Skip to content
EN
FrançaisEnglish

Privacy Policy

Effective

1. Data controller

The controller of your personal data is PUMPEAT, a French simplified joint-stock company (société par actions simplifiée) with a share capital of 2 000 €, registered office at 30 boulevard de Sébastopol, 75004 Paris, France, registered with the Paris Trade and Companies Register under number 109 451 757, represented by its president.

Contact: [email protected].

2. Data collected

We collect the following data:

  • Account data: email, hashed password, username, profile picture, date of birth, gender.
  • Fitness and nutrition profile: height, weight, activity level, goal, dietary restrictions, dietary profile.
  • Health data (optional, opt-in): weight, height, age, sex, steps, energy burned and heart rate, read from Apple Health / Health Connect with your permission. See the Health Data Policy for details.
  • Activity data: recorded workouts, exercises, loads, durations, estimated calories, meals consumed, custom recipes, shopping lists.
  • Location data (optional): if you record an outing with GPS, your route trace, altitude, speed and, where applicable, the heart rate measured during the effort are stored on our servers and attached to that outing. GPS is only active during an outing you start, and you can delete an outing at any time.
  • Social data: follows, posted sessions, comments, likes.
  • Technical data: anonymized device identifier, error logs, app version.
  • Usage log: navigation events (app opened, questionnaire step completed, feature used), without any content you type. It is kept for 90 days, stays on our own servers and is never sent to a third-party analytics tool.

3. Purposes

Your data is processed to:

  • Create and manage your account.
  • Provide the Application's features (workout tracking, nutrition calculations, social feed).
  • Ensure security and prevent abuse, including an automated check of published images and texts before they go live, and the handling of reports.
  • Improve the service (aggregated and anonymized statistics).
  • Respond to your requests and to our legal obligations.

4. Legal bases

Processing is based on:

  • The performance of the contract between you and the Publisher (account management, core features).
  • Your consent, for optional processing (push notifications, social sharing).
  • Your EXPLICIT consent, for health data read from Apple Health or Health Connect (Article 9(2)(a) GDPR). It is separate from accepting this policy: it is given on your phone's permission screen, then recorded and timestamped. You can withdraw it at any time from Settings → Health data, or revoke the permission from the Health app (iPhone) or Health Connect (Android) — reading stops immediately.
  • The Publisher's legitimate interest, for security and service improvement.
  • Compliance with legal obligations where required.

5. Retention

Your data is retained as long as your account is active. Upon account deletion, it is erased within 30 days, except for data required for legal obligations (e.g. security logs kept for up to one year).

The usage log is deleted automatically after 90 days, without waiting for account deletion.

Technical backups are purged within 90 days after deletion.

6. Recipients

Your data is accessible only to the Publisher and its technical providers (processors under the GDPR), bound by a confidentiality obligation:

  • Supabase (database, authentication and sign-in emails — hosted in the European Union).
  • Render (API hosting — European Union).
  • Cloudflare R2 (storage of the images you publish).
  • Anthropic (analysis of the meal photos you submit, and automated checking of published images and texts). Only the content concerned is transmitted, for the duration of the check; it is not retained by the provider to train its models.
  • Resend (delivery of transactional emails).
  • Google Firebase (push notifications and crash reports).
  • RevenueCat, Apple and Google (subscription management and billing).
  • Apple and Google (store distribution).
  • OpenFreeMap (map background for outings): tiles are downloaded from your phone, so this service receives your IP address and the area displayed when you view a route.
  • Open Food Facts (public food product database): queried from our servers for a scanned barcode, never from your phone — no data about you is sent to it.

No data is sold to third parties for advertising purposes. No third-party analytics tool (Google Analytics or equivalent) is used: usage statistics are computed on our own servers.

7. Transfers outside the EU

Your data is stored in the European Union: both the database and authentication (Supabase) and the API (Render) run on European servers.

Some processing nonetheless involves providers established in the United States: Anthropic, when you submit a meal photo for analysis or when content you publish is screened; Google (Firebase), for push notifications and crash reports; and RevenueCat, Apple and Google for subscription management. These transfers are governed by the European Commission's Standard Contractual Clauses or, where the provider is certified under it, by the EU–U.S. Data Privacy Framework.

You can avoid meal photo and description analysis simply by not using it: it is a feature you trigger, never background processing.

8. Security

We implement technical and organizational measures to protect your data: in-transit encryption (TLS), token authentication, environment separation, access logging, regular backups.

Despite these measures, no internet transmission or storage system is completely secure. In case of a breach likely to result in a high risk, you will be notified.

9. Your rights

Under the GDPR, you have the following rights: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time.

You can exercise these rights from the "GDPR" section of the Application or by writing to [email protected].

You also have the right to lodge a complaint with the CNIL (www.cnil.fr) or your local data protection authority.

10. Minors

The Application is not intended for children under 15. If you are a parent and notice that a child has provided us with data without your consent, contact us for immediate deletion.

11. Changes

This policy may be amended at any time to reflect changes in the service or regulations. The current version is always accessible from the Application.

12. Contact

For any question regarding the protection of your data: [email protected].