1. Controller and contact details
The data controller is Nicolò Accorsi. For questions, privacy requests, or to exercise your rights, contact support@gredup.app.
GREDUP does not sell personal data and does not use data obtained through Apple or Google Sign-In for advertising or for purposes other than those stated in this policy.
2. GREDUP website
The gredup.it website presents the app and provides legal and support information. It does not contain user accounts, a user database, contact forms, checkout, or profiling tools.
When you visit the website, the server and hosting provider may process technical data normally required to deliver and protect a web page, such as IP address, date and time, requested URL, user agent, request outcome, and security information.
The website uses one functional cookie, gredup-locale, when you explicitly select a language. It remembers your preference for 12 months, has the SameSite=Lax attribute, and is not used for advertising or analytics.
The website is delivered through Cloudflare infrastructure. Cloudflare may process technical connection data needed to provide, secure, and maintain the reliability of the service under its applicable terms and configurations.
3. GREDUP app: data processed
GREDUP is a fitness and wellness app intended only for people aged 18 or over. Most user content is stored on the device and is not automatically uploaded to a GREDUP cloud repository.
Some information, especially weight, nutrition, sleep, recovery, and free-text notes, may describe health-related aspects or allow inferences about wellbeing. GREDUP uses it only to provide the features requested by the user, not for diagnosis, advertising, or the sale of profiles.
Account and sign-in
- email address, verification status, and sign-in method;
- name or nickname selected by the user;
- technical Supabase account identifier;
- technical creation and last sign-in dates;
- tokens and session data needed to keep you signed in; a new GREDUP login revokes the account’s previous reusable sessions.
Fitness data and local content
- fitness profile, including age, height, biological sex, activity level, experience, preferences, goals, and measurement units;
- routines, custom exercises, sets, loads, repetitions, timers, notes, history, and collections;
- meals, foods, calories, macros, nutrition goals, hydration, barcodes, optional meal photos, favourites, and recent searches;
- weight measurements and trends, targets, reminders, sleep/recovery data, and related preferences;
- workout-plan or workout photos, voice memos, and transcripts when the user chooses assisted features;
- Journey and Performance data and results, periodic reviews, proposals, inferences, and user decisions;
- app settings, language, haptic feedback, and workout tool configurations.
Technical data
- app version and build, operating system, device type, language, and time zone;
- usage events permitted by telemetry, technical outcomes, and sanitised error codes;
- metadata about backend feature requests, such as feature, model, tokens, estimated cost, latency, and status;
- purchase status, product, renewal, entitlement, and related technical metadata;
- the Supabase session identifier used by remote functions to reject a previously revoked session; no hardware fingerprint is created.
HealthKit Sleep
If you authorise it, GREDUP reads only Apple HealthKit Sleep Analysis samples to display sleep and recovery. Access is read-only: GREDUP does not write HealthKit data. Samples remain in the device's local vault, are not sold or used for advertising, and are not sent to PostHog, AI features, or Edge Functions. You can revoke future reads in iOS Health settings; copies already imported remain local until you delete the account or remove the app data from the device.
4. Local storage and backups
Routines, sessions, nutrition, hydration, weight, recovery, preferences, and Journey data are stored mainly with AsyncStorage in the device's application space. The operating system sandbox and protections restrict access by other apps, but the code does not describe these fitness archives as a separately encrypted database.
The Supabase Auth session is handled differently: it is encrypted locally with AES-256-GCM. The master key is stored in the device SecureStore with access limited to the unlocked device and is not included in the portable backup file.
From Settings → Data and backup, you can export a JSON file verified by checksum. The file may include fitness profile, goals, workouts, weight, nutrition, recovery, and Journey data, but the format intentionally excludes email addresses, account IDs, tokens, and passwords. The file is created in the cache for sharing and then handled at the destination chosen by the user. An exported copy remains under the user's control and cannot be removed by GREDUP when the account is deleted.
5. Apple, Google, and external authentication
If you choose Continue with Google, the app requests only the openid, email, and profile scopes. GREDUP receives an ID token to verify your identity; the application code uses the unique account identifier, email address, email verification status, and display name. It does not use Gmail, files, contacts, calendars, or the profile photo as app content.
This data is used only to authenticate you, create or link your GREDUP account, display the account email address, and suggest a display name. The ID token is exchanged with Supabase Auth to create a GREDUP session; it is not used as fitness content or for advertising analytics.
Supabase Auth stores the account identifier, email address, provider used, and profile metadata relevant to authentication in order to manage the GREDUP account. On the device, the resulting session is stored in encrypted form as described above.
We do not sell Google data, share it for advertising, or use it for undisclosed purposes. GREDUP does not request access to Gmail, Drive, Calendar, Contacts, or any other Google service and cannot read their content. If additional scopes are requested in the future, this policy and the Google consent flow will be updated before they are enabled.
If you choose Continue with Apple, Apple confirms your identity and provides Supabase Auth with the authentication data required; name and email are available subject to the user's choices and Apple's rules. Apple and Google independently manage their own accounts, logs, and retention periods: deleting a GREDUP account does not delete the account held by either provider.
6. Supabase Auth and transactional email
Supabase provides authentication, account management, email verification, sessions, and backend functions. For email/password registration, OTP, password recovery, email changes, and account-related transactional messages, Supabase Auth uses Brevo as the email delivery provider configured by the controller.
Brevo receives the email address, the technical content of the message, and delivery metadata such as date, sending status, delivery, or error. In the verified Production configuration, delivery logs are retained for one month and content preview is disabled. GREDUP does not use this data for newsletters or marketing unless separate consent is introduced in the future; no such consent is currently present on the website or in the app described by this policy.
7. Edge Functions and AI features
Features requiring remote processing are invoked through Supabase Edge Functions with an authenticated session. The user chooses whether to use them and, where provided by the interface, sees or confirms the result before it becomes part of the data saved in the app.
The Edge Functions send OpenRouter only the content necessary for processing. OpenRouter may dynamically route a request to providers available for the model and feature: the verified routing can reach Mistral AI for transcription and OpenAI, including through Azure OpenAI or Amazon Bedrock, for other generations. The actual provider may change with availability and routing. Retention terms depend on the model, underlying provider, and applicable configuration; GREDUP does not promise universal absence of retention or logging.
In the verified code, original photo and audio files are used for the request and are not written to GREDUP application tables. Technical usage metadata and, for some features, validated results required for limits, idempotency, continuity, and cost control may remain. The providers involved may process inputs and outputs under their respective agreements and settings.
Before the first covered sharing, the app shows the data categories needed and identifies GREDUP, OpenRouter, and third-party AI providers. Transmission requires explicit permission through a positive choice recorded for the account. You can revoke permission through Profile → Data sharing with AI providers; revocation blocks new covered transmissions but cannot recall data already sent. This permission required by Apple's rules is separate from GDPR legal bases and any Article 9 condition.
Content sent when you choose to use the feature
- Meal photo: compressed image of the meal and app language;
- Workout plan from photos: up to six JPEG images of the plan and app language;
- Voice workout: audio recording, format, duration, and the subsequently confirmed transcript;
- Journey and reviews: structured, minimised context derived from relevant period data when remote generation is requested.
- Relevant context: workout, nutrition, weight, goal, and Journey data only where required by the feature; HealthKit samples are not included.
8. PostHog EU: product analytics
PostHog EU is used for product analytics in builds configured with the https://eu.i.posthog.com host. The processing relies on Article 6(1)(f) GDPR: GREDUP’s legitimate interest in understanding onboarding, activation, funnels, and feature use in order to improve the product and its reliability.
PostHog receives only events and properties included in a closed, minimized allowlist, such as a step identifier and position, onboarding variant, placement, feature identifier, technical outcome, app version, platform and, where already required, a pseudonymous internal user ID. PostHog does not receive weight, workout or personal exercise details, loads, repetitions, nutrition or meal data, calories, macros, sleep, recovery, HealthKit data, notes, free text, photos, audio, transcripts, AI content, email addresses, or names.
This data is used for no advertising, advertising profiling, or cross-app tracking. Automatic lifecycle capture, session replay, automatic error tracking, surveys, IP geolocation, and push-notification capture are disabled. Demo, Test Profile, and Developer fixture activity remains local and does not enter production analytics.
Usage analytics is enabled by default. You can exercise your right to object and stop new transmissions at any time through Avatar → Settings → Usage analytics. The choice is stored on the device and can be changed at any time; events already queued or in transmission cannot be recalled. You may also contact support@gredup.app to exercise your rights.
The workspace shows a 12-month event retention value, but automatic enforcement of that value is not enabled. GREDUP therefore does not describe 12 months as guaranteed automatic deletion and applies the criteria set out in the Retention section.
On sign-out or account change, GREDUP resets the analytics identity and reapplies the collection state appropriate to the current context, without associating events across accounts.
10. Food catalogues and search
OpenNutrition is used as a local dataset bundled with the app, not as a remote data-processing provider. Browsing this catalogue does not send data to OpenNutrition and does not require sending food diary data. GREDUP also includes data attributed to Open Food Facts.
When you search online for a packaged food or scan a barcode, the search text or barcode may be sent to Open Food Facts. If no sufficient result exists, GREDUP does not start an AI search and lets you enter the product manually. The complete food diary or fitness profile is not automatically sent for this search.
11. Purposes and legal bases
Providing the requested service
We process account and authentication data, entered data, workout, nutrition, weight, Journey/Performance features, user-selected HealthKit synchronisation, requested AI features, and Premium status to perform the agreement with the user and provide the selected features (Article 6(1)(b) GDPR). Required account data is necessary to create an account; other categories depend on the features used.
Security and product improvement
We process minimised technical logs, current-session verification, Premium status, purchase transfer, abuse prevention, quotas, security, reliability, and configured product analytics on the basis of the legitimate interest in protecting and understanding GREDUP (Article 6(1)(f) GDPR), balanced through minimisation, pseudonymous identifiers, allowlists, and the right to object.
Legal obligations and special-category data
We may process information strictly required for specific legal obligations (Article 6(1)(c) GDPR) or to establish, exercise, or defend legal claims under the applicable basis. Fitness, nutrition, weight, sleep, and related inferences may qualify as health data depending on their content and context. The app neither assumes that every fitness data point is always special-category data nor that it can never be so. Classification and any Article 9 condition require professional confirmation; the positive choice required before sharing with AI providers is not presented as an automatic GDPR legal basis.
Decisions and inferences
Journey, Performance, and AI outputs provide analyses, estimates, or proposals under the user's control. GREDUP does not use this data for solely automated decisions that produce legal or similarly significant effects on the user.
12. Retention periods and criteria
- Website language cookie: 12 months from the latest explicit choice.
- Cloudflare website technical logs: 3 days in the verified configuration.
- Local app data: while needed by the user, until deleted in the app or account deletion occurs; system copies or external backups depend on the device and the user's choices.
- Food search cache: online queries are stored locally for about 24 hours; retrieved products may remain in the local cache for about 30 days.
- Supabase account and linked metadata: for the life of the account, except for additional periods required for legal obligations, security, or dispute management.
- Backend feature metadata and technical results: for as long as needed for quotas, idempotency, security, continuity, and cost control; inventoried user-owned records are deleted by the account deletion procedure. Original temporary photo and audio files are removed from the local flow after use and are not stored in GREDUP tables.
- Brevo transactional email: delivery logs for one month in the verified configuration, with content preview disabled.
- PostHog: the workspace shows 12 months, but event-retention enforcement is not enabled; automatic deletion at the end of 12 months is not promised.
- OpenRouter, Mistral AI, and other underlying AI providers: according to the request, configuration, and applicable policies/terms; universal absence of retention is not guaranteed.
- Pseudonymous deletion receipt: technical expiry after 30 days.
- Account, Auth, purchase, and provider data held by Supabase, Apple, Google, and RevenueCat: for the duration and purposes of the relevant service and under applicable agreements, obligations, and policies; GREDUP does not control internal Apple or Google account retention.
13. Recipients and international transfers
Data is shared only when necessary with providers supporting the service: Cloudflare for the website; Supabase for Auth, the technical database, and Edge Functions; Brevo for transactional email; Apple and Google for user-selected authentication; Apple/StoreKit and RevenueCat for purchases and entitlements; PostHog EU for minimised analytics; Open Food Facts for search and barcodes; and OpenRouter with reachable underlying AI providers, including Mistral AI, OpenAI, Azure OpenAI, and Amazon Bedrock, for selected features. AI routing can vary, and not every provider receives every request.
The verified Supabase database is in the Stockholm (EU) region, while Edge Functions may run dynamically near the caller. Some providers or subprocessors may operate outside the European Economic Area. Where documented and applicable, the providers' DPA, Standard Contractual Clauses, or an adequacy decision support the transfer. This is not a guarantee that every processing operation remains in the EEA; updated information can be requested through the privacy contact.
GREDUP may also disclose data where required by law or necessary to protect rights, security, and service integrity. It does not sell personal data.
14. Security
GREDUP applies measures proportionate to the risks: device sandboxing, authenticated session encryption, a SecureStore key, JWT authentication for Edge Functions, authorisation controls, RLS on technical tables, size and frequency limits, error sanitisation, analytics allowlists, and remote-first deletion.
No system is risk-free. Protect your device, use strong credentials, do not share OTPs, and keep the app and operating system up to date. Use the contact details above to report a security or privacy issue.
15. GDPR rights
Where applicable, you may request access, rectification, erasure, restriction, portability, and object to processing. You may also withdraw consent without affecting prior processing and lodge a complaint with the Italian Data Protection Authority or your competent supervisory authority. Contact support@gredup.app; we may request reasonable information to confirm that the request relates to your account.
The app also offers direct tools to change your name and email, opt out of usage analytics, revoke AI-provider sharing permission, export a backup, and delete an account. Apple and Google deletion flows require renewed provider identity confirmation and revoke applicable access before remote-first deletion. Other rights that are not automated can be requested through support.
16. Account deletion
Follow Home → profile in the top right → Profile → Account → Delete account. An email/password account uses the current authenticated session; an Apple or Google account requires renewed provider confirmation and applicable access revocation. GREDUP then deletes inventoried user-owned remote artefacts and the Supabase Auth user, followed by the Personal vault and Personal keys on the device.
Deleting the GREDUP account does not automatically cancel an Apple subscription. Before deletion, the app warns the user and provides a link to manage the subscription; alternatively, Premium can later be transferred to a new GREDUP account through Restore purchases.
For details, reauthentication or revocation problems, data excluded from the purge, and previously exported backups, see the Account deletion page.
17. Changes to this policy
We will update this policy when features, providers, legal bases, or applicable requirements change. The date at the top shows the latest revision. For material changes, we will provide a notice on the website or in the app where appropriate.
Have a question?
Contact support about accounts, privacy, purchases, or deletion.
support@gredup.app