← grumzi.app

Grumzi Privacy Policy

Effective date: 27 July 2026

Grumzi is made by Lazar Spasic ("we", "us"). This policy explains what data the Grumzi app handles, where it goes, and what never leaves your phone. Contact: support@grumzi.app.

The short version

Data stored only on your device

The following never leaves your phone and is never uploaded to us or anyone else:

Apple Health (iOS)

Grumzi reads Apple Health read-only, with your permission, and only to reflect your movement inside the app. The app's health-import code contains no network access by design.

Google Health Connect (Android)

On Android, Grumzi connects to Health Connect the same way — read-only, with your permission, and only these three data types: steps, exercise sessions (workouts), and active calories burned. Everything read from Health Connect is processed on your device only and stored in the app's local storage; it is never transmitted to us or anyone else. Grumzi never writes to Health Connect, never reads any other data type, and you can change or revoke access at any time in the Health Connect app — the app keeps working either way.

Data we collect and where it goes

Account (only if you create one)

If you sign up with email, Sign in with Apple, or Sign in with Google, we store your email address (and, where the provider shares it, your name) with our backend provider Supabase, which hosts our database and authentication. In guest mode, no account data exists.

When you use Apple or Google to sign in, that provider confirms your identity to us: they pass us your email address (and name), and they learn that you use Grumzi. We never see or receive the password for those accounts, and we do not read anything else from them — no contacts, no calendar, no files, no other Google or Apple services.

Profile and progress sync (only if you have an account)

So that your account can be restored on a new phone, we sync a minimal set of data to Supabase:

AI meal and exercise logging

When you log by text or photo, the app sends only what is needed for the analysis: your text (or a compressed photo), your device language, and the local hour. This request is processed by our backend function and passed to our AI provider — OpenAI — solely to produce the analysis result. It is not linked to your identity, and neither we nor the function store your text or photo; photos are deleted from your device's temporary storage after the result arrives. Nothing is sent until you explicitly confirm the log.

Analytics

We use PostHog (hosted in the EU) to understand how the app is used — for example, that a meal was logged and by which method. Events are restricted to a strict allowlist enforced in the app's code: no meal text, no photos, no calorie values, no weight, height, or age, no step counts, and no health data can be sent.

Crash reporting

We use Sentry (hosted in the EU) to learn when the app crashes so we can fix it. A crash report contains technical diagnostics only: the stack trace, your device model and OS version, the app version, the screen name the crash happened on, and limited performance data. Crash reports are scrubbed in the app's code before upload: no health data, no meal text or photos, no calorie values, no weight, height, or age, no step counts, and no email or name can be sent, and they are not linked to your identity. Crash and performance data is used solely to keep the app working and never for tracking.

Feedback (only if you send it)

If you use Send feedback in the Me tab, we store your message with our backend provider Supabase so we can read it and improve the app. Alongside the message we attach your app version and build, your platform and OS version, and whether you have a premium subscription — the form discloses this before you send. Adding a reply email is optional and it is used only to reply to you. If you are signed in, your feedback is linked to your account; sent as a guest, it is anonymous. If you later delete your account, feedback you sent is kept for product improvement but is permanently detached from the deleted account (the account link is removed). Feedback is never used for marketing and never shared with third parties.

Purchases

Subscriptions are processed by Apple and managed through RevenueCat, which receives purchase and subscription-status information to unlock premium features. We never see your payment details.

What we never do

Legal bases (EEA/UK users)

Where the GDPR applies, we process account and sync data to perform our contract with you, analytics on our legitimate interest in improving the app (you can object at any time by contacting us), and AI-logging input because it is necessary to deliver the feature you invoked.

Retention and deletion

Local data stays on your device until you delete the app or use in-app deletion. If you have an account, Settings → Delete account permanently deletes your account and all synced data (profile, streak, daily summaries) from our servers immediately — deletion cascades at the database level and there is no undo — and wipes the app's local storage. You can also email us to exercise access, correction, or deletion rights.

Security

Synced data is transmitted over TLS and stored with Supabase. AI provider keys live server-side and are never shipped in the app.

Children

Grumzi is not directed at children under 13, and we do not knowingly collect personal data from them.

Changes

If this policy changes materially, we will update it here and note it in the app. The effective date above always reflects the current version.

Contact

Questions or requests: support@grumzi.app.