Legal
FuelForm Privacy Policy
Effective date: July 20, 2026
This policy explains how FuelForm, provided by the developer or seller identified on FuelForm's App Store product page, collects, uses, stores, shares, and protects information. FuelForm is a nutrition and wellness tracking app. It is not a medical device and is not a substitute for advice from a qualified healthcare professional.
Information You Provide
FuelForm stores and processes information you choose to enter so the app can calculate nutrition goals, keep food history, personalize insights, and sync your data when enabled.
- Food entries, meal descriptions, calories, macros, meal types, ingredients, saved or custom foods, AI feedback, confidence labels, review flags, selected dates, and barcode values.
- Meal photos or image data you choose to capture or upload for food analysis.
- Voice input after speech recognition converts your speech into text, typed text, and meal descriptions or action parameters you provide through Siri or Shortcuts for food logging, chat, meal suggestions, and nutrient suggestions.
- Profile details such as height, weight, goal weight, activity level, nutrition goals, dietary preferences, eating window, reminders, theme, language, unit settings, streaks, badges, and progress data.
- Account details such as email address, password credentials handled by Supabase, full name if provided, Google sign-in information if you choose Google OAuth, and anonymous app user identifiers.
- Purchase and subscription status, product identifiers, entitlement status, and related subscription metadata provided by Apple and RevenueCat.
- Referral information such as your account-linked referral code, a code you redeem, referral and reward status, friends-referred count, and promotional months earned.
Information Collected Automatically
FuelForm may create limited technical and operational data automatically to run the app, prevent abuse, maintain security, manage usage limits, troubleshoot errors, and understand onboarding performance.
- A random onboarding or device identifier, onboarding variant, screen views, screen timing, interaction counts, device model, iOS version, and app version may be sent to Supabase onboarding analytics.
- Supabase authentication identifiers, access tokens, request timestamps, usage counts, quota events, device trust headers, device integrity signals, nonces, rate-limit events, referral eligibility and redemption events, IP-derived network information received by the server, and security audit events may be processed for authentication, fraud prevention, abuse prevention, and service reliability.
- Crash, error, latency, diagnostic, and model-observability metadata may be generated by iOS, Apple, Supabase, Braintrust if enabled, or other service providers. We configure observability to avoid storing raw meal photos and to summarize model inputs where practical.
- Local app settings, cached logs, pending sync queues, streak data, and widget or Siri nutrition snapshots may be stored on your device using iOS and App Group storage.
Sensitive and Consumer Health Data Notice
Nutrition logs, weight, body measurements, age, biological sex, activity information, dietary preferences, goals, Apple Health information, and AI-generated health or nutrition inferences may be considered sensitive personal information or consumer health data in some locations.
We collect these categories directly from you, from Apple Health when you authorize access, from action parameters you provide through Siri or Shortcuts, and from calculations or inferences generated while providing FuelForm's features.
- Purposes: provide food logging, calorie and macro tracking, personalized goals, progress insights, Apple Health sync, AI estimates, meal suggestions, Siri nutrition summaries, account sync, security, and support.
- Categories shared to provide requested features: meal text, photos, dietary context, and nutrition inferences may be processed by Supabase and the AI or food-data providers listed below; selected nutrition data may be written to Apple Health; and a limited nutrition summary may be returned to Siri or Shortcuts when you invoke that action.
- We do not sell personal information, meal content, Apple Health data, or consumer health data, and we do not use this information for targeted advertising or marketing profiles.
- You can stop optional processing by disabling Apple Health sync, revoking iOS or Siri permissions, not using AI or Siri actions, deleting applicable data, or contacting us.
- Depending on your location, you may request access to, deletion of, or a list of recipients of consumer health data, withdraw applicable consent, or appeal a decision as described under Your Choices and Rights.
AI Meal Analysis and Food Intelligence
When you use AI features such as photo, text, voice, Siri, or barcode logging; chat; meal or nutrient suggestions; day-close summaries; or Progress Coach, FuelForm sends the content and context needed for the request to our Supabase Edge Function over TLS. Progress Coach may request a new brief when you open that feature.
Depending on the feature, the request may contain a meal photo, barcode, typed or transcribed text, a Siri-provided meal description, dietary preferences and restrictions, calorie or nutrient goals, eating-window and habit context, today's meal names and nutrients, aggregate food history, local time, or derived weight-trend and body-response summaries. Raw Apple Health samples are not sent to the AI service, but values you import into your FuelForm profile and summaries derived on device may be included.
The server may process the request with Google Gemini and, when needed for packaged foods or barcode enrichment, Tavily and Open Food Facts. AI results are estimates and may be incomplete, inaccurate, or unsuitable for you. You are responsible for reviewing and correcting entries before relying on them.
- Do not submit information you do not want processed by our AI and data providers, including Google Gemini, Supabase, Tavily, Open Food Facts, and Braintrust if observability is enabled.
- FuelForm does not use meal photos, meal text, voice text, AI conversations, or Apple Health data for advertising.
- Requests may include device integrity and quota data to prevent abuse and enforce daily limits aligned with your subscription plan.
- Text or barcode logging may use an on-device food database or cache when offline or when AI is unavailable.
Apple Health
FuelForm integrates with Apple Health only after you grant permission. Apple Health lets you control each data type separately, and you can change those permissions at any time in iOS Settings.
- FuelForm may read active energy, basal energy, steps, body mass, height, biological sex, and date of birth or age when you allow access.
- FuelForm may write dietary energy, protein, carbohydrates, total fat, sugar, fiber, and sodium to Apple Health when Apple Health sync is enabled.
- Raw Apple Health samples are queried on your device. If you choose to import a value such as age, sex, height, or weight into your FuelForm profile, the value you accept becomes profile data and may sync to Supabase. Derived progress summaries may be sent for an AI feature as described above.
- FuelForm does not use HealthKit data for advertising, does not sell HealthKit data, and does not share HealthKit data with analytics or advertising services.
- You can turn off Health sync in FuelForm or revoke permissions in iOS Settings > Privacy & Security > Health > FuelForm.
Siri, App Shortcuts, and Speech
FuelForm makes specific actions discoverable to Apple system features such as Siri, Spotlight, and Shortcuts. These integrations are optional. Apple processes the invocation and passes FuelForm the selected action and any resolved parameters under Apple's privacy practices and your device settings.
For a command spoken to Siri, FuelForm receives the action and parameters Apple passes, not Siri's raw recording. FuelForm's separate in-app voice logger uses Apple's Speech framework. Because the app does not require on-device-only recognition, microphone audio may be sent to and processed by Apple for transcription depending on the language, device, and system capabilities.
- Log Meal: Siri or Shortcuts passes the meal description to FuelForm, may repeat or display that text in its confirmation, and opens the app. FuelForm then submits up to 500 characters through the normal AI, local persistence, Supabase sync, and optional Apple Health flow without a second in-app confirmation.
- Today's Nutrition: after local device authentication, FuelForm reads a cached on-device snapshot and returns calories logged, calorie goal or remaining amount, and protein to Siri or Shortcuts. The result may be spoken, displayed, or passed by a custom shortcut to another action or service.
- Open Meal Camera: the action opens FuelForm's camera. No photo or barcode is submitted until you capture or select it and then choose to send it.
- Start Voice Logging: the action opens FuelForm and starts its microphone and Speech flow after required permissions. The transcript stays in the composer until you choose to send it for analysis.
- You can manage FuelForm's Siri access, suggested actions, custom shortcuts and automations, Siri history, microphone access, and Speech Recognition access in Apple's Siri, Shortcuts, and privacy settings.
Camera, Photos, Microphone, Speech, and Notifications
FuelForm asks for protected device permissions only when a feature needs them. You can deny or revoke these permissions through iOS Settings.
- Camera access is used to take food photos and scan barcodes for calorie tracking.
- Photo library access is used if you choose an existing image for food analysis.
- Microphone and Speech Recognition access are used to convert voice input into food logging text. The app does not save a voice recording, but Apple may process the live audio as described above.
- Notifications are scheduled on your device for reminders, streaks, badges, summaries, and other app alerts if you allow them.
Accounts, Sync, and Authentication
FuelForm uses Supabase for authentication, automatically created anonymous user sessions, optional email/password accounts, optional Google OAuth, database sync, and security controls. Anonymous authentication allows server data to be scoped to a stable app user identifier before you create a named account.
- Food entries, ingredients, saved foods, profile data, usage records, device daily usage, security events, referrals, and related records may be stored in Supabase and protected with row-level security and access controls.
- If you sign in with email/password or Google, Supabase and the identity provider process the credentials and identity information needed to sign you in.
- Cross-device sync and account recovery may require storing account-linked data on our servers rather than only on your device.
Purchases and Subscriptions
FuelForm uses Apple purchase systems and RevenueCat to manage premium access, product availability, subscription status, purchase restoration, entitlements, and billing-related support. We do not receive or store your full payment card number.
- RevenueCat may receive app user identifiers, purchase tokens, product identifiers, offering information, entitlement status, renewal status, and related subscription metadata.
- Apple processes App Store payments, refunds, taxes, and billing under Apple's own terms and privacy practices.
- Premium status may be saved locally and in service-provider systems so the app can show the correct experience.
Referral Rewards
If you use Refer a Friend, FuelForm generates an account-linked code and processes referral and promotional-entitlement records through Supabase and RevenueCat. Referral eligibility is checked using authenticated account dates, verified-account status, and a verified device identifier to prevent duplicate or fraudulent rewards.
- Records may include referrer and invited-user account identifiers, the referral code, a verified device identifier, redemption and fulfillment status, reward expiration dates, attempt counts, limited error codes, and timestamps.
- The referrer sees aggregate friends-referred and free-months-earned counts, not the invited person's email address, food data, or profile details.
- FuelForm does not read your contacts or send invitations for you. The system share sheet lets you choose the recipient and app, and the selected third party processes what you share under its own terms.
- A limited referral ledger may remain after account deletion with participant account links removed or tombstoned, where needed to preserve earned rewards, prevent repeated claims or fraud, resolve disputes, and meet legal or accounting obligations.
How We Use Information
FuelForm uses information to operate, secure, and improve the app; provide food logging, AI analysis, nutrition insights, Siri and Shortcuts actions, Apple Health sync, widgets, reminders, streaks, badges, progress views, subscriptions, referral rewards, account sync, support, and legal compliance.
- We use information to provide features you request, personalize nutrition targets, estimate meals, answer food questions, suggest meals, track progress, and sync enabled data.
- We use limited technical data to authenticate users, enforce quotas, protect against abuse, diagnose crashes, debug errors, maintain security, and measure onboarding and app performance.
- We may use aggregated or de-identified data that does not reasonably identify you to understand app performance, evaluate AI quality, improve product flows, and plan features.
- FuelForm does not include third-party advertising SDKs and does not track your activity across other companies' apps or websites for advertising.
- We may disclose information if required by law, to protect users or the service, to enforce our terms, or to operate services through providers such as Supabase, Google Gemini, RevenueCat, Apple, Tavily, Open Food Facts, Braintrust if enabled, and identity providers you choose.
Legal Bases and Consent
Where privacy laws require a legal basis, we process information as needed to provide the service or perform our agreement with you; with consent for optional permissions or sensitive processing where required; for legitimate interests such as securing, debugging, and improving FuelForm when those interests are not overridden by your rights; and to meet legal obligations or establish and defend legal claims.
- You may withdraw optional permissions through iOS Settings or app settings, but some features may stop working.
- Where applicable law requires separate affirmative or explicit consent, FuelForm will rely on that consent or another valid legal exception before the covered collection or sharing; merely reading this policy is not consent.
- Withdrawal of consent does not affect processing that occurred before withdrawal or records we must keep for legal, security, fraud prevention, billing, referral-reward, or dispute reasons.
- Where processing is based on legitimate interests, you may object by contacting us. You may also have the right to complain to your local privacy or data-protection authority.
Sharing and Service Providers
FuelForm uses service providers to operate the app. They may process information only as needed to provide their services to us or to you, subject to their own terms, privacy practices, and data-processing obligations. We require processors acting for FuelForm to protect personal information consistently with this policy and applicable law and to process it only for authorized purposes.
- Supabase: authentication, database storage, Edge Functions, security events, quotas, and sync.
- Google: OAuth sign-in when you choose Continue with Google, and Google Gemini for AI food analysis, chat, recommendations, and related model processing.
- Apple: Siri, Shortcuts, Spotlight, Speech Recognition, Apple Health, notifications, App Store purchases, and other platform features you enable.
- RevenueCat: subscription status, entitlements, purchase restoration, and promotional referral access.
- Tavily and Open Food Facts: packaged food, barcode, and nutrition enrichment when needed.
- Braintrust or similar diagnostics providers if enabled: observability, logs, model traces, crash or performance diagnostics.
Storage, Retention, and Deletion
Retention depends on where the data is stored and the feature involved. We aim to keep personal information only as long as needed for the app, security, legal compliance, billing, dispute resolution, and user requests.
- Local settings, protected profile cache, profile photo, manual weigh-ins, failed drafts, barcode cache, streaks, badges, widget or Siri snapshots, and pending sync data remain on your device for the feature's operational life or until you delete them, clear applicable data, or remove the app. Cached barcode results are treated as stale after about 30 days and the cache is size-limited.
- Widgets may visibly show nutrition totals, goals, streak information, and the latest meal to people who can view your device. Siri or Shortcuts output may be spoken, displayed, or forwarded by a shortcut you create.
- Synced food entries, ingredients, saved foods, profile data, account data, and usage records in Supabase remain until deleted, overwritten, or no longer needed for the service, subject to backup, legal, security, and fraud-prevention retention. Removing the app does not by itself delete server data.
- Onboarding analytics and operational usage data are intended for limited product, abuse prevention, and reliability purposes. Security, quota, and audit records may be retained as needed to protect the service.
- FuelForm sends meal photos for analysis but does not save the raw photo in your FuelForm food history or Supabase food-entry record. AI providers may retain request data for the periods allowed by their contracts, service terms, and applicable law.
- Referral redemption and reward records may be retained with account links removed or tombstoned after account deletion to preserve a surviving participant's reward and support fraud prevention, dispute handling, and legal or accounting requirements.
- Purchase records may be retained by Apple, RevenueCat, or us for fraud prevention, accounting, tax, refund, entitlement, and legal compliance.
- Deletion from active systems and service-provider backups may take additional time where permitted by law. You can clear food history, export a limited food-log CSV, delete your account, or submit a broader privacy request using in-app settings or by emailing fuelform@arqai.dev.
Your Choices and Rights
Depending on where you live, you may have rights to access, confirm, correct, export, delete, restrict, object to, or appeal decisions about certain personal information. You may also have rights relating to sensitive personal information or consumer health data.
- You can change iOS permissions for camera, photos, microphone, Speech Recognition, notifications, Apple Health, and FuelForm's Siri integration at any time.
- You can stop Apple Health sync by turning it off in FuelForm settings or revoking Health permissions in iOS Settings.
- You can clear meal records from Settings > Data & Privacy > Clear Food History. This does not delete your account or profile.
- Settings > Data & Privacy > Export My Data creates a limited CSV containing food-log date, time, description, calories, protein, carbohydrates, and fat; it is not a complete export of every account record.
- You can permanently request deletion of your FuelForm account and associated active server data from Settings > Data & Privacy > Delete Account. Deleting your FuelForm account does not cancel an Apple subscription.
- You can manage or remove FuelForm actions and automations in Siri and Shortcuts settings, and manage Siri request history through Apple's settings.
- You can request access, correction, a broader export, deletion, restriction, objection, a list of consumer-health-data recipients, or privacy help by emailing fuelform@arqai.dev. We may need to verify your request before acting on it.
- If we decline a privacy request, you may appeal by replying to the decision or emailing fuelform@arqai.dev with 'Privacy Appeal' in the subject. Depending on your location, you may also complain to the relevant privacy regulator or attorney general.
International Transfers
FuelForm and its providers may process and store information in countries other than your country of residence. Privacy laws in those countries may differ from the laws where you live.
- When required, we rely on appropriate safeguards such as contractual protections, data-processing terms, standard contractual clauses, consent, or other lawful transfer mechanisms.
- Service providers such as Supabase, Google, RevenueCat, Apple, Tavily, Open Food Facts, and Braintrust may maintain infrastructure or support operations in multiple regions.
Security
We use reasonable technical and organizational safeguards designed to protect information, including TLS in transit, iOS Keychain for sensitive local secrets, Supabase row-level security, authentication controls, device trust checks, rate limits, quotas, and security logging.
- No app, network, database, or AI service can be guaranteed to be completely secure.
- You are responsible for keeping your device, Apple ID, account credentials, and email account secure.
- If you believe your account or data has been compromised, contact fuelform@arqai.dev.
Children's Privacy
FuelForm is not intended for children under 13, or the minimum age required in your country. We do not knowingly collect personal information from children. If you believe a child provided personal information, contact us so we can delete it.
Changes to This Policy
We may update this policy when FuelForm changes or when legal, platform, security, provider, or operational requirements change. The effective date above will be updated when the policy changes materially. If a change is material, we may provide additional notice in the app, by email, or by another reasonable method.
Contact
Questions about privacy, support, access, correction, export, deletion, withdrawal of consent, or a privacy-request appeal can be sent by email.
fuelform@arqai.dev