Privacy Policy

Last Updated: December 23, 2025

This Privacy Policy describes how Have Your Cookie collects, uses, and protects your personal information. We are committed to GDPR compliance.

1. Data Controller

The data controller responsible for your personal data is:

Dr. Friedrich Georg Fröbel
Humboldtstr. 69
22083 Hamburg, Germany
Email: friedrich@haveyourcookie.com

2. Data We Collect

Account Information
• Email address
• Password (encrypted)

Health & Nutrition Data
• Weight, height, age, and gender
• Nutrition goals and activity level
• Food logs and calorie data
• Progress and tracking data
This data is considered sensitive under GDPR and is processed with your explicit consent.

Technical Data
• Device type and operating system
• App version
• IP address (for security purposes)
• Usage analytics

3. How We Use Your Data

Provide the Service: Calculate calories, track nutrition, and personalize your experience
Account Management: Create and manage your account
Communication: Send service-related notifications and respond to inquiries
Improvement: Analyze usage to improve the App
Security: Protect against fraud and unauthorized access

4. Legal Basis for Processing

We process your data based on:

Consent: For health data and optional features
Contract: To provide the services you requested
Legitimate Interest: For security and service improvement
Legal Obligation: When required by law

5. Data Sharing & Third-Party Services

We do not sell your personal data. We may share data with:

Service Providers: Infrastructure services that help us operate the App
Legal Requirements: When required by law or to protect our rights

Third-Party Services We Use:

Supabase (Database & Authentication)
Data is stored in the EU (Frankfurt region). Supabase provides secure database hosting and user authentication services.
Privacy Policy →

Vercel (Hosting)
Our application is hosted on Vercel's edge network. Vercel processes technical data necessary for serving the application.
Privacy Policy →

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. When you delete your account, we delete your personal data within 30 days, except where retention is required by law.

7. Your Rights (GDPR)

Under GDPR, you have the right to:

Access: Request a copy of your personal data
Rectification: Correct inaccurate data
Erasure: Request deletion of your data
Portability: Receive your data in a portable format
Restriction: Limit how we process your data
Objection: Object to certain processing activities
Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at friedrich@haveyourcookie.com.

8. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit and at rest. However, no method of transmission over the Internet is 100% secure.

9. International Data Transfers

Your data is primarily stored within the EU. When data is processed outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

10. Children's Privacy

The App is not intended for users under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware of such collection, we will delete the data promptly.

11. Cookies & Local Storage

As a Progressive Web App, we use local storage to save your preferences and session data on your device. This data remains on your device and is used to provide a seamless experience.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy in the App. Continued use after changes constitutes acceptance.

13. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Email: friedrich@haveyourcookie.com