Skip to content
RecTake
How it works Privacy FAQ Blog DE Get the app
  1. Home
  2. Privacy policy

Privacy Policy

Last updated: 11 September 2026 Applies to: the RecTake app (iOS and Android) and the website rectake.de


The short version

Your entries — what you take, what you eat, how you feel — live in a database on your phone. They are not transmitted to us. The voice recording stays there too: your phone turns it into text itself, using the speech recognition built into its operating system. Your account knows your email address, an account ID and your subscription status — not what you record.

Since 11 September 2026 no health data whatsoever leaves your device. Until then the voice recording went to France to be recognised. That path has been removed from the app; what it means for consent you gave earlier is in section 8.

The rest of this text explains that in detail, because it legally has to.


1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

IT Consulting & Development Tino Sanchez Ross
Bismarckring 6
65185 Wiesbaden
Germany

Email: support@rectake.de

The second contact route is the support page, which states the promised response time.

Data protection officer: none appointed.


2. What data is processed

2.1 Your entries — health data that stays on the device

This is what the app is actually about. The app knows exactly eight kinds of entry:

Kind of entryWhat it holds
Supplementswhat you take, how much, when
Medicationover-the-counter and prescribed medicines
Foodmeals
Drinkbeverages
Caffeinecoffee, tea and the like
Moodscale and notes
Symptomshow you feel, what you notice
Notesfree text for anything that fits none of the others

In addition:

  • History — every recorded day
  • Routines — your recurring patterns
  • Vocabulary — the supplement and food names you use
  • the finished text of your entries

Medication and symptoms are the most sensitive items on that list. Someone who records which prescribed medicine they take and which complaints they have is disclosing their health at its core.

These entries do not leave the device — and neither does the voice recording they are made from. Anyone who speaks a medication or a symptom transmits nothing by doing so. How recognition works without any transmission is in the next section.

This is health data within the meaning of Art. 4(15) GDPR and therefore a special category of personal data under Art. 9(1) GDPR. It has the strongest protection the Regulation provides.

Where it lives: exclusively in a SQLite database in the app's private storage area on your device. There is no code path in the app that transmits entries to a server — not to us, not to anyone else. We have no access to this data: not on request, not with a court order. We simply do not have it.

What follows from that, and what you need to know: if you delete the app or lose the device, the entries are gone. There is no copy with us to restore from. You can export your entries yourself as a file (Settings → Your data). The export goes through your device’s share sheet; where the file ends up – e-mail, cloud storage, a messenger – is your choice, and that provider then processes it under its own terms. Nothing is transmitted to us.

2.2 The voice recording

To turn what you say into an entry, the recording has to be converted into text. This happens on your phone. It uses the speech recognition of the operating system — the same one that works when you tap the microphone on your keyboard. On iPhones that is Apple's Speech framework, on Android devices the recogniser the system ships with.

The app explicitly requires on-device recognition. It only starts if the operating system confirms that it can recognise your language without a network. If it does not confirm that, there is no speech recognition — and no silent fallback to a server. This mainly affects Android devices before version 13.

What follows from that:

  1. The recording exists in your phone's memory and becomes text there.
  2. It is not transmitted — not to us, not to a third party.
  3. Afterwards it is discarded. What is stored is only what you keep as an entry, and that lives in the database on the device.

Your vocabulary — the supplement names you use — is given to the recogniser as a hint, so that "Elalanin" becomes "L-Alanine". It stays on the device as well.

What the operating system itself does is its maker's decision. Whoever makes your phone and its operating system is its supplier, not our processor. We explicitly ask for on-device recognition and do not start without it; what diagnostic data an operating system sends to its maker beyond that is governed by its own privacy terms and your system settings.

Until 11 September 2026 this was different. Until then the recording went through an endpoint of ours to a recognition service in France. That path has been removed from the app entirely, along with the consent it required (section 8).

2.3 Your account

The account is not there to store your entries. It exists for one reason: a subscription has to be recognisable on a new phone, and that needs something that recognises you.

So exactly this is stored:

DataPurpose
Email addressSign-in, recognition, contact about account matters
Account ID (technical identifier)Linking the subscription
Subscription / licence statusUnlocking paid features
Sign-in and last-activity timestampsOperations and abuse prevention

No name, no date of birth, no address, no entries.

Until 11 September 2026 there was one more row here: the recording seconds used in the current period. It served the minute allowance for the recognition service. That service is gone, and the number has not been updated since. Accounts from before that date still carry an old value; it is deleted along with the account.

There are three ways to sign in: Google, Apple, or email with a six-digit code. With Google and Apple we learn only the email address and an identifier from them — not your address book, not your profile. Conversely, Google or Apple learns that you signed in to RecTake; see section 4.

2.4 The website rectake.de

The website sets no cookies, embeds no analytics and loads nothing from third-party servers. That is also why there is no cookie banner.

Server access logs are produced on request, as with any web server: IP address, timestamp, page requested, browser type submitted. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). The host states that it keeps them only as long as operation and security require, and publishes no fixed period.

The website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel is certified under the EU-US Data Privacy Framework; its data processing agreement with standard contractual clauses forms part of its terms of service. The site itself transmits no personal data to us — there is no form, no account and no comment function.

Domain, name resolution and email sit with a German provider instead, see section 4.6. Anyone opening rectake.de asks there first where the address points.

2.5 Purchases and subscription

Processing runs through the App Store or Google Play. We learn from them whether a purchase is valid — no payment data, no card number, no billing address. Apple and Google are responsible for payment processing in their own right; their privacy notices apply in addition. Validation of purchases is handled by RevenueCat, see section 4.5.


3. Legal bases

ProcessingLegal basis
Account (email, account ID, subscription status)Performance of a contract, Art. 6(1)(b) GDPR
Website access logs, abuse preventionLegitimate interest, Art. 6(1)(f) GDPR
Entries on the deviceNo processing by us — the data never reaches us
Voice recording and vocabularyNo processing by us — they do not leave the device

This table has been shorter since 11 September 2026. Until then two rows stood at the top which relied on Art. 9(2)(a) GDPR: the voice recording and the vocabulary sent with it, both health data, both only with explicit consent. That transmission no longer exists, so the consent has nothing left to cover.

No health data reaches us. What we process is an account and a subscription status. That is not a special category of personal data under Art. 9 GDPR.


4. Who receives data

We do not pass data on for advertising, sale or profiling — to anyone. The recipients below are processors under Art. 28 GDPR, or independent controllers where that is stated explicitly.

4.1 Supabase — account and sign-in

Supabase Pte. Ltd.
65 Chulia Street #38-02/03, OCBC Centre
Singapore 049513
Place of processing for the database: Frankfurt am Main (eu-central-1)

Our contracting party is the Singapore company, not the US-based Supabase, Inc. The latter acts as a sub-processor for support.

What goes there: email address, account ID, subscription status. Nothing else.

What goes there without us controlling it: the sign-in service records the IP address, your device or browser identifier and the time of every sign-in. These logs sit with a sub-processor (Google BigQuery); there is no assurance that this storage is located in the EU.

What does not go there: your entries, your voice recordings, your vocabulary.

Until 11 September 2026 this also hosted the endpoint that passed voice recordings on to the recognition service (an Edge Function, explicitly pinned to Frankfurt am Main). It has been deleted.

Processing agreement: in place. Under the terms of service it applies automatically on entering into the contract, without separate signature (version of 1 August 2026). The European Commission's standard contractual clauses (implementing decision 2021/914, module 2) are incorporated.

4.2 The recognition service — there is none any more

Until 11 September 2026 a processor stood here: Scaleway SAS, Paris. Every voice recording went there to become text. This section stays because the question stays — it just answers it differently now.

Why the service is gone. We had asked the provider in writing whether its recognition service may carry health data under Art. 9 GDPR. The answer was no: the certification for hosting health data under French law (HDS) covers servers, storage and networking — not the recognition service. A second provider we checked answered the same way.

That left two options: find a third provider, or abolish the transmission. We abolished the transmission. Since 11 September 2026 recognition is done by your phone's operating system (section 2.2).

What this means: there is no processor for voice recordings any more — not in France, not anywhere. No contract, no transmission, no exception for fault cases, no open question under Art. 9.

What is left from that time: nothing that would need deleting. The service contractually neither stored nor logged nor trained on requests. The one exception was a technical fault case, for which the provider allowed retention of up to two weeks — at a frequency of roughly 1 in 1,000,000 requests. That period has long expired for every request there ever was.

4.3 Google — Google Sign-In

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland

Only if you choose this sign-in path. Google learns that you are signing in to RecTake and transmits an identifier and your email address to us. Google processes the sign-in in its own right; Google's own privacy notices apply to that.

Google does not learn your entries. They do not leave the device.

4.4 Apple — Sign in with Apple

Apple Distribution International Ltd.
Hollyhill Industrial Estate, Hollyhill
Cork, Ireland

As with Google, only if you choose this path. Apple offers to hide your email address; in that case we receive a relay address instead of your real one. Here too: no entries.

4.5 RevenueCat — subscription management

RevenueCat, Inc.
1032 E Brandon Blvd #3003
Brandon, FL 33511, USA

If you take out a subscription, this service validates the purchase. It is the party that knows, towards the App Store and Google Play, whether your subscription is valid.

What goes there: your RecTake account ID, the store receipts and technical details of your device that the embedded module sends along.

What does not go there: your entries, your voice recordings, your vocabulary. And no payment data — neither we nor this service see a card number or a billing address. Payment is handled solely by Apple and Google.

Place of processing: United States. That is a third country. The transfer relies on the European Commission's standard contractual clauses. The processing agreement forms part of the terms of service and does not need to be signed separately.

Why we transmit your account ID and not your email address: the service needs to attach the purchase to an account. The identifier is enough. The email address stays with us.

4.6 Serverprofis — domain, name resolution and email

Serverprofis GmbH
Otto-Lilienthal-Ring 34-36
85622 Feldkirchen
Germany

This is where the address rectake.de is registered, where name queries for it are answered, and where our mailbox sits.

What goes there: your emails to us — support requests and anything you ask for under the GDPR, such as access or erasure. Plus the technical data of every name query, when your device wants to know where rectake.de points.

What does not go there: your entries, your voice recordings, your account.

Place of processing: Germany. No third-country transfer.

Which is why the deletion page and this page both say: do not send us health details by email. We never need them to resolve a request, and an email does sit on a mail server.

4.7 Nobody else

There are no further recipients. In particular:

  • no analytics SDK (no Firebase Analytics, no Amplitude, nothing comparable)
  • no advertising IDs, no tracking, no sharing with ad networks
  • no crash reports containing content
  • no sharing with health insurers, insurance companies, employers or any other third party — under no circumstances

5. Third-country transfers

Speech recognition is no longer a transmission at all — it runs on your phone. Of the processing that does reach us, the database sits in Frankfurt am Main.

There is a third-country element nonetheless, at one point. Our contracting party for account and sign-in is established in Singapore, its support provider in the United States. There is no adequacy decision of the European Commission for that company. The transfer therefore relies on the standard contractual clauses under Art. 46(2)(c) GDPR, supplemented by the provider's transfer impact assessment. There is no participation in the EU-US Data Privacy Framework.

This concerns your account data and the sign-in logs. Not affected are your entries and your voice recordings — they do not leave the device at all. Domain, name resolution and email are not affected either; those sit in Germany (section 4.6).

For the sign-in paths via Google and Apple, see 4.3 and 4.4; both companies act as controllers in their own right.


6. How long data is kept

DataDuration
Entries on the deviceAs long as you want. They are yours; you delete them in the app or by uninstalling
Voice recordingNot at all — it never reaches us. On the phone it lives only for the duration of the recording
Account (email, account ID, subscription)Until you delete the account (see Delete account)
Website access logsWith the host, no fixed published period (section 2.4)
Technical logs (numbers only, no content)7 days at most

Tax and commercial retention obligations may bind individual invoice data for longer (§ 147 AO, § 257 HGB). Invoices are issued by the stores, not by us; none arise with us.


7. Your rights

Under the GDPR you have the following rights against us:

  • Access (Art. 15) — which data we hold about you. With us that is a short list, because your entries are not part of it.
  • Rectification (Art. 16)
  • Erasure (Art. 17) — see Delete account
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing based on legitimate interests (Art. 21)
  • Withdrawal of consent (Art. 7(3)) — see section 8

An informal message to support@rectake.de is enough for all of it. We reply within one month (Art. 12(3) GDPR). It costs you nothing.

An honest note on access requests: we cannot hand you your entries, because we do not have them. They are on your device. You can, however, export them yourself as a file at any time (Settings → Your data).


8. Consent to speech recognition

There is none any more, and there is nothing you need to do.

Until 11 September 2026 the app obtained explicit consent under Art. 9(2)(a) GDPR the first time you recorded: without it, no recording was transmitted for recognition. The transmission is gone, and with it the consent. The “Allow speech recognition” switch has disappeared from the settings, because there is nothing left for it to permit.

What that means for consent you gave earlier: it has nothing left to cover. No processing relies on it any more. The lawfulness of processing carried out until then is unaffected (Art. 7(3) sentence 2 GDPR). There is nothing to delete: nothing was stored at the recognition service of the time, and the one exception for technical faults has long expired (section 4.2).

A right of withdrawal under Art. 7(3) GDPR of course applies to any consent we might obtain in future. At present no processing relies on consent (section 3).


9. Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority if you believe we are infringing the GDPR (Art. 77 GDPR). The competent authority is the one where you live, where you work, or where the alleged infringement took place.

The authority competent for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian Commissioner for Data Protection and Freedom of Information)
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany

https://datenschutz.hessen.de

This authority is competent because the controller is established in Wiesbaden, in the German federal state of Hesse.


10. Security

  • The safest path is the one that does not exist. Voice recordings, transcripts and vocabulary are never transmitted, so they can never be intercepted, stored or logged anywhere.
  • The connection between app and account endpoint is TLS-encrypted end to end.
  • Your session lives in the operating system's keychain, not in a file next to the entries.
  • Account data is locked down row by row on the server: a signed-in user can read their own row and no one else's, and can write none.

11. No automated decision-making, no profiling

There is no automated decision-making within the meaning of Art. 22 GDPR. We do not build profiles and do not derive any assessment of you from your data.


12. Children

The app is not directed at children. You must be at least 16 years old to use it. This matches Art. 8 GDPR on consent in information society services as applied in Germany, and the age ratings in both stores.


13. Not a medical application

RecTake is a diary, not a medical device. It gives no diagnosis and no treatment recommendation. See the disclaimer.


13a. Waiting list on this website

While the app is not in the store yet, you can leave your email address on the home page. It is used for exactly one purpose: to send you a single message — the one saying RecTake is available. No newsletter, no advertising, no sharing with third parties.

What is stored: your address, the time, the language of the page and the fact that the entry came from the website. No IP address, no cookie, no identifier. Nothing leaves your browser until you tap “Join the list” — simply reading the page transmits nothing.

Where it is stored: in the same database as the app accounts, at Supabase in Frankfurt. The table is set up so that the website can only write to it and never read from it.

Legal basis: your consent (Art. 6(1)(a) GDPR), given the moment you submit the address. Withdrawal: any time, informally, to support@rectake.de — we delete the entry. At the latest, we delete the entire list once the launch message has been sent.


14. Changes to this policy

If processing changes — for instance because a new service provider is added — we change this text and update the date at the top. For material changes that require consent, we obtain it explicitly. The change of 11 September 2026 went the other way: a processing operation falls away, none is added.


15. Contact

Questions about data protection, access requests, deletion: support@rectake.de

Legal notice: Legal notice · Impressum (deutsch, maßgeblich)

RecTake

A diary that listens. For supplements, medication, food, drinks, caffeine, mood, symptoms and notes.

Product

  • How it works
  • Features
  • Privacy
  • FAQ

Read

  • Blog
  • Search
  • Support
  • Deutsch

Legal

  • Legal notice
  • Privacy policy
  • Terms of use
  • Disclaimer
  • Delete account

RecTake is a diary, not a medical device. The app makes no diagnosis and is no substitute for medical or pharmaceutical advice.

This site uses no cookies, no tracking and no external scripts. The only code it loads sits on this domain.

© 2026 IT Consulting & Development Tino Sanchez Ross