EvrFit Privacy Policy
Draft — not approved for publication
Effective date: 1 August 2026
1. Who we are
EvrFit is provided by IntegratingMe d.o.o., registered in Bosnia and Herzegovina under number [COMPANY REGISTRATION NUMBER], with its registered office at [REGISTERED ADDRESS] ("EvrFit", "we", "us", or "our"). We are the controller of the personal data described in this policy.
Privacy contact: privacy@evrfit.app
2. Scope and age requirement
This policy applies to the EvrFit mobile app and related services. EvrFit is intended only for people aged 18 or older. By creating or using an account, you confirm that you are at least 18.
If we learn that a person under 18 has provided personal data, we will restrict the account, investigate, and delete the data unless the law requires otherwise. A parent or guardian may contact us at privacy@evrfit.app.
3. Data we collect
Depending on the features you use, we collect:
- Account data, such as your user ID, email address, name, authentication-provider details, and account timestamps.
- Profile and preference data, such as birth year, sex, height, weight, goals, fitness level, activity level, cuisine and workout preferences, active hours, timezone, avatar, smoking and drinking preferences, injuries, medical conditions, and medications.
- Health and fitness data, such as workouts, exercises, sets, repetitions, load, distance, duration, calories, water intake, weight, heart-rate summaries, and sleep summaries and stages.
- Nutrition data, such as food entries, serving information, meal type, and estimated nutrients. If you request photo analysis, the image is processed for that request but is not saved in EvrFit Storage or attached to your food log.
- Medical-report data, such as an uploaded PDF, extracted report text, your caption, and an AI-generated explanation or summary.
- Medication-log data, including medication name, dose, and time taken.
- Device and app data, such as push-notification tokens, device identifiers used for notifications, app activity needed to provide the service, AI usage and credit records, and security or diagnostic logs maintained by our service providers.
Apple Health access is optional and controlled through Apple’s permission interface. If you grant access, EvrFit reads only the categories you approve. The current app uploads derived daily summaries needed by its features to our backend; the complete Apple Health database remains under Apple’s and your device’s controls.
4. How we obtain data
We receive data directly from you, from Apple Health when you authorize access, from Google when you choose Google Sign-In, and from technical systems that operate and secure the service.
5. Why we use data and our legal bases
We use personal data to:
- create and secure your account and provide requested app features;
- generate plans, summaries, insights, and progress views;
- process food photos and medical reports when you ask us to;
- synchronize authorized Apple Health information;
- send reminders and service notifications you enable;
- prevent abuse, troubleshoot, and maintain service security;
- comply with law and respond to valid legal requests.
For ordinary account and service data, we generally rely on performing our contract with you. For special-category health data, including medical conditions, medications, HealthKit summaries, and medical reports, we rely on your explicit consent where required by law. We may rely on legal obligations or legitimate interests for narrowly scoped security, fraud prevention, and legal compliance after assessing your rights.
AI-assisted processing of health data is integral to EvrFit: plan generation, weekly reviews, food-photo analysis, and medical-report interpretation all depend on it. For this reason consent is requested once, before you begin using the app, and the app cannot be used without it.
There is no separate in-app control to withdraw this consent while keeping your account. To withdraw, delete your account from Profile → Account → Delete Account. Deletion is immediate and permanent, and erases the data described in section 9. Withdrawal does not make earlier lawful processing unlawful.
You can revoke Apple Health access separately at any time in iOS Settings, without affecting your account.
6. AI processing
When you request an AI feature, relevant content is sent from our backend to OpenRouter, which routes the request to the selected model provider. Depending on the feature, the content can include profile details, goals, food or workout information, health metrics, known conditions, medications, and extracted medical-report text.
This information is not anonymous merely because your account ID is omitted from an AI prompt: the content itself may identify you or concern your health. AI output may be incomplete or wrong and is provided for general wellness information, not diagnosis, treatment, or emergency care.
Every request we send to OpenRouter sets a data-collection policy of deny. This restricts routing to model providers that do not retain submitted content beyond serving the request. Your content is not used to train AI models, by us, by OpenRouter, or by the providers we route to. Requests currently use the model google/gemini-3.1-flash-lite and are served by Google (Google AI Studio and Google Cloud Vertex AI endpoints).
If we change models or providers in a way that alters this position, we will update this policy and, where the change concerns health data, seek renewed consent.
7. When we share data
We disclose data only as needed to operate the service, follow your instructions, protect the service, or comply with law. Current categories of recipients include:
- Supabase, for authentication, database, file storage, and backend functions;
- OpenRouter and the selected AI model provider, for user-requested AI processing;
- Google, when you choose Google Sign-In;
- Apple, for platform services, Apple Health permissions, and push-notification delivery;
- professional advisers, authorities, or transaction counterparties where legally necessary.
We do not sell personal data. We do not use Apple Health or medical data for advertising, data brokerage, or marketing profiling.
8. International transfers
Some providers process data outside your country or the European Economic Area. Where required, we use an approved transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and assess supplementary safeguards.
Our Supabase project is hosted in the ap-northeast-1 region (Tokyo, Japan). Japan is covered by a European Commission adequacy decision, so transfers of EEA personal data to this region rely on that decision.
AI requests are routed by OpenRouter (United States) to Google endpoints, which may process content in multiple regions. These transfers rely on Standard Contractual Clauses in the respective providers' data processing terms.
Publication blocker: complete and record the transfer impact assessments for OpenRouter and Google, and confirm the signed DPA/SCC set for each processor.
9. Retention and deletion
We keep personal data only as long as needed for the purposes above, legal obligations, dispute handling, and security. EvrFit automatically deletes food logs and their referenced legacy photos, workout logs, water logs, weight logs, medication logs, synchronized health summaries, plans, and reviews after they are more than 90 days old. The cleanup runs daily, so an expired item may remain for up to about 24 additional hours. New food-analysis photos are not stored by EvrFit. This does not delete information held independently in Apple Health.
Medical reports, your account and profile, avatar, devices, and AI usage/credit records follow separate retention rules and are not deleted by the rolling activity cleanup. You may delete individual items where the app offers that control. Reset Preferences deletes many logs, plans, and medical reports but does not delete your account or all associated data. You can permanently delete your account and associated production data from Profile → Account → Delete Account. Limited security or billing records may be retained only where another documented legal basis requires it and are otherwise deleted or de-identified.
10. Security
We use measures intended to protect data, including authenticated access, owner-scoped database rules, private file storage, encrypted transport, and platform credential storage. No system is completely secure. Access controls protect confidentiality but do not make data anonymous.
11. Your rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, and to withdraw consent. You may also complain to [SUPERVISORY AUTHORITY] or your local data-protection authority.
Send requests to privacy@evrfit.app. We may request proportionate information to verify your identity. We normally respond within one month where the GDPR applies, subject to lawful extensions.
You can revoke Apple Health permissions in iOS settings at any time. As explained in section 5, consent to AI processing of health data is withdrawn by deleting your account, which erases your data immediately.
12. Changes
We may update this policy when our practices, providers, or laws change. We will post the updated date and provide additional notice when a change is material or requires renewed consent.
13. Contact
IntegratingMe d.o.o.[REGISTERED ADDRESS]
privacy@evrfit.app