YOUR DATA / YOUR RULES
PRIVACY POLICY
LAST UPDATED: JULY 30, 2026
1. The short version
Fat Gym Bro is local-first. Core workout data is stored on your device and the app works without an account. If you choose to sign in, use cloud sync, enable push notifications, purchase Pro, scan a meal, or create a custom avatar, the information needed for those features is sent to the service providers described below.
We do not sell personal information and we do not use your information for cross-app advertising tracking.
2. Information we process
- Account information: email address, account ID and optional display name.
- Fitness information: workouts, exercises, sets, repetitions, weights, streaks, achievements and progress.
- Health information: when you use the Apple Watch app and grant permission, workout duration, active calories and heart-rate summaries.
- Nutrition information: meals, calories, quality ratings and macronutrients.
- Photos: meal photos submitted for AI analysis and optional selfies submitted to create a custom avatar.
- Identifiers: account ID, device-level identifier and push-notification token.
- Purchase information: subscription product, status and entitlement history. We do not receive your full payment-card details.
3. How we use information
We use information only to provide app functionality: authentication, local and cloud data access, cross-device sync, progress and character personalization, push notifications, purchase validation, AI features, fraud prevention, security and customer support. Purchase history may also be used for subscription analytics supplied by RevenueCat.
4. HealthKit and Apple Health
With your permission, the Apple Watch companion can read heart rate and active energy during a workout and save completed workouts to Apple Health. Health data is used only to provide health and fitness functionality. It is not used for advertising, sold, or shared with data brokers. You can change Health permissions in Apple's Health app or system settings.
5. AI photos
Meal photos and optional avatar reference photos are sent through our protected backend to OpenAI for the requested analysis or image generation. We do not add the original meal photo to cloud sync and we do not store the original avatar reference photo in our database. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring unless shorter retention controls apply. API data is not used to train OpenAI models by default.
6. Service providers
- Supabase: authentication, database, file storage and server functions.
- RevenueCat: subscription management, purchase validation and subscription analytics.
- Expo: app updates and push-notification delivery.
- OpenAI: meal-photo analysis and custom-avatar generation.
- Apple: Sign in with Apple, StoreKit, Apple Health and Apple Push Notification services.
7. Retention and security
Local data remains on your device until you delete it, delete the app, or use an in-app deletion option. Account-linked cloud data is retained while your account is active and removed when account deletion completes, subject to limited legal, security and transaction-record obligations. We use access controls, encrypted transport and account-scoped database policies to protect cloud data.
8. Your choices
You can use core features without an account, decline camera, notification or Health permissions, export your data, sign out, and delete your account from the app. See theaccount deletion instructions.
9. Contact
Questions or privacy requests can be sent tosupport@vuvee.me.