Privacy Policy
Developer: DataCraft Studio LLC
Contact: support@datacraftllc.com
Effective Date: June 19, 2026
Last Updated: September 7, 2026
This Privacy Policy covers every app published by DataCraft Studio LLC — currently fitr+ — and applies automatically to any app we publish in the future. The General section below applies to all of our apps and to your account. Each app then has its own section describing exactly what that app collects and how it works.
General — Account & All Apps
Your account. Our apps require you to create a DataCraft Studio account — used only for signing in, nothing else — via Firebase Authentication, a service operated by Google.
- What we collect for the account: your email address and a password. Your password is managed entirely by Firebase Authentication — we never see or store it ourselves, Firebase Authentication handles that using industry-standard hashing. Your email address is also stored, associated with your account identifier, in our Cloud Firestore database (Google Cloud) — this is what lets us identify your account for support requests and account-level actions like deletion.
- Account actions: every app offers the same core actions — Sign Up, Sign In, Sign Out, Forgot Password, and Change Password (from within Settings) — plus the ability to permanently delete your account and all data tied to it in every app.
- Deleting your account removes your account itself and all app-specific data associated with it (see each app’s section below for exactly what that includes), across every app you’ve used with that account. This can’t be undone.
Support Communications
If you contact us for support (e.g., by email), we may receive your email address, name, and any information you choose to include in your message. We use this only to respond to your request and provide support — we don’t share it with third parties or use it for marketing.
Third-Party SDKs
Our apps are built with Expo and React Native, which include standard open-source libraries and development tooling. Some of these frameworks may collect minimal anonymous diagnostic data (such as crash signals or SDK version pings) as part of their standard operation, governed by their own privacy policies. We do not currently use analytics or crash-reporting SDKs beyond what’s included by default in the Expo/React Native framework. If that changes, we’ll update this policy and disclose it in-app.
California Residents (CCPA)
If you are a California resident, you have the right to know what personal information is collected about you, request deletion of it, and opt out of its sale. We do not sell personal information. Nearly all app data is tied to your account and deleted via each app’s own account-deletion action (see each app’s section below); the few things stored only on your device (remaining API keys, app settings) are already under your full control without any request needed.
International Users (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, correct, or erase your personal data. Contact us at support@datacraftllc.com for any account-level request, or use each app’s own account-deletion action; anything stored only on your device (remaining API keys, app settings) remains under your full control at all times.
Children’s Privacy
Our apps are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through one of our apps, contact us and we will take steps to address it.
Changes to This Policy
If we make material changes to this policy, we’ll update the “Last Updated” date above. Continued use of any of our apps after changes constitutes acceptance of the updated policy. For significant changes, we’ll make reasonable efforts to notify you in-app.
Contact
DataCraft Studio LLC
support@datacraftllc.com
fitr+
fitr+ is a fitness tracking app. fitr+ requires a DataCraft Studio account (see General above) — used to keep your Energy Points balance (spent on AI coaching answers, AI meal recipes, and AI workout plans) safe across devices, and to sync your workouts, nutrition logs, biometrics, goals, and profile so they survive a reinstall or a new device.
Data tied to your account, stored in Cloud Firestore (Google Cloud):
- Energy Points balance — a points ledger used to pay for AI coaching answers, AI meal recipes, and AI workout plans; server-managed, never directly editable by the app.
- Workout logs — exercise names, sets, reps, weights, and dates.
- Nutrition logs — meal names, calorie counts, macros (protein, carbs, fat), dates, saved meal favorites, and manually-entered foods.
- Biometric entries — body weight and body fat percentage measurements over time. This is the one place your weight history is stored — your profile itself does not duplicate it (see below).
- Goals — target weight, body fat, workout frequency, fitness goal, pace, and activity level.
- User profile — name, date of birth, height, sex, and activity level. Your starting weight, entered during onboarding, is deliberately not included here — it’s stored as a biometric entry instead, so there’s only one place your weight actually lives.
- AI Workout Plan — your most recently generated/saved workout plan, if any.
- Saved recipes — AI-generated recipes you chose to save, including their ingredients, steps and nutrition totals.
- Weekly check-ins & nutrition target history — the app’s periodic nutrition recommendations and the record of target changes you’ve applied.
- Coach selection — which coach avatar you picked and the name you gave them.
- Reminder settings — which reminders you’ve enabled and the times and days you chose. The reminders themselves are scheduled and delivered entirely by your own device (see Notifications below).
- Membership & purchase records — if you buy Energy Points or subscribe to Membership, we store the Apple-issued transaction ID and product ID for each purchase (used to verify it with Apple and prevent double-crediting), and, for Membership, your subscription status and renewal date. See Payments & Subscriptions below for the full picture, including what we never see.
Data stored only on your device (never transmitted to DataCraft Studio LLC): app settings (theme, unit preferences, accessibility settings); meal schedules; the muscle group you assign to a custom exercise; and recurring exercise notes. Workout and meal photos also stay device-only — if you attach a photo to a workout or meal, it’s never uploaded or synced, even though the workout/meal entry itself is.
Notifications: fitr+ has no push-notification capability at all — the app is built with the remote-push entitlement deliberately removed, so nothing we run can ever send your device a message. Every notification the app produces (workout, nutrition, weigh-in and weekly-review reminders, the rest timer, and the Lock Screen rest-timer Live Activity) is scheduled by your own device and delivered by iOS locally. They work with no network connection, and no notification content ever leaves your phone.
iCloud Backup: iOS may include your app data in your iCloud backup by default, controlled entirely by you through your iPhone’s iCloud settings and governed by Apple’s Privacy Policy — we have no access to it.
AI Features (AI Coach, Meal Recipes, Workout Plan Builder): These use Google’s Gemini model through our own backend (Firebase Cloud Functions) — you do not need, and the app does not ask for, your own Gemini API key. When you use one of these features, relevant app context (goals, recent workouts, nutrition summary, and — if you have connected Apple Health — your recent daily step counts) and your prompt are sent from your device to our Cloud Function, which forwards them to Google’s Gemini API using a key we manage, and returns the response to your device. Our backend does not store or log your prompts or Gemini’s responses — the only thing recorded is which feature you used, when, and whether it succeeded, tied to your account (this is also what your Energy Points balance is spent against). Responses are general guidance only, may be inaccurate, and are not a substitute for professional advice — do not enter sensitive medical information. Governed by Google’s Privacy Policy.
Apple Health (Steps & Energy): fitr+ can optionally read three things from Apple Health: your daily step count, your resting (basal) energy burned, and your active energy burned. This is entirely opt-in — the app never reads Apple Health unless you turn on “Sync daily steps” in your goals, and iOS asks your permission separately first. It is read-only (fitr+ never writes to Apple Health), and no other Health data type is requested. Steps appear on your Home dashboard and chart in Trends; the two energy figures are used only to estimate how many calories you burn in a day, so that number can be shown against what you ate. All three are read fresh each time a screen needs them — they are not copied into your account, not stored on our servers, and not part of the account sync above. If you also use Ask Coach, your recent daily step totals are included in the context sent to Google’s Gemini API (see AI Features above) so guidance can account for your general daily activity; your energy figures are not sent. Health data obtained through Apple Health is never used for advertising, marketing, or use-based data mining, and is never sold or shared with data brokers. Turning the toggle off stops all Health reading immediately and removes that data from everywhere it appears in the app.
Barcode Scanning (Packaged Foods): Tapping the barcode button in Log Meal opens your camera to read the barcode on a food package. No image is stored or transmitted — the camera is used only to decode the barcode, and frames are processed on your device by iOS. The decoded barcode number is then sent to Open Food Facts (openfoodfacts.org), a free, community-maintained open database of packaged foods, to look up the product name and nutrition information. Nothing about you is sent with that lookup — no account, no email, no user ID, no other fitness data; the request carries the barcode number and an identifier for the app itself (name, version, and a support contact), which Open Food Facts asks every client to provide so they can reach the developer about problem traffic. Open Food Facts is an independent third party with its own privacy policy; product data it returns is published under the Open Database License. If a product is not found and you add the food yourself, the barcode is saved with that food in your account so the same package is recognized next time without another lookup. Scanning is entirely optional — if you never tap the button, no camera access is requested and no request is ever made.
Food Search: fitr+’s food search runs entirely against a food database built into the app, plus any foods you’ve manually entered yourself — there’s no external food-search service and no data leaves your device to perform a search.
Payments & Subscriptions: Energy Points packages and the Membership subscription are purchased through Apple’s In-App Purchase system. Your payment details (card number, billing address, etc.) are handled entirely by Apple — we never see or store them. When a purchase completes, Apple provides our backend a signed transaction record, which we verify and use to credit your Energy Points or activate Membership; we store the resulting transaction ID, product ID, and (for Membership) your subscription status and renewal date, tied to your account, so your purchase and entitlement survive a reinstall. Apple may also notify our backend directly of subscription events (renewals, cancellations, refunds) so your Membership status stays current without reopening the app. Purchases are governed by Apple’s Privacy Policy and the Apple Media Services Terms — refund requests go to Apple, not to us (see fitr+’s Terms of Service for the full Membership/Energy Points terms).
Deleting your account: available via Profile → Delete Account — permanently deletes your account, Energy Points balance, and all synced workouts/nutrition/biometrics/goals/profile data. This can’t be undone. This is the only way to delete your fitness data — there is no separate local-only wipe. Note: the Apple transaction/product IDs used to verify past purchases (see Payments & Subscriptions above) are retained after account deletion as a fraud-prevention record tied to the transaction itself, not to your account — they’re not linked back to your name, email, or fitness data once your account is deleted.
Your Rights: Access your data anytime in the app, or delete everything (account + all synced data) via Profile → Delete Account.
| Service | Purpose | Data Sent | Their Privacy Policy |
|---|---|---|---|
| Firebase Authentication | Account sign-in | Email, password (handled by Firebase) | Link |
| Cloud Firestore | Storing your Energy Points balance, workouts, nutrition logs, biometrics, goals, profile, and purchase/Membership records | Fitness data + points balance + purchase records | Link |
| Cloud Functions (our backend) | Proxies AI Coach, Meal Recipes, and Workout Plan Builder requests to Gemini using our own key — not stored or logged; also verifies Apple purchase transactions | App context + your prompt (in transit only); Apple transaction data | Link |
| Google Gemini API | Generates AI Coach, Meal Recipes, and Workout Plan Builder responses | App context + your prompt (via our backend) | Link |
| Apple Health (HealthKit) | Reads your daily steps and your resting/active energy, opt-in and read-only, to show progress and estimate calories burned | Nothing is sent to Apple; data is read on-device only | Link |
| Open Food Facts | Looks up a packaged food’s name and nutrition from a scanned barcode | The barcode number and an app identifier only — no account or personal data | Link |
| Apple In-App Purchase | Processes Energy Points and Membership payments | Payment/billing details (never seen by us); transaction record shared with our backend | Link |
DataCraft Studio