Panotxa is a meal-quality coaching app: you photograph or describe what you eat, an AI reads the plate, and the app turns that into scores and trends. This policy explains, in plain language, what personal data we handle to do that, why, who helps us process it, how long we keep it, and what your rights are. It applies to the Panotxa app (iOS, Android and web atapp.panotxa.com) and to this website.
1. Who is responsible
The data controller is Oriol Jiménez, NIF[NIF — Oriol to fill], postal address[postal address — Oriol to fill], Spain. For anything about your data, write to hello@panotxa.com. There is no data protection officer, because none is required for a service of this size.
2. What data we process
- Account. Your email address, an optional display name and a password (stored only as a salted hash). If you sign in with Google or Apple we receive the email and name that provider releases and a provider user id — never your provider password. Apple's "hide my email" relay addresses are accepted.
- Profile. What you choose to tell us in the app: your focus (habits or weight), language and time zone, diet type and intolerances, and — only if you turn on weight tracking — date of birth, height, sex, activity level, target weight and pace, protein preferences, and notification settings.
- Meals. Meal photos, text descriptions, meal type and time, your answers to clarification questions (portion, "was this yours?"), corrections and notes; and the results the app derives from them (dish and meal scores, extracted food signals, calories and macros, recommendations, daily notes, weekly focus goals).
- Chat. The messages you exchange with the in-app nutritionist assistant and its replies. The assistant is an AI, not a person.
- Habits and body data. Water and movement entries you log; weight and body fat entries you type in or that we import from your health app.
- Health data (opt-in only). If you switch on health sync, with your permission we read from Apple Health or Health Connect: daily step counts, active energy (and on Android total and basal energy, to correct for wearables that exclude workouts), body weight and body fat percentage. If you switch on "write to Health" we write the day's calories consumed into the same apps. We read nothing else, and we never write back anything we read.
- Pro connections. If you connect a nutrition or training professional (by entering their invite code), the connection record, which categories you chose to share, and the comments and notes that professional leaves on your data.
- Devices and technical data. Push-notification tokens for the devices where you enable notifications; the client identifiers the app uses to avoid duplicate uploads; and standard server logs (IP address, user agent, timestamps, requested URLs).
- Error reports. When the app or the server hits an error, a report is sent to our error-monitoring service with a stack trace, app version, device model/OS and the URL involved. The app's error reporting is configured not to send personal identifiers by default; a report may still contain fragments of the data being processed at the moment of the error.
We do not collect precise location, contacts, advertising identifiers or payment data.
3. Why we process it and on what legal basis
| Purpose | Data | Legal basis (GDPR art. 6 / 9) |
|---|---|---|
| Running your account and the service you asked for: analysing meals, computing scores and trends, syncing across your devices, sending service emails (sign-up confirmation, password reset, the digests you enable) | Account, profile, meals, chat, habits | Performance of a contract (art. 6.1.b) — the terms of use |
| Sending your meal photos, texts and relevant profile context to an AI model (Google Gemini) to analyse the plate and answer in the chat | Photos, texts, meal type, diet and intolerances, chat, a summary of your recent data for the chat's context | Your consent (art. 6.1.a), given when you take/upload the first photo or send the first message. Diet and intolerance data are health-related; we rely on your explicit consent (art. 9.2.a). Withdraw by deleting the data or your account. |
| Reading and writing health data via Apple Health / Health Connect | Steps, energy, weight, body fat (read); calories consumed (written) | Your explicit consent (art. 9.2.a), given in the OS permission dialog and the in-app toggle. Withdraw any time in the app or the OS. |
| Sharing your data with a professional you connect | The categories you toggle on (meals & photos, scores, habits, body data, history) | Your explicit consent (art. 6.1.a / 9.2.a). Withdraw by disconnecting. |
| Public meal share links you create | The shared meal: photo(s), dish titles, scores, plate breakdown | Your consent (art. 6.1.a) — you create and can revoke each link |
| Push notifications you enable (trend changes, gentle logging reminders, weekly focus review) | Device push token, notification settings | Contract (art. 6.1.b); you can switch them off in the app or the OS |
| Keeping the service secure and working: server logs, rate limiting, error monitoring, prompt/quality observability of the AI calls | Technical data, error reports, AI traces | Legitimate interest (art. 6.1.f) in a reliable, secure service. You may object (section 8). |
| Answering your requests and exercising your rights | Your email and the request | Legal obligation (art. 6.1.c) |
We do not sell your data, we do not use it for advertising, and we do not build profiles for any purpose other than the coaching you see in the app. Automated analysis (scores, recommendations, chat replies) is informational; no decision with legal or similarly significant effects on you is made automatically.
4. Who helps us process it (processors) and international transfers
We use a small number of service providers, each bound by a data-processing agreement (GDPR art. 28) and only receiving what they need:
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the servers and database (managed through Coolify) | EU (Germany) [datacenter location — confirm] |
| Backblaze, Inc. (B2 cloud storage) | Storage of meal photos and generated share images | United States (region us-west-004) — transfer under the EU-US Data Privacy Framework / standard contractual clauses [confirm Backblaze DPF status] |
| Google (Gemini API) | AI analysis of meal photos and texts, recommendations, daily notes, chat replies | United States / global — Google is certified under the EU-US Data Privacy Framework. Under the paid Gemini API terms Google does not use your prompts to train its models [confirm paid-tier API] |
| Langfuse GmbH | Observability of the AI calls (the prompt sent, the model's answer, timings and cost, keyed to your account id) so we can find and fix bad answers | EU (Germany, cloud.langfuse.com EU region) |
| Resend, Inc. | Sending transactional emails (confirmations, password resets, digests, data exports) | United States — EU-US Data Privacy Framework / standard contractual clauses[confirm] |
| Sentry [Sentry.io (US) or self-hosted GlitchTip — confirm] | Error monitoring for the app and the server | [US under DPF, or EU if self-hosted — confirm] |
| Google (Firebase Cloud Messaging) and Apple (APNs) | Delivering push notifications to your device | United States — EU-US Data Privacy Framework |
| Google Sign-In / Sign in with Apple | Optional social login; they tell us who you are, we tell them nothing about your use of the app | United States — EU-US Data Privacy Framework |
Where a provider is outside the EEA, transfers rely on an adequacy decision (the EU-US Data Privacy Framework for certified US companies) or on the European Commission's standard contractual clauses. You can ask us for a copy of the safeguards in place.
Other recipients. A professional you connect sees the categories you chose to share, and only from the date you chose. Anyone who has a share link you created can open that page. We disclose data to authorities only when the law obliges us to.
5. How long we keep it
- Account, profile, meals, chat, habits, body and health data: for as long as your account exists. When you delete your account (section 7) everything is deleted, including photos in storage.
- Public share links: until you unshare the meal, delete it, or delete your account.
- Data-export files: the zip we email you a link to is deleted 24 hours after it is created.
- Pro connections: disconnecting stops the professional's access immediately; the professional's own notes and comments about you are deleted with your account.
- Server logs and error reports:[N days — confirm], then deleted or anonymised.
- AI observability traces (Langfuse):[N days — confirm].
- Emails you send us: for as long as needed to answer and, if relevant, to prove we did.
Nothing survives account deletion by default — no hashed email, no aggregate that could identify you.
6. Public share links and professionals — a closer look
Share links. When you tap "share" on a meal, we create a public page (and a preview image for messaging apps) showing that meal's photo(s), dish names, scores and plate breakdown — never your name or email. It is reachable by anyone who has the link, and it can be indexed if it is posted publicly. You can revoke it from the meal at any time; it also stops working if you delete the meal or your account.
Professionals (Panotxa Pro). A nutritionist or trainer only sees your data after you enter their invite code and pick what to share: meals and photos, scores and trends, water and movement, weight and body data (off by default), and whether they see history from before the connection. They can leave comments on meals and private notes. You can disconnect at any time from the app; access ends immediately. Professionals are separately responsible for how they use what they see under their own professional obligations.
7. Deleting your account and exporting your data
In the app, under Profile, you can download all your data(a zip of CSV files, one per dataset, sent to your email as a link valid for 24 hours) anddelete your account. Deletion removes your account and everything tied to it — meals, photos, chat, habits, body and health data, professional connections and notes, push tokens — and every share link you created stops working. Deletion is immediate on the account and completes in the background within a short time; it cannot be undone. Data written into Apple Health or Health Connect stays on your phone under your control; you can delete it there.
8. Your rights
You can ask us at any time to access your data, rectifyit, erase it, restrict its processing, receive it in aportable format, and object to processing based on legitimate interest. Where processing relies on consent you can withdraw it at any time without affecting what was done before. Most of this you can do yourself in the app (edit your profile, delete meals, export, delete the account); for the rest write tohello@panotxa.com. We will answer within one month.
If you think we are not handling your data properly, you have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es), or with the authority of the EU country where you live.
9. Cookies and local storage
This website (panotxa.com) sets no cookies and uses no analytics or tracking of any kind. The app uses the browser's or device's local storage only for what it needs to work — your session token, your language and preferences, and a small offline queue of pending uploads — never for advertising or cross-site tracking. No cookie banner is shown because none is required.
10. Children
Panotxa is not intended for anyone under 14 (the age of digital consent in Spain; up to 16 in some EU countries). We do not knowingly create accounts for children; if you believe a child has given us data, write to us and we will delete it.
11. Security
All traffic is encrypted in transit (HTTPS). Passwords are hashed, access to production systems is limited to the controller, photos are stored in a private bucket and served through the app, and the API rate-limits authentication endpoints. Should a breach ever put your rights at risk we will notify the AEPD within 72 hours and you without undue delay, as the GDPR requires.
12. Changes to this policy
We will update this page when the service changes what it does with your data, and bump the date at the top. For material changes we will tell you in the app or by email before they take effect. Previous versions are available on request.