Privacy Policy
MintChip is a habit-and-behaviour app for people who do not want to count calories. This policy explains what the app collects, why, and what you can do about it. It describes the app as it actually works during the closed beta. If we change how the app handles your data, we will update this page.
Who operates MintChip
MintChip is operated by MkStudios – Mario Koll, Drosselweg 5/2, 4030 Linz, Austria. You can reach us at office@mk-studios.net for any question about this policy or your data. Full company details are in our Impressum.
What we collect and why
Account and sign-in
You create an account with an email address and password, with Sign in with Apple, or with Google Sign-In. We store your email address, the sign-in method you used, and an internal account identifier. If you enter a first name during setup, we store that so the app can greet you. We use this only to sign you in and to keep your data attached to your account.
Setup answers
During setup MintChip asks a few questions to calculate your starting Treat Balance. We store your answers about sugary drinks, snacking, and eating out.
Some setup answers never leave your phone. The date of birth, gender, height, and weight entered during the setup questions are used on your device only, to calculate your starting balance. They are not sent to our servers and we do not store them. Weight is stored only if you separately turn on weight tracking (below).
What you log
The app exists to record what you eat and drink, so this is the bulk of what we hold:
- Meals, treats, and drinks you log — including any description you type, the attributes you pick (such as whether there was protein or vegetables, portion size, where the food came from), and the time of the entry.
- Optional extras you may add to an entry, such as how full you felt afterwards, how the treat felt afterwards, or whether it was planned.
- Your coin balance and coin history, weekly summaries, streaks, badges, Focus Quests, and any experiments you accept.
- Optional daily mood ratings and check-ins.
We use this to run the app's features: your Treat Balance, your history, your Insights, and your Coach.
Weight and progress photos — both optional
MintChip works fully without either of these.
- Weight: if you turn on weight tracking, we store the weights you enter with their date and unit, plus your chosen goal, starting weight, and pace.
- Progress photos: if you add one, the image is stored in a private storage area under your account, together with the date and any note you add. Photos are not public, are not shared with anyone, and are not sent to any AI service.
You can skip both, and you can delete photos individually at any time.
Photos of food and drinks
When you use the photo ("Snap") logging feature, the picture is sent to OpenAI so it can be turned into a meal entry. MintChip does not store that picture. It is used for the classification and then discarded. We keep only the resulting entry and a small technical record of the classification (which method was used and what kind of item it identified) so we can monitor how well the feature works.
AI processing
MintChip uses OpenAI to power three things:
- Turning a typed meal description into a structured entry — the text you typed is sent.
- Turning a photo of food or a drink into an entry — the image is sent, as described above.
- The Coach — your message is sent, together with a summary of your recent activity that our server assembles (currently: your coin totals for the last 30 days, counts of a few logged habits, and your treat categories with any "how did that feel" tags).
These calls are made by our servers, not by your phone, and our API credentials never leave our servers. The Coach model has no access to our database — it can only see the text summary we send it. This processing takes place on OpenAI's infrastructure, which is outside the EU. We do not send your email address, your name, your weight, or your progress photos to OpenAI. MintChip does not store your Coach conversation on our servers; the conversation lives on your phone for the length of the session, and we keep only a timestamped record that a message was sent, to enforce a daily usage limit.
Analytics and diagnostics
MintChip uses PostHog to understand how the app is used and to catch crashes. Events are sent to PostHog's EU ingestion servers. We do not use automatic capture of everything you tap — the app sends a defined list of product events, for example that onboarding was completed or that a meal log succeeded or failed. Events are linked to your account identifier, so this data is not anonymous.
If you agree to analytics, PostHog session replay is enabled during the beta for a sample of your sessions. Replay records how the app's screens were used. Text you type into fields, images, and system views are masked before recording; network content and console logs are not recorded. Uncaught errors are also reported so we can fix crashes.
Analytics is your choice. You are asked when you create your account, and you can change your mind at any time in Settings → Data & Privacy → Analytics consent. If you decline, MintChip sends no product events, no session replays and no error reports — and nothing is collected while we are still checking what you chose. Declining does not limit any feature of the app.
Notifications
MintChip's reminders are scheduled by your own device. We do not operate a push server and we do not store a push token. If you decline the notification permission, the rest of the app works normally. You can turn individual reminders off in Settings.
Where your data is stored
Your account and everything you log are stored with Supabase, in their Frankfurt region (EU). Access is restricted at the database level so that an account can only read and write its own rows, and progress photos sit in a private storage area scoped to your account. Transfers outside the EU happen for the AI processing described above.
Third parties we use
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Database, account sign-in, photo storage | Everything described above |
| OpenAI | Meal/drink classification, Coach | Typed descriptions, food photos, Coach messages and the activity summary |
| PostHog (EU) | Product analytics, session replay, crash reports | Product events, account identifier, masked replays, error reports |
| Apple | Sign in with Apple | Sign-in only, per Apple's own terms |
| Google Sign-In | Sign-in only, per Google's own terms |
Legal bases for processing
If you are in the EU or the UK, we process your data on these bases:
| What | Basis |
|---|---|
| Running your account and the app's core features | Performance of a contract (Art. 6(1)(b)) |
| Food, drink and habit logs, and anything you choose to add about your health or weight | Your explicit consent, given at sign-up (Art. 6(1)(a), and Art. 9(2)(a) where the data concerns health) |
| Analytics, session replay and crash reporting | Your consent, which you can withdraw at any time (Art. 6(1)(a)) |
| Keeping the service secure and preventing abuse | Our legitimate interests (Art. 6(1)(f)) |
Where processing rests on consent, withdrawing it is straightforward and does not affect the lawfulness of what happened before you withdrew it.
Your rights
If you are in the EU or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we process it, and to receive it in a portable form. The app implements the two you are most likely to want directly — see Your choices below — and you can exercise any of them by emailing office@mk-studios.net. We will respond within one month.
You also have the right to complain to a data protection supervisory authority. Our lead authority is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria (dsb.gv.at). You may also complain to the supervisory authority in the country where you live.
How long we keep things
We keep your data for as long as your account exists, because the app's value comes from your own history. We do not currently run an automatic deletion schedule for older entries. When you delete your account, the deletion described below happens straight away.
Your choices
- Export your data: Settings → Data & Privacy → Export my data gives you a file containing your account's data.
- Delete your account: Settings → Data & Privacy → Delete my account. This removes your progress photos from storage and then deletes your account, which removes the records attached to it. It cannot be undone.
- Sign in with Apple: deleting your MintChip account does not by itself withdraw the Apple sign-in permission. The app tells you this and points you to Settings → your name → Sign in with Apple on your device, where you can remove MintChip.
- Analytics: turn it off, or back on, at any time in Settings → Data & Privacy. The change takes effect immediately.
- Notifications, weight tracking, and progress photos can each be turned off or skipped entirely.
- Questions or requests about your data: email office@mk-studios.net.
Age
MintChip is not intended for children. The setup flow does not accept a date of birth for anyone under 13, and we ask that you do not use MintChip if you are younger than that.
Changes to this policy
If the app starts handling data differently, we will update this page and change the date at the top. During the beta we will also tell participants directly when something material changes.