Unpound

Privacy policy

Last updated 7 August 2026 · version 2026-08-07

Unpound records what you eat, what you weigh and how much you move. That is health information about your own body, and it is treated as such: it is stored to show you back to yourself, and for nothing else.

Who is responsible

The controller of the personal data described here is:

Kai Vijzelaar, trading as Unpound
De Slufter 4
1771 JB Wieringerwerf
The Netherlands
Chamber of Commerce (KvK) number 42128648
VAT identification number NL005517249B05
privacy@unpound.com

Unpound is a sole trader, so there is no company between you and the person responsible — the controller is the individual named above, and nothing in this policy is limited by an entity that does not exist.

What is stored, and why

What Why Legal basis
A sign-in identifier from Apple or Google, and your email address where the provider confirms that it is verified To recognise your account and let you back into it Performance of our contract with you
Your height, date of birth, biological sex and activity level To work out an energy target. Without them the app can count but not advise Performance of our contract with you, and your explicit consent (Article 9(2)(a) GDPR)
Weights you record, and the dates you recorded them To show your trend over time Performance of our contract with you, and your explicit consent (Article 9(2)(a) GDPR)
Foods and meals you log, and any foods you add to your library To keep your diary and total your day Performance of our contract with you, and your explicit consent (Article 9(2)(a) GDPR)
How much you drink each day, as a running total To fill the day towards the target you set Performance of our contract with you, and your explicit consent (Article 9(2)(a) GDPR)
Steps, active energy, exercise minutes and distance, read from Apple Health with your permission. iPhone only To count movement without you having to log it Performance of our contract with you, and your explicit consent (Article 9(2)(a) GDPR)
Whether your subscription is in trial, active, lapsed or cancelled, its start and end date, the product, the store and the transaction identifier the store gave it To know whether to let you in, and to react when the store tells us something changed Performance of our contract with you
How you want figures shown and the day set up: weight and energy units, light or dark, what one tap on the liquid card adds and the daily figure it fills towards, the hours you mean to fit your eating into, and an energy target you set yourself To show you your own numbers the way you asked for them Performance of our contract with you
Which version of this policy and of the terms you agreed to, and when To be able to show which wording you were given rather than assert that you were given one A legal obligation — Article 7(1) GDPR puts the burden of demonstrating consent on us — and performance of our contract for the terms
If we ever suspend an account under the terms: the date and the reason we give you To withdraw access for a breach of the terms, and to be able to tell you why Performance of our contract with you, and our legitimate interest in a service that is not abused
When a warning or error occurs: technical connection and security data, such as your IP address, the time and address of the request, a request ID, the response status and technical error information To secure the service, prevent abuse and resolve technical problems Our legitimate interest in a secure and reliable service
If you email us: your sender address, technical message headers, and the content and any attachments of your message To provide support, handle privacy requests and administer the related correspondence Performance of our contract for support; a legal obligation for GDPR requests; and our legitimate interest in handling other correspondence carefully and, where necessary, establishing a legal claim

Unpound never stores your payment details or the amount you paid. Apple and Google tell us only which purchase belongs to your account and whether it gives you access.

Health data

Weight, body measurements, food intake and movement are special category data under Article 9 of the GDPR. Two things have to be true before we may hold it, and they are not the same thing. We rely on our contract with you under Article 6(1)(b) GDPR, because a food diary cannot be provided without processing what you put in it; and on your explicit consent under Article 9(2)(a) GDPR, which is what lifts Article 9's prohibition on health data. The app asks for that explicit consent on its own screen before you enter anything — and the server insists on it, refusing to store a profile, a diary entry or a weight until it is on record. Granting Apple Health access is a second, separate consent, asked for by iOS.

You can withdraw that consent at any time. You can do so in the app by deleting your account, or by writing to us at the address below. Withdrawal is as easy as giving consent and does not affect the lawfulness of earlier processing. Because Unpound cannot provide its core service without this health data, we will then close the account and erase that data.

Data read from Apple Health is never used for advertising or marketing, is never sold, and is never shared with anyone. Apple requires this, and we would do it anyway.

What we do not do

Who else sees it

The app communicates only with its own server, Apple and Google. Scaleway processes the app data for us; DigitalOcean serves this website and answers the domain's DNS; Google Workspace processes email for us. Apple and Google act on their own account for sign-in and the sale of a subscription. Google therefore has two different roles: as an independent party for Google Login and Google Play, and as our processor for Google Workspace.

The app and its database are hosted in Amsterdam, and your diary and health data entered in the app remain in the European Union. The website is a separate thing from them and holds none of it. Apple and Google process their own account and transaction data for sign-in and any purchases under their own privacy policies. Google may also process Workspace correspondence outside the European Economic Area; the European data-at-rest setting does not mean that all processing takes place exclusively in Europe. Applicable safeguards, such as an adequacy decision or standard contractual clauses, are used for transfers outside the EEA. You may ask us at privacy@unpound.com for more information about those safeguards.

Do not send health data by email unless it is necessary for your question. If it is necessary, include this statement in your message: “I explicitly consent to Unpound processing the health data in this message to handle my request.” This is your explicit consent under Article 9(2)(a) GDPR; handling the question itself rests on the bases described above. If that confirmation is missing, we will ask for it before using the health data substantively. You may withdraw consent, although this can mean that we cannot continue handling the question.

Cookies

This website sets one cookie, and not one we chose. Cloudflare, which delivers the site on DigitalOcean's behalf, sets __cf_bm to tell a browser apart from a bot. It expires after thirty minutes, it contains no name, email address or account, and we neither read it nor get anything out of it. It is set without asking because it is strictly necessary to deliver the site you asked for, securely — and for that, Dutch law does not require your consent first.

There is nothing else. No analytics cookie, no advertising cookie, no tracking pixel, and no script, font, image or stylesheet loaded from any other domain — every page here is served from this one. The app sets no cookies at all.

Foods you add

Unpound ships with a catalogue of packaged products so that scanning a barcode usually finds something. That catalogue contains no personal data.

Foods that you create are not added to the shared catalogue and cannot be found by other users. Another user who has already saved such an item in their own library does keep it there. If you delete your account, we remove its link to you. Only the name, brand and nutritional values then remain, without an account, email address or other technical link to you, for the libraries in which the item was already stored. Name and brand are free-text fields. Do not put a name, email address or other personal data in them. If you do, the text itself may remain recognisable after the technical link is removed, and the item is not necessarily anonymous. Tell us at privacy@unpound.com if such text needs to be removed or replaced.

How long it is kept

For as long as your account exists. Delete your account — Settings, then Delete account, or from the page for it if you no longer have the app — and your account, health data, sessions and all subscription data are erased from the database immediately. A technical acknowledgement of a store notification remains for thirty days. It contains only the message sequence number, without a name, account or subscription data. Foods you entered yourself remain only in the detached form described above.

Deletion from the active database does not immediately alter an existing database backup. A backup may therefore still contain a copy of deleted data. Backups are kept outside the active service, cannot be accessed through the app and are used only to restore the service as a whole after a serious failure — not to retrieve a deleted account. A backup is replaced or deleted when it is no longer needed for safe recovery, taking account of the availability and integrity of newer recovery points.

Technical platform logs in Scaleway Cockpit are erased after seven days. Technical database logs are kept for no more than thirty days. We do not use these logs to analyse your use or build a profile of you. Production logging on the app server is set to Warning: ordinary successful requests do not enter the application log.

Visits to this website are logged by DigitalOcean and Cloudflare to run and protect it, on their own retention periods. Those logs record a connection, not a person: there is no account behind this website to attach one to. We do not use them to analyse you, and nothing in them is joined to your Unpound account.

Email sent to support or privacy, including attachments, is deleted twelve months after our last substantive response. We delete health data sooner once it is no longer needed for the question. The period is extended only for as long as an ongoing complaint, legal claim or statutory retention duty makes that necessary.

An account that nobody has signed into for two years is erased on its own in the same way. Health data should not sit in a database belonging to somebody who has moved on, and an account with no end is what that would be. The two years run from the last time you were here rather than from when you signed up, so using the app keeps it indefinitely.

Your rights

Two of these you can exercise yourself, without asking and without waiting: Settings, then Export my data hands you one file with your whole account in it, and Settings, then Delete account erases it. Both are free and neither needs a reason.

Under the GDPR you may also ask us to:

Write to privacy@unpound.com. We will respond without undue delay and within one month. The GDPR lets us extend that period by two months only for a complex request or many simultaneous requests, in which case we will tell you within the first month. If you are not satisfied with the answer you may complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority where you live.

Children

Unpound is for people aged 16 and over, and the app will not accept a younger date of birth. Sixteen because holding health data rests on your consent, and below that age the law in several countries — including the Netherlands and Germany — asks for a parent's agreement instead, which Unpound has no way to obtain. We do not knowingly keep data about anyone younger; if you believe a child has an account, write to us and it will be removed.

Security

Traffic is encrypted in transit. The sign-in token that keeps you signed in is held in your device's secure storage — the keychain on iPhone, the keystore on Android — rather than in ordinary app storage, tied to that device and left out of backups. Only a one-way hash of it is stored on our side, so a copy of our database would yield nothing anyone could sign in with. Access to the database is restricted to the application.

No system is perfect. Where notification is required, we will report a personal-data breach to the competent supervisory authority, where feasible, within 72 hours after becoming aware of it. If it is likely to result in a high risk to you, we will tell you without undue delay.

Changes

The app records which version of this privacy information was shown to you. If the policy changes materially, we will tell you before the change takes effect. For a new purpose or a materially different use that requires consent, we will separately ask for your explicit consent again. The version at the top is the one in force. Smaller corrections are published here with a new date and no new version.