Kaunto

Privacy Policy

Effective · Last updated

1. Who we are

EN PLACE AD S.R.L. (“Kaunto”, “we”, “us”, “our”) is the data controller for the personal data described in this policy.

CompanyEN PLACE AD S.R.L.
Registered officeStr. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania
Trade RegisterJ2018002711129 · EUID ROONRC.J2018002711129
Tax ID (CUI)39521926
Emailcontact@fabelx.com
Phone+40 742 092 489

Privacy questions and rights requests: contact@fabelx.com.

This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have. It applies to the Kaunto mobile app and our supporting servers.


2. Summary — the short version

  • We are based in Romania (EU). Your account data is stored, and our servers run, in the European Union. Some third parties we rely on process data outside the EU — see §8.
  • We use your data to run the app for you. We do not sell your data, and we do not use it for advertising. We show no ads and the app contains no advertising software — the only promotional message you may ever see is our own, for Kaunto Pro, and it involves no one else and no data sharing.
  • Health data is never used for marketing, advertising, or shared with data brokers. Ever.
  • Meal photos you scan are never stored on our servers — they are processed in memory and discarded.
  • We use OpenAI to recognise food from photos — it is not retained by them and never used to train their models. See §6.1.
  • You can delete your account and data from inside the app, at any time.
  • Kaunto Pro (an optional subscription) is bought through Apple or Google. We never see your payment details. Deleting your account does not cancel a subscription — cancel it in your store settings first (§10).
  • You must be 16 or older to use Kaunto.

This summary is for orientation only — the detail below governs.


3. What we collect

3.1 Account data

DataSourceWhy
Email addressYou, or Google/Apple sign-inCreate and secure your account
Authentication identifier (Firebase UID)GeneratedLink your data to you
Sign-in providerGoogle / Apple / passwordLet you sign back in

We never see or store your password — authentication is handled by Google Firebase Authentication.

3.2 Profile and goals — health data

Name; avatar (emoji, colour, or photo); units preference; gender; age; height; weight; goal weight; body goal; macro split; activity level; goal speed; calorie/protein/carbohydrate/fat targets; notification preference; food-region country.

3.3 Activity in the app — health data

Food and drink you log (item, quantity, meal, date/time); activities and workouts you log; your weight history — each weigh-in you record, with its date, including readings imported from Apple Health / Health Connect if you connect it (§3.4); recipes you create; custom activities; app settings; streaks and statistics derived from the above.

3.4 Apple Health / Health Connect — health data, only with your permission

If you grant access:

  • We read: steps, active energy burned, exercise time, distance, weight, height, workouts.
  • We write: the workouts and activities you log and the active energy they burn, the food you log (as nutrition), and your weight and height when you update them in Kaunto — so your health app stays in step with what you record here. Only data you entered yourself is written; nothing we read from the health app is ever written back.

This is entirely optional. The app works without it, and you can revoke access at any time in your device settings.

3.5 Photos

  • Meal photos you submit for food recognition.
  • A profile photo, if you choose to set one.

3.6 Technical and security data

IP address (recorded automatically in our server request logs); your device’s country code; search queries and scanned barcodes; usage timestamps for rate limiting.

Crash reports. When the app crashes or hits an unexpected error, it sends a crash report to Firebase Crashlytics (Google, §6.2): the technical trace of what failed, the app and operating-system version, the device model, and a random installation identifier that Crashlytics creates. Crash reports carry no account identifier, name, email, food, weight or health data, and are not linked to your account. They are kept for 90 days.

3.7 Kaunto Pro — purchase and subscription data

Only if you subscribe. The purchase itself is made with Apple or Google, who process your payment as independent controllers under their own privacy policies — we never receive your card number, billing address, or store account credentials.

What we and our subscription processor (RevenueCat, §6.5) do receive: which plan you bought (monthly or annual), the store it was bought on, the purchase, renewal and expiry dates, whether a free trial was used, the store’s transaction and receipt identifiers, the price and currency as reported by the store, and the subscription’s current status (active, cancelled, in a grace period, refunded). This is linked to your account by the same authentication identifier as everything else (§3.1). For free accounts we also keep weekly counters of AI photo scans and barcode scans used, so the weekly limits can be applied.

3.8 What we do NOT collect

No advertising identifiers (no IDFA/AAID) are read. No analytics or tracking SDKs; the one third-party diagnostic tool is crash reporting (§3.6). No location beyond a coarse country code. No contacts, no microphone, no precise location. We do not track you across other apps or websites, and we have not asked for — and do not use — the iOS tracking permission.

About advertising, precisely. Kaunto shows no ads and contains no advertising software. After the first week of use, a free account waits a few seconds, with a short message from us about Kaunto Pro, each time it starts adding food; it is part of the app, involves no advertising network, and shares nothing with anyone. If we ever introduced advertising we would update this policy first and ask for your consent where the law requires it.

Health data is “special category” data under GDPR Art. 9. Sections 3.2, 3.3 and 3.4 are all treated as health data, and dietary logs can reveal health information — so we apply the same protection to all of it.


PurposeDataLegal basis (GDPR)
Create and operate your account§3.1Contract — Art. 6(1)(b)
Provide tracking, goals and statistics§3.2, §3.3Contract — Art. 6(1)(b) and Explicit consent — Art. 9(2)(a) for the health elements
Sync with Apple Health / Health Connect§3.4Explicit consent — Art. 9(2)(a). Granted via your device’s health permission prompt; withdraw any time
Recognise food from a photo§3.5 meal photosConsent — Art. 6(1)(a) and Art. 9(2)(a); you choose to submit each photo
Display your profile photo§3.5 profile photoContract — Art. 6(1)(b)
Look up food and barcode datasearch queries, barcodes, countryContract — Art. 6(1)(b)
Security, abuse prevention, rate limiting, debugging, crash reports§3.6Legitimate interests — Art. 6(1)(f): keeping the service available, stable, secure and affordable
Manage your Kaunto Pro subscription, apply free-account limits, and unlock Pro features§3.7Contract — Art. 6(1)(b)
Comply with legal obligationsas requiredLegal obligation — Art. 6(1)(c)

Withdrawing consent. Where we rely on consent you may withdraw it at any time — revoke health access in device settings, stop submitting photos, or delete your account. Withdrawal does not affect processing already carried out.

Is providing data mandatory? Account data and the profile figures used to calculate your targets are necessary to provide the app — without them it cannot function. Everything else (health sync, photos, avatar) is optional.


5. Automated processing

When you submit a meal photo, an automated AI model estimates what the food is. Nutritional values are then looked up from food databases — they are not invented by the model.

This is not automated decision-making producing legal or similarly significant effects (GDPR Art. 22). It is a suggestion you review, edit, and confirm before anything is saved. It is frequently inaccurate; always check the result.


6. Who we share data with

We do not sell your personal data, and we do not share it for advertising. We use the following processors and third parties:

6.1 OpenAI — meal photo recognition

When you scan a meal photo, a downscaled copy (max 1024px, metadata/EXIF stripped — including any location data) is sent to OpenAI’s API for recognition, together with the photo’s capture timestamp if available.

We do not send your name, email, user ID, or IP address to OpenAI.

OpenAI does not use your photos to train its models. We have disabled every data-sharing option in our OpenAI organisation settings, so nothing we send is used for model training, evaluation, or fine-tuning.

Retention by OpenAI: we send each request with logging disabled, so your photo is not stored in our OpenAI organisation’s records. OpenAI may still hold the request for up to 30 days for its own abuse-monitoring purposes, after which it is deleted. OpenAI does not have access to your identity — only the image and its capture time.

Transfer: United States — see §8.

6.2 Google (Firebase) — authentication, database, file storage

Google Ireland Ltd / Google LLC processes your account, profile, logs and photos on our behalf, and receives crash reports through Firebase Crashlytics (§3.6). Our database and file storage are hosted in the European Union (a multi-region location spanning Belgium and the Netherlands); our application servers run in Belgium (europe-west1). Governed by Google’s Data Processing Terms.

6.3 USDA FoodData Central — nutrition lookup

We send only the search text (typed by you, or a food name derived from a photo). No identifier of any kind. Operated by the U.S. Department of Agriculture — transfer to the United States.

6.4 Open Food Facts — barcode and product data

We send the scanned barcode or search text, plus your device’s country code (used to select the regional database, so Open Food Facts learns your approximate country). No identifier. Product data is provided under the Open Database License (ODbL). Operated from France (EU).

6.5 RevenueCat — subscription management

If you subscribe to Kaunto Pro, RevenueCat, Inc. (United States) verifies your purchase with Apple or Google and tells our servers whether your account is Pro. It receives your account’s authentication identifier (§3.1) and the purchase and subscription data in §3.7 — never your name, email, health data, or payment details. Governed by RevenueCat’s Data Processing Addendum. Transfer: United States, under Standard Contractual Clauses — see §8.

Apple and Google, as the stores you buy through, handle the payment itself under their own privacy policies.

6.6 Other disclosures

We may disclose data where legally required (court order, lawful request), to establish or defend legal claims, or to a successor in a merger or acquisition — in which case we will notify you and this policy will continue to apply until replaced.


7. Your custom foods — private to you

Foods you create (name, brand, barcode and nutritional values) are visible only to you: they are stored inside your own account’s data, which only you can read. Other Kaunto users cannot see, find or use them. You can edit or delete them at any time, and they are deleted with your account.

Everything else stays private to your account too — your logs, weight history, recipes, profile, photos and health data are never shown to other users.

If we ever offer a way to share foods with other users, it will be your choice, per food, and we will update this policy first.


8. International transfers

Your account data is stored in the EU. Some processors are in the United States (OpenAI, RevenueCat, USDA, and Google as a US parent). Where data leaves the EEA we rely on:

  • Standard Contractual Clauses approved by the European Commission; and/or
  • the processor’s certification under the EU–US Data Privacy Framework; together with
  • supplementary measures — data minimisation (no identifiers sent to OpenAI/USDA/OFF; only an account identifier and purchase data to RevenueCat), EU-region storage, and encryption in transit.

You may request a copy of the relevant safeguards at contact@fabelx.com.


8A. This website

This policy also covers kaunto.app, the website you may be reading it on.

The site is a set of static pages. It sets no cookies, runs no advertising or cross-site tracking scripts, and makes no third-party requests — the typeface is served from this domain rather than a font CDN, so loading a page contacts nobody but us. That is also why you are not being asked to accept anything.

If privacy-preserving analytics are enabled, they count page views and referrers in aggregate, without cookies, without fingerprinting, and without anything that identifies an individual visitor.

Our hosting provider processes your IP address in order to serve the page to you, and may retain it briefly in its own security logs.


9. How long we keep it

DataRetention
Account, profile, logs, weight history, recipes, settingsUntil you delete your account
Profile photoUntil replaced, or until account deletion
Meal photos (our servers)Not stored at all — processed in memory and discarded
Meal photos (OpenAI)Not retained in our OpenAI records; OpenAI may hold the request up to 30 days for abuse monitoring — see §6.1
Food search cacheAutomatically deleted after 30 days. Not linked to your account.
Rate-limiting recordsUntil account deletion
Kaunto Pro subscription status (our record) and free-account weekly scan countersUntil account deletion
Purchase records held by RevenueCatFor as long as needed to service the subscription and per RevenueCat’s own retention; deleted on our request — see §10
Server request logs (incl. IP, queries, barcodes, user ID)30 days
Custom foodsUntil you delete them, or your account — see §7
Crash reports (Firebase Crashlytics)90 days. Not linked to your account — see §3.6

We do not maintain separate backups of your data; when your account is deleted, deletion is not delayed by a backup-retention period. Server request logs age out on the 30-day schedule above.


10. Deleting your account

You can delete your account at any time: Profile → Support → Delete Account.

This permanently erases your profile, food and activity logs, weight history, recipes, custom foods, custom activities, settings, and your profile photo. It cannot be undone.

If you have Kaunto Pro, deletion also removes our record of your subscription and your weekly scan counters. Deleting your account does not cancel the subscription itself — that is a contract between you and Apple or Google. Cancel it in your App Store or Google Play subscription settings first, or you may keep being charged. RevenueCat keeps its own record of the purchase for as long as it needs to service the subscription; on request at contact@fabelx.com we will ask RevenueCat to delete it. Apple and Google keep their own purchase records under their policies.

Two limited exceptions, both time-bound: server request logs (§9) age out on their own 30-day schedule and are not erased on request; and where we are legally required to retain something, we keep only what the law requires, for as long as it requires.


11. Your rights

Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict processing; object to processing based on legitimate interests; receive it in a portable format (data portability); and withdraw consent at any time.

To exercise any of these, email contact@fabelx.com. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Complaints. You may lodge a complaint with the Romanian supervisory authority:

Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania anspdcp@dataprotection.ro · www.dataprotection.ro

You may also complain to the authority in your own EU country of residence.


12. If you are in California (CCPA/CPRA)

In the past 12 months we collected the categories in §3, for the purposes in §4, from the sources described there.

We have not sold or shared personal information, and we do not sell or share the personal information of anyone under 16. We do not use sensitive personal information for purposes requiring an opt-out right.

You have the right to know, delete, correct, and not be discriminated against for exercising these rights. Contact contact@fabelx.com or use in-app deletion (§10). You may use an authorised agent.


13. Children

Kaunto is not for anyone under 16, and we do not knowingly collect their data. If we learn that we hold data from someone under 16, we delete it. If you believe a child has given us data, contact contact@fabelx.com.


14. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers. Every server endpoint requires a verified authentication token. Access to production systems is restricted, and secrets are held in a managed secret store — never in our source code.

No system is perfectly secure. If a breach affects your rights, we will notify the supervisory authority within 72 hours and you directly where legally required.


15. Changes

We may update this policy. The “Last updated” date will change, and for material changes we will notify you in the app or by email before they take effect. Continuing to use Kaunto after that means you accept the updated policy.


16. Contact

EN PLACE AD S.R.L. Str. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania contact@fabelx.com · +40 742 092 489