1. Controller
Responsible for the processing of data on this website and in the apps is:
Emsstraße 57
48145 Münster
Germany
Represented by: Ulf Patrick Habig, Julia Hollmann
E-mail: support@aisafit.app
No data protection officer has been appointed; the conditions of § 38 BDSG and Art. 37 GDPR are not currently met. For anything to do with privacy you can reach us at the address above.
2. Principles
We process personal data only as far as that is necessary for a working service and for our content and features. Depending on the case, the legal bases are Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract or pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in secure and trouble-free operation).
3. Hosting and server log files
This website is hosted by:
Am Vogelherd 14
97295 Waldbrunn, Germany
Server location: Germany
When you open the site, information your browser transmits is automatically stored in what are called server log files:
- the page requested and the date and time of the request
- the amount of data transferred and a message about the successful retrieval
- browser type and version, operating system used
- referrer URL and IP address
This data is not merged with other sources. The basis is Art. 6(1)(f) GDPR. We have a legitimate interest in a technically correct presentation and in the security of our website. The log files are deleted after seven days at the latest.
We have a data processing agreement with the hoster under Art. 28 GDPR.
4. Encryption
For security reasons this site uses TLS encryption. You can recognise it by the browser's address bar starting with “https://”. While encryption is active, the data you send us cannot be read by third parties.
5. Storage in your browser
This website sets no cookies and embeds no external services. It stores exactly one value locally in your browser (localStorage):
- aisa-lang: the language you picked (German, English or Spanish), so the page appears in the same language on your next visit.
This value contains no personal data, is never transmitted to us and stays on your device. You can delete it at any time in your browser settings. The legal basis is Art. 6(1)(f) GDPR.
6. No analytics, no advertising, no external fonts
We use no analytics or tracking tools on this website, embed no ad networks and load no fonts from external servers. The font we use is embedded directly in the page, so your browser makes no connection to third parties when you open it.
7. Getting in touch
If you write to us by e-mail, we process what you send in order to handle your enquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR. We delete enquiries once they are settled and no legal retention obligations stand in the way.
8. Links to the app stores
The download buttons on this site are plain links. Only when you click one are you taken to Apple's App Store or to Google Play, and from that point the privacy terms of Apple Inc. or of Google Ireland Limited apply. We transmit no data about you to Apple or Google in the process.
9. The AISA Fitness Coach app
This section covers both versions of the app: the iPhone app from the App Store and the Android app from Google Play. They are the same app with the same features, and the differences between the two platforms are named where they exist. Neither version needs a user account or a sign-in.
9.1 Data on your device
The data you enter in the app stays on your device:
- your profile: the name you type in, age, sex, height, weight, your training level, your goal, your food preference, which meals of the day you eat, your training days, how long you train, whether you train at home or in a gym and which equipment you have, and any injuries you note down;
- your training plans, the workouts you save and any exercises you create yourself;
- your completed sessions, and the days you mark as a sick day or a day off;
- your daily check-in, on which you rate sleep, energy, stress and soreness;
- foods and nutritional values, and your food diary;
- the water you drink and the vitamins and supplements you tick off, day by day;
- your weight history and your body measurements, as numbers. Most of that history is what you typed in, but not necessarily all of it: if you have switched on the exchange with Apple Health or Health Connect, a weight measured somewhere else — by a smart scale, say — is copied into the app's own history and is from then on an ordinary entry in it. Section 9.2 says when that happens;
- pictures: the photos you take of your meals, your progress photos, and the photos you attach to a message in the chat;
- your conversation with the coach.
All of it is held in the app's own private storage, which other apps cannot read. We run no user database for it and cannot see any of it.
If you have switched on backup in your device settings, this data is additionally copied to your iCloud account (iPhone), where Apple stores it encrypted, or to your Google account (Android). Apple and Google are responsible for that copy; we have no access to it. Section 9.9 explains what the Android backup includes and what it leaves out. If you delete the app, the copy on the device goes with it — a backup copy already made in your iCloud or Google account is not affected and is removed through Apple's or Google's own settings.
9.2 Apple Health and Health Connect
The app can exchange data with Apple Health on the iPhone and with Health Connect on Android. This exchange only happens if you switch it on in the app and explicitly allow it in the system dialog, and you can withdraw that permission at any time in your device settings. Health data is a special category of personal data within the meaning of Art. 9 GDPR; the basis for processing it is your explicit consent under Art. 9(2)(a) GDPR.
On Android the app asks for exactly eight permissions, four for reading and four for writing: it reads weight, steps, distance and active energy, and it writes workouts, weight, active energy and nutrition. Weight and active energy appear in both lists because reading a figure and writing one are two separate permissions. Whatever the app writes there — on either platform — belongs to Apple Health or Health Connect from then on: it stays there after a reset and after you delete the app, and you remove it in the health app itself. What it writes is what you logged in the app — with one addition: alongside each workout it also writes the calories that workout burned, which is the app's own estimate from the exercise and your weight, not a figure you entered.
Neither app measures your movement with the phone's own sensors. On Android any distance it shows is a figure some other app or device wrote to Health Connect.
Two things are worth knowing. Revoking the permission in the Android settings does stop the exchange: from that moment nothing is read and nothing is written. What stays behind is only the appearance of it — the switch inside the app still shows as on and the app still asks Health Connect, which now hands it nothing back. And while the exchange is on, the values the app has read — today's steps, distance and active energy — become part of what is sent to the AI coach when you ask it a question in the chat; see section 9.3.
Your weight is a case of its own, and it works the same way on both platforms. While the exchange is on, the app looks for the newest weight in Apple Health or in Health Connect each time it comes to the foreground, each time you open the home screen, and at the moment you switch the exchange on. If what it finds is newer than anything already in the app and differs from your current weight by more than a rounding error, that value is copied into the app's own weight history. From then on it is an ordinary entry there, and everything that happens to your weight happens to it: it counts as your current weight, it travels with your profile in every chat request, the weekly review's weight change is worked out from it, and it is part of the export file and of the backup. Switching the exchange off later does not take it out again, because the entry has already been written. You can delete it in the app like any other weight entry, and the app then remembers not to import that same measurement a second time. So while your weight does go to the coach whether the exchange is on or off, the exchange decides whether a number in that history could have been measured by something other than you.
9.3 The AI coach
The AI coach does not run on your phone. When you ask the coach a question, take a photo of a meal, scan the equipment in your gym, record a short clip for a form check or have two progress photos compared, that request is processed over the internet.
What is sent is what the answer needs, and how much that is depends on which feature you used. The chat sends by far the most; the camera features send the picture and almost nothing else.
The chat sends:
- your question, and any photo you attach to it;
- your profile, including the name you entered in the app, your age, sex, height, weight, level, goal, food preference, how many days a week you train — the number, not which days — how long a session lasts and whether you train at home or in a gym, and the injuries or limitations you have noted;
- the context of the conversation: this week's plan and today's workout and check-in, a session you have running at that moment, a workout you have already finished today with its title, its length in minutes and the app's calorie estimate for it, your four daily nutrition targets, what you have eaten and logged today and whether that has been treat-heavy for days, your weight change, your latest body measurements, how many workouts you have logged, your current streak, the three lifts whose weight has changed most, with the first and the latest weight, how many progress photos you have on file, the supplements the app suggests for your profile, and the recent messages in the chat;
- and, if you have switched on the health exchange described in section 9.2, your steps, distance and active energy for today. Your weight is not part of this condition: it goes with the profile in every chat request, whether the health exchange is on or off — though with the exchange on, the number itself may be one read out of Health, as section 9.2 explains.
The camera features send the picture and nothing about you. When you scan the equipment in your gym, have a meal photo identified, record a clip for a form check or have two progress photos compared, what travels with the image is a fixed instruction and the language the answer should be in — no profile, no name, no history, no health figures. Three of the four send that language; the gym scan is the exception and sends the fixed instruction alone, because its answer is picked from a fixed list of equipment names and needs no language. A form check sends at most eight still frames taken from the clip, never the clip itself. There is one exception: the meal advisor, which recommends what to eat from a photo of your food, your fridge or a menu, also sends four numbers and your food preference: your calorie and protein target for the day, and the calories and protein you have logged so far today. The foods themselves are not part of it.
Beyond the chat and the camera features, the app makes ten further requests as part of other things you do in it. Not all of them are ones you would think of as asking the coach:
- when you open the weekly review — your name, the sessions done, missed and sick this week, your weight change, the three lifts whose weight has changed most, your average calories against your calorie target, your goal and your streak;
- when you tap refresh on the motivation card on the home screen — your name, your goal, how many workouts you did this week, and the line the card is showing at that moment, so that the next one is not the same;
- when you type a food instead of picking one from a list — only the words you wrote and the language the answer should be in, not your targets and not your day's eating;
- when a product you scanned by barcode comes back with almost no vitamin figures on it — the product's name is then sent, with the app's language, to have them filled in;
- when you ask for a food suggestion that balances your day — your four daily targets and, as four totals rather than a list of foods, the calories, protein, carbs and fat you have logged so far today, plus your food preference and whether your day has leaned treat-heavy;
- when you ask for ideas for a vitamin or another nutrient — the nutrient and your food preference;
- when you tap the healthier-alternative line on a food you have logged — that food's name and its calories, protein, carbs and fat;
- when you type or dictate a workout, or ask for extra exercises to be added to one — the words you wrote, plus your level, your goal, how long a session should last, the equipment you train with and the injuries you noted down;
- when you log an activity you typed in yourself, to rate how strenuous it is — only that word or phrase, and nothing else about you;
- and once per launch, for up to five saved foods that have no serving weight yet, their names and the app's language, to have their nutritional values filled in.
Almost all of this is behind Pro: it only happens on a device with an active subscription. Nine of the ten also need you to be on the screen concerned. The tenth does not: the top-up of older saved foods runs shortly after the app starts, on no screen in particular and with nothing shown while it does. Two of the ten are not behind Pro at all and run for anyone: the intensity rating for an activity you typed in yourself, and the healthier alternative for a food you have logged. Every one of them sends only what the bullets above name.
Your e-mail address is not sent, and no device identifier is sent either, because the app needs no user account. The name in your profile is sent, but only by three of the requests above: the chat, the weekly review and the motivation card. The others go without it — all four camera features, every food and workout suggestion, the intensity rating and the background top-up of saved foods. If you would rather your name not travel at all, enter a nickname or an initial in the app instead. And as with every request your phone makes over the internet, the recipient sees the IP address you are connecting from, even though it is not part of what the app sends.
The request travels through an intermediary we operate with Cloudflare Germany GmbH, Rosental 7, 80331 Munich (parent company: Cloudflare, Inc., San Francisco, USA). It runs on Cloudflare's network, which means it is handled at whichever of Cloudflare's locations is nearest to you, not necessarily in Germany. This intermediary does not store the requests you send to the coach; it passes them on to our AI provider. (It does store one other thing, and only on the iPhone: a shared-workout link, which has nothing to do with the coach — section 9.8 describes it.) The provider is:
Gordon House, Barrow Street
Dublin 4, Ireland
Model used: Google Gemini
Under our agreement with Google, Google processes the request on our behalf solely in order to produce the answer and does not use it to train its own models. That is an undertaking from the agreement, not something the app can check or enforce from your phone. For a limited time Google may store the request in order to detect abuse. The processing may also take place on servers of Google LLC in the USA; the basis for that transfer is the EU Commission's standard contractual clauses under Art. 46(2)(c) GDPR together with Google LLC's certification under the EU-US Data Privacy Framework.
Here the two versions of the app differ in the route a coach request takes. For everything to do with the coach, the Android app talks to our intermediary and to nothing else. The iPhone app has a second way: a build of it that carries its own access key can send the request straight to Google's Gemini service, with everything described above in it. That happens when our intermediary cannot be reached at all, or answers with an error other than a plain “not found” — and in a build that has the key but no credentials for our intermediary, it happens for every request rather than only after a failure. What is sent is the same either way. What is not the same is who receives it and under which arrangement. A request sent this way goes to Google's own service and does not travel through us at all. That matters, and plainly put it means this: the two protections described just above — that Google handles the request on our behalf and only in order to produce the answer, and that the standard contractual clauses and the EU-US Data Privacy Framework cover its transfer to the USA — both rest on our agreement with Google, and a request that never passes through us is not covered by either of them. Which of the two routes your copy of the app can take is fixed when that copy is built: there is no setting for it in the app, and the app does not tell you which route a request took.
If the coach cannot be reached, the app does not always say so. In the chat, both versions answer from a small set of canned replies held in the app, which involves no transfer and no AI. Three of the camera features do the same rather than fail: a gym scan then reports a standard set of equipment, a form check a standard score with standard remarks, and a photo comparison a set of standard observations — none of which came from your pictures, and none of which left your phone. Three further features answer from the app itself rather than fail: a workout you describe in words is then put together by the app from its own exercise library; an activity you typed in yourself is rated with a fixed middling intensity value, which is what the calorie burn recorded for it is then worked out from; and the motivation card falls back to one of the lines stored in the app. Nothing in the app marks any of these answers as canned, which is why it is said here. Every other request in this section produces no result at all until the connection is back, and none of them invents one: identifying a meal from a photo, the weekly review, and all four of the food suggestions — the meal advisor, the day balancer, the ideas for a nutrient and the healthier alternative. Most of these say on screen that they could not fetch an answer; a few simply show nothing new — the meal advisor, adding exercises to a workout, refreshing the weekly review, and on the iPhone the day balancer (the Android app shows a message there). The two requests that fill in a food's nutritional values in the background — after a barcode scan, and once per launch — are the exception: they fail in silence, and the food simply keeps the values it already had.
The legal basis is Art. 6(1)(b) GDPR. Without this transfer the coach cannot answer, so it is necessary in order to perform the usage agreement. Where a request contains health information — about complaints, weight, injuries or nutrition — or a photo of your body, we additionally rely on your explicit consent under Art. 9(2)(a) GDPR. There is no separate consent dialogue for this anywhere in either app: for the requests you make yourself, sending the request is the act of consenting. Not all of them are made that way, and it is worth being exact about how many are not. Three follow from something you did that was not itself a question for the coach: opening the weekly-review screen starts the review; scanning a barcode also sends the product's name to the coach if the label carries almost no vitamin figures; and logging an activity you typed in yourself sends that word or phrase to have its intensity rated. A fourth follows from nothing you did at all: the top-up of up to five saved foods without a serving weight runs shortly after the app starts, with nothing shown on screen.
Withdrawal works forwards only, and it does not reach back to a request that has already been sent and answered. For everything in this section but one, leaving those features alone is enough to stop any further requests. The top-up of saved foods is that one exception, and it should be named as such: there is no setting for it in either app, so short of not opening the app you cannot prevent it. It works on saved foods that have no serving weight yet, five at a time, and foods are still saved that way every day — a meal from the meal plan that you mark as eaten, or a meal identified from a photo — so it does not run out of work by itself, and a request that fails is simply tried again at the next launch. It stops when a Pro subscription ends, or when no saved food without a serving weight is left.
If you would rather not have this, simply do not use the AI coach. The training log, your weight history and the nutrition tables work without it and then stay entirely on your device.
9.4 Purchases and subscriptions
AISA Pro is an in-app purchase: through the App Store on the iPhone, through Google Play on Android. Your contract partner for the payment is Apple or Google, and you manage or cancel the subscription in your Apple account or your Google Play account. We receive no payment data from either of them, only whether an entitlement exists.
On Android the app asks Google Play which subscriptions are active on this device, and stores a single switch from the answer: Pro yes or no. It sends no identifier of yours to Play — although Google of course knows which account made a purchase, because that is how the store works. This check runs whenever the app starts or comes back to the foreground, not only around a purchase, and at the same time it fetches the current prices for the two subscriptions whenever it does not already have them. If Play cannot be reached, the last stored answer is left as it is.
When you finish a guided workout, and only once you have been using the app for a few days and have completed at least two sessions, the app may ask the store to show its own rating prompt. It asks only once, ever. Whether the prompt then appears is Apple's or Google's decision, and we learn nothing about it either way.
9.5 Statistics from Apple and Google
Apple and Google provide us with aggregated, non-personal statistics about downloads, crashes and technical problems, as far as you have agreed to sharing analytics data in your device settings. These statistics come from the store and the operating system, not from anything built into the app. We cannot draw conclusions about individual people from them.
9.6 Camera, microphone and notifications
Beyond the health access in section 9.2, the Android app asks for three permissions. The iPhone app asks for one more, because iOS asks about speech recognition separately from the microphone. Each question comes at the moment you first use the feature that needs it, and each one can be refused:
- Camera — for the barcode scanner, which is the only live viewfinder in the app, and for photos and clips you take inside the app: a meal, the equipment in your gym, a form check, a progress photo. A form check is meant to be a clip of about ten seconds, and only the first ten seconds of it are ever used. On the iPhone the recording stops at ten seconds by itself; on Android the app asks the camera app for the same limit, but a camera app is free to ignore it, so a longer recording is possible there — either way only the first ten seconds are looked at, and a clip you pick from your library can be any length. The clip itself stays on your device — including its audio — and only still frames taken from it are sent to the coach, at most eight of them (section 9.3).
- Pictures from your library. You can pick an existing picture or clip instead of taking a new one, and a picture picked that way travels exactly like one you take. This is not a permission: neither version of the app asks for access to your photo library. Both open the system's own picker, which runs outside the app and hands back only the one file you chose, so the app never sees the rest of your library.
- Microphone, and on the iPhone speech recognition as a second question — for dictating a message to the coach and for dictating when you create a workout. See section 9.7.
- Notifications — for the reminders the app schedules on the device itself. On Android there is also an ongoing notification while a workout timer is running, which is how Android keeps the timer alive; the iPhone app shows nothing comparable. There are no push messages from a server; neither app has a push channel at all.
If you refuse one of these, only that feature stops working and everything else stays usable. You can change your mind at any time in your device settings.
9.7 Dictation and reading answers aloud
Dictation is not done by us. The app hands the recording to your device's own speech recognition — Apple's on the iPhone, the speech service set on your Android phone, which on most phones is Google's. On both platforms that service normally sends the recording to its provider's servers for recognition; we deliberately do not force offline recognition, because for most of the app's languages it is noticeably worse. What you dictate therefore reaches Apple or Google under their own privacy terms, exactly as it does when you dictate anywhere else on your phone. If you would rather avoid that, type instead of dictating.
The same applies in reverse when you have a coach answer read aloud: the text is handed to the speech engine installed on your device, which may likewise be a cloud-backed service of the platform vendor.
9.8 Other connections to the internet
Apart from the AI coach in section 9.3, the app contacts the following:
- Open Food Facts (world.openfoodfacts.org) — when you scan a barcode, the digits are sent there to look the product up, together with the app's display language and an app name as the user agent. No account and no identifier of yours is involved. If the answer contains a product photo, that picture is then downloaded from the image server behind the Open Food Facts entry. A barcode scan can also lead to one further request that is not to Open Food Facts: if the entry found carries almost no vitamin figures, the product's name and the app's language go to the AI coach to have them estimated (section 9.3).
- TheMealDB (www.themealdb.com) — to find a picture for a food, the name of that food is requested as a plain image address. Again no account, no identifier.
- Shared workouts. A workout you share from Android is carried inside the link itself, in the part of an address that a browser keeps to itself and never sends on, so the workout itself reaches no server. A short link created on the iPhone works differently: the workout list behind it is stored on our intermediary and kept there for at most 180 days. The upload happens when you tap Share, before the share sheet opens, so it is stored even if you then cancel. Either way the payload contains the workout only, and nothing about you — for each day its title and weekday, the kind of session and its break length, every exercise with its muscle group, the equipment it needs and its sets, reps and rest, and any cardio activities planned for that day with their duration and an intensity value. A shared week carries one such day after another in the same link. There is no profile in it and no identifier. Note that the title of a day, the name of an exercise you added yourself and the name of an activity you typed in yourself can all be text you wrote. If you open a short link, the app downloads the stored payload. And with either kind of link, opening it in a browser first fetches the landing page from our intermediary, which in doing so sees the request and the IP address it came from.
- Buttons that leave the app. Some screens offer a button that opens another site or app: a YouTube search for the name of an exercise, an Amazon search for a supplement or a nutrient, the app's own page in the store, a link to your subscriptions in the store, and on the subscription screen the store's terms of service and a privacy page. The iPhone additionally offers a link for writing a review, where the Android app instead links to its own page in Google Play. On Android the app simply hands the address to the system, which opens whichever app is set to handle it — for a YouTube or Amazon address that is often the YouTube or Amazon app rather than a browser; on the iPhone the exercise tutorial opens in a browser view inside the app rather than switching to Safari. Either way, from that moment you are on the other provider's site or app under their privacy terms. The app sends nothing of yours with it: the only thing that travels is the search term itself, which is the name of the exercise, supplement or nutrient you tapped on. For supplements and nutrients, and for an exercise from the app's own library, that name is one of the app's own fixed terms. For an exercise you added yourself, or one the coach wrote into your plan, it is the text that was typed — so, as with the shared links above, it can be words of your own.
Barcodes themselves are recognised on your device: on Android by a recognition component built into the app, on the iPhone by the system's own scanner. Either way the picture from the viewfinder never leaves the phone; only the number that was read is looked up.
9.9 Backup and moving to a new phone
On Android, the system backup is switched on for the app. If you have enabled backup in your device settings, Android copies the app's data to your Google account and restores it onto a new phone. That copy is Google's responsibility and we have no access to it. It is worth being clear about what it contains: the app's document with your profile, plans, food log and chat history, all of your stored pictures — progress photos, food photos and chat photos — and the app's settings file. That last one holds considerably more than the word suggests: besides your language, units and reminders it holds the water you log and the vitamins and supplements you tick off day by day, a workout you have started and not finished, any interval blocks you have put together yourself, a count of how often you have used the AI features, the note that you own Pro, and the weekly summaries the AI coach has written about your training weeks, which the app keeps so it does not have to ask for the same one twice. Deliberately excluded are only: the scratch files of the camera and video capture, the cache the home-screen widgets read, the temporary files written while saving, the “quarantine” folder (which only ever appears if the app once found its own data file damaged, and which holds that damaged file) and the device-specific switches, such as whether you have refused the camera prompt. The same list applies to the direct transfer to a new device.
On the iPhone, the equivalent is the iCloud backup described in section 9.1. The app stores its document and its pictures where an iCloud backup picks them up, and excludes nothing from it. Apple manages that copy and protects it in transit and on its servers; whether Apple itself can read it depends on whether you have switched on Advanced Data Protection in your iCloud settings. Either way we have no access to it.
9.10 Widgets, reminders and the timer
If you place one of the app's home-screen widgets, it shows data from the app outside the app, where anyone holding the phone can see it: today's workout, the calories and protein you have eaten against your targets, which days of this week you trained and which you missed, your streak, your vitamin rings and the day's quote. The same goes for reminders and, on Android, for the ongoing notification while a workout timer runs: their text can appear on the lock screen. Widgets read a small cache file on the device; nothing about them is sent anywhere.
9.11 Exporting and deleting your data
In the app's settings you can export your data and share the file wherever you want, and you can reset the app. The export is the app's data document — profile, plans, food log, chat history and the other entries kept in that document; the picture files are not part of it, and neither is anything kept in the app's settings file — which includes your water and vitamin days and the weekly summaries.
What a reset removes differs between the two versions, and it is only fair to say so plainly. On Android it deletes the data document and every stored picture — progress photos, food photos and chat photos — and clears everything derived from your entries, such as the water and vitamin days and the saved weekly summary. On the iPhone it deletes the data document and your progress photos, but the food photos and the photos from the chat stay on the device, as do settings-level leftovers such as the water and vitamin days and the cached weekly summary. In both versions your language, your units, your reminders and the record that you own Pro come through a reset intact, so that it does not take away your settings or a subscription you paid for. The reason differs, though, and that is what explains the difference above. On Android each of the app's stored settings was gone through one by one and marked either as data, to be cleared, or as a setting, to be kept. On the iPhone there was no such sorting: the reset removes the data document and the folder of progress photos, and nothing else — and two things from the data document come straight back: your own nutrition targets and the names of your food folders are still held by the running app and are written into the fresh document the next time it saves. Your language, units, reminders and Pro record are left behind because nothing goes looking for them — and so, for exactly the same reason, are the food photos, the chat photos and the water and vitamin days named above.
On Android one more thing survives a reset on purpose: the “quarantine” copy mentioned in section 9.9, because it may be the only copy left of data you might still get back — the app could not read it, but that is not the same as it being lost, and a reset must not be what finally destroys it. These are two different things, so to be clear about both: that copy is never included in the backup to your Google account, and it is not removed by a reset inside the app — it stays on that one phone and nowhere else. Deleting the app removes everything the app itself stores on the device, on either platform and quarantine copy included. What it wrote into Apple Health or Health Connect is not the app's own storage and stays there (section 9.2).
9.12 What the app does not do
It keeps no user account, uses no advertising ID, embeds no ad networks, and we have built no analytics, tracking or crash reporting into it. We have added no connection to third parties beyond the ones named in sections 9.3 and 9.8, the app store and the operating system's own services (Apple Health or Health Connect, speech recognition, backup).
One qualification, and it is the barcode reader in section 9.8. On Android that reader is a Google component built into the app. Your pictures still never leave the phone, and nothing about you is sent with it — but the component can report technical data about its own use to Google, which we neither see nor receive. On the iPhone the scanner is part of the operating system and the same applies to it as to any other iOS function.
10. Your rights
You have the right at any time to
- information about the data stored about you (Art. 15 GDPR)
- correction of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to the processing (Art. 21 GDPR)
You can withdraw consent you have given at any time with effect for the future. A message to support@aisafit.app is enough for any of this.
11. Right to complain
If you believe that we process your data unlawfully, you can complain to a data protection supervisory authority. The competent one is the authority of your place of residence or of our registered office:
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de
12. Changes
We update this privacy policy whenever the legal situation or our website and apps change. The version published here is the one that applies to your next visit.
Last updated: 18 September 2026