Karbi

Privacy notice

Version 4

1. Who we are

Karbi is operated by, and your data is controlled by, Deme Szabolcs Barnabás, sole proprietor (registration number: 57683711; registered seat: 3321 Egerbakta, Felszabadulás utca 14/A, Hungary). You can reach us about privacy at privacy@karbiapp.com. We have not appointed a data protection officer, because the GDPR (Art. 37) does not require one for processing of this scale; we will re-assess as the service grows. Privacy questions go to the address above. The full set of provider details is in the Legal notice.

2. What Karbi does

Karbi estimates nutritional values from meal photos, keeps a meal log on your device, optionally in an account with cloud sync, and can accept optional product-label contributions. It provides nutritional information only. It is not a medical device and does not give medical or insulin-dosing advice.

We do not sell your data, use it for advertising, or track you across other apps.

3. What stays on your device

Meal entries, nutritional values, meal times, saved thumbnails, your dietary settings, your language choice and this acknowledgement are stored in the app's local storage. Karbi does not receive this device database unless you enable cloud sync or deliberately submit information through another feature. With cloud sync switched on, the meal log items and settings listed in section 8 also live on our servers.

Local data stays until you delete entries, clear the app's data, or uninstall the app. A deleted entry stays in the app's deleted-entries list for 30 days so you can restore it, and the app removes it from the device after that. Your device's own backup service may copy it under its own terms.

If you sign out of your account, the account's copy on this phone is removed only once everything has been uploaded. If anything is still waiting to go up, the app asks you first, because your phone is then holding the only copy of it.

4. Meal estimates

An estimate request contains a resized meal photo with its metadata removed, and your app language. It contains no name and no text you typed, and the photo carries no location. It also carries what the free allowance is tied to: either a pseudonymised usage identifier for this device, or your account session when you are signed in.

To enforce the free allowance we have to count what has been used. When you are not signed in, the request carries a pseudonymised usage identifier for this device: Android's app-set device identifier, or an identifier the app generated for itself where the device has none. We store it only as a salted hash together with a count, and the value itself is never stored and never written to a log. Even though the identifier says nothing about who you are, the salted hash is pseudonymised personal data rather than anonymous data: we cannot recover the identifier from it, but it still counts as data about you under the law. When you are signed in, the request carries your account session instead and the count is kept on your account. Every estimate request counts, including one that turns out to show no food. The legal basis is our legitimate interest (Art. 6(1)(f)) in limiting what the AI providers' work costs us and in preventing abuse of the free tier. We have carried out the balancing test the law requires for this interest and will send it to you on request. You can object to this counting at the address above; without the count we cannot offer the free allowance. We keep the hashed identifier and its count for as long as we run the free allowance, because the allowance is granted once per device and this record is what stops it being granted a second time; deleting the app does not reset it. The record holds no name and we cannot trace it back to you. The counter on your account is deleted when your account is deleted.

To produce two independent readings, the photo is sent to Anthropic and to Google. If one of them is unavailable, OpenAI may be used instead. They act as our processors: they process the photo on our behalf under data-processing agreements, namely their business API terms, and they do not use it to train their models. They do this outside the European Economic Area, on the basis of the European Commission's standard contractual clauses (SCC); a copy of these safeguards can be requested at privacy@karbiapp.com.

Our backend does not keep the meal photo after the estimate is returned. Our servers keep ordinary security logs of connections, including the IP address, for at most 30 days, on our legitimate interest in keeping the service secure. Those logs do not contain the photo or the request contents.

5. Barcode lookups

When you scan a barcode, the app asks our product database for that barcode and your app language. Nothing is stored about the lookup and it is not linked to you.

6. Optional label contributions

If you contribute a photo of a product label, we receive the barcode, the market and app language, the front-of-package and nutrition-label photos, a random identifier generated when the app was installed, the time of the submission, the values read from the label, and technical hashes used to detect duplicates and abuse.

Photos are re-encoded and their location and device metadata removed before they leave your phone. Please keep people and unrelated personal information out of the frame.

We do this to check the label, improve the shared product catalogue, keep auditable evidence of where a value came from, and prevent abuse. The legal basis is our legitimate interest (Art. 6(1)(f)) in a reliable, abuse-resistant catalogue. Contributing is optional and is not needed to use meal estimates or your meal log. You can object using the contact address above.

Photos of rejected submissions are deleted within 30 days. A submission that is still waiting for a second person's confirmation is kept at most 12 months, then deleted. Once confirmed, the photo is removed from normal access immediately and deleted after a further 30 days. The install identifier and the submission record are kept for 12 months after that installation's last submission, then deleted or irreversibly anonymised. Product facts that no longer relate to a contributor may remain in the catalogue.

Publishing a contributed label photo to other users is a planned feature that is not switched on today. If it arrives, it will be separate and optional, and we will tell you before it starts.

7. Your account

An account is optional. You can sign in with Google. Cloud sync is available only with an account; everything else in the app works without one.

When you sign in, we store the identifier Google uses for your account, your e-mail address, the time the account was created, and hashed session tokens that keep you signed in. We do this to sign you in and to keep your account for you; the legal basis is the performance of our contract with you (Art. 6(1)(b)). The sign-in itself goes to Google, which acts as an independent controller for it rather than as our processor: it receives that request under its own terms, may process the sign-in data outside the European Union, and what it does with it is described in Google's privacy policy.

We keep this for as long as the account exists. "Delete account" in Settings removes the account, its sessions, its usage counters, and every synced item and thumbnail.

8. Cloud sync

The purpose of cloud sync is to make your meal log available on every device signed in to your account and restorable after a lost or replaced phone. Cloud sync is off unless you switch it on. It takes an account and your separate, explicit consent, given in Settings as a standalone confirmation. We never ask for it as part of signing in and never as a step of the first run.

With it switched on, the app uploads and keeps on our servers: your meal entries (their names, nutritional values, amounts, meal times and the other fields stored with an entry), the entries in your deleted list, the foods you defined yourself, the edit history of your entries, the 512-pixel meal thumbnails, and your settings (your carb and energy targets and display mode, your meal schedule, the reminder preference and the theme). The full-size photo taken for an estimate is never kept.

It is stored in the European Union, in Frankfurt, Germany, by our hosting provider and our database provider, who process it for us under data-processing agreements.

The legal basis is your explicit consent (Art. 9(2)(a)), together with Art. 6(1)(a), because a meal log kept in a diabetes context can reveal health data. Automated decision-making is not involved; section 11 explains this for the whole app.

You can pause sync at any time in Settings: uploads stop and nothing is deleted. You can also withdraw your consent at any time in Settings: withdrawal erases your synced meal log, thumbnails and settings from our servers immediately, and only the record of your consent and of its withdrawal is kept, as the retention paragraph below sets out. The app keeps working fully with the data on your phone either way.

When you withdraw consent or delete your account, deletion happens in steps: your synced data disappears from the server at once, a record of the fact of deletion remains there for at most 90 days, and for 5 years we keep only a record of when you gave and withdrew your consent. We keep synced data while your consent is in force. An entry you delete stays 30 days in the deleted list on the server too, then is removed. A record that an item was permanently deleted is kept 90 days, so your other devices learn that it is gone. The record of your consent and of its withdrawal is kept for 5 years after the withdrawal or after the account is deleted, on our legitimate interest in being able to prove that your consent was valid if a dispute ever arises; 5 years is the general limitation period for claims under the Hungarian Civil Code, which we use as the yardstick for how long such a dispute could arise.

9. If you contact us

If you write to us, we process your message and contact details to answer you and to document the request.

10. Who else is involved

The AI providers named above act as our processors: they process the meal photo for us under data-processing agreements, namely their business API terms. They do this outside the European Economic Area, on the basis of the European Commission's standard contractual clauses (SCC); a copy of these safeguards can be requested at privacy@karbiapp.com.

Our other service providers only receive what they need for their task and are bound by data-processing agreements: our hosting provider and our database provider, in the European Union (Frankfurt, Germany), for accounts, the free-allowance counters and cloud sync; our product-database provider for barcode lookups and label contributions; and Sentry for crash reports, on servers in the European Union.

If you sign in, Google runs the sign-in itself and receives that request under its own terms, as the controller of its own service.

If you subscribe to the newsletter, it is sent for us by EmailOctopus (Three Hearts Digital Ltd., London, United Kingdom), which keeps subscriber data on servers in the European Union (Ireland); the United Kingdom is covered by the European Commission's adequacy decision. EmailOctopus delivers the e-mails through its own sub-processors, SendGrid and SparkPost, companies headquartered in the United States, under the standard contractual clauses in its agreements with them.

11. Where the data comes from, and automated processing

Data comes from you, from your device, and from what AI models read out of the photos you submit. Nothing here is required by law. A photo is technically necessary for a photo estimate; an account, label contributions and cloud sync are optional.

AI models produce the estimates and read the labels, and automated checks can reject a label contribution. These do not have legal or similarly significant effects on you. The results can be wrong and should always be verified.

12. Your rights

You can ask for access to your data, correction, deletion, restriction, portability, or object to processing based on our legitimate interest, and withdraw a consent you have given. Withdrawing does not affect processing that already happened lawfully. We do not keep the meal photo, so the photo behind a past estimate cannot be produced; the entry it resulted in is in the log on your phone and, with cloud sync switched on, in your account. The usage counter on your account and everything you have synced are covered by access, portability and deletion through your account, and you withdraw your consent to cloud sync in Settings.

We normally answer within one month. You can also complain to the National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11; postal address 1363 Budapest, Pf. 9; ugyfelszolgalat@naih.hu; www.naih.hu - or go to court.

13. Crash reports

If the app stops working, it can send us an anonymous crash report so we can find the fault and fix it. This is switched on by default. You can switch it off at any time in Settings, under Diagnostics, and the first-run setup shows you the same switch.

A report contains the technical description of the crash and where in the code it happened, plus technical details about your device and the app: your device model, your Android or iOS version, your language, your time zone and the Karbi version. It carries no screenshot, no account, no name and no e-mail address, and no identifier for your installation unless you switch on the crash id described below. We do not send your photos or your logged meals, and reports are not meant to carry anything you type. We do not keep the IP address a report arrives from.

The legal basis is our legitimate interest in keeping the app working: we cannot fix a fault we never hear about, and a report anonymous enough to say nothing about you is a proportionate way to hear about it. Switching the toggle off is an objection and it takes effect immediately, so nothing further is collected or sent from that moment.

Crash reports are processed for us by Sentry, on servers in the European Union, under a data-processing agreement.

You can also switch on a crash id. It is off unless you turn it on, in Settings under Diagnostics or during the first-run setup, and it is the only part of crash reporting we ask your agreement for. The legal basis for it is your consent, which you can withdraw at any time and as easily as you gave it. Everything above keeps working if you never switch it on.

The crash id is a random value your phone creates when you switch this on. It is used only inside crash reporting: it is not your account, it is not the identifier the app sends with label contributions, and we do not link it to anything else we hold about you. All it lets us see is that several crash reports came from the same installation. Switching the setting off deletes it from your phone, and switching it on again creates a new one, so reports from before and after a withdrawal cannot be connected.

14. Newsletter

If you ask for it, we send you the Karbi newsletter: news about the app, a few times a year. Nobody is subscribed by installing the app, by creating an account or by signing in; the box you tick for it starts unticked, in the first-run setup, after a sign-in and in Settings.

What we process: the e-mail address you give us (or, if you subscribe while signed in, the address of your Google account), when you subscribed, which screen you did it on, the app language and the app version. We keep this as the record of your consent. If you type the address yourself, we first send a confirmation e-mail, and you are only subscribed once you open the link in it; an address that is not confirmed is not written to. The newsletter carries app news only: nothing you log, and nothing about your health, is used to decide what you receive.

The legal basis is your consent (GDPR Art. 6(1)(a)). You can withdraw it at any time, with the unsubscribe link in every e-mail or in Settings, and we stop sending at once. Deleting your account, or wiping the app's local data, unsubscribes you as well. Withdrawing does not affect the sending that happened before it.

The newsletter is sent for us by EmailOctopus as our processor; section 10 says where. We keep the record of your consent, and of your unsubscribing, for as long as you are subscribed and for the limitation period afterwards, so we can show that the sending was lawful. When you unsubscribe, your address is marked as unsubscribed at the sending service and receives nothing further from us.

15. Changes

We will update this notice before we materially change what we do with your data, and show it to you again when that happens.