Basal

Privacy policy — Basal

Last updated: 12 October 2026

This is a translation of the French privacy policy. If the two versions ever differ, the French version prevails.

This policy describes exactly what the Basal app does today, without anticipating features that are not yet available.

1. Summary

2. Data you record in the app

When you use Basal, you can record:

This data is considered health and wellbeing data in the broad sense (weight, diet, physical activity). It is handled with the same care as any sensitive data: it stays on your device and is shared with no one by the app itself.

An account remains entirely optional (see section 3): if you don't create one, the app asks for no email address, no username, no phone number and no password. Even if you create an account, none of this data is linked to your civil identity — it is only used to power the calculations and charts shown in the app.

3. Account (optional)

If you wish, you can create an account from Settings → Account — never forced on you when the app starts, never required to use it fully. An account is used to back up your data and get it back on another device, and to carry a Premium subscription from one platform to another.

Creating an account records:

Your address must be confirmed through a link sent by email before the account can be used. You can sign out, reset your password, or permanently delete your account at any time from the same screen.

Signing in with Google or Apple

Instead of choosing a password, you can create your account — or sign back in — through Google or Apple. The resulting account is exactly the same, with the same data and the same delete button.

In that case, your Google or Apple password is never passed to the app: the provider recognises you on its own side, then hands us a signed confirmation. From it we only take your email address and a technical identifier — never your contacts, calendar, photos or anything else from your Google or Apple account.

If you go through Apple, it offers to hide your address. If you accept, you give us a relay address ending in @privaterelay.appleid.com: it works normally to receive our messages, but does not reveal your real address. The app treats it like any other address.

Signing out also ends the session on Google's side, so that the previous account is not automatically selected again the next time you sign in.

Deleting the account erases your data from the server, but not from your device: weight, meals, recipes and goals remain there, and the app simply becomes local again, as it was before the account was created.

4. Where this data is stored

Without an account, all your data described in section 2 is stored only on your device, using the app's native storage. None of it is sent to a server: uninstalling the app deletes it permanently, and switching devices without using the manual export (section 8) transfers none of it.

With an account, the same data is also copied to a server hosted by Supabase, in the Ireland (European Union) region. There it is linked to your account and protected by isolation that technically prevents any other user from accessing it. This copy is used to give it back to you on another device.

Some information stays specific to each device and is never sent, because it would make no sense elsewhere or would disrupt another device:

Finally, if an unexpected technical error occurs (bug, crash), an anonymous, purely technical report — never your personal data — may be sent to a third-party diagnostic service (see section 6).

5. Sharing data with third parties

The publisher of the app does not sell, rent or share any of your data with a third party, for advertising, commercial or any other purposes. No third-party audience analytics (behavioural analytics), advertising or ad tracking tool is built in.

The app makes one kind of network request triggered by you — food search and barcode scanning: when you type a search, the text you typed is sent to the public, collaborative Open Food Facts database; when you scan a barcode, only the barcode number is sent to it to identify the product.

No other information (your profile, your weight, the meals you have already logged) is sent on these occasions. These requests are subject to the privacy policy of Open Food Facts, a project independent from the publisher of this app.

A second kind of network request exists, triggered not by a deliberate action but by an unexpected technical error: see section 6 (technical diagnostics / Sentry).

Finally, if you have created an account, the app communicates with Supabase, our hosting and authentication provider, to back up your data there and check your identity when you sign in. Supabase acts solely on our behalf and on our instructions; it does not use your data for its own purposes. The servers used are located in Ireland, in the European Union. Without an account, no such communication takes place.

6. Technical diagnostics (crash reports)

The app uses Sentry, a third-party technical diagnostic service, to be notified automatically when a bug or crash occurs so that it can be fixed. It is a diagnostic tool, not an audience analytics or ad tracking tool — it only activates when a software error occurs.

What is sent to Sentry when an error occurs:

What is never sent to Sentry: your profile, your weight, your meals, your goals, your workouts, your account information, or any other data described in sections 2 and 3 — nor your IP address (the tool's default collection of personal data is explicitly turned off in its configuration). No photo or location data is collected.

Where and when:

7. Notifications

The app can send you local reminders (weigh-in, unlogged meal, daily summary) if you turn this feature on. These notifications are scheduled entirely on your device: no external server is involved, and no data is sent to generate these reminders.

8. Exporting your data

At any time, you can export all your data (profile, weight, meals, steps, workouts, metabolism) as JSON or CSV, from Settings → My data. This file is generated on your device and is:

The publisher of the app has no access to any of these exports: the choice of destination is entirely yours.

9. Permissions requested by the app

The app requests up to three permissions on your device, each tied to a specific feature, never turned on by default without your consent, and which can be turned off at any time in your phone's settings:

You can refuse or revoke these permissions at any time; the app remains usable, and only the corresponding features (barcode scanning, reminders, step sync) will then be unavailable — entering steps manually always remains possible.

10. Deleting your data

You can delete your data at any time:

Without an account, no copy of your data exists outside your device: there is therefore nothing more to do with the publisher.

How long is your data kept?

For as long as you keep your account, and not a minute longer. There is no automatic expiry: someone who comes back after two years finds their history intact, which is precisely the point of long-term tracking. Your data is kept for as long as the service is provided, then deleted when you delete your account.

Without an account, the question does not arise: nothing is kept anywhere other than on your device, and uninstalling the app erases everything.

How to delete

With an account, deleting your account from Settings → Account also immediately erases all the associated data on the server. This deletion is permanent and requires no email request: it is available directly in the app, as the App Store and the Play Store require. Your local data stays on your device until you erase it yourself.

If you have uninstalled the app or changed phones, the steps to follow — along with the exact details of what is and isn't deleted — are on the account deletion page (in French).

11. Privacy of minors

This app is reserved for people aged 18 and over.

This threshold is stricter than the law requires, and that is deliberate. In France, the age of digital consent is 15: above it, a person can consent on their own to the processing of their data. Nothing therefore required excluding 15-to-17-year-olds.

Two reasons led us to do so anyway.

The first is the subject itself. Calorie tracking touches on sensitive issues, and eating disorders particularly affect teenagers. Counting calories every day is a behaviour that the scientific literature documents as a risk factor at that age. The app shows warnings to that effect, offers no aggressive goal and in no way replaces the advice of a healthcare professional — but no interface precaution makes up for the exposure itself.

The second is the data. A weight, daily weigh-ins and food intake are health data. For a minor, they fall under a stricter regime, and processing them requires parental consent that this app does not put in place — and therefore does not claim to cover.

No data is knowingly collected from anyone under 18. If you find that a minor has created an account, write to the address in section 14: the account and the associated data will be deleted.

This choice is carried over to the distribution platforms: the age rating is set to 18 and over, and access for users identified as minors is restricted. The app is not enrolled in any programme aimed at children.

12. Legal basis and your rights

On what basis is this data processed

No processing is based on advertising, profiling or resale: there simply isn't any.

Your rights

Without an account, the publisher neither receives nor stores any of your personal data: the rights of access, rectification and erasure under the GDPR are exercised directly by you, on your device — you are the only person who holds this data (see sections 8 and 10).

With an account, a copy of your data is hosted in Ireland, in the European Union. Your rights are then exercised as follows:

For any question or complaint, the contact address is in section 14. You also have the right to lodge a complaint with the CNIL, the French data protection authority.

The only exception, limited to the anonymous technical reports described in section 6: as they are attached to no identity (even if you have created an account, this anonymous identifier is never linked to it), they cannot be traced back to you specifically to exercise an individual right of access or erasure — they are kept by Sentry under its own retention policy, then deleted automatically.

13. Future changes

If an additional health sync (Garmin, Fitbit) or any other processing involving a new transfer of data were to be offered, this policy would be updated beforehand to describe it precisely, and the feature would be presented to you as optional — exactly as the account described in section 3 already is.

14. Contact

Data controller — Théo Serrano, sole trader trading under the business name Basal (SIRET 943 668 137 000 12), registered at 958 route de Saint Abdon, 69390 Charly, France.

For any question about this privacy policy, or to exercise any of the rights described in section 12, you can write to contact@basal-app.fr, or go through the app's page on the store you downloaded it from.

If you believe your rights are not being respected, you can lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés, cnil.fr).