Privacy Policy
Elements – AI calorie tracker · Effective 27 September 2026
1. Who is responsible
Elements is developed and operated by Marcin Stelmach (the “controller”). Contact for any privacy question or request: elements-app@stelmach.biz.
2. Data stored only on your device
Meals, drinks, ingredients, meal photos, favourites, weight, body measurements and your goals are stored locally in the app on your iPhone. We do not receive them. If you allow access to Apple Health, Elements reads burned calories and writes meals, water and weight to Health; this data is exchanged only between Elements and Apple Health on your device and is never sent to our server or to OpenAI.
3. AI analysis (OpenAI)
When you analyse a meal or drink, the photo (downscaled) or the text you entered is sent directly from your device to OpenAI (OpenAI, L.L.C., USA) through the OpenAI API, and the nutrition estimate is returned to your device. According to OpenAI's API data policy, API content is not used to train their models and may be retained for up to 30 days to detect abuse. Please avoid including people or other personal information in meal photos.
4. Data we process on our server
| Data | Purpose | Kept |
|---|---|---|
| A random account ID and the user identifier provided by Sign in with Apple. We do not request or store your name or e-mail address. | Your account | Until you delete your account |
| Session tokens (stored only as hashes) and Apple's refresh token (encrypted) | Keeping you signed in; revoking Apple access when you delete your account | Until they expire or you delete your account |
| Number and type of AI analyses per day (e.g. “meal photo”), with timestamps | Daily analysis limits and your usage history | 90 days |
| If you connect WHOOP: your WHOOP user ID and encrypted access tokens | Fetching your WHOOP daily cycles (calories burned and day strain), which are passed to your device and not stored on our server. We request no other WHOOP data. | Until you disconnect WHOOP or delete your account |
| Anonymous success rate and response time of AI and WHOOP requests, not linked to any account | The public service status page | 15 days |
| Technical logs (request type and time; error logs may include an IP address) | Operating and securing the service | Rotated automatically after a short time |
5. Legal bases (GDPR)
We process account, usage-limit and WHOOP-connection data to provide the service you asked for (Art. 6(1)(b) GDPR). Meal photos and descriptions may reveal information about your health; they are analysed only when you explicitly choose to do so (Art. 9(2)(a) GDPR). You can stop at any time by not using AI analysis or by deleting your account. Security logs and the anonymous status statistics rely on our legitimate interest in running a reliable and secure service (Art. 6(1)(f) GDPR).
6. Service providers and transfers
- Hetzner Online GmbH – server hosting in Helsinki, Finland (EU).
- OpenAI, L.L.C. (USA) – AI nutrition analysis.
- Apple Inc. – Sign in with Apple and Apple Health on your device.
- WHOOP, Inc. (USA) – only if you connect your WHOOP account.
Transfers to the USA rely on the EU–U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. We never sell your data or share it for advertising.
7. Deleting your data
In the app, go to Profile → Delete Account. This immediately deletes your account data from our server and revokes Elements' access to Sign in with Apple and WHOOP. Encrypted database backups are overwritten within 14 days. Data stored on your iPhone is removed when you delete the app. You can disconnect WHOOP at any time in Profile → WHOOP.
8. Your rights
You have the right to access, correct, delete, restrict or port your data, to object to processing and to withdraw consent at any time, by writing to elements-app@stelmach.biz. You may also lodge a complaint with a data protection authority – in Poland the President of the Personal Data Protection Office (uodo.gov.pl) – or the authority in your country of residence.
9. Security
All connections use HTTPS. WHOOP and Apple tokens are encrypted at rest (AES-256-GCM), session tokens are stored only as hashes, and our servers are hosted in the EU with restricted access.
10. Children
Elements is not intended for children under 16 and we do not knowingly process their data.
11. Changes
If this policy changes, we will update the effective date above and, for significant changes, inform you in the app.