Privacy Policy — Food Moments

Effective date: September 19, 2026. This policy is available in English, German, Dutch, Spanish, French and Portuguese; the English version is authoritative.

Food Moments estimates the nutritional value of your meals from photos and your own words. It was built so that your data stays yours: no advertising, no tracking, and no name — your account is nothing more than your email address. Everything you record is stored in that account, on our own servers in the European Union, with the recent days kept on your iPhone; that is what lets a new iPhone bring everything back, and it comes with two buttons that keep the data yours in practice: one that downloads everything, one that deletes everything. What is sent where — and the one flow that can leave the EU — is described precisely below; the AI analysis and dictation each begin only after you have agreed in the app, and we look at your meals themselves only if you invite us to (§11).

1. Who is responsible

The data controller is Smart Backoffice Solutions B.V., Saal van Zwanenbergweg 11, 5026 RM Tilburg, Netherlands, registered with the Dutch Chamber of Commerce under number 90141482. Contact: info@smart-backoffice.nl.

2. What the app processes, and where it stays

Stored in your account, on our servers in the European Union:

This storage runs on Microsoft Azure in West Europe (§4). Your iPhone keeps roughly the last two weeks ready to show and fetches older days when you scroll back to them; signing in on a new iPhone restores everything. Deleting the app therefore no longer deletes your data — deleting your account does, completely and in the app (§6, §8).

Your account is deliberately minimal: your email address, and nothing else — no name, no password. You sign in with a one-time six-digit code we email you; each iPhone you sign in on gets its own session, and signing out ends it. Legal basis for the account and for storing your meal data in it: the performance of our contract with you (Art. 6(1)(b) GDPR) — this storage is the service — and, because meals can say something about your health, your explicit consent, which you give when you create the account (Art. 9(2)(a) GDPR). Deleting the account withdraws it.

Apple Health, if you enable "Take activity data from Apple Health": the app reads your resting and active energy on this iPhone to set the day's energy target. The readings stay in Apple Health — they are never sent to the AI model, never used for advertising, and the app never writes to Health. What your account stores is the result: each day's energy target, together with the burned-energy total it was computed from, kept with your daily targets so a past day keeps its true target on a new iPhone.

We also run a gateway that every analysis and dictation request passes through, described in §3. It keeps none of your meal content — photos, notes and recordings travel through it and are gone as soon as the answer comes back. What it does keep is a technical identifier for your device and a record of each request for fair use, both explained in §3.

Sent for a meal analysis (only with your consent, see §3):

Sent when you dictate a note (only with your consent, see §3):

Kept only on your iPhone, while something is unfinished:

Both are kept in the app's private storage on your iPhone, protected by iOS encryption and left out of iPhone backups; neither is ever uploaded to your account.

Sent when you scan a barcode, or one is found in a photo:

Sent automatically if the app crashes, freezes or uses too much processor or storage:

Looked at to make the app work better — technical details, never what you ate:

Shared by you, from your iPhone straight to another (nothing passes through us):

3. Meal analysis by AI — your consent

To compute an estimate, the app sends the data listed above to an AI model (OpenAI GPT) running on Microsoft Azure servers in the European Union, on our own deployment. What the app sends is used to compute your nutritional estimate — and, only if you have switched on Help improve Food Moments, to improve the app as §11 describes. It is not used to train AI models. Your account carries no name, and the AI model sees nothing of it: what reaches the model is the meal, not who you are.

Every request first passes through our own gateway. This is a small server we operate on Microsoft Azure in the European Union. It exists so that the credentials for the AI service are not inside the app, where anyone could extract them from the downloaded file and run up costs on our account. The gateway checks that a request really comes from an unmodified copy of Food Moments on a genuine Apple device — using Apple's App Attest — and that it belongs to a signed-in account, so that the fair-use limits are counted per account rather than per phone, and then passes it on. For an analysis it inserts your photos from your account's storage into the request; it does not otherwise read what you send, and keeps no copy of it. For fair use and cost control it records, per account, a line for each request: when, what kind, which model, how long it took, how much data and computing it used, which meal it concerned and whether it succeeded. Your photos, notes and recordings never appear in these records or in its logs, and the records are deleted with your account.

For that check your iPhone creates a cryptographic key that never leaves the device, and the gateway stores the key's identifier together with a counter that stops a captured request from being replayed. The identifier is a random value created by this installation of the app: it contains no name, no email address and no device serial number. While you are signed in, our records link it to your account's session, so we treat it as personal data. It is created the first time the app talks to our server — when you sign in — and deleting the app makes it useless. Legal basis for this one technical record: our legitimate interest in protecting the service against abuse (Art. 6(1)(f) GDPR).

The app asks for your explicit consent before the first analysis (legal basis: Art. 6(1)(a) GDPR, and Art. 9(2)(a) GDPR because meals can say something about your health). You can withdraw consent at any time in Settings → Privacy; analysis then stays off until you agree again, and the rest of the app keeps working.

Dictation has its own consent, and one difference worth reading. A spoken note is turned into text by a speech model, also on our own Microsoft Azure deployment — but that deployment is a Global Standard one, because the speech model the app uses is not offered as an EU-pinned deployment. Microsoft routes each request to whichever of its data centres has capacity, which may be outside the European Union, including the United States. Dictation is therefore the one part of Food Moments whose data can leave the EU; §5 describes the safeguards that apply. The app asks before your first dictation (Art. 6(1)(a) GDPR as well) and you can withdraw that consent in the same place; dictation then stays off, and a note can always be typed instead — a note you only type, without dictating into it, stays inside the European Union, in your account like everything else.

Meal photos and notes can incidentally reveal things about you — a diet, an allergy, a fasting practice. We minimize this by sending only the meal being analyzed, keeping the results in your own account where only you can reach them, and storing none of it on our gateway.

4. Service providers

We share no data with anyone else. We sell no data. There are no analytics or advertising SDKs in the app. This policy covers the app; the website smart-backoffice.nl has its own privacy statement, and uses Google Analytics only after you accept its cookie banner.

5. International transfers

Meal analysis is pinned to Azure's EU Data Zone and is processed in the European Union. The gateway it passes through (§3), the storage behind your account (§2) and the service that sends login-code and export emails (§4) run in the European Union as well, so none of them adds a transfer.

Dictation is not. Its speech deployment is a global one, so the audio of a dictation — and the last few sentences of the note written so far, typed or dictated, which are sent along so that words and names stay consistent — may be processed outside the EEA, including in the United States. That transfer is covered by the EU standard contractual clauses in Microsoft's Data Protection Addendum, together with Microsoft's supplementary measures: encryption in transit and at rest, no use of the data to train models, and no storage beyond the transient abuse monitoring described in §4. Microsoft additionally participates in the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023. Nothing that identifies you accompanies a recording, and your meals, photos and timeline are never part of a dictation request.

If you would rather nothing of yours left the EU, type your notes and do not dictate: the app is fully usable without dictation, and the dictation consent can be withdrawn at any time in Settings → Privacy.

Where Microsoft as a global company could in exceptional cases process support or telemetry data outside the EEA, Microsoft's EU Data Boundary commitments and the same standard contractual clauses apply as safeguards.

6. Retention

Your account's data is kept until you delete it — that is the point of an account. A single meal is deleted by swiping it away, on our servers as well as on the phone; Settings → Account → Delete account erases everything we hold at once — meals, photos, profile, sessions and any export file still waiting. Deleting the app no longer deletes anything: sign in again and everything is back; delete the account when you want it gone.

Everything around the account is short-lived. A login code works once and expires after about ten minutes. The zip made by Download all my data is deleted from our server a few days after it was made (its download link stops working after 24 hours), and like any deleted file it then stays recoverable in our backup for up to 35 days. Nothing you send for an analysis or a dictation is stored on our gateway — it is forwarded and then gone — and Microsoft's transient retention is described in §4.

On your iPhone, an unfinished meal or correction, and a dictation recording still waiting for its text, are kept only as long as §2 describes: until you finish or cancel it, or until its text has arrived — and never past logging out or deleting your account.

The device identifier described in §3 is kept because it is what a request is checked against; it is not yet deleted automatically when an installation stops using the service, so we delete it on request — write to the address in §1 and mention that you want your device registration removed. Its link to your account ends when you sign out or delete the account. It tells us nothing about what you eat.

The fair-use records of §3 — the line per request and the counts per week and month — are kept with your account and deleted with it.

Crash diagnostics (§2) are kept for 90 days and then deleted automatically — long enough to notice and fix a problem, not a permanent record.

Help improve Food Moments (§11) adds no storage of its own: your meals stay in your account. A working copy made for a comparison is deleted when the comparison is done, and in any case within 30 days of you switching the setting off.

We keep backups. Your account is the only complete copy of your meals — your iPhone keeps only the recent days — so we back it up. Photos and files can be restored to any moment in the last 30 days, and the rest of your account is written to a dated file every night and kept for the same 30 days. A file that has been deleted — a photo, or a nightly file that has aged out — stays recoverable for up to 35 days more before it is gone for good. All of it stays with the rest of your data in the European Union and is used for nothing else. One consequence, plainly: deleting your account erases everything we hold in service immediately, but what sits in those backups disappears as it ages out — photos within about five weeks, the nightly copies of your account within 66 days at the latest — rather than in the same instant.

7. Security

Everything sent leaves your device over encrypted connections (TLS), and on the device your data is protected by iOS's built-in encryption and your device passcode. Your account's data also lives on our servers now, so it is protected there rather than by not existing: it is stored on Microsoft Azure in the European Union and encrypted at rest; it can be reached only through the app itself, because every request must prove — via Apple's App Attest (§3) — that it comes from an unmodified copy of Food Moments and must carry a valid session for your account; sessions are per device and end when you sign out; and the server stores session tokens only as hashes, so a stolen copy of our records could not be used to sign in as you. There are no passwords to steal: a login code arrives by email, works once, and dies after minutes.

8. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time without affecting the lawfulness of processing before the withdrawal. The app is built so that you exercise them directly, without writing to anyone:

For anything else, or questions, contact info@smart-backoffice.nl — we answer within one month. You also have the right to lodge a complaint with a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), but you may contact the authority of your own country.

9. Children

Food Moments is not directed at children, and we knowingly process no children's data. If you believe a child has created an account, write to the address in §1 and we will delete it.

10. Changes

If the app's data flows change, this policy is updated before the change ships, with the effective date above.

Every change is published on the support page. Small ones — wording, grammar, a typo, a clarification that does not change what happens to your data — are announced there and nowhere else.

A change with substantial implications for your data is announced in the app as well, before it takes effect. And a genuinely new data flow that processes what you photograph, write or say — the kind analysis and dictation are — needs more than an announcement: it does not start until you have agreed to it. A new technical signal about the app itself, like the crash diagnostics in §2, changes nothing about how your meals or account are handled; it is disclosed rather than gated, the same way the device identifier in §3 already is.

11. Helping improve Food Moments — only if you switch it on

Food Moments gets better by seeing where its estimates go wrong, and the amount on the plate is where they go wrong most. Under Settings → Help improve Food Moments there is a switch that lets us use your meals for exactly that. It is off unless you switch it on.

What you allow when you switch it on. We — the people at Smart Backoffice Solutions B.V. who make Food Moments, and nobody else — may look at the meals in your account: the photos, your notes and corrections, the estimates and their history, and the size measurements that come with the photos. We use them for one purpose: to find out where the app's estimates go wrong and why, and to check whether a change to the app makes them better. To check a change, we may send a meal through the analysis again with the improved instructions, on the same Microsoft Azure deployment in the European Union that analyzes your meals (§4); the answer is compared with the original and never changes the meal in your timeline. Meals can say something about your health — a diet, an allergy, how much you eat — so this needs your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR). The switch is that consent: its label says what you agree to, switching it on is agreeing, and the app shows the date you did.

What it never allows. Your meals are not used to train AI models, ours or anyone else's. They are not shared with anyone, not sold, not published and not used for advertising. What we learn is kept as general findings and totals ("the first estimate was 15 % off on average") that do not point to you. Nobody will contact you because of it.

Where your meals stay. In your account, in the European Union, as before. When a comparison needs a working copy — a photo next to its old and new estimate — that copy is kept only on our own encrypted computers, for as long as the comparison runs, and deleted afterwards.

Switching it off. You can switch it off in the same place at any time, as easily as you switched it on; your other iPhones follow within minutes. From then on we no longer look at your meals, and we delete any working copy of them without delay, at the latest within 30 days. Withdrawing does not undo what was done before it (Art. 7(3) GDPR), and general findings that no longer point to you stay. Nothing else in the app changes either way. Deleting your account switches it off too, and signing in with another account starts with it off.