Privacy policy
Last updated August 26, 2026 · applies to the Lipsis app (Google Play, App Store), the nutritionist workspace and the website lipsis.app
In short
- We collect only what the food diary and your work with a nutritionist require: account details, body parameters, meal entries and photos, and health information — the latter only with your separate consent.
- Data is stored in a data centre in Poland (EU). For food recognition, photos are sent to an external AI provider without your name or contact details.
- A nutritionist sees your data only after you connect them. You can disconnect them at any time.
- We do not sell data and do not show ads. You can delete your account and everything in it in the app or by request.
- The Service is intended for people aged 18 and over.
1. Who we are and what this document covers
The Lipsis app (the “App”) and the web workspace for nutritionists (the “Workspace”, together the “Service”) are owned and operated by Quantrol LLC, identification number 405580250, registered address: 2 Givi Kartozia St., apt. 47, Saburtalo district, Tbilisi, Georgia (“we”, “Lipsis”). We are the controller of the personal data of the Service's users.
This policy explains what data we collect, why, who we share it with, where and for how long we store it, and what rights you have. It applies to the App on Google Play and the App Store, to the Workspace and to the website lipsis.app.
For any questions about your data, write to support@quantrol.ge.
2. What data we collect
2.1. Data you provide yourself
| Category | What exactly | Required? |
|---|---|---|
| Account | Data passed by the sign-in method you choose: with Google — your name, email address and Google account identifier; with Apple — your name, email (or Apple's private relay address) and Apple ID identifier; with Telegram — your name and Telegram identifier; with phone sign-up — your phone number. We never receive or store your passwords for these services | One sign-in method — yes |
| Body and goals | Date of birth, sex, height, weight and weight history, activity level, goal (e.g. losing or maintaining weight), daily calorie target | Needed to calculate your target |
| Nutrition | Food photos, meal entries, dishes and their weight, recipes, task completion marks | At your discretion |
| Health | Allergies, intolerances and dietary restrictions, diagnoses, test results and any other health information you choose to enter | No — only with your separate consent |
| Communication | Chat messages with your nutritionist, comments on entries | At your discretion |
Health information is a special (sensitive) category of data. We process it only on the basis of your explicit consent, which you give when filling in the relevant section, and only to tailor your diet and support your nutritionist's work. You can delete this information or withdraw consent at any time — in the App's settings or by writing to us.
Signing in to the Service goes through external providers (currently Google; Apple, Telegram and phone-number sign-in will be added as the Service develops). The wording “if you sign in with…” applies to whichever method you use.
2.2. Data collected automatically
- Device and app data: device model, operating system version, App version, language, time zone, app instance identifier, push notification token.
- Usage data: which screens and features you open, when and how often, in pseudonymized form (via Firebase Analytics).
- Crash reports: technical crash logs (via Firebase Crashlytics). They do not contain the contents of your diary.
- Server logs: IP address, request time and type — for security and debugging.
We do not collect precise location and do not access your contacts, photo library or microphone, other than the photos you take or choose yourself for a diary entry.
2.3. Payments
The Service is currently free. If paid features are introduced, purchases will go through Google Play Billing or the App Store. We do not receive or store card details — only the transaction identifier, the product purchased and its status, so that we can give you access.
3. Why we use data and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create your account and give you access to the Service | Account | Performance of a contract (Art. 6(1)(b)) |
| Calculate your calorie target, keep the diary, count what's left, suggest meals | Body and goals, Nutrition | Performance of a contract (Art. 6(1)(b)) |
| Recognize dishes and count calories from photos | Food photos | Performance of a contract (Art. 6(1)(b)) |
| Take restrictions and health conditions into account when tailoring your diet, and show them to your nutritionist | Health | Explicit consent (Art. 9(2)(a)) |
| Give your nutritionist access to your diary, progress and chat | All categories you keep | Performance of a contract and your action of connecting a nutritionist |
| Send reminders and notifications | Push token, reminder settings | Performance of a contract; you can turn them off in settings |
| Improve the Service, fix bugs, keep it secure | Device, usage and crash data, logs | Legitimate interest (Art. 6(1)(f)) |
| Respond to your requests | Contact details, content of the request | Legitimate interest (Art. 6(1)(f)) |
| Comply with the law (accounting, lawful requests) | Transaction data, account | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, do not show advertising and do not use your diary for advertising profiling.
4. Your nutritionist and your data
The App works without a nutritionist. If you connect one — via their invite link or code, or by confirming an addition on their side — you give them access to your diary, photos, progress, health information (if you have entered it) and chat. Access remains until you disconnect the nutritionist in the App's settings or delete your account.
Nutritionists are independent professionals, not Lipsis employees. When they use your data to advise you, they act as independent controllers and must comply with applicable law and professional ethics. Lipsis provides them with a tool but does not control the content of their recommendations. If you have concerns about how a nutritionist handles your data, write to us — we will look into it and restrict access if necessary.
A nutritionist sees only the clients who have connected them and cannot see other users.
5. Who we share data with
We share data only with providers who help us run the Service, and only to the extent needed for their task. We have a data processing agreement with each of them.
| Who | Why | What data | Where |
|---|---|---|---|
| Cloud AI recognition service provider | Recognizing dishes and estimating portions from photos or text descriptions | The food photo and description, without your name or contact details. The provider processes this data for analysis and recognition | USA / EU |
| Google (Google sign-in; Firebase Analytics, Crashlytics, Cloud Messaging) | Authentication, pseudonymized analytics, crash reports, push notification delivery | Account identifier at sign-in; device and usage data, push token | USA / EU |
| Apple (Sign in with Apple, Apple Push Notification service) | Apple ID sign-in (if you choose it), push notification delivery on iOS | Apple ID identifier at sign-in; push token | USA / EU |
| Google Play, App Store | Processing purchases (if paid features are introduced) | Transaction data without card details | Per the stores' rules |
| Zomro (hosting provider) | Hosting servers and the database | All Service data in encrypted storage | Poland (EU) |
| Telegram | Sign-in with Telegram, if you choose it | Telegram identifier and name | Per Telegram's rules |
We may also disclose data when required by law or by a lawful request from a public authority, and in the event of a reorganization or sale of the company — subject to the terms of this policy.
6. Where data is stored and international transfers
Service data is stored on servers in a data centre in Poland (European Union). Our company is registered in Georgia, and our staff access data from Georgia to the extent needed for support and development. Some providers listed in section 5 process data in the United States.
When transferring data outside the EU/EEA, we rely on safeguards provided by law: the European Commission's Standard Contractual Clauses, the provider's participation in the EU-U.S. Data Privacy Framework, or other recognized mechanisms. You can request a copy of the applicable safeguards at support@quantrol.ge.
7. How long we keep data
- While you have an account — everything you keep in it, so that the Service works.
- After you delete your account — data is removed from production systems within 30 days and from backups within 90 days.
- Health information — removed as soon as you delete it in the App or withdraw consent.
- Analytics and crash data — up to 14 months, in pseudonymized form.
- Transaction data — for the period required by accounting law.
- Support correspondence — up to 2 years, so that we can return to your question.
8. How we protect data
Data is transmitted over encrypted connections (TLS) and stored encrypted. Sign-in goes through trusted providers (Google, with Apple and Telegram to follow) — your passwords for those services are never passed to us or stored by us. Staff access is limited to what their work requires and is logged. We keep software up to date and make regular backups. No system can guarantee absolute security, so if you notice anything suspicious, write to support@quantrol.ge — we will respond without delay.
9. Your rights
At any time you can:
- view and export your data;
- correct inaccurate data — most of it can be edited directly in the App;
- delete specific data (for example, health information or photos) or your entire account — see “Delete your account”;
- withdraw consent to processing health information — this does not affect the lawfulness of processing before withdrawal;
- disconnect your nutritionist and thereby end their access to your data;
- restrict processing or object to processing based on legitimate interest;
- receive your data in a machine-readable format to move it to another service.
To exercise your rights, write to support@quantrol.ge from the address your account is registered with. We will respond within 30 days. If you are in the EU/EEA or the UK, you may also lodge a complaint with your country's data protection authority. In Georgia, this is the Personal Data Protection Service.
California residents. We do not sell personal data and do not share it for targeted advertising. You have the right to know what data we collect, to request its deletion, and not to be discriminated against for exercising your rights.
10. Age
The Service is intended for people aged 18 and over. We do not knowingly collect data from children. If you become aware that a child has registered for the Service, write to us — we will delete the account and the data.
11. Deleting your account
You can delete your account and all data in the App (Settings → Account → Delete account) or by request to support@quantrol.ge. Step-by-step instructions, timelines and the list of what is deleted are on the “Delete your account” page.
12. Changes to this policy
We may update this policy. We will notify you of material changes in the App or by email at least 14 days before they take effect. The current version is always available at lipsis.app/en/privacy.html; the date of the last update is shown at the top of the page.
13. Contact
Quantrol LLC, identification number 405580250, registered address: 2 Givi Kartozia St., apt. 47, Saburtalo district, Tbilisi, Georgia
Data questions: support@quantrol.ge