Privacy Policy — Food Moments
Food Moments estimates the nutritional value of your meals from photos and your own words. It was built so that your data stays yours: no advertising, no tracking, and no name — your account is nothing more than your email address. Everything you record is stored in that account, on our own servers in the European Union, with the recent days kept on your iPhone; that is what lets a new iPhone bring everything back, and it comes with two buttons that keep the data yours in practice: one that downloads everything, one that deletes everything. What is sent where — and the one flow that can leave the EU — is described precisely below; the AI analysis and dictation each begin only after you have agreed in the app, and we look at your meals themselves only if you invite us to (§11).
1. Who is responsible
The data controller is Smart Backoffice Solutions B.V., Saal van Zwanenbergweg 11, 5026 RM Tilburg, Netherlands, registered with the Dutch Chamber of Commerce under number 90141482. Contact: info@smart-backoffice.nl.
2. What the app processes, and where it stays
Stored in your account, on our servers in the European Union:
- Your meal photos, notes, corrections and edit history
- The nutritional estimates and your timeline
- Your nutrition profile (birth year, sex, weight, height, activity, calorie goal)
- Your daily targets, day by day — for days based on Apple Health, including the burned-energy figure the target was computed from (see below)
- Your timeline background photos, if you picked your own
- Which of your meal photos and scanned products you have marked as favorites, so they come first when you use one again
- Your app settings: the appearance, when your day starts, whether your activity data comes from Apple Health, and how you like to eat — the protein, fibre, fruit and vegetables, free sugars, fat and salt levels you chose for your daily targets
- Sizes you have told the app about, in your own words — how wide your dinner plate is, what a slice of your bread weighs — kept so the app does not have to guess them again
- The size measurement of each photo your iPhone could measure (see below), together with technical details of how it was made — how steadily the phone was tracking, which surface it found and how sure it was
- A record of each analysis and dictation request for fair use: when it was made, what kind it was, which AI model answered, how long it took, how much data and computing it used, which meal it belonged to and whether it succeeded — never its content (§3)
- Whether you have switched on Help improve Food Moments, and since when (§11)
This storage runs on Microsoft Azure in West Europe (§4). Your iPhone keeps roughly the last two weeks ready to show and fetches older days when you scroll back to them; signing in on a new iPhone restores everything. Deleting the app therefore no longer deletes your data — deleting your account does, completely and in the app (§6, §8).
Your account is deliberately minimal: your email address, and nothing else — no name, no password. You sign in with a one-time six-digit code we email you; each iPhone you sign in on gets its own session, and signing out ends it. Legal basis for the account and for storing your meal data in it: the performance of our contract with you (Art. 6(1)(b) GDPR) — this storage is the service — and, because meals can say something about your health, your explicit consent, which you give when you create the account (Art. 9(2)(a) GDPR). Deleting the account withdraws it.
Apple Health, if you enable "Take activity data from Apple Health": the app reads your resting and active energy on this iPhone to set the day's energy target. The readings stay in Apple Health — they are never sent to the AI model, never used for advertising, and the app never writes to Health. What your account stores is the result: each day's energy target, together with the burned-energy total it was computed from, kept with your daily targets so a past day keeps its true target on a new iPhone.
We also run a gateway that every analysis and dictation request passes through, described in §3. It keeps none of your meal content — photos, notes and recordings travel through it and are gone as soon as the answer comes back. What it does keep is a technical identifier for your device and a record of each request for fair use, both explained in §3.
Sent for a meal analysis (only with your consent, see §3):
- The photos of the meal being analyzed
- Your note and any later corrections for that meal
- Text of nutrition labels and barcode product information found in the photos
- Your meals of the last two weeks in short form — at most 30, each with its time, title and dishes with their portions and calories — so portions stay consistent across days; and the date, time and language of the meal being analyzed
- Once, for each of your meals of the last two weeks that was analyzed before 19 September 2026: its title and dishes with their portions, sugars and weight, in short form, so the app can add free sugars and fruit and vegetables without analyzing the meal again
- The sizes you have told the app about (above), so portions are measured against your own plates rather than average ones
- A size measurement of each photo, where your iPhone could make one: how many centimetres across the picture covers at the surface the food is resting on, how far away and at what angle the camera was held, and the size of the shapes on that surface. Your iPhone works this out by itself while you are framing the shot, from the small movements of your hand and, on models that have one, the depth sensor. No extra pictures are taken and nothing about the room is mapped or kept. Where the measurement is reliable, the app also sends a copy of that photo with a centimetre grid drawn on the surface, so the model can read sizes off it. Photos you pick from your library carry no measurement; a meal someone shares with you keeps the measurement their iPhone made
Sent when you dictate a note (only with your consent, see §3):
- The audio recording of your dictation, to be transcribed into text, together with the last few sentences of the note written so far — typed or dictated — so that words and names stay consistent. Unlike everything else in this list, this one is processed on a worldwide Azure deployment and can therefore leave the European Union — see §3 and §5
Kept only on your iPhone, while something is unfinished:
- A meal you have started but not yet analyzed — its photos, scanned barcodes and typed note — so that the capture screen opens again where you left off if the app is closed, crashes or is ended by iOS; the same goes for a correction you have started on a meal but not yet applied. It stays until you press Analyze or Apply, when it becomes your meal or your correction and is stored in your account as described above, or Cancel, when it is deleted. It is also deleted when you log out or delete your account, and nothing in it is sent for analysis before you press Analyze or Apply
- The recording of a dictation, from the moment it is complete — when you let go of the mic button, or about every minute during a long note — until its text has arrived, normally a second or two, after which it is deleted. If it cannot be sent yet, because there is no network or the service is unavailable, it waits on your iPhone and is sent automatically when the connection returns or you open the app again, and your note fills itself in. A waiting recording is also deleted when you cancel the meal or correction it belongs to, log out or delete your account, and it is never sent without your dictation consent
Both are kept in the app's private storage on your iPhone, protected by iOS encryption and left out of iPhone backups; neither is ever uploaded to your account.
Sent when you scan a barcode, or one is found in a photo:
- The barcode number, looked up in the public Open Food Facts database (§4). The product's name, pack size, nutrition values and photograph come back to your iPhone and are kept there; the photograph is never uploaded to us, never sent for analysis and never travels in a meal you share — your iPhone fetches its own copy from Open Food Facts. Legal basis: our legitimate interest in basing the estimate on the product's own printed values (Art. 6(1)(f) GDPR); the lookup only happens once you have agreed to meal analysis
Sent automatically if the app crashes, freezes or uses too much processor or storage:
- A technical diagnostic report from Apple's own on-device crash detection (MetricKit) — what kind of failure happened, which part of the app was involved, your iPhone model and iOS version, and the app version, so we can find and fix the problem. It carries none of your photos, notes, or anything you typed, and it is stored with this iPhone's installation rather than with your account. Legal basis: our legitimate interest in an app that works (Art. 6(1)(f) GDPR).
Looked at to make the app work better — technical details, never what you ate:
- To find out where the app fails and whether a change fixed it, we look at technical details of how it worked, which are already kept with your meals or on our gateway: for each photo, whether and how well your iPhone could measure it (the measurement's quality, the reason it could not measure, the distance and angle, how steadily the phone was tracking, and whether the surfaces it found agreed with each other); where a photo came from — the camera, your library, or an earlier meal; for each analysis, which AI model answered, how long it took, how many rounds it needed, how much data it carried and whether it succeeded; and the crash reports above. We look at them without your photos, notes, corrections, meal names or nutritional values, and report on them only as totals that do not point to you ("the camera could measure 44 % of photos"). Nothing new is collected for this: these details exist anyway, for the purposes described in this section. Legal basis: our legitimate interest in an app that works and gets better (Art. 6(1)(f) GDPR). You can object at any time by writing to the address in §1; we then leave your account out.
Shared by you, from your iPhone straight to another (nothing passes through us):
- When you share a meal with someone who ate it with you, the meal — its photos and their size measurements, your note, the estimate and its history — goes from your iPhone directly to the recipient you choose, over AirDrop, Messages or whichever app you pick. It does not pass through our servers: we never see it and keep no copy of it. A meal someone shares with you appears in your timeline and is then stored in your account like a meal you photographed yourself.
3. Meal analysis by AI — your consent
To compute an estimate, the app sends the data listed above to an AI model (OpenAI GPT) running on Microsoft Azure servers in the European Union, on our own deployment. What the app sends is used to compute your nutritional estimate — and, only if you have switched on Help improve Food Moments, to improve the app as §11 describes. It is not used to train AI models. Your account carries no name, and the AI model sees nothing of it: what reaches the model is the meal, not who you are.
Every request first passes through our own gateway. This is a small server we operate on Microsoft Azure in the European Union. It exists so that the credentials for the AI service are not inside the app, where anyone could extract them from the downloaded file and run up costs on our account. The gateway checks that a request really comes from an unmodified copy of Food Moments on a genuine Apple device — using Apple's App Attest — and that it belongs to a signed-in account, so that the fair-use limits are counted per account rather than per phone, and then passes it on. For an analysis it inserts your photos from your account's storage into the request; it does not otherwise read what you send, and keeps no copy of it. For fair use and cost control it records, per account, a line for each request: when, what kind, which model, how long it took, how much data and computing it used, which meal it concerned and whether it succeeded. Your photos, notes and recordings never appear in these records or in its logs, and the records are deleted with your account.
For that check your iPhone creates a cryptographic key that never leaves the device, and the gateway stores the key's identifier together with a counter that stops a captured request from being replayed. The identifier is a random value created by this installation of the app: it contains no name, no email address and no device serial number. While you are signed in, our records link it to your account's session, so we treat it as personal data. It is created the first time the app talks to our server — when you sign in — and deleting the app makes it useless. Legal basis for this one technical record: our legitimate interest in protecting the service against abuse (Art. 6(1)(f) GDPR).
The app asks for your explicit consent before the first analysis (legal basis: Art. 6(1)(a) GDPR, and Art. 9(2)(a) GDPR because meals can say something about your health). You can withdraw consent at any time in Settings → Privacy; analysis then stays off until you agree again, and the rest of the app keeps working.
Dictation has its own consent, and one difference worth reading. A spoken note is turned into text by a speech model, also on our own Microsoft Azure deployment — but that deployment is a Global Standard one, because the speech model the app uses is not offered as an EU-pinned deployment. Microsoft routes each request to whichever of its data centres has capacity, which may be outside the European Union, including the United States. Dictation is therefore the one part of Food Moments whose data can leave the EU; §5 describes the safeguards that apply. The app asks before your first dictation (Art. 6(1)(a) GDPR as well) and you can withdraw that consent in the same place; dictation then stays off, and a note can always be typed instead — a note you only type, without dictating into it, stays inside the European Union, in your account like everything else.
Meal photos and notes can incidentally reveal things about you — a diet, an allergy, a fasting practice. We minimize this by sending only the meal being analyzed, keeping the results in your own account where only you can reach them, and storing none of it on our gateway.
4. Service providers
- Microsoft Ireland Operations Ltd. (Azure) provides the infrastructure and processes analysis requests and dictation recordings as our processor, under Microsoft's Data Protection Addendum. This covers the AI deployments, the gateway described in §3 — which runs on Azure Functions in West Europe, with its device identifiers and the crash diagnostics from §2 in Azure Table Storage in the same region — and the storage behind your account (§2): your meals, photos and profile live in Azure storage in West Europe, inside the European Union. The emails that carry a login code or an export link are sent through Azure Communication Services, configured with its data location in the European Union, from noreply@smart-backoffice.nl. The two AI deployments differ in where they run. Meal analysis runs on an Azure EU Data Zone deployment, so those photos, notes and corrections are processed in the European Union. Dictation runs on a Global Standard deployment, because the speech model is not available as an EU-pinned one: Microsoft routes each recording to available capacity in any region worldwide, which may be outside the EU (§5). Microsoft's abuse monitoring checks requests automatically at the time of processing without storing them; only requests flagged as potentially abusive may be stored temporarily for review under Microsoft's standard published procedure — for EU deployments stored and reviewed within the EU — and are deleted afterwards. Microsoft does not use your data to train models.
- Open Food Facts (a French non-profit) receives only the digits of a scanned barcode to return public product information, and your iPhone then fetches that product's photograph from them. As with any internet request, their servers technically see your IP address. Their product data is published under the Open Database License and their photographs under Creative Commons Attribution-ShareAlike 3.0; the app credits their contributors where it shows them.
- Apple distributes the app and, should you ever buy a subscription, processes that purchase as an independent controller under its own terms. Label reading and barcode detection run entirely on your iPhone using Apple's on-device frameworks — no data leaves the device for these.
We share no data with anyone else. We sell no data. There are no analytics or advertising SDKs in the app. This policy covers the app; the website smart-backoffice.nl has its own privacy statement, and uses Google Analytics only after you accept its cookie banner.
5. International transfers
Meal analysis is pinned to Azure's EU Data Zone and is processed in the European Union. The gateway it passes through (§3), the storage behind your account (§2) and the service that sends login-code and export emails (§4) run in the European Union as well, so none of them adds a transfer.
Dictation is not. Its speech deployment is a global one, so the audio of a dictation — and the last few sentences of the note written so far, typed or dictated, which are sent along so that words and names stay consistent — may be processed outside the EEA, including in the United States. That transfer is covered by the EU standard contractual clauses in Microsoft's Data Protection Addendum, together with Microsoft's supplementary measures: encryption in transit and at rest, no use of the data to train models, and no storage beyond the transient abuse monitoring described in §4. Microsoft additionally participates in the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023. Nothing that identifies you accompanies a recording, and your meals, photos and timeline are never part of a dictation request.
If you would rather nothing of yours left the EU, type your notes and do not dictate: the app is fully usable without dictation, and the dictation consent can be withdrawn at any time in Settings → Privacy.
Where Microsoft as a global company could in exceptional cases process support or telemetry data outside the EEA, Microsoft's EU Data Boundary commitments and the same standard contractual clauses apply as safeguards.
6. Retention
Your account's data is kept until you delete it — that is the point of an account. A single meal is deleted by swiping it away, on our servers as well as on the phone; Settings → Account → Delete account erases everything we hold at once — meals, photos, profile, sessions and any export file still waiting. Deleting the app no longer deletes anything: sign in again and everything is back; delete the account when you want it gone.
Everything around the account is short-lived. A login code works once and expires after about ten minutes. The zip made by Download all my data is deleted from our server a few days after it was made (its download link stops working after 24 hours), and like any deleted file it then stays recoverable in our backup for up to 35 days. Nothing you send for an analysis or a dictation is stored on our gateway — it is forwarded and then gone — and Microsoft's transient retention is described in §4.
On your iPhone, an unfinished meal or correction, and a dictation recording still waiting for its text, are kept only as long as §2 describes: until you finish or cancel it, or until its text has arrived — and never past logging out or deleting your account.
The device identifier described in §3 is kept because it is what a request is checked against; it is not yet deleted automatically when an installation stops using the service, so we delete it on request — write to the address in §1 and mention that you want your device registration removed. Its link to your account ends when you sign out or delete the account. It tells us nothing about what you eat.
The fair-use records of §3 — the line per request and the counts per week and month — are kept with your account and deleted with it.
Crash diagnostics (§2) are kept for 90 days and then deleted automatically — long enough to notice and fix a problem, not a permanent record.
Help improve Food Moments (§11) adds no storage of its own: your meals stay in your account. A working copy made for a comparison is deleted when the comparison is done, and in any case within 30 days of you switching the setting off.
We keep backups. Your account is the only complete copy of your meals — your iPhone keeps only the recent days — so we back it up. Photos and files can be restored to any moment in the last 30 days, and the rest of your account is written to a dated file every night and kept for the same 30 days. A file that has been deleted — a photo, or a nightly file that has aged out — stays recoverable for up to 35 days more before it is gone for good. All of it stays with the rest of your data in the European Union and is used for nothing else. One consequence, plainly: deleting your account erases everything we hold in service immediately, but what sits in those backups disappears as it ages out — photos within about five weeks, the nightly copies of your account within 66 days at the latest — rather than in the same instant.
7. Security
Everything sent leaves your device over encrypted connections (TLS), and on the device your data is protected by iOS's built-in encryption and your device passcode. Your account's data also lives on our servers now, so it is protected there rather than by not existing: it is stored on Microsoft Azure in the European Union and encrypted at rest; it can be reached only through the app itself, because every request must prove — via Apple's App Attest (§3) — that it comes from an unmodified copy of Food Moments and must carry a valid session for your account; sessions are per device and end when you sign out; and the server stores session tokens only as hashes, so a stolen copy of our records could not be used to sign in as you. There are no passwords to steal: a login code arrives by email, works once, and dies after minutes.
8. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time without affecting the lawfulness of processing before the withdrawal. The app is built so that you exercise them directly, without writing to anyone:
- Access: the app shows you your meals, profile and settings, and the download below contains all of it, including what the app does not show, such as the photo measurements. For the rest — the fair-use records of §3, crash reports, the device identifier — write to us and we send you a copy.
- Rectification: correct any meal in the app; change your profile in Settings.
- Portability: Settings → Account → Download all my data has the server pack everything — every photo, a set of pages you can browse on any computer, a table a spreadsheet can read, and one data file with everything your account holds, corrections, profile, settings and daily targets included — and email you a download link.
- Erasure: swipe a meal away, or delete everything at once with Settings → Account → Delete account.
- Withdrawing consent: analysis and dictation in Settings → Privacy, Help improve Food Moments with its own switch (§11).
- Objection: to our use of technical details (§2), by writing to us; we then leave your account out.
For anything else, or questions, contact info@smart-backoffice.nl — we answer within one month. You also have the right to lodge a complaint with a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), but you may contact the authority of your own country.
9. Children
Food Moments is not directed at children, and we knowingly process no children's data. If you believe a child has created an account, write to the address in §1 and we will delete it.
10. Changes
If the app's data flows change, this policy is updated before the change ships, with the effective date above.
Every change is published on the support page. Small ones — wording, grammar, a typo, a clarification that does not change what happens to your data — are announced there and nowhere else.
A change with substantial implications for your data is announced in the app as well, before it takes effect. And a genuinely new data flow that processes what you photograph, write or say — the kind analysis and dictation are — needs more than an announcement: it does not start until you have agreed to it. A new technical signal about the app itself, like the crash diagnostics in §2, changes nothing about how your meals or account are handled; it is disclosed rather than gated, the same way the device identifier in §3 already is.
11. Helping improve Food Moments — only if you switch it on
Food Moments gets better by seeing where its estimates go wrong, and the amount on the plate is where they go wrong most. Under Settings → Help improve Food Moments there is a switch that lets us use your meals for exactly that. It is off unless you switch it on.
What you allow when you switch it on. We — the people at Smart Backoffice Solutions B.V. who make Food Moments, and nobody else — may look at the meals in your account: the photos, your notes and corrections, the estimates and their history, and the size measurements that come with the photos. We use them for one purpose: to find out where the app's estimates go wrong and why, and to check whether a change to the app makes them better. To check a change, we may send a meal through the analysis again with the improved instructions, on the same Microsoft Azure deployment in the European Union that analyzes your meals (§4); the answer is compared with the original and never changes the meal in your timeline. Meals can say something about your health — a diet, an allergy, how much you eat — so this needs your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR). The switch is that consent: its label says what you agree to, switching it on is agreeing, and the app shows the date you did.
What it never allows. Your meals are not used to train AI models, ours or anyone else's. They are not shared with anyone, not sold, not published and not used for advertising. What we learn is kept as general findings and totals ("the first estimate was 15 % off on average") that do not point to you. Nobody will contact you because of it.
Where your meals stay. In your account, in the European Union, as before. When a comparison needs a working copy — a photo next to its old and new estimate — that copy is kept only on our own encrypted computers, for as long as the comparison runs, and deleted afterwards.
Switching it off. You can switch it off in the same place at any time, as easily as you switched it on; your other iPhones follow within minutes. From then on we no longer look at your meals, and we delete any working copy of them without delay, at the latest within 30 days. Withdrawing does not undo what was done before it (Art. 7(3) GDPR), and general findings that no longer point to you stay. Nothing else in the app changes either way. Deleting your account switches it off too, and signing in with another account starts with it off.