1 Controller
Jörg Kornbrodt
Hans-Holbein-Str. 2
50999 Cologne, Germany
Email: jkornbrodt@gmail.com
A data protection officer has not been appointed, as the conditions of Art. 37 GDPR / § 38 BDSG do not apply.
2 Core principle & data processed
MoonBowl is designed as a “local-first” app. Your entries, along with any health data read from Apple Health, are stored primarily on your device. If you enable iCloud synchronization in the App, your app entries are additionally synced with your private iCloud so they stay up to date across your devices and are backed up (see 4.5). We do not operate a central user database, do not transfer this data to us, and have no access to your iCloud data. Transfers to service providers are described in Section 4.
The App processes the following categories of data:
- Profile data: age/year of birth, sex, height, target and starting weight, activity level.
- Nutrition: logged meals, calories and nutritional values, water intake.
- Body & health data: weight, fasting logs and — where permitted — values read from Apple Health (see Section 3).
- Cycle data: information about the menstrual cycle, where entered by you or read from Apple Health.
- Technical data: an app-specific device identifier and, when you use the online features, technical connection data (e.g. IP address, see 4.2/4.3).
Health and cycle data are special categories of personal data (Art. 9 GDPR) and are processed only with your explicit consent.
3 Apple Health (HealthKit)
If you explicitly allow it, the App exchanges data with Apple Health. You control each individual category in your iOS settings.
Read from Apple Health (if permitted):
- Sleep
- Heart rate variability (HRV)
- Resting heart rate
- Activity / steps
- Weight
- Menstrual cycle
Written back to Apple Health (if permitted):
- Weight
- Cycle data
- Nutrition/water values (where logged by you)
Purpose: calculating your personal recommendations and insights.
Storage location: locally on your device or in Apple Health; entries stored in the App (e.g. weight, cycle) are synced to your private iCloud if iCloud synchronization is enabled (see 4.5).
Legal basis: explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR); revocable at any time in your iOS settings.
Health data is not used for advertising and is not shared with third parties.
4 Data shared with service providers
4.1 AI-powered food analysis (photo, text, voice)
If you use the AI analysis, the relevant content (image or text) is transmitted via a proxy server operated by us to an AI service:
- Cloudflare, Inc. (USA) – operates our proxy server, which receives and forwards the request. A technical device identifier (see 4.2) is processed; images are not stored there permanently.
- Anthropic PBC (USA) – analyzes the image/text and returns the estimated nutritional values. The data is processed solely for the analysis and, according to the provider, is not used to train the AI models.
Purpose: recognizing foods and estimating nutritional values.
Legal basis: consent (Art. 6(1)(a); where health-related, additionally Art. 9(2)(a) GDPR).
Note: Please do not upload photos in which people or other personal content are identifiable.
Accuracy: AI estimates can be inaccurate or incomplete. Please check the results for plausibility before relying on them.
4.2 Technical device identifier (abuse protection)
With each AI request, an app-specific device identifier (identifierForVendor) is transmitted to the proxy and stored briefly in order to enforce usage limits.
Purpose: protection against abuse, limiting requests.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Retention period: automatically deleted, as a rule within 7 days; the identifier can be reset in your iOS settings.
4.3 Food database (Open Food Facts)
For search and barcode scanning, search terms or the barcode are forwarded via our proxy server (Cloudflare, see 4.1) to Open Food Facts (non-profit, France/EU). In doing so, the proxy processes technical connection data (e.g. IP address) for forwarding and caching; images are not transmitted.
Purpose: retrieving product and nutritional information.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Product data is provided under the Open Database License (ODbL).
4.3a Community food database
When you enter a barcode-scanned, still-unknown product yourself, you can (enabled by default, switchable off anytime in the app settings) contribute the barcode, product name and nutrition values per 100 g anonymously to our shared community database. No personal data whatsoever is transmitted – no device identifier, no location, nothing that links back to you. Contributions are plausibility-checked on the server and used solely to auto-fill the same barcode for other users.
Purpose: collaborative improvement of product/nutrition data.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR); as contributions are anonymous and carry no personal reference, there is no processing of personal data in the narrower sense.
Storage location: our database at Cloudflare (EU region).
4.4 Purchases and subscriptions (Apple)
Purchases/subscriptions are handled exclusively via the Apple App Store / StoreKit system. Apple is independently responsible for this. We receive no payment data, only the information that a valid entitlement exists. Apple’s privacy policy applies additionally.
4.5 iCloud synchronization (Apple)
You can enable synchronization of your entries via iCloud in the App. If it is switched on and you are signed in to iCloud on your device, your entries stored in the App — including health-related entries such as weight, sleep and cycle — are synchronized via Apple iCloud (CloudKit) in your private iCloud database. Synchronization is disabled by default and starts only after you explicitly enable it in the App.
Purpose: cross-device synchronization and backup of your data.
Storage location: your private iCloud database at Apple. We have no access to this content; we only receive anonymous schema and usage statistics.
Legal basis: explicit consent (Art. 6(1)(a); where health-related, additionally Art. 9(2)(a) GDPR) — given by enabling iCloud synchronization in the App.
Control: can be disabled at any time in the App; additionally in your iOS settings under “Apple ID › iCloud”.
Apple is responsible for the iCloud infrastructure; Apple’s privacy policy applies additionally. Processing may also take place in the USA (see Section 5). Whether the content is end-to-end encrypted depends on your iCloud settings (Apple’s “Advanced Data Protection”).
5 Transfers to third countries (USA)
Cloudflare, Anthropic and Apple (including iCloud synchronization) process data in the USA, among other locations. Transfers are made on the basis of appropriate safeguards, in particular the Standard Contractual Clauses (Art. 46 GDPR) or — where certified — the EU-US Data Privacy Framework.
Data processing agreements (Art. 28 GDPR) are in place with Cloudflare and Anthropic. Apple processes purchases/subscriptions and iCloud data as an independent controller; the Apple Developer Program License Agreement and Apple’s privacy policy apply.
Switzerland: For users in Switzerland, the revised Federal Act on Data Protection (revFADP) applies additionally. Transfers to the USA rely, where relevant, on the Swiss-U.S. Data Privacy Framework or the Standard Contractual Clauses with Swiss adaptations. The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
6 Automated recommendations
MoonBowl automatically calculates personal recommendations from your entries and — where permitted — Apple Health data. These serve solely as general guidance, have no legal or similarly significant effect, and do not constitute an automated decision within the meaning of Art. 22 GDPR. No profiling for advertising or scoring purposes takes place.
7 Data security
We take appropriate technical and organizational measures to protect your data. All of the App’s online connections — in particular to the AI analysis and the food database — use encrypted transport (TLS/HTTPS) exclusively. Because most data never leaves the device, the attack surface is deliberately kept small.
8 No advertising, no tracking
MoonBowl contains no advertising and no tracking for advertising purposes. No personal data is sold or shared for advertising or profiling purposes.
9 Retention period
- Local data remains stored until you delete it in the App or by deleting the App.
- Data synchronized to iCloud remains there until you delete it in the App (deletions are propagated to your devices and to iCloud) or disable iCloud synchronization for the App (4.5).
- Content transmitted for AI analysis is used only for the duration of processing and is not stored permanently (4.1).
- The technical device identifier is stored briefly (4.2).
10 Your rights
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent at any time (Art. 7(3) GDPR), e.g. via the iOS permissions or by deleting the App. Because we process most data exclusively locally and cannot attribute it to you, you can view and delete it yourself at any time in the App / on your device.
Contact: jkornbrodt@gmail.com. You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf. You may, however, contact any supervisory authority; in Switzerland, the FDPIC.
11 Children
MoonBowl is not directed at children under 16. We do not knowingly process data of children without the consent of a parent or guardian. If we become aware of such data, we delete it without undue delay.
12 No medical advice
The nutritional values and recommendations shown are estimates for general guidance and do not constitute medical, dietary or diagnostic advice. They do not replace consultation with physicians or nutrition professionals. Please seek professional advice before making major dietary changes — in particular if you have pre-existing conditions, take medication, are pregnant or breastfeeding. Since recommendations and AI estimates can be inaccurate, always check them for plausibility before acting on them.
13 Additional information for users in the USA
The following additional information applies to users residing in the United States. Our core principle is unchanged: most data stays locally on your device, we run no advertising and no tracking, and we do not sell data.
13.1 Breach notification (FTC Health Breach Notification Rule)
MoonBowl processes health data. In the event of unauthorized access to, or unauthorized disclosure of, unsecured identifiable health data, we will notify affected users and — where legally required — the U.S. Federal Trade Commission (FTC), in accordance with the FTC Health Breach Notification Rule. A “breach” here also includes an unauthorized sharing of data with third parties, not only a technical attack.
13.2 California (CCPA/CPRA)
We do not sell personal information and do not share it for targeted advertising (“sale”/“sharing” within the meaning of the CCPA). This has also been the case over the past twelve months.
Categories collected: identifiers (device identifier), health and nutrition data, technical connection data.
Sensitive data: health and cycle data qualify as “sensitive personal information”. We use it solely to provide the App.
As a California consumer, you have the right to know, delete and correct, the right to limit the use of sensitive data, and the right not to be discriminated against for exercising these rights. A “Do Not Sell or Share My Personal Information” opt-out is not required, as we do not sell or share data. To exercise these rights: jkornbrodt@gmail.com.
13.3 Washington & similar laws (My Health My Data Act)
For users in Washington and states with comparable laws (e.g. Nevada), we treat health data — including cycle and reproductive data — as protected “consumer health data”. We collect and process it only with your consent, do not sell it, and do not share it without separate authorization. You can withdraw your consent at any time and request deletion.
14 Changes to this privacy policy
We reserve the right to amend this privacy policy if the App, the underlying services or the legal framework change. The version published here and linked within the App is always the authoritative one. The “Last updated” date above indicates when the current version was last changed.
We will inform you in an appropriate manner about material changes that affect the processing of your data or that require renewed consent — for example through a notice in the App or the next time you use the relevant feature. Please review this policy from time to time to stay informed of the current version.