Privacy Policy — Sprouted
Effective date: 30 July 2026
This Privacy Policy explains how Daniel Elsinga (“we”, “us”, or “our”), operating the mobile application Sprouted (iOS and Android, bundle identifier com.daniel.sprouted), collects, uses, shares, and protects your personal data.
By creating an account or using Sprouted, you acknowledge this Privacy Policy. Where we rely on your consent (for example, for optional analytics), we will ask for it separately in the app.
1. Who we are
| Controller | Daniel Elsinga (individual) |
| Brand | Sprouted |
| Country | Netherlands |
| Contact | support@getsprouted.app |
For privacy requests, email support@getsprouted.app. We currently provide email contact only.
2. Data we collect
We collect the following categories of personal data when you use Sprouted.
2.1 Account data
Email address, hashed password, age, height, weight, sex, dietary preference, and activity level. Used to create and operate your account and provide core app features.
2.2 Health-related tracking data (special category)
Weight entries, food logs, and water logs. Used to provide nutrition, weight, and water tracking. This information can qualify as special-category (health) data under the GDPR and as sensitive personal information under California law.
2.3 Optional profile data
Allergies and recipe photos or notes that you choose to add. Used for personalization. You can remove this information yourself, or it is deleted when you delete your account.
2.4 Product analytics (optional, consent-gated)
Pseudonymized usage events that help us improve Sprouted. When analytics is enabled, this may include events such as weight_logged, water_logged, meal_logged, and food_searched. These events record that you took an action and may include limited context (for example, meal category or where in the app you logged it). They do not include your exact weight, water amounts, or food quantities. Health-derived events of this kind are only processed for analytics if you have enabled Analytics.
2.5 Crash and diagnostic data (optional, consent-gated)
Redacted technical error logs used to diagnose crashes and improve stability. These reports do not include your account user ID.
2.6 Subscription and purchase data
Subscription tier or status and transaction identifiers needed to manage entitlements and billing. Payment card details are handled by Apple or Google, not by us.
2.7 Device and usage data
Device type, operating system, and app version. Used for support, compatibility, and reliable delivery of the service.
2.8 Barcode and product lookups
When you look up a product by barcode, we query the OpenFoodFacts public product database. We do not share your account personal data with OpenFoodFacts. Lookup queries are not retained by us beyond the lookup, except where you choose to save related information in your own food log entries.
3. Purposes and legal bases
We process personal data only for the purposes below, under the legal bases indicated (GDPR Articles 6 and, where applicable, 9).
| Purpose | Data involved | Legal basis |
|---|---|---|
| Provide your account and core app functionality (including nutrition, weight, and water tracking) | Account data; health-related tracking data; optional profile data | Contract — Art. 6(1)(b). For special-category health data needed to provide tracking features: explicit consent — Art. 9(2)(a), in addition to what is needed to perform the contract |
| Personalization (allergies, recipe photos/notes) | Optional profile data | Contract — Art. 6(1)(b) |
| Product analytics and product improvement | Pseudonymized analytics events (including health-derived events when Analytics is on) | Consent — Art. 6(1)(a); for health-derived analytics events also Art. 9(2)(a) |
| Crash reporting and app stability | Redacted crash/diagnostic logs | Consent to send reports. After you withdraw consent, we may retain shared, de-identified crash issues (without your account ID) under legitimate interest — Art. 6(1)(f) — to keep the app stable for all users |
| Subscription entitlement and billing coordination | Subscription/purchase data | Contract — Art. 6(1)(b) |
| Support and compatibility | Device/usage data | Legitimate interest — Art. 6(1)(f) (reliable service and support) |
| Product barcode lookup | Barcode / product query | Legitimate interest — Art. 6(1)(f) (providing product lookup) |
| Transactional email (sign-up, password reset) | Email address | Contract — Art. 6(1)(b) |
| Push notifications (where enabled on your device) | Push token, device identifier | Contract / operation of the service — Art. 6(1)(b), as needed to deliver notifications you receive through the app |
Our legitimate interests, where used, are to operate a secure, compatible, and stable app and to look up public product information you request. You may object to processing based on legitimate interest as described in Your rights.
We do not use personal data for cross-context behavioural advertising. No advertising network is integrated into Sprouted.
4. Special-category / health data and analytics consent
Because Sprouted processes health-related information (such as weight, food, and water logs), we rely on your explicit consent, in addition to what is needed to provide the app’s core functionality, before using this data for analytics purposes.
You control this with a single Analytics setting in Settings → Analytics, and with a one-time prompt after you first enter the app (Enable / Not now).
- Turning Analytics on enables both general product analytics and analytics involving health-derived data — one decision.
- Analytics is off by default until you enable it. If you never turn it on, this data is never used for analytics.
- Turning Analytics off (or choosing “Not now”) means we stop new analytics and crash-report collection immediately. We delete your analytics profile and associated events from our analytics provider (PostHog). De-identified crash reports that do not include your account identifier may be retained separately for app stability purposes and are not deleted, as they are not linked back to you.
Health-related logs used for core tracking features (showing your own history, plans, and related functionality) remain available while your account exists, whether or not Analytics is enabled. Deleting your account removes that data as described below.
5. How we share data (processors and others)
We do not sell your personal information. We share data with service providers (“processors”) who help us run Sprouted, only as needed for their role, and with Apple or Google for payments as independent controllers.
| Recipient | Role | Data | Location | Transfer note |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | User data we store to operate your account | EU — Sweden (eu-north-1) |
Within the EEA |
| PostHog | Product analytics (only if Analytics is enabled) | Pseudonymized events | EU (eu.posthog.com) |
Within the EEA |
| Sentry | Crash reporting (only if Analytics is enabled for sending reports) | Redacted technical logs; no account user ID | United States | Standard Contractual Clauses (SCCs) |
| RevenueCat | Subscription management | Subscription status, transaction IDs | United States | SCCs |
| Apple App Store / Google Play | Billing and payment processing | Purchase and subscription data | Per Apple / Google | Independent controllers for payment processing |
| Resend | Transactional email (sign-up, password reset) | Email address | United States (account data stored in the US) | SCCs and/or EU–US Data Privacy Framework |
| Expo | Push notification delivery | Push token, device identifier | United States | SCCs |
| OpenFoodFacts | Public product database | Barcode / product query | Public API | No account personal data shared |
We may also disclose data if required by law, or to protect rights, safety, or the integrity of the service, where permitted.
6. International transfers
- Data hosted with Supabase and PostHog is processed in the European Economic Area (Sweden / EU PostHog infrastructure).
- Some providers (Sentry, RevenueCat, Resend, Expo) process data in the United States. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Apple and Google process payment-related data under their own privacy policies and transfer mechanisms.
7. Retention
| Data | Retention |
|---|---|
| Account data, health logs, optional profile data | Until you delete your account (instant hard delete; no grace period) |
| Product analytics (PostHog) | Deleted when you withdraw Analytics consent or delete your account |
| Crash / diagnostic data (Sentry) | Retained according to Sentry’s retention for shared, de-identified issues. Not deleted on consent withdrawal or account deletion, because reports are not linked to your account ID |
| Subscription / purchase records | As retained by Apple, Google Play, and RevenueCat for entitlement and legal/billing purposes |
| Device / usage data | For as long as needed for support and compatibility in the ordinary course of operating the app |
| Barcode lookups | Not retained by us beyond the lookup, except information you save in your own logs |
8. Account deletion
You can delete your account in the app: Settings → Delete account.
Deletion is an immediate hard delete. There is no waiting or grace period. In practice we remove your stored files and account data, revoke related subscription records we manage via RevenueCat, and purge your analytics profile from PostHog. Shared, de-identified Sentry crash issues are not deleted.
Some purchase or subscription records may remain with Apple, Google, or RevenueCat under their own retention rules.
9. Your rights (GDPR)
If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar rights, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
How these rights work in Sprouted today:
| Right | How to exercise | Timeline |
|---|---|---|
| Erasure / account deletion | Settings → Delete account | Immediate (no grace period) |
| Access / portability | Email support@getsprouted.app (manual request; there is no in-app export yet) | Up to 30 days; up to 60 days if complex, with notice |
| Rectification | Edit your profile in the app where available; otherwise email support | Immediate in-app; otherwise up to 30 days |
| Object / restrict | Turn Analytics off in Settings → Analytics; for other requests, email support | Analytics: immediate; other requests: up to 30 days |
| Withdraw consent (Analytics) | Settings → Analytics → turn Analytics off | Immediate stop of new collection; PostHog profile and events deleted (asynchronously) |
We may need to verify your identity before fulfilling email requests.
10. Children’s privacy
Sprouted is intended for users aged 18 and over. We do not knowingly collect personal data from children. The app is not directed at children under 13, and COPPA does not apply to our intended audience. If you believe we have collected data from someone under 18, contact support@getsprouted.app and we will take appropriate steps.
11. California residents (CCPA / CPRA)
If you are a California resident, this section applies in addition to the rest of this Policy.
Categories of personal information we collect are described above (identifiers such as email; account and profile characteristics; commercial/subscription information; internet or device information; and health-related information from weight, food, and water tracking).
Sensitive personal information under California law includes health-related information we process for tracking features (such as weight, food, and water logs) and related account characteristics such as age, height, and sex. We use this information to provide the service you request and, only if you enable Analytics, for product improvement as described in this Policy. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA beyond what is necessary to provide the service, except where you have consented to Analytics.
We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We do not have an advertising network integrated in Sprouted.
You may have the right to know, access, correct, delete, and receive a portable copy of personal information, and to non-discrimination for exercising your rights. To submit a request, email support@getsprouted.app. We will respond within the timeframes required by law. You may also delete your account in the app for an immediate erasure of the account data we control, subject to the limitations described in this Policy (for example, store billing records and de-identified crash reports).
12. Automated processing
Sprouted may generate meal plans and related suggestions using algorithms based on information you provide. This processing helps deliver the product features you use. It does not produce legal or similarly significant decisions about you within the meaning of GDPR Article 22.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will change the effective date at the top of this page and, where appropriate, notify you by email or in the app. Continued use of Sprouted after an update means you acknowledge the revised Policy. Where an update requires fresh consent (for example, a material change to Analytics), we will ask for consent again in the app.
14. Contact
For privacy questions or requests:
Email: support@getsprouted.app
Controller: Daniel Elsinga, Netherlands
App: Sprouted (com.daniel.sprouted)