Privacy Policy

Privacy notice on the processing of personal data

This notice explains how CarboZen collects, uses and protects the personal data of users who use the app and related web services.

Last updated: Agosto 2025

1. Introduction

This notice explains how CarboZen collects and processes the personal data of users who use the app and related web services. By using our services, you accept the terms of this Privacy Policy.

2. Data controller & contacts

Data controller: CarboZen.
Contact email: info@carbozen.it

3. Data processed

  • Email as an identifier for login and communications. We do not require first and last name.
  • Uploaded photos (meal images) and analysis results generated by the app.
  • Technical data such as logs, IP address, device type and any crash events, for security and service improvement.

Photos and analysis results may imply health-related data (special categories under art. 9 GDPR). Such data are processed only with your explicit consent and for the purposes indicated below.

4. Purposes and legal bases

  • Provision of the service (account creation, meal analysis, saving results) — performance of a contract (art. 6.1.b GDPR).
  • Security, abuse prevention, debugging — legitimate interest (art. 6.1.f GDPR).
  • Processing of photos/analyses potentially related to health — explicit consent (art. 9.2.a GDPR).
  • Service communications (e.g. password reset) — performance of a contract.

5. Anonymized data and aggregated use

We may use data in anonymized and aggregated form (not attributable to individual users) for statistical analysis, model improvement, research, publications, reporting, commercial purposes and partnerships, for example with research bodies or companies in the health/food sector.

We do not sell identifiable personal data such as email addresses and we do not share content that could directly identify you.

You may object at any time to the use of your data for such statistical or research purposes, when not already anonymized, by writing to info@carbozen.it.

6. Data retention

We keep data for as long as necessary to provide the service and in any case no longer than required by applicable law. Photos and results may be deleted upon user request. Inactive accounts may be periodically anonymized or deleted.

7. Processors & transfers

We use Supabase as an infrastructure provider for authentication, database and storage. Supabase acts as a Data Processor pursuant to art. 28 GDPR.

Data may be hosted in data centers located in the European Union or in third countries with adequate safeguards, for example Standard Contractual Clauses. Additional technical providers may be used for logs, analytics or email delivery, always acting as Processors.

8. Sharing with third parties

We do not sell personal data. We share personal data only if: (i) required by law or by request of competent authorities; (ii) with technical providers strictly necessary to provide the service; (iii) with your consent.

We may share anonymized or aggregated data for research and commercial purposes as described above.

9. Security

We adopt technical and organizational measures to protect data, such as encryption in transit, access controls and system monitoring. However, no measure is absolute: we encourage the use of strong passwords and the protection of personal devices.

10. Children under 16

The service is not intended for children under 16 years of age. If you believe that a minor has provided us with data without the consent of a parent or guardian, contact us to request its removal.

11. Your rights (GDPR)

You may exercise your rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, where applicable, by contacting us at info@carbozen.it. You also have the right to lodge a complaint with the competent data protection authority.

12. Cookies and analytics

We may use cookies or measurement tools for strictly technical purposes and aggregated analytics. Where required, we will show a consent banner and preferences can be managed.

13. Changes to this notice

We may update this Privacy Policy. In the event of substantial changes, we will inform users through notices in the app, on the website or by email.

14. Contacts

For any question or request related to privacy, you can write to info@carbozen.it.