Grumzi Privacy Policy
Effective date: 27 July 2026
Grumzi is made by Lazar Spasic ("we", "us"). This policy explains what data the Grumzi app handles, where it goes, and what never leaves your phone. Contact: support@grumzi.app.
The short version
- Your health data never leaves your device. Steps, workouts, and active energy read from Apple Health (iOS) or Google Health Connect (Android) stay on your phone. Grumzi never writes health data and never uploads anything it reads.
- Your food diary stays on your phone. What you ate, when, and every internal calculation about it are stored only in the app's local storage.
- Meal photos and text are processed once, then discarded. When you use AI logging, your text or photo is sent for a single AI analysis and is not stored on any server.
- You can use Grumzi without an account. Guest mode keeps everything local.
- We don't track you across apps or sites, and we don't sell or share your data for advertising. Ever.
Data stored only on your device
The following never leaves your phone and is never uploaded to us or anyone else:
- Your meal log: the text you typed, recognized food items, portion severity, and all internal estimates.
- Your workout log and anything imported from Apple Health or Health Connect (steps, workouts, active energy).
- Your daily free-tier usage counter, challenge progress, notification preferences, and app settings.
Apple Health (iOS)
Grumzi reads Apple Health read-only, with your permission, and only to reflect your movement inside the app. The app's health-import code contains no network access by design.
Google Health Connect (Android)
On Android, Grumzi connects to Health Connect the same way — read-only, with your permission, and only these three data types: steps, exercise sessions (workouts), and active calories burned. Everything read from Health Connect is processed on your device only and stored in the app's local storage; it is never transmitted to us or anyone else. Grumzi never writes to Health Connect, never reads any other data type, and you can change or revoke access at any time in the Health Connect app — the app keeps working either way.
Data we collect and where it goes
Account (only if you create one)
If you sign up with email, Sign in with Apple, or Sign in with Google, we store your email address (and, where the provider shares it, your name) with our backend provider Supabase, which hosts our database and authentication. In guest mode, no account data exists.
When you use Apple or Google to sign in, that provider confirms your identity to us: they pass us your email address (and name), and they learn that you use Grumzi. We never see or receive the password for those accounts, and we do not read anything else from them — no contacts, no calendar, no files, no other Google or Apple services.
Profile and progress sync (only if you have an account)
So that your account can be restored on a new phone, we sync a minimal set of data to Supabase:
- Profile: name, gender, age, weight, height, activity level, and goal (used to personalize the app).
- Streak: your current streak count and last log date.
- Daily summary: per day, your earned energy total and the app's mood indicator — never your meals, never step counts, never any calorie values.
AI meal and exercise logging
When you log by text or photo, the app sends only what is needed for the analysis: your text (or a compressed photo), your device language, and the local hour. This request is processed by our backend function and passed to our AI provider — OpenAI — solely to produce the analysis result. It is not linked to your identity, and neither we nor the function store your text or photo; photos are deleted from your device's temporary storage after the result arrives. Nothing is sent until you explicitly confirm the log.
Analytics
We use PostHog (hosted in the EU) to understand how the app is used — for example, that a meal was logged and by which method. Events are restricted to a strict allowlist enforced in the app's code: no meal text, no photos, no calorie values, no weight, height, or age, no step counts, and no health data can be sent.
Crash reporting
We use Sentry (hosted in the EU) to learn when the app crashes so we can fix it. A crash report contains technical diagnostics only: the stack trace, your device model and OS version, the app version, the screen name the crash happened on, and limited performance data. Crash reports are scrubbed in the app's code before upload: no health data, no meal text or photos, no calorie values, no weight, height, or age, no step counts, and no email or name can be sent, and they are not linked to your identity. Crash and performance data is used solely to keep the app working and never for tracking.
Feedback (only if you send it)
If you use Send feedback in the Me tab, we store your message with our backend provider Supabase so we can read it and improve the app. Alongside the message we attach your app version and build, your platform and OS version, and whether you have a premium subscription — the form discloses this before you send. Adding a reply email is optional and it is used only to reply to you. If you are signed in, your feedback is linked to your account; sent as a guest, it is anonymous. If you later delete your account, feedback you sent is kept for product improvement but is permanently detached from the deleted account (the account link is removed). Feedback is never used for marketing and never shared with third parties.
Purchases
Subscriptions are processed by Apple and managed through RevenueCat, which receives purchase and subscription-status information to unlock premium features. We never see your payment details.
What we never do
- No advertising, no ad SDKs, no cross-app tracking (our iOS privacy manifest declares tracking: false).
- No selling or sharing personal data for marketing.
- No storing of meal photos or meal text on any server.
- No push notification tokens — all Grumzi reminders are scheduled locally on your device.
Legal bases (EEA/UK users)
Where the GDPR applies, we process account and sync data to perform our contract with you, analytics on our legitimate interest in improving the app (you can object at any time by contacting us), and AI-logging input because it is necessary to deliver the feature you invoked.
Retention and deletion
Local data stays on your device until you delete the app or use in-app deletion. If you have an account, Settings → Delete account permanently deletes your account and all synced data (profile, streak, daily summaries) from our servers immediately — deletion cascades at the database level and there is no undo — and wipes the app's local storage. You can also email us to exercise access, correction, or deletion rights.
Security
Synced data is transmitted over TLS and stored with Supabase. AI provider keys live server-side and are never shipped in the app.
Children
Grumzi is not directed at children under 13, and we do not knowingly collect personal data from them.
Changes
If this policy changes materially, we will update it here and note it in the app. The effective date above always reflects the current version.
Contact
Questions or requests: support@grumzi.app.