Privacy Policy
Effective · Last updated
1. Who we are
EN PLACE AD S.R.L. (“Kaunto”, “we”, “us”, “our”) is the data controller for the personal data described in this policy.
| Company | EN PLACE AD S.R.L. |
| Registered office | Str. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania |
| Trade Register | J2018002711129 · EUID ROONRC.J2018002711129 |
| Tax ID (CUI) | 39521926 |
| contact@fabelx.com | |
| Phone | +40 742 092 489 |
Privacy questions and rights requests: contact@fabelx.com.
This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have. It applies to the Kaunto mobile app and our supporting servers.
2. Summary — the short version
- We are based in Romania (EU). Your account data is stored, and our servers run, in the European Union. Some third parties we rely on process data outside the EU — see §8.
- We use your data to run the app for you. We do not sell your data. We do not use it for advertising. We show no ads.
- Health data is never used for marketing, advertising, or shared with data brokers. Ever.
- Meal photos you scan are never stored on our servers — they are processed in memory and discarded.
- We use OpenAI to recognise food from photos — it is not retained by them and never used to train their models. See §6.1.
- You can delete your account and data from inside the app, at any time.
- You must be 16 or older to use Kaunto.
This summary is for orientation only — the detail below governs.
3. What we collect
3.1 Account data
| Data | Source | Why |
|---|---|---|
| Email address | You, or Google/Apple sign-in | Create and secure your account |
| Authentication identifier (Firebase UID) | Generated | Link your data to you |
| Sign-in provider | Google / Apple / password | Let you sign back in |
We never see or store your password — authentication is handled by Google Firebase Authentication.
3.2 Profile and goals — health data
Name; avatar (emoji, colour, or photo); units preference; gender; age; height; weight; goal weight; body goal; macro split; activity level; goal speed; calorie/protein/carbohydrate/fat targets; notification preference; food-region country.
3.3 Activity in the app — health data
Food and drink you log (item, quantity, meal, date/time); activities and workouts you log; recipes you create; custom activities; app settings; streaks and statistics derived from the above.
3.4 Apple Health / Health Connect — health data, only with your permission
If you grant access:
- We read: steps, active energy burned, total calories burned, exercise time, distance, weight, height, workouts, heart rate.
- We write: workouts you log in Kaunto.
This is entirely optional. The app works without it, and you can revoke access at any time in your device settings.
3.5 Photos
- Meal photos you submit for food recognition.
- A profile photo, if you choose to set one.
3.6 Technical and security data
IP address (recorded automatically in our server request logs); your device’s country code; search queries and scanned barcodes; usage timestamps for rate limiting.
3.7 What we do NOT collect
No advertising identifiers (no IDFA/AAID). No third-party analytics or tracking SDKs. No location beyond a coarse country code. No contacts, no microphone, no precise location. We do not track you across other apps or websites.
Health data is “special category” data under GDPR Art. 9. Sections 3.2, 3.3 and 3.4 are all treated as health data, and dietary logs can reveal health information — so we apply the same protection to all of it.
4. Why we process it, and our legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and operate your account | §3.1 | Contract — Art. 6(1)(b) |
| Provide tracking, goals and statistics | §3.2, §3.3 | Contract — Art. 6(1)(b) and Explicit consent — Art. 9(2)(a) for the health elements |
| Sync with Apple Health / Health Connect | §3.4 | Explicit consent — Art. 9(2)(a). Granted via your device’s health permission prompt; withdraw any time |
| Recognise food from a photo | §3.5 meal photos | Consent — Art. 6(1)(a) and Art. 9(2)(a); you choose to submit each photo |
| Display your profile photo | §3.5 profile photo | Contract — Art. 6(1)(b) |
| Look up food and barcode data | search queries, barcodes, country | Contract — Art. 6(1)(b) |
| Security, abuse prevention, rate limiting, debugging | §3.6 | Legitimate interests — Art. 6(1)(f): keeping the service available, secure and affordable |
| Comply with legal obligations | as required | Legal obligation — Art. 6(1)(c) |
Withdrawing consent. Where we rely on consent you may withdraw it at any time — revoke health access in device settings, stop submitting photos, or delete your account. Withdrawal does not affect processing already carried out.
Is providing data mandatory? Account data and the profile figures used to calculate your targets are necessary to provide the app — without them it cannot function. Everything else (health sync, photos, avatar) is optional.
5. Automated processing
When you submit a meal photo, an automated AI model estimates what the food is. Nutritional values are then looked up from food databases — they are not invented by the model.
This is not automated decision-making producing legal or similarly significant effects (GDPR Art. 22). It is a suggestion you review, edit, and confirm before anything is saved. It is frequently inaccurate; always check the result.
6. Who we share data with
We do not sell your personal data, and we do not share it for advertising. We use the following processors and third parties:
6.1 OpenAI — meal photo recognition
When you scan a meal photo, a downscaled copy (max 1024px, metadata/EXIF stripped — including any location data) is sent to OpenAI’s API for recognition, together with the photo’s capture timestamp if available.
We do not send your name, email, user ID, or IP address to OpenAI.
OpenAI does not use your photos to train its models. We have disabled every data-sharing option in our OpenAI organisation settings, so nothing we send is used for model training, evaluation, or fine-tuning.
Retention by OpenAI: we send each request with logging disabled, so your photo is not stored in our OpenAI organisation’s records. OpenAI may still hold the request for up to 30 days for its own abuse-monitoring purposes, after which it is deleted. OpenAI does not have access to your identity — only the image and its capture time.
Transfer: United States — see §8.
6.2 Google (Firebase) — authentication, database, file storage
Google Ireland Ltd / Google LLC processes your account, profile, logs and photos on our behalf. Our database and file storage are hosted in the European Union (a multi-region location spanning Belgium and the Netherlands); our application servers run in Belgium (europe-west1). Governed by Google’s Data Processing Terms.
6.3 USDA FoodData Central — nutrition lookup
We send only the search text (typed by you, or a food name derived from a photo). No identifier of any kind. Operated by the U.S. Department of Agriculture — transfer to the United States.
6.4 Open Food Facts — barcode and product data
We send the scanned barcode or search text, plus your device’s country code (used to select the regional database, so Open Food Facts learns your approximate country). No identifier. Product data is provided under the Open Database License (ODbL). Operated from France (EU).
6.5 Other disclosures
We may disclose data where legally required (court order, lawful request), to establish or defend legal claims, or to a successor in a merger or acquisition — in which case we will notify you and this policy will continue to apply until replaced.
7. Community food database — this part is public
When you create a new food item, that entry is added to a shared community food database and becomes visible to, and usable by, other Kaunto users.
Shared: the food’s name, brand, barcode and nutritional values. Not shared: your name, email, or profile. The entry is never labelled with who created it, and no other user sees your identity in the app.
For completeness: each entry does store an internal account identifier recording which account added it, so that you can find and edit your own entries. It is a random identifier — not your name or email — and it is not displayed to anyone, but it is technically readable by other signed-in users. When you delete your account this identifier is removed and the entry is re-saved with no reference to your account at all.
Everything else stays private to your account — your logs, recipes, profile, photos and health data are never shown to other users.
Please do not put personal information in a food name. If you delete your account, previously shared food entries may remain in the database (other users’ logs may depend on them), but as described above they no longer carry any link to you.
8. International transfers
Your account data is stored in the EU. Some processors are in the United States (OpenAI, USDA, and Google as a US parent). Where data leaves the EEA we rely on:
- Standard Contractual Clauses approved by the European Commission; and/or
- the processor’s certification under the EU–US Data Privacy Framework; together with
- supplementary measures — data minimisation (no identifiers sent to OpenAI/USDA/OFF), EU-region storage, and encryption in transit.
You may request a copy of the relevant safeguards at contact@fabelx.com.
8A. This website
This policy also covers kaunto.app, the website you are reading it on.
The site is a set of static pages. It sets no cookies, runs no advertising or cross-site tracking scripts, and makes no third-party requests — the typeface is served from this domain rather than a font CDN, so loading a page contacts nobody but us. That is also why you are not being asked to accept anything.
If privacy-preserving analytics are enabled, they count page views and referrers in aggregate, without cookies, without fingerprinting, and without anything that identifies an individual visitor.
Our hosting provider processes your IP address in order to serve the page to you, and may retain it briefly in its own security logs.
9. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, logs, recipes, settings | Until you delete your account |
| Profile photo | Until replaced, or until account deletion |
| Meal photos (our servers) | Not stored at all — processed in memory and discarded |
| Meal photos (OpenAI) | Not retained in our OpenAI records; OpenAI may hold the request up to 30 days for abuse monitoring — see §6.1 |
| Food search cache | Automatically deleted after 30 days. Not linked to your account. |
| Rate-limiting records | Until account deletion |
| Server request logs (incl. IP, queries, barcodes, user ID) | 30 days |
| Shared community food entries | Indefinitely. Unlinked from you once you delete your account — see §7 |
We do not maintain separate backups of your data; when your account is deleted, deletion is not delayed by a backup-retention period. Server request logs age out on the 30-day schedule above.
10. Deleting your account
You can delete your account at any time: Profile → Delete account.
This permanently erases your profile, food and activity logs, recipes, custom activities, settings, and your profile photo. It cannot be undone.
Shared community food entries remain in the database but carry no link to you (§7).
Two limited exceptions, both time-bound: server request logs (§9) age out on their own 30-day schedule and are not erased on request; and where we are legally required to retain something, we keep only what the law requires, for as long as it requires.
11. Your rights
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict processing; object to processing based on legitimate interests; receive it in a portable format (data portability); and withdraw consent at any time.
To exercise any of these, email contact@fabelx.com. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Complaints. You may lodge a complaint with the Romanian supervisory authority:
Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania anspdcp@dataprotection.ro · www.dataprotection.ro
You may also complain to the authority in your own EU country of residence.
12. If you are in California (CCPA/CPRA)
In the past 12 months we collected the categories in §3, for the purposes in §4, from the sources described there.
We have not sold or shared personal information, and we do not sell or share the personal information of anyone under 16. We do not use sensitive personal information for purposes requiring an opt-out right.
You have the right to know, delete, correct, and not be discriminated against for exercising these rights. Contact contact@fabelx.com or use in-app deletion (§10). You may use an authorised agent.
13. Children
Kaunto is not for anyone under 16, and we do not knowingly collect their data. If we learn that we hold data from someone under 16, we delete it. If you believe a child has given us data, contact contact@fabelx.com.
14. Security
Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers. Every server endpoint requires a verified authentication token. Access to production systems is restricted, and secrets are held in a managed secret store — never in our source code.
No system is perfectly secure. If a breach affects your rights, we will notify the supervisory authority within 72 hours and you directly where legally required.
15. Changes
We may update this policy. The “Last updated” date will change, and for material changes we will notify you in the app or by email before they take effect. Continuing to use Kaunto after that means you accept the updated policy.
16. Contact
EN PLACE AD S.R.L. Str. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania contact@fabelx.com · +40 742 092 489