Last updated: July 2025
1. Privacy at a Glance
The following information provides a simple overview of what happens to your personal data when you visit our website or use our CarbLens app. Personal data is any data that can be used to personally identify you.
Data Collection at CarbLens
Who is responsible for data collection?
Data processing is carried out by the operator of this website/app:
Lukas Müller
Bautzener Str. 25
10829 Berlin, Germany
Email: contact@carblens.com
How do we collect your data?
Your data is collected in part by you providing it to us. This may include data you enter into a contact form or leave for the waitlist.
Other data is collected automatically or after your consent when visiting the website through our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
In the CarbLens app:
- Photos of meals you upload for carbohydrate analysis
- Email address (if you sign up for the waitlist)
- Device information for authentication
- Payment information (processed exclusively by Apple App Store / Google Play Store)
What do we use your data for?
- Photos: Exclusively for analyzing carbohydrate content using AI (Claude API by Anthropic)
- Email (waitlist): To inform you about app availability
- Technical data: To provide and operate the website/app
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients, and purpose of your stored personal data. You also have the right to request correction or deletion of this data. You can contact us at any time with questions about data protection.
2. Hosting and Content Delivery Networks (CDN)
Cloudflare
We use the service of Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”) for the following purposes:
- Website hosting via Cloudflare Pages
- DDoS protection and CDN for fast, secure content delivery
- Cloudflare Workers for processing API requests
- Cloudflare D1 for database functions
- Cloudflare R2 (planned for future) for image storage
Cloudflare receives your personal data and acts as a data processor on our behalf. This corresponds to our legitimate interest within the meaning of Art. 6 para. 1 sentence 1 lit. f GDPR, not having to maintain a server on our premises.
Cloudflare has certified under the EU-US Data Privacy Framework and thus committed to comply with EU data protection requirements.
For more information about objection and removal options regarding Cloudflare, see: https://www.cloudflare.com/privacypolicy/
Data Protection
The operator of these pages takes the protection of your personal data very seriously. I treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
Note on the Responsible Party
The responsible party for data processing is:
Lukas Müller
Bautzener Str. 25
10829 Berlin, Germany
Email: privacy@carblens.com
Storage Duration
Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with me until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted unless I have other legally permissible grounds for storing your personal data (e.g., tax or commercial law retention periods).
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of data processing carried out until revocation remains unaffected by the revocation.
Right to Lodge a Complaint with the Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, place of work, or place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
The competent supervisory authority for Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin, Germany
Right to Data Portability
You have the right to have data that I process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.
4. Data Collection in the CarbLens App
Processing of Meal Photos
What is collected?
When you upload a photo of a meal in the app, it is temporarily processed.
Legal basis:
Processing is carried out to fulfill a contract or to carry out pre-contractual measures in accordance with Art. 6 para. 1 lit. b GDPR.
Purpose of processing:
The photo is used exclusively to analyze carbohydrate content. The analysis is performed via the Claude API by Anthropic, PBC.
Storage duration:
In the current version, photos are deleted immediately after analysis. No permanent storage takes place.
Data sharing:
Photos are transmitted to Anthropic, PBC (Claude API) for analysis. Anthropic is a US company. The transmission is encrypted. Anthropic does not use the transmitted data for its own purposes or to train its models.
For more information, see Anthropic’s privacy policy: https://www.anthropic.com/privacy
Payment Processing
Payment processing for premium subscriptions is handled exclusively through:
- Apple App Store (for iOS users)
- Google Play Store (for Android users)
We only receive information about completed transactions (subscription status, transaction ID) from the app stores, but no payment details such as credit card numbers. The privacy policies of the respective app stores apply.
To manage your free daily usage and any subscription, we store an anonymized device ID. This does not allow any conclusions to be drawn about your person.
5. Waitlist (Website)
Email Address for Waitlist
What is collected?
When you sign up for our waitlist, we collect your email address.
Legal basis:
Processing is based on your consent according to Art. 6 para. 1 lit. a GDPR.
Purpose:
Your email address is used exclusively to inform you about the availability of the CarbLens app.
Storage duration:
Your email address will be deleted as soon as you unsubscribe from the waitlist or at the latest after we have informed you about app availability and you do not wish to receive further information.
Unsubscribe:
You can unsubscribe from the waitlist at any time by sending an email to unsubscribe@carblens.com.
No sharing:
Your email address will not be shared with third parties and will not be used for advertising purposes.
6. Your Rights
Within the framework of applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing and, if applicable, a right to correction or deletion of this data.
Restriction of Processing
You have the right to request the restriction of processing of your personal data.
Objection to Processing
You have the right to object at any time to the processing of your personal data carried out on the basis of Art. 6 para. 1 lit. e or f GDPR.
7. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy. The new privacy policy will then apply to your next visit.
If you have any questions about data protection, you can contact us at any time:
Lukas Müller
Email: contact@carblens.com