Privacy Policy
Effective date: 15 June 2026 · Last updated: 15 June 2026
Aphil Fitness (“AphilFitness”, “we”, “us”) helps you track meals, workouts, and progress with an AI coach that keeps things calm and realistic. To do that, we handle some of your personal information — including health and fitness data, which we treat with extra care. This policy explains what we collect, why, how advertising and payments work, and the choices you have.
The short version: We collect what we need to run the app and nothing more. We never sell your health or fitness data, and we never use it to target ads — not by us, not by anyone. The free tier shows ads; Premium is completely ad-free. You can export or delete everything, anytime.
Who this policy covers
This policy applies to the AphilFitness mobile apps (iOS and Android), our website, and our backend services together, the “Service.” It covers everyone, with extra, region-specific rights set out near the end for people in the European Economic Area, the UK and Switzerland, the United States (including state-specific health-data rights), Singapore, and elsewhere.
What we collect
Account information. When you sign up, we collect your name and email address through our third-party authentication provider. If you sign in with a third-party account, we receive the basic profile information you authorise.
Profile and goals. Information you choose to add: age, height, weight, sex, activity level, and your fitness or nutrition goals. This is used solely to personalise your experience — calorie targets, progress tracking, and coaching suggestions.
Health and fitness data you log. Meals and foods (including portion sizes and nutrition estimates), workouts, body measurements, progress photos (if you upload them), and if you choose to use the feature, menstrual cycle tracking data.
Cycle tracking data is used only to provide the cycle tracking feature. We do not use it for advertising, analytics profiling, or marketing, and we only share it with service providers where necessary to store, secure, or operate the Service under contract. You can delete your cycle data independently of the rest of your account at any time.
Subscription and purchase data. If you buy a Premium subscription, we collect the fact and status of your purchase, your subscription tier and entitlements, transaction and receipt identifiers, renewal and cancellation events, and an app-level user identifier used to keep your subscription in sync across your devices. We do not receive or store your full card number or bank details, those go directly to the relevant app store or payment processor, as described under “Subscriptions and payments.”
Advertising data (free tier only). If you use the free tier, our third-party advertising partners collect data needed to show and measure ads, typically the advertising identifier provided by your device’s operating system, advertising cookies and similar web identifiers, approximate location derived from IP address, device and browser information, and ad interactions. This is described in detail under “Advertising and cookies.” Premium subscribers do not see ads. Once your Premium entitlement is active, we do not intentionally enable advertising SDKs or advertising cookies for your account.
Usage and device data. Standard technical information: device type, browser, IP address, app interactions, and crash logs. We use this to keep the service secure, fix bugs, and understand which features are useful.
AI coaching interactions. Messages you send to the in-app AI coach and the food or workout descriptions you submit for analysis.
How we use your information
- To provide the service: tracking, progress views, reminders, and personalised targets
- To power AI features: food recognition, nutrition estimation, and coaching responses are processed using third-party AI providers running on our cloud infrastructure. We do not use your personal health or fitness data to train our general-purpose AI models. Where we use third-party AI providers, we configure them, where available, so your inputs and outputs are not used to train their general-purpose models.
- To manage subscriptions and payments: process purchases, grant and sync Premium entitlements, prevent fraud, issue refunds, and meet tax and accounting obligations
- To show and measure advertising on the free tier, using non-health signals only (see “Advertising and cookies”)
- To maintain and improve the service: debugging, performance, and aggregate (non-identifying) feature analytics
- To communicate with you: service updates, and — only if you opt in — product news
- To meet legal obligations
We do not sell your health or fitness data, and we do not share it with advertisers or data brokers. The hard line below applies regardless of which tier you’re on.
Subscriptions and payments
We never see or store your full payment-card or bank details. Depending on where you subscribe, one of the following third-party providers processes the payment, each under its own privacy policy:
- Mobile app stores (iOS and Android). Premium subscriptions bought inside the mobile apps are processed by the app store you purchase through. The app store handles the payment and shares with us the purchase status and identifiers we need to grant your subscription.
- Web payment processor. Premium subscriptions bought on our website are processed by a third-party payment processor. The processor collects and stores your payment details to complete the transaction; we receive confirmation, status, and limited transaction metadata. Through the processor’s managed-payments and tax functionality, it also calculates, collects, and remits applicable sales tax and VAT/GST on these transactions.
- Subscription-management provider. Across all platforms, we use a third-party subscription-management service to manage subscription state and entitlements. It receives purchase and receipt data, your app user identifier, subscription status, and platform/device identifiers so that your Premium access stays consistent across web, iOS, and Android. This provider acts as our service provider/processor and does not use this data for its own advertising.
Each provider operates under its own privacy policy, which you can review at the point of purchase or on that provider’s website. We retain the minimum billing and transaction records required for tax, accounting, refund, and fraud-prevention purposes, as described under “How long we keep your data.”
Advertising and cookies
Premium is ad-free. If you subscribe, you will not see ads from us in the app or on the web, and we do not enable advertising identifiers or advertising cookies for your account.
The free tier shows ads. To keep a free tier available, we display advertising to free users through third-party advertising partners — a mobile advertising network in our apps, and a web advertising network on our website (including signed-in free pages and public content such as the blog).
To serve and measure these ads, our advertising partners may use device advertising identifiers, cookies and similar technologies, IP-based approximate location, and ad-interaction data. On iOS, we will only access the device advertising identifier for cross-app tracking if you allow it through your device’s app-tracking permission prompt; if you decline, you’ll still see ads, but they won’t be personalised using that identifier. In the EEA, the UK, and Switzerland, ads are personalised only where you have given consent through our consent banner; otherwise you’ll see non-personalised ads.
The hard line on health data. Your in-app health and fitness data, what you eat, your workouts, body measurements, progress photos, and cycle tracking is never shared with advertisers and is never used to target or personalise ads, by us or by anyone else. Advertising is based only on non-health signals (such as advertising identifiers, general device/browser information, and approximate location). We never sell health or fitness data.
A note for US users. We don’t sell your personal information for money. However, using advertising cookies and SDKs to show personalised ads can count as a “sale” or “sharing” (for cross-context behavioural advertising) under some US state laws. You can opt out, see “Your US state privacy rights.”
Controlling ads and tracking.
- Use our consent banner to accept or decline non-essential cookies; you can change your choice anytime with the button below.
- On iOS, manage tracking in Settings → Privacy & Security → Tracking. On Android, reset or delete your advertising ID in Settings → Privacy → Ads.
- Opt out of personalised advertising using your ad personalisation settings, or via the industry opt-out tools at aboutads.info and youronlinechoices.eu.
- We honour the Global Privacy Control (GPC) browser signal as an opt-out of sale/sharing where required by law.
- Or simply upgrade to Premium for an ad-free experience.
Cookies we use
Cookies help websites remember things, like keeping you signed in, and in the case of advertising cookies, help show and measure ads.
Essential cookies (always on). Required for the Service to work. Primarily authentication session cookies set by our authentication provider to keep you signed in securely, and your cookie-consent preference itself. These can’t be switched off, because the app doesn’t function without them.
Analytics cookies (with your consent). Help us understand how the Service is used in aggregate, which pages are visited and which features matter, so we can improve it. These load only if you accept them in the consent banner.
Advertising cookies (free tier, with your consent). Used by our third-party web advertising network to show and measure ads for free users, as described above. These are never used on, or fed by, your in-app health and fitness data, and they are not set for Premium subscribers.
Cookie settings
- Use the consent banner to accept or decline non-essential cookies; you can change your choice anytime
- Opt out of personalised ads or third-party vendor cookies via the links in the “Advertising and cookies” section above
- Block or delete cookies in your browser settings (note: blocking essential cookies will sign you out)
Who we share data with
We share data only with the categories of third-party providers needed to run the Service, each under contract and only for the purposes we specify:
- Cloud hosting and storage providers — to run and store the Service
- Authentication provider — to create and secure your sign-in
- AI processing provider — to power food recognition, nutrition estimation, and coaching
- Payment and subscription-management providers — to process purchases and sync entitlements (see “Subscriptions and payments”)
- Advertising partners (free tier only) — using non-health signals only
- Legal and safety recipients — authorities or advisers, where required by law or to protect rights, safety, or the integrity of the Service
- A successor entity — in the event of a merger, acquisition, or asset sale, under the same privacy commitments
We do not sell your personal information for money, and we do not sell or share your health or fitness data with advertisers or data brokers. Some advertising-related disclosures on the free tier may be considered “sale” or “sharing” under certain US state privacy laws, and you can opt out.
Where your data lives
AphilFitness runs on third-party cloud infrastructure. Your data is stored and processed by our cloud infrastructure providers, who act as our data processors under their standard data processing terms.
Your data may be stored or processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on recognised safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms, together with additional measures where needed.
Legal bases for processing (EEA / UK / Switzerland)
Where data protection law requires a legal basis, we rely on:
- Performance of a contract — to provide the Service you sign up for, including tracking, AI features, and managing your subscription
- Consent — for non-essential cookies, personalised advertising on the free tier, optional product communications, and processing of sensitive data such as health and cycle data (you can withdraw consent at any time)
- Legitimate interests — to secure, debug, and improve the Service and prevent fraud, balanced against your rights
- Legal obligation — to meet tax, accounting, and other legal requirements
How long we keep your data
We keep your data for as long as your account is active. If you delete your account, your personal data is deleted from our production systems within 30 days, and from backups within 90 days. Some minimal records, such as billing, tax, and legal-compliance records may be retained for as long as the law requires.
Your rights and choices
Wherever you are, you can:
- Access and export your data — request a copy in a portable format
- Correct anything that’s inaccurate
- Delete your account and data, in full or in part (including cycle data on its own)
- Object or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of advertising by declining advertising cookies, adjusting your device tracking settings, or upgrading to Premium
To exercise any of these, email us at support@aphilfitness.com or use the controls in your account settings. We respond within the timeframe the applicable law requires (generally within 30 days; up to 45 days for US state requests, extendable where permitted).
Additional Information for Certain Jurisdictions
This section adds detail for people in specific regions and supplements the rest of this policy. Where a law described here applies to you and differs from anything stated earlier, the terms in this section govern for you. Every right described below is subject to verification of your identity and to the exceptions the relevant law allows — for example, where we need to keep information to complete a transaction you asked for, secure the Service, prevent fraud, comply with a legal obligation, or protect the rights of others. Exercising a right is free unless a request is excessive, repetitive, or manifestly unfounded, in which case we will tell you before proceeding.
United States — overview
There is no single federal privacy law in the US; your rights depend on the state you live in. Wherever you live, the categories of information we collect and the purposes we use it for are set out in “What we collect” and “How we use your information,” which together serve as our notice at collection.
We do not sell your personal information for money, and we do not sell or share your health or fitness data with advertisers or data brokers. Some advertising-related disclosures on the free tier may be considered “sale” or “sharing” under certain US state privacy laws, and you can opt out.
Premium is ad-free. On the free tier, our advertising partners use advertising identifiers and cookies to show and measure ads, and under some state laws that activity can be treated as a “sale” or as “sharing” for cross-context behavioural advertising. You can opt out at any time:
- Use the “Manage cookie settings” control (this is our “Do Not Sell or Share My Personal Information” mechanism)
- Adjust your device’s ad-tracking settings, as described under “Advertising and cookies”
- We treat a Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing where the law requires it
- Or upgrade to Premium
Your health and fitness data is sensitive information that we never sell, never share with advertisers, and never use for advertising or profiling — regardless of tier or opt-out status.
California (CCPA / CPRA)
In the past 12 months we have collected the following categories of personal information, all directly from you or automatically from your use of the Service (and, for purchases, confirmation data from the relevant app store or payment processor):
| Category (CCPA) | Examples | Used for free-tier ads? |
|---|---|---|
| Identifiers | Name, email, account/app user ID, IP address, device identifiers | Device ad identifiers only, free tier only |
| Customer records | Name, contact details | No |
| Commercial information | Subscription tier, purchase and renewal records | No |
| Internet / network activity | App and site interactions, crash logs, ad interactions | Yes, free tier only |
| Geolocation | Approximate location derived from IP address | Approximate only, free tier only |
| Sensitive personal information | Health and fitness data you log (meals, workouts, body measurements, progress photos, cycle data) | Never |
We do not collect government identifiers, financial account numbers (these go to our payment processors, not us), precise geolocation, biometric identifiers, or the contents of your private communications outside the Service.
Sale and sharing. We have not sold personal information for money. Free-tier advertising may constitute “sharing” or a “sale” of identifiers and internet activity, which you can opt out of as described above. We do not sell or share sensitive personal information, and because the Service is intended only for adults, we do not knowingly sell or share the personal information of anyone under 16.
Sensitive personal information — right to limit. We use your sensitive personal information only to provide the features you use. We do not use or disclose it to infer characteristics or for advertising, so the uses that trigger the right to limit do not arise; you may still contact us with any concern.
Your California rights. You may request to know and access the specific pieces and categories of personal information we hold; request deletion; request correction; obtain a portable copy; opt out of sale/sharing; and limit the use of sensitive personal information. We will not deny you service, charge you a different price, or otherwise discriminate or retaliate against you for exercising these rights.
Making a request. Email support@aphilfitness.com, or use the cookie and device controls for advertising opt-outs. We will verify your identity by matching your request to information in your account, and may ask for additional confirmation for sensitive requests. An authorised agent may submit a request with your written permission, and we may still ask you to verify your identity directly. We aim to acknowledge requests within 10 business days and to respond within 45 days, extendable by a further 45 days where permitted, with notice to you.
“Shine the Light.” We do not disclose personal information to third parties for those third parties’ own direct marketing. California residents may request confirmation of this once per year at support@aphilfitness.com.
Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others)
If you live in a US state with a comprehensive privacy law, you generally have the right to confirm whether we process your personal data and access it; correct it; delete it; obtain a portable copy; and opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We do not sell personal data for money, we do not carry out that kind of profiling, and we do not process sensitive data for advertising. Opt out of targeted advertising using the controls described under “Advertising and cookies”; we honour the Global Privacy Control where the law requires it.
Appeals. If we decline your request, you may appeal by replying to our decision. We will respond within the period your state’s law requires and explain our reasoning. If you remain unsatisfied, you may contact your state Attorney General.
Consumer health data (Washington My Health My Data Act, Nevada SB 370, Connecticut, and similar)
These laws treat the health-related data you log with us — meals, workouts, body measurements, progress photos, cycle data, and inferences drawn from them — as protected consumer health data. Our commitments:
- We collect this data only to provide the features you choose to use, with your consent where the law requires it
- We do not sell consumer health data, and we will not do so without the separate, valid authorisation these laws require
- We do not use consumer health data for advertising and do not share it with advertisers
- We do not use geofencing to identify or track you around health-care facilities
You may confirm whether we are processing your consumer health data and access it; obtain a list of the third parties and affiliates with whom we have shared it; withdraw your consent; and delete it. When you delete it, we also instruct our processors to delete it from their records. To make a consumer-health-data request, email support@aphilfitness.com.
European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)
Controller. The controller of your personal data is Aphil Fitness Pte. Ltd. You can reach us, including on data-protection matters, at support@aphilfitness.com.
Legal bases. The bases on which we process your data are set out under “Legal bases for processing.” We rely on your consent for non-essential cookies, free-tier personalised advertising, optional communications, and health and cycle data; you can withdraw consent at any time without affecting processing already carried out.
Your rights. Subject to the conditions in the law, you may: be informed about our processing; access your data; have inaccurate data corrected; have your data erased; restrict processing; receive your data in a portable format; object to processing (including direct marketing and any profiling); and withdraw consent. We do not make decisions producing legal or similarly significant effects based solely on automated processing. If we ever introduce such processing, we will update this policy and provide a way to object.
Complaints and transfers. You may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). International transfers are described under “Where your data lives,” and retention under “How long we keep your data.”
Singapore (PDPA)
If you are in Singapore, the Personal Data Protection Act applies. You may request access to, and correction of, your personal data, and you may withdraw consent on reasonable notice. We collect and use personal data on the basis of your consent or as otherwise permitted under the PDPA. Our Data Protection Officer can be reached at support@aphilfitness.com, and you may also lodge a complaint with the Personal Data Protection Commission.
Canada, Brazil, Australia, and other regions
We aim to honour equivalent rights — access, correction, deletion, portability, and objection — to the extent the relevant local law applies to you:
- Canada (PIPEDA): access and correction, withdrawal of consent, and complaints to the Office of the Privacy Commissioner of Canada
- Brazil (LGPD): confirmation and access, correction, anonymisation or deletion, portability, information about sharing, withdrawal of consent, and complaints to the ANPD
- Australia (Privacy Act / APPs): access and correction, and complaints to the Office of the Australian Information Commissioner
Wherever you are, contact support@aphilfitness.com and we will help.
Children
AphilFitness is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted and logged. No system is perfectly secure, but if a breach affects your personal data, we will notify you and the relevant authorities as required by law.
Changes to this policy
If we make material changes — such as adding new advertising or payment providers — we’ll notify you in the app or by email before they take effect, and where the law requires it we’ll ask for your renewed consent. The “last updated” date at the top always reflects the current version.
Contact
Questions about privacy, or to exercise any right: support@aphilfitness.com
Aphil Fitness Pte. Ltd.
Singapore
