1. Controller
The controller responsible for data processing in the "Walk It Off" app is:
Fabian BrunsingReuterstr. 95
12053 Berlin
Germany
Email: mail@letswalkitoff.com
2. Principle: your data largely stays on your device
Walk It Off is built to be data-minimal. Your health, weight, and nutrition data is stored locally on your iPhone only and is not transmitted to us. There is no advertising and no sharing of your data for marketing purposes.
Data leaves your device only in the few, clearly described cases below (for example, when you scan a photo for recognition, log a meal by voice, or when we collect pseudonymous usage statistics to improve the app). In those cases, selected service providers process this data exclusively on our behalf.
3. Health and motion data (steps, weight, body data)
What data: step count, weight, and the details you provide during setup (e.g. height, gender, age/year of birth, current weight, goal weight, step goal).
Where from / how:
- Steps are read from your iPhone's motion sensors (Core Motion / "Motion & Fitness") and β if you allow it β from Apple Health (HealthKit) (e.g. values from an Apple Watch).
- Weight is β if you allow it β read from Apple Health (e.g. from a smart scale) or entered manually by you.
Purpose: calculating your calorie and step targets, your projection, and displaying your progress. This is the app's core function.
Storage: exclusively local on your device. This data is not transmitted to us or to third parties.
Apple Health access: The app requests read-only access to steps and weight. We do not write anything to your Apple Health data. You can revoke the permission at any time in iOS Settings under Privacy & Security β Health. Data from Apple Health is never used for advertising or shared for marketing purposes.
Legal basis: Health data is a special category of personal data (Art. 9 GDPR). We process it on the basis of your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR), which you give by granting the permission and using the feature. Since processing happens locally on your device, you remain in full control.
4. Nutrition tracking, photo scan, and voice input
Manual entries: When you log meals or water, these entries are stored locally on your device.
Photo scan (AI recognition): When you take a photo of your meal to have it recognized automatically, the following happens:
- The photo is downscaled and sent for analysis to our processing service (a Cloudflare Worker acting as an intermediary) and from there to the AI provider Anthropic (Claude). Anthropic analyzes the image and returns the estimated nutritional values.
- On our side and at the AI provider, the photo is processed only for the immediate analysis and is not stored permanently; in particular, it is not used to train AI models (see data processing agreements below).
- On your device, only a small preview image (thumbnail) of the photo is kept so you can recognize your entries. The full-resolution original photo is not retained.
Voice input: If you speak a meal instead of typing it, the app uses your iPhone's speech recognition (Apple). Your voice recording is converted to text by Apple β locally or on Apple's servers, depending on device and language; Apple's privacy policy applies. We receive only the recognized text, not the audio recording, and we store no audio data. You can revoke the microphone and speech recognition permissions at any time in iOS Settings.
Barcode scan: If you scan the barcode of a packaged product, this product code (EAN) is sent to the open database Open Food Facts to retrieve nutritional values. No personal data is transmitted β only the product number.
Purpose: automatic recognition of foods and nutritional values so that logging is fast.
Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) β the recognition is the feature you requested β as well as your consent to the use of camera, photos, and microphone (Art. 6(1)(a) GDPR).
5. Pseudonymous usage analytics
To understand how the app is used and to improve it, we collect pseudonymous usage statistics with the service PostHog, hosted in the EU (Germany/Ireland).
- No real name, no email, no account: A random device ID serves as the identifier (with no link to a name, email, or account). We cannot identify you from it.
- No health or content data: No weight, calorie, nutrition, or photo data and no raw values are transmitted. We collect only pseudonymous interaction events (e.g. "app opened", which screen was viewed, which option or button was used, that an entry was made β as a category such as "snack", without calories; that a weigh-in happened β without the weight value) plus general device context (e.g. iOS version, app version, device model). Exact numbers β precise step, weight, or calorie values β are never transmitted.
- Coarse profile ranges to understand our audience: When you complete onboarding, we transmit β in coarse bands β your initial step goal (rounded to the nearest 1,000), your weight-loss goal (rounded to the nearest 5 kg), and your self-assessed activity level (low/medium/high) β always as ranges, never exact values, capped against outliers and with no link to your person. This helps us understand who the app serves, without storing a health datum about you.
- No precise location: IP-based location enrichment is disabled (no storage of city, postal code, or coordinates).
- No ad tracking: The data is used exclusively for product improvement, not for advertising, and is not shared with third parties for marketing purposes.
Legal basis: our legitimate interest in a stable, user-friendly app (Art. 6(1)(f) GDPR). Processing is pseudonymized (via a random device ID only, without a real name or account) and limited to what is necessary.
6. Subscription and purchases
Purchases and subscriptions are handled by Apple (App Store / in-app purchase). Your payment data is processed exclusively by Apple; we do not receive or store it. To manage your purchase status ("subscription active", restore purchases) we use RevenueCat, Inc. (USA) β only a pseudonymous, random user identifier and the purchase status are processed, no real names and no payment data. Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
6a. Android waiting list (website)
On our website (letswalkitoff.com) you can optionally join the Android waiting list. We store your email address on our server (Cloudflare Workers KV) β solely to notify you once when the Android version becomes available. No sharing, no newsletter, no advertising. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time and request deletion of your address β a short email to mail@letswalkitoff.com is enough. After the notification has been sent (or upon your withdrawal), we delete the address.
7. Data processing agreements and transfers to third countries
The service providers named in sections 4β6a process data exclusively on our behalf on the basis of data processing agreements (Art. 28 GDPR). Usage analytics (PostHog) runs on servers in the EU.
Some providers are based in the USA (Anthropic, possibly Cloudflare, RevenueCat). Transfers to the USA take place on the basis of appropriate safeguards under Art. 44 et seq. GDPR β in particular EU Standard Contractual Clauses (SCCs) or certification under the EU-US Data Privacy Framework.
8. No advertising
Walk It Off contains no advertising and sets no ad-tracking cookies. We create no user profiles for advertising purposes and sell no data. The only data collection beyond your device is what is described in sections 4β6 (photo/voice/barcode recognition, pseudonymous usage analytics, and subscription/purchase handling).
9. Retention
- Local data stays on your device until you delete it in the app or uninstall the app.
- Photo scans are held only briefly (for processing) during AI analysis and are not stored permanently.
- Pseudonymous analytics data is stored only as long as needed for product improvement.
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You can withdraw any consent at any time with effect for the future (Art. 7(3)) β for example by revoking the Health, camera, or microphone permission in iOS Settings or by deleting the data in the app.
Since most of your data lives only on your device, you can exercise these rights largely yourself, directly in the app and in iOS Settings. For everything else, you can reach us at the email address above.
You also have the right to lodge a complaint with a data protection supervisory authority (for Berlin: the Berlin Commissioner for Data Protection and Freedom of Information).
11. Changes to this privacy policy
We update this privacy policy when the app or legal requirements change. The dated version published here applies.