1. Controller
Burzinski & Jaenisch GbR, Burgunder Str. 1, 14197 Berlin, Germany, is the controller responsible for processing personal data in the Trayly iOS app, the website, and the related API.
Contact for privacy requests: info@bejanic.de. A data protection officer has not been appointed unless and until a statutory appointment obligation applies.
2. Data We Process
- Account and authentication data, especially user ID, login status, email address, and technical authentication attributes from Clerk.
- Profile and health goal data, especially gender, date of birth, height, weight, activity level, goal, pace, and calculated calorie and macro targets.
- Meal, ingredient, favorite, and weight data, especially timestamps, meal type, title, summary, nutrition values, portions, barcodes, product details, images, and AI confidence values.
- Chat data, especially chat sessions, messages, attachment names, selected date, image attachments, app language, and location or activity context if you use it in chat.
- Photos, label images, barcodes, and notes where you use analysis, scanning, camera, or chat features.
- Restaurant and location data, especially coordinates, search radius, region, restaurant selection, and menu selection when you use location or restaurant features.
- Apple Health data if you grant permission: steps, active calories, resting calories, and body weight; also body weight and nutrition values written by Trayly, such as calories, protein, carbohydrates, and fat. Activity data is only attached to chat when your chat question relates to steps, movement, or calories burned.
- Push and device data, especially APNs tokens, platform, environment, time zone, language, local reminder settings, and notification settings.
- Purchase and subscription data processed for Trayly Pro through Apple and RevenueCat, especially customer ID, entitlement status, product ID, term information, and restore status.
- Technical operational data such as IP address, timestamp, request ID, path, status code, user agent, rate-limit events, audit logs, and AI usage metrics.
- Product analytics and telemetry data such as app version, build, platform, environment, anonymous or account-related user ID, app lifecycle events, selected main areas, selected logging modes, onboarding and paywall status, permission status, feature usage, analysis, chat, restaurant, and meal logging events, and technical API usage events without intentionally transmitting meal, photo, chat text, or health content.
3. Purposes and Legal Bases
- Providing the account, app, API, synchronization, meal tracking, weight progress, and restaurant features, Art. 6(1)(b) GDPR.
- Analyzing texts, photos, labels, barcodes, and chat messages to determine nutrition values and generate assistant responses, Art. 6(1)(b) GDPR and, where health data is involved, Art. 9(2)(a) GDPR based on your explicit consent.
- HealthKit import and export of activity, weight, and nutrition values, Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
- Location-based restaurant search, Art. 6(1)(a) GDPR if you allow location access.
- Push notifications and reminders, Art. 6(1)(a) GDPR.
- Subscription management, payment preparation, purchase restoration, and abuse protection, Art. 6(1)(b) and (f) GDPR.
- Security, error analysis, abuse prevention, rate limiting, auditing, and system stability, Art. 6(1)(f) GDPR.
- Product analytics, feature improvement, and technical telemetry for the app and API, Art. 6(1)(f) GDPR; we do not use this data for advertising or data trading.
- Compliance with legal obligations, especially tax, commercial, and consumer protection obligations, Art. 6(1)(c) GDPR.
4. Website
The website provides information, legal pages, and static app content. We currently do not use our own analytics or marketing cookies on the website.
When you access the website, the hosting provider and technical protection systems may process access data such as IP address, browser, timestamp, and requested URL to deliver the website, secure it, and investigate errors.
5. Health Data and Apple Health
Trayly is not a medical app. Information about calories, macros, weight, activity, and scores is intended for fitness and nutrition purposes and does not replace medical, therapeutic, or nutritional advice.
Apple Health data is read or written only after you grant permission. The app currently reads steps, active calories, resting calories, and body weight to show progress and daily values. Activity data is sent to the coach only for relevant chat questions about steps, movement, or calories burned. The app can write weight entries you record and daily values for calories, protein, carbohydrates, and fat to Apple Health.
HealthKit data written by Trayly is cleaned up as far as reasonably possible before writing the same day again to avoid duplicates. HealthKit data is not used for advertising or data trading.
You can revoke HealthKit permissions at any time in iOS settings. Without this permission, app areas that require HealthKit data may not work or may work only in a limited way.
6. AI Analyses and Photos
When you use AI features, your inputs, photos, label images, barcodes, portion details, chat history, and relevant context data are transmitted to our API and configured AI service providers to generate nutrition values, ingredients, summaries, translations, restaurant suggestions, and chat responses.
For AI calls, we use an AI gateway and connected model providers. Operational AI usage logs contain technical metadata such as feature, model, duration, token counts, status, and errors; raw inputs and raw outputs are not intentionally stored in these AI usage logs.
AI results may be incomplete or incorrect. Please review results before using them for health, training, or nutrition decisions.
7. Recipients and Service Providers
- Clerk: authentication, session management, user identities, and account deletion.
- Vercel: hosting and delivery of the website and related technical logs.
- Cloudflare: hosting of the Worker API, D1 database, R2 image storage, KV cache, rate limiting, routing, security, and technical logs.
- Vercel AI Gateway and connected model providers, currently especially Google (Gemini models): processing of text, photo, label, and chat data for analysis and response generation.
- PostHog: product analytics and technical telemetry for app and API usage events.
- Google Places or OpenStreetMap/Overpass: nearby restaurant, place, rating, photo, and map information.
- Open Food Facts: barcode and product database for food information.
- Apple, App Store, APNs, and HealthKit: app distribution, in-app purchases, payment processing, push delivery, platform services, and HealthKit permissions.
- RevenueCat: management of subscriptions, entitlements, offers, purchase status, and purchase restoration.
- Public restaurant, map, logo, and image sources, for example Wikimedia or restaurant CDNs, when such content is loaded in the app or website.
8. International Transfers
Some service providers may process data outside the European Economic Area, especially in the United States. Where required, we use appropriate safeguards such as EU standard contractual clauses, adequacy decisions, data processing agreements, and additional protective measures.
9. Retention
- We generally store account data, profile data, meals, weight, favorites, chat sessions, analysis results, and uploads for as long as your account exists or the data is required for the selected feature.
- We store push tokens and notification settings for as long as push features are active or the token is needed for delivery and abuse protection.
- Restaurant, barcode, and public menu information may remain stored as product data independently of your account.
- We store technical logs, audit logs, rate-limit data, AI usage metrics, and security events for as long as required for operations, traceability, abuse prevention, and legal obligations.
- The following regular deletion periods apply to operational data: AI usage logs after 14 days, raw AI data (raw inputs and raw outputs) after 14 days, processing jobs after 30 days, chat sessions after 90 days, delivery logs for push notifications after 14 days, delivery logs for emails after 180 days, audit logs after 365 days, and unreferenced uploads after 365 days.
- We store product analytics and telemetry data only for as long as required for product improvement, error analysis, security, and abuse prevention; users can disable product analytics in the app settings.
- Statutory retention obligations remain unaffected. Once the purpose no longer applies, we delete or anonymize data unless there is an obligation or legitimate interest in further storage.
10. Local Data and Caches
The app stores certain data locally on your device, such as settings, cached profile, meal, weight, restaurant, and chat data, images, place data, favorites, push token states, and temporary analysis or offline queue states. More sensitive app caches are stored in protected app storage with iOS file protection where technically possible.
You can remove local data by deleting the app or through system storage cleanup; server-side account data is not affected until you delete it or request deletion.
11. Your Rights
- Access to your personal data, Art. 15 GDPR.
- Rectification of inaccurate data, Art. 16 GDPR.
- Erasure, Art. 17 GDPR.
- Restriction of processing, Art. 18 GDPR.
- Data portability, Art. 20 GDPR.
- Objection to processing based on legitimate interests, Art. 21 GDPR.
- Withdrawal of granted consent with effect for the future, Art. 7(3) GDPR.
- Complaint to a data protection supervisory authority, Art. 77 GDPR.
12. Obligation to Provide Data
You only need to provide data that is required for the relevant feature. Without an account, we cannot provide account-related features. Without photo, location, HealthKit, or push permissions, the respective optional features may not work or may work only in a limited way.
13. Automated Decisions
Trayly does not make legally significant decisions solely by automated means. Scores, estimates, rankings, and recommendations are assistant features and can be ignored, corrected, or deleted by you.
14. Minors
Trayly is not directed at children under 16. If you are under 16, you may use Trayly only if your legal guardians have consented.
15. Changes to This Privacy Policy
We may update this Privacy Policy if features, service providers, the legal situation, or technical processes change. The current version is available in the app and on this website.