SnackUp

Privacy Policy

Last updated: September 2026

This is a translation provided for information purposes only. As this business is registered in Germany, the German version is the legally binding one. → German version

1. Data controller

Mathieu Joestens
Mathys Lab
Gebrüder-Künnemeyer-Str. 34
32805 Horn-Bad Meinberg
Germany
Email: contact@snackup.fun

2. This website (snackup.fun)

This website uses no cookies, no tracking or analytics tools, and does not measure its audience. No external service (fonts, maps, videos) is embedded that would transfer data to third parties — the font used is hosted locally on this server.

Local storage for the theme — if you pick the light or dark theme, that choice is kept in your browser's local storage (key snackup-theme) so it can be applied again on your next visit. It stays on your device, is transmitted to no one, and cannot be used to recognise you: this is storage strictly necessary to provide the service you explicitly requested (§ 25(2) no. 2 TDDDG), and therefore requires no consent. You can erase it at any time by clearing site data in your browser.

Hosting — this website is hosted on GitHub Pages, a service of GitHub, Inc. (88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA). When you visit the site, your browser transmits technical access data (server log files) to that host: IP address, date and time of the request, page accessed, browser and operating system used. This processing serves to ensure the reliable and secure delivery of the site (Art. 6(1)(f) GDPR); the data is deleted automatically after a short period and we have no access to it ourselves.

Hosting involves a transfer of data to the United States. GitHub covers such transfers with the European Commission's standard contractual clauses; its parent company, Microsoft Corporation, is additionally certified under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision. GitHub's privacy statement: docs.github.com.

If you contact us by email, we process the information you provide in order to handle your request (Art. 6(1)(b) or (f) GDPR).

3. The SnackUp app

SnackUp works entirely locally ("local-first"): there is no server to which the app transmits data. All your information (profile, workout history, settings) is stored exclusively on your device. As the provider, we have no access to this data.

The app requires no account, no sign-up and no email address. It contains no analytics, behavioural tracking, crash-reporting or advertising library, and displays no advertising.

Depending on the features used, the app requests the following permissions:

  • Notifications — for local reminders; scheduling happens entirely on the device, nothing is sent to a server.
  • Location (optional) — only if you enable the recurring-places feature; processing happens locally on the device and is never transmitted or sent to us.
  • Health store (optional) — only if you enable synchronisation with Health Connect or Apple Health; see section 4 for details.

Since all data is stored locally, you can delete or export it yourself at any time — directly within the app (export feature) or by uninstalling the app.

4. Synchronisation with Health Connect / Apple Health (optional)

SnackUp can write completed snacks to your operating system's health store: Health Connect on Android, Apple Health (HealthKit) on iOS. This feature is disabled by default and is only switched on by an explicit action on your part within the app.

Data transmitted — only the following, per completed snack: the activity type (strength training, core training, flexibility), the name of the exercise, and the start and end time. No profile data, no location data, no calorie estimate.

Write-only — SnackUp only writes. The app requests no read permission and therefore never accesses the health data already present on your device (e.g. steps, heart rate, sleep, workouts from other apps).

Legal basis — This is health data within the meaning of Art. 9 GDPR. Processing is based exclusively on your explicit consent (Art. 9(2)(a) GDPR), given by enabling the feature in the app. You may withdraw it at any time with effect for the future, by disabling the feature in SnackUp or by revoking the permission in Health Connect or Apple Health.

Recipient — This data is not transmitted to us and does not pass through any server we operate. It is written to the local health store on your device, which is managed by your operating system and remains under your control; we have no access to it. From that store, you may subsequently allow other apps to read this data yourself — such sharing is then your own decision alone and is outside our influence. Please also note that on iOS, Apple Health may be synchronised with iCloud depending on your device settings; that transfer is performed by Apple, not by SnackUp.

Deletion — When you delete a snack from your history in SnackUp, the corresponding entry is also deleted from the health store, provided the feature is active and the permission is still granted. SnackUp additionally offers a function to delete all entries it has written there in one go. Simply disabling synchronisation does not retroactively delete entries already written — use the deletion function mentioned above, or the Health Connect / Apple Health app itself. We can neither delete nor modify entries originating from other apps.

5. App stores (Google Play, App Store)

The app is downloaded and premium subscriptions are purchased via your device's app store. Its operator then processes personal data (e.g. account, device and payment data) as an independent controller, over which we have no influence:

  • Google Play — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: policies.google.com/privacy.
  • App Store — Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Privacy policy: apple.com/legal/privacy.

Your subscription is verified directly between the app and the store, on your device: we operate no server involved in that exchange. These stores pass us no data that would identify you personally, and we have access to neither your payment methods nor the details of your transactions.

6. Your rights

Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) regarding your personal data. To exercise these rights, simply contact us at the address above.

You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the authority responsible for North Rhine-Westphalia:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de

7. Changes to this policy

We update this privacy policy whenever the website or the app's features change (e.g. new data processing activities). The version in force at the time of your visit applies.