Legal
FuelForm Privacy Policy
Effective date: August 30, 2026
This policy explains how FuelForm, provided by Eduard Bazhenov, collects, uses, stores, shares, and protects information. Eduard Bazhenov is the legal controller for FuelForm. FuelForm is a nutrition and wellness tracking app. It is not a medical device and is not a substitute for advice from a qualified healthcare professional.
Information You Provide
FuelForm stores and processes information you choose to enter so the app can calculate nutrition goals, keep food history, personalize insights, and sync your data when enabled.
- Food entries, meal descriptions, calories, macros, meal types, ingredients, saved or custom foods, AI feedback, confidence labels, review flags, selected dates, and barcode values.
- Meal photos or image data you choose to capture or upload for food analysis.
- Voice input after speech recognition converts your speech into text, typed text, and meal descriptions or action parameters you provide through Siri or Shortcuts for food logging, chat, meal suggestions, and nutrient suggestions.
- Profile details such as height, weight, goal weight, activity level, nutrition goals, dietary preferences, eating window, reminders, theme, language, unit settings, streaks, badges, and progress data.
- Account details such as email address, password credentials handled by our account-service providers, full name if provided, and anonymous app user identifiers. Your email address and optional first name may also be used for essential account messages such as verification, password reset, and a one-time welcome email.
- Purchase and subscription status, product identifiers, entitlement status, and related subscription metadata provided by Apple and our subscription-service providers. If you use Apple's official offer-code sheet, FuelForm does not receive or store the code text you enter there.
- Legacy referral records, if a prior app version created them, such as account-linked referral codes, redemption status, participant account identifiers, device-verification status, limited error codes, and timestamps. FuelForm does not currently present its own referral or custom promo codes as a way to unlock Pro.
Information Collected Automatically
FuelForm may create limited technical and operational data automatically to run the app, prevent abuse, maintain security, manage usage limits, troubleshoot errors, and understand onboarding performance.
- A random onboarding or device identifier, onboarding variant, screen views, screen timing, interaction counts, device model, iOS version, and app version may be processed by FuelForm's analytics and cloud-service providers.
- Authentication identifiers, access tokens, request timestamps, usage counts, quota events, device trust headers, device integrity signals, nonces, rate-limit events, any legacy referral eligibility or redemption events, IP-derived network information received by the server, and security audit events may be processed for authentication, fraud prevention, abuse prevention, and service reliability.
- Crash, error, latency, diagnostic, and model-observability metadata may be generated by iOS, Apple, and our operational service providers. FuelForm limits observability data to bounded operational metadata rather than raw meal photos, meal text, prompts, model responses, ingredient names, email addresses, or authentication tokens.
- Local app settings, cached logs, pending sync queues, streak data, and widget or Siri nutrition snapshots may be stored on your device using iOS and App Group storage.
Website Traffic and AI Referral Measurement
When you visit fuelform.pro, Cloudflare processes the standard network request information needed to deliver and protect the public website. This may include an IP address and request headers under Cloudflare's privacy terms. FuelForm uses a separate, limited server-side counter to understand when a recognized AI assistant sends someone to a public website page.
- The counter writes only a fixed AI-source label, the requested public pathname, whether the match came from an exact utm_source value or a referring host, and a count of one. It does not write the raw query string, raw UTM value, raw referrer, IP address, user agent, cookie, account identifier, or device identifier to the Analytics Engine dataset.
- FuelForm does not set a measurement cookie or create a persistent visitor identifier for this counter. Requests with Do Not Track set to 1 or Global Privacy Control enabled are excluded.
- FuelForm uses these aggregate counts to assess website and AI-search discoverability, not for advertising, cross-site tracking, or personal profiles.
- Cloudflare Analytics Engine retains this limited referral dataset for three months.
How We Collect Information
FuelForm collects information only through the methods described below. The categories collected depend on the features and permissions you choose.
- Directly from you when you type or dictate text, take or choose a photo, scan a barcode, answer onboarding or profile questions, set goals or reminders, log meals or water, contact support, or create or sign in to an account.
- From your device and Apple services when you grant a system permission or invoke a feature, including Apple Health values you choose to import, Speech Recognition transcripts, Siri or Shortcuts parameters, App Attest integrity signals, and App Store purchase information.
- From Supabase and RevenueCat when they return authentication, sync, quota, subscription, entitlement, or transaction status needed to operate your account and purchased access.
- Automatically when you use FuelForm, such as app and OS version, device model, pseudonymous account or installation identifiers, request time and type, usage counts, latency, errors, IP-derived server security information, and onboarding interactions.
- By calculation or inference from information already described, such as nutrition estimates, calorie and macro targets, streaks, progress trends, daily totals, and AI-generated guidance.
Sensitive and Consumer Health Data Notice
Nutrition logs, weight, body measurements, age, biological sex, activity information, dietary preferences, goals, Apple Health information, and AI-generated health or nutrition inferences may be considered sensitive personal information or consumer health data in some locations.
We collect these categories directly from you, from Apple Health when you authorize access, from action parameters you provide through Siri or Shortcuts, and from calculations or inferences generated while providing FuelForm's features.
- Purposes: provide food logging, calorie and macro tracking, personalized goals, progress insights, Apple Health sync, AI estimates, meal suggestions, Siri nutrition summaries, account sync, security, and support.
- Categories shared to provide requested features: meal text, photos, dietary context, and nutrition inferences may be processed by Supabase and, only after your AI data-sharing permission, Google Gemini, Tavily, Open Food Facts, and Braintrust as described below; selected nutrition data may be written to Apple Health; and a limited nutrition summary may be returned to Siri or Shortcuts when you invoke that action.
- We do not sell personal information, meal content, Apple Health data, or consumer health data, and we do not use this information for targeted advertising or marketing profiles.
- You can stop optional processing by disabling Apple Health sync, revoking iOS or Siri permissions, not using AI or Siri actions, deleting applicable data, or contacting us.
- Depending on your location, you may request access to, deletion of, or a list of recipients of consumer health data, withdraw applicable consent, or appeal a decision as described under Your Choices and Rights.
AI Meal Analysis and Food Intelligence
When you use AI features such as photo, text, voice, Siri, or barcode logging; chat; meal or nutrient suggestions; day-close summaries; or Progress Coach, FuelForm sends the content and context needed for the request through Supabase to Google Gemini (Google), the AI model provider. Progress Coach may request a new brief when you open that feature.
Depending on the feature, the request may contain a meal photo, barcode, typed or transcribed text, a Siri-provided meal description, dietary preferences and restrictions, calorie or nutrient goals, eating-window and habit context, today's meal names and nutrients, aggregate food history, local time, or derived weight-trend and body-response summaries. Raw Apple Health samples are not sent to the AI service, but values you import into your FuelForm profile and summaries derived on device may be included.
For a barcode or packaged-food lookup, Open Food Facts may receive the barcode, and Tavily may receive the barcode, product name, or packaged-food search description. When AI operational tracing is enabled, Braintrust may receive a pseudonymous account ID, request type, model, latency and token diagnostics, prompt length and whether an image was present, and returned nutrition totals. Braintrust does not receive raw meal text, raw prompts, meal photos, ingredient names, email addresses, or authentication tokens.
The purposes are to return the nutrition estimate, food answer, meal suggestion, day summary, nutrient suggestion, or progress brief you requested; authenticate and route the request; enforce security and usage limits; and diagnose AI reliability. FuelForm does not use this content for advertising. AI results are estimates and may be incomplete, inaccurate, or unsuitable for you. Review and correct entries before relying on them.
- Before the first covered request, FuelForm names Google Gemini, Supabase, Tavily, Open Food Facts, and Braintrust; identifies the data and purposes above; and asks you to choose Allow and Enable AI or Continue Without AI. Declining sends no AI request content to those providers and leaves manual logging available.
- You can turn AI data sharing off at any time in Settings > AI Data Processing. Turning it off blocks future AI requests. If the named recipients or data uses materially change, FuelForm will ask for a new choice before using the changed processing.
- FuelForm does not use meal photos, meal text, voice text, AI conversations, or Apple Health data for advertising.
- Requests may include device integrity and quota data to prevent abuse and enforce daily limits aligned with your subscription plan.
- Previously approved meals may be reused from your local history. New AI estimates require an online analysis request.
Open Food Facts Attribution
Barcode product data identified as coming from Open Food Facts is provided by Open Food Facts contributors under the Open Database License (ODbL) 1.0. Attribution and share-alike requirements apply to reuse of the database.
Apple Health
FuelForm integrates with Apple Health only after you grant permission. Apple Health lets you control each data type separately, and you can change those permissions at any time in iOS Settings.
- FuelForm may read active energy, basal energy, steps, body mass, height, biological sex, and date of birth or age when you allow access.
- FuelForm may write dietary energy, protein, carbohydrates, total fat, sugar, fiber, and sodium to Apple Health when Apple Health sync is enabled.
- Raw Apple Health samples are queried on your device. If you choose to import a value such as age, sex, height, or weight into your FuelForm profile, the value you accept becomes profile data and may sync to FuelForm's cloud service. Derived progress summaries may be sent for an AI feature as described above.
- FuelForm does not use HealthKit data for advertising, does not sell HealthKit data, and does not share HealthKit data with analytics or advertising services.
- You can turn off Health sync in FuelForm or revoke permissions in iOS Settings > Privacy & Security > Health > FuelForm.
Siri, App Shortcuts, and Speech
FuelForm makes specific actions discoverable to Apple system features such as Siri, Spotlight, and Shortcuts. These integrations are optional. Apple processes the invocation and passes FuelForm the selected action and any resolved parameters under Apple's privacy practices and your device settings.
For a command spoken to Siri, FuelForm receives the action and parameters Apple passes, not Siri's raw recording. FuelForm's separate in-app voice logger uses Apple's Speech framework. Depending on the language, device, downloaded speech assets, and system capabilities, microphone audio may be processed on device or sent to Apple for transcription. To improve food-name accuracy, FuelForm may also provide Apple Speech with a limited set of short structured ingredient names from valid meals in your locally available recent history as contextual hints; it does not include free-form meal names, full meal descriptions, or nutrition totals in those hints.
- Log Meal: Siri or Shortcuts passes the meal description to FuelForm, may repeat or display that text in its confirmation, and opens the app. If you previously chose Allow and Enable AI and have not turned it off, FuelForm submits up to 500 characters through the normal AI, local persistence, secure sync, and optional Apple Health flow without a second in-app confirmation. Otherwise the provider boundary blocks the AI request.
- Today's Nutrition: after local device authentication, FuelForm reads a cached on-device snapshot and returns calories logged, calorie goal or remaining amount, and protein to Siri or Shortcuts. The result may be spoken, displayed, or passed by a custom shortcut to another action or service.
- Open Meal Camera: the action opens FuelForm's camera. No photo or barcode is submitted until you capture or select it and then choose to send it.
- Start Voice Logging: the action opens FuelForm and starts its microphone and Speech flow after required permissions. The transcript stays in the composer until you choose to send it for analysis.
- You can manage FuelForm's Siri access, suggested actions, custom shortcuts and automations, Siri history, microphone access, and Speech Recognition access in Apple's Siri, Shortcuts, and privacy settings.
Camera, Photos, Microphone, Speech, and Notifications
FuelForm asks for protected device permissions only when a feature needs them. You can deny or revoke these permissions through iOS Settings.
- Camera access is used to take food photos and scan barcodes for calorie tracking.
- Photo library access is used if you choose an existing image for food analysis.
- Microphone and Speech Recognition access are used to convert voice input into food logging text. The app does not save a voice recording, but Apple may process the live audio and limited contextual food-name hints as described above.
- Notifications are scheduled on your device for reminders, streaks, badges, summaries, and other app alerts if you allow them.
Accounts, Sync, and Authentication
FuelForm uses Supabase for authentication, temporary anonymous onboarding sessions, verified email/password accounts, Apple and Google sign-in, database sync, Edge Functions, and security controls. FuelForm may create an anonymous Supabase identity while onboarding so server data can be scoped to a stable identifier, but that temporary identity does not provide access to the main app. Before entering the app, you must create or sign in to an account with Apple, Google, or a verified email address. Apple or Google also processes the identity and authorization data needed when you choose its sign-in service. FuelForm uses an email-delivery provider to send essential account messages, including a one-time welcome email after registration.
- Food entries, ingredients, saved foods, hydration entries and goals, profile data including activity level, usage records, device daily usage, security events, legacy referral records, and related records may be stored in Supabase and protected with access controls.
- When you create or sign in with email/password, Supabase processes the credentials and identity information needed to authenticate you. Email registration requires verification before FuelForm opens the main app.
- Account-linked storage supports ownership controls, cross-device sync, and account recovery and may keep data on our servers rather than only on your device.
- If signing in changes to an existing account, FuelForm asks whether to merge or discard eligible local data before continuing. A merge may reassign unsynced meal drafts, hydration entries and goals, manual weigh-ins, and matching pending Apple Health changes to the destination account; merged server-eligible records may then sync under that account. A separately marked meal accepted during anonymous onboarding is transferred only through a short-lived server capability and can also be discarded.
Purchases and Subscriptions
FuelForm uses Apple's App Store purchase systems and RevenueCat to manage premium access, product availability, subscription status, purchase restoration, entitlements, Apple subscription offer-code results, and billing-related support. We do not receive or store your full payment card number.
When you choose Redeem App Store Offer Code, Apple presents and controls its native sheet. FuelForm does not receive, read, or store the code text you type or paste into that sheet.
- RevenueCat may receive app user identifiers, purchase tokens, product identifiers, offering information, entitlement status, renewal status, and related subscription metadata returned through Apple's purchase system.
- Apple processes App Store payments, refunds, taxes, billing, offer-code entry, validation, eligibility, and redemption under Apple's own terms and privacy practices.
- After Apple's sheet closes, FuelForm may refresh bounded redemption-flow status and the resulting product, transaction, or entitlement state. FuelForm does not include the entered code, clipboard contents, or Apple sheet contents in its analytics.
- Premium status may be saved locally and in service-provider systems so the app can show the correct experience. Opening or closing the offer-code sheet does not itself grant premium access.
Legacy Referral Records
FuelForm does not currently present its own referral codes, custom promo-code field, or external code validator as a way to unlock FuelForm Pro. Apple's official subscription offer-code sheet is separate and FuelForm does not receive or store the code entered there. If an earlier app version created FuelForm referral or custom-redemption records, FuelForm may retain and process a limited legacy ledger only for record integrity, fraud prevention, dispute handling, and legal or accounting obligations.
- Legacy records may include participant account identifiers, a referral-code record, a verified device identifier, redemption or fulfillment status, expiration dates, attempt counts, limited error codes, and timestamps.
- FuelForm does not read your contacts or send invitations for you.
- Where no longer needed, participant account links may be removed or tombstoned.
How We Use Information
FuelForm uses information to operate, secure, and improve the app; provide food logging, AI analysis, nutrition insights, Siri and Shortcuts actions, Apple Health sync, widgets, reminders, streaks, badges, progress views, subscriptions, account sync, support, and legal compliance.
- We use information to provide features you request, personalize nutrition targets, estimate meals, answer food questions, suggest meals, track progress, and sync enabled data.
- We use limited technical data to authenticate users, enforce quotas, protect against abuse, diagnose crashes, debug errors, maintain security, and measure onboarding and app performance.
- We use your account email address and, when available, your first name to send essential account communications. The one-time welcome message is operational and is not a promotional mailing list.
- We may use aggregated or de-identified data that does not reasonably identify you to understand app performance, evaluate AI quality, improve product flows, and plan features.
- FuelForm does not include third-party advertising SDKs and does not track your activity across other companies' apps or websites for advertising.
- We may disclose information if required by law, to protect users or the service, to enforce our terms, or to operate services through cloud, AI, food-data, subscription, observability, Apple, and identity providers you choose.
Legal Bases and Consent
Where privacy laws require a legal basis, we process information as needed to provide the service or perform our agreement with you; with consent for optional permissions or sensitive processing where required; for legitimate interests such as securing, debugging, and improving FuelForm when those interests are not overridden by your rights; and to meet legal obligations or establish and defend legal claims.
- You may withdraw optional permissions through iOS Settings or app settings, but some features may stop working.
- Where applicable law requires separate affirmative or explicit consent, FuelForm will rely on that consent or another valid legal exception before the covered collection or sharing; merely reading this policy is not consent.
- Withdrawal of consent does not affect processing that occurred before withdrawal or records we must keep for legal, security, fraud prevention, billing, legacy-record integrity, or dispute reasons.
- Where processing is based on legitimate interests, you may object by contacting us. You may also have the right to complain to your local privacy or data-protection authority.
Sharing and Service Providers
FuelForm uses the named providers below to operate the app. We require every processor acting for FuelForm to provide the same or equivalent protection of personal information described in this policy and required by applicable law and applicable platform rules, to process it only for documented and authorized purposes, and to apply appropriate confidentiality, security, deletion, and transfer safeguards. They may not use FuelForm personal information for their own advertising. Apple and Google may also act independently when you choose their platform or identity services, under their own privacy notices.
- Supabase: temporary anonymous onboarding authentication, verified account authentication, account identifiers, email and profile metadata, database storage and sync, Edge Function request routing, AI request content in transit, security events, quotas, server logs, onboarding analytics, and account deletion.
- Resend: account email address, optional first name, transactional message content, and limited delivery metadata used to send account verification, password-reset, and one-time welcome emails.
- Google Gemini (Google): the AI request content and context described in AI Meal Analysis and Food Intelligence, used to generate the requested estimate, answer, suggestion, summary, or brief. Google also processes sign-in identity data if you choose Google sign-in.
- Tavily and Open Food Facts: barcodes, product names, or packaged-food search descriptions used only when a barcode or packaged-food lookup needs external product evidence.
- Braintrust: the limited pseudonymous AI diagnostics and nutrition totals described above when tracing is enabled; no raw meal text or photos.
- Apple: Sign in with Apple when selected, Siri, Shortcuts, Spotlight, Speech Recognition, Apple Health, notifications, App Store purchases, and other platform features you enable.
- RevenueCat: pseudonymous app user identifier, product and purchase identifiers, subscription status, entitlements, purchase restoration, renewal status, and related transaction metadata.
Storage, Retention, and Deletion
Retention depends on where the data is stored and the feature involved. We aim to keep personal information only as long as needed for the app, security, legal compliance, billing, dispute resolution, and user requests.
- Local settings, protected profile cache, profile photo, manual weigh-ins, failed drafts, barcode cache, streaks, badges, widget or Siri snapshots, and pending sync data remain on your device for the feature's operational life or until you delete them, clear applicable data, or remove the app. Cached barcode results are treated as stale after about 30 days and the cache is size-limited.
- Widgets may visibly show nutrition totals, goals, streak information, and the latest meal to people who can view your device. Siri or Shortcuts output may be spoken, displayed, or forwarded by a shortcut you create.
- Synced food entries, ingredients, saved foods, hydration entries and goals, profile data, account data, and usage records in FuelForm's cloud service remain until deleted, overwritten, or no longer needed for the service, subject to backup, legal, security, and fraud-prevention retention. Removing the app does not by itself delete server data.
- Onboarding analytics and operational usage data are intended for limited product, abuse prevention, and reliability purposes. Security, quota, and audit records may be retained as needed to protect the service.
- FuelForm sends meal photos through Supabase to Google Gemini for analysis but does not save the raw photo in your FuelForm food history or cloud food-entry record. Named providers may retain request or diagnostic data for the limited periods allowed by their contracts, service terms, configuration, and applicable law.
- Limited legacy referral or redemption records may be retained with account links removed or tombstoned for record integrity, fraud prevention, dispute handling, and legal or accounting requirements.
- Purchase records may be retained by Apple, subscription-service providers, or us for fraud prevention, accounting, tax, refund, entitlement, and legal compliance.
- Resend may retain limited transactional-email and delivery metadata for the periods permitted by its service terms, configuration, and applicable law.
- Deletion from active systems and service-provider backups may take additional time where permitted by law. You can clear food history, export a limited food-log CSV, delete your account, or submit a broader privacy request using in-app settings or by emailing support@fuelform.pro.
Your Choices and Rights
Depending on where you live, you may have rights to access, confirm, correct, export, delete, restrict, object to, or appeal decisions about certain personal information. You may also have rights relating to sensitive personal information or consumer health data.
- You can change iOS permissions for camera, photos, microphone, Speech Recognition, notifications, Apple Health, and FuelForm's Siri integration at any time.
- You can stop Apple Health sync by turning it off in FuelForm settings or revoking Health permissions in iOS Settings.
- You can review the named AI-request recipients and turn AI data sharing on or off in Settings > AI Data Processing. This choice separately covers any Apple Health-derived height, weight, age, biological sex, activity or body context, and derived progress summaries included in an AI request.
- You can clear meal records from Settings > Data & Privacy > Clear Food History. This does not delete your account or profile.
- Settings > Data & Privacy > Export My Data creates a limited CSV containing food-log date, time, description, calories, protein, carbohydrates, and fat; it is not a complete export of every account record.
- You can permanently request deletion of your FuelForm account and associated active server data from Settings > Data & Privacy > Delete Account. Deleting your FuelForm account does not cancel an Apple subscription.
- You can manage or remove FuelForm actions and automations in Siri and Shortcuts settings, and manage Siri request history through Apple's settings.
- You can request access, correction, a broader export, deletion, restriction, objection, a list of consumer-health-data recipients, or privacy help by emailing support@fuelform.pro. We may need to verify your request before acting on it.
- If we decline a privacy request, you may appeal by replying to the decision or emailing support@fuelform.pro with 'Privacy Appeal' in the subject. Depending on your location, you may also complain to the relevant privacy regulator or attorney general.
International Transfers
FuelForm and its providers may process and store information in countries other than your country of residence. Privacy laws in those countries may differ from the laws where you live.
- When required, we rely on appropriate safeguards such as contractual protections, data-processing terms, standard contractual clauses, consent, or other lawful transfer mechanisms.
- Supabase, Resend, Google, RevenueCat, Apple, Tavily, Open Food Facts, and Braintrust may maintain infrastructure or support operations in multiple regions.
Security
We use reasonable technical and organizational safeguards designed to protect information, including TLS in transit, iOS Keychain for sensitive local secrets, access controls, authentication controls, device trust checks, rate limits, quotas, and security logging.
- No app, network, database, or AI service can be guaranteed to be completely secure.
- You are responsible for keeping your device, Apple ID, account credentials, and email account secure.
- If you believe your account or data has been compromised, contact support@fuelform.pro.
Children's Privacy
FuelForm is not intended for children under 13, or the minimum age required in your country. We do not knowingly collect personal information from children. If you believe a child provided personal information, contact us so we can delete it.
Changes to This Policy
We may update this policy when FuelForm changes or when legal, platform, security, provider, or operational requirements change. The effective date above will be updated when the policy changes materially. If a change is material, we may provide additional notice in the app, by email, or by another reasonable method.
Contact
Questions about privacy, support, access, correction, export, deletion, withdrawal of consent, or a privacy-request appeal can be sent by email.
support@fuelform.pro