Kaunto

Privacy Policy

Effective · Last updated

1. Who we are

EN PLACE AD S.R.L. (“Kaunto”, “we”, “us”, “our”) is the data controller for the personal data described in this policy.

CompanyEN PLACE AD S.R.L.
Registered officeStr. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania
Trade RegisterJ2018002711129 · EUID ROONRC.J2018002711129
Tax ID (CUI)39521926
Emailcontact@fabelx.com
Phone+40 742 092 489

Privacy questions and rights requests: contact@fabelx.com.

This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have. It applies to the Kaunto mobile app and our supporting servers.


2. Summary — the short version

This summary is for orientation only — the detail below governs.


3. What we collect

3.1 Account data

DataSourceWhy
Email addressYou, or Google/Apple sign-inCreate and secure your account
Authentication identifier (Firebase UID)GeneratedLink your data to you
Sign-in providerGoogle / Apple / passwordLet you sign back in

We never see or store your password — authentication is handled by Google Firebase Authentication.

3.2 Profile and goals — health data

Name; avatar (emoji, colour, or photo); units preference; gender; age; height; weight; goal weight; body goal; macro split; activity level; goal speed; calorie/protein/carbohydrate/fat targets; notification preference; food-region country.

3.3 Activity in the app — health data

Food and drink you log (item, quantity, meal, date/time); activities and workouts you log; recipes you create; custom activities; app settings; streaks and statistics derived from the above.

3.4 Apple Health / Health Connect — health data, only with your permission

If you grant access:

This is entirely optional. The app works without it, and you can revoke access at any time in your device settings.

3.5 Photos

3.6 Technical and security data

IP address (recorded automatically in our server request logs); your device’s country code; search queries and scanned barcodes; usage timestamps for rate limiting.

3.7 What we do NOT collect

No advertising identifiers (no IDFA/AAID). No third-party analytics or tracking SDKs. No location beyond a coarse country code. No contacts, no microphone, no precise location. We do not track you across other apps or websites.

Health data is “special category” data under GDPR Art. 9. Sections 3.2, 3.3 and 3.4 are all treated as health data, and dietary logs can reveal health information — so we apply the same protection to all of it.


PurposeDataLegal basis (GDPR)
Create and operate your account§3.1Contract — Art. 6(1)(b)
Provide tracking, goals and statistics§3.2, §3.3Contract — Art. 6(1)(b) and Explicit consent — Art. 9(2)(a) for the health elements
Sync with Apple Health / Health Connect§3.4Explicit consent — Art. 9(2)(a). Granted via your device’s health permission prompt; withdraw any time
Recognise food from a photo§3.5 meal photosConsent — Art. 6(1)(a) and Art. 9(2)(a); you choose to submit each photo
Display your profile photo§3.5 profile photoContract — Art. 6(1)(b)
Look up food and barcode datasearch queries, barcodes, countryContract — Art. 6(1)(b)
Security, abuse prevention, rate limiting, debugging§3.6Legitimate interests — Art. 6(1)(f): keeping the service available, secure and affordable
Comply with legal obligationsas requiredLegal obligation — Art. 6(1)(c)

Withdrawing consent. Where we rely on consent you may withdraw it at any time — revoke health access in device settings, stop submitting photos, or delete your account. Withdrawal does not affect processing already carried out.

Is providing data mandatory? Account data and the profile figures used to calculate your targets are necessary to provide the app — without them it cannot function. Everything else (health sync, photos, avatar) is optional.


5. Automated processing

When you submit a meal photo, an automated AI model estimates what the food is. Nutritional values are then looked up from food databases — they are not invented by the model.

This is not automated decision-making producing legal or similarly significant effects (GDPR Art. 22). It is a suggestion you review, edit, and confirm before anything is saved. It is frequently inaccurate; always check the result.


6. Who we share data with

We do not sell your personal data, and we do not share it for advertising. We use the following processors and third parties:

6.1 OpenAI — meal photo recognition

When you scan a meal photo, a downscaled copy (max 1024px, metadata/EXIF stripped — including any location data) is sent to OpenAI’s API for recognition, together with the photo’s capture timestamp if available.

We do not send your name, email, user ID, or IP address to OpenAI.

OpenAI does not use your photos to train its models. We have disabled every data-sharing option in our OpenAI organisation settings, so nothing we send is used for model training, evaluation, or fine-tuning.

Retention by OpenAI: we send each request with logging disabled, so your photo is not stored in our OpenAI organisation’s records. OpenAI may still hold the request for up to 30 days for its own abuse-monitoring purposes, after which it is deleted. OpenAI does not have access to your identity — only the image and its capture time.

Transfer: United States — see §8.

6.2 Google (Firebase) — authentication, database, file storage

Google Ireland Ltd / Google LLC processes your account, profile, logs and photos on our behalf. Our database and file storage are hosted in the European Union (a multi-region location spanning Belgium and the Netherlands); our application servers run in Belgium (europe-west1). Governed by Google’s Data Processing Terms.

6.3 USDA FoodData Central — nutrition lookup

We send only the search text (typed by you, or a food name derived from a photo). No identifier of any kind. Operated by the U.S. Department of Agriculture — transfer to the United States.

6.4 Open Food Facts — barcode and product data

We send the scanned barcode or search text, plus your device’s country code (used to select the regional database, so Open Food Facts learns your approximate country). No identifier. Product data is provided under the Open Database License (ODbL). Operated from France (EU).

6.5 Other disclosures

We may disclose data where legally required (court order, lawful request), to establish or defend legal claims, or to a successor in a merger or acquisition — in which case we will notify you and this policy will continue to apply until replaced.


7. Community food database — this part is public

When you create a new food item, that entry is added to a shared community food database and becomes visible to, and usable by, other Kaunto users.

Shared: the food’s name, brand, barcode and nutritional values. Not shared: your name, email, or profile. The entry is never labelled with who created it, and no other user sees your identity in the app.

For completeness: each entry does store an internal account identifier recording which account added it, so that you can find and edit your own entries. It is a random identifier — not your name or email — and it is not displayed to anyone, but it is technically readable by other signed-in users. When you delete your account this identifier is removed and the entry is re-saved with no reference to your account at all.

Everything else stays private to your account — your logs, recipes, profile, photos and health data are never shown to other users.

Please do not put personal information in a food name. If you delete your account, previously shared food entries may remain in the database (other users’ logs may depend on them), but as described above they no longer carry any link to you.


8. International transfers

Your account data is stored in the EU. Some processors are in the United States (OpenAI, USDA, and Google as a US parent). Where data leaves the EEA we rely on:

You may request a copy of the relevant safeguards at contact@fabelx.com.


8A. This website

This policy also covers kaunto.app, the website you are reading it on.

The site is a set of static pages. It sets no cookies, runs no advertising or cross-site tracking scripts, and makes no third-party requests — the typeface is served from this domain rather than a font CDN, so loading a page contacts nobody but us. That is also why you are not being asked to accept anything.

If privacy-preserving analytics are enabled, they count page views and referrers in aggregate, without cookies, without fingerprinting, and without anything that identifies an individual visitor.

Our hosting provider processes your IP address in order to serve the page to you, and may retain it briefly in its own security logs.


9. How long we keep it

DataRetention
Account, profile, logs, recipes, settingsUntil you delete your account
Profile photoUntil replaced, or until account deletion
Meal photos (our servers)Not stored at all — processed in memory and discarded
Meal photos (OpenAI)Not retained in our OpenAI records; OpenAI may hold the request up to 30 days for abuse monitoring — see §6.1
Food search cacheAutomatically deleted after 30 days. Not linked to your account.
Rate-limiting recordsUntil account deletion
Server request logs (incl. IP, queries, barcodes, user ID)30 days
Shared community food entriesIndefinitely. Unlinked from you once you delete your account — see §7

We do not maintain separate backups of your data; when your account is deleted, deletion is not delayed by a backup-retention period. Server request logs age out on the 30-day schedule above.


10. Deleting your account

You can delete your account at any time: Profile → Delete account.

This permanently erases your profile, food and activity logs, recipes, custom activities, settings, and your profile photo. It cannot be undone.

Shared community food entries remain in the database but carry no link to you (§7).

Two limited exceptions, both time-bound: server request logs (§9) age out on their own 30-day schedule and are not erased on request; and where we are legally required to retain something, we keep only what the law requires, for as long as it requires.


11. Your rights

Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict processing; object to processing based on legitimate interests; receive it in a portable format (data portability); and withdraw consent at any time.

To exercise any of these, email contact@fabelx.com. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Complaints. You may lodge a complaint with the Romanian supervisory authority:

Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania anspdcp@dataprotection.ro · www.dataprotection.ro

You may also complain to the authority in your own EU country of residence.


12. If you are in California (CCPA/CPRA)

In the past 12 months we collected the categories in §3, for the purposes in §4, from the sources described there.

We have not sold or shared personal information, and we do not sell or share the personal information of anyone under 16. We do not use sensitive personal information for purposes requiring an opt-out right.

You have the right to know, delete, correct, and not be discriminated against for exercising these rights. Contact contact@fabelx.com or use in-app deletion (§10). You may use an authorised agent.


13. Children

Kaunto is not for anyone under 16, and we do not knowingly collect their data. If we learn that we hold data from someone under 16, we delete it. If you believe a child has given us data, contact contact@fabelx.com.


14. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers. Every server endpoint requires a verified authentication token. Access to production systems is restricted, and secrets are held in a managed secret store — never in our source code.

No system is perfectly secure. If a breach affects your rights, we will notify the supervisory authority within 72 hours and you directly where legally required.


15. Changes

We may update this policy. The “Last updated” date will change, and for material changes we will notify you in the app or by email before they take effect. Continuing to use Kaunto after that means you accept the updated policy.


16. Contact

EN PLACE AD S.R.L. Str. Regina Maria nr. 14D, Cluj-Napoca, Județul Cluj, Romania contact@fabelx.com · +40 742 092 489