Privacy Policy
Last updated: 2026-08-08
1. Responsible Party
The party responsible for data processing on this website is:
Thomas Beckmann
Eduard-Salfeld-Straße 9
29614 Soltau
E-Mail: info@meallens.de
2. Collection and Storage of Personal Data
2.1 When Visiting the Website
When you access our website, the browser on your device automatically sends information to our website server. This information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the accessed file
- Website from which access was made (referrer URL)
- Browser used and, if applicable, the operating system of your computer
The aforementioned data is processed by us for the following purposes:
- Ensuring a smooth connection to the website
- Ensuring comfortable use of our website
- Evaluation of system security and stability
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
2.2 When Registering and Using the App
When you register with MealLens, we collect the following data:
- Email address (for login and communication)
- Password (stored encrypted)
- First and last name (optional)
- Intolerances (entered by you)
When using the app, we store:
- Meal photos (uploaded by you)
- Food entries (recorded by you)
- Symptom entries (documented by you)
- Analysis results (generated by AI)
Some of the information you enter (e.g., symptoms, intolerances, or connections between foods and complaints) may relate to your health. This data is used exclusively to provide MealLens functions (analysis, history, reports) and is not used for advertising purposes.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
2.3 In-App Purchases (Subscriptions)
If you purchase a paid subscription in the MealLens app, billing is handled through the Apple App Store. We do not receive direct payment data (e.g., credit card number), but only information about whether a subscription is active or has been renewed.
The legal basis for this processing is Art. 6 para. 1 lit. b GDPR (contract fulfillment).
3. AI-Powered Analysis (OpenAI)
To analyze your meals, we use the OpenAI API. The following data is transmitted to OpenAI:
- Food names and ingredients
- Your documented intolerances
- Symptom information
Important: Your photos are NOT transmitted to OpenAI. Image recognition is performed locally or via a separate, GDPR-compliant API.
OpenAI processes this data according to their Privacy Policy. OpenAI does not use your data to train their models when you use the API.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
4. Push Notifications
If you enable push notifications, we store your push subscription (endpoint, keys). This data is used exclusively to send you reminders.
You can deactivate push notifications at any time in your browser or device settings.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
5. Cookies and Local Storage
Our website uses:
- Session cookies (for login status, 30 days validity)
- Remember-Me cookie (optional, if "Stay logged in" is enabled)
- IndexedDB (local storage for offline functionality)
- Service Worker cache (for faster loading times)
All cookies are technically necessary for the app's functionality. We do not use tracking or advertising cookies.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
6. Data Sharing
We only share your personal data if:
- You have expressly consented (Art. 6 para. 1 lit. a GDPR)
- This is necessary for contract fulfillment (Art. 6 para. 1 lit. b GDPR)
- A legal obligation exists (Art. 6 para. 1 lit. c GDPR)
Recipients:
- OpenAI (USA) - for AI analyses (see point 3)
- Hosting provider (Netcup, Germany) - for server operation
7. Storage Duration
We store your data as long as you use your account. After deletion of your account, all personal data will be completely deleted within 30 days.
Exception: Data that we must store due to legal retention periods (e.g., invoices).
8. Your Rights
You have the following rights:
- Access (Art. 15 GDPR) - What data do we store about you?
- Rectification (Art. 16 GDPR) - Correction of incorrect data
- Erasure (Art. 17 GDPR) - "Right to be forgotten"
- Restriction (Art. 18 GDPR) - Blocking of processing
- Data portability (Art. 20 GDPR) - Export of your data
- Objection (Art. 21 GDPR) - Objection to processing
To exercise your rights, contact us at: info@meallens.de
You also have the right to file a complaint with a data protection supervisory authority.
9. Data Security
We use SSL/TLS encryption for the entire website. Passwords are stored using modern hashing methods (bcrypt). Only authorized persons have access to the database.
10. Changes to this Privacy Policy
We reserve the right to adjust this privacy policy to adapt it to changed legal situations or changes to our services. We recommend that you visit this page regularly.
11. Contact
For questions about data protection, contact us at:
Email: info@meallens.de