Privacy Policy – Crumb Counter (iOS and Android)
Last updated: 10 August 2026
1. Scope and overview
This Privacy Policy applies to the “Crumb Counter” (“Krümelzähler”) app for iOS and Android and to the related services provided through api.peppertools.de.
Crumb Counter is intended for the personal documentation of nutrition, weight, water intake, vital measurements and optional GLP-1-related information. The app is not a medical device and does not replace medical advice, diagnosis or treatment.
Most data entered in the app is processed locally on your device. Data leaves your device only when you use one of the functions described in this policy, in particular sign-in, online backup, file import, AI photo analysis, AI voice analysis, food search, bug reports and feature requests, or in-app purchases.
We currently do not use advertising networks, analytics SDKs or cross-app or cross-website tracking in the app. We do not sell personal data.
2. Data controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Charles Imilkowski<br>
PepperTools<br>
Stubbenweg 29<br>
27753 Delmenhorst<br>
Germany<br>
Email: support@peppertools.de
No data protection officer has been appointed.
3. Data processed locally in the app
Depending on how you use the app, you may enter or generate the following data in particular:
- profile and goal data, such as name, date of birth, biological sex, height, activity level, starting weight, target weight and calorie target;
- weight history and notes;
- meals, food items, recipes, quantities, calories and nutritional values;
- water intake and water target;
- blood pressure, pulse, blood glucose, estimated HbA1c and uric acid;
- GLP-1-related information, such as medication, injections, dosage, injection site, food noise, side effects, titration plan, reminders, pens and supplies;
- app settings, units, language and appearance options.
This data is generally stored in the app’s local database. We do not receive it automatically. It is transmitted to our server only when you actively use a corresponding online feature, such as online backup, file import, or AI photo or voice analysis.
Signing out does not delete locally stored tracking data. You can remove data through the available deletion functions or uninstall the app together with its local data. You must delete files exported by you from the storage location you selected.
In the app configuration intended for release, local databases containing health and tracking data are excluded from Apple and Google device/cloud backups. Depending on your system settings, non-sensitive app preferences may form part of a platform backup. We do not operate or receive these system backups; they are governed by the privacy terms of the relevant platform provider. Backup files deliberately exported by you may be synchronized by a storage location or cloud service selected by you.
Processing required to provide the app functions selected by you is based on Art. 6(1)(b) GDPR. Where we as controller process health data as a special category of personal data, the legal basis is your explicit consent under Art. 9(2)(a) GDPR.
4. Account and sign-in
We use Sign in with Apple on iOS and Google Account sign-in on Android. We never receive your Apple or Google password.
4.1 Sign in with Apple
When you sign in with Apple, we process in particular:
- a stable, app-specific Apple user identifier;
- an identity token and authorization code to verify the sign-in;
- depending on your choice, your name and email address, which may be an Apple relay address;
- device model and iOS version;
- account, session and purchase-assignment identifiers generated by us.
4.2 Sign in with Google
When you sign in with Google, we process in particular:
- a stable Google user identifier;
- a Google ID token to verify the sign-in;
- email address, display name and, where available, profile picture URL;
- device manufacturer, device model and Android version;
- account, session and purchase-assignment identifiers generated by us.
This data is processed for account creation, authentication, session management, abuse prevention and assignment of optional purchases. The legal basis is Art. 6(1)(b) GDPR and, for security-related processing, Art. 6(1)(f) GDPR. Our legitimate interest is protecting accounts and systems against unauthorized use.
Apple and Google process data independently in connection with their sign-in services. Further information is available in the Apple Privacy Policy and the Google Privacy Policy.
5. Apple Health and Health Connect
If you enable the feature and grant the system permission, Crumb Counter can read existing body-weight data from Apple Health or Health Connect and import it into the app.
- Access is voluntary and read-only.
- We do not write data back to Apple Health or Health Connect.
- Imported weight values are subsequently stored locally in the same way as weight values entered manually.
- If you later create an online backup or export your data, it may include weight values previously imported from Apple Health or Health Connect.
- Revoking the system permission prevents future access but does not delete values already imported. You must also delete those values in the app.
The legal basis is your explicit consent under Art. 9(2)(a) GDPR. You can revoke the permission at any time in your device’s privacy or health settings.
We do not use Apple Health or Health Connect data for advertising, marketing, profiling or data trading.
6. AI analysis using OpenAI
Crumb Counter offers two optional AI features for estimating foods and nutritional values: analysis of a photo and analysis of a voice recording. Both are handled through our server api.peppertools.de and the OpenAI API. You can use the app without these features.
6.1 AI photo analysis
If you take or select a photo and confirm the analysis, the following processing takes place:
- The app reduces the image size and converts it to JPEG.
- The image is transmitted over encrypted HTTPS and together with your app session to
api.peppertools.de. - Our server normalizes the image and sends it, together with an analysis instruction, to the OpenAI API.
- OpenAI analyzes the image automatically. The result containing estimated foods, quantities, calories and nutritional values is returned to the app through our server.
The upload may contain a photo and nutrition or health information that can be inferred from it. Please use photos of the food only where possible. Do not upload images showing identifiable people, identity documents, addresses or other information concerning third parties.
Our server does not store the uploaded photo permanently. The temporary server file is deleted when the request is completed or aborted. On Android, a local copy taken with the camera may remain temporarily in the app cache until the cache is cleared by the app, the operating system or you.
6.2 AI voice analysis
Voice input lets you describe your meal by speaking instead of typing or photographing it. The feature requires you to grant your device’s microphone permission. If you start a recording and confirm the analysis, the following processing takes place:
- Only after you actively start it, the app records a short voice clip of no more than 30 seconds (mono, compressed AAC format). It is initially stored only temporarily on your device.
- The recording is transmitted over encrypted HTTPS and together with your app session to
api.peppertools.de. - Our server sends the audio file to the OpenAI API, where it is automatically converted into text (speech recognition).
- The recognized text is then sent to the OpenAI API again, together with an analysis instruction, and evaluated automatically.
- The result containing estimated foods, quantities, calories and nutritional values, along with the recognized text, is returned to the app through our server. The recognized text is displayed to you so that you can check it.
No speech recognition takes place on your device. The actual audio recording is transmitted and analyzed, not merely text generated on the device.
The recording contains your voice and anything else audible at the time, including background noise and statements by people present. Nutrition or health information may be inferred from what is spoken. Please describe your meal only and do not record information about third parties or other sensitive content. We do not use the recording to recognize or uniquely identify individuals by their voice; no processing of biometric data for the purpose of unique identification takes place.
The temporary recording on your device is deleted after it is sent, after the analysis is completed, or if you cancel. Our server does not store the audio file permanently: it is held temporarily only for the duration of the request and deleted afterwards, including in the event of an error. We do not permanently store the recording or the recognized text, and we do not write them to logs. The maximum size of a transmitted recording is 5 MB.
6.3 Information applying to both AI features
The recipient and processor is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI may use affiliates and subprocessors outside the European Economic Area. Where required, adequacy decisions or the European Commission’s Standard Contractual Clauses are used for these transfers. Details are provided in the OpenAI Data Processing Addendum.
According to the OpenAI API data controls, API inputs and outputs are not used to train OpenAI models by default unless the API customer expressly opts in to data sharing. By default, OpenAI may retain content and metadata from an API request in abuse-monitoring logs for up to 30 days, unless longer retention is legally required. We do not use the photos, voice recordings or the text recognized from them for our own AI training, advertising or marketing.
The sole purpose is to provide the food and nutrition estimate requested by you. The legal basis is your explicit consent under Art. 6(1)(a) GDPR and, where health data is involved, Art. 9(2)(a) GDPR. Withdrawal applies to future analyses and does not affect the lawfulness of processing completed before withdrawal. You can revoke the microphone permission at any time in your device’s system settings.
AI results are non-binding estimates and may differ substantially from actual values. No decision producing legal or similarly significant effects is made solely by automated means within the meaning of Art. 22 GDPR.
7. Food search and Open Food Facts
For online food searches and barcode lookups, the app connects directly to the public Open Food Facts services. The following data in particular is transmitted to Open Food Facts:
- the search term you enter or the barcode you scan;
- the selected language;
- for technical reasons, your IP address, time of access, device/network information and the app user agent.
Your PepperTools account token is not sent to Open Food Facts. Open Food Facts is an independent controller based in France. According to its privacy policy, IP and access logs may be retained for up to three years. Further information is available in the Open Food Facts Privacy Policy.
The purpose is to perform the food search or barcode lookup requested by you. The legal basis is Art. 6(1)(b) GDPR.
8. File and URL imports
You can import weight data from a file or from a URL entered by you.
- When importing a file, selected CSV, spreadsheet or text files are transmitted in encrypted and authenticated form to
api.peppertools.defor preview and conversion. Depending on its contents, the file may contain personal data or health data. - The conversion service is stateless. Temporary server files are deleted after each request; the converted data is then stored locally in the app.
- Depending on the import flow, the same file may be transmitted more than once for preview and full import.
- When importing from a URL, your device first accesses the address entered by you. The operator of that destination receives technical data including your IP address. The downloaded file is then transmitted to our conversion service as described above.
- Recently used import URLs may be stored locally on your device.
The legal basis is Art. 6(1)(b) GDPR and, where the file contains health data, your explicit consent under Art. 9(2)(a) GDPR.
9. Local and optional online backups
9.1 Local backup
You can create a backup file on your device or at a storage location selected by you. This file is not automatically transmitted to us. It may contain sensitive profile, nutrition, vital-measurement and GLP-1 data. After export, you control its storage, sharing and deletion. Automatic synchronization of that location by Apple, Google or another storage service selected by you is governed by that service’s privacy terms.
9.2 Online backup
If you voluntarily select “Back up online”, a JSON backup file is sent over encrypted HTTPS to api.peppertools.de. It may contain profile, weight, nutrition, water, blood pressure, blood glucose, uric acid, GLP-1 data and app settings. The file is stored in an access-controlled server area separated by account. The backup is not currently encrypted with a separate end-to-end encryption key held only by you.
Only one current online backup is retained. A new backup overwrites the previous one. You can restore or delete the online backup in the app. If you do not use this feature, your tracking data is not transmitted to us for online backup.
The purpose is the backup and restoration requested by you. The legal basis is your consent under Art. 6(1)(a) GDPR and, where health data is included, Art. 9(2)(a) GDPR.
10. In-app purchases and subscriptions
Purchases and subscriptions are processed through the Apple App Store on iOS and Google Play on Android. Apple or Google processes your payment method and payment data under its own responsibility. We do not receive complete credit card, bank account or other payment-instrument data.
To verify purchases and enable or restore premium features, the relevant store and api.peppertools.de process in particular:
- the product or subscription identifier;
- signed transaction data or a purchase token;
- transaction or order identifiers;
- purchase date, status, term, expiry date, renewal, refund or revocation status;
- a pseudonymous account reference linked to your app account.
This data is processed to perform the contract and provide purchased features under Art. 6(1)(b) GDPR, to comply with legal obligations under Art. 6(1)(c) GDPR, and to prevent fraud and duplicate entitlements and to establish or defend legal claims under Art. 6(1)(f) GDPR.
Apple and Google may also notify us server-to-server about renewals, cancellations, refunds or revocations. Further information is available in the privacy terms of Apple and Google.
Deleting your Crumb Counter account does not automatically cancel a store subscription. Manage and cancel subscriptions directly through Apple or Google Play.
11. Bug reports and feature requests
In the app you can voluntarily report a problem or request a feature under “More” → “Bug or feature report”. The function requires a sign-in; anonymous reports are not provided for, because your report has to be linked to your account and we need to be able to reply to you.
When you submit a report, the following is transmitted to api.peppertools.de and stored there:
- the report text you entered;
- the type of report (bug or feature request);
- the language selected in the app;
- the app version, the operating system version and the model designation of your device;
- the reference to your Crumb Counter account and to the sign-in method used;
- any later replies you send within the report.
You decide what the report text contains. Please include only what is needed to describe the problem or request, and avoid health data or other sensitive information unless it is required in order to handle your report. The function does not accept screenshots or file attachments.
The purposes of the processing are handling your report, fixing errors and further developing the app. The legal basis is Art. 6(1)(b) GDPR for handling your request in the context of using the app, and Art. 6(1)(f) GDPR for our legitimate interest in a functioning and improved app. The device model, operating system version and app version are transmitted as well because an error usually cannot be classified and fixed without this information.
You can withdraw a report yourself for as long as we have not processed it; it is then permanently deleted together with its history. Once we have assigned a status or replied, the report is part of an ongoing case and is retained. The app can be used without restriction if you do not use this function.
12. API communications and server logs
When the app connects to api.peppertools.de, in particular for sign-in, session verification, backups, imports, AI analysis, bug reports and feature requests, and purchase verification, technically necessary connection and log data is generated. This may include:
- IP address;
- date and time;
- HTTP method, requested API path, status code and amount of data transferred;
- device/operating-system information and user agent;
- correlation identifier, platform used and limited technical error details;
- transaction and status identifiers required for payment events.
This data is used to deliver the service, analyze errors, maintain stability, apply rate limits, prevent abuse and fraud and ensure IT security. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the app and its interfaces.
API application and error logs are normally retained for seven days. Technical server access logs are generally retained for up to 30 days. Extracts relating to a specific security incident may be retained for longer where necessary to investigate and defend against that incident. We do not intentionally write request bodies, authentication tokens, uploaded photos, voice recordings or the text recognized from them to logs.
The app also generates local operating-system diagnostic logs. These are not transmitted to us automatically. If you voluntarily send us diagnostic information as part of a support request, we process it only to handle that request.
13. Hosting, recipients and processors
We disclose personal data only where necessary for a function described in this policy, secure operation or compliance with a legal obligation. Recipients may include:
- WIIT AG, Joachim-Erwin-Platz 3, 40212 Düsseldorf, Germany, as infrastructure and hosting provider for our rented server;
- Apple for Sign in with Apple, Apple Health and App Store purchases;
- Google for Google sign-in, Health Connect and Google Play purchases;
- OpenAI Ireland Limited as processor for AI photo and voice analysis requested by you;
- Open Food Facts Association, 21 rue des Iles, 94100 Saint-Maur-des-Fossés, France, as an independent controller for search and barcode requests;
- recipients, apps, websites or storage services selected by you when exporting, sharing or importing from a URL.
Where service providers process data on our behalf, they are contractually required to maintain confidentiality, data protection and appropriate security measures. We disclose data only to recipients for which contractual commitments, applicable law or prior assessment ensure protection of the transferred personal data that is at least equivalent to the protection described in this policy. Independent controllers also remain subject to their own statutory data protection obligations.
14. International data transfers
Our own app server is operated in Germany. Open Food Facts is based in France. Apple, Google and OpenAI may use affiliates or subprocessors located outside the European Union or European Economic Area.
Where the European Commission has not adopted an adequacy decision for a recipient country, transfers are based on appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses under Art. 46 GDPR. Further information about the relevant safeguards is available in the privacy terms linked above and in OpenAI’s Data Processing Addendum.
15. Retention periods
We retain personal data only for as long as required for the relevant purpose:
- Local app data: until you delete it or uninstall the app together with its data. Backup files exported by you remain at the selected storage location until you delete them there.
- Account and profile data on our server: until account deletion or for as long as the account is needed for use of the app.
- Session data: until expiry, sign-out, revocation or account deletion.
- Online backup: until you delete or overwrite it, or request its deletion as part of account deletion.
- Temporary AI photos and voice recordings on our server: only for the duration of the request; the temporary file is then deleted. We do not permanently store the text recognized from a voice recording.
- Voice recordings on your device: only until the recording is sent, the analysis is completed or you cancel; the temporary file is then deleted.
- OpenAI API data: under OpenAI’s standard data controls, for up to 30 days in abuse-monitoring logs unless longer retention is legally required.
- Temporary import files: only for the relevant conversion request.
- API application and error logs: normally seven days.
- Server access logs: generally up to 30 days.
- Open Food Facts access logs: according to Open Food Facts, up to three years.
- Purchase, transaction and billing data: for as long as required by a statutory retention obligation, an outstanding payment or refund, or the establishment, exercise or defence of a specific legal claim. Accounting and tax-relevant documents may be retained for up to ten years. Other account links are removed or permanently anonymised when the account is deleted unless one of those reasons requires their temporary retention.
- Bug reports and feature requests: until they have been dealt with and beyond that for as long as the report remains relevant for error analysis and the further development of the app. Reports you withdraw are deleted immediately. If you delete your account, the personal reference is removed and the reported content is retained in anonymised form.
- Support communications: until the request has been resolved and thereafter only where statutory retention obligations or the establishment, exercise or defence of a specific existing legal claim require continued storage.
16. Consent and withdrawal
You can choose not to use voluntary features such as health imports, AI photo analysis, AI voice analysis and online backup without losing the app’s other functions. You can withdraw consent at any time with effect for the future by:
- disabling a system permission;
- deleting an online backup;
- no longer using the relevant optional feature;
- or emailing support@peppertools.de.
Withdrawal does not affect the lawfulness of processing completed before withdrawal. Data already imported or stored locally must also be deleted by you.
17. Account and data deletion
You can:
- delete individual or available data areas within the app;
- delete an online backup in the “Backups” section;
- remove all local app data by uninstalling the app;
- initiate deletion of your Crumb Counter account and associated server-side data directly in the app.
Account deletion is available in the app under “More” or “Settings” → “Account” → “Delete account”. You will be asked to confirm before deletion is finalized.
If you have already uninstalled the app or no longer have access to it, you can request account deletion by email through our public deletion page without reinstalling the app:
Email support@peppertools.de with the subject “Crumb Counter account deletion”. We may need to verify your identity to prevent unauthorized deletion.
After confirmed account deletion, all active app sessions are terminated and directly identifiable profile and session data is deleted or permanently anonymised. For an Apple account, we also initiate revocation of all stored Apple authorisation tokens through Apple’s revocation endpoint and then delete the tokens from our systems. Any online backup is also deleted; where this does not happen automatically, we remove it as part of processing the request. Purchase, transaction, deletion or security records are retained only where required by a statutory retention obligation, an outstanding payment or refund, or a specific legal claim; otherwise, account links are removed or permanently anonymised. We cannot remotely delete local data from your devices; the in-app deletion flow therefore removes it from the device in use or immediately offers local deletion.
Your bug reports and feature requests are not deleted when you delete your account; they are anonymised instead: the reference to your identity and your app account is removed, while the reported content is retained as product knowledge for the further development of the app. No reports are visible in the app afterwards.
Deletion affects your Crumb Counter account only, not your Apple or Google account. It does not cancel an active App Store or Google Play subscription. We process deletion requests without undue delay, normally within one month.
18. Your data protection rights
Subject to the applicable legal requirements, you have the right to:
- access under Art. 15 GDPR;
- rectification under Art. 16 GDPR;
- erasure under Art. 17 GDPR;
- restriction of processing under Art. 18 GDPR;
- data portability under Art. 20 GDPR;
- object to processing based on legitimate interests under Art. 21 GDPR;
- withdraw consent with effect for the future.
To exercise your rights, email support@peppertools.de.
You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is generally the State Commissioner for Data Protection of Lower Saxony.
19. Data security
We use appropriate technical and organizational measures. These include TLS/HTTPS encryption in transit, protected session tokens, access restrictions, account-separated server storage, rate limiting and the minimization and time limitation of log data.
No method can guarantee absolute security. You should therefore protect your device, local backup files and Apple or Google account against unauthorized access.
20. Children
The app is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided data to us without the required consent, please contact support@peppertools.de.
21. Changes to this Privacy Policy
We update this Privacy Policy if app functions, recipients, retention periods or legal requirements change. The current version will be made available on our website and through an easily accessible link in the app. Where legally required, we will provide appropriate notice of material changes.

