← grumzi.app

Grumzi Privacy Policy

Effective date: [set at publication]

Grumzi is made by Lazar Spasic ("we", "us"). This policy explains what data the Grumzi app handles, where it goes, and what never leaves your phone. Contact: lazarspasic96@gmail.com.

The short version

  • Your health data never leaves your device. Steps, workouts, and active energy read from Apple Health stay on your phone. Grumzi never writes to Apple Health and never uploads anything it reads from it.
  • Your food diary stays on your phone. What you ate, when, and every internal calculation about it are stored only in the app's local storage.
  • Meal photos and text are processed once, then discarded. When you use AI logging, your text or photo is sent for a single AI analysis and is not stored on any server.
  • You can use Grumzi without an account. Guest mode keeps everything local.
  • We don't track you across apps or sites, and we don't sell or share your data for advertising. Ever.

Data stored only on your device

The following never leaves your phone and is never uploaded to us or anyone else:

  • Your meal log: the text you typed, recognized food items, portion severity, and all internal estimates.
  • Your workout log and anything imported from Apple Health (steps, workouts, active energy).
  • Your daily free-tier usage counter, challenge progress, notification preferences, and app settings.

Grumzi reads Apple Health read-only, with your permission, and only to reflect your movement inside the app. The app's health-import code contains no network access by design.

Data we collect and where it goes

Account (only if you create one)

If you sign up with email or Sign in with Apple, we store your email address (and, with Apple, the name Apple shares) with our backend provider Supabase, which hosts our database and authentication. In guest mode, no account data exists.

Profile and progress sync (only if you have an account)

So that your account can be restored on a new phone, we sync a minimal set of data to Supabase:

  • Profile: name, gender, age, weight, height, activity level, and goal (used to personalize the app).
  • Streak: your current streak count and last log date.
  • Daily summary: per day, your earned energy total and the app's mood indicator — never your meals, never step counts, never any calorie values.

AI meal and exercise logging

When you log by text or photo, the app sends only what is needed for the analysis: your text (or a compressed photo), your device language, and the local hour. This request is processed by our backend function and passed to an AI provider — OpenAI (primary) or Google (fallback) — solely to produce the analysis result. It is not linked to your identity, and neither we nor the function store your text or photo; photos are deleted from your device's temporary storage after the result arrives. Nothing is sent until you explicitly confirm the log.

Analytics

We use PostHog (hosted in the EU) to understand how the app is used — for example, that a meal was logged and by which method. Events are restricted to a strict allowlist enforced in the app's code: no meal text, no photos, no calorie values, no weight, height, or age, no step counts, and no health data can be sent. You can turn analytics off in the app's settings.

Purchases

Subscriptions are processed by Apple and managed through RevenueCat, which receives purchase and subscription-status information to unlock premium features. We never see your payment details.

What we never do

  • No advertising, no ad SDKs, no cross-app tracking (our iOS privacy manifest declares tracking: false).
  • No selling or sharing personal data for marketing.
  • No storing of meal photos or meal text on any server.
  • No push notification tokens — all Grumzi reminders are scheduled locally on your device.

Legal bases (EEA/UK users)

Where the GDPR applies, we process account and sync data to perform our contract with you, analytics on our legitimate interest in improving the app (and you can opt out), and AI-logging input because it is necessary to deliver the feature you invoked.

Retention and deletion

Local data stays on your device until you delete the app or use in-app deletion. If you have an account, Settings → Delete account permanently deletes your account and all synced data (profile, streak, daily summaries) from our servers immediately — deletion cascades at the database level and there is no undo — and wipes the app's local storage. You can also email us to exercise access, correction, or deletion rights.

Security

Synced data is transmitted over TLS and stored with Supabase. AI provider keys live server-side and are never shipped in the app.

Children

Grumzi is not directed at children under 13, and we do not knowingly collect personal data from them.

Changes

If this policy changes materially, we will update it here and note it in the app. The effective date above always reflects the current version.

Contact

Questions or requests: lazarspasic96@gmail.com.