v1.0 · 08.08.2026
Status: 08.08.2026 Scope: GDPR Art. 13, 14, Art. 9 GDPR Controller: flowgeist
The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: info@flowgeist.de Web: https://foodapp.flowgeist.de
Data Protection Officer: Pursuant to Art. 37 GDPR and § 38 BDSG, no data protection officer has been appointed at this time, as the requirements of § 38 (1) BDSG (as a rule, employment of at least 20 persons continuously engaged in automated processing) are not met. Contact person for data protection matters: datenschutz@flowgeist.de (interim).
This Privacy Policy informs you about the processing of personal data by the flowgeist FOOD app, in particular the processing of health data within the meaning of Art. 9 GDPR as well as nutrition and photo data. The app is distributed as a Progressive Web App (PWA) at foodapp.flowgeist.de and as a native app for iOS and Android via the respective app stores.
We process your data exclusively on the basis of statutory provisions and only to the extent necessary for the provision and operation of the app. Due to the processing of health data (Art. 9 GDPR), the app is subject to special protection requirements, which are detailed in this Privacy Policy.
The flowgeist FOOD app processes health data within the meaning of Art. 9 (1) GDPR. This includes in particular:
Legal basis: The processing of these special categories of personal data is carried out on the basis of Art. 9 (2)(a) GDPR, i.e., on the basis of your explicit consent. Consent is obtained separately before the first recording of health data and logged (with timestamp, IP address, and version of the consent declaration).
You may withdraw your consent at any time without affecting the lawfulness of the processing carried out up to the withdrawal. Withdrawal results in the immediate deletion of the affected health data, unless other retention obligations exist.
The app processes the following categories of personal data:
| Data Category | Description | Examples |
|---|---|---|
| Master data | Basic user data | Name, email address |
| Health data (Art. 9 GDPR) | Specially protected data | Allergies, intolerances, dietary goals |
| Nutrition data | Recorded nutrition data | Nutrition diary, food items, nutritional values, meals |
| Photo data | Food item photos | Images for AI-powered food item analysis |
| Access data | Authentication data | Apple/Google Sign-In token, session token |
| Device and app data | Technical metadata | Device ID, app version, operating system, language |
| Audit data | Logging data | Access logs, change logs, consent logs |
Your personal data is processed for the following purposes:
The processing of personal data is carried out on the following legal bases:
| Legal Basis | Scope of Application |
|---|---|
| Art. 6 (1)(b) GDPR | Processing for the performance of the user contract (nutrition tracking, app operation) |
| Art. 6 (1)(a) GDPR | Processing on the basis of consent (analytics/error tracking opt-in) |
| Art. 6 (1)(f) GDPR | Processing for the protection of legitimate interests (error tracking, security, audit trail) |
| Art. 9 (2)(a) GDPR | Processing of health data on the basis of explicit consent |
Legitimate interest (Art. 6 (1)(f) GDPR): The legitimate interest of flowgeist consists in ensuring the security, stability, and freedom from errors of the app. This includes in particular error tracking for rapid error resolution and the maintenance of an audit trail for security purposes.
Your personal data is disclosed to the following recipients:
| Recipient | Location | Purpose | Third-Country Transfer |
|---|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany (DE) | Hosting, PostgreSQL 16, MinIO Object Storage, Redis Cache | None (EU) |
| Mistral AI SAS | France (FR) | Mistral Vision API for photo-based food item analysis | None (EU-only) |
| Sentry (Functional Software, Inc.) | USA (US) | Error tracking, error diagnosis | EU-US Data Privacy Framework + Standard Contractual Clauses (SCC) |
| Apple Inc. | USA (US) | Apple Sign-In authentication | Subject to Apple privacy policy |
| Google LLC | USA (US) | Google Sign-In authentication | Subject to Google privacy policy |
Disclosure to Apple and Google takes place exclusively within the framework of authentication (Sign-In). Only the data required for use (name, email address) is transmitted.
The primary processing of your personal data takes place in Germany (Hetzner Online GmbH, Falkenstein). The database (PostgreSQL 16), the object storage (MinIO), and the cache (Redis) are operated exclusively in Germany.
Third-country transfers:
Sentry (USA): For error tracking, minimized error data (no health data, PII-minimized) is transmitted to Sentry in the USA. The transfer is carried out on the basis of the EU-US Data Privacy Framework (DPF), to which Sentry is subject, as well as additionally on the basis of Standard Contractual Clauses (SCC) of the European Commission. Health data within the meaning of Art. 9 GDPR is not transmitted to Sentry.
Mistral AI (France): The photo-based food item analysis is performed via the Mistral Vision API, operated by Mistral AI SAS in France. France is a member state of the European Union, so there is no third-country transfer. The provisions of the GDPR apply directly.
Apple/Google (USA): When using Apple Sign-In or Google Sign-In, authentication data is transmitted to Apple or Google. Both companies are subject to the EU-US Data Privacy Framework.
The storage duration depends on statutory retention periods and the purpose of processing. Upon expiry of the respective period, the data is deleted, unless other retention obligations exist.
| Data Category | Storage Duration | Remarks |
|---|---|---|
| Master data | 30 days after account deletion | Period for exercising data subject rights |
| Health data (Art. 9 GDPR) | 30 days after account deletion; immediately upon withdrawal of consent | Immediate deletion upon withdrawal |
| Nutrition data | 30 days after account deletion | — |
| Photo data | 30 days after account deletion | — |
| Audit logs | 3 years | Statutory retention obligation, security purposes |
| Sentry data | 30 days | PII minimized, automatic deletion |
You have the following rights under the GDPR:
10.1 Right of Access (Art. 15 GDPR) You have the right to request information from us as to whether and which personal data concerning you is being processed, as well as further information about the circumstances of processing and a copy of the data.
10.2 Right to Rectification (Art. 16 GDPR) You have the right to request the rectification of inaccurate and the completion of incomplete personal data.
10.3 Right to Erasure (Art. 17 GDPR) You have the right to request the erasure of your personal data, provided that the processing is not necessary for the fulfillment of a legal obligation or for the establishment, exercise, or defense of legal claims.
10.4 Right to Restriction of Processing (Art. 18 GDPR) You have the right to request the restriction of the processing of your personal data, in particular during the review of a request for rectification or erasure.
10.5 Right to Data Portability (Art. 20 GDPR) You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and to transmit it to another controller.
10.6 Right to Object (Art. 21 GDPR) You have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1)(f) GDPR. In the event of an objection, we will no longer process your data unless we can demonstrate compelling legitimate grounds.
10.7 Right to Lodge a Complaint (Art. 77 GDPR) You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
10.8 Withdrawal of Consent (Art. 7 (3) GDPR) You have the right to withdraw any consent given at any time with effect for the future. Withdrawal does not affect the lawfulness of the processing carried out up to the withdrawal. Withdrawal of consent to the processing of health data results in the immediate deletion of this data.
To exercise the rights listed above, you may contact us at any time:
Email: info@flowgeist.de Data protection: datenschutz@flowgeist.de
We will respond to your request without undue delay, and in any event within one month of receipt (Art. 12 (3) GDPR). If processing takes longer, we will inform you of the reasons and the expected duration within one month.
For identification purposes, we may request additional information to ensure that the information is not disclosed to unauthorized third parties.
Automated decision-making within the meaning of Art. 22 GDPR does not take place. The AI-powered analyses (photo-based food item analysis using the Mistral Vision API, personalized recommendations) serve exclusively as a support function and require human review by the user. The results of the AI analysis are non-binding and do not constitute a binding decision that produces legal or similarly significant effects on the user.
The flowgeist FOOD app uses the following tracking and cookie technologies:
Technical cookies / session tokens:
Sentry error tracking:
No other analytics services (e.g., Google Analytics, tracking pixels) are used.
To protect your personal data, in particular health data (Art. 9 GDPR), flowgeist implements the following technical and organizational measures:
A detailed description of the technical and organizational measures can be found in the separate TOMs document.
The photo-based food item analysis of the flowgeist FOOD app uses the Mistral Vision API, an AI-powered feature within the meaning of the EU AI Act (Regulation (EU) 2024/1689).
Transparency obligations:
Art. 50 (2) EU AI Act (Digital Omnibus): From December 2, 2026, obligations for machine-readable labeling (watermarking) of AI-generated content apply. flowgeist will implement these obligations in a timely manner and ensure that AI-generated analyses and recommendations are labeled accordingly.
When authenticating via Apple Sign-In or Google Sign-In, only the data required for the use of the app is transmitted:
Apple and Google process this data under their own privacy policies and terms of use. For processing within the framework of authentication, Apple and Google are each separate controllers. Further provisions on data protection at Apple can be found at https://apple.com/legal/privacy, and at Google at https://policies.google.com/privacy.
flowgeist reserves the right to adapt this Privacy Policy to ensure that it always reflects current legal requirements or responds to changes in the app or services. The current version is available on the website at https://foodapp.flowgeist.de/datenschutz.
In the event of material changes that affect the processing of your data, we will inform you in advance of their entry into force and, if necessary, obtain renewed consent, where required.
If you have questions about data protection, the processing of your personal data, or the exercise of your data subject rights, please contact:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: datenschutz@flowgeist.de
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The competent supervisory authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) Postfach 20 04 44 40102 Düsseldorf Web: https://www.ldi.nrw
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version for flowgeist FOOD |
© 2026 flowgeist – Ralf Carsjens · All rights reserved