EN RO

Privacy Policy

Last updated: September 21, 2026

Version 1.7.1

Both the English and Romanian versions of this Policy are authentic. In case of inconsistency, the Romanian version prevails for users whose primary interface language is Romanian.

In Brief

This summary is provided under GDPR Article 12(1) to make the detail that follows easier to navigate. It does not replace the full Policy below, which is what governs.

1. A Note About Health-Related Data

FormChase collects data that may qualify as "data concerning health" within the meaning of Articles 4(15) and 9 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").

This includes body measurements (weight, body fat percentage, BMI) and fitness or nutrition records linked to health-related goals (such as losing or gaining weight).

We process body data and Apple Health data only with your explicit consent (GDPR Article 9(2)(a)). This consent is separate from accepting the Terms, is optional, and is not needed to create an account or to log workouts and meals. We ask for it on its own screen, per category, the first time it is needed:

Until you give a consent, the related feature stays locked and we collect nothing for that category. You can give or withdraw your body data and Apple Health consents at any time in More → Legal & Privacy → Health data, and your coach sharing choices in More → Legal & Privacy → Data shared with your coach. To withdraw your consent for questionnaire answers, email contact@formchase.com and we will delete them. Withdrawing consent does not affect the lawfulness of processing before withdrawal. When you withdraw your body data or Apple Health consent, we stop collecting and syncing that category straight away and offer to delete its existing data at the same time. If you choose deletion, the data is deleted straight away and drops out of our encrypted backups within 14 days at most. If you choose to keep it, it stays in your account and you can delete it at any time; kept body data is no longer visible to any Professional User, and other kept data stays visible to a Professional User only in the categories you have chosen to share with them.

To meet our demonstrability obligation under GDPR Article 7(1), we record each consent grant and withdrawal (including timestamp and the scope of what was consented to) in our systems.

FormChase is a SaaS software service, not a healthcare provider, clinic, dietetic practice, medical device, or regulated health app. It does not provide medical diagnoses, treatment, medical nutrition therapy, or professional credential verification, and it does not replace professional medical or nutritional advice. The data you enter is for your personal fitness and nutrition tracking and for software features you choose to use. See our Terms and Conditions (Section 3) for important disclaimers.

2. What Data We Collect

2.1 Account Data

2.2 Authentication Data

Depending on your sign-in method:

We receive only the identifiers and email provided by Apple or Google during authentication. We do not receive your Apple ID password or Google account password.

2.3 Fitness and Workout Data

2.4 Nutrition Data

2.5 Body and Health Measurements

2.6 Apple Health Data (Optional)

If you enable Apple Health integration, we may read the following data types, only with your explicit per-type permission:

With your permission we also write to Apple Health the workouts, food and water entries, and body weight, body fat and lean body mass measurements that you log in FormChase, so your other health apps stay up to date.

If you use the FormChase Apple Watch app, your heart rate and active calories are shown on the watch during a workout and the finished workout is saved to Apple Health. Heart rate readings are not sent to our servers.

Apple Health data is:

You can disconnect Apple Health at any time in More → Activity Sync. Disconnect stops future syncing and keeps the data already synced; Disconnect & delete data also deletes from FormChase the data synced from Apple Health (data in the Health app is not affected), while keeping the data you entered yourself. You can also change FormChase's access to each data type in the Health app on your iPhone.

2.7 Professional User – Client Shared Data

If you are a Client of a Professional User (e.g., a trainer or nutritionist), they can see only the categories you choose to share. You choose them when you accept their invitation; if you have not chosen yet, the choice appears when you open My Trainer. All categories start off:

Body measurements reach the Professional User only if you have also given your body data consent (Section 1). Meal plans they assign to you are their own content and are not part of this choice. You can change your choices at any time in More → Legal & Privacy → Data shared with your coach. Every choice is kept as a dated consent record, together with its history.

What your Professional User never sees: your email address, your password or sign-in identifiers, your subscription and billing records, your security and audit logs (Section 2.18), your feedback and bug reports, and any category you have not chosen to share. Turning a category off, or ending the connection, removes their access to it immediately.

2.8 Subscription and Billing Data

We do NOT store your full payment card details. Payments are processed by Apple or Google through their respective app stores.

2.9 Technical and Diagnostic Data

2.10 Product Analytics Data (Optional, Off by Default)

If you opt in to product analytics, we collect:

We do NOT collect through analytics:

Analytics data is processed on EU servers by our analytics provider. It is never used for advertising, your IP address is stripped before transmission, and analytics is off by default until you opt in.

2.11 Photos and Document Scans

FormChase only accesses the photos you choose or take. It does not scan your photo library.

Nutrition labels. If you use the food label scanning feature, photos of food labels are sent to Google Cloud Vision API through our backend for text extraction. We send only the image; no account identifiers are attached to the request to Google. Google's processing is governed by the Google Cloud Data Processing Addendum and Google's AI/ML Privacy Commitment, under which submitted content is not used to train Google's models. The extracted text is returned to our backend and used to populate your food entry.

Training and meal plan documents (Professional Users). If you import a program or meal plan from a photo or image, the iOS and Android apps send that image to Google Cloud Vision API in the same way, and the extracted text is used to prepare an import draft for you to review. On the web, the text is extracted in your browser and the image is not uploaded. Please avoid importing documents that contain other people's personal data you do not need.

Recipe photos and business logos (Professional Users). A photo you add to a recipe, and the logo you add in brand settings, are stored in our file storage and served through a public link, because they are shown to your clients and on recipe share links. Please avoid uploading images that show other people or personal information. They are deleted when you remove them or delete your account.

2.12 Push Notification Tokens

If you enable push notifications, we store a device push token to deliver workout reminders, meal reminders, and account-related notifications (e.g., new messages from your trainer, subscription updates). Push tokens are transmitted through Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and the Expo push service which routes the request to APNs/FCM.

You can revoke push permissions at any time through your device's system settings. Revoking the permission stops all further notifications from FormChase.

A notification tells you that something happened, and in some cases who did it (for example, that your trainer assigned you a meal plan). It never carries the content of a message, a meal log, a measurement, or any other health data, so that data is not exposed on your lock screen or to the services that route the notification (Section 4.12).

2.13 Questionnaire and Intake Responses

If your Professional User (trainer or nutritionist) sends you a questionnaire, we store the answers you choose to give. Built-in questionnaire templates include health-related questions (such as medical conditions, medications, injuries, or pregnancy), so your responses may include health data, which we process only with your explicit consent (GDPR Art. 9(2)(a)). Your responses are visible only to you and the Professional User who sent the questionnaire. We ask for this consent before you send your answers. You cannot yet delete answers in the app: to withdraw your consent, email contact@formchase.com and we will delete them.

2.14 Messages With Your Trainer or Clients

If you use the in-app messaging feature, we store the content of the messages you exchange with your trainer or your clients, together with delivery metadata (timestamps, read status), solely to deliver the messaging feature. Messages are visible only to the participants in the conversation.

2.15 Feedback and Bug Reports

If the app hits an unexpected error, you can choose to send us a short description of what happened. We process the text you write, together with the technical diagnostic report for that error (see Section 4.5), so we can find and fix the problem. Sending a report is optional and you write it yourself, so please do not include sensitive personal details in it.

2.16 Device Calendar (Optional)

If you choose to add a training session or workout to your calendar, FormChase creates the event in your device calendar with your permission. We store only the identifier of each event FormChase creates, so we can update or remove it if the session changes.

Professional Users can also choose calendars to show next to their coaching schedule. Events from those calendars are read and displayed on your device only; they are never uploaded to our servers or shared with anyone, and your choice of calendars is stored on your device. You can turn this off in the schedule screen or revoke calendar access in your device settings at any time.

2.17 Shared Shopping Lists

If you share a shopping list, people who open your link (valid for 7 days) and join the list can see and edit that list's items until you delete the list or they leave it. They do not see any of your other data.

2.18 Security and Audit Logs

We record security-relevant and sensitive account events, so that we can detect fraud, prevent abuse, and show that a change to an account was authorised. Each entry holds:

These logs are readable only by our server, never by other users or by a Professional User, and are deleted automatically after at most 12 months (Section 6). They are not included in the self-service export, because releasing fraud-detection records on demand would undermine them; you can obtain the entries about you through a formal data rights request (Section 7.9). We separately keep a record of each data export you run and each role change on your account, and both of those are in your export.

3. Why We Process Your Data and Our Legal Bases

Data Category Purpose Legal Basis (GDPR)
Account data Create and manage your account, provide the Service Art. 6(1)(b): contract performance
Authentication data Verify your identity, secure your account Art. 6(1)(b): contract performance
Fitness/workout data Provide core workout tracking features Art. 6(1)(b): contract performance
Nutrition data Provide core nutrition tracking features Art. 6(1)(b): contract performance
Body/health measurements Display your progress, calculate targets Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for health data
Apple Health data Sync health data at your request Art. 6(1)(a) + Art. 9(2)(a): explicit consent
Professional User – Client shared data Enable Professional User features Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent from the Client
Billing data Process subscriptions, comply with fiscal law Art. 6(1)(b): contract + Art. 6(1)(c): legal obligation
Analytics data Improve the Service (if you opt in) Art. 6(1)(a): consent
Error reports Diagnose and fix technical issues Art. 6(1)(f): legitimate interest (service reliability)
Security logs Detect fraud, prevent abuse Art. 6(1)(f): legitimate interest (security)
Food label photos and imported document images (OCR) Extract nutritional information; prepare program and meal plan import drafts Art. 6(1)(b): contract performance
Recipe photos and business logos Show your recipes and brand to your clients Art. 6(1)(b): contract performance
Identifiers of calendar events FormChase creates Update or remove the event when a session changes Art. 6(1)(b): contract performance
Push notification tokens Deliver workout/meal reminders and account notifications Art. 6(1)(b): contract performance (service reminders); Art. 6(1)(a): consent (any optional notification of a promotional nature)
Questionnaire and intake responses Deliver trainer questionnaires you choose to answer Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for any health data in your answers
Messages with your trainer/clients Deliver the in-app messaging feature Art. 6(1)(b): contract performance
Shared shopping lists Share a shopping list with the people you choose Art. 6(1)(b): contract performance
Referral codes and attribution Credit the referrer if you sign up via a referral link or participate in the trainer referral programme Art. 6(1)(f): legitimate interest (operating the referral programme)

The legitimate interests we rely on, and how we balanced them. Where the table above cites Article 6(1)(f), the interest is keeping the Service reliable and secure, and the balancing test is set out here as required by Article 13(1)(d). For error reports, we strip your email address, IP address, authentication tokens and body measurement values before transmission, so what remains is technical. For security and audit logs, the entries are server-only, kept for at most 12 months, and never used to profile you or to make decisions about you. For referral attribution, we record only the code and the transaction amount needed to calculate a commission. In each case the processing is limited to what the purpose needs, is not used for advertising or profiling, and you can object to it at any time under Section 7.6.

Information required by GDPR Article 13(2)(e). Providing your email address and basic account data is a contractual requirement: we cannot create or operate an account without them. Consent for health data is optional; if you refuse or withdraw it, the only consequence is that the related features (body measurements, health integrations, sharing data with your trainer) will not be available. Consent for product analytics is entirely optional, and refusing it has no impact whatsoever on the Service.

Purchase records. Apple and Google maintain the payment records for purchases through their stores (see Terms §8). We store the subscription status (plan, expiry, store identifier) returned by RevenueCat and, for the referral programme only, the gross transaction amount used to calculate the commission, covered by the "Billing data" and "Referral codes and attribution" rows of the table above. FormChase does not receive or store card details.

4. Who We Share Your Data With

We do not sell your personal data.

We share data only with the recipients below. Those acting as our processors handle data under data processing agreements. Apple and Google (for store billing), Open Food Facts, YouTube, Vimeo and Professional Users receive data as independent controllers, and their own privacy policies govern their processing.

4.1 Supabase: Cloud Database, Authentication, and File Storage

4.2 RevenueCat: Subscription Management

4.3 Apple & Google: App Store and Google Play Billing

4.4 PostHog EU: Product Analytics (Only If You Opt In)

4.5 Sentry: Error Monitoring (Production Only)

4.6 Resend: Transactional Email

4.6b Mailjet: Transactional Email (Overflow Only)

4.7 Google Cloud Vision API: Image Recognition (OCR)

4.8 Cloudflare: CDN, Web Security, Legal & Marketing Site Hosting, Backups

4.9 Open Food Facts: Open Food Database

4.10 Professional Users (Trainers/Nutritionists): Independent Controllers

If you are a Client and grant consent, your Professional User (a trainer or nutritionist) may view specific categories of your data (see Section 2.7). In this relationship:

4.10b Records About People Without a FormChase Account (GDPR Article 14 Notice)

Professional Users can store records inside the Service about clients who do not have a FormChase account, for example imported client lists (name, email, notes), goals, injuries, body measurements, progress notes, logged training sessions, meal-plan share links, and invitations. Injuries and measurements are health data. For that data:

4.11 Google Gemini: Food-Data Text Processing

4.12 Expo: Push-Notification Delivery and App Updates

4.13 YouTube and Vimeo: Trainer-Attached Exercise Videos

Professional Users can attach YouTube or Vimeo videos to exercises. When you open such a video, or when its thumbnail is loaded, your device connects directly to that platform, which receives your device's IP address and applies its own privacy policy (Google/YouTube, Vimeo). FormChase does not send any account data to these platforms.

4.14 Infrastructure Endpoints

The app performs technical availability checks (network connectivity probes and requests to our status-page host). These requests expose only your device's IP address and standard request metadata; no account identifiers are attached.

5. International Data Transfers

Your data is primarily stored in the EU.

Some processors are located in the United States. For these transfers, we rely on:

You can obtain a copy of the relevant transfer safeguards (for example, the Standard Contractual Clauses) by writing to contact@formchase.com.

Our direction of travel. FormChase is built for the Romanian market and governed by Romanian and EU law. We prefer processors that store and process data inside the EU, and we already use EU regions or EU-based providers for the database, product analytics, error monitoring and the food database. Where we still rely on a provider outside the EU, we keep to the minimum data the purpose needs, and we review those choices as EU alternatives become viable. If we move a processor into the EU, we will update the list in Section 4 accordingly.

6. How Long We Keep Your Data

Data Retention Period
Account and profile data Until you delete your account; deleted immediately upon confirmed deletion
Fitness, nutrition, and measurement data Until account deletion, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion
Apple Health synced data Until account deletion, until you manually delete it, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion
Questionnaire and intake responses Until you ask us to delete them (by emailing contact@formchase.com) or you delete your account
Messages with your trainer/clients Until account deletion, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion
Feedback and bug reports Up to 90 days (linked to the diagnostic error record)
Subscription status (plan, expiry, store identifier) As long as the subscription is active; deleted immediately upon confirmed account deletion
Error/diagnostic logs 90 days
Analytics events (if opted in) 90 days in our own database; up to 12 months at PostHog EU (the retention period of our PostHog plan), then deleted automatically. When you delete your account, we also ask PostHog to delete the events linked to your account ID.
Push notification tokens Until you disable push notifications or delete your account
Recipe photos and business logos Until you remove them or delete your account; deleted immediately upon confirmed deletion
Images sent for text extraction (OCR) The image is not stored. A usage record without the image (time, result quality and a one-way fingerprint of the image) is kept for 30 days for rate limiting
Security and audit logs Up to 12 months at most; reviewed periodically and deleted or anonymised when no longer needed
Consent and legal acceptance records After account deletion, kept in pseudonymised form (identifiers hashed with a secret key, what was accepted, version and date) for 3 years as evidence of lawful processing, then deleted
Training sessions a Professional User logged with you If you delete your account, the sessions stay with that Professional User, without your name, contact details, notes or health data
Public library contributions Retained in anonymised form after account deletion
Data rights request records 3 years after resolution (legal evidence)
Database backups Created every 6 hours, encrypted (AES-256) and kept for at most 14 days in a private Cloudflare R2 bucket restricted to the EU jurisdiction; Supabase also keeps its own daily backups for 7 days in the same EU region. Deleted data drops out of backups within 14 days at most

Dormant accounts. We do not keep your data indefinitely just because you stop using FormChase. If you do not sign in for 3 years, we delete the account and its personal data, so that nothing is kept for longer than it is needed (GDPR Article 5(1)(e)). We warn you first, by email to your account address, about 60 days and again about 30 days before the deletion date, and simply signing in once stops the process and resets the clock. If you never signed in at all, the 3 years run from the day the account was created. The deletion is the same one described on the Delete Account page, so the same limited records survive it: pseudonymised consent evidence, and the training sessions a coach logged, stripped of anything identifying you.

Account deletion is immediate and cannot be cancelled once confirmed. Upon deletion, your personal data is permanently deleted or anonymised, except where retention is required by law or specified above; deleted data drops out of backups within 14 days at most. See the Delete Account page for full details.

If we permanently discontinue the Service (Terms of Service, Section 16.4), remaining account data is deleted within at most 90 days of the shutdown date, subject to the limited legal retention described above.

7. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

7.1 Right of Access (Art. 15)

Request a copy of the personal data we hold about you. You can do this in-app (More → Legal & Privacy → Data Rights → Export My Data) or by contacting us.

7.2 Right to Rectification (Art. 16)

Correct inaccurate or incomplete data. Most data can be corrected directly in the app. For other corrections, contact us.

7.3 Right to Erasure (Art. 17)

Request deletion of your personal data. Use the in-app account deletion feature (More → Legal & Privacy → Danger Zone → Delete Account & Data) or contact us. Deletion is immediate and cannot be cancelled once confirmed. If you were a client of a Professional User, your identity and health data are removed from their records too; training sessions they logged stay with that Professional User, without your name, contact details, notes or health data. We keep a limited set of records only in the cases and for the periods in Section 6: where the law requires it, for the establishment, exercise or defence of legal claims (for example, consent evidence, in pseudonymised form, for 3 years), and the training sessions described above (see also the Delete Account page).

7.4 Right to Restrict Processing (Art. 18)

Request restriction of processing in certain circumstances (e.g., while we verify the accuracy of contested data).

7.5 Right to Data Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format (JSON). Available in-app via the Export feature.

7.6 Right to Object (Art. 21)

Object to processing based on legitimate interests (error reporting, security). We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for the establishment, exercise or defence of legal claims.

7.7 Right to Withdraw Consent (Art. 7)

Where we process data based on your consent (analytics, body data, Apple Health, questionnaire answers that contain health data, data sharing with Professional Users), you can withdraw consent at any time. In the app, go to More → Legal & Privacy: for analytics, Consent Preferences; for body data and Apple Health, Health data; for coach sharing, Data shared with your coach. For questionnaire answers, email contact@formchase.com and we will delete them. Withdrawal does not affect processing that occurred before withdrawal.

7.8 Profiling and Automated Decision-Making (Art. 22)

To provide coaching features, FormChase analyses your logged health, nutrition and activity data to generate insights such as nutrition-adherence scores, progress trends and coaching signals. Where you have linked a Professional User (trainer), these insights are also shown to them, subject to your consent. This analysis is profiling within the meaning of Art. 4(4) GDPR. These insights support human coaching and your own decisions; FormChase does not make solely automated decisions that produce legal or similarly significant effects on you (Art. 22). Calorie and macro calculations are informational estimates. You can object to this profiling at any time (see your right to object above) or, where it relies on your consent, withdraw that consent.

7.9 How to Exercise Your Rights

We will respond without undue delay and in any event within one month of receipt of your request, as required by GDPR Article 12(3). That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you of the extension and the reasons within one month of receipt.

7.10 Right to Complain

You have the right to lodge a complaint with:

ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1

București 010336, România

Website: dataprotection.ro

Or with the supervisory authority in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

No system is perfectly secure. If we discover a personal data breach, we will notify ANSPDCP within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay and in clear and plain language, as required by GDPR Article 34, describing the nature of the breach, the likely consequences, the measures taken to mitigate it, and a contact point for further information.

9. Children

FormChase is not intended for children under 16. Under Article 8(1) GDPR, where processing is based on consent, a child's data in connection with information society services may be processed on the child's own consent only from the age of 16; Member States may set a lower age by law, not below 13, but Romania has not done so. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, contact us at contact@formchase.com and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes at least 30 days before they take effect, through in-app notification and/or email, matching the notice period in our Terms (Section 17). A change is material if it introduces a new purpose, a new category of recipient, or a change of legal basis. Where a change requires your consent, we will ask for it again rather than rely on the old consent, and the related feature stays locked until you give it. The "Last updated" date at the top reflects the most recent revision.

11. Data Controller

The data controller responsible for processing your personal data is:

COCOȘ DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ

CUI: 54218790

Trade Register: F2026013034001

EUID: ROONRC.F2026013034001

Registered professional address: B-dul Bucureștii Noi nr. 136, et. parter, ap. 5, Sector 1, București, România

Telephone: +40 750 451 098

Email: contact@formchase.com

We process your data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation), Romanian Law no. 190/2018 on measures implementing Regulation (EU) 2016/679, Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, and other applicable data protection legislation.

At our current scale, we are not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy inquiries, contact us at contact@formchase.com. We will reassess this obligation as we grow.

12. Contact

For questions about this Privacy Policy or to exercise your data rights:

Email: contact@formchase.com

Earlier versions. Each version of this Policy carries its own version number and effective date, and we record which version you accepted and when. If you want to read a version you accepted in the past, ask us at contact@formchase.com and we will send you a copy.