Junkfoodselfie — Privacy Policy

Last updated: 26 September 2026 · Version 2.0

Junkfoodselfie helps you pause before ordering junk food by blocking your food-delivery apps on days you choose. This policy explains what we collect, what we deliberately don't, and what happens to your data. We've written it in plain English on purpose — and everything in it describes how the app actually works.

Who we are

Junkfoodselfie is operated by Rosenbia Technologies Ltd, a company registered in England and Wales (company number [INSERT COMPANY NUMBER]) with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. Rosenbia Technologies Ltd is the data controller for the personal data described in this policy.

The short version

unlock moment and are never uploaded, stored on our servers, or seen by us.

technology gives us opaque, device-bound tokens we could not read or upload even if we wanted to.

trained on your photos, messages, or behaviour — by us or anyone else.

no cross-app tracking of any kind.

What Junkfoodselfie does (so the rest makes sense)

You pick food-delivery apps to block and the weekdays to block them. On a blocked day, opening those apps brings you to Junkfoodselfie, where unlocking requires a deliberate ritual: taking a live selfie, or holding a promise you wrote to yourself, optionally over photos you chose. You can log how each day went, see streaks and an estimated-savings tally, and share chosen meal photos with friends you add by mutual invite. It is a behavioural aid — a speed bump you set up for yourself — not a guarantee of anything.

What we collect, and why

Each row states what it's for. The lawful bases and retention are detailed in the sections below.

DataWhat it's for
Email address and password (or Sign in with Apple credential)Your account, sign-in and recovery. We never see your password in usable form (it is hashed) or your Apple credential.
Name (required)Your profile; shown to friends you add.
Age (optional)Your own profile record only. Never shown to friends.
Location — free text you type (optional)Your own profile record only. Never shown to friends. Not device location: we never access GPS.
Profile picture (optional)Shown to friends you add.
Your written promise note (max 90 characters)Displayed to you during unlock. Private to you; never shown to friends.
Inspiration / Before-and-Now photos (optional)Displayed to you during unlock. Private to you; never shown to friends.
Meal photos, captions, recipes you choose to shareShown only to friends you add, only because you tapped share.
Blocked weekdays and day outcomes (strong / ordered healthy / ordered junk / day off / plans changed)Your calendar, streaks and savings tally; the last 60 days of outcomes are visible to friends you add.
Average order value and currency (if you enable money saving)Your private savings estimate. Never shown to friends.
Friend connections, invite code and emoji reactionsThe mutual-invite friends feature.
Device push token (if you allow notifications)Delivering notifications (e.g. a friend cheered you on).
Reports you make about a friend's photoContent moderation.
Subscription entitlement statusKnowing your plan is active. Payment itself is handled entirely by Apple — we never receive card details, and we store no purchase history on our servers.
Support correspondenceAnswering you when you email us.
Infrastructure logs (IP address, request metadata)Generated automatically by our hosting provider when the app talks to our servers, for security and service operation.

Photographs, exactly

Photos deserve their own section, because different photos are treated completely differently:

moment, on your phone. It is never uploaded to any server. The app checks that a face is present using Apple's on-device detection — it does not identify you, match you against anything, or create or store any biometric template. These are ordinary photographs, not biometric data.

private storage bucket accessible only to your account through short-lived signed links; encrypted in transit and at rest by our hosting provider. Never shown to friends. Replacing a photo overwrites the old one; deleting your account erases them entirely.

storage and encryption; readable only by you and the friends you added. Each meal photo can be individually deleted by you at any time, and friends can report a photo, which hides it pending review.

Your promise note

The personal message you write to yourself is stored in your account record on our servers (so it survives a reinstall), protected by row-level security so only your own signed-in account can read it, and encrypted in transit and at rest by our hosting provider. It is never shown to friends, never analysed, and never used for anything except displaying it back to you. Deleting your account erases it.

No AI training — stated plainly

Your photos, promise note, day outcomes, and every other piece of your content are not used to train any AI or machine-learning model, ours or anyone else's. The app sends no user content to any AI provider. The only automated image processing is Apple's on-device face detection during the selfie unlock, which leaves your phone never.

What we deliberately do NOT collect

We also run no third-party analytics, advertising or crash-reporting SDKs — the app contains only Apple's own frameworks and our own code.

Our lawful bases

PurposeLawful basis (UK GDPR)
Running your account, blocking schedule, calendar, streaks, savings, photos, friends and notifications — the service you signed up forPerformance of a contract (Art. 6(1)(b))
Security, abuse prevention, content-report handling, pruning dead push tokens, infrastructure logsLegitimate interests (Art. 6(1)(f)) — keeping the service safe and working
Showing you notificationsYour consent via the iOS permission prompt; withdraw anytime in iOS Settings
Camera and photo-library accessYour consent via the iOS permission prompts; each use is user-initiated
Responding to legal obligations (e.g. a valid request from authorities)Legal obligation (Art. 6(1)(c))

We do not process special-category data. Day outcomes are self-logged lifestyle entries, not health records; unlock selfies are not biometric data (no identification is performed).

Who can see what

Everything is private by default. The only sharing in the product is with friends you add by mutual invite code — and they see exactly this, no more:

Friends never see: your age, location, promise note, inspiration or before-and-now photos, savings figures, order values, or which apps you block. Removing a friend cuts visibility both ways. Nothing about you is ever public.

Processors and where your data lives

ProviderWhat they do
Supabase (Supabase Inc.)Our backend: database, authentication, photo storage, push-dispatch functions. Hosted in [VERIFY: Supabase project region], encrypted in transit and at rest, governed by Supabase's data processing agreement.
Apple Inc.Sign in with Apple, App Store payments and subscription management, and delivery of push notifications through Apple's notification service. Governed by Apple's developer and services terms.
[INSERT: email provider used for auth/support emails, if any beyond Supabase's built-in sender]Account confirmation and password-reset emails.

We use no other processors, no data brokers, and we never sell or rent personal data.

International transfers

Our hosting provider's infrastructure for this app is located in [VERIFY: region — if United Kingdom or EEA, no restricted transfer of stored data occurs]. Where a provider (such as Supabase Inc. or Apple Inc.) is established outside the UK, transfers are safeguarded by that provider's data processing terms incorporating recognised transfer mechanisms (the UK Addendum / International Data Transfer Agreement or UK adequacy, as applicable) — [VERIFY provider DPA terms]. We will not transfer your data anywhere without an appropriate safeguard.

Security

What we actually do, not slogans: all traffic between the app and our servers uses TLS; stored data and photos are encrypted at rest by our hosting provider; every database table is protected by row-level security so an account can only ever read what it is entitled to; photos live in private buckets reachable only through short-lived signed links; server-side administrative access is limited to audited serverless functions (for push delivery and account deletion) rather than standing credentials in the app; the app itself holds no secret keys capable of reading other users' data. No system is perfectly secure and we don't claim to be — if a breach ever creates a risk to you, we will assess and notify the ICO and affected users as UK law requires.

How long we keep things

DataRetention
Account, profile, photos, notes, calendar, friends, reactionsUntil you delete your account — then erased immediately (see below)
Day outcomes shared with friendsOnly the most recent 60 days are ever served to friends; the underlying record lasts until account deletion
Push tokensDeleted when you sign out, when Apple reports the device gone, or at account deletion
Support emails[INSERT retention period, e.g. 24 months after resolution]
Infrastructure logsProvider-side, short-term rotation — [VERIFY Supabase log retention]
BackupsProvider-managed backups expire on a rolling basis — [VERIFY backup retention for our Supabase plan]; deleted-account data ages out of backups within that window and backups are never used to restore deleted accounts

Your rights

Under UK data protection law you can: access your data, correct it, erase it, restrict or object to processing, receive a portable copy, and withdraw consent where consent is the basis (e.g. notifications, via iOS Settings). How to exercise them: most are built in — your profile is editable in-app, every meal photo is individually deletable, and Settings → Delete account erases everything instantly. For anything else (including a copy of your data), email [INSERT PRIVACY EMAIL] and we will respond within one month, verifying that the request really comes from the account holder. You can complain to the UK Information Commissioner's Office at ico.org.uk — though we'd appreciate the chance to fix things first.

Deleting your account — what actually happens

Settings → Delete account triggers immediate, permanent server-side deletion: your stored photos are wiped, then your account record is deleted, which cascades through every table — profile, calendar history, friendships, reactions, meal records, reports and push tokens. Friends immediately lose access to anything you had shared (their view is served live from our database, not stored on their phones beyond short-lived caches). Your Apple subscription is separate — cancel it in iOS Settings → Apple Account → Subscriptions, since Apple, not us, bills you. Residual copies in provider backups expire within the backup window above and are never restored.

Age — 18+

Junkfoodselfie is for adults aged 18 and over, as our Terms of Use require and as users confirm at sign-up. It is not directed at children, we do not knowingly collect data from anyone under 18, and accounts we reasonably believe belong to minors will be deleted. The App Store listing carries an [INSERT: chosen App Store age rating] rating.

No tracking, no advertising

Junkfoodselfie performs no cross-app or cross-site tracking, uses no advertising identifiers or ad networks, contains no attribution SDKs, and shares nothing with data brokers. Because there is no tracking, Apple's App Tracking Transparency prompt never appears — there is nothing to ask about.

Website

[INSERT when the junkfoodselfie website launches: its own cookie/analytics inventory. The website is a separate system from the app; this policy will be updated to cover it before it collects anything.]

Changes

When this policy materially changes, we'll update the version and date above and make you aware in the app before or when the change takes effect. Previous versions are available on request.

Contact

Rosenbia Technologies Ltd 128 City Road, London, EC1V 2NX, United Kingdom Privacy and rights requests: [INSERT PRIVACY EMAIL — currently alisalum@live.com]