Privacy policy

Effective from August 24, 2026 · information on data processing under the GDPR and transparency of artificial-intelligence features

1. Data controller

The data controller is Jan Alexandr Janicek, Nove sady 988/2, 602 00 Brno - Stare Brno, Czech Republic, Company ID (ICO) 74651382. Contact: info@histamin.io.

2. What data we process

  • Email address – provided at registration, used for sign-in and communication.
  • Password – we store it only in a secure, one-way derived form and never store the password itself.
  • Plan and credit data – current plan, one-time trial data (grant date, end date, and grant method), subscription identifiers from the payment provider, Assistant credit balance and usage, and the necessary audit of administrative account changes. We do not store payment-card data.
  • Scan history – product compositions and analysis results that the user chooses to save.
  • Diary data – voluntarily entered meals, reactions, symptoms, and related factors. This data may reveal health information.
  • Physiological profile – month and year of birth, sex, height, and weight provided to tailor the personal histamine-load calculation. In this context, this information may reveal health information.
  • Data for artificial-intelligence features – text prompts, Assistant conversations, recipe text, data needed for a quick diary entry, a limited summary of saved reactions used for optional personalisation, and images uploaded for analysis. We send data to Google Gemini only for a user-requested feature; saved reactions are added to context only after personalisation is separately enabled. We do not send reaction notes or audio recordings to Gemini.
  • Consent records – date, IP address, user agent, and type of consent (terms, marketing, health-data processing in the diary and physiological profile, or optional Assistant personalisation) under Art. 7 GDPR.
  • Loyalty data – a stable internal account ID, points, rewards, and usage events required for the Perkamo loyalty program.
  • Analytics and advertising-measurement data – traffic statistics via Google Analytics and completed-conversion data. If you give the relevant consent, conversions imported from Google Analytics may also be used in Google Ads to measure and optimise advertising.
  • Activity data for marketing purposes – viewed foods, search queries, and completed conversions (registration and subscription payment). We share it with Meta only with your marketing consent. This data may reveal health information.

4. Retention period

  • Account data is retained for the lifetime of the account.
  • Plan, trial, and Assistant-credit data are retained for the lifetime of the account and deleted with it. We anonymise administrative audit records related to a deleted account.
  • Assistant conversation history, including your prompts and responses, is retained for no more than 180 days after the last message in that conversation; you can delete an individual conversation sooner. We do not retain original one-off diary-draft text outside this history or any audio recording. Images saved with scans or feedback are retained with the relevant record.
  • After you withdraw health-data consent in your profile, we delete diary data including food-tolerance check records and the physiological profile without undue delay. If you gave consent before withdrawing it, we may aggregate reactions into summary statistics without a link to the account before deleting their source records. Assistant conversations are not deleted by this withdrawal and can be deleted individually. Choice records remain for the lifetime of the account.
  • After account deletion, data used to operate the account is removed without undue delay and no later than 30 days. If you gave consent to diary-data processing before deleting the account, reactions may remain as summary statistics without a link to the account.
  • After the Perkamo profile is erased, only a pseudonymised internal identifier remains to prevent delayed or repeated events from recreating the deleted profile; it retains no profile or loyalty data.
  • Consent records are retained for the lifetime of the account and are deleted with it.

5. Data recipients

We do not sell your personal data. We share it with third parties for marketing purposes only with your explicit consent and within the scope described below. Data may be shared solely with:

  • The hosting provider (processor, bound by a data processing agreement).
  • Google LLC – within reCAPTCHA, Google Analytics, and Google Ads. We use Google Analytics to measure visits; with consent, completed-conversion data may be imported into Google Ads to measure and optimise advertising.
  • Meta Platforms Ireland Limited – operator of Facebook and Instagram. Only when you give marketing consent. We share website activity information (viewed foods, search queries, completed registration and subscription payment) and browser technical identifiers. Registered office: Merrion Road, Dublin 4, Ireland. Meta policy: facebook.com/privacy/policy.
  • Google LLC – through the Gemini API only when the user requests the relevant feature; depending on the feature, we transfer a text prompt, recipe text, necessary diary context, a limited summary of saved reactions, or an uploaded image, but not reaction notes or audio files.
  • Brevo SAS (formerly Sendinblue) – an email marketing platform; your email address is passed only if you consented to receive updates. Registered office: 7 rue de Madrid, 75008 Paris, France. Processing takes place within the EU.
  • Stripe Inc. – payment gateway for processing payments. More info: stripe.com/privacy. For transfers to the United States, we use standard contractual clauses under Chapter V GDPR.
  • Apple – processor of subscription purchases in the iOS application through the App Store. Apple processes purchase data under its privacy policy.
  • Perkamo – a loyalty points and rewards service; we provide a stable internal account ID, selected profile data, and usage events needed to calculate rewards.
  • Google uses standard contractual clauses under Chapter V GDPR for transfers of personal data to the United States. Meta uses the EU–US Data Privacy Framework for transfers to the United States; where another mechanism is relevant to a particular transfer, it uses appropriate safeguards under Chapter V GDPR. We will provide details of the safeguards on request.

6. Processing personal data when using artificial intelligence (AI) features

To provide advanced application features – in particular to facilitate communication, analyse and recognise the content of uploaded images and photographs, and automatically suggest data entries – we use artificial intelligence technologies (large language and vision models) provided by Google Ireland Limited or Google LLC through the Gemini API.

We process only text inputs (prompts), image files, and data necessary to fulfil the request. If you gave explicit consent, Assistant personalisation may also use a limited summary of your saved reactions without free-text notes or family data. The general legal basis is performance of the application agreement (Art. 6(1)(b) GDPR), depending on the feature; health data is processed solely on explicit consent under Art. 9(2)(a) GDPR.

Data security and use for training

Communication with artificial intelligence, including the transfer and analysis of image data, takes place through the paid Gemini API in a commercial service mode. Under Google's paid-services terms, Google does not use submitted prompts, files, or generated responses to train or improve its products. Google may retain them for up to 55 days solely to detect violations of its usage rules. We do not enable optional developer logging or dataset sharing. Images used only for a one-off analysis are not retained in our application; if the user explicitly saves them with a scan or feedback item, their retention follows the relevant record. Images are not used for biometric identification of individuals.

Transparency and human control

AI-generated responses and suggestions are labelled in the application and are advisory only. A proposed diary entry or data change is not fully automated decision-making within the meaning of Art. 22 GDPR. A final entry or data change is made only after your explicit approval and review in the user interface. Because of the technical limitations of generative AI, we recommend checking all suggested data before confirming it.

7. Your rights

You have the right to:

  • access your personal data (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (“right to be forgotten”, Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • portability of data (Art. 20 GDPR),
  • objecting to processing based on legitimate interests (Art. 21 GDPR),
  • withdrawal of consent at any time without giving a reason,
  • lodging a complaint with the Office for Personal Data Protection (uoou.cz).

Send requests to info@histamin.io. We will respond within 30 days.

8. Cookies

We use three categories of cookies and similar technologies: essential technical cookies – session, storing your consent choice, and abuse protection; analytics cookies – Google Analytics 4 for measuring visits and use of the Service; marketing cookies – Google Ads Conversion Linker and Meta Pixel for measuring advertising effectiveness and targeting advertising. We load the Google tag and related measurement only after at least one optional consent category is granted; the measurement scope then follows the selected categories.

To evaluate the cookie banner, we store only aggregate daily statistics by domain and decision type, without an individual decision history. You can change or withdraw your choice at any time in the cookie settings in the website footer.

NamePurposeProviderCategoryLifetime
cookie_consent_analyticsStore the analytics-cookie choiceHistamin.ioEssential1 year
cookie_consent_marketingStore the marketing-cookie choiceHistamin.ioEssential1 year
cookie_consentCompatibility with the previous cookie-settings versionHistamin.ioEssential1 year
_ga, _ga_*Measure visits and use of the ServiceGoogle LLCAnalyticsup to 2 years
_fbpMeasure advertising effectiveness and target advertisingMeta Platforms Ireland LimitedMarketingaccording to the provider's current configuration (usually 90 days)
_fbcStore the Meta advertising-click identifier for measuring advertising effectivenessMeta Platforms Ireland LimitedMarketingaccording to the provider's current configuration (usually 90 days)
_gcl_auStore the identifier used to measure Google Ads conversionsGoogle LLCMarketingaccording to the provider's current configuration (usually 90 days)

9. Security

Passwords are stored only in a secure, one-way derived form. Communication takes place encrypted over HTTPS. Database access is restricted to the necessary minimum.

10. Changes to the policy

We will inform you of any material changes by email. The current version is always available on this page.