Skip to content
AboutGuidesData & privacySupportJoin waitlist
Legal

Privacy policy

This policy explains how Haps handles personal data in its iOS and Android applications, related API, and supporting public website. It is privacy information, not a request for optional analytics consent and not part of accepting the Terms.

Version
2026-08-30
Effective
30 August 2026
Before public launch

Haps is still preparing for public launch. These documents describe the implemented service and require final Danish legal review before production publication.

On this page1. Controller and contact2. Personal data we handle3. Where personal data comes from4. Purposes and legal bases5. Required and optional data6. Recipients and service providers7. International transfers8. Analytics, website storage, and crash diagnostics9. Notifications and communications10. How long data is kept11. Data on your device12. Your data-protection rights13. Security14. Adults only and automated decisions15. Changes to this policy

1. Controller and contact

Srex Digital ApS (CVR 44123967), c/o Stig Rex Rørkær, Yrsavej 4, 2. th., 5200 Odense V, Denmark, is the controller for Haps account administration, product operation, security, support, and optional analytics.

Contact us about privacy or your rights by email or telephone. Stig Rex Rørkær is the current privacy contact; Srex Digital ApS has not appointed a formal data protection officer.

Email [email protected]Call +45 42 31 13 11

2. Personal data we handle

  • Account and profile data: email address, optional display name, preferred language, timezone, email-verification state, age-confirmation time, account status, and account timestamps.
  • Authentication and legal records: Apple or Google provider identifiers where you choose social sign-in, hashed email codes and API tokens, device and session labels, expiry and revocation state, accepted Terms and privacy-policy versions, and acceptance timestamps.
  • Calorie-ledger data: calorie targets, food-entry names, calorie and any supplied macronutrient values, occurrence time, preserved local date, IANA timezone and offset, entry source, revision, sync, conflict, and deletion state.
  • Connected-health data: the provider, connection and permission state, separately selected active-calorie and body-measurement sources, applicable privacy-policy version, height-consent time, connection and sync times, limited error state, a one-way keyed Google Health user reference, and daily active-calorie total or no-data status with its preserved local date, timezone, and offset. Haps can also keep an encrypted local daily summary of the selected provider's total calories, step count, distance, and exercise duration, together with an independent availability or permission status for each value. Total calories include active and resting energy; for Apple Health, Haps calculates the cached total by adding Apple Health's active- and basal-energy sums for that day. Google activity details pass transiently through the Haps API during a foreground refresh but are not written to server storage. Health Connect and Apple Health details are read on the device. The daily summary shows only active calories as Burned; the extra details are not shown there and are not used to calculate calories remaining. Imported body-weight measurements include the measurement time, preserved local date and offset, weight in grams, provider, a one-way keyed source-record reference, source-update time where supplied, and sync time. Haps retains only the newest valid height from the selected body-measurement source, including its measurement time, preserved local date and offset, height in millimetres, provider, one-way keyed source-record reference, source-update time where supplied, and sync time. Signed Google activity, exercise, weight, or height change intervals are processed transiently to identify which stored data needs refreshing and are not retained.
  • Packaged-food contribution data: submitting account identifier, barcode, reviewed product name, brand, calorie and nutrient values, serving basis, country, publication and duplicate-check state, inputs used to evaluate contribution-point eligibility, raw nutrition-label text, parsed result, parser/model metadata, nutrition-label image, and front-of-package image.
  • Transient nutrition-label assistance data: a random client scan identifier, client and server pipeline versions, OCR text and spatial tokens, token coordinates and recognized-language candidates, locally detected nutrition values, per-field confidence and evidence references, image-quality warnings, and the temporary server result with alternatives and warnings. Image assistance is currently disabled; if later enabled after panel-only cropping is available, the captured panel is also processed transiently.
  • Notification data: your reminder choices, local reminder time, timezone, last sign-in or profile-check state, latest food-log activity, device platform, push token, delivery state, and limited diagnostic codes.
  • Consent and analytics data: your separate account-level analytics and transient nutrition-label assistance choices and policy versions; the required catalogue-contribution processing state and policy version recorded when you choose to contribute; the website analytics choice stored on your device; and, only after analytics consent, allowlisted product actions and sanitized website page-lifecycle measurements, including the maximum proportion of page content reached, with restricted technical context.
  • Launch-reminder data: if you ask to be told when Haps is first released, the email address you supply, the confirmation state of that address, the privacy-policy version and time your consent was recorded, the page you gave it on, and a one-way keyed reference derived from your IP address as proof of that consent. Confirmation and opt-out links are stored only as hashes.
  • Technical and support data: IP and request-security information, the country code derived from the current network and any manual country override, app and operating-system details, sync operation identifiers and results, limited crash diagnostics, support correspondence, privacy-request type and status, verification state, export-delivery state, and account-deletion records.

3. Where personal data comes from

Most data comes directly from you when you create an account, enter records, choose settings, contact support, or make a privacy request. Authentication identifiers can come from Apple or Google when you choose that sign-in method. Technical data comes from your device, browser, current network, and automated service and security events. Cloudflare derives a two-letter country code from the network IP when the API is configured behind its trusted edge.

Nutrition-label recognition, spatial parsing, and the editable result run on your device. If you enable online assistance in Privacy settings, an uncertain scan may temporarily send its OCR text and layout, detected nutrition values, field confidence and evidence, and scan warnings to Haps for deterministic self-hosted refinement. Medium-confidence assistance sends no image. The client image gate is currently off; after panel-only cropping and both image gates are approved, a low-confidence scan may also send that panel. Assistance images are not retained or used for training or manual review, the structured result expires after 10 minutes, and saving never waits for this service. You can turn the assistance off in Privacy settings; label scanning remains available locally and offline.

Packaged-food contribution data comes directly from you when you scan a barcode or nutrition label, review the extracted values, and choose to photograph the front of a product. Choosing product-name photography starts an optional catalogue contribution. To process it, Haps uploads the private label and product-name photos, on-device OCR text and result, final reviewed values, and the names of fields you changed, and links the contribution to your account for duplicate checks, contribution-point eligibility, security, and abuse prevention. Haps then runs self-hosted Tesseract OCR and deterministic parsing on the server, ignores user-edited fields when comparing results, and routes unexplained differences to an authorised manual reviewer. An accepted, non-duplicate product can qualify for points only after the client-side and server-side label OCR results match. This evidence processing and account attribution are required for a submitted contribution and are not separate optional settings; you can avoid them by not starting a product-photo contribution. Haps does not use advertising networks or data brokers to enrich your ledger.

Connected-health data comes from Google Health, Android Health Connect, or Apple Health only after you choose Agree and connect and complete the provider or operating-system permission. The app you connect becomes the source for active calories and body measurements; Haps asks you to choose one source for each category only when two providers are connected at once. All three integrations read active calories, total calories, steps, distance, exercise duration, body weight, and height. Activity and weight imports begin on the day you connect. Because a current height is often recorded earlier, Haps may read older height records but retains only the newest valid one. The daily summary shows active calories as Burned and never substitutes total calories, resting energy, steps, distance, or exercise time. Only active calories can increase calories remaining. Google supplies reconciled daily total-calorie, step, and distance rollups plus reconciled exercise-session active duration to the Haps API during a foreground refresh; those four values are returned to the phone and not retained on the server. Google also supplies durable daily active-calorie totals, timestamped weight measurements, the newest height, and signed activity, exercise, weight, or height notifications; notification bodies and raw Google Health user identifiers are not retained. Health Connect is read on your Android device. Apple Health is read on your iPhone and its cached total is the sum of the day's active- and basal-energy values. Extra activity details stay in encrypted local app storage and are not shown in the daily summary. Haps does not read exercise names, notes, routes, raw workout intervals, heart rate, sleep, food, or location. On supported Health Connect versions, Haps requests the additional past-data permission only to locate the newest height when it is older than the normal 30-day read window. Haps requests only read access to Apple Health and never writes anything back to it. Because Apple deliberately does not tell an app whether a health read was allowed, a type you decline simply reads as no data. Imported weight and height are stored and exported but do not change your calorie target, calories logged, calories remaining, or calories over target.

4. Purposes and legal bases

  • Contract and requested steps (GDPR Article 6(1)(b)): create and secure your account, save and synchronise your ledger, preserve local dates, provide recent-food, local-catalogue, scan, contribution, and copy features, verify submitted catalogue contributions and their point eligibility, follow your country override, deliver settings you request, and respond to support and privacy requests.
  • Legal obligations (Article 6(1)(c)): keep records and respond to authorities where applicable law requires it, and handle data-protection requests.
  • Legitimate interests (Article 6(1)(f)): protect Haps and its users, prevent abuse and duplicate contribution rewards, improve label scanning, maintain and improve the shared packaged-food catalogue and its private supporting evidence, operate reliable queues and backups, keep limited security and diagnostic records, investigate incidents, and establish or defend legal claims, balanced against your rights.
  • Consent (GDPR Article 6(1)(a)) and explicit consent for connected-health data (Article 9(2)(a)): connected-health access, optional product and website analytics, and transient nutrition-label assistance stay off until you allow the relevant choice. Existing health connections may need their provider or operating-system permission completed again before Haps can read newly added data types. Google activity details use the activity-and-fitness read-only scope you approve when connecting. Health Connect and Apple Health ask for total-calorie, step, distance, and exercise-duration read access alongside the core types; declining an optional activity type does not disable the types you allowed, and you can allow it later in the device's health settings. You can disconnect a health provider or switch the selected activity or body-measurement source at any time. Disconnecting Google Health revokes the Haps Google OAuth grant before Haps removes its connection and imported data; the source health data remains with Google. Nutrition-label assistance consent is controlled in Privacy settings and covers temporary transmission of spatial OCR evidence, locally detected values, confidence and warnings, and the account-scoped refinement result; the currently disabled image step would require the same consent after panel-only cropping is available. Turning it off stops new refinement and polling. The launch reminder is a separate consent: nothing is sent until you confirm the address from the email we send, and every message carries a one-click opt-out.

5. Required and optional data

An email address, age confirmation, current legal-document acceptance, timezone, a calorie target, and the values required by a logging workflow are needed to create and use the relevant parts of Haps. Without them, those features cannot work.

A display name, social sign-in, food-entry name, macronutrient values, country override, local food suggestions, connected-health access, online nutrition-label assistance, packaged-food contribution, push notifications, inactivity reminders, daily reminders, and analytics are optional. If you choose to submit a packaged-food contribution, its label-scan identifier, private label and product-name images, OCR comparison, account attribution, duplicate checks, and eligibility checks are required to validate the product and determine whether it qualifies for points; there is no separate contribution toggle. You can leave connected health and optional analytics off, keep online scan assistance off, add foods manually, and use Haps without connecting another app, enabling notifications, or making a catalogue contribution. The launch reminder is entirely optional and is not connected to having a Haps account.

6. Recipients and service providers

We do not sell personal data, share calorie-ledger content for advertising, or let analytics providers receive food names, calories, targets, dates, email addresses, account identifiers, or free text. We disclose data only as needed to operate Haps, follow your request, protect rights and security, or comply with law.

  • DigitalOcean and Laravel Forge: planned EU-region application hosting, database, cache, private file storage, backups, deployment, and operations.
  • Cloudflare: API proxying, transport security, abuse protection, and country-code derivation from the request IP. Haps uses only the two-letter country result for local-food selection and does not request city or precise-location data.
  • Anthropic: raw nutrition-label OCR text for the legacy structured-extraction path. The confidence-routed assistance service does not use Anthropic, and no label or product-front image is sent to Anthropic; product-name recognition runs on the device.
  • Mailgun EU: transactional email, including sign-in, privacy-request verification, export delivery, and sanitised OCR-review alerts. OCR-review email contains only a random scan identifier and differing field names, not the image, OCR text, food name, or nutrition values. Mailgun Technologies, Inc. is a US-based Sinch company even when the EU service region is selected.
  • Apple and Google: optional social sign-in, app distribution, and platform services you choose to use. If you connect Google Health, Google supplies requested active- and total-calorie rollups, steps, distance, reconciled exercise duration, timestamped weight measurements, the newest height, and signed activity, exercise, weight, or height change notifications to the Haps API. The extra Google activity details are processed transiently and returned to your phone without being retained on the server. On Android, Health Connect supplies permitted activity, weight, and height records to Haps on your device before Haps receives the selected durable data. On iPhone, Apple Health supplies permitted active and basal energy, steps, walking and running distance, exercise time, weight, and height data on the device. Haps does not send your health data to Apple, and connecting Apple Health does not disclose your ledger to Apple.
  • Firebase and Apple Push Notification service: generic push delivery, device tokens, consent-gated mobile analytics, and minimised iOS and Android crash diagnostics.
  • PostHog EU: optional product analytics after the relevant consent. Person profiles, session replay, broad autocapture, and persistent analytics identity are disabled in Haps.
  • Google Tag Manager and Google Analytics 4: optional public-website analytics loaded only after the website choice allows analytics; advertising storage and personalisation remain denied.
  • Professional advisers, courts, regulators, law enforcement, or a business successor only where disclosure is necessary, proportionate, and legally permitted. A successor must continue to handle the data consistently with this policy and applicable law.
DigitalOcean privacyCloudflare privacyAnthropic privacyApple privacyGoogle privacyMailgun privacyFirebase privacy and securityPostHog privacy

7. International transfers

Haps is designed to keep its core production application, database, cache, private storage, analytics project, and transactional-email region in the EU. Cloudflare, Anthropic, and some other global providers or their subprocessors may nevertheless process data outside the European Economic Area.

Before production launch, Srex Digital ApS must verify every provider, subprocessor, selected region, retention control, data-processing agreement, and transfer route. Where required, a transfer must rely on an adequacy decision or the European Commission’s Standard Contractual Clauses with appropriate supplementary safeguards. Provider and transfer details will be updated if the production configuration changes.

8. Analytics, website storage, and crash diagnostics

Mobile Firebase Analytics and PostHog event collection are disabled until you grant account-level analytics consent. Haps accepts only a small allowlist of action names and simple properties such as sign-in method, queued or saved state, and whether a setting is enabled. The shared telemetry boundary removes keys related to identity, foods, calories, targets, dates, routes, URLs, queries, and free text.

The public website stores your analytics choice in browser local storage. PostHog and Google Tag Manager are loaded only after an “Allow analytics” choice. PostHog uses in-memory persistence, with broad autocapture, automatic page-view capture, session recording, and person profiles disabled in the website code. Its isolated scroll measurement runs only in consented sessions. After consent, Haps sends sanitized page-view and page-leave lifecycle events for public-site navigation and page exit so aggregate bounce rate, session duration, and content depth can be measured. The send-time allowlist retains ephemeral event, session, and page-view identifiers, page duration, and the maximum content-depth percentage while removing URLs, routes, query strings, page titles, referrers, campaign parameters, pixel scroll positions, all other scroll fields, persistent identity, and unexpected event names. You can refuse when prompted or change your choice at any time through “Analytics settings” in the site footer. Clearing Haps site data also removes the saved choice.

Crash diagnostics are separate from optional analytics and may remain enabled to keep the mobile apps reliable. The Haps wrapper reduces handled errors to a sanitised error type and stack trace rather than the original error message, nutrition fields, or identity fields. No diagnostic system can guarantee that unexpected software failures never expose unintended context, so this boundary is tested and must be reviewed before launch.

9. Notifications and communications

Push notifications are off until you enable a reminder and grant the operating-system permission. Haps sends neutral notification text and a generic destination rather than food names, calorie values, or targets. Delivery depends on Firebase, Apple, Google, your device, and network availability and is not guaranteed.

We send service emails when needed for sign-in, privacy-request verification, export delivery, security, and support.

Haps runs no newsletter and no marketing campaigns. The one exception is the launch reminder: if you ask for it on the Haps website and then confirm your address from the email we send, Haps emails that address a single time, when the apps are first released. You can opt out from the link in either email, and doing so erases the address.

10. How long data is kept

  • Active account, ledger, settings, consent, and synchronisation data are retained while the account is active and as needed to provide Haps.
  • A connected-health authorization attempt expires after 10 minutes and its encrypted verifier is eligible for daily pruning. Connection metadata, daily active-calorie summaries, timestamped weight measurements, and only the newest valid height are retained while the provider remains connected. Total-calorie, step, distance, and exercise-duration summaries from the selected provider are retained only in encrypted local app storage while the connection and account remain on that device; disconnecting that provider, signing out, or switching accounts removes them. Google details pass through the API only in the foreground response and are not retained on the server. Google Health disconnect first revokes Haps' Google OAuth grant and then removes Haps’ live credentials and that provider’s imported activity, weight, and height data. Disconnecting Health Connect or Apple Health removes that provider’s stored connection and imported activity, weight, and height data immediately, because Haps holds no remote grant for either; you can also withdraw the underlying permission in Health Connect or in iOS Settings under Privacy & Security, then Health. If Google reports a temporary revocation failure, Haps keeps the encrypted connection and imported data so you can retry. The original health data remains with the provider and encrypted backups follow the account-deletion expiry below.
  • Email sign-in codes expire after 10 minutes, public privacy-request verification codes expire after 20 minutes, and API sessions expire after 90 days unless revoked earlier. Expiry stops use of the credential; limited security records may remain where necessary.
  • A requested CSV-only export uses a private, single-use download link that expires after 72 hours. The internal target is to complete verified privacy requests within 25 days.
  • Transient nutrition-label assistance uploads are not placed in object storage. Any normalized OCR image temporary file is deleted immediately after processing, including failures. The account-scoped structured refinement result remains in the ephemeral cache for no more than 10 minutes, cannot be polled after consent withdrawal, and is not included in the account export.
  • Nutrition-label scan records, including raw OCR text, parsed output, parser/model metadata, and a stored label image, are pruned after 30 days and deleted earlier if the account is purged. A private contributed product and its front image are deleted when that account is purged. If the contribution was published to the shared catalogue, its product record and private front image remain after purge while the contributor link is removed.
  • A verified deletion request deactivates the account and revokes active sessions and devices immediately. You may recover the account for 30 days. After that, live account data is purged and encrypted rolling backups expire within a further 30 days. Any restored backup must replay the deletion ledger before service resumes.
  • A minimal deletion ledger, hashed former-account reference, and necessary privacy-request, legal, security, or dispute records may be retained for as long as needed to apply deletions to backups, demonstrate compliance, meet law, or establish or defend claims. They are not used to reconstruct the deleted calorie ledger.
  • A launch-reminder address that is never confirmed is deleted 30 days after you submit it. A confirmed address is deleted 30 days after the launch email is sent, or immediately when you opt out, which keeps only a hashed record so the address is not added again by mistake. Deleting your Haps account also removes a launch-reminder entry for the same address.
  • The selected country code and Haps catalogue are cached in encrypted device storage for offline use until refreshed, replaced, or cleared at sign-out.

11. Data on your device

Haps renders from an encrypted local database and keeps durable operation queues so core logging, submitted catalogue-contribution evidence, and connected-health data can continue offline. The activity upload queue keeps only the provider, local date, timezone and offset, active-calorie total or no-data status, and source time. A separate local cache keeps the selected day's provider total calories, steps, distance, exercise duration, and each metric's availability or permission status. Google details are written to this cache from the transient foreground response; Health Connect and Apple Health details are read directly on the device. The cache is not shown in the daily summary, uploaded as durable server data, or included in the server-generated account export. The weight queue keeps the provider, source record identifier, measurement and update times, preserved local date and offset, weight in grams, an exact-day upload generation, and the position marker Haps uses to ask the device for changes since its last read. The height queue keeps only the selected provider's newest source record identifier, measurement and update times, preserved local date and offset, height in millimetres, no-data state, and pending-upload marker. The catalogue-contribution queue keeps the private image URI and comparison payload and waits until the required current-policy processing state is recorded before sending. The selected country, optional override, latest local-food catalogue, connected-app state, and recent activity summaries are also kept locally. The database encryption key and account token are held in the platform Keychain or Keystore for that device. Pending records are sent to the API when synchronisation resumes.

Signing out through Haps clears the app’s locally stored account records and pending-operation queue. Device-level backups, screenshots, notification history, or exports you save outside Haps are controlled by your operating system and your own storage choices.

12. Your data-protection rights

Depending on the circumstances, you may request information and access, correction, deletion, restriction, objection, and data portability, and you may withdraw consent at any time. You may also complain to the Danish Data Protection Agency. These rights can be limited where applicable law allows.

Use the public export and deletion journeys or contact [email protected], including to request correction or removal of a packaged-food contribution or its retained private image. We verify control of the account email before acting and do not reveal whether an account exists before verification. Haps provides account exports as a UTF-8 CSV-only ZIP with protections against spreadsheet-formula injection.

Request a copy of your dataDelete your Haps accountDanish Data Protection Agency: your rightsComplain to the Danish Data Protection Agency

13. Security

Haps uses account scoping, hashed server-side authentication tokens and email codes, encryption in transit, encrypted mobile storage, device-bound secure key storage, private exports and product images, one-use links, generic notification payloads, backups, retry-safe processing, and data-minimising telemetry boundaries. Access is revoked immediately when deletion begins.

No technical or organisational measure makes a service completely secure. Protect your email and devices, install trusted updates, revoke sessions you do not recognise, and report suspected misuse to [email protected].

14. Adults only and automated decisions

Haps is intended only for people aged 18 or older and is not directed to children. We record an 18+ confirmation rather than a date of birth. Contact us if you believe a person under 18 has created an account.

Haps does not make decisions producing legal or similarly significant effects solely by automated processing. Daily target comparisons, recent-food ordering, sync conflict detection, and notification schedules are operational or arithmetic features, not personalised health decisions.

15. Changes to this policy

The version and effective date appear above. We will update this policy when Haps changes what it collects, why it processes data, its providers, retention, or user choices. Material changes will be highlighted in the service, and renewed consent will be requested if an optional consent purpose changes.

Email privacy questions to [email protected]
Haps
© 2026 Srex Digital ApS
Join waitlistAboutGuidesData & privacyPrivacyTermsRequest dataDelete accountSupport