmittel und Gerichte (Name, Marke, Barcode, Nährwerte, Portionen), Ihre Einträge pro Tag und Mahlzeit, als „nicht getrackt" markierte Tage. | Kernfunktion der App. | Art. 9 Abs. 2 lit. a DSGVO: Ihre ausdrückliche Einwilligung. |
| Zeitzone: die Zeitzone Ihres Geräts. | Damit ein „Tag" in der App Ihrem lokalen Kalendertag entspricht. | Art. 6 Abs. 1 lit. b DSGVO. |
| KI-Nutzungszähler: Nutzer-ID, Datum, verwendete Funktion und Anzahl der Aufrufe. | Durchsetzung eines Tageslimits pro Nutzer, damit der Dienst nicht durch automatisierten Missbrauch erschöpft wird. | Art. 6 Abs. 1 lit. f DSGVO: berechtigtes Interesse an der Verfügbarkeit. |
| Verbindungsdaten: IP-Adresse, Zeitpunkt der Anfrage, App-Version, von unseren Hostern nur vorübergehend verarbeitet. | Bereitstellung des Dienstes, Sicherheit, Abwehr von Angriffen. | Art. 6 Abs. 1 lit. f DSGVO. |
Teller enthält keine Werbung, keine Tracking-Pixel und keine Analyse-SDKs. Ihre Daten werden nicht verkauft und nicht zu Werbe- oder Marketingzwecken weitergegeben.
4. Gesundheitsdaten und Ihre Einwilligung
Gewicht, Körperdaten und ein Ernährungstagebuch sind Gesundheitsdaten im Sinne von Art. 9 DSGVO und besonders geschützt. Teller verarbeitet sie ausschließlich, um die von Ihnen gewünschten Funktionen bereitzustellen, und ausschließlich, weil Sie sie selbst eingegeben haben. Mit der Eingabe erteilen Sie Ihre ausdrückliche Einwilligung in diese Verarbeitung.
Sie können die Einwilligung jederzeit widerrufen, indem Sie die Daten oder Ihr Konto in der App löschen. Die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung bleibt unberührt.
5. Fotos und KI-Auswertung
Teller kann eine Nährwerttabelle vom Foto ablesen und eine Mahlzeit anhand eines Fotos schätzen, damit Sie die Werte nicht abtippen müssen. Nutzen Sie eine dieser Funktionen, wird das Foto an unseren Server und von dort an die Gemini-API von Google zur Auswertung übermittelt. Die zurückgelieferten Nährwerte werden Ihnen angezeigt.
- Das Foto wird im Arbeitsspeicher verarbeitet und danach sofort verworfen. Es wird nicht in unserer Datenbank gespeichert, nicht in einem Dateispeicher abgelegt und nicht mit Ihrem Konto verknüpft.
- Google verarbeitet das Bild auf eigener Infrastruktur, die sich außerhalb der EU, auch in den USA, befinden kann. Grundlage der Übermittlung sind EU-Standardvertragsklauseln sowie die Zertifizierung von Google unter dem EU-US Data Privacy Framework.
- Für die von Teller genutzte kostenpflichtige Stufe der Gemini-API gibt Google an, übermittelte Inhalte nicht zum Training oder zur Verbesserung der Modelle zu verwenden. Google speichert sie für einen begrenzten Zeitraum (derzeit angegeben mit bis zu 55 Tagen) allein zur Missbrauchserkennung und löscht sie danach.
- Das Scannen von Barcodes funktioniert anders: Der Barcode wird auf Ihrem Gerät erkannt, dabei verlässt kein Bild Ihr Telefon.
Diese Funktionen sind optional. Fotografieren Sie nie eine Tabelle oder eine Mahlzeit, werden auch keine Bilddaten übermittelt. Bitte achten Sie darauf, auf diesen Fotos keine anderen Personen oder fremde personenbezogene Angaben abzubilden.
6. Barcode-Abfragen (Open Food Facts)
Beim Scannen eines Barcodes fragt Ihr Gerät die freie Produktdatenbank Open Food Facts ab (Betreiberin: der gemeinnützige Verein Open Food Facts, Frankreich). Diese Anfrage geht direkt von Ihrem Gerät an Open Food Facts; dabei erhält Open Food Facts Ihre IP-Adresse und den gescannten Barcode. Kontodaten, Namen oder Gesundheitsdaten werden nicht übermittelt.
Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO, da die Abfrage die von Ihnen angeforderte Funktion darstellt. Die gefundenen Produktdaten werden anschließend in Ihrer eigenen Lebensmittel-Bibliothek gespeichert, damit dasselbe Produkt nicht erneut abgefragt werden muss.
7. Daten auf Ihrem Gerät
Teller speichert Ihre Anmeldesitzung und Ihre Einstellungen lokal auf dem Gerät, damit die App offline funktioniert und Sie sich nicht jedes Mal neu anmelden müssen. Das ist gewöhnlicher App-Speicher, kein Cookie, und wird bei der Deinstallation entfernt.
8. App-Aktualisierungen
Teller nutzt den Update-Dienst von Expo (Expo, Inc., USA), um Korrekturen ohne vollständige Store-Veröffentlichung auszuliefern. Beim Start prüft die App auf Aktualisierungen; Expo erhält dabei Ihre IP-Adresse, die Geräteplattform und die App-Version. Konto- oder Gesundheitsdaten werden nicht übermittelt. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO, also unser berechtigtes Interesse an der schnellen Verteilung von Fehlerbehebungen. Die Übermittlung ist durch Standardvertragsklauseln abgedeckt.
9. Käufe und Abonnements
Teller ist derzeit kostenlos. Sollten kostenpflichtige Abonnements eingeführt werden, wird die Zahlung vollständig über den Apple App Store bzw. Google Play abgewickelt. Wir erhalten zu keinem Zeitpunkt Ihre Zahlungsdaten, Kartennummer oder Rechnungsanschrift. Wir erfahren lediglich, ob für Ihr Konto ein aktives Abonnement besteht. Diese Erklärung wird aktualisiert, bevor eine solche Funktion live geht.
10. Auftragsverarbeiter
Folgende Anbieter verarbeiten Daten in unserem Auftrag, jeweils auf Grundlage eines Auftragsverarbeitungsvertrags:
| Anbieter | Zweck | Ort |
|---|---|---|
| Supabase, Inc. (USA) | Datenbank, Kontoverwaltung, Serverfunktionen | Server in Frankfurt am Main (AWS eu-central-1). Der Anbieter sitzt in den USA, abgedeckt durch Standardvertragsklauseln. |
| Google Ireland Ltd. / Google LLC | Gemini-API, Auswertung von Etiketten- und Mahlzeitenfotos (Abschnitt 5) | Verarbeitung auch außerhalb der EU, u. a. in den USA, möglich. |
| Expo, Inc. (USA) | App-Aktualisierungen (Abschnitt 8) | USA |
| Cloudflare, Inc. (USA) | Hosting ausschließlich dieser Website, keine App-Daten | Globales Netzwerk |
Apple und Google sind darüber hinaus eigenständig Verantwortliche für die Verbreitung der App und, sofern Sie sie nutzen, für die Anmeldung. Dafür gelten deren eigene Datenschutzerklärungen.
11. Speicherdauer und Löschung
Ihre Daten werden gespeichert, solange Ihr Konto besteht. Eine automatische Löschfrist gibt es nicht, denn ein Ernährungstagebuch ist nur mit seiner Historie sinnvoll.
Sie können Ihr Konto jederzeit in der App unter Profil → Konto löschen löschen. Die Löschung erfolgt sofort und endgültig. Ihr Konto und sämtliche daran hängenden Daten (Tagebuch, Lebensmittel, Gerichte, Gewichte, Einstellungen, Zielhistorie und Nutzungszähler) werden gemeinsam entfernt. Es gibt kein Rückgängig und keine Sicherung, aus der wir sie wiederherstellen könnten.
Einzelheiten und das Vorgehen nach bereits erfolgter Deinstallation finden Sie auf der Seite zur Kontolöschung.
12. Ihre Rechte
Nach der DSGVO haben Sie das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) sowie das Recht, einer auf berechtigten Interessen beruhenden Verarbeitung zu widersprechen (Art. 21). Soweit die Verarbeitung auf einer Einwilligung beruht, können Sie diese jederzeit widerrufen.
Wenden Sie sich dafür an hello@heyteller.app. Ihnen steht zudem ein Beschwerderecht bei einer Aufsichtsbehörde zu, insbesondere im Mitgliedstaat Ihres Aufenthaltsorts oder Arbeitsplatzes.
13. Kinder
Teller richtet sich nicht an Kinder. Wenn Sie unter 16 Jahre alt sind, nutzen Sie die App bitte nur mit Zustimmung eines Erziehungsberechtigten.
14. Änderungen dieser Erklärung
Ändert sich die App, ändert sich diese Erklärung mit. Das Datum oben nennt stets die aktuelle Fassung. Über wesentliche Änderungen, die Ihre Daten betreffen, informieren wir in der App.