Technical privacy information
Updated: 22 September 2026. This overview describes technical processing. A complete privacy policy with operator contact details, legal bases, specific provider retention periods and data subject rights must be added and reviewed before commercial publication.
Controller and privacy contact
Controller: MANUELL EINZUTRAGEN. Legal name and address are still missing; see the legal notice. LEGAL REVIEW REQUIRED.
datenschutz@buildyourprogress.comUse this contact for access, correction, deletion, restriction, portability, objection and withdrawal requests. We need to verify entitlement to each request. Legal bases for each processing purpose, the competent supervisory authority and binding provider retention periods must be completed before launch.
Domain and contact emails
Hostinger manages the domain and business mailboxes. If you email us, your sender address, message and attachments are processed there to handle your request. Send only necessary information. The operator must confirm contracts, processing regions and retention periods.
Account and diary
Supabase Auth processes your email address and sign-in. Exercises, workouts, body weight, meals, nutrients, targets and favourites are stored in Supabase PostgreSQL under your account. Weight and nutrition information may reveal information about your health. Only enter what you need for your diary.
Weekly check-in
Weekly check-ins store weight, a note and an optional smaller photo in Supabase. Photos are re-encoded locally as JPG without original metadata and uploaded only when you save the check-in. They are accessible only to your signed-in account, are not sent to AI services and can be downloaded individually in the check-in history. The JSON export includes the other check-in data. Remove a photo by editing and saving or delete the whole check-in.
Training with a coach
The operator assigns coaching rights to a specific account. A client connection requires reviewing a single-use code and explicit confirmation. Connected accounts see each other’s sign-in email. Your coach can read your exercises and manage training plans; nutrition, photos and training history are not shared. Revoke access in Training plans. Previously viewed or copied data cannot be retrieved. Connections and plan changes are logged with user IDs, action and time and are included in account exports. Invitations expire after 24 hours.
Coach chat
Messages are stored while connected. Revoking the connection or deleting an account removes the shared chat. Existing exports remain with their recipients.
Text messages are stored in Supabase with their sender, connection and timestamp. Only actively connected participants can read them. Account export includes accessible shared history. Unsent text remains only in the open form; there are no AI replies or audio recordings.
Browser and hosting
Vercel hosts the app, which involves technical connection data such as IP addresses and requested URLs. Supabase stores sign-in details in local browser storage to keep you signed in. The app has no built-in advertising pixels or analytics scripts. Fonts come from your device. Provider logs and their retention periods must be clarified separately by the operator.
Food search
If the internal food list is insufficient, our server sends your search term or barcode to Open Food Facts. Your email address and session token are not sent. Public product responses and the search URL are cached on the server for up to 24 hours. Do not enter personal information here.
Optional AI and voice
Before analysis, the app shows the configured provider (OpenAI or Google Gemini). Only after your permission are selected photos or your description and size reference sent through our server. Previous food corrections are used only with additional permission. Meal analysis does not store photos or voice recordings; confirmed foods are saved as diary entries.
OpenAI requests use store:false. This does not promise that the provider keeps no security logs or other records. Data may be processed outside the EU. During voice entry, your browser’s speech recognition service may also receive audio. You can type and enter food manually instead.
Permissions start off and apply to the open entry area. Remove the check mark to stop further transfers. Withdrawing permission cannot recall data already sent. A technical counter limits AI requests; it contains no photos or meal contents.
Export, correction and deletion
Workout dictation: The app first tries local browser speech recognition in the selected language. If unavailable, the browser’s speech recognition service can be used after separate voluntary permission; audio may be sent to its provider. The app itself stores neither audio nor dictation. Only “Save workout” sends the reviewed workout values to your account.
Cardio: A check-in saves the day, activity, duration and intensity, plus an optional distance and note, in your account. Entries can be deleted individually, are included in your account export and are deleted with your account.
Steps and native health services: A technical provider structure is prepared but not offered in the interface. Apple Health and Android Health Connect are not connected, and no automatic synchronisation takes place.
Under “Account & privacy”, you can download your app data and change your password or email address. Entries can be corrected and deleted in their respective areas. Account deletion requires your password and explicit confirmation. It removes the login and associated app entries on the server once the operator has configured this feature. If configuration is missing, an error appears; deletion is never simulated.
Diary data is stored until you delete it. Automatic deletion for inactivity is not configured. Exports already downloaded remain on your device. Backups and provider logs have separate retention periods that still need to be confirmed.