Privacy Policy
This policy explains what AI Fitness Coach 360 (the “App”, com.aifc360.app) and the website aifc360.app (the “Site”) collect, why, and what control you have. The data controller is GRIBAN.DEV, trading as Thaliro, Ukraine (see About). Contact: support@aifc360.app.
1. Data we collect
| Category | Examples | Purpose | Leaves your device? |
|---|---|---|---|
| Account | Email address, account identifier, sign-in provider (email or Google) | Sign-in, syncing your data between the App and the Site | Yes, stored on our backend |
| Profile and body data | Age, sex, height, weight, goals, training level | Workout and nutrition plans | Yes, when sync is on |
| Workouts | Exercises, reps, form-quality scores, duration | Progress history, plan adaptation | Yes, when sync is on |
| Nutrition | Meals, calories, macros | Food diary | Yes, when sync is on |
| Camera | Frames during a workout or a food scan | On-device pose detection; food recognition | No for form analysis: frames are processed on the phone and never uploaded. A food photo is sent only when you use the cloud scanner; in on-device mode nothing is sent |
| Microphone | Your voice during a Coach+ live voice session (off unless you turn it on in Settings) | Talking with the live voice coach | Yes: streamed to Google while the session runs, see section 4; we do not store it |
| Health and wearables | Heart rate, HRV, sleep, steps from health platforms or wearables | Recovery scoring, training-intensity recommendations | Only if you connect an integration yourself |
| Purchases | Google Play purchase tokens and product IDs; for web purchases, the Paddle transaction ID, plan and billing status | Unlocking plans and trainer programs | Yes, verified with Google Play or Paddle |
| Usage analytics | Screen views, feature usage, device model, OS version | Fixing bugs, understanding which features are used | Yes, PostHog |
We do not collect your precise location, contacts, SMS, call logs or browsing history. We do not sell personal data and do not share it with data brokers or advertising networks. The Site sets no advertising cookies. It keeps your theme choice in your browser. Only if you choose “Allow analytics” in the banner does it also keep a random anonymous id and your choice there, and send page views and clicks (page address, referrer, language) to PostHog; “No thanks” sends nothing. You can change your mind by clearing the site’s data in your browser.
2. On-device processing
Pose detection (ML Kit) and the on-device AI coach run entirely on your phone. Camera frames used for form analysis are held in memory for the duration of a frame and are never written to disk or transmitted. Strict Offline Mode in Settings → Privacy disables all network sync and third-party integrations.
3. Payments
- In the App, purchases go through Google Play Billing. We never see or store your card number, bank details or billing address; Google sends us only a purchase token to verify your plan.
- On the Site, purchases go through Paddle, our merchant of record. Paddle collects the payment details and billing address under its own privacy policy and sends us the transaction identifier, the plan bought and its status. We do not receive your card number.
4. Who we share data with (processors)
- Supabase (cloud, EU region, Frankfurt): authentication, database and file storage.
- Google Play: purchase verification and licensing.
- Paddle: web checkout, invoicing, refunds and tax handling for purchases on the Site.
- RevenueCat: keeps your plan status in sync between purchases in Google Play and on the Site.
- OpenAI API (primary) and Google Gemini API (backup, used when OpenAI is unavailable): when you use the cloud AI coach, the cloud food scanner or the post-workout form report, we send the text of your question with limited context (recent chat messages, recent workouts and form-error summaries, weekly totals, your goal and level, your nutrition log for the day), the food photo, or the metrics of the set being analysed (joint-angle summaries, rep timing, detected form errors). We never send your name, email, video or camera frames. Under both providers’ API terms this data is not used to train their models; each may keep request logs solely to detect abuse (OpenAI for up to 30 days).
- Google Gemini Live API (Coach+ live voice coaching only, off unless you turn it on in Settings): during a live voice session your phone streams your microphone audio, together with short workout context such as the current exercise, rep count and detected form errors, directly to Google, and Google streams the coach’s spoken reply back. The audio does not pass through our servers and we do not store it. Under Google’s paid API terms it is not used to train Google’s models; Google may keep it for a limited time to detect abuse.
- Open Food Facts: when you scan a barcode, the barcode number is sent to Open Food Facts to look up the product. No photo is sent.
- Hugging Face: when you download an on-device AI model, the model file is fetched from Hugging Face. As with any download, they see your IP address; no personal data, photos or workout data are sent.
- PostHog (cloud, US): product analytics.
- Resend: transactional email (sign-in links, account notices).
- Wearable and health platforms: only the connections you authorise yourself.
Where a processor is outside the EU, transfers rely on the European Commission’s standard contractual clauses or the EU–US Data Privacy Framework.
5. Retention
Account and training data are kept while your account exists. Analytics events are retained for 12 months. When you delete your account, personal data is erased within 30 days, except records we are legally required to keep, such as purchase and invoice records for tax purposes. Deleting the account also cancels an active web subscription.
6. Your rights
Under the GDPR and comparable laws you may access, correct, export, restrict or delete your data, and object to processing. In the App, Settings → Data & Privacy offers Export Data, Delete Local Data and account deletion; Delete your account lists every way to do it. You can also email support@aifc360.app; we answer within 30 days. EU residents may complain to their local data-protection authority.
7. Children
The App and the Site are not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
8. Security
Data travels over HTTPS. Sign-in tokens are stored in the device’s secure storage. Access to data in our database is restricted by row-level security, so an account can read and change only its own records.
9. Health disclaimer
The App provides general fitness information and is not a medical device. It does not diagnose, treat or prevent any condition. Consult a physician before starting a training program.
10. Changes
We update this page and the date at the top when the policy changes. Material changes are announced in the App.