HealthSync · Legal
Privacy Policy
Preamble
HealthSync (hereinafter "HealthSync", "the app", "we", "us" or "our") is a personal health-tracking Progressive Web App offered as part of itsmarian's projects and reachable at https://healthsync.itsmarian.dev. The app combines calorie tracking (CalSync), hydration tracking (DropSync) and workout logging in a single interface.
The following Privacy Policy is intended to inform you about the types of personal data (hereinafter also referred to as "data") we process when you use HealthSync, the purposes for which we do so, and the extent of such processing. Because HealthSync handles information about your nutrition, hydration, fitness and goals, parts of the data we process may constitute data concerning health within the meaning of Art. 9 GDPR. We therefore explain these aspects in particular detail below.
The terms used herein are not gender-specific.
Last updated: 18 June 2026
Table of Contents
Controller
Marian D. (operating under the name itsmarian)
Germany
Germany
HealthSync is a personal project of Marian and is provided as part of the itsmarian portfolio of projects.
E-mail address: support@itsmarian.dev
Legal notice / imprint: https://itsmarian.dev/imprint
Overview of Processing Activities
The following overview summarises the types of data processed when you use HealthSync, the purposes of their processing, and the categories of data subjects concerned.
Types of Data Processed
- Account data (e.g. e-mail address, password handled in hashed form by our authentication provider, optional display name).
- Health-related entries (food log, drink log, calorie/macro goals, hydration goal, workout sessions and routines).
- App preferences (theme, onboarding state, AI opt-in, language hints).
- Usage data (which views you open, frequency of interactions for diagnostic and aggregated analytics).
- Meta, communication and procedural data (IP addresses, timestamps, session identifiers, browser/device information).
- Log data (server access logs for hosting and request handling).
Categories of Data Subjects
- Users of HealthSync (registered account holders and unregistered visitors).
- Communication partners (e.g. persons contacting us by e-mail).
Purposes of Processing
- Provision of HealthSync as a contractual / free service and fulfilment of related obligations.
- Operation and synchronisation of your personal food, hydration and workout entries across devices.
- Security measures, fraud prevention and abuse prevention.
- Aggregated and pseudonymous reach/usage analysis (only with your consent).
- AI-based food analysis (only when explicitly enabled by you, with your own API key).
- Communication and user support.
- Information-technology infrastructure (hosting, monitoring, technical operation).
Applicable Legal Bases
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission, and automated individual decision-making including profiling. The data protection laws of the individual German federal states may also apply.
Note on the applicability of the GDPR and the Swiss FADP: These data protection notices serve both to provide information pursuant to the Swiss Federal Act on Data Protection (FADP) and pursuant to the General Data Protection Regulation (GDPR). For this reason, please note that the terminology of the GDPR is used due to its broader geographical scope and comprehensibility.
Legal bases at a glance: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR); legal obligation (Art. 6(1)(c) GDPR); explicit consent for special categories of data, in particular health data, pursuant to Art. 9(2)(a) GDPR.
Health Data (Art. 9 GDPR)
The entries you make in HealthSync - in particular food and drink logs, calorie and macro goals, hydration goals and workout sessions - may, depending on context, constitute data concerning health within the meaning of Art. 4(15) and Art. 9(1) GDPR. We process this data only in order to provide you with the core functionality of HealthSync as expressly requested by you (e.g. saving your food log so that you can see your daily intake).
Legal basis: Your explicit consent pursuant to Art. 9(2)(a) GDPR, which you grant by voluntarily registering for a HealthSync account, enabling cloud synchronisation and actively entering data into the app. Without this consent, cloud synchronisation cannot be provided.
Voluntary nature: You are never obliged to enter any health-related data. You may use HealthSync entirely locally (without an account), in which case your entries remain on your device in your browser's local storage and are not transmitted to our backend.
Withdrawal: You may withdraw your consent at any time with effect for the future by signing out, disabling cloud sync, deleting individual entries or deleting your account. The lawfulness of processing carried out prior to withdrawal remains unaffected.
No medical use: HealthSync is a personal-tracking tool. It is not a medical device, does not provide medical advice and must not be used as a substitute for professional medical consultation, diagnosis or treatment.
Security Measures
We implement appropriate technical and organisational measures in accordance with the applicable legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular: TLS/SSL encryption for all traffic to and from the app and its backend; access protection for the production database; row-level security (RLS) policies in our database backend so that each user can only read and modify their own data; optional Two-Factor Authentication (TOTP) for account login; storage of authentication tokens in secure HTTP cookies; and the principle of data minimisation in our database schema.
Securing online connections via TLS/SSL encryption (HTTPS): All connections between your browser and HealthSync, as well as between HealthSync and its hosting/backend providers, are protected by TLS/SSL. The presence of HTTPS in the address bar indicates that your session is encrypted.
International Data Transfers
Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where such transfer occurs in the context of using third-party services, this is done exclusively in accordance with the applicable legal requirements.
Some of the services we (or you, when you opt in) use may be provided by companies based in the United States, including Vercel (hosting / CDN), Google LLC / Google Ireland Limited (Google Analytics and, where enabled by you, the Google Gemini API). For such transfers we primarily rely on the EU-US Data Privacy Framework (DPF), recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023, and additionally on Standard Contractual Clauses concluded with the respective providers.
Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/.
Information on third-country transfers and applicable adequacy decisions can be obtained from the European Commission's information portal: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Data Retention and Erasure
We erase personal data that we process in accordance with the applicable statutory provisions as soon as the underlying consents are revoked or no further legal grounds for the processing exist.
- Account data: Retained for as long as your HealthSync account exists. Upon deletion of your account, all associated rows in our database (food entries, drink entries, workout sessions, user settings) are deleted without undue delay, subject to any statutory retention obligations.
- Health-related entries: Stored only for as long as you keep them in your account. Individual entries can be deleted at any time from within the app.
- Server log files: Stored for a maximum of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes is exempt from erasure until the final resolution of the relevant incident.
- Local data on your device: Remains in your browser's local storage until you clear it (e.g. through your browser settings, the “sign out” function, or by deleting site data). HealthSync cannot remotely erase data from your device.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time. The lawfulness of processing carried out prior to withdrawal remains unaffected.
- Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed, and to receive information about such data as well as further details and a copy of the data.
- Right to rectification: You have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without undue delay, or alternatively to request the restriction of the processing of such data. For most data, you can directly trigger erasure from within the app (deleting entries, deleting your account).
- Right to data portability: You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
Hosting, Auth and Application Backend
To deliver HealthSync we rely on the following processors, each of which acts as a data processor under Art. 28 GDPR on the basis of a written data processing agreement.
- Types of data processed: Account data; health-related entries (food, drinks, workouts, goals); usage data; meta/communication/procedural data (IP addresses, timestamps, identification numbers); log data.
- Data subjects: Users of HealthSync.
- Purposes of processing and legitimate interests: Provision of HealthSync; information technology infrastructure; security measures; performance of contract; explicit consent for health data (Art. 9(2)(a) GDPR).
- Retention and erasure: Erasure in accordance with the section "Data Retention and Erasure".
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR); explicit consent (Art. 9(2)(a) GDPR) for health data.
Further information on processing activities, procedures and services:
- Vercel (web hosting / CDN): HealthSync is built with Next.js and deployed via Vercel. Vercel provides server-side rendering, edge delivery and access logging. Service provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://vercel.com/legal/privacy-policy. Basis for third-country transfers: Data Privacy Framework (DPF) and Standard Contractual Clauses.
- Supabase (authentication, database, storage): Account management, login sessions and persistent storage of your food, drink, workout and settings data are handled by Supabase. We have configured Row Level Security (RLS) so that each authenticated user can only access their own rows. Session tokens are stored in secure cookies (not localStorage). Service provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992. Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR); explicit consent for health data (Art. 9(2)(a) GDPR). Privacy policy: https://supabase.com/privacy. Data processing agreement: https://supabase.com/legal/dpa.
- Static assets and shared resources (itsmarian static CDN): HealthSync loads shared fonts, design variables and the Font Awesome icon set from https://static.itsmarian.dev, which is operated by us. Loading these assets transmits standard request data (IP address, user agent, referrer). Legal bases: Legitimate interests (Art. 6(1)(f) GDPR) in efficient and consistent design.
- Collection of access data and log files: Access to HealthSync is logged in the form of "server log files". These log files may include the address and name of the pages and files accessed, the date and time of access, the volume of data transferred, a report on successful retrieval, the browser type and version, the operating system of the user, the referrer URL and, as a general rule, IP addresses and the requesting provider. Server log files may be used for security purposes (e.g. to prevent server overload or abusive attacks) and to ensure server utilisation and stability. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days and then erased or anonymised.
Local Storage on Your Device
HealthSync is offline-capable. To make this possible, the app uses your browser's localStorage to persist information such as your food and drink entries, daily goals, selected theme, onboarding state, AI opt-in flag and similar preferences directly on your device.
This local storage is not a cookie within the meaning of § 25 TDDDG / ePrivacy Directive when it is strictly necessary for the operation of the service you have requested (e.g. remembering your last entries so the app works without reload). Where local storage is used for purposes that are not strictly necessary, we will rely on the legal basis applicable to that purpose (typically your consent under Art. 6(1)(a) GDPR).
Local data never leaves your device unless you actively sign in and enable cloud synchronisation. You can clear local data at any time via your browser's site settings or by signing out.
Use of Cookies
The term "cookies" refers to functions that store and retrieve information on users' end devices. Cookies may be used for various purposes, including ensuring the functionality, security and convenience of online offerings, as well as the analysis of visitor traffic. We use cookies in accordance with the applicable legal provisions. Where required, we obtain prior consent from users.
For a full description of the cookies HealthSync uses, please refer to our Cookie Policy.
- Strictly necessary: Including the secure authentication cookies set by Supabase that keep you signed in. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) and Art. 25(2) TDDDG (strictly necessary exemption).
- Analytics (only with consent): Google Analytics is loaded with Google Consent Mode v2 defaulting to "denied" for all storage. Cookies are only set once you give consent in the cookie banner. Legal basis: consent (Art. 6(1)(a) GDPR).
- AI feature flag (only if enabled): When you enable AI Detection in the settings, your preference and your personal API key are stored locally and not in cookies.
General notes on withdrawal and objection (opt-out): You may withdraw any consent you have given at any time via the cookie banner ("Change Cookie Preferences" link in the footer of every page) and via your browser settings.
Registration, Login and User Account
Using HealthSync without an account is possible - all entries are then stored only in your browser's local storage. If you want your data to be synchronised across devices, you may voluntarily create a user account. During the registration process, we collect the data marked as mandatory (e-mail address and a password). Passwords are never stored in clear text; they are hashed by our authentication provider (Supabase Auth).
In the context of registration and login, we additionally process your IP address and the time of each authentication action on the basis of our legitimate interests in protection against misuse and other unauthorised use. This data is not disclosed to third parties unless such disclosure is necessary to pursue our claims or there is a statutory obligation to do so.
- Types of data processed: Account data (e-mail address, hashed password, optional display name, profile picture if you provide one); content data (food, drink, workout entries you create); usage data; log data.
- Data subjects: Registered users of HealthSync.
- Purposes of processing and legitimate interests: Provision of contractual services and cloud sync; security measures; provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the section "Data Retention and Erasure". Erasure upon deletion of the account.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR); explicit consent for health data (Art. 9(2)(a) GDPR).
Further information on processing activities, procedures and services:
- Use of pseudonyms: You may use a pseudonym instead of your real name as your display name.
- User profiles are not publicly visible: HealthSync has no social feed or public profile feature. Your data is visible only to you.
- Erasure on account deletion: When you delete your account, all rows in our database that are associated with your user ID are removed without undue delay, subject only to statutory retention obligations.
- No obligation to retain data: It is your responsibility to back up your data before requesting account deletion. We are entitled to irreversibly erase all data stored for your account once it has been deleted.
Two-Factor Authentication (MFA/TOTP)
HealthSync supports optional Two-Factor Authentication via Time-based One-Time Passwords (TOTP). When you enable MFA, an authenticator secret is generated and stored encrypted by our authentication provider. During login, you provide a six-digit code from your authenticator app, which is verified server-side.
If you choose "Remember this device", your e-mail address is added to a locally stored list (
mfa_trusted_emailsin your browser's localStorage) so that the MFA step is skipped on this device for future logins. You can revoke this trust at any time by clearing the app's site data or signing out.Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in account security (Art. 6(1)(f) GDPR).
AI Detection (Google Gemini, opt-in)
HealthSync offers an optional AI Detection feature inside CalSync which can analyse food photos, camera input or text descriptions and return estimated nutrition values. This feature is strictly opt-in, disabled by default, and uses your own Google Gemini API key. Without an explicit opt-in and a valid API key, no AI request is ever sent.
When you actively trigger an AI request, HealthSync sends the food-related input you provided (image bytes or text description) directly from your browser to generativelanguage.googleapis.com, authenticated with your API key. We do not proxy this traffic through our servers and do not store the request or the model response on our backend.
The processing of that request is governed by Google's terms and privacy policy applicable to the Gemini API: https://ai.google.dev/gemini-api/terms and https://policies.google.com/privacy.
Legal bases: Your explicit consent (Art. 6(1)(a) GDPR) by enabling the feature and confirming the in-app AI terms; for health-related image or text content, additionally your explicit consent under Art. 9(2)(a) GDPR.
For details on how AI is used inside HealthSync, the risks it brings and your responsibilities, please refer to our AI Guidelines.
Barcode Scanner & Open Food Facts
CalSync includes a barcode scanner powered by the open-source ZXing library running entirely in your browser. The camera stream itself never leaves your device - only the decoded numeric barcode is used for product lookup.
When a barcode is scanned, HealthSync queries the public Open Food Facts database to retrieve product information (name, brand, nutrition values). This query transmits the barcode and standard request metadata (IP address, user agent) to Open Food Facts.
Service provider: Open Food Facts (non-profit association), 21 rue des Iris, 94250 Gentilly, France. Privacy policy: https://world.openfoodfacts.org/privacy. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in providing a convenient food lookup feature you have actively triggered by scanning a barcode.
Analytics (Google Analytics, consent-based)
HealthSync loads Google Analytics (GA4) in order to understand how the app is used in aggregated, pseudonymous form (e.g. which views are most popular, on which devices HealthSync runs). Google Analytics is initialised with Google Consent Mode v2, where all storage categories (
ad_storage, ad_user_data, ad_personalization, analytics_storage, functionality_storage, personalization_storage) default to denied. Storage and cookie placement are activated only after you grant consent through our cookie banner.IP addresses transmitted to Google Analytics for EU users are not logged; Google only derives approximate geographic location metadata before discarding the IP. We do not use Google Analytics for advertising purposes.
- Types of data processed: Usage data (pages visited, time spent, click paths, intensity and frequency of use, devices and operating systems used, interactions with content and functions); meta, communication and procedural data (timestamps, identification numbers, derived geolocation).
- Data subjects: Users of HealthSync who have given analytics consent.
- Purposes of processing: Reach measurement; provision of our online offering and user-friendliness.
- Retention and erasure: Cookies are stored for up to two years (or shorter, depending on type). Erasure of cookies takes place automatically or via your browser settings.
- Legal bases: Consent (Art. 6(1)(a) GDPR).
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses. Opt-out plug-in: https://tools.google.com/dlpage/gaoptout.
Contact and Enquiry Management
When you contact us (e.g. by e-mail) and in the context of existing user relationships, the information provided is processed to the extent necessary to respond to your request.
- Types of data processed: Contact data (e.g. e-mail address); content data (textual messages and their content); meta, communication and procedural data (e.g. timestamps).
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback; user support.
- Retention and erasure: Erasure in accordance with the section "Data Retention and Erasure" once the enquiry is resolved and no statutory retention obligation applies.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
Children
HealthSync is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without the consent of a parent or guardian. If you believe that a child has provided us with personal data, please contact us so that we can erase the data.
Changes and Updates
We request that you familiarise yourself regularly with the content of our Privacy Policy. We revise the Privacy Policy as soon as changes to the data processing activities carried out by us make this necessary. We will notify you as soon as changes require an action on your part (e.g. consent) or any other form of individual notification.
Where addresses and contact details of companies and organisations are provided in this Privacy Policy, please note that such details may change over time and we recommend that you verify the information before making contact.
Definitions
This section provides an overview of the terms used in this Privacy Policy. Where terms are defined by law, the statutory definitions apply. The following explanations are intended primarily to aid understanding.
- Account data: Information necessary to identify and administer your HealthSync user account, such as your e-mail address, hashed password, optional display name and any avatar information.
- Content data: Information you create or upload while using HealthSync, in particular food entries, drink entries, workout sessions and routines, custom notes, goals and preferences.
- Contact data: Essential information enabling communication with you, in particular your e-mail address.
- Meta, communication and procedural data: Information about the manner in which data is processed, transmitted and managed, including IP addresses, timestamps, session identifiers and similar log information.
- Usage data: Information that captures how you interact with HealthSync, such as which views you open, how often, on which device type and operating system.
- Personal data: Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
- Health data: Personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status (Art. 4(15) GDPR). Within HealthSync, the food, drink and workout entries you make can constitute health data.
- Log data: Information about events or activities that have been logged in a system or network, such as timestamps, IP addresses, user actions and error messages.
- Reach measurement: Evaluation of the flow of visitors to an online offering, which may encompass visitor behaviour or interests in relation to certain content. HealthSync uses reach measurement only with your consent.
- Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data (Art. 4(7) GDPR).
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means (Art. 4(2) GDPR).