Privacy Policy
Last updated: September 21, 2026
Version 1.7.1
Both the English and Romanian versions of this Policy are authentic. In case of inconsistency, the Romanian version prevails for users whose primary interface language is Romanian.
In Brief
- We do not sell your data, show you adverts, or run advertising or cross-app tracking of any kind.
- Product analytics are off by default and start only if you turn them on; this legal site sets no cookies at all.
- Health data needs your explicit consent, asked per category the first time it is needed, and you can withdraw it at any time.
- Your coach sees only the categories you choose, and never your email, password, subscription records or security logs.
- Your data is stored in the EU. The few processors outside it are covered by the safeguards in Section 5.
- You can export everything and delete your account from inside the app, on any plan, free of charge.
This summary is provided under GDPR Article 12(1) to make the detail that follows easier to navigate. It does not replace the full Policy below, which is what governs.
1. A Note About Health-Related Data
This includes body measurements (weight, body fat percentage, BMI) and fitness or nutrition records linked to health-related goals (such as losing or gaining weight).
We process body data and Apple Health data only with your explicit consent (GDPR Article 9(2)(a)). This consent is separate from accepting the Terms, is optional, and is not needed to create an account or to log workouts and meals. We ask for it on its own screen, per category, the first time it is needed:
- Body data: when you first add body measurements, your current weight, height or body fat (including on the Body & Goals screen), or import measurements (target weight, diet type and excluded foods are not part of this category);
- Apple Health sync: when you first connect Apple Health, before we read or write any of its data (Apple also asks you to authorise each data type);
- Sharing with a Professional User (e.g., a trainer or nutritionist): when you accept their invitation, you choose which categories they can see (workouts, nutrition logs, body measurements); all start off (see Section 2.7);
- Questionnaire answers: before you send a Professional User answers that may contain health data (see Section 2.13).
Until you give a consent, the related feature stays locked and we collect nothing for that category. You can give or withdraw your body data and Apple Health consents at any time in More → Legal & Privacy → Health data, and your coach sharing choices in More → Legal & Privacy → Data shared with your coach. To withdraw your consent for questionnaire answers, email contact@formchase.com and we will delete them. Withdrawing consent does not affect the lawfulness of processing before withdrawal. When you withdraw your body data or Apple Health consent, we stop collecting and syncing that category straight away and offer to delete its existing data at the same time. If you choose deletion, the data is deleted straight away and drops out of our encrypted backups within 14 days at most. If you choose to keep it, it stays in your account and you can delete it at any time; kept body data is no longer visible to any Professional User, and other kept data stays visible to a Professional User only in the categories you have chosen to share with them.
To meet our demonstrability obligation under GDPR Article 7(1), we record each consent grant and withdrawal (including timestamp and the scope of what was consented to) in our systems.
FormChase is a SaaS software service, not a healthcare provider, clinic, dietetic practice, medical device, or regulated health app. It does not provide medical diagnoses, treatment, medical nutrition therapy, or professional credential verification, and it does not replace professional medical or nutritional advice. The data you enter is for your personal fitness and nutrition tracking and for software features you choose to use. See our Terms and Conditions (Section 3) for important disclaimers.
2. What Data We Collect
2.1 Account Data
- Full name and display name
- Email address
- Language and timezone preferences
- User role (Trainee or Professional User)
2.2 Authentication Data
Depending on your sign-in method:
- Email and password (password is hashed; we never store it in plain text)
- Apple Sign-In identifier and associated email
- Google Sign-In identifier and associated email
We receive only the identifiers and email provided by Apple or Google during authentication. We do not receive your Apple ID password or Google account password.
2.3 Fitness and Workout Data
- Exercise logs (type, sets, reps, weights, duration)
- Workout routines and schedules
- Workout notes
- Personal records
- Program assignments (if assigned by a Professional User)
2.4 Nutrition Data
- Meal logs (foods, portions, meal type, timestamps)
- Calorie and macronutrient calculations
- Water intake records
- Custom recipes
- Meal plans (created by you or assigned by a Professional User)
- Food preferences (diet type and the foods or allergens you choose to exclude) and bookmarks
2.5 Body and Health Measurements
- Height, weight, body mass index (BMI)
- Body fat percentage
- Body measurements (waist, chest, arms, etc.)
2.6 Apple Health Data (Optional)
If you enable Apple Health integration, we may read the following data types, only with your explicit per-type permission:
- Workouts (type, duration, distance, calories burned)
- Step count
- Active calories and walking or running distance
- Food and water intake (calories, protein, carbohydrates, fat, sugar, fibre, sodium, water)
- Body weight, body fat percentage and lean body mass
With your permission we also write to Apple Health the workouts, food and water entries, and body weight, body fat and lean body mass measurements that you log in FormChase, so your other health apps stay up to date.
If you use the FormChase Apple Watch app, your heart rate and active calories are shown on the watch during a workout and the finished workout is saved to Apple Health. Heart rate readings are not sent to our servers.
Apple Health data is:
- accessed only with your explicit permission for each data type;
- used solely to display your activity, nutrition and body data within FormChase, to keep it in sync with Apple Health and, only if you separately choose to share that category with your Professional User, to show it to them, including in the progress and adherence insights described in Section 7.8;
- never used for advertising, marketing, or sale to data brokers;
- never shared with third parties except as described in this Policy for providing the Service;
- stored securely and marked as externally synced so you can identify it.
You can disconnect Apple Health at any time in More → Activity Sync. Disconnect stops future syncing and keeps the data already synced; Disconnect & delete data also deletes from FormChase the data synced from Apple Health (data in the Health app is not affected), while keeping the data you entered yourself. You can also change FormChase's access to each data type in the Health app on your iPhone.
2.7 Professional User – Client Shared Data
If you are a Client of a Professional User (e.g., a trainer or nutritionist), they can see only the categories you choose to share. You choose them when you accept their invitation; if you have not chosen yet, the choice appears when you open My Trainer. All categories start off:
- Workouts (workout logs and program progress)
- Nutrition logs (the meals and water you log)
- Body measurements
Body measurements reach the Professional User only if you have also given your body data consent (Section 1). Meal plans they assign to you are their own content and are not part of this choice. You can change your choices at any time in More → Legal & Privacy → Data shared with your coach. Every choice is kept as a dated consent record, together with its history.
What your Professional User never sees: your email address, your password or sign-in identifiers, your subscription and billing records, your security and audit logs (Section 2.18), your feedback and bug reports, and any category you have not chosen to share. Turning a category off, or ending the connection, removes their access to it immediately.
2.8 Subscription and Billing Data
- Subscription plan and status
- App Store or Google Play transaction identifiers and subscription status
- RevenueCat app user ID (for entitlement validation)
- If you signed up with a trainer's referral code, the gross amount of your subscription transactions, used to calculate their commission
- Promotional codes redeemed
We do NOT store your full payment card details. Payments are processed by Apple or Google through their respective app stores.
2.9 Technical and Diagnostic Data
- Device type, operating system, app version
- Screen dimensions
- Error reports (with email address, IP address, authentication tokens and body measurement values automatically removed before transmission; your account ID stays attached, see Section 4.5)
- Session identifiers (locally generated)
2.10 Product Analytics Data (Optional, Off by Default)
If you opt in to product analytics, we collect:
- Screen views and feature usage events
- Device type, OS version, app version
- A pseudonymous user identifier (your FormChase account ID), so we can measure how features are used across sessions
We do NOT collect through analytics:
- Your name, email, or contact details
- Location data (GeoIP enrichment is disabled)
- Body measurements, weight, or health data
- Meal contents, calorie, or macro values
- Payment or billing information
Analytics data is processed on EU servers by our analytics provider. It is never used for advertising, your IP address is stripped before transmission, and analytics is off by default until you opt in.
2.11 Photos and Document Scans
FormChase only accesses the photos you choose or take. It does not scan your photo library.
Nutrition labels. If you use the food label scanning feature, photos of food labels are sent to Google Cloud Vision API through our backend for text extraction. We send only the image; no account identifiers are attached to the request to Google. Google's processing is governed by the Google Cloud Data Processing Addendum and Google's AI/ML Privacy Commitment, under which submitted content is not used to train Google's models. The extracted text is returned to our backend and used to populate your food entry.
Training and meal plan documents (Professional Users). If you import a program or meal plan from a photo or image, the iOS and Android apps send that image to Google Cloud Vision API in the same way, and the extracted text is used to prepare an import draft for you to review. On the web, the text is extracted in your browser and the image is not uploaded. Please avoid importing documents that contain other people's personal data you do not need.
Recipe photos and business logos (Professional Users). A photo you add to a recipe, and the logo you add in brand settings, are stored in our file storage and served through a public link, because they are shown to your clients and on recipe share links. Please avoid uploading images that show other people or personal information. They are deleted when you remove them or delete your account.
2.12 Push Notification Tokens
If you enable push notifications, we store a device push token to deliver workout reminders, meal reminders, and account-related notifications (e.g., new messages from your trainer, subscription updates). Push tokens are transmitted through Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and the Expo push service which routes the request to APNs/FCM.
You can revoke push permissions at any time through your device's system settings. Revoking the permission stops all further notifications from FormChase.
A notification tells you that something happened, and in some cases who did it (for example, that your trainer assigned you a meal plan). It never carries the content of a message, a meal log, a measurement, or any other health data, so that data is not exposed on your lock screen or to the services that route the notification (Section 4.12).
2.13 Questionnaire and Intake Responses
If your Professional User (trainer or nutritionist) sends you a questionnaire, we store the answers you choose to give. Built-in questionnaire templates include health-related questions (such as medical conditions, medications, injuries, or pregnancy), so your responses may include health data, which we process only with your explicit consent (GDPR Art. 9(2)(a)). Your responses are visible only to you and the Professional User who sent the questionnaire. We ask for this consent before you send your answers. You cannot yet delete answers in the app: to withdraw your consent, email contact@formchase.com and we will delete them.
2.14 Messages With Your Trainer or Clients
If you use the in-app messaging feature, we store the content of the messages you exchange with your trainer or your clients, together with delivery metadata (timestamps, read status), solely to deliver the messaging feature. Messages are visible only to the participants in the conversation.
2.15 Feedback and Bug Reports
If the app hits an unexpected error, you can choose to send us a short description of what happened. We process the text you write, together with the technical diagnostic report for that error (see Section 4.5), so we can find and fix the problem. Sending a report is optional and you write it yourself, so please do not include sensitive personal details in it.
2.16 Device Calendar (Optional)
If you choose to add a training session or workout to your calendar, FormChase creates the event in your device calendar with your permission. We store only the identifier of each event FormChase creates, so we can update or remove it if the session changes.
Professional Users can also choose calendars to show next to their coaching schedule. Events from those calendars are read and displayed on your device only; they are never uploaded to our servers or shared with anyone, and your choice of calendars is stored on your device. You can turn this off in the schedule screen or revoke calendar access in your device settings at any time.
2.17 Shared Shopping Lists
If you share a shopping list, people who open your link (valid for 7 days) and join the list can see and edit that list's items until you delete the list or they leave it. They do not see any of your other data.
2.18 Security and Audit Logs
We record security-relevant and sensitive account events, so that we can detect fraud, prevent abuse, and show that a change to an account was authorised. Each entry holds:
- what happened: the event type and action, for example an entitlement, plan or role change;
- your account identifier, and the account or record affected where that is not your own;
- the IP address and the app or browser user agent the request came from;
- a timestamp, and technical detail about the event.
These logs are readable only by our server, never by other users or by a Professional User, and are deleted automatically after at most 12 months (Section 6). They are not included in the self-service export, because releasing fraud-detection records on demand would undermine them; you can obtain the entries about you through a formal data rights request (Section 7.9). We separately keep a record of each data export you run and each role change on your account, and both of those are in your export.
3. Why We Process Your Data and Our Legal Bases
| Data Category | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Account data | Create and manage your account, provide the Service | Art. 6(1)(b): contract performance |
| Authentication data | Verify your identity, secure your account | Art. 6(1)(b): contract performance |
| Fitness/workout data | Provide core workout tracking features | Art. 6(1)(b): contract performance |
| Nutrition data | Provide core nutrition tracking features | Art. 6(1)(b): contract performance |
| Body/health measurements | Display your progress, calculate targets | Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for health data |
| Apple Health data | Sync health data at your request | Art. 6(1)(a) + Art. 9(2)(a): explicit consent |
| Professional User – Client shared data | Enable Professional User features | Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent from the Client |
| Billing data | Process subscriptions, comply with fiscal law | Art. 6(1)(b): contract + Art. 6(1)(c): legal obligation |
| Analytics data | Improve the Service (if you opt in) | Art. 6(1)(a): consent |
| Error reports | Diagnose and fix technical issues | Art. 6(1)(f): legitimate interest (service reliability) |
| Security logs | Detect fraud, prevent abuse | Art. 6(1)(f): legitimate interest (security) |
| Food label photos and imported document images (OCR) | Extract nutritional information; prepare program and meal plan import drafts | Art. 6(1)(b): contract performance |
| Recipe photos and business logos | Show your recipes and brand to your clients | Art. 6(1)(b): contract performance |
| Identifiers of calendar events FormChase creates | Update or remove the event when a session changes | Art. 6(1)(b): contract performance |
| Push notification tokens | Deliver workout/meal reminders and account notifications | Art. 6(1)(b): contract performance (service reminders); Art. 6(1)(a): consent (any optional notification of a promotional nature) |
| Questionnaire and intake responses | Deliver trainer questionnaires you choose to answer | Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for any health data in your answers |
| Messages with your trainer/clients | Deliver the in-app messaging feature | Art. 6(1)(b): contract performance |
| Shared shopping lists | Share a shopping list with the people you choose | Art. 6(1)(b): contract performance |
| Referral codes and attribution | Credit the referrer if you sign up via a referral link or participate in the trainer referral programme | Art. 6(1)(f): legitimate interest (operating the referral programme) |
The legitimate interests we rely on, and how we balanced them. Where the table above cites Article 6(1)(f), the interest is keeping the Service reliable and secure, and the balancing test is set out here as required by Article 13(1)(d). For error reports, we strip your email address, IP address, authentication tokens and body measurement values before transmission, so what remains is technical. For security and audit logs, the entries are server-only, kept for at most 12 months, and never used to profile you or to make decisions about you. For referral attribution, we record only the code and the transaction amount needed to calculate a commission. In each case the processing is limited to what the purpose needs, is not used for advertising or profiling, and you can object to it at any time under Section 7.6.
Information required by GDPR Article 13(2)(e). Providing your email address and basic account data is a contractual requirement: we cannot create or operate an account without them. Consent for health data is optional; if you refuse or withdraw it, the only consequence is that the related features (body measurements, health integrations, sharing data with your trainer) will not be available. Consent for product analytics is entirely optional, and refusing it has no impact whatsoever on the Service.
Purchase records. Apple and Google maintain the payment records for purchases through their stores (see Terms §8). We store the subscription status (plan, expiry, store identifier) returned by RevenueCat and, for the referral programme only, the gross transaction amount used to calculate the commission, covered by the "Billing data" and "Referral codes and attribution" rows of the table above. FormChase does not receive or store card details.
4. Who We Share Your Data With
We do not sell your personal data.
We share data only with the recipients below. Those acting as our processors handle data under data processing agreements. Apple and Google (for store billing), Open Food Facts, YouTube, Vimeo and Professional Users receive data as independent controllers, and their own privacy policies govern their processing.
4.1 Supabase: Cloud Database, Authentication, and File Storage
- Provider: Supabase, Inc. (privacy policy)
- Purpose: Primary database, authentication, object storage, server-side business logic (Edge Functions)
- Location: EU region (France, Paris)
- Data: All user data stored in our database (profile, workouts, meals, measurements, PT relationships, subscription references)
- Safeguards: GDPR-compliant DPA, EU data residency, Row-Level Security enforced on every table, encryption in transit and at rest. Although the data is hosted in the EU (France), Supabase, Inc. is incorporated in the United States; any processing by the US entity is safeguarded by the EU Standard Contractual Clauses included in its DPA.
4.2 RevenueCat: Subscription Management
- Provider: RevenueCat, Inc. (privacy policy)
- Purpose: Cross-platform subscription validation, purchase restoration, entitlement management
- Location: United States
- Data: App user ID, subscription status, App Store / Play Store transaction references, product identifier
- Safeguards: DPA with EU Standard Contractual Clauses (SCCs)
4.3 Apple & Google: App Store and Google Play Billing
- Providers: Apple Distribution International Ltd (Ireland) and Google Ireland Ltd (respective store privacy notices apply)
- Purpose: In-app purchase processing, subscription management, payment handling, refund processing
- Data: Transaction identifiers, subscription status, purchase history (we do not receive your payment card details)
- Safeguards: Platform privacy policies and billing terms; transfer safeguards handled by Apple/Google
4.4 PostHog EU: Product Analytics (Only If You Opt In)
- Provider: PostHog, Inc., EU Cloud (privacy policy)
- Purpose: Understand pseudonymised feature usage to improve the Service
- Location: EU (Germany,
eu.i.posthog.com) - Data: Screen views, feature events, device type, OS version, app version, a pseudonymous user identifier (your FormChase account ID)
- NOT shared: Name, email, IP address, geolocation, device fingerprint, health data, nutrition data, payment data
- Safeguards: EU data residency, GeoIP enrichment disabled, IP address stripped before transmission, DPA
4.5 Sentry: Error Monitoring (Production Only)
- Provider: Functional Software, Inc. d/b/a Sentry (privacy policy)
- Purpose: Crash reporting and error diagnostics to improve service reliability
- Location: European Union: Sentry's EU data-residency region (
de.sentry.io) - Data: Your FormChase user ID (attached deliberately as a Sentry user tag so a crash report can be traced back to your account when we investigate a bug you reported), device model, OS version, app version, locale, build metadata (git SHA, build number), and error stack traces. The user ID is a personal identifier under GDPR, not an anonymous token.
- Bug reports you send: if you send a bug report from an error screen, the free-text description you write is sent to Sentry and linked to the related error so we can investigate it.
- NOT sent: Email, username, IP address (scrubbed to
0.0.0.0in-app before transmission), health payload values, nutrition payload values, payment data, and authentication tokens (masked in request URLs before breadcrumbs are emitted). - Safeguards: Client-side PII scrubbing via Sentry's
beforeSendandbeforeBreadcrumbhooks, data minimisation, EU data residency, DPA with EU Standard Contractual Clauses (the provider is US-incorporated), production-only (disabled in development)
4.6 Resend: Transactional Email
- Provider: Resend, Inc. (privacy policy)
- Purpose: Account verification emails, password reset, security notifications, support replies, privacy-request notifications
- Location: United States
- Data: Recipient email address, email subject and body, delivery metadata
- Safeguards: DPA with SCCs, transactional-only use; no marketing emails are sent through this channel
- Role: Primary sender. Resend sends through Amazon SES in Ireland, so the message itself is handled in the EU even though Resend, Inc. is a US company
4.6b Mailjet: Transactional Email (Overflow Only)
- Provider: Mailjet SAS, a Sinch company (privacy policy)
- Purpose: The same emails as above, sent only when Resend refuses a message for a reason another provider could satisfy, such as a quota limit or an outage. An email you cannot receive is worse than one sent by a second provider, because it can leave you unable to get back into your account
- Location: European Union (France)
- Data: Recipient email address, email subject and body, delivery metadata
- Safeguards: DPA, EU processing, transactional-only use. We switch Mailjet’s open-tracking and click-tracking off on every message we send, so no invisible tracking image is added to an email and links are not rewritten through a third party
- What we could not switch off: Mailjet adds a one-click unsubscribe header, which your email app may show as an Unsubscribe button even on a security email. Using it may stop us being able to email you, including for password resets, so please do not use it on an email you asked us to send
4.7 Google Cloud Vision API: Image Recognition (OCR)
- Provider: Google Ireland Ltd / Google LLC (Cloud privacy notice)
- Purpose: Text extraction from food label photos, and from program or meal plan document images that Professional Users import
- Location: European Union. We call Google’s EU regional endpoint (
eu-vision.googleapis.com) rather than the global one, which is how Google says to keep this processing inside the EU. The image is therefore not sent outside the EU for this feature - Data: Image bytes only (no account identifiers attached to the call). The request is relayed through our Supabase Edge Function.
- Safeguards: Google Cloud Data Processing Addendum, Standard Contractual Clauses, and Google's AI/ML Privacy Commitment (submitted content is not used to train Google's models).
4.8 Cloudflare: CDN, Web Security, Legal & Marketing Site Hosting, Backups
- Provider: Cloudflare, Inc. (privacy policy)
- Purpose: Static hosting for
legal.formchase.com, content delivery, DDoS protection, Turnstile CAPTCHA for web signup, and storage of encrypted database backups (Cloudflare R2) - Location: Global edge network with EU presence; backups are stored in a private R2 bucket restricted to the EU jurisdiction
- Data: IP addresses, request metadata (in transit), Turnstile challenge tokens; for backups, a copy of our database (including health data), created every 6 hours and encrypted (AES-256) on a machine operated by FormChase before upload, kept for at most 14 days
- Safeguards: DPA, SCCs, strictly-necessary use; no advertising or analytics cookies are set by our Cloudflare properties
4.9 Open Food Facts: Open Food Database
- Provider: Open Food Facts (non-profit, France; privacy policy)
- Purpose: Nutritional information lookup by barcode or name
- Location: EU (France)
- Data: Requests to Open Food Facts are made directly from your device. Their server therefore receives the standard HTTP request metadata: your IP address, User-Agent string, the search query or barcode, and a timestamp. We do not attach any FormChase account identifier (user ID, email, session token). The response is nutritional data that we display in the Service.
- Safeguards: Public open data under the Open Database License (ODbL); Open Food Facts' own privacy policy governs their retention of request logs. If we later route these requests through our backend (so that only our backend IP is visible to Open Food Facts), we will update this section.
4.10 Professional Users (Trainers/Nutritionists): Independent Controllers
If you are a Client and grant consent, your Professional User (a trainer or nutritionist) may view specific categories of your data (see Section 2.7). In this relationship:
- FormChase remains the controller of the platform data and the technical means by which the Professional User accesses your data.
- The Professional User is an independent controller of the portion of your data they access for their own professional practice (e.g., notes, programs, and communications they produce outside the Service). They are responsible for complying with GDPR and their professional obligations in their own capacity. They must provide their own privacy notice to you for any processing they carry out outside the Service, and must respond independently to any data-subject rights request you direct to them about data they hold outside the Service.
- The in-app granular consent controls, combined with the Professional User's own notice to you, together make the essence of the joint-controller arrangement available to you, as required by GDPR Article 26(2), to the extent FormChase and the Professional User are joint controllers for any processing.
- When you revoke consent or the professional relationship ends, the Professional User's access inside the Service is immediately revoked. Their obligation to delete copies of your data they hold outside the Service is governed by our Terms (Section 6.2) and their own legal duties.
- Allocation of responsibility. FormChase is not responsible for a Professional User's breach of their independent GDPR obligations (for example, failure to honour your access or erasure request for data they hold outside the Service, failure to provide their own privacy notice, or unauthorised onward disclosure of your data outside the Service). You retain the full set of GDPR rights against the Professional User as an independent controller, including the right to lodge a complaint with ANSPDCP naming that Professional User directly.
4.10b Records About People Without a FormChase Account (GDPR Article 14 Notice)
Professional Users can store records inside the Service about clients who do not have a FormChase account, for example imported client lists (name, email, notes), goals, injuries, body measurements, progress notes, logged training sessions, meal-plan share links, and invitations. Injuries and measurements are health data. For that data:
- The Professional User is the data controller. FormChase processes this data only on the Professional User's instructions, as their processor, and does not use it for its own purposes.
- Invitation emails sent through the Service contain only the email address the Professional User provided and a link to accept the invitation.
- Non-account client data is deleted when the Professional User deletes it or deletes their own account.
- If you believe a Professional User has stored data about you and you do not have a FormChase account, you can contact that professional directly or contact us at contact@formchase.com.
4.11 Google Gemini: Food-Data Text Processing
- Provider: Google (United States).
- Purpose: Improving the shared food catalogue (translating and expanding food names and portion descriptions).
- Data: Food product names and descriptions only. We do not send any account identifier, email, or health/nutrition-log data.
- Safeguards: US transfer covered by Standard Contractual Clauses. Because only non-personal food-catalogue text is sent, no personal data is transferred through this service.
4.12 Expo: Push-Notification Delivery and App Updates
- Provider: Expo (650 Industries, Inc., United States), which routes notifications to Apple (APNs) and Google (FCM).
- Purpose: Delivering the push notifications you have enabled and delivering over-the-air (OTA) app updates.
- Data: Your device push token and the notification content. Update checks send the app version and basic device metadata (platform, runtime version) to Expo's update service; no account identifiers are attached.
- Safeguards: Processor DPA and EU Standard Contractual Clauses for the US transfer.
4.13 YouTube and Vimeo: Trainer-Attached Exercise Videos
Professional Users can attach YouTube or Vimeo videos to exercises. When you open such a video, or when its thumbnail is loaded, your device connects directly to that platform, which receives your device's IP address and applies its own privacy policy (Google/YouTube, Vimeo). FormChase does not send any account data to these platforms.
4.14 Infrastructure Endpoints
The app performs technical availability checks (network connectivity probes and requests to our status-page host). These requests expose only your device's IP address and standard request metadata; no account identifiers are attached.
5. International Data Transfers
Your data is primarily stored in the EU.
Some processors are located in the United States. For these transfers, we rely on:
- the EU-U.S. Data Privacy Framework, where the recipient is certified under it. The European Commission's adequacy decision of 10 July 2023 means no further safeguard is needed for a transfer to a certified recipient. Google LLC and Cloudflare, Inc. are certified; you can check any company's current status on the official list at dataprivacyframework.gov
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission, which we rely on for recipients that are not certified under the Framework, and as a fallback for those that are, should a certification lapse
- Processor DPAs with appropriate safeguards
- Technical measures (encryption in transit and at rest, and sending the minimum data the purpose needs)
You can obtain a copy of the relevant transfer safeguards (for example, the Standard Contractual Clauses) by writing to contact@formchase.com.
Our direction of travel. FormChase is built for the Romanian market and governed by Romanian and EU law. We prefer processors that store and process data inside the EU, and we already use EU regions or EU-based providers for the database, product analytics, error monitoring and the food database. Where we still rely on a provider outside the EU, we keep to the minimum data the purpose needs, and we review those choices as EU alternatives become viable. If we move a processor into the EU, we will update the list in Section 4 accordingly.
6. How Long We Keep Your Data
| Data | Retention Period |
|---|---|
| Account and profile data | Until you delete your account; deleted immediately upon confirmed deletion |
| Fitness, nutrition, and measurement data | Until account deletion, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion |
| Apple Health synced data | Until account deletion, until you manually delete it, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion |
| Questionnaire and intake responses | Until you ask us to delete them (by emailing contact@formchase.com) or you delete your account |
| Messages with your trainer/clients | Until account deletion, or until the account becomes dormant (see below); deleted immediately upon confirmed deletion |
| Feedback and bug reports | Up to 90 days (linked to the diagnostic error record) |
| Subscription status (plan, expiry, store identifier) | As long as the subscription is active; deleted immediately upon confirmed account deletion |
| Error/diagnostic logs | 90 days |
| Analytics events (if opted in) | 90 days in our own database; up to 12 months at PostHog EU (the retention period of our PostHog plan), then deleted automatically. When you delete your account, we also ask PostHog to delete the events linked to your account ID. |
| Push notification tokens | Until you disable push notifications or delete your account |
| Recipe photos and business logos | Until you remove them or delete your account; deleted immediately upon confirmed deletion |
| Images sent for text extraction (OCR) | The image is not stored. A usage record without the image (time, result quality and a one-way fingerprint of the image) is kept for 30 days for rate limiting |
| Security and audit logs | Up to 12 months at most; reviewed periodically and deleted or anonymised when no longer needed |
| Consent and legal acceptance records | After account deletion, kept in pseudonymised form (identifiers hashed with a secret key, what was accepted, version and date) for 3 years as evidence of lawful processing, then deleted |
| Training sessions a Professional User logged with you | If you delete your account, the sessions stay with that Professional User, without your name, contact details, notes or health data |
| Public library contributions | Retained in anonymised form after account deletion |
| Data rights request records | 3 years after resolution (legal evidence) |
| Database backups | Created every 6 hours, encrypted (AES-256) and kept for at most 14 days in a private Cloudflare R2 bucket restricted to the EU jurisdiction; Supabase also keeps its own daily backups for 7 days in the same EU region. Deleted data drops out of backups within 14 days at most |
Dormant accounts. We do not keep your data indefinitely just because you stop using FormChase. If you do not sign in for 3 years, we delete the account and its personal data, so that nothing is kept for longer than it is needed (GDPR Article 5(1)(e)). We warn you first, by email to your account address, about 60 days and again about 30 days before the deletion date, and simply signing in once stops the process and resets the clock. If you never signed in at all, the 3 years run from the day the account was created. The deletion is the same one described on the Delete Account page, so the same limited records survive it: pseudonymised consent evidence, and the training sessions a coach logged, stripped of anything identifying you.
Account deletion is immediate and cannot be cancelled once confirmed. Upon deletion, your personal data is permanently deleted or anonymised, except where retention is required by law or specified above; deleted data drops out of backups within 14 days at most. See the Delete Account page for full details.
If we permanently discontinue the Service (Terms of Service, Section 16.4), remaining account data is deleted within at most 90 days of the shutdown date, subject to the limited legal retention described above.
7. Your Rights Under GDPR
As a data subject in the EU, you have the following rights:
7.1 Right of Access (Art. 15)
Request a copy of the personal data we hold about you. You can do this in-app (More → Legal & Privacy → Data Rights → Export My Data) or by contacting us.
7.2 Right to Rectification (Art. 16)
Correct inaccurate or incomplete data. Most data can be corrected directly in the app. For other corrections, contact us.
7.3 Right to Erasure (Art. 17)
Request deletion of your personal data. Use the in-app account deletion feature (More → Legal & Privacy → Danger Zone → Delete Account & Data) or contact us. Deletion is immediate and cannot be cancelled once confirmed. If you were a client of a Professional User, your identity and health data are removed from their records too; training sessions they logged stay with that Professional User, without your name, contact details, notes or health data. We keep a limited set of records only in the cases and for the periods in Section 6: where the law requires it, for the establishment, exercise or defence of legal claims (for example, consent evidence, in pseudonymised form, for 3 years), and the training sessions described above (see also the Delete Account page).
7.4 Right to Restrict Processing (Art. 18)
Request restriction of processing in certain circumstances (e.g., while we verify the accuracy of contested data).
7.5 Right to Data Portability (Art. 20)
Receive your data in a structured, commonly used, machine-readable format (JSON). Available in-app via the Export feature.
7.6 Right to Object (Art. 21)
Object to processing based on legitimate interests (error reporting, security). We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for the establishment, exercise or defence of legal claims.
7.7 Right to Withdraw Consent (Art. 7)
Where we process data based on your consent (analytics, body data, Apple Health, questionnaire answers that contain health data, data sharing with Professional Users), you can withdraw consent at any time. In the app, go to More → Legal & Privacy: for analytics, Consent Preferences; for body data and Apple Health, Health data; for coach sharing, Data shared with your coach. For questionnaire answers, email contact@formchase.com and we will delete them. Withdrawal does not affect processing that occurred before withdrawal.
7.8 Profiling and Automated Decision-Making (Art. 22)
To provide coaching features, FormChase analyses your logged health, nutrition and activity data to generate insights such as nutrition-adherence scores, progress trends and coaching signals. Where you have linked a Professional User (trainer), these insights are also shown to them, subject to your consent. This analysis is profiling within the meaning of Art. 4(4) GDPR. These insights support human coaching and your own decisions; FormChase does not make solely automated decisions that produce legal or similarly significant effects on you (Art. 22). Calorie and macro calculations are informational estimates. You can object to this profiling at any time (see your right to object above) or, where it relies on your consent, withdraw that consent.
7.9 How to Exercise Your Rights
- In-app: More → Legal & Privacy
- Privacy request page: Privacy Requests
- Email: contact@formchase.com
- Formal data rights request: Available in-app and via email, including for logged-out users with email verification
We will respond without undue delay and in any event within one month of receipt of your request, as required by GDPR Article 12(3). That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you of the extension and the reasons within one month of receipt.
7.10 Right to Complain
You have the right to lodge a complaint with:
ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1
București 010336, România
Website: dataprotection.ro
Or with the supervisory authority in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (TLS) and at rest, including AES-256 encryption of our database backups
- Row-level security enforced in the database itself on every table, so a record is reachable only by the account that owns it, and by a Professional User only for the categories that account has chosen to share
- The only images we store are the recipe photos and business logos a Professional User uploads, and those are served through a public link by design, because they are shown to that Professional User's clients and on recipe share links (Section 2.11). Food label and document images sent for text extraction are never stored (Section 6)
- Passwords are hashed and never stored in plain text; credentials for our email, image-recognition and storage providers are held server-side only and never shipped inside the app
- Email addresses, IP addresses, authentication tokens and body measurement values are automatically removed from error reports
- Rate limiting and abuse detection enforced in the database on sensitive operations, including sign-in, account deletion and content reporting
- Identity verification before sensitive account operations, and a two-step confirmation before account deletion
- An automated test suite that runs before every release and includes tests asserting the database access policies above, so a change that would widen access fails the build
- Access to production data limited to the sole trader named in Section 11, for support and operations only
- Regular security reviews
No system is perfectly secure. If we discover a personal data breach, we will notify ANSPDCP within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay and in clear and plain language, as required by GDPR Article 34, describing the nature of the breach, the likely consequences, the measures taken to mitigate it, and a contact point for further information.
9. Children
FormChase is not intended for children under 16. Under Article 8(1) GDPR, where processing is based on consent, a child's data in connection with information society services may be processed on the child's own consent only from the age of 16; Member States may set a lower age by law, not below 13, but Romania has not done so. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, contact us at contact@formchase.com and we will delete the account.
10. Changes to This Policy
We may update this Privacy Policy. We will notify you of material changes at least 30 days before they take effect, through in-app notification and/or email, matching the notice period in our Terms (Section 17). A change is material if it introduces a new purpose, a new category of recipient, or a change of legal basis. Where a change requires your consent, we will ask for it again rather than rely on the old consent, and the related feature stays locked until you give it. The "Last updated" date at the top reflects the most recent revision.
11. Data Controller
The data controller responsible for processing your personal data is:
COCOȘ DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ
CUI: 54218790
Trade Register: F2026013034001
EUID: ROONRC.F2026013034001
Registered professional address: B-dul Bucureștii Noi nr. 136, et. parter, ap. 5, Sector 1, București, România
Telephone: +40 750 451 098
Email: contact@formchase.com
We process your data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation), Romanian Law no. 190/2018 on measures implementing Regulation (EU) 2016/679, Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, and other applicable data protection legislation.
At our current scale, we are not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy inquiries, contact us at contact@formchase.com. We will reassess this obligation as we grow.
12. Contact
For questions about this Privacy Policy or to exercise your data rights:
Email: contact@formchase.com
Earlier versions. Each version of this Policy carries its own version number and effective date, and we record which version you accepted and when. If you want to read a version you accepted in the past, ask us at contact@formchase.com and we will send you a copy.