KernBite

Privacy Policy

for the “KernBite” app and the associated server infrastructure

Last updated: 1 September 2026 · Version 1.0

Translation notice: the German version of this privacy policy is authoritative. This English version is a translation provided solely for ease of understanding. The binding German version is available at /datenschutz.

This policy provides information pursuant to Art. 13 and 14 GDPR on the processing of personal data when using KernBite.

§ 1 Controller

The controller within the meaning of the GDPR is:

Jose Daniel Encarnacao
Schwetzinger Str. 16
68775 Ketsch
Germany
E-mail: kontakt@kernbite.de

KernBite is a private project run by a single individual. There is no advertising, no sale of data and no tracking by third parties.


§ 2 Principles and overview

(1) Data minimization. KernBite processes only the data that are necessary for the functioning of the service or that you provide voluntarily.

(2) No advertising, no tracking. No third-party advertising, analytics or tracking services are used. No profiling for advertising purposes takes place.

(3) Pseudonymity. A pseudonym is intended to be used as the user name; the use of your real name is expressly undesired (data minimization).

(4) Local before server. Sensitive evaluations (e.g. InBody import, step data) take place as far as possible exclusively on your device and are not transmitted to the server.


§ 3 Hosting and server location

(1) The server, backend and synchronization infrastructure (database and API) is operated at

netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe

in a data centre at the Nuremberg location, Germany. Processing therefore takes place exclusively within the European Union; no transfer to a third country takes place.

(2) A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider. The hosting provider processes data exclusively on instructions, in order to provide the infrastructure.

(3) Server logs. When the server infrastructure is accessed, technically necessary connection data (e.g. IP address, time, requested resource, status code) may be processed for a short period in order to ensure operation and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR (interest in secure, trouble-free operation). These data are not merged with other data sources and are deleted after a short time.

(4) Backend technology. The backend used is a self-operated instance based on Supabase/PostgreSQL, running on the infrastructure named above. There is no transfer to any independent third party.

(5) Protection against mass sign-ups. Before you register, the server sets a computational task that your device solves in the background. This takes fractions of a second and requires no input from you. Its purpose is to make it harder to create large numbers of accounts automatically. Only random numbers and the expiry time of the task are processed; your IP address is not stored, no cookie is set, no device characteristics are read out, and no third-party service is involved. The mechanism (ALTCHA) runs on the same server as the rest of the service. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing abusive registrations and protecting the deliverability of confirmation messages.


(1) Account and authentication. For sign-in, an e-mail address and a password are processed. The password is stored exclusively as a cryptographic hash. Where access takes place via an access code, this too is stored only as a hash. Purpose: provision and protection of the user account. Legal basis: Art. 6(1)(b) GDPR (contract/user relationship).

(2) Profile and requirement information. Information such as goal, activity level, sex (where stated), age/year of birth and the daily and weekly values calculated from these. Purpose: computational conversion of portions and nutritional values, and planning. Legal basis: Art. 6(1)(b) GDPR.

(3) Body and health data (special category, Art. 9 GDPR). Weight, height, body composition and, where actively used, activity and vital data. These data belong to the special categories of personal data. They are processed exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR. You decide on your own responsibility whether and which of these data you enter. Consent can be withdrawn at any time with effect for the future.

(4) Nutrition and planning data. Nutrition goals, meal and shopping planning, recipe favorites and aversions/intolerances. Purpose: personalization of the recipe and planning functions. Legal basis: Art. 6(1)(b) GDPR; insofar as intolerances have a health-related aspect, Art. 9(2)(a) GDPR (consent).

(5) Groups and challenges. User name, group membership and values shared in joint challenges (e.g. daily check-ins on weight, training, wellbeing). Purpose: operation of the group/contest function you have chosen. Legal basis: Art. 6(1)(b) GDPR; for the health-related aspect, Art. 9(2)(a) GDPR (consent through active participation).

(6) Support communication. If you contact us, we process the information you provide in order to handle your enquiry. Legal basis: Art. 6(1)(b) and (f) GDPR.


§ 5 Visibility in groups and challenges

You are aware that your user name, group membership and the values shared in joint challenges are visible to the other users authorized in each case, and can be stored or copied by them. Further dissemination by third parties cannot be prevented technically. Therefore share only values whose visibility you accept.


§ 6 Local processing: InBody, Garmin, Health Connect

(1) The import of InBody measurements (photo/CSV) and the transfer of activity data from Garmin or Health Connect take place, as far as technically possible, exclusively locally on your device. Image files, CSV files and intermediate results of text recognition (OCR) remain on the device and are not transmitted to the server and not shared with other users.

(2) Health Connect (Android): if you activate it, the app reads step and activity data locally from Health Connect. Access is granted via your device's permissions and can be revoked there at any time. Legal basis: Art. 6(1)(a) and Art. 9(2)(a) GDPR (consent).

(3) InBody, Garmin and Health Connect are third-party offerings and are not part of the service. The respective provider alone is responsible for their data processing; that provider's privacy notices apply. There is no business connection.

(4) For locally stored data, securing the device (screen lock, encryption, updates) and backing up the data are solely a matter for the user. In the event of loss, resetting or uninstallation, local data may be irretrievably lost; there is no entitlement to restoration, since the operator does not hold this data.


§ 7 Recipe images (AI symbolic images)

The recipe images displayed in the app are AI-generated symbolic images, created in advance (not at runtime) with an image model from Google and delivered with the app as fixed image files. No personal data are transmitted to Google when these images are displayed. They are symbolic images that may differ from the actual result.


§ 8 Recipients and transfer to third countries

(1) Personal data are transferred to third parties only insofar as this is necessary for the performance of the contract (processing by the hosting provider, § 3) or a statutory obligation exists.

(2) No transfer to a third country outside the EU/EEA takes place. The servers are located in Germany (§ 3).

(3) App store. The app is obtained via the respective app store (e.g. Google Play). The respective store operator is independently responsible for its data processing.


§ 9 Storage period and deletion

(1) Personal data are stored only for as long as is necessary for the purposes stated or as statutory retention obligations exist.

(2) You can delete your account in the app at any time. When the account is deleted, the associated data stored on the server are deleted or anonymized, unless a statutory retention obligation stands in the way. Values that have already become visible to other users in joint challenges cannot be retrieved from those third parties by the operator (§ 5).

(3) You delete data stored locally on your device by uninstalling the app or deleting the app data.


§ 10 Your rights

Under the GDPR you have the following rights:

  • Access to the data processed about you (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure (Art. 17) and restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Objection to processing based on legitimate interests (Art. 21).
  • Withdrawal of consent given, with effect for the future (Art. 7(3)); the lawfulness of the processing carried out up to that point remains unaffected.

An informal message to kontakt@kernbite.de is sufficient to exercise these rights.


§ 11 Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible is in particular:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart.

You can also contact the supervisory authority of your place of habitual residence.


§ 12 No automated decision-making

(1) Automated decision-making, including profiling, producing legal effects within the meaning of Art. 22 GDPR does not take place. The app merely performs computational conversions on the basis of your information; you alone decide how to use them.

(2) No use of AI services on your data. Your personal data are currently not transmitted to artificial intelligence services and are not used to train such systems. The recipe images under § 7 are not affected by this: they were generated in advance and contain no user data.

(3) Should a function be introduced in future that processes personal data with the help of AI services, this privacy policy will be amended accordingly beforehand, naming the purpose, the legal basis and the provider used. Such processing will take place only after that amendment and, insofar as it is based on consent, only after your express agreement. In doing so, the operator will give preference to providers that process data within the European Union.


§ 13 Minors

The service is not directed at children. Use requires the minimum age laid down in the Terms of Use. We do not knowingly process data of persons who have not reached that age.


§ 14 Data security

Appropriate technical and organizational measures are taken to protect data against unauthorized access, loss and manipulation (including encrypted transmission, storage of passwords only as a hash, access restrictions). Complete protection cannot, however, be guaranteed for data transmission over the internet.


§ 15 Amendments to this privacy policy

This privacy policy may be adapted if the legal situation, the data processed or the functions change. The current version is available in the app and at https://kernbite.de/datenschutz.


Last updated: 1 September 2026 · Version 1.0 · KernBite