Fodo Privacy Policy
Draft pending legal review. Highlighted fields will be completed before the app is published.
Version: DRAFT · Effective date: DATA_WEJSCIA_W_ZYCIE
This policy describes what data the Fodo app ("Fodo", "the app") processes, why, on what legal basis, how long we keep it, and what your rights are. We keep the language plain — both the GDPR and common sense require it.
1. Data controller
The controller of your personal data is:
Logi Labs sp. z o.o., a company registered in Warsaw, Poland (KRS 0001226746, NIP 7011302004) ul. Rokosowska 11/15, Warsaw
Privacy contact: [email protected]
2. Short summary (TL;DR)
- Fodo processes data about your health (gut symptoms, meal diary, food test results) — solely with your explicit, separate consent and solely to make the app work.
- Health data is stored on your device (encrypted local database) and synchronised to servers in the European Union (encrypted in transit and at rest).
- Health data never reaches external analytics or crash-reporting tools — analytics and error reporting cover only technical, non-health events.
- We show no ads, we do not sell your data, and we do not share it for third-party marketing.
- You can delete your account yourself in the app (full data purge), and export your data first (a JSON file) — no emails required.
- Meal photos from the AI scanner are processed ephemerally — we do not keep them after the meal has been recognised, and metadata (EXIF, including location) is stripped on your device before upload.
3. What data we process
3.1. Account data
- Anonymous account (from first launch): a random account identifier bound to your device, plus authentication tokens. You do not need to provide your name or email address to use Fodo.
- Optional email linking: if you choose to link your account to an email address (one-time-code / OTP sign-in), we process that address solely for authentication and account recovery.
- Apple / Google sign-in identifiers (if you choose that method) — verified cryptographically, with no access to your password.
3.2. Health data (special-category data — GDPR Art. 9)
With your explicit consent we process:
- gut symptoms and their severity (including the FSS composite), the Bristol scale,
- your meal diary (ingredients, weights, FODMAP load) and hydration,
- the course of your protocol: phases, food tests (challenges), verdicts, your tolerance profile,
- optional confounders, if you log them: menstruation, sleep, stress,
- the contents of the PDF report generated at your request.
This data lives in two places: in the encrypted local database on your device (key held in the Keychain/Keystore; the database is excluded from the operating system's cloud backups) and — via synchronisation — on our server in the EU.
3.3. Meal photos and descriptions (AI scanner)
- You voluntarily submit a photo and/or a text description of a meal so the app can recognise its ingredients.
- EXIF metadata (including GPS location and device identifiers) is stripped on your device before upload.
- The photo is processed solely to extract ingredients and is not stored after processing has finished.
- Exception: if you give a separate, optional consent to use photos for recognition quality assurance, a photo may be stored for at most 30 days on servers in the EU, after which it is permanently deleted.
3.4. Purchase data
- Purchases are handled by the Apple App Store or Google Play — we have no access to your card or bank details. We receive a transaction confirmation from the platform (identifier, product type, status), which we use to activate features (entitlements) on your account.
3.5. Technical data
- Push notification tokens (APNs/FCM) — for delivering plan notifications; lock-screen notification content is generic by default, with no health details.
- Crash reports — technical data about app failures, with no health attributes (the filtering mechanism is covered by automated tests).
- Usage statistics (analytics) — only with your separate, optional consent; non-health events (e.g. onboarding steps, feature usage) linked to a random pseudonym, never to your symptoms, meals, or protocol history.
- Server logs — technical request records (including IP address and timestamps) for security and diagnostics.
- Device integrity signals (App Attest / Play Integrity) — to protect free scan quotas against abuse.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Running the protocol, diary, verdicts, tolerance profile, PDF report | health data (3.2) | GDPR Art. 9(2)(a) — your explicit consent |
| Recognising a meal from a photo/description | meal photo/description (3.3) | GDPR Art. 9(2)(a) (content may reveal health data) |
| Scanner quality assurance (opt-in) | meal photos, up to 30 days | GDPR Art. 6(1)(a) / Art. 9(2)(a) — separate consent |
| Creating and operating your account, sync, OTP email | account data (3.1) | GDPR Art. 6(1)(b) — performance of a contract |
| Activating purchases and managing entitlements | purchase data (3.4) | GDPR Art. 6(1)(b) |
| Plan notifications (push) | device token | GDPR Art. 6(1)(b); controlled in system and app settings |
| Usage statistics | pseudonymous non-health events | GDPR Art. 6(1)(a) — separate analytics consent |
| Error reporting, security, abuse prevention | technical data, logs | GDPR Art. 6(1)(f) — legitimate interest (service stability and security) |
| Tax and accounting obligations | platform settlement data | GDPR Art. 6(1)(c) |
Both consents (health and analytics) are separate, voluntary, and withdrawable at any time in Settings → Privacy. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Withdrawing the health consent stops protocol guidance (it cannot run without symptom data); the food database and educational materials remain available.
5. How long we keep data (retention)
| Data | Period |
|---|---|
| Diary, protocol history, tolerance profile, account data | until account deletion |
| Scan photos | not stored after processing; with QA consent — max. 30 days |
| PDF report | generated on demand, streamed to you, no server-side retention and no permanent URLs |
| Server logs | 90 days |
| Server backups | rolling 30 days (encrypted client-side before offsite transfer) |
| Analytics events (with consent) | per the EU-hosted tool's configuration; pseudonymous |
When you delete your account, your data is removed from the production database immediately and disappears from backups no later than the end of the 30-day backup rotation cycle. During that interim period backups are used for nothing other than potential disaster recovery.
6. Recipients (data processors)
We use the following providers (each under a data processing agreement — DPA):
| Provider | Role | What data | Location |
|---|---|---|---|
| Hetzner Online GmbH | server hosting (VPS, database) | all server-side data (encrypted at rest) | Germany / Finland (EU) |
| MailerSend | sending OTP emails | email address | EU (Lithuania) |
| Sentry (EU instance) | app crash reporting | technical data, no health attributes | EU |
| PostHog (EU instance) | usage analytics (consent only) | pseudonymous non-health events | EU |
| Apple (APNs) | push notification delivery (iOS) | device token, generic content | global |
| Google (FCM) | push notification delivery (Android) | device token, generic content | global |
| OpenAI | ingredient extraction from photo/text (AI scanner) | meal photo/description, ephemerally (no provider-side retention) | USA — transfer mechanism: DO_WERYFIKACJI: DPF/SCC |
| Offsite backup provider: DO_WERYFIKACJI: name — EU region | storage of encrypted backups | ciphertext only (key held elsewhere) | EU |
In addition, Apple and Google, as operators of the app stores and payment systems, act as independent controllers for purchases — see their own privacy policies.
7. Transfers outside the EEA
We keep data on servers in the EU. Exceptions:
- Push notifications — delivery requires Apple (APNs) and Google (FCM) infrastructure, which operates globally. We transfer only the device token and generic notification content (no health data). The transfer mechanism is standard contractual clauses / a DPF adequacy decision DO_WERYFIKACJI: transfer mechanism to be confirmed in the DPAs.
- AI scanner — ingredient extraction is performed by OpenAI (USA). We transfer only the meal photo or description (EXIF metadata, including GPS, is stripped on the device before upload); we transfer no health data about you — no symptoms, protocol stage or results. The photo is not retained after extraction, neither by us nor by the provider. The transfer mechanism is standard contractual clauses / a DPF adequacy decision DO_WERYFIKACJI: DPF/SCC.
8. Your rights
You have the right to:
- access your data and obtain a copy of it,
- export your data — in the app: Settings → Privacy → Data export (a JSON file; right to data portability),
- rectification — edit entries directly in the app,
- erasure — in the app: Settings → Account → Delete account (a full, irreversible data purge; see §5),
- withdraw consents — Settings → Privacy, each consent separately,
- restriction of processing and objection to processing based on legitimate interest,
- lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (PUODO, uodo.gov.pl); you may also complain to the authority in your country of residence.
Any rights you cannot exercise yourself in the app, we will fulfil upon request sent to [email protected] — without undue delay, and within one month at the latest.
9. Automated processing and profiling
- The AI scanner automatically suggests a list of meal ingredients — this is a suggestion you can edit; it produces no legal effects concerning you.
- Test verdicts and the tolerance profile are computed deterministically from data you enter yourself and are educational in nature — they are not a diagnosis or a decision within the meaning of GDPR Art. 22.
- We do not profile you for advertising. The app contains no ads and no advertising trackers.
10. Security
Our measures include: encryption in transit (TLS), encryption of server data at rest, an encrypted local database on your device (key in the hardware-backed key store), backups encrypted client-side before leaving the server (with the key stored separately), rotation of authentication tokens with reuse detection, telemetry minimisation (automated tests excluding health attributes from external tools), and restricted, monitored access to our infrastructure.
11. Children and age
Fodo is intended for people aged 16 or over (the age of independent consent to information society services in Poland). We do not direct the service at younger users and do not knowingly collect their data; if we learn that an account belongs to a person under 16, we will delete it together with its data. Independently of that, the elimination protocol is available only to adults — for users under 18 the app provides only the food database and educational materials (nutritional safety reasons).
12. Changes to this policy
We will notify you of material changes in the app in advance. If a change were to expand the scope of health data processing, we will ask for fresh consent — we will never expand it silently.
13. Contact
- Privacy matters: [email protected]
- Everything else: [email protected]
Contact: [email protected]