xform.fit

Privacy Policy

Effective 10 August 2026

Who we are

xform.fit (“we”, “us”) is operated by Christian Kopp from Switzerland. This policy explains what data the app collects, why, and the controls you have over it — including data that counts as sensitive personal data under the Swiss Federal Act on Data Protection (FADP), and as special category health data under GDPR Article 9 if you are in the EU. See the Imprint for our full contact details.

What we collect

Account data: email, name, a hashed password. Never your plaintext password.

Profile data: height, sex, birth date, training goal and experience level, and — if you choose to enter it — the exercise equipment you own.

Health data (sensitive personal data): body weight, waist circumference, step count, sleep hours, and — if you log them — blood pressure and resting heart rate. We only process this with your explicit, separate consent, given at registration.

Nutrition data: meals you log, their calories and macros, and any photo you submit for AI meal recognition.

Workout data: the exercises, sets, reps and loads you log, and any training program you generate or import.

Voice recordings: if you use voice logging, the audio is sent to our AI provider for transcription and is not stored by us afterward.

Technical and log data: IP address (used for rate limiting and abuse prevention), request/timestamp logs, authentication logs (including failed login attempts, for lockout purposes), and, on mobile, crash/error reports. Our request logs record method, path, status, and timing only — never request bodies or headers.

Cookies

The web app uses two functional cookies to keep you signed in (a short-lived session cookie and a longer-lived refresh cookie), both httpOnly so they are never readable by page scripts. We do not use advertising or tracking cookies, and we do not run third-party analytics or advertising trackers of any kind.

Why we process it, and on what legal basis

Our home framework is the Swiss FADP. For users in the EU, GDPR applies as well (it reaches services offered to EU-based individuals regardless of where the provider is established). Under both:

  • Consent: obtained explicitly and separately from your general Terms/Privacy acceptance when you create an account, before any health data is collected — the basis the FADP requires for processing sensitive personal data, and (GDPR Art. 9(2)(a)) for EU users.
  • Contract necessity (GDPR Art. 6(1)(b) for EU users): to provide the logging, analytics, and coaching features you sign up for.
  • Legitimate interest (GDPR Art. 6(1)(f) for EU users): account security — brute-force lockout, rate limiting, fraud prevention.

Automated recommendations

We use automated processing to estimate your calorie targets, energy expenditure, macro recommendations, and training suggestions, based on the information you log — including adjusting these estimates over time as your logged trends change. This processing is strictly necessary to provide the app’s core features. These outputs are informational only, do not carry legal or similarly significant effects, and you can review, override, or ignore them at any time — nothing is applied to your account without your action.

AI processing

Depending on which features you use, we send specific data to our AI provider, Groq, solely to generate the result you requested:

  • Voice logging: the audio recording, for speech-to-text transcription.
  • Meal-photo logging: the photo you submit, for food and macro recognition.
  • Text parsing: the specific text you enter (a voice transcript or manual note) to structure it into a meal, workout, or stat entry.
  • AI-coached training programs: the training data (e.g. logged exercise history) needed to design or adapt a program.

We never send your full account or unrelated data to the AI provider. Groq does not use data submitted through its API to train its models. We have additionally enabled Zero Data Retention on our Groq account, so your inputs and the results returned are not logged or stored once the request has been served — Groq’s standard API retention (up to 30 days, for reliability and compliance purposes) does not apply to your data. AI outputs are estimates and suggestions, not verified fact and not human-reviewed before being shown to you — you can always ask us to look at an automated result, or simply edit or override it yourself; see our Termsfor the “not medical advice” disclaimer that applies to all calorie, macro, and coaching output.

The web planner’s “bring your own LLM” feature is different: it builds a prompt on your device for you to copy into an AI service of your own choosing (e.g. your own ChatGPT, Claude, or Gemini account). That copy-paste happens entirely outside xform.fit — we do not transmit it, and that provider’s own privacy terms, not ours, govern what you paste there.

Who else processes your data (subprocessors)

We use the following infrastructure providers to run the service. Each processes data only on our instructions and only as needed to provide their service to us:

  • Railway — backend hosting
  • MongoDB Atlas — database hosting
  • Vercel — web app hosting
  • Groq — AI transcription, vision and language processing (voice, meal photos, coaching)
  • Resend — transactional email (verification, password reset)
  • Sentry — mobile crash and error reporting

Some of these providers may process data outside Switzerland, including in the EU/EEA (recognized as offering adequate protection under Swiss law) and elsewhere; where a provider is outside Switzerland or the EU/EEA, we rely on appropriate safeguards such as standard contractual clauses.

Legal and government requests

We may disclose data if required to do so by law, a valid court order, or a lawful request from a competent authority, or where necessary to protect our rights, users, or the public from harm. Outside of these circumstances, we do not share your data with third parties for their own purposes.

How long we keep it

We keep your logged history (meals, workouts, stats, water) while your account is active — this is by design, since long-term history is what makes progress tracking and the adaptive calorie calculations meaningful; a fresh account with no history cannot be compared against a trend.

If you request deletion, your account and all associated data are deleted from our active production systems after a 24-hour grace period (which you can cancel at any time from your Profile). Residual encrypted copies may persist for a limited period in our hosting providers’ routine automated backups until those backups rotate out on their normal schedule; backup data is not accessed or used for any purpose other than disaster recovery during that window. Internal usage counters used for AI cost protection expire automatically after roughly 13 months regardless of account status.

Your rights

Under the Swiss FADP (and, if you are in the EU, GDPR) you have the right to access, correct, delete, restrict, or export your data, and to object to our processing of it. Because these actions happen from within your own authenticated account, no separate identity-verification step is needed — being logged in is the verification. In this app:

  • Access and export:Profile → “Download my data” gives you a complete export, in JSON format, of everything we hold about you.
  • Correction: edit your profile and logged entries directly in the app — changes take effect immediately.
  • Erasure:Profile → “Delete account” starts a 24-hour undoable deletion; after that window everything is permanently removed from active systems (see “How long we keep it” above for backup residency).

To lodge a complaint, contact us first at the address below so we can try to resolve it directly; you also have the right to complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or — if you are in the EU — your local data protection supervisory authority, at any time.

Children

xform.fit is not directed at, and we do not knowingly collect data from, anyone under 16 years old.

A note for US users

xform.fit is not a HIPAA-covered entity, and HIPAA does not govern the data you enter into a consumer wellness app like this one. The protections that do apply are the ones described throughout this policy.

Security

Passwords are hashed (never stored in plain text). Sessions use short-lived access tokens with rotating refresh tokens. All traffic is encrypted in transit. We rate-limit and lock out repeated failed logins, and sanitize input against injection attacks.

If something goes wrong

If a personal data breach occurs that is likely to result in a high risk to your rights or freedoms, we will notify affected users and the relevant supervisory authority without undue delay, where required by law.

Changes to this policy

We will update the effective date above if this policy changes materially, and — where required — ask for renewed consent.

Contact

Questions about this policy or your data, or to exercise any of the rights above: christian.j.kopp@gmail.com.