Privacy Policy
Quanto has no accounts. No email, no password, no username. Food and weight data is stored in the European Union and is never used to train AI models.
This is a translation. The Italian version at launchd.online/quanto/it/privacy is the authoritative text and prevails in case of conflict.
Last updated: 8 September 2026 · Version 1.0
This policy explains what personal data the Quanto app collects, why, how long it is kept and what rights you have. It is written under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Who processes your data
The data controller is:
launchd, a sole trader established in Italy.
Email for data protection matters: support@launchd.online
Contact form: launchd.online/contact
No Data Protection Officer has been appointed, as the conditions of Article 37 GDPR do not apply. Write to the address above for any request.
2. In short
- You are not asked to create an account. No email, no password, no username. The app creates an anonymous identifier on your phone.
- Food and weight data is health data. It is processed only with your explicit consent and stored on servers in the European Union (Frankfurt, Germany).
- Meal photographs are sent to the United States to OpenAI to be recognised. This is the most important part of this policy and has its own section, §5.
- We do not sell your data, we do not run profiled advertising, and we use no behavioural analytics.
- We do not use your photographs to train AI models, ours or anyone else's.
- You can delete everything from inside the app, at any time, without asking anyone.
3. What we collect
3.1 Data you enter
| Data | Where it goes |
|---|---|
| Name (optional) | Profile |
| Sex, date of birth, height | Profile |
| Current weight, goal weight, desired pace | Profile |
| Activity level, goal (lose, maintain, gain) | Profile |
| Dietary preferences, stated obstacles, usual meals | Profile |
| Daily calorie and macronutrient target | Profile |
| Logged meals: foods, ingredients, grams, calories, protein, carbs, fat | Diary |
| Meal photographs | Photo storage |
| Scanned barcodes | Diary |
| Values read from nutrition labels you choose to submit | Product contributions. The label photograph itself is not retained: it is processed and discarded. |
| Free-text corrections (for example “no béchamel”) | Diary |
Some of this, in particular weight, goal weight, eating habits and photographs of what you eat, is health data, that is, a special category under Article 9 GDPR. It is processed with heightened protection and only on the basis of your explicit consent.
3.2 Data the app generates
| Data | Why it exists |
|---|---|
| Anonymous user identifier (UUID) | Links your records together. Not linked to your name or email. |
| Eight-character support code | Used solely to identify your data if you write to us. |
| Daily scan count | Enforces the daily limit. |
| Record creation and modification timestamps | Ordering the diary. |
3.3 What we do NOT collect
- No email address, phone number, username or password.
- No location data.
- No advertising identifier (IDFA) and no cross-app or cross-site tracking.
- No behavioural analytics or usage measurement tools.
- No access to Apple Health, HealthKit or other health apps.
- No access to contacts, microphone or location.
- No payment data: cards and billing details are handled entirely by Apple and are never disclosed to us.
4. Why we process your data, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Recognising food from a photograph and calculating nutrition | Photographs, ingredients | Explicit consent, Art. 9(2)(a) GDPR |
| Keeping the food diary and showing your history | Meals, ingredients, photographs | Explicit consent, Art. 9(2)(a) GDPR |
| Calculating your daily calorie and macro target | Profile, weight, goal | Explicit consent, Art. 9(2)(a) GDPR |
| Showing weight, trend and averages | Weight, history | Explicit consent, Art. 9(2)(a) GDPR |
| Running the app and its synchronisation | Anonymous identifier, records | Performance of a contract, Art. 6(1)(b) GDPR |
| Managing the subscription and access rights | Subscription state | Performance of a contract, Art. 6(1)(b) GDPR |
| Enforcing the daily scan limit and preventing abuse | Scan count | Legitimate interest, Art. 6(1)(f) GDPR: service sustainability and security |
| Answering your support requests | Support code, message content | Legitimate interest, Art. 6(1)(f) GDPR |
| Improving the product database from labels you submit | Label photograph, values read | Consent, Art. 6(1)(a) GDPR, given at the moment of submission |
| Meeting legal obligations (tax, accounting) | Transaction data received from Apple | Legal obligation, Art. 6(1)(c) GDPR |
You can withdraw consent at any time by deleting your data in the app or writing to us. Withdrawal does not affect the lawfulness of processing carried out beforehand. If you withdraw consent for health data, the app can no longer perform its main function.
5. Photographs and artificial intelligence
This is the section to read carefully, because it describes the only point at which your data leaves the European Union.
How it works. When you photograph a plate, the photograph is sent from our server to OpenAI, Inc., a company based in the United States, which processes it with a vision model and returns the dish name, the ingredient list, estimated grams and nutritional values. The same happens when you photograph a nutrition label.
What is sent. The photograph alone, plus the text instructions needed for the analysis. Your name, weight, goal, user identifier and any other profile data are not sent.
What does not happen. The photographs are not used to train OpenAI's models. Processing takes place through OpenAI's API, for which the provider contractually undertakes not to use transmitted data for training.
Basis for the transfer. The provider participates in the EU-U.S. Data Privacy Framework, found adequate by the European Commission's adequacy decision of 10 July 2023, which is the primary basis for the transfer. In addition and cumulatively, the transfer is covered by the standard contractual clauses approved by the European Commission (Implementing Decision (EU) 2021/914), incorporated in the data processing agreement with the provider.
What this means. United States public authorities could, in circumstances provided for by local law, request access to data processed on US territory. The safeguards above aim to limit that risk but cannot eliminate it entirely. We tell you this explicitly so you can decide knowingly.
Where the photographs are stored. After recognition, the photograph is stored on servers in Frankfurt, Germany, in storage where each photograph is accessible only to the user who uploaded it. It is not retained by OpenAI beyond the technical time needed for processing.
6. Where your data is
| Data | Location |
|---|---|
| Profile, diary, meals, weight | European Union, Frankfurt (Germany) |
| Meal photographs | European Union, Frankfurt (Germany) |
| Local copy of the diary | On your iPhone |
| Photograph processing | United States, for the duration of processing (§5) |
| Subscription state | United States (§7) |
The infrastructure is hosted in the European Union deliberately, precisely because this is health data.
7. Who we share your data with
We do not sell, rent or trade your personal data. We share it only with the providers that make the service work, each acting as a processor under a contract pursuant to Article 28 GDPR.
| Provider | Role | Where | What it receives |
|---|---|---|---|
| Supabase | Database, authentication, photo storage | European Union (Frankfurt) | All diary and profile data |
| OpenAI | Photograph and label recognition | United States | The photograph only (§5) |
| RevenueCat | Subscription state management | United States | Anonymous user identifier and subscription state. No health data. |
| Apple | App distribution and payment processing | United States and European Union | Transaction data. Apple acts as an independent controller under its own policy. |
We may also disclose data to judicial or competent authorities where necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.
If the business or a branch of it is transferred, data may pass to the acquirer. In that case we will notify you in advance inside the app and you may delete your data before the transfer.
8. How long we keep data
| Data | Retention |
|---|---|
| Profile, diary, meals, weight, photographs | Until you delete it |
| Daily scan count | Until you delete your account |
| Values extracted from submitted labels | The values remain in the product database in a form not attributable to you. The label photograph itself is not retained. |
| Tax and accounting records for subscriptions | 10 years, as required by Italian law |
| Support correspondence | 24 months from closure of the request |
If you delete the app without deleting your data, the data stays on our servers. The anonymous identifier, however, lives in your phone's keychain and is lost on uninstall: from that moment nobody, including us, can link that data back to you. For this reason we recommend using the delete function inside the app before uninstalling it.
9. Your rights
Under Articles 15 to 22 GDPR you have the right to:
| Right | How to exercise it |
|---|---|
| Access (Art. 15) | Data export in Settings, or write to support@launchd.online |
| Rectification (Art. 16) | Every value is editable directly in the app |
| Erasure (Art. 17) | Settings → delete account. Immediate and permanent. |
| Restriction (Art. 18) | Write to support@launchd.online |
| Portability (Art. 20) | Data export in Settings, in a machine-readable format |
| Objection to processing based on legitimate interest (Art. 21) | Write to support@launchd.online |
| Withdrawal of consent (Art. 7) | At any time, without affecting prior processing |
We respond within 30 days, extendable by a further two months in the complex cases provided for by Article 12(3) GDPR, with notice to you.
A limitation you should know about. Because there is no account with an email and password, we cannot verify your identity in the usual way. To exercise your rights by email you will need to give us the support code found in Settings. Without it we cannot locate your data, and we cannot delete or hand over data to someone we cannot identify as its subject. This is inherent in the choice not to require an account, and it is why deletion from inside the app is the most reliable route.
Complaints. If you believe the processing of your data breaches the law, you have the right to lodge a complaint with the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it, or with the supervisory authority of the Member State where you reside.
10. Children
The service is not intended for children under 14, in line with Article 8 GDPR as implemented in Italy. We do not knowingly collect data from children under 14. If you become aware that a child under 14 has given us personal data, write to support@launchd.online and we will delete it.
11. Security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- database-level isolation, under which each user can read and write only their own rows and photographs, enforced by the server rather than by the app;
- privileged access keys never present in the app installed on the phone;
- system access limited to the controller.
No system is absolutely secure. In the event of a personal data breach likely to result in a high risk to your rights, we will notify you without undue delay as required by Article 34 GDPR, and inform the Garante within 72 hours.
12. No automated decision-making
We carry out no processing producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
Food recognition is automated, but it produces an editable estimate that carries no legal consequence and remains under your control: you can correct any value by hand.
13. Changes to this policy
If we change this policy we publish the new version at this address with a different update date. If the changes concern the purposes or legal bases for processing health data, we notify you inside the app and, where necessary, ask for fresh consent.
14. Contact
For anything about your personal data, write to support@launchd.online or use the contact form.
Quanto is not a medical device and does not replace the advice of a doctor or a nutritionist.