Privacy Policy — Sprouted

Effective date: 30 July 2026

This Privacy Policy explains how Daniel Elsinga (“we”, “us”, or “our”), operating the mobile application Sprouted (iOS and Android, bundle identifier com.daniel.sprouted), collects, uses, shares, and protects your personal data.

By creating an account or using Sprouted, you acknowledge this Privacy Policy. Where we rely on your consent (for example, for optional analytics), we will ask for it separately in the app.


1. Who we are

Controller Daniel Elsinga (individual)
Brand Sprouted
Country Netherlands
Contact support@getsprouted.app

For privacy requests, email support@getsprouted.app. We currently provide email contact only.


2. Data we collect

We collect the following categories of personal data when you use Sprouted.

2.1 Account data

Email address, hashed password, age, height, weight, sex, dietary preference, and activity level. Used to create and operate your account and provide core app features.

2.2 Health-related tracking data (special category)

Weight entries, food logs, and water logs. Used to provide nutrition, weight, and water tracking. This information can qualify as special-category (health) data under the GDPR and as sensitive personal information under California law.

2.3 Optional profile data

Allergies and recipe photos or notes that you choose to add. Used for personalization. You can remove this information yourself, or it is deleted when you delete your account.

2.4 Product analytics (optional, consent-gated)

Pseudonymized usage events that help us improve Sprouted. When analytics is enabled, this may include events such as weight_logged, water_logged, meal_logged, and food_searched. These events record that you took an action and may include limited context (for example, meal category or where in the app you logged it). They do not include your exact weight, water amounts, or food quantities. Health-derived events of this kind are only processed for analytics if you have enabled Analytics.

2.5 Crash and diagnostic data (optional, consent-gated)

Redacted technical error logs used to diagnose crashes and improve stability. These reports do not include your account user ID.

2.6 Subscription and purchase data

Subscription tier or status and transaction identifiers needed to manage entitlements and billing. Payment card details are handled by Apple or Google, not by us.

2.7 Device and usage data

Device type, operating system, and app version. Used for support, compatibility, and reliable delivery of the service.

2.8 Barcode and product lookups

When you look up a product by barcode, we query the OpenFoodFacts public product database. We do not share your account personal data with OpenFoodFacts. Lookup queries are not retained by us beyond the lookup, except where you choose to save related information in your own food log entries.


3. Purposes and legal bases

We process personal data only for the purposes below, under the legal bases indicated (GDPR Articles 6 and, where applicable, 9).

Purpose Data involved Legal basis
Provide your account and core app functionality (including nutrition, weight, and water tracking) Account data; health-related tracking data; optional profile data Contract — Art. 6(1)(b). For special-category health data needed to provide tracking features: explicit consent — Art. 9(2)(a), in addition to what is needed to perform the contract
Personalization (allergies, recipe photos/notes) Optional profile data Contract — Art. 6(1)(b)
Product analytics and product improvement Pseudonymized analytics events (including health-derived events when Analytics is on) Consent — Art. 6(1)(a); for health-derived analytics events also Art. 9(2)(a)
Crash reporting and app stability Redacted crash/diagnostic logs Consent to send reports. After you withdraw consent, we may retain shared, de-identified crash issues (without your account ID) under legitimate interest — Art. 6(1)(f) — to keep the app stable for all users
Subscription entitlement and billing coordination Subscription/purchase data Contract — Art. 6(1)(b)
Support and compatibility Device/usage data Legitimate interest — Art. 6(1)(f) (reliable service and support)
Product barcode lookup Barcode / product query Legitimate interest — Art. 6(1)(f) (providing product lookup)
Transactional email (sign-up, password reset) Email address Contract — Art. 6(1)(b)
Push notifications (where enabled on your device) Push token, device identifier Contract / operation of the service — Art. 6(1)(b), as needed to deliver notifications you receive through the app

Our legitimate interests, where used, are to operate a secure, compatible, and stable app and to look up public product information you request. You may object to processing based on legitimate interest as described in Your rights.

We do not use personal data for cross-context behavioural advertising. No advertising network is integrated into Sprouted.


4. Special-category / health data and analytics consent

Because Sprouted processes health-related information (such as weight, food, and water logs), we rely on your explicit consent, in addition to what is needed to provide the app’s core functionality, before using this data for analytics purposes.

You control this with a single Analytics setting in Settings → Analytics, and with a one-time prompt after you first enter the app (Enable / Not now).

Health-related logs used for core tracking features (showing your own history, plans, and related functionality) remain available while your account exists, whether or not Analytics is enabled. Deleting your account removes that data as described below.


5. How we share data (processors and others)

We do not sell your personal information. We share data with service providers (“processors”) who help us run Sprouted, only as needed for their role, and with Apple or Google for payments as independent controllers.

Recipient Role Data Location Transfer note
Supabase Database, authentication, file storage User data we store to operate your account EU — Sweden (eu-north-1) Within the EEA
PostHog Product analytics (only if Analytics is enabled) Pseudonymized events EU (eu.posthog.com) Within the EEA
Sentry Crash reporting (only if Analytics is enabled for sending reports) Redacted technical logs; no account user ID United States Standard Contractual Clauses (SCCs)
RevenueCat Subscription management Subscription status, transaction IDs United States SCCs
Apple App Store / Google Play Billing and payment processing Purchase and subscription data Per Apple / Google Independent controllers for payment processing
Resend Transactional email (sign-up, password reset) Email address United States (account data stored in the US) SCCs and/or EU–US Data Privacy Framework
Expo Push notification delivery Push token, device identifier United States SCCs
OpenFoodFacts Public product database Barcode / product query Public API No account personal data shared

We may also disclose data if required by law, or to protect rights, safety, or the integrity of the service, where permitted.


6. International transfers

Apple and Google process payment-related data under their own privacy policies and transfer mechanisms.


7. Retention

Data Retention
Account data, health logs, optional profile data Until you delete your account (instant hard delete; no grace period)
Product analytics (PostHog) Deleted when you withdraw Analytics consent or delete your account
Crash / diagnostic data (Sentry) Retained according to Sentry’s retention for shared, de-identified issues. Not deleted on consent withdrawal or account deletion, because reports are not linked to your account ID
Subscription / purchase records As retained by Apple, Google Play, and RevenueCat for entitlement and legal/billing purposes
Device / usage data For as long as needed for support and compatibility in the ordinary course of operating the app
Barcode lookups Not retained by us beyond the lookup, except information you save in your own logs

8. Account deletion

You can delete your account in the app: Settings → Delete account.

Deletion is an immediate hard delete. There is no waiting or grace period. In practice we remove your stored files and account data, revoke related subscription records we manage via RevenueCat, and purge your analytics profile from PostHog. Shared, de-identified Sentry crash issues are not deleted.

Some purchase or subscription records may remain with Apple, Google, or RevenueCat under their own retention rules.


9. Your rights (GDPR)

If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar rights, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

How these rights work in Sprouted today:

Right How to exercise Timeline
Erasure / account deletion Settings → Delete account Immediate (no grace period)
Access / portability Email support@getsprouted.app (manual request; there is no in-app export yet) Up to 30 days; up to 60 days if complex, with notice
Rectification Edit your profile in the app where available; otherwise email support Immediate in-app; otherwise up to 30 days
Object / restrict Turn Analytics off in Settings → Analytics; for other requests, email support Analytics: immediate; other requests: up to 30 days
Withdraw consent (Analytics) Settings → Analytics → turn Analytics off Immediate stop of new collection; PostHog profile and events deleted (asynchronously)

We may need to verify your identity before fulfilling email requests.


10. Children’s privacy

Sprouted is intended for users aged 18 and over. We do not knowingly collect personal data from children. The app is not directed at children under 13, and COPPA does not apply to our intended audience. If you believe we have collected data from someone under 18, contact support@getsprouted.app and we will take appropriate steps.


11. California residents (CCPA / CPRA)

If you are a California resident, this section applies in addition to the rest of this Policy.

Categories of personal information we collect are described above (identifiers such as email; account and profile characteristics; commercial/subscription information; internet or device information; and health-related information from weight, food, and water tracking).

Sensitive personal information under California law includes health-related information we process for tracking features (such as weight, food, and water logs) and related account characteristics such as age, height, and sex. We use this information to provide the service you request and, only if you enable Analytics, for product improvement as described in this Policy. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA beyond what is necessary to provide the service, except where you have consented to Analytics.

We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We do not have an advertising network integrated in Sprouted.

You may have the right to know, access, correct, delete, and receive a portable copy of personal information, and to non-discrimination for exercising your rights. To submit a request, email support@getsprouted.app. We will respond within the timeframes required by law. You may also delete your account in the app for an immediate erasure of the account data we control, subject to the limitations described in this Policy (for example, store billing records and de-identified crash reports).


12. Automated processing

Sprouted may generate meal plans and related suggestions using algorithms based on information you provide. This processing helps deliver the product features you use. It does not produce legal or similarly significant decisions about you within the meaning of GDPR Article 22.


13. Changes to this Policy

We may update this Privacy Policy from time to time. We will change the effective date at the top of this page and, where appropriate, notify you by email or in the app. Continued use of Sprouted after an update means you acknowledge the revised Policy. Where an update requires fresh consent (for example, a material change to Analytics), we will ask for consent again in the app.


14. Contact

For privacy questions or requests:

Email: support@getsprouted.app

Controller: Daniel Elsinga, Netherlands
App: Sprouted (com.daniel.sprouted)