Deutsch · English

ALPINA+SANA – Privacy Policy

Alpinasana AG · Schaffhauserstrasse 230a · 8057 Zurich · Switzerland · Version: 24 August 2026

This document is an English convenience translation of the German original («Datenschutzerklärung»). In the event of any discrepancy, the German version shall prevail.

1. Controller and contact

The controller responsible for the processing of your personal data in connection with the mobile application «ALPINA+SANA» (the «App») and the associated services (together the «Services») is:

Alpinasana AG, Schaffhauserstrasse 230a, 8057 Zurich, Switzerland

Email for data protection matters: support@alpinasana.ch

2. Scope and applicable law

This Privacy Policy describes how we process personal data when you use the App and the Services, communicate with us or are otherwise in contact with us. «Personal data» means any information relating to an identified or identifiable natural person (Art. 5 let. a of the Swiss Federal Act on Data Protection, FADP). Swiss law, in particular the FADP, is decisive. The App is offered exclusively through the Swiss Apple App Store and the Swiss Google Play Store and is intended for persons of legal age resident in Switzerland.

By using the Services, you confirm that you have taken note of this Privacy Policy. Where we require your consent for specific processing activities – in particular for the processing of health data (Section 5) – we obtain it separately and expressly in the App.

3. What personal data we process

3.1 Account and contact data

A name and an email address are required to use the App; you may optionally provide your telephone number. This information is stored and used for App access. We may also use it to contact you after around four weeks to arrange a voluntary feedback interview. In addition, we do not store your PIN code itself, but only a cryptographic verification value (hash) derived from it; the PIN code is used to sign in to the App. When registering, you also confirm that you are of legal age and resident in Switzerland; we store this confirmation together with the consent records (Section 3.3).

The App language you select serves to display the App’s content and functions in the appropriate language. When you log a meal, the App language selected at that time is transmitted to our servers and stored together with the meal entry; we use it to generate the AI-based results for that meal (e.g. ingredient names and any clarifying questions) in the correct language. This is to be distinguished from the device language, which is processed in the context of subscription management (Section 3.5) and error analysis (Section 3.8).

You may optionally indicate which person or institution recommended the App to you. This information is stored together with your account data and evaluated for the improvement and further development of the App and its offering; we use the results of this evaluation in aggregated form only. When you create your profile, we also record your age and gender; we use this information to calculate your daily targets (if requested) and, in aggregated form not related to individual persons, for the improvement and further development of the App and its offering (including pricing and offer design). If you communicate with us (e.g. support requests), we also process the content of that communication.

3.2 Health-related data (sensitive personal data)

The core functions of the App concern your nutrition. In doing so, we process data that may qualify as health data and thus as sensitive personal data within the meaning of Art. 5 let. c no. 2 FADP. Such data is processed only with your express consent (Section 5):

  • meal logs (time, description, scanned products and – for text entries – the clarifying dialogue with the AI model, i.e. its follow-up questions and your answers);
  • photos of your meals;
  • AI-estimated nutritional values (energy (kcal), protein, fat, carbohydrates);
  • your daily targets (energy, protein) and the comparison with your actual nutritional intake;
  • reminders for meals and for the intake of foods for special medical purposes (FSMP), including the products and intake times you record (these entries are optional);
  • your optional self-assessment of your state of health and nutrition. We evaluate this exclusively in aggregated or anonymised form for the improvement and further development of the App;
  • your voluntary information on the reasons for using the App. We evaluate this information for the improvement and further development of the App and its offering; we use the results in aggregated form only.

Height and weight: If you wish your daily targets to be calculated automatically, you provide your height, weight and activity level. This information is transmitted to our servers to perform the calculation, used there exclusively for that calculation, is not stored permanently and is deleted once the calculation is complete. Only the resulting nutritional requirement is stored.

3.3 Consent records

We log when, and in which version, you accepted our Terms of Use and granted or withdrew your data protection consents.

3.4 Feedback data

If you take part in the voluntary feedback interview, we record your feedback in the form of notes and summaries. These are used for the evaluation and further development of our Services, wherever possible in aggregated or pseudonymised form. We store the notes and summaries in our internal repository (Microsoft SharePoint, Section 7).

Through the feedback function in the App, you may at any time send us feedback and suggestions for new features or feature changes. In doing so, we process the category you select, your free-text entries, your indication of whether we may contact you about your feedback, and technical information about your device (platform, operating system and App version, device model) so that we can classify your feedback technically. We store this feedback together with your account and use it for the evaluation and further development of the Services. Only if you agree to being contacted do we use your contact details for follow-up questions about your feedback. Please do not include any health information or personal data of third parties in free-text feedback.

3.5 Device, usage and subscription data

To manage your subscription, we process – through our service provider RevenueCat – a pseudonymous user ID (a random internal identifier without your name or email address), your purchase history (e.g. sign-up, renewal, cancellation) and basic device information (device model, operating system, device language). RevenueCat cannot attribute the pseudonymous user ID to any person; only we can link it to your account.

3.6 Payment data

All payments are processed by Apple (App Store) or Google (Google Play). These providers process your identity and payment data under their own responsibility within your respective store account. We do not receive or store any payment card data.

3.7 Barcode queries

When you scan a product barcode, our server queries the Open Food Facts product database; only the barcode number is transmitted. No information about you – not even your IP address or device information – is transmitted to Open Food Facts.

3.8 Technical diagnostic and error data

To detect and resolve technical problems, we record diagnostic data when errors or crashes occur in the App: technical error logs (stack trace, error type, system state), App version and build, operating system version and device model, device language, technical status data (e.g. battery, memory and network status) and a technical log of the last user actions before the error (e.g. screen opened, failed server call). This data contains no meal content (photos, descriptions), no information such as height or weight, and no names or email addresses; no IP addresses are stored in crash reports. Wherever possible, the data is pseudonymised.

When our servers are accessed, standard access logs are also created containing the IP address of your device, the time and technical details of the request. They serve exclusively for security, abuse prevention and troubleshooting and are automatically deleted after 7 days.

4. Purposes of processing

We process your personal data for the following purposes:

  • provision of the Services, in particular meal logging, AI-based nutritional estimation, calculation of daily targets, comparison of your actual nutritional intake with your daily nutritional requirement, reminders, display of your history and creation of PDF reports. You send or share a report yourself via your device’s share function (e.g. with your email app); we do not send reports and do not learn to whom you pass on a report;
  • management of your user account and your subscription;
  • customer support and communication with you;
  • ensuring security, stability and abuse prevention, including the evaluation of technical diagnostic and error data to detect and resolve technical problems (Section 3.8);
  • analysis, improvement and further development of the App and its offering (including pricing and offer design), in particular the evaluation of suggestions submitted via the feedback function, the review and improvement of the accuracy of the nutritional estimation on the basis of individual meal entries (Section 6), and aggregated evaluations not related to individual persons concerning the use of the App’s functions and based on age, gender, recommending party, the reasons for using the App and the optional self-assessment of your state of health and nutrition;
  • contacting you after around four weeks of App use to arrange a voluntary feedback interview and evaluating your feedback;
  • compliance with legal obligations and the establishment, exercise and defence of legal claims.

We do not sell or rent your personal data and do not pass it on to third parties for advertising purposes.

5. Legal bases and consent

For the processing of sensitive personal data (Section 3.2), we obtain your express consent before you use the corresponding functions. Giving consent is voluntary. As the processing described is a technical prerequisite for operating the App, the App cannot be used without this consent.

You may withdraw your consent at any time, without giving reasons and with effect for the future. You can declare the withdrawal directly in the App under Profile → «Withdraw consent». The withdrawal does not affect the lawfulness of the processing carried out up to that point. After withdrawal, you can no longer use the affected functions. Section 9 governs the retention, deletion and anonymisation of your data after withdrawal. If you grant your consent again within 30 days of the withdrawal, you can continue to use the App with your existing data; after that, your data is irretrievably deleted.

We process personal data in accordance with the principles of the FADP. Where justification is required for a particular processing activity, it may lie in particular in your consent, in an overriding private or public interest (e.g. security, aggregated evaluations for the improvement and further development of the App and its offering, enforcement of legal claims), in the performance of the contract with you, or in the law.

6. AI-based analysis of your meals

To estimate nutritional values, we transmit the meal photo or your text description, together with a general instruction for nutritional analysis, to Google’s Gemini API. The following applies:

  • We do not transmit any account or identification data (name, email address, user ID). For text entries, a short dialogue with clarifying follow-up questions from the model may also take place. The content of your photos and texts is in your hands. With the exception of the capture time and the image orientation, we remove the metadata of your photos – in particular location data – on your device before the photo is transmitted.
  • Google acts as our data processor. We use the paid enterprise version; under the contract, the transmitted content and the generated responses are not used by Google to train or improve its AI models. Google logs requests only for a limited period for abuse monitoring and security purposes.
  • From Gemini’s response, we store the structured nutritional values. In addition, we store the meal photo or your description and any clarifying dialogue (the model’s follow-up questions and your answers) as part of your meal log (Section 3.2). No further model output is stored.
  • In two cases, trained and authorised Alpinasana staff may view meal photos, meal descriptions (including the clarifying dialogue) and the associated estimates: exceptionally, where the automatic estimation cannot be completed, and for quality assurance – in particular where an estimate appears to be incorrect, where you report a problem to us, or on a random-sample basis to review the accuracy of the estimation. Your name and contact details are not visible in this process; access follows the need-to-know principle and serves exclusively to produce, review and improve the nutritional estimation. This does not alter the fact that Google does not use the content to train its AI models.
  • The nutritional values returned are automatically generated estimates without legal or medical authority.
Note: Photos may unintentionally show faces, other persons or your surroundings; they are transmitted unredacted. Where possible, photograph only the meal itself and avoid other persons or third parties’ personal data being visible. If third parties or their personal data are nevertheless identifiable, the photos will still be used for nutritional analysis. Please do not upload such photos or delete the relevant meal entry in the App without delay (see Section 9 of the Terms of Use); deleting a meal entry also deletes the associated photo.

7. Recipients of the data (processors and third parties)

We use the following service providers to operate the Services. Data processing agreements are in place with our processors, restricting the processing to our purposes:

Service providerFunctionData processedLocation / safeguards
Amazon Web Services (AWS) Hosting of the App backend and data storage; processing as a data processor exclusively on our instructions. AWS accesses data content only to the extent required to provide and maintain the services or where legally required. Account data (name, email, telephone number, PIN verification value (hash)), profile data, health-related data (meal logs, photos, nutritional values, targets, FSMP plan, self-assessment), consent records, feedback data Data centre Stockholm, Sweden (EU-North-1); data processing agreement with EU protection standards; storage encrypted
Google (Gemini) AI analysis of meal photos and descriptions (data processor) Only the content of the meal entry (photo or text description, incl. any clarifying dialogue), without identifiers Paid enterprise version; no use for AI training; time-limited logging for abuse monitoring; transfers possibly to the USA (safeguards as per Section 8)
RevenueCat Management of App subscriptions Pseudonymous user ID, purchase history, device information (model, OS, device language); no names, email addresses or health data USA; data processing agreement with safeguards as per Section 8
Apple App Store / Google Play Distribution of the App and payment processing Identity and payment data within your store account; knowledge of your ALPINA+SANA subscription Independent controllers; their own privacy policies apply
Open Food Facts Product database for barcode scans Only the barcode number, no personal data France (non-profit organisation)
Sentry (Functional Software, Inc.) Error and crash analysis (data processor) Technical diagnostic data as per Section 3.8, pseudonymised; no meal content, names or email addresses EU data region (Frankfurt, Germany); data processing agreement
Microsoft Internal filing and collaboration (Microsoft 365/SharePoint): notes and summaries from feedback interviews Interview notes, summaries and the contact details needed to arrange appointments; no meal logs or photos Data centre region Switzerland; data processing agreement (Microsoft Data Protection Addendum)

In addition, we may disclose personal data where we are legally obliged to do so (e.g. to authorities and courts), to enforce our rights, or in the context of a corporate transaction (e.g. merger or sale), in which case the protection of your data is maintained.

8. Disclosure abroad

Your App data is stored in the AWS data centre in Stockholm (Sweden); technical diagnostic data (Section 3.8) is processed in the EU data region of our service provider Sentry in Frankfurt (Germany). Under Art. 8 para. 1 in conjunction with Annex 1 of the Swiss Data Protection Ordinance (DPO; SR 235.11), Sweden, Germany and France provide an adequate level of data protection.

Individual service providers process data outside Switzerland and the EU. For RevenueCat (USA), the disclosure is based on the EU Standard Contractual Clauses agreed with RevenueCat, as adapted to Swiss data protection law. In the case of Google, data may be transferred to the USA or to other countries in which Google or its sub-processors maintain facilities. Google LLC is certified under the Swiss–U.S. Data Privacy Framework; for certified companies, the Swiss Federal Council recognises an adequate level of data protection (Annex 1 DPO). For transfers to other countries without adequate data protection, the EU Standard Contractual Clauses agreed with Google apply. You may request a copy of the relevant contractual safeguards via the contact address in Section 1. In the case of Microsoft, remote access from third countries in the context of support and maintenance work cannot be excluded; Microsoft is certified under the Swiss–U.S. Data Privacy Framework, and the EU Standard Contractual Clauses agreed with Microsoft additionally apply.

9. Retention and deletion

  • Account and health-related data: for as long as your account exists. You can delete individual entries in the App at any time. After deletion of your account or withdrawal of your consent, your personal data is deleted from the production system within 30 days, unless statutory retention obligations apply. Aggregated evaluations already produced (Section 4) do not allow any conclusions to be drawn about you, are not personal data and remain unaffected by the deletion.
  • Data from voluntary feedback interviews: once the evaluation is complete, the data – including the copies and versions in our internal repository (Section 7) – is deleted or fully anonymised.
  • Accounting and billing-related records: where legally required, generally for up to 10 years.
  • Consent records: for as long as required for evidential purposes.
  • Backup copies are created automatically and deleted after fixed retention periods. Deleted data may remain in backup copies for a limited time (no longer than 90 days); it is not actively processed there and is deleted again in the event of a restore.
  • Technical diagnostic and error data: only for as long as required for error analysis, generally no longer than 90 days; thereafter it is deleted.
  • Server access logs (including IP addresses): automatic deletion after 7 days.
  • Feedback submitted via the feedback function: after deletion of your account or withdrawal of your consent, this feedback is not deleted but anonymised. We remove your name, email address and telephone number as well as the link to your account. Anonymised feedback does not allow any conclusions to be drawn about you, is not personal data and may continue to be used by us for the improvement and further development of the App and its offering.

10. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss and misuse, in particular encryption in transit and at rest, access restrictions based on the need-to-know principle, and logging. However, no system offers absolute security; complete security of data transmission and storage cannot be guaranteed.

11. Your rights

Under the FADP, you have in particular the following rights:

  • information as to whether and which personal data we process about you;
  • correction of inaccurate personal data;
  • deletion of your personal data, unless retention obligations prevent this;
  • delivery or transfer of the personal data you have provided to us, in a commonly used electronic format;
  • objection to certain processing activities;
  • withdrawal of consents granted, at any time and with effect for the future (directly in the App, Section 5).

To exercise your rights, a message to support@alpinasana.ch is sufficient. We may request proof of identity. You can also delete your account, including your data, directly in the App. You are free to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) (www.edoeb.admin.ch).

12. No automated individual decisions; no high-risk profiling

We do not take any automated individual decisions that have legal effects for you or significantly affect you. The AI-based nutritional estimates and target calculations are purely informational functions that you can adjust manually at any time.

13. Minors

The Services are intended exclusively for persons of legal age (18+). We do not knowingly process personal data of minors. If we become aware that a minor has opened an account, we delete that account and the associated data.

14. Changes to this Privacy Policy

We may amend this Privacy Policy at any time. The version published in the App at the relevant time is decisive. We will inform you of material changes in the App or by email; where processing is based on your consent and is materially extended, we will obtain your consent again.

15. Contact

Alpinasana AG
Schaffhauserstrasse 230a
8057 Zurich, Switzerland
Email: support@alpinasana.ch