MintChip

Privacy Policy

Beta version · Last updated 27 August 2026

MintChip is a habit-and-behaviour app for people who do not want to count calories. This policy explains what the app collects, why, and what you can do about it. It describes the app as it actually works during the closed beta. If we change how the app handles your data, we will update this page.

Who operates MintChip

MintChip is operated by MkStudios – Mario Koll, Drosselweg 5/2, 4030 Linz, Austria. You can reach us at office@mk-studios.net for any question about this policy or your data. Full company details are in our Impressum.

What we collect and why

Account and sign-in

You create an account with an email address and password, with Sign in with Apple, or with Google Sign-In. We store your email address, the sign-in method you used, and an internal account identifier. If you enter a first name during setup, we store that so the app can greet you. We use this only to sign you in and to keep your data attached to your account.

Setup answers

During setup MintChip asks a few questions to calculate your starting Treat Balance. We store your answers about sugary drinks, snacking, and eating out.

Some setup answers never leave your phone. The date of birth, gender, height, and weight entered during the setup questions are used on your device only, to calculate your starting balance. They are not sent to our servers and we do not store them. Weight is stored only if you separately turn on weight tracking (below).

What you log

The app exists to record what you eat and drink, so this is the bulk of what we hold:

We use this to run the app's features: your Treat Balance, your history, your Insights, and your Coach.

Weight and progress photos — both optional

MintChip works fully without either of these.

You can skip both, and you can delete photos individually at any time.

Photos of food and drinks

When you use the photo ("Snap") logging feature, the picture is sent to OpenAI so it can be turned into a meal entry. MintChip does not store that picture. It is used for the classification and then discarded. We keep only the resulting entry and a small technical record of the classification (which method was used and what kind of item it identified) so we can monitor how well the feature works.

AI processing

MintChip uses OpenAI to power three things:

These calls are made by our servers, not by your phone, and our API credentials never leave our servers. The Coach model has no access to our database — it can only see the text summary we send it. This processing takes place on OpenAI's infrastructure, which is outside the EU. We do not send your email address, your name, your weight, or your progress photos to OpenAI. MintChip does not store your Coach conversation on our servers; the conversation lives on your phone for the length of the session, and we keep only a timestamped record that a message was sent, to enforce a daily usage limit.

Analytics and diagnostics

MintChip uses PostHog to understand how the app is used and to catch crashes. Events are sent to PostHog's EU ingestion servers. We do not use automatic capture of everything you tap — the app sends a defined list of product events, for example that onboarding was completed or that a meal log succeeded or failed. Events are linked to your account identifier, so this data is not anonymous.

If you agree to analytics, PostHog session replay is enabled during the beta for a sample of your sessions. Replay records how the app's screens were used. Text you type into fields, images, and system views are masked before recording; network content and console logs are not recorded. Uncaught errors are also reported so we can fix crashes.

Analytics is your choice. You are asked when you create your account, and you can change your mind at any time in Settings → Data & Privacy → Analytics consent. If you decline, MintChip sends no product events, no session replays and no error reports — and nothing is collected while we are still checking what you chose. Declining does not limit any feature of the app.

Notifications

MintChip's reminders are scheduled by your own device. We do not operate a push server and we do not store a push token. If you decline the notification permission, the rest of the app works normally. You can turn individual reminders off in Settings.

Where your data is stored

Your account and everything you log are stored with Supabase, in their Frankfurt region (EU). Access is restricted at the database level so that an account can only read and write its own rows, and progress photos sit in a private storage area scoped to your account. Transfers outside the EU happen for the AI processing described above.

Third parties we use

ServiceWhat it doesWhat it receives
SupabaseDatabase, account sign-in, photo storageEverything described above
OpenAIMeal/drink classification, CoachTyped descriptions, food photos, Coach messages and the activity summary
PostHog (EU)Product analytics, session replay, crash reportsProduct events, account identifier, masked replays, error reports
AppleSign in with AppleSign-in only, per Apple's own terms
GoogleGoogle Sign-InSign-in only, per Google's own terms

Legal bases for processing

If you are in the EU or the UK, we process your data on these bases:

WhatBasis
Running your account and the app's core featuresPerformance of a contract (Art. 6(1)(b))
Food, drink and habit logs, and anything you choose to add about your health or weightYour explicit consent, given at sign-up (Art. 6(1)(a), and Art. 9(2)(a) where the data concerns health)
Analytics, session replay and crash reportingYour consent, which you can withdraw at any time (Art. 6(1)(a))
Keeping the service secure and preventing abuseOur legitimate interests (Art. 6(1)(f))

Where processing rests on consent, withdrawing it is straightforward and does not affect the lawfulness of what happened before you withdrew it.

Your rights

If you are in the EU or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we process it, and to receive it in a portable form. The app implements the two you are most likely to want directly — see Your choices below — and you can exercise any of them by emailing office@mk-studios.net. We will respond within one month.

You also have the right to complain to a data protection supervisory authority. Our lead authority is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria (dsb.gv.at). You may also complain to the supervisory authority in the country where you live.

How long we keep things

We keep your data for as long as your account exists, because the app's value comes from your own history. We do not currently run an automatic deletion schedule for older entries. When you delete your account, the deletion described below happens straight away.

Your choices

Age

MintChip is not intended for children. The setup flow does not accept a date of birth for anyone under 13, and we ask that you do not use MintChip if you are younger than that.

Changes to this policy

If the app starts handling data differently, we will update this page and change the date at the top. During the beta we will also tell participants directly when something material changes.

Contact

office@mk-studios.net