Privacy policy
How FluxFree handles your data – explained clearly, especially for the health data you log in the app.
Last updated: 27 September 2026
This English version is provided for convenience. The German version (Datenschutzerklärung) is legally binding; in case of any discrepancy, the German version prevails.
Protecting your personal data matters to us – all the more so for a health app. This policy informs you under Articles 13 and 14 of the General Data Protection Regulation (GDPR) about which data we process when you use this website and the FluxFree app, what we use it for and which rights you have.
1. Controller
Ali.ci UG (haftungsbeschränkt)Lilienthalstraße 17
70771 Leinfelden-Echterdingen
Germany
Email: info@ali-ci.de
Phone: +49 711 49050870
The data protection officer is Onur Alici. For questions about data protection, contact us at the email address above.
2. Overview of processing
| Area | Data | Purpose | Legal basis |
|---|---|---|---|
| Website | IP address, date/time, page requested, browser and system details (server log files) | Delivering the website, security, error analysis | Art. 6(1)(f) GDPR |
| Account | Email, username, password (hash only), where applicable Google/Facebook account ID | Providing the account and the app | Art. 6(1)(b) GDPR |
| Profile & health | Gender, age, height, weight, activity level, reflux severity; meals, symptoms, triggers, medication, activity, sleep, plans | Diary, nutrition goals, risk estimate, eating and medication plan | Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR (explicit consent) |
| Community | Username, posts, comments, likes | Exchange between users | Art. 6(1)(b) GDPR |
| Subscription | Pseudonymous user ID, purchase and subscription status | Managing trial and Premium | Art. 6(1)(b) GDPR |
| Product images | IP address when images are loaded | Displaying product images | Art. 6(1)(f) GDPR |
3. Visiting this website
This website runs on our own, self-managed servers (see section 1 for the address) – there is no external hosting provider. When you open it, we process technically necessary data in server log files: IP address, date and time, page requested, amount of data transferred, referrer URL, and browser type and operating system. This processing is necessary to deliver the website and ensure its security (legitimate interest, Art. 6(1)(f) GDPR). Log files are deleted after 7 days.
No cookies, no tracking: This website sets no cookies and uses no analytics, marketing or social media services. The fonts (Fraunces, Karla) are served from our own server; no connection is made to Google Fonts or other third parties. Links to Google Play or the App Store only lead to those sites once you click them; the privacy terms of the respective provider apply there.
4. Contacting us
If you email us, we process your details (email address, content of your message) to handle your request (Art. 6(1)(b) or (f) GDPR). We delete the correspondence once the request has been resolved and no statutory retention obligations apply. Please avoid sending us health data by email where possible.
5. Account, registration and login
To use the app you create an account. We process your email address, a username and your password – the password is stored only in encrypted form (as a so-called hash). After login your device receives an access token that is kept in the operating system’s protected storage (iOS Keychain or Android Keystore).
Login with Google or Facebook: If you sign in with one of these services, we receive the details required for login from the respective provider (ID, email address, possibly name). The provider may process data and possibly transfer it to the USA; its own privacy terms apply (Google Ireland Limited; Meta Platforms Ireland Limited). Use is voluntary – you can also register with email and password. The Facebook component is used only for login; automatic event logging and collection of the advertising ID are disabled.
6. Health data in the app
The core of the app is a diary. For this we process the details you enter yourself: gender, age, height, weight, activity level and reflux severity (profile), as well as your meals, symptoms, trigger factors (e.g. smoking, alcohol, coffee), medication, activity and sleep entries, weight history and your progress and results in the eating and medication plan. This information is health data within the meaning of Art. 9 GDPR.
The legal basis is your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR), which you give when registering. You can withdraw it at any time with effect for the future, for example by emailing info@ali-ci.de; we will then delete your account and the associated data. The lawfulness of processing carried out until then remains unaffected.
Your logs are not visible to other users. We do not use them for advertising and do not pass them on for advertising purposes.
7. Automated analysis (AI)
From your input the app calculates on our server (a) a reflux score for foods according to fixed rules (e.g. based on fat, acid, sugar, caffeine and alcohol content and typical triggers) and (b) with a machine learning model a daily probability of reflux symptoms (“Reflux Risk Indicator”). The app also detects recurring patterns and suggests eating and medication plans. Processing takes place on our own servers; we do not use external AI services for this.
There are no exclusively automated decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR. The results are a guide, not a medical finding, and do not replace medical advice.
8. Community
In the community, your username and the posts, comments and likes you publish are visible to other users of the app. Please choose a username that does not directly identify you, and do not publish health data or other details you do not wish to share. You can edit and delete your own posts and comments. The legal basis is Art. 6(1)(b) GDPR (use of the community function); for health details you publish voluntarily, your consent under Art. 9(2)(a) GDPR.
9. Premium, trial and payments
After a free 7-day trial, using the app requires a Premium subscription. Purchases are made through the app store (currently Google Play). Payment details (e.g. credit card) are processed exclusively by the store operator – we do not receive them. To manage your subscription we use RevenueCat, Inc. (USA) as a service provider. RevenueCat processes a pseudonymous user ID, your purchase and subscription status and timestamps; we also store this ID in your account to match purchases. The legal basis is Art. 6(1)(b) GDPR. A data processing agreement with RevenueCat is in place under Art. 28 GDPR.
10. Camera and notifications
Camera: For the barcode scanner the app asks for camera access. No photos are stored or transmitted; only the detected barcode is evaluated, and we send it to our server to find the product. You can revoke the permission at any time in your device settings.
Notifications: Meal and medication reminders are scheduled and displayed locally on your device; no device identifier is transmitted to us for this. You can turn them off in the app or in your device settings.
11. Food data and product images
Nutrition and product data come from Open Food Facts. Your search queries are handled via our server. However, the app loads product images directly from the servers of Open Food Facts (hosted at Amazon Web Services, Europe/Paris region); for technical reasons your IP address is transmitted to the operator of these servers. The legal basis is our legitimate interest in a clear presentation (Art. 6(1)(f) GDPR).
12. Recipients and processors
We only pass on personal data where necessary for the stated purposes or where you have consented. Recipients and service providers are:
- The server infrastructure and database are operated on our own, self-managed servers in Germany.
- RevenueCat, Inc., USA – subscription management (processor)
- Google Ireland Limited – Google Play (payment processing, subscription) and, only if used, Google sign-in
- Meta Platforms Ireland Limited – only if you use Facebook sign-in
- Open Food Facts (product images, see section 11)
Data is passed to authorities only where legally required. We do not sell personal data.
13. Transfers to third countries
Some of the providers named (in particular RevenueCat, Google and Meta) are based in the USA or process data there. We base such transfers on an adequacy decision of the European Commission (EU-US Data Privacy Framework) or on EU standard contractual clauses (Art. 45, 46 GDPR).
14. Storage period and deletion
We store your data for as long as your account exists. If you have your account deleted, we delete account, profile and health data within 30 days. Data we have to keep for commercial and tax law reasons (e.g. billing records, generally 6 to 10 years) remains stored in restricted form until the retention periods expire. Backups are overwritten in the regular cycle. Website log files are deleted after the period stated in section 3.
Food entries you created remain in place after your account is deleted, but are anonymized, since other users may be using them in their own meals or recipes. It is no longer possible to trace them back to you.
15. Data security
We take technical and organisational measures to protect your data: encrypted transmission between app and server (TLS/HTTPS), storing passwords only as hashes, keeping the access token in the device’s protected storage, access restrictions to server and database, and regular backups. Absolute security cannot be guaranteed for data transmission over the internet, however.
16. Your rights
You have the following rights towards us regarding your personal data:
- Access (Art. 15 GDPR) to the data stored about you,
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR) in a common, machine-readable format,
- Objection to processing based on legitimate interests (Art. 21 GDPR),
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).
Simply contact us informally at info@ali-ci.de. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (the Baden-Württemberg state data protection authority).
17. Necessity of information
Providing an email address, username and password is required for an account. Profile and health details are voluntary, but without them nutrition goals, the risk estimate and plans cannot be calculated or only to a limited extent.
18. Minimum age
FluxFree is intended for people aged 18 and over. If we learn that we have collected data from persons below this age, we will delete it.
19. Changes to this policy
We update this privacy policy when the app, the website or the legal situation changes. The version published here applies. For significant changes concerning health data we will additionally inform you in the app.
Last updated: 27 September 2026