Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains how Gramsof (“Gramsof”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you use the Gramsof mobile application (the “App”) and related websites such as gramsof.app (together, the “Services”).
We designed Gramsof so that your protein-tracking data primarily stays on your device. We do not sell your personal data. This Policy is intended to meet requirements under the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and comparable privacy laws worldwide.
This Policy is provided for transparency. It is not legal advice. If you need advice about your rights, contact a qualified professional or your local data-protection authority.
1. Who we are (data controller)
For GDPR and UK GDPR purposes, the data controller responsible for your personal data is Gramsof, contactable at gramsof.app@outlook.com.
If we appoint an EU or UK representative under applicable law, we will update this Policy with their contact details.
2. Scope and who this covers
This Policy applies to users of the App and visitors to our legal pages, wherever you are located. Depending on where you live, additional local rights may apply (see Sections 9 and 10).
3. Personal data we process
“Personal data” means information that identifies or can reasonably be linked to you. Depending on how you use the Services, we may process:
A. Data you provide
- Nutrition and tracking data — food names, protein amounts, log timestamps, daily goals, custom foods, and related preferences you enter.
- Emails you send us — if you email us (including via “Request a feature” in the App, which opens your device’s mail app), we receive whatever you choose to send: your email address, the subject and message, any attachments, and related metadata your email provider includes (such as date and time). We do not collect this unless you contact us.
- Exported files — CSV or PDF exports you create and choose to share or save outside the App.
Emailing us is optional. We use your message only to understand and reply to your request (for example a feature idea, support question, or privacy request). We do not add you to a marketing list, and we do not sell the contents of your emails.
B. Data stored on your device
- App settings — onboarding completion, reminder preferences, sort preferences, haptics, and similar configuration stored locally (for example in on-device storage).
- Local notifications — if you enable reminders, the App schedules local notifications on your device. We do not use those notifications to collect additional personal data about you.
C. Purchase and subscription data (Apple)
- Purchases and subscriptions are processed by Apple through StoreKit / the App Store. Apple may process identifiers, purchase history, and payment details under Apple’s privacy policy. We receive limited purchase/entitlement status needed to unlock paid features — not your full payment card details.
D. Device / platform services (Apple)
- If you use Apple features such as iCloud backup or sync associated with your Apple ID, Apple may store App data in your iCloud account under Apple’s terms and privacy policy. That processing is controlled by Apple according to your Apple ID settings.
- We do not operate our own advertising SDK, analytics SDK, or cross-app tracking as part of Gramsof’s core product.
E. Data we do not intentionally collect
- We do not require you to create a Gramsof account.
- We do not knowingly collect precise GPS location for advertising.
- We do not sell personal data or share it for cross-context behavioral advertising.
4. Purposes and legal bases (GDPR / UK GDPR)
We process personal data only when we have a valid legal basis:
- Performance of a contract (Art. 6(1)(b)) — to provide the App’s core features: logging protein, goals, streaks/stats display, custom foods, reminders you enable, and export tools you use.
- Consent (Art. 6(1)(a)) — where required, for optional features such as notification permission. You may withdraw consent at any time in system settings (or by contacting us), without affecting the lawfulness of processing before withdrawal.
- Legitimate interests (Art. 6(1)(f)) — to receive and respond to emails you send us (support, feature requests, and similar), maintain security, prevent abuse, and improve reliability of the Services, balanced against your rights and interests.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with applicable law, regulation, or valid legal process.
Special-category data: nutrition logs can relate to health. We process this information only because you voluntarily enter it to use the App. Where GDPR Art. 9 applies, our basis is your explicit consent by using those features and/or that the data is manifestly made public by you only if you choose to share exports yourself. We do not use nutrition data for medical diagnosis.
5. Sharing and processors
We share personal data only as needed to operate the Services:
- Apple Inc. — App Store distribution, in-app purchases, device OS services, and (if enabled by you) iCloud. See Apple’s Privacy Policy.
- Microsoft (Outlook) — our contact inbox is gramsof.app@outlook.com. Emails you send us are processed by Microsoft so we can receive and reply. Microsoft’s processing is subject to Microsoft’s Privacy Statement.
- Service providers — if we use hosting or similar providers to operate gramsof.app, they process data only on our instructions and under appropriate contracts (including GDPR Art. 28 terms where required).
- Legal and safety — when required by law, or to protect rights, safety, and integrity of users or the Services.
- Business transfers — if we undergo a merger, acquisition, or asset sale, personal data may transfer under continued confidentiality and this Policy (or a successor policy we notify you about).
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
6. International transfers
Your data is primarily stored on your device. If you contact us by email, or if Apple or another processor stores data in another country, personal data may be processed in the United States or other locations.
Where GDPR/UK GDPR applies and we transfer personal data outside the EEA/UK to a country without an adequacy decision, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK addendum where applicable), or another lawful transfer mechanism, unless a derogation applies (for example transfers necessary to provide the Service at your request).
7. Retention
- On-device App data — retained until you delete it in the App, reset data, or uninstall the App (subject to any device/iCloud backups you control).
- Emails you send us — kept only as long as needed to resolve your request and for a reasonable period afterward for follow-up, accountability, or legal requirements (typically up to 24 months unless a longer period is required).
- Purchase records — handled primarily by Apple; any entitlement records we hold are kept while needed to provide paid features and comply with law.
8. Security
We use reasonable technical and organizational measures appropriate to the risk, including relying on platform security (iOS sandboxing, device encryption when enabled by you, and Apple’s purchase infrastructure). No method of electronic storage is 100% secure; please keep your device and Apple ID protected.
9. Your rights (GDPR, UK GDPR, and similar laws)
If you are in the European Economic Area, United Kingdom, Switzerland, or another region with similar laws (including many jurisdictions with GDPR-style rights), you may have the right to:
- Access — obtain confirmation and a copy of personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion (“right to be forgotten”) where applicable
- Restriction — request that we limit processing in certain cases
- Portability — receive data you provided in a structured, commonly used format (the App’s CSV export can help for on-device logs)
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
- Lodge a complaint — with your local supervisory authority (see Contact)
Because most tracking data stays on your device, the fastest way to access, correct, or delete it is usually within the App (edit/delete entries, reset data, or uninstall). For data we hold in support correspondence or elsewhere under our control, email gramsof.app@outlook.com with the subject “Privacy Request”. We may need to verify your identity before fulfilling a request. We will respond within the timeframe required by applicable law (generally within 30 days under GDPR, subject to permitted extensions).
10. California and other US state privacy rights
If you are a California resident (or a resident of another US state with similar laws such as Virginia, Colorado, Connecticut, Utah, and others), you may have rights to:
- Know/access categories and specific pieces of personal information collected
- Delete personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising
- Limit use/disclosure of sensitive personal information, where applicable
- Non-discrimination for exercising privacy rights
Sale / sharing: We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. If that changes, we will update this Policy and provide a required opt-out method.
Sensitive personal information: Nutrition/health-related logs you enter are used only to provide the App’s tracking features, not for inferring characteristics for advertising.
To exercise these rights, email gramsof.app@outlook.com with “California Privacy Request” (or your state) in the subject line. Authorized agents may submit requests where legally permitted; we will verify authenticity as required by law.
11. Children
The Services are not directed to children under 13 (or under 16 where required by local law, including GDPR age of digital consent rules that Member States may set between 13 and 16). We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
12. Automated decision-making
We do not use personal data for automated decision-making that produces legal or similarly significant effects about you (including profiling of that kind).
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be indicated by updating this page and, where required by law, by additional notice in the App or by email if we have your address. Continued use after the effective date means you acknowledge the updated Policy.
14. Contact and complaints
Questions, feature requests, support, or privacy requests: email gramsof.app@outlook.com. You can also start a message from the App (Settings → Request a feature).
If you are in the EEA/UK and believe we have not handled your personal data appropriately, you may lodge a complaint with your local data protection authority. A list of EEA authorities is available from the European Data Protection Board. UK users may contact the Information Commissioner’s Office (ICO). You may also seek a judicial remedy where available.