Privacy Policy
Document version: 2026-08-02-email-delivery-v1 · Operated from Spain (GDPR + Spanish LOPDGDD)
Notice reviewed: 28/08/2026 · This notice describes first-party Premium journey measurement and reduces its retention without adding purposes or consent.
1. Data controller
- Identity: Rafael Perez
- Address: Trakiafit 2026
- Privacy contact: privacidad@trakiafit.com
A data protection officer has not been formally appointed because the mandatory circumstances in Article 37 GDPR do not apply. The contact above handles all privacy questions and rights requests.
2. Data, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Email and optional name | Identification, access, service communications and interface personalisation. | Performance of a contract (Art. 6(1)(b) GDPR) |
| Food photos and descriptions | AI nutritional analysis. They are sent to Anthropic, OpenAI or Google as processors and retained until you delete them. | Contract + explicit consent (Art. 6(1)(a) and (b)) |
| AI operational metadata | Reliability, cost and quality measurement: provider, model, duration, tokens, estimated cost, technical outcome, fallback, created entry and catalogue matches. It excludes photos, instructions, prompts and full responses. | Contract + legitimate interest in reliability and security (points (b) and (f)) |
| Temporary recipe request | During background generation it may contain preferences and, with “Based on my day”, a structured nutrition summary. The request and context are deleted on reaching a final state. The library retains only the recipe, rating/status and minimum operational indicators; it does not retain free text, goals, intake, history, times, prompts or provider responses. | Contract + explicit consent where nutrition or health may be included (Arts. 6(1)(a)/(b) and 9(2)(a)) |
| Canonical recipes and illustrations | OpenAI moderates public fields. Approved recipes may enter the catalogue and be shared without identity, author, personal reason, request or profile. The internal creator link is not public and is deleted with the account. OpenAI and, on failure, Google receive only title, ingredients and taxonomy for an image that is moderated and re-encoded without metadata. | Contract + legitimate interest in an identifier-free catalogue |
| Voice and transcription | On the web, the browser performs transcription. In the apps, Apple Speech Recognition or Google Speech Recognition may send audio to their respective servers. Trakiafit receives only the text and does not retain audio. | Microphone consent + contract |
| Nutrition, weight and corrections | Your history. Photo meals may retain a minimal history of the initial value and corrections, up to 100 events per entry, without names, notes, images, identifiers, prompts or responses. | Performance of a contract |
| Wellness and activity | Water, weight, steps, active calories, workouts and data authorised from Apple Health or Health Connect. When available, movement accounts for 20% of the daily score; otherwise only nutrition is shown. It does not change calorie targets or TDEE. | Contract + consent to the health integration |
| In-app and push notifications | Send enabled notices and measure their usefulness. The internal ID and first view, open, action, dismiss, resolve or conversion event are retained for 90 days without text, links or health parameters. A random installation ID without hardware or personal data renews the token without disconnecting other devices. Meal times may be inferred from up to 30 complete days, with at least 5 days and a stable pattern. Firebase receives the token and minimum content; lock-screen text excludes weight, calories, protein, fasting, inferred times and foods. | Contract and legitimate interest for functional notices; consent for push and marketing |
| Consumption time and evening caffeine preference | Time-related suggestions and storing “Do not remind me”, without changing other notifications. | Contract + legitimate interest |
| Subscriptions and payments | Premium plans, renewals, cancellations, billing, charge issues and fraud prevention. | Contract + legal obligations (points (b) and (c)) |
| First-party Premium journey stages | Identify in aggregate where the offer → click → checkout → verified trial or purchase journey stops, and correct friction or errors. We retain the internal account ID, a stage and source/feature from allowlists, plan, platform, provider when known, timestamp and a hashed deduplication key. We do not retain URLs, free text, advertising or device IDs, photos, meals, weight, health data or payment payloads. These data are not shared with third parties, are not used for advertising, personalised pricing or automated decisions, and the panel shows aggregated results. | Trakiafit's legitimate interest in finding errors in the optional purchase process and improving its clarity and effectiveness, after necessity and balancing assessments (Art. 6(1)(f) GDPR) |
| Email preferences | Transactional messages, enabled summaries and marketing only with consent. To monitor delivery, Trakiafit retains for 90 days the masked recipient, type/source, status, dates and sanitised reason; it does not retain subject, body, full address, or individual opens or clicks. | Contract, consent or legitimate interest depending on the message |
| IP, user agent and device fingerprint | Sessions, security and abuse prevention. The fingerprint is a hash of user agent, language and encoding; it does not include the IP address, is not shared and is not used for advertising. | Legitimate interest (point (f)) |
| Social features | Username, avatar, friends, groups, points and rankings. Competition is based on habits, never weight. Profiles are private by default and appear in global rankings only when made public. | Contract + consent to enable social features and a public profile |
| Contact form | Respond to support requests. | Legitimate interest |
3. Processors and international transfers
The AI providers Anthropic, Inc., OpenAI, LLC and Google LLC, in the United States, process the photos, instructions and required canonical fields on Trakiafit's instructions (Art. 28 GDPR). Transfers are covered by data processing agreements, Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
| Party | Purpose | Safeguards |
|---|---|---|
| Stripe, Inc. | Web payments. | DPA + SCCs |
| Apple Inc. | App Store payments and, with consent, Apple Ads attribution. | DPA + SCCs + DPF |
| Google LLC | Google Ads conversion on the production web; Google Play, Firebase Analytics/GA4, Android campaign measurement and Firebase Cloud Messaging, according to platform and consent. | DPA + SCCs + DPF |
| Cloudflare, Inc. | Turnstile and network security; it processes IP and browser characteristics to detect bots. | DPA + SCCs |
| Brevo (Sendinblue) | Transactional email and authorised communications; delivery, bounce, spam and unsubscribe events. Trakiafit does not record individual opens or clicks. | EU processor |
| Functional Software, Inc. (Sentry) | Errors; the SDK does not send PII by default and removes tokens, authentication and IP. | DPA + SCCs |
| Apple Health / Health Connect | Import of authorised activity data. | Explicit consent |
| Apple / Google Speech Recognition | Transcription when you tap the microphone; the system may send audio to the relevant provider. | Explicit consent |
| Open Food Facts (French non-profit association) — | Lookup of nutritional information for packaged products when scanning a barcode or searching for food manually — Barcode scanned or search term. Zero personal data of the user. | Performance of contract (Art. 6.1.b GDPR) |
Analytics and campaign measurement remain disabled until consent. On the production web, the Google tag may use _gcl_* identifiers for up to 90 days and receives only completed registration, value and currency, plus IP and the URL with any click parameters; it does not receive email, name or nutrition data. In Android/iOS, Trakiafit sends Firebase an opaque internal identifier, language, platform, plan and a restricted event list. GA4 also processes the app-instance ID, session statistics, approximate location derived from the connection IP (country/region) and basic platform or device-category data automatically. Granular collection is disabled in every region, so it does not collect city, the user-agent string, device brand/model/name, minor versions or screen resolution. GA4 user/event data are retained for up to 14 months. Apple AdServices uses a temporary token that is not retained and does not use IDFA. Personalisation and remarketing remain denied.
4. Retention
- Account: while active or until deletion is requested; sessions: up to 14 days.
- Photos, history, corrections and technical copies: until the entry or account is deleted; the private snapshot is removed when no longer linked to a meal.
- AI metadata: up to 365 days and disconnected from the user when the account is deleted.
- Recipe requests: request and context until a final state. Accounting records and attempts for up to 365 days, removed by the daily process before day 366; anonymous monthly summaries may retain volume, reliability and cost without identifiers or text. The technical deduplication marker linked only to the recipe is deleted with it.
- Personal library: for the life of the account. A removed recipe may retain a link and feedback so it is not suggested again; account deletion removes the association.
- Canonical recipes and illustrations: while active in the catalogue; account deletion removes the library and internal attribution, but non-identifying culinary content may remain.
- Water and weight: until manual or account deletion. Push tokens and random installation ID: until disabled, signed out on that device, or account deletion.
- Inferred times: maximum 30-day window; deleted when reminders are disabled, the time zone changes or the account is deleted.
- Push attribution and notification-centre interactions: 90 days. Security logs: 90 days.
- Email delivery details: 90 days after the attempt; daily cleanup deletes masked recipient, status, dates, sanitised reason and associated events.
- Billing: for the contract and generally up to 6 years afterwards under Spanish commercial and tax obligations.
- First-party Premium journey stages: a maximum of 180 days from each stage, or until account deletion if earlier. Cleanup uses its own cutoff, separate from Firebase/GA4 and Google Ads.
- Contacts: until resolved, maximum 1 year. Consent records: for the life of the account and up to 3 years after closure.
5. Your rights
You may exercise your rights of access, rectification, erasure, portability, withdrawal of consent, objection and restriction free of charge by emailing privacidad@trakiafit.com. On grounds relating to your particular situation, you may object to processing based on legitimate interests, including first-party Premium journey measurement; we will then stop processing unless compelling legitimate grounds override your interests or processing is required for legal claims. We may request additional information only when necessary to verify identity.
In your profile you can correct data, delete the account and download a structured, reconstructable export, including the Premium library and diary link, but not prompts, temporary context or provider responses. Direct export is technically limited to once every 24 hours; an email request is not subject to that limit.
We respond within one month, extendable by two further months for complex or numerous requests, with notice within the first month. You may complain to the Spanish Data Protection Agency: www.aepd.es.
6. Security
We apply technical and organisational measures including bcrypt password hashing, SHA-256-hashed session tokens, HTTPS/TLS, brute-force protection and HTTP security headers. Photos are not public files: they require an authenticated session and an account-bound signed link. To report a vulnerability, see security.txt.