This is the English version of our privacy notice. It describes the same processing operations as the German version and is written to be relied on. We have translated it with care. Some legal terms in this notice refer to German and European law and have no exact English equivalent. Where the German wording of a legal term and this translation differ in meaning, the German wording is decisive for the interpretation of that term. This does not limit your rights: your rights under the GDPR, and the information we owe you under Articles 12 to 14 GDPR, apply on the basis of this English version as well. You may contact us in English or in German at info@the8protocol.com.
Last updated: August 26, 2026
No Data Protection Officer has been appointed, because there is no legal obligation to do so (Art. 37 GDPR, Section 38 of the German Federal Data Protection Act, BDSG).
The 8 Protocol is a local-first app. All diary entries, fasting periods, drink entries, sauna days, exercise sessions, your profile (in particular age, sex, height, weight, activity level, training frequency, nutrition goal, longevity mode setting and a profile picture you choose) and your calculated or self-defined goals are stored locally on your iPhone (standard iOS Data Protection). All evaluations in the app as well, for example portion suggestions derived from your own entries, protein overviews or fasting times, are calculated by The 8 Protocol exclusively on your device. The 8 Protocol does not create user accounts and does not transmit your profile data or health data to me or to third parties; the only exception is the photo estimate that you trigger yourself (section 4). Data only leaves your device in the cases named in this notice: food search and barcode scan via Open Food Facts (section 3), the voluntary nutrient estimate from a photo (section 4), Apple Health permissions (section 5), purchase and premium subscription via Apple (section 8), voluntary feedback (section 7), and files that you create and pass on yourself (next paragraph).
Export and daily report: In the app you can create your data as an archive (CSV and JSON) or as a daily report (PDF) and pass it on yourself using the iOS share sheet, for example to a nutrition counselor. The file is created on your device. Whether, when and to whom you pass it on is entirely your decision; I do not receive a copy and have no access to it. The recipient is responsible for any further processing. Please note that such a file contains data concerning health.
Note on device backups: If you use iCloud Backup or a computer backup of your iPhone, your operating system also includes the local data of The 8 Protocol in that backup. This is an iOS system function that you control yourself in your device settings; The 8 Protocol has no access to your backups and does not transmit anything to them. Apple is the controller for the iCloud service.
Note on data concerning health: Information such as weight, height, nutrition goal, fasting periods, exercise sessions and Apple Health data constitutes data concerning health within the meaning of Art. 9 GDPR. The 8 Protocol processes it exclusively on your device, with the exception of the photo estimate that you trigger yourself (section 4). For Apple Health data you give your explicit consent through the iOS permission dialog (Art. 9(2)(a) GDPR). You enter your profile data yourself in the app and can change or delete it at any time.
Providing your profile data is neither required by law nor by contract; without this information the app simply cannot calculate personal calorie and macronutrient goals. There is no automated decision-making producing legal effects concerning you (Art. 22 GDPR); the goal calculation is a purely informational calculation on your device.
When you search for a food or scan a barcode, The 8 Protocol sends your search query or the barcode to the Open Food Facts database (Open Food Facts, a non-profit association under French law, 21 rue des Îles, 94100 Saint-Maur-des-Fossés, France), together with the technically necessary connection data (in particular your IP address). Camera images during a barcode scan are evaluated locally for barcode recognition only and are neither stored nor transmitted. Open Food Facts is a separate, independent controller; there is no processing on my behalf within the meaning of Art. 28 GDPR. The 8 Protocol does not transmit a user account or any identifier that would identify you to Open Food Facts.
Please note: your search terms and scanned products may allow indirect conclusions about your diet. The search is only performed when you actively start it. Legal basis: Art. 6(1)(b) GDPR (providing the function you requested), in any case Art. 6(1)(f) GDPR (legitimate interests in providing the search function). Open Food Facts is operated in France (EU); The 8 Protocol does not transfer your data to countries outside the EU or the EEA. Open Food Facts privacy policy: https://world.openfoodfacts.org/privacy
The 8 Protocol can estimate the nutrients of a meal from a photo. This feature is part of The 8 Protocol+ and only runs if you actively start it and take or select a photo. No image is ever transmitted without your action.
What is transmitted: the photo (downsized on your device and compressed as JPEG), the language you want the results in, and cryptographic proof that the request comes from a genuine, unmodified installation of The 8 Protocol (Apple App Attest). Because the feature is part of the subscription, a purchase receipt signed by Apple is sent as well, so that my server can verify that an active subscription exists for this installation; it contains the details of your purchase, in particular transaction numbers, purchase and expiry date, product, price and currency, the store country and whether the subscription is shared via Family Sharing, but not your name and not your Apple ID. Not transmitted are your name, your profile, your diary entries or your Apple Health data. An identifier of your installation is sent along: no name, no device identifier, no account, but a random value that serves solely for abuse and quota control. Your IP address is technically involved in the transmission; it is not stored or evaluated beyond technical operation. One exception applies when an installation is set up: so that nobody can obtain a multiple of the quota through many new installations, my server records which sender address (for IPv6 only its network part) started how many set-ups on which day. That entry is deleted after 40 days and is tied to no photo and no individual request.
Process and recipients: the photo first goes to my own server (Hetzner Online GmbH, Germany, as hosting provider and processor). That server passes it on immediately to Anthropic PBC (548 Market St, PMB 90375, San Francisco, CA 94104, USA), whose language model estimates the visible ingredients and their quantities. Anthropic processes the image solely on my instructions as a processor under Art. 28 GDPR; the European Commission's standard contractual clauses are in place. Inputs and outputs are contractually not used to train models. Anthropic uses its own sub-processors, in particular for cloud infrastructure; Anthropic publishes the current list at https://trust.anthropic.com/subprocessors
Transfer to a third country: processing at Anthropic takes place in the United States. The basis is the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR, which form part of the data processing agreement. Despite these safeguards, a level of protection equivalent to the European one cannot be guaranteed in every case, in particular with regard to access by United States authorities. You decide for each individual photo whether you use this feature; you can enter every ingredient by hand instead. You can request a copy of the standard contractual clauses at info@the8protocol.com; Anthropic's data processing addendum is available at https://www.anthropic.com/legal/data-processing-addendum
Storage: the photo is stored neither on my server nor by me. It exists in memory only for as long as the response takes and is discarded afterwards. For abuse and cost control, my server stores the public App Attest key of your installation together with the time it was set up and the time it was last used, a counter against replay attacks, and the number of your requests per day. The purchase receipt itself is checked in memory only and is neither stored nor logged. What is stored is only a short hash of your transaction number together with the number of requests per day, so that the quota is tied to the subscription and not to the individual device; without it, one subscription could draw a multiple of the quota across several installations. Your transaction number cannot be recovered from the hash, and the hash is deleted after 40 days like the daily counts. The daily counts are deleted after 40 days, because a calendar month has to stay fully countable until its last day, and the key once your installation has made no request for one year. If you switch the feature off in your profile, the key and the daily counts tied to your installation are deleted immediately; the short hash of your transaction number with its daily counts, the record of the initial setup and the technical log entries run out over the periods named above instead, because they are not tied to your installation. In addition, the server logs technical details for each request with no reference to the image content (time, success or error code, and a shortened checksum of your installation's key). How long an estimate took and what it cost is deliberately not recorded per request, because that would allow conclusions about the image; those figures exist only as an hourly total across all users. The web server's access log, which arises for technical reasons and contains your IP address, is deleted after seven days. Nothing about what your photos showed can be derived from any of this.
At Anthropic, inputs and outputs are deleted within 30 days. They are kept longer only if Anthropic's safety systems flag a request as a possible breach of the usage policies, or where legally required; Anthropic states up to two years for this, and up to seven years for assessments by its trust and safety team. The estimated values that you confirm end up as ordinary diary entries locally on your device; the photo itself is not stored there either.
Please photograph only your food. People, other people's documents or other things in the background do not belong in the picture. The app points this out on the capture screen.
Legal basis for processing the photo: your explicit consent under Art. 6(1)(a) and, because a photo of food allows conclusions about your diet and thus about data concerning health, under Art. 9(2)(a) GDPR. You give this consent once in a dedicated dialog before you use the feature for the first time. You can withdraw it at any time with effect for the future: in your profile under "Photo estimate", with a single tap. Doing so also deletes the data of your installation stored on my server. If the app cannot reach the server, or if you reinstalled the app beforehand, the periods named above apply. The lawfulness of processing carried out before the withdrawal remains unaffected. Use is entirely voluntary: every entry can be recorded without a photo, by hand, via the search or via the barcode scan.
Legal basis for the App Attest key, the purchase receipt, the counters, the set-up records and the connection data: Art. 6(1)(f) GDPR. You can object to this processing at any time (Art. 21 GDPR), informally at info@the8protocol.com. My legitimate interest is protecting this paid feature against abuse and against costs caused by outside use; without this information, a genuine installation could not be distinguished from a rebuilt one, nor could a daily quota be enforced, nor could it be established whether a subscription exists for the request at all.
An estimate is an estimate. It replaces neither weighing nor a nutrient table, and it is not a medical statement. You can change the values before accepting them.
The 8 Protocol can be connected to Apple Health if you wish. Without your permission in the iOS permission dialog, no access takes place. You grant permission there individually per data type and separately for reading and writing; you can change it at any time in the Health app or in the iOS settings.
Data types read: active energy burned (activity calories), body mass, body fat percentage and lean body mass and, if you use the sleep and activity display, sleep analysis (time asleep), step count and workout time. Active calories are shown for information only and are not offset against your calorie goal. Sleep and activity data are shown only as context for your food diary; The 8 Protocol does not evaluate them and derives no recommendations from them. Body fat percentage and lean body mass are only displayed (with history) and are never written to Apple Health. If no lean body mass value is available in Apple Health for a given day but weight and body fat percentage are, The 8 Protocol calculates lean body mass for display locally on your device from these two values (weight × (1 − body fat percentage)) and marks it as calculated in the app. Calculated values are only displayed and are not written to Apple Health. For the history display, The 8 Protocol reads measurements from the last 90 days from Apple Health. Your Health weight is only adopted as your profile weight if you explicitly tap to do so.
Data types written: dietary energy consumed (dietaryEnergyConsumed), the macronutrients protein (dietaryProtein), carbohydrates (dietaryCarbohydrates) and fat (dietaryFatTotal) and, if you use the water tracker, water consumed (dietaryWater), and only if you enable write-back in the profile of The 8 Protocol (off by default). Sleep and activity data are only read, never written. When you delete a diary entry, The 8 Protocol removes only the nutrition entries written by The 8 Protocol itself from Apple Health (all four nutrition data types); when you delete a drink entry, accordingly only the corresponding water entry.
Purpose of writing back: your nutrition data is then available centrally in Apple Health, for example for other health or training apps you use that import data from Apple Health. Please note: what The 8 Protocol writes to Apple Health becomes part of your Health database and can be read there by other apps to which you yourself have granted access to these data types. Those apps are independent controllers; The 8 Protocol does not transmit any data directly to them and has no influence on their processing. You control which apps have access in the Health app.
Legal basis: your explicit consent through the iOS permission dialog (Art. 9(2)(a) GDPR). Processing: exclusively on your device; HealthKit data is not transmitted to servers by The 8 Protocol, not stored in iCloud by The 8 Protocol and never used for advertising or marketing (Apple Guideline 5.1.3). For system-level device backups see section 2.
Withdrawal: You can end Health access at any time. "Disconnect" in the profile of The 8 Protocol stops all reading and writing by the app. You additionally revoke the system permission in the Health app (profile picture, Privacy, Apps) or under Settings, Apps, Health, Data Access & Devices. You can delete values already stored locally in The 8 Protocol. Entries already written to Apple Health remain there after disconnecting; you can view and delete them at any time in the Health app.
The 8 Protocol contains no analytics, advertising or tracking SDKs, no third-party crash reporting services and no social media integrations. No data is processed for advertising purposes. Apart from the cases described in this notice, no data is transmitted to any further recipients. On the voluntary nutrient estimate from a photo and the recipients involved, see section 4. On the indirect readability of Health data by other apps you have authorised, see section 5. On the feedback function see section 7, on the premium subscription see section 8.
As the platform operator, Apple may process data in connection with obtaining the app from the App Store and (if enabled by you at system level) anonymised app analytics; The 8 Protocol has no influence on this. Apple is the controller for this.
The app contains a voluntary feedback function. Only if you actively use it and tap "Send" is the following data transmitted to my server: your feedback text, your optionally provided email address, and app version, build number, iOS version and device model (to classify error reports). There are no mandatory fields other than the text; the email address is only needed if you would like a reply.
Purpose: handling your request (support, bug fixing, product improvement). The recipient is me (Nils Harder, section 1); transmission runs via my self-operated automation server (Hetzner Online GmbH, Germany, as hosting provider and processor) and my email service provider and is delivered to me by email; no transfer outside the EU or the EEA takes place. Your IP address is technically involved in the transmission; it is not stored or evaluated beyond technical operation.
Legal basis: Art. 6(1)(b) and (f) GDPR (handling your request; legitimate interests in improving the app). Retention period: until your request has been handled, then deletion; email correspondence in accordance with statutory retention periods under German law. Please do not enter data concerning health in the feedback field.
Premium features of The 8 Protocol are unlocked through a subscription ("The 8 Protocol+") that you take out as an in-app purchase via the Apple App Store.
Payment handled entirely by Apple: purchase, payment, withdrawal and refund of the subscription are handled by Apple through your Apple Account; I (Nils Harder) remain the provider of the app service. Your contractual partner for the purchase is the Apple entity that applies to your country under the Apple Media Services Terms (for customers in Germany: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland). Apple processes your payment and billing data as an independent controller. I receive no payment data, no billing address and no information from Apple that would allow me to identify you, only aggregated sales reports (for example the number of active subscriptions) that allow no conclusions about you personally. Apple's privacy policy applies (https://www.apple.com/legal/privacy/).
Subscription status on your device: The 8 Protocol checks whether a valid subscription exists via Apple's StoreKit directly on your device. The transaction information processed in the course of this (e.g. subscription product, term, renewal status) remains on your device and is evaluated there for all premium features. There is one exception, the photo estimate: because every estimate costs me money, my server has to be able to verify that a subscription exists for the request. For that purpose and no other, the purchase receipt signed by Apple is sent to my server along with the request; the details are in the section on the photo estimate above. For every other premium feature, no transaction information leaves your device. Legal basis, insofar as I process this data locally: Art. 6(1)(b) GDPR (performance of the contract for the premium features).
Cancellation, withdrawal, refund: You manage and cancel the subscription in the iOS settings (Apple Account, Subscriptions). If you are a consumer in the European Union, you have a statutory right of withdrawal. Apple provides the withdrawal instructions and the model withdrawal form; for customers in Germany they are at https://www.apple.com/legal/internet-services/itunes/de/rightofwithdrawal-de.pdf, and the version for your country is linked from the Apple Media Services Terms (https://www.apple.com/legal/internet-services/itunes/). You declare withdrawal using the "Request a refund" function in your Apple Account, which Apple also offers under "Report a Problem". Outside the EU there is generally no statutory right of withdrawal; refunds are handled there under Apple's refund process. In every case the refund is made by Apple. I have no influence on Apple's purchase, withdrawal and refund processes and receive no personal data from them.
Offer codes: If you redeem a subscription offer code, Apple processes the redemption. I do not learn which person redeemed a code.
Your data stays on your device until you delete it in the app or uninstall the app. On uninstall, all local data of The 8 Protocol is removed by iOS (entries written to Apple Health by The 8 Protocol are managed by you in the Health app; device backups created by your operating system are managed by you, see section 2). Purchase and subscription data held by Apple is subject to Apple's retention periods (section 8). Photos from the nutrient estimate are not stored by me; at the AI provider the periods named in section 4 apply. The information kept on my server for abuse and cost control (section 4) is deleted after 40 days or after one year without use, and immediately if you switch the feature off in your profile. Not deleted along with it are the short hash of your transaction number with its daily counts, the record of the initial setup and the technical log entries; they are not tied to your installation and run out over the periods named in section 4. The short hash has to remain, because otherwise the monthly quota could be reset any number of times by switching the feature off repeatedly; this processing is based on Art. 6(1)(f) GDPR, and you may object to it under Art. 21 GDPR.
You have the rights under Art. 15 to 21 GDPR (access, rectification, erasure, restriction, data portability, objection) as well as the right to withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR). Since The 8 Protocol processes your data predominantly locally on your device, you generally exercise access and erasure directly in the app or on your device. For rights concerning purchase and subscription data, please contact Apple (section 8). For questions you can reach me at info@the8protocol.com. Right to lodge a complaint: if you are in the EU or the EEA, you can lodge a complaint with any data protection supervisory authority (Art. 77 GDPR), in particular with the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW, State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia), Kavalleriestr. 2-4, 40213 Düsseldorf, www.ldi.nrw.de.
The 8 Protocol is intended for people aged 16 and over; the onboarding asks for your age (self-declared). A weight loss goal can only be selected from the age of 18. This age limit follows the assessment in Art. 8 GDPR. We do not knowingly collect personal information from children under 13.
This privacy notice will be adapted if the functionality of the app changes (e.g. future cloud synchronisation or accounts; in that case the handling of Health data in particular will be reassessed and made transparent).
The 8 Protocol is offered from Germany and follows the GDPR. The description above applies to you as well: the app stores your entries on your device, creates no user accounts, contains no analytics, advertising or tracking SDKs, and sells or shares no personal information.
Because no personal information is sold or shared for cross-context behavioral advertising, and because I operate no server that holds your diary, health or profile data, the exercise of choices such as opting out of sale or sharing does not arise. The one exception is the photo estimate described in section 4, which you start yourself: the photo travels through my server to a processor in the United States and is not stored along the way. If you have questions about your data, write to info@the8protocol.com in English or German; I will answer requests from users in the United States on the same terms as requests under the GDPR.
This website (the8protocol.com) is operated at a hosting provider within the European Union, which processes the data exclusively on my behalf and within the EU or the EEA (processing under Art. 28 GDPR).
When you visit this website, the server automatically processes technical access data and stores it in server log files: your IP address, the date and time of access, the page or file requested, the previously visited page (referrer) and details about your browser and operating system. This processing is technically necessary in order to deliver the website, ensure its stability and security and to prevent misuse. The legal basis is my legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR). The log files are stored only for as long as necessary for these purposes and are then deleted automatically; in the event of a specific security incident they are kept until it has been resolved.
Contacting me: If you contact me using the email address given on this website, I process your details (email address, content of your message) exclusively in order to handle your request. The legal basis is Art. 6(1)(b) GDPR (for contract-related enquiries) or Art. 6(1)(f) GDPR (legitimate interest in replying). I delete this data once your request has been finally handled and no statutory retention periods stand in the way.
This website uses no cookies, no tracking and no analytics or advertising services, and embeds no external resources that transmit data to third parties. Typefaces are rendered from the system fonts present on your device; no external font, map or CDN services are used.