Animal Based Coach
Privacy Policy
Last updated: 3 September 2026
This policy explains what Animal Based Coach collects, why, and what we do with it. It is written to be read, not to be survived.
It applies to a health app that may hold your weight, your bloodwork, your medications and your conversations about all three. We have tried to write it the way we'd want it written for us.
The short version
- You sign in with Sign in with Apple. There is no password — we never ask you to invent a secret, so there is no secret of yours for us to lose.
- Your data is stored on your phone and backed up to your account, so a new phone is a sign-in rather than a fresh start. No other user can read your backup, and we don't read it except as needed to run the service.
- To answer you, the app sends the information the coach needs to an AI model provider. A few other services help run the app and your subscription — the full list is below.
- We do not sell your data. We do not share your health data, meals, photos or chats with anyone but the services that run the app, listed below. One exception, stated plainly: to measure whether our own ads work, the app includes Meta's measurement SDK and a RevenueCat integration that can report installs and subscriptions to Meta. If you allow tracking when iOS asks, that includes a device identifier; if you decline, only Apple's privacy-preserving, aggregated attribution is used and you are not identified. Details below.
- You can delete everything, permanently — on your phone and on our server — from inside the app: Profile → Delete my account and all data.
What we collect, and where it lives
Everything you enter is stored on your device, and backed up to your account so it survives a lost or replaced phone. That includes:
- Your name and email
- Your body stats (sex, age, height, weight, goal weight)
- Your goals, training schedule, food preferences, budget and allergies
- Any health conditions, medications and blood test results you choose to enter
- Your daily check-ins (how you feel, energy, digestion, sleep, weight)
- Any Apple Health data you choose to connect (HRV, resting heart rate, steps, sleep, weight, body fat and active energy)
- Your meal plans, experiments and findings
- Your conversations with the coach
Your account and the backup
Authentication and the backup are handled by Supabase, a hosted Postgres provider, acting as our data processor. The backup is protected by row-level security: on every single request, the database itself enforces that no other user can read or write your data. It is encrypted in transit and at rest. Running the service does require an administrative key that can technically reach the data, which is exactly why the promise below matters:
We do not sign in as you and read it. We do not mine it, profile you with it, or use it to train anything.
Sign in with Apple
If you use Sign in with Apple and choose to hide your email, we receive only Apple's relay address. We never see your real one, and we do not try to.
Apple Health
Connecting Apple Health is optional and read-only — we never write anything back to Health. If you connect it, we read only seven things: heart-rate variability, resting heart rate, steps, sleep, weight, body fat percentage, and active energy. We ask for nothing else. You can revoke it at any time in iOS Settings → Health → Data Access & Devices, and the app will simply stop showing those metrics rather than fill in the gap with a guess. Apple Health data is never used for advertising or marketing, is never sold, and is never shared with data brokers. It is used only to show you those metrics and to inform your coaching.
Health information
Some of what you can enter is sensitive: blood markers, medications, health conditions. You choose whether to provide any of it. The app works without it; the coaching is simply less specific. We do not ask about, and do not collect, any eating-disorder history.
Where your data is sent
To answer a question, build your meal plan, or read your week, the app sends the relevant parts of the above to an AI model provider (currently Google Gemini) through our backend.
- Our backend passes the request to the model and passes the answer back. It is not a database and is not built to keep your health data — but the server it runs on (Render) may hold short-lived operational logs for a limited period, as any web server does, to keep the service running and secure.
- The model provider processes the request under their own terms. They do not use data sent through the paid API to train their models.
- Requests are sent over HTTPS.
The companies that help run the app
These are the service providers that may receive some of your data so the app can work. This is the complete list.
- Supabase — stores your account and your cloud backup.
- Google (Gemini API) — processes each coaching request, including any blood-test photo you scan. Not used for training.
- Render — hosts the backend server your requests pass through.
- RevenueCat — manages your subscription. It receives your account's user ID and your purchase history so it can track whether your subscription is active. If you allowed tracking, it also passes a device identifier and your IP address to Meta so the install or subscription can be attributed to an ad.
- Meta (Facebook SDK) — ad measurement only. It receives app-lifecycle events (the app was installed, opened, a subscription started) so we can tell whether an ad led to them. It never receives your health data, meals, photos, chats or diet. When you allow tracking in the iOS prompt, Meta may link those events to your device's advertising identifier; when you decline, Meta receives only app-open events with an app-scoped random ID and aggregated measurement, neither of which identifies you.
- Expo (EAS) — delivers the app and its updates to your phone.
- Apple — provides Sign in with Apple and processes your payments.
Nobody else receives your data, for any purpose.
If you use the restaurant finder, the app sends the city or approximate location you provide, so the coach can suggest places near you. We don't store your exact GPS position; if we can't turn your location into a place name, the app may store approximate coordinates — rounded to roughly 110 metres — with that feature and in your backup.
If you scan a blood test report, or photograph a meal so the coach can estimate what is on the plate, the photo is sent to the model to read it. It travels the same path as any other coaching request — through our backend — and is not stored on our server or used for training; the same note above about short-lived operational logs applies. Meal photos are downscaled on your phone before they are sent.
Tracking and the iOS "Allow tracking" prompt
Before your subscription starts, iOS asks whether the app may track you. This exists for one reason: measuring our own advertising. If you tap Allow, Meta and RevenueCat may use your device's advertising identifier, a per-app device identifier and your IP address to attribute the install or purchase to an ad. If you tap Ask App Not to Track, your advertising identifier is never collected and no identifier-based attribution runs; Meta's SDK still receives standard app-open events carrying an app-scoped random ID and, like any internet request, your IP address, and attribution uses only Apple's SKAdNetwork and Meta's aggregated measurement — neither of which identifies you to us or to Meta. Your choice changes nothing else about the app, and you can change it any time in iOS Settings → Privacy & Security → Tracking. Health data, meals, photos and chats are never used for advertising, whatever you choose.
What we do NOT do
- We do not sell your personal information.
- We do not share your health data, meals, photos or chats with advertisers or data brokers.
- We do not track you across other apps or websites unless you allow tracking in the iOS prompt — and then only to measure our own ads.
- The only advertising-related SDK in the app is Meta's measurement SDK, described above; there are no other analytics or advertising SDKs.
- We do not ask you for a password, so we cannot leak one.
- We do not read any Apple Health data beyond the seven things listed above, and only if you connect it.
Payments
Subscriptions are handled by Apple's In-App Purchase system. Apple processes the payment. We never see your card number. Through RevenueCat we receive your subscription status and purchase history (which product, when it renews) — never your payment details.
Your rights
- Delete everything: Profile → Delete my account and all data. This deletes your account and your backup on our server and wipes the app on your phone. It is immediate and permanent. If the server deletion fails for any reason, the app tells you and deletes nothing — you will never be shown a deletion that did not happen. Two things sit outside this: the subscription record Apple and our billing provider (RevenueCat) keep for accounting, and short-lived server logs that expire on their own. Deleting your account does not cancel your subscription — to stop billing, cancel separately in Settings → your Apple ID → Subscriptions.
- Delete your conversations only: Profile → Delete all coach conversations. This clears your chat history from your phone and your backup. A small set of distilled facts the coach keeps so it stays useful across chats — its working memory — is stored separately and is not removed by this action; to erase everything, use Delete my account and all data.
- Access or correct your data: all of it is visible and editable in the app. If you want a copy in machine-readable form, email us and we'll send it.
- If you are in the EU/UK (GDPR) or California (CCPA/CPRA): the rights those laws give you — access, correction, deletion, portability, and not having your data sold — are all available above or on request. We do not sell personal information and never have.
We keep your backup for as long as your account exists. Delete the account and it goes with it, immediately.
Children
Animal Based Coach is not intended for anyone under 13, and the app does not accept an age below 13. If you believe a child has used the app, delete the account in-app; that removes everything.
This is not medical advice
Animal Based Coach provides nutrition and lifestyle coaching. It is not a medical device, and it does not diagnose, treat, cure or prevent any disease. Nothing in the app is a substitute for advice from a qualified healthcare professional. Do not use it to make medical decisions, and speak to your doctor before making significant changes to your diet — particularly if you are pregnant, have a medical condition, or take medication.
Changes
If this policy changes materially, we will update the date at the top and notify you in the app.
Contact
Questions about your privacy, or this policy: carterpace26@gmail.com