Last updated: 2026-08-10
The controller responsible for the processing of personal data in connection with the TravelTaste app and the website ankerloop.ch is:
Ankerloop KLG
Switzerland
Email: info@ankerloop.ch
Website: https://ankerloop.ch
Within this privacy policy, "TravelTaste", "we", "us" or "our" refer to the controller named above.
This privacy policy explains which personal data we process in connection with TravelTaste, for which purposes, which service providers are used, and which rights data subjects have.
This English version is a convenience translation provided for easier understanding. The German version is authoritative.
This privacy policy applies to the use of the TravelTaste mobile app, to related features such as menu scanning, translation, the waiter card ("Show to the waiter"), bill scanning and bill splitting, and in-app purchases, as well as to the website ankerloop.ch insofar as it refers to TravelTaste.
TravelTaste can in principle be used worldwide. Depending on your place of residence or stay, different data protection laws may apply, in particular the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR) and, where applicable, further local data protection rules.
We process personal data only to the extent necessary for the provision, security, billing, improvement or legal safeguarding of TravelTaste.
We do not use user accounts where this is not technically required for using the app.
We do not permanently store uploaded menu images, receipts or free-text input on our own servers, unless expressly described otherwise in this policy.
We do not sell personal data to third parties.
We do not use in-app advertising or advertising-based cross-app tracking, unless a future version expressly announces this and any required consent is obtained.
The following overview summarizes the most important data categories, purposes and possible legal bases. For users in the EU or EEA, the legal bases follow in particular from Art. 6 GDPR and, where health-related information is concerned, Art. 9 GDPR where applicable. For users in Switzerland, the principles and obligations of the FADP apply.
Menu images, photos of menus, recognized text
Purpose: OCR, translation, menu analysis, display of information
Examples: image, recognized text, language, context
Legal basis: performance of a contract or pre-contractual measures; legitimate interest in secure service provision
Manually entered text
Purpose: waiter card ("Show to the waiter"), translation of special requests and context phrases
Examples: free text, requested language, context
Legal basis: performance of a contract; consent where sensitive information is concerned
Receipts and bills
Purpose: bill splitting, recognition of individual items, prices, taxes and tips
Examples: receipt photo, prices, items, taxes, tip
Legal basis: performance of a contract; legitimate interest in technical provision
Dietary restrictions and health-related preferences
Purpose: personalized warnings and guidance
Examples: allergies, intolerances, pregnancy-related notes, dietary preferences
Legal basis: explicit consent, insofar as special categories of personal data are concerned
Technical operating data
Purpose: operation, security, abuse prevention, error analysis
Examples: IP address, approximate region/country derived from the IP address, timestamps, app version, device type, operating system, stable device/installation ID (for quota and abuse control, hashed server-side), request outcome, log data
Legal basis: legitimate interest; performance of a contract; legal obligations
Purchase and entitlement data
Purpose: activation of usage passes and scan quotas
Examples: product ID, purchase status, expiry time, transaction/receipt reference, entitlement status
Legal basis: performance of a contract; legal obligations; legitimate interest in fraud prevention
Support communication
Purpose: handling of inquiries and complaints
Examples: email address, content of the inquiry, technical details
Legal basis: performance of a contract; legitimate interest; legal obligations
Optional crash and performance data
Purpose: bug fixing and app optimization
Examples: crash reports, error messages, system runtimes
Legal basis: consent or legitimate interest, depending on the specific technical implementation
5.1 Menu scanning, OCR, translation and analysis
When you capture a menu or other relevant text with TravelTaste, image data, recognized text and context information may be processed. This serves to recognize and translate text and to display user-friendly information about dishes, ingredients, allergens or dietary aspects.
Image and text data are generally only processed when you actively trigger the scan or translation. Permanent storage of these menu images or free texts on TravelTaste servers is not intended.
5.2 Waiter card ("Show to the waiter")
Using the waiter card, you can manually enter special requests, questions or phrases to have them translated into another language. These entries may contain personal or sensitive information if you enter such details yourself. Please do not enter any information that is not required for the order or translation.
5.3 Bill scanning and splitting
When scanning and splitting bills, receipts or invoices may be processed to recognize individual items, prices, taxes, tips or splitting information. Please take care not to scan receipts that contain unnecessary personal data of third parties, where this is avoidable.
Names or labels of companions that you enter to split a bill are, under the current product logic, processed locally on your device. Should this technical implementation change, this privacy policy must be updated beforehand.
5.4 Camera and photo library access
TravelTaste requires access to the camera and, where applicable, to the photo library when you want to analyze menus, receipts or images. Access takes place only after the respective operating system permission is granted on iOS or Android. You can revoke or restrict these permissions at any time in the system settings. Without camera or photo access, certain features are unavailable or only available to a limited extent.
5.5 No device location data; approximate origin from the IP address
TravelTaste does not collect device location data (e.g. GPS) and does not request location permission. The display and translation language is derived from your device's language setting, not from your location.
When the service is technically provided via our server and proxy infrastructure, an approximate region or country may be derived from your IP address. This serves security, abuse prevention and — insofar as you have consented to the collection of usage data — a coarse, country-level analysis. No precise positioning takes place. The country determined in this way may be returned to the app in the server's response so that the app can suggest the likely currency of a scanned menu; this value is processed only transiently on your device, is not stored server-side beyond the processing described above, and is used independently of any consent to usage-data collection.
5.6 Dietary restrictions, allergies and health-related information
If you voluntarily provide information about allergies, intolerances, pregnancy, diets, religious or other dietary requirements, this information may allow conclusions about your health or other sensitive areas of your life. Providing such information is voluntary.
We use this information exclusively to provide menu analyses and notices within the app. TravelTaste does not replace medical advice and cannot guarantee complete or error-free detection of allergens, ingredients, calories or health-related risks. Binding information must always be obtained from the restaurant, the manufacturer or medical professionals.
Where required by applicable law, we obtain separate consent for the processing of such information. Consent, once given, can be withdrawn at any time with effect for the future.
Under the current product logic, TravelTaste can be used without registration and without a classic user account. We therefore generally do not collect account data such as name, password or a permanent user profile, unless you provide such information yourself as part of a support request or a voluntary entry.
Certain settings, preferences or locally stored information may be stored on your device, such as language settings, app permissions, dietary preferences or temporary app states. Depending on the feature, you can delete such data within the app, influence it by changing device settings, or remove it by uninstalling the app.
Payment processing for in-app purchases and usage passes is handled by the Apple App Store or Google Play. TravelTaste does not process credit card, bank account or other complete payment data.
However, purchase and entitlement data may be processed to activate and manage purchased usage passes, such as product ID, purchase status, purchase time, expiry time, transaction or receipt references, entitlement status and information about remaining or used scan quotas. This data is required to provide paid features, prevent abuse and handle support requests.
Refunds, cancellations and payment questions are generally governed by the terms and processes of the respective app store provider.
We use service providers and platforms where necessary for operation, processing, app distribution, payment processing, security or support. We review this list regularly and update it when changes occur.
Anthropic PBC
Role: service provider / API provider, role depending on the contractual arrangement
Purpose: AI-supported analysis, translation or context processing
Data: image/text data, context variables, technical API data
Google Ireland Limited / Google LLC
Role: service provider or independent controller, depending on the service
Purpose: translation, OCR, cloud/API functions, Android/Google Play services
Data: image/text data, technical data, location/context data, purchase status via Google Play
Apple Distribution International Ltd. / Apple Inc.
Role: app store operator, regularly an independent controller
Purpose: app distribution, in-app purchases, store functions
Data: purchase and store data, device and app information
Google Play / Google Payments
Role: app store and payment service, regularly an independent controller
Purpose: app distribution, in-app purchases, store functions
Data: purchase and store data, device and app information
Hosting and infrastructure providers, e.g. for the website or technical interfaces
Role: processor or independent controller depending on the service
Purpose: website operation, security, log files, infrastructure
Data: IP address, timestamps, technical log data
RevenueCat, Inc.
Role: processor
Purpose: validation of in-app purchases, management of usage passes and entitlements
Data: app user ID, purchase, transaction and receipt data, entitlement/purchase status, device and app information
PostHog
Role: processor
Purpose: product and usage analytics (only with active consent)
Data: event and usage data, pseudonymous identifier, technical device/app data
Sentry (Functional Software, Inc.)
Role: processor
Purpose: crash and error reports as well as masked error session replays (only with active consent)
Data: crash/error data, technical device/app data, masked screen interactions (text and images are masked)
Cloudflare, Inc.
Role: processor
Purpose: operation of our key-holding proxy/API infrastructure and the website (edge delivery, forwarding of requests to the AI and translation services, quota and abuse control, analytics, returning the approximate country to the app for currency suggestions)
Data: IP address, approximate region/country derived from it, technical request data, server-side hashed device/installation ID, request outcome; image/text data passed through transiently (not permanently stored)
Expo (650 Industries, Inc.)
Role: processor
Purpose: delivery of over-the-air app updates (provision of updated app content)
Data: IP address, app/runtime version, platform and device information
Where we engage service providers as processors, we conclude the required contractual agreements. Where providers act as independent controllers, their own privacy policies additionally apply.
For certain features, data may be processed via professional interfaces of AI and cloud providers. Under our current technical concept, this takes place in particular via commercial API offerings of Anthropic and Google as well as the further service providers named in section 8.
Where contractually assured, submitted content is not used to train the providers' general AI models. This statement applies only to the extent of the applicable commercial API terms, data protection agreements and technical settings of the specific services used. Should provider terms or technical settings change, we will review the implications and amend this privacy policy where necessary.
Please note that after transmission to third-party providers, data may be processed on their systems according to their security, abuse-prevention and retention rules, to the extent contractually or legally provided for.
Since individual service providers are located outside Switzerland, the EU or the EEA, or may process data there, international data transfers may occur, in particular to the USA.
Where required, we base such transfers on appropriate safeguards, for example adequacy decisions, the EU-U.S. Data Privacy Framework or Swiss-U.S. Data Privacy Framework, standard contractual clauses of the European Commission, safeguards recognized under Swiss law, or other mechanisms permitted under applicable law.
Despite such safeguards, individual third countries may have a level of data protection different from that in Switzerland or the EU. Where necessary, we assess additional technical, organizational or contractual measures.
We store personal data only for as long as necessary for the stated purposes or as required by legal obligations. The specific retention period depends on the data category and the technical implementation.
Menu images, receipt images and free texts: no permanent storage on our own servers intended; processing is generally transient to execute the respective operation.
Analysis and translation results: generally displayed temporarily in the app; local data may remain on the device until deleted or until the app is uninstalled.
Purchase and entitlement data: stored or processed for as long as necessary to handle usage passes, scan quotas, restoration of purchases, support and abuse prevention.
Technical security and operating logs as well as analytics and operating records on our proxy infrastructure (e.g. server-side hashed device/installation ID, approximate region/country derived from the IP address, request outcome): retained for a maximum of 180 days, then deleted automatically.
Support communication: stored for as long as necessary to handle the inquiry and to document legitimate interests or legal obligations.
Legally relevant records: retained according to the applicable statutory periods, where such obligations exist.
We use appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration or destruction.
Data transmissions are encrypted, for example via TLS, where technically under our control.
Administrative access is restricted to persons who need it for operation, security or support.
By avoiding classic user accounts and permanent storage of menu and receipt images, we reduce certain privacy and security risks.
Absolute security cannot be guaranteed for internet-based services. Security measures are selected on a risk basis and developed further as needed.
Depending on applicable law, you may in particular have the following rights:
Access to the personal data we process about you;
Rectification of inaccurate or incomplete data;
Erasure of personal data, unless statutory retention obligations or overriding interests prevent this;
Restriction of processing;
Objection to certain processing operations;
Data portability, where applicable;
Withdrawal of consent given, with effect for the future;
Lodging a complaint with a competent data protection supervisory authority.
Requests can be sent by email to info@ankerloop.ch. To prevent unauthorized access requests, we may require appropriate proof of identity where legally permissible and necessary.
The competent Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC). Persons in the EU or EEA may also contact the data protection supervisory authority of their place of residence, place of work or the place of the alleged infringement.
You can control various data flows yourself:
Camera and photos: revoke or restrict via the iOS or Android system settings.
Usage and analytics data (including the approximate region derived from the IP address): enable or disable via the privacy/analytics settings in the app. With consent disabled, we do not store any analytics-related geo derivations; the transmission of the IP address technically required to establish the connection cannot be avoided for system reasons.
Dietary preferences: change or delete within the app, where the feature is offered.
Crash and performance data: enable or disable according to the app settings, where this feature is offered.
Local app data: delete via app features, operating system features or by uninstalling the app, where technically available.
TravelTaste is not directed at children under 13 or at persons under the applicable legal minimum age for the independent use of digital services.
We do not knowingly collect personal data from children under 13 without the required consent of a parent or guardian. If parents or guardians suspect that a child has provided us with personal data, they can contact us at info@ankerloop.ch. We will review the matter and delete the data concerned, insofar as it is still technically available and no legal grounds prevent this.
Insofar as the GDPR applies to our data processing, we process personal data only on the basis of a legal basis under Art. 6 GDPR. For health-related information or other special categories of personal data, we rely, where required, on explicit consent or another exception permitted under Art. 9 GDPR.
Since Ankerloop is based in Switzerland, it must be assessed whether a representative pursuant to Art. 27 GDPR must be appointed for certain EU/EEA processing operations or whether a statutory exception applies. Should such a representative be required, this privacy policy will be amended accordingly before publication.
Insofar as US data protection laws, including California privacy rules, apply to TravelTaste, data subjects may have further rights, such as rights to access, deletion, correction or information about data categories and recipients.
We do not sell personal data. Under the current product logic, we also do not share personal data for cross-app behavioral advertising. Should this change, we will provide the required notices and choices.
Requests regarding US or California privacy rights can be sent to info@ankerloop.ch.
We may amend this privacy policy when features, service providers, technical processes, legal bases or legal requirements change. The current version is made available in the app and/or on ankerloop.ch.
In the event of significant changes that materially affect your rights or choices, we will inform you in an appropriate manner, where technically and legally required.
This privacy policy serves to inform you about our data processing. Where consent is required for certain processing operations, we obtain it separately, for example via app settings, operating system permissions or explicit selection fields. Consent, once given, can be withdrawn at any time with effect for the future.
When you actively use the "Share menu" feature, TravelTaste sends a compressed copy of the already translated menu result to our Cloudflare infrastructure and stores it in Cloudflare Workers KV. This is an express exception to the statements above describing scan and translation data as transient.
The shared record may contain restaurant and menu titles, source and target languages, currency, section and dish names, prices, short descriptions, allergens, dietary flags, and compact preparation attributes. It does not contain the original menu images, receipt images, dining-companion names, your personal dietary settings, or a device identifier inside the menu record.
The purpose of this storage is to provide a short link that works across devices and a web preview. The random URL is a bearer link: anyone who receives it, or to whom it is forwarded, can view the menu without an account. Share it only with intended recipients and do not use this feature for confidential content.
Under the current configuration, new shared menus are retained for up to 30 days and are then deleted automatically. On creation, the sending app receives a separate revocation token and uses it to attempt early deletion when the native share sheet is dismissed or fails. The token is not included in the public link or stored alongside the menu.
If you use the "share the app and receive a free scan" feature, we separately store a pseudonymous device or installation identifier and the earned and used bonus status. This claim marker has no automatic expiry because it permanently enforces the one-credit-per-device limit and prevents a spent credit from being granted again. It is not included in the shared link and is retained only while needed for this purpose or operation of the service; your rights under Section 13 remain unaffected.
Cloudflare, Inc. processes this data as our service provider for hosting, retrieval, abuse prevention, and automatic expiry. Share creation and retrieval also produce short-lived hashed IP-based security counters and technical request data. The legal basis is performance of the sharing feature you request and our legitimate interest in secure, abuse-resistant operation. International transfers and data-subject rights are addressed in Sections 10 and 13.
Many restaurants no longer hand out a printed card and instead provide their menu through a QR code at the table. When you scan such a code, TravelTaste may open the restaurant's website behind it in a browser built into the app. This happens only in response to your explicit action.
Once you start a translation on such a page, the page's text content and, where applicable, PDF menus or menu images downloaded from that page are transmitted for processing to the AI service providers named in Sections 8 and 9. This data is treated exactly like a photo you take with the camera: it is processed transiently and is not permanently stored on our servers.
To judge whether a page is a menu at all, a small, low-cost model request may be made. This check does not consume any scan allowance.
When the page is read, content from embedded third-party frames is excluded; only content of the page you actually opened can reach the translation. Downloaded files are size-limited and are removed from your device after processing or after a short period.
No browsing history: We do not collect, store, or analyze which websites you open in the built-in browser. Neither the address nor the hostname of a visited page enters our usage analytics. What is collected — and only where you have actively consented to usage analytics — are event metrics with no page reference, such as the fact that a web-menu view was opened, how many characters of text were found, or the technical reason a download failed.
Please note that the website you open is a third-party website. Its operator is responsible for its own data processing and, as a technical necessity of the request, receives your IP address; cookies or comparable technologies may also be used there. The privacy policy of that website applies to this, not the present one.
Ankerloop KLG · info@ankerloop.ch · ankerloop.ch