Guiltfree Privacy Policy
Effective date: 20 September 2026. Version: 1.0.
Guiltfree is a mobile app that turns a cooking video, link or screenshot into a recipe with nutrition estimates, and offers a lighter version of the same dish. This policy explains what data the app handles, why, for how long, who processes it and what your rights are. It is written in plain English on purpose. Where a law needs a specific term, it is in brackets.
1. Who is responsible
The app is published by Anthony Terjesen, an individual trader based in the Netherlands (the "controller" under the GDPR).
- Address: Keurenplein 41 (A1874), 1069 CD Amsterdam, Netherlands
- Email: support@guiltfreeapp.fit (privacy questions: the same address, subject "Privacy")
- Phone: +1 945-203-5909
2. What we collect and why
Data you give us
| Data | Why we use it | Legal basis |
|---|---|---|
| Recipes you import (the link or screenshot you share, and the recipe we build from it), your notes, ratings, cookbooks, grocery lists | To provide the app: this is the product | Performance of a contract (the Terms) |
| Screenshots or photos you choose to import | To read a recipe from them; the original image is deleted within 24 hours of processing unless you keep it as the recipe photo | Contract |
| Unit system, age bracket (never a birthday), sex, height, current weight, goal weight, activity level, goal, target date | To build your daily calorie target and the guiltfree engine's brief, and to show your progress | Your explicit consent, given by ticking the box on the weight step. Weight and goals are health data; you can skip that step and still use the app |
| Email address or name, only if you later create an account with Apple, Google or email | To let you sign in on another device and recover your library | Contract |
| Answers to "how did you hear about us" and your cooking-time preference | To improve the app and to time reminders | Legitimate interest (understanding how people find and use the app) |
Data collected automatically
| Data | Why | Legal basis |
|---|---|---|
| A random user identifier created when you first open the app (an anonymous account) | To keep your recipes together without asking you to sign up | Contract |
| Product analytics: which screens are opened, when an import starts and finishes, when a guiltfree version is made, paywall views, subscription outcomes. Sent to PostHog under the random identifier only, never with your weight, goals, recipes or email | To see which features work and which do not | Legitimate interest (improving the app). No advertising identifiers, no cross-app tracking, no session recordings |
| Subscription status (free, trial, paid) and the Apple transaction reference, via Superwall | To unlock paid features and honour your purchase | Contract |
| A push notification token, if you allow notifications | To send the reminders you asked for | Consent (the system permission) |
| Crash and error reports, if we add a crash reporter later | To fix bugs | Legitimate interest |
| Technical logs on our servers (timestamps, job status, error messages), which may include the link you imported | To run and secure the service | Legitimate interest |
What we do not collect: your date of birth, phone number, contacts, precise location, advertising identifier, device fingerprint, full photo library, or free-text health notes. We do not sell personal data and we do not use it for advertising.
3. How the AI part works
When you import a video or link, our server fetches the public post (its caption, and where available its subtitles or thumbnail), and sends that text and image to an AI model to write the recipe, estimate the nutrition and suggest lighter swaps. Nutrition for everyday ingredients comes from a reference table built from the US Department of Agriculture's public food database, not from the model. Your weight, goals and name are not sent to the AI provider; the guiltfree engine only receives your goal type (lose, maintain, gain) and protein target. Estimates are estimates: see the Terms for the health disclaimer.
4. Who processes data for us
We use these service providers ("processors"). Each is bound by a contract to process data only on our instructions.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage. Holds your recipes, profile and images | EU (Frankfurt, Germany) |
| Railway | Runs the server that processes imports | United States |
| Anthropic | AI model that structures recipes and plans swaps. Inputs and outputs are deleted within 30 days and are not used to train models | United States |
| OpenAI | Speech-to-text (Whisper) for videos with no captions. Audio is deleted from our side straight after processing; OpenAI keeps API inputs for up to 30 days for abuse monitoring and does not train on them | United States |
| Apify | Fetches public posts from Instagram, TikTok and YouTube when those platforms block direct access | Czech Republic (EU) |
| PostHog | Product analytics, under your random identifier only | EU (Frankfurt, Germany) |
| Superwall | Paywalls and subscription status | United States |
| Apple | App distribution, payments, push notifications | United States and worldwide |
| Expo (EAS) | App build and update delivery, push notification relay | United States |
Transfers to the United States are covered by the EU Standard Contractual Clauses (and the UK Addendum for UK users), or by the provider's participation in the EU-US Data Privacy Framework where it applies.
5. How long we keep data
- Your recipes, profile and settings: until you delete them or delete your account.
- Source videos and audio: deleted within an hour of processing. Screenshots you import: within 24 hours unless kept as the recipe photo.
- Raw transcripts and import job logs: 30 days. Failed job records: 90 days.
- Analytics events: 12 months.
- Anonymous accounts that never saved a recipe: deleted after 90 days.
- After you delete your account: everything above is removed immediately, and from backups within 30 days.
6. Your rights
You can, at any time:
- Export your data (Progress, Settings, Export my data): a file with everything we hold about you.
- Delete your account (Progress, Settings, Delete account): removes your account, recipes, images and profile within minutes, no email needed.
- Ask us to correct or restrict data, object to processing based on legitimate interest, or withdraw consent (untick the weight consent, or delete your account). Email support@guiltfreeapp.fit.
We answer within 30 days. If you are in the EU you can complain to the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); in the UK, to the ICO (ico.org.uk).
California residents: you have the right to know, delete and correct personal information and to opt out of sale or sharing. We do not sell or share personal information for cross-context advertising, and we do not discriminate for exercising your rights. Use the in-app tools or the email above.
7. Children
The app is for people aged 13 and over. The weight-loss plan is only available to users who state they are 18 or over. We do not knowingly collect data from children under 13; if you believe we have, email us and we will delete it.
8. Security
Data travels encrypted (TLS). The database enforces row-level access so one user can never read another's data. Sign-in sessions on your phone are stored encrypted. Our servers never expose the keys that can read the database; the app only carries a public key with limited rights. We review security before each release.
9. Changes
We will post changes here with a new effective date, and tell you in the app for anything material.
10. Contact
support@guiltfreeapp.fit. Postal address above.