Fyvorin β Privacy Policy
Version: Beta 1.1 Β· Last updated: 2026-09-28 Β· Locale: English (en)
[!WARNING] DRAFT β NOT LEGAL ADVICE. This describes what the software actually does, written by an engineer. It has not been reviewed by a lawyer. It is intended for a closed beta and must be reviewed by qualified counsel before public launch. Data-protection decisions that I cannot make for you are marked [COUNSEL] and listed under "Open legal questions".
[!NOTE] What changed in Beta 1.1. This version adds approximate-location handling for the "find your gym" feature, and adds Google (Google Maps Platform) as a processor. The location section is new (Β§3.5) and the provider table gains a Google row (Β§6).
1. Summary
- Fyvorin collects health and fitness data you enter, plus data you authorise us to read from Health Connect.
- If you choose to find your gym, Fyvorin uses your approximate location, only while you are using the search, and it is not stored on our servers. The gym you pick is stored as its Google place identifier plus a short-lived display copy of its name and address.
- Your data is stored on Google Cloud (Cloud Run, Cloud SQL,
us-central1, United States) and in Firebase (authentication, crash reporting). - To generate plans and coaching, relevant context β including health information β is sent to third-party AI and data providers: DeepSeek, Spoonacular, TheMealDB, ElevenLabs, RapidAPI and, for gym search only, Google (Google Maps Platform).
- You can delete your account and all data, in the app or on the web. Deletion is permanent and immediate.
2. Who is responsible
Cypher Systems Group Β· Data Controller
Data-protection contact: fyvorin-support@cyphersystemsapps.com.
3. What we collect
3.1 Information you give us
Your profile, as entered during onboarding and later edits. This includes:
- Identity and basics: name, age, date of birth, sex, physiological sex, gender identity, pronouns, country of origin.
- Body: height, weight, goal weight, body-fat percentage, target body fat, and measurements (chest, waist, hips, arms, thighs, shoulders).
- Training: activity level, experience level, goals, available equipment, weekly availability, session duration, programme length, sessions per week, training focus, rep ranges, tempo preference, target RPE, injuries and physical constraints.
- Nutrition: dietary preference, allergies, other medical conditions, nutrition strategy, calorie/protein/carbohydrate/fat targets, meals per day, meal-frequency preferences.
- Reproductive health (optional): whether you track your cycle, last period start date, cycle length, symptoms, pregnancy status and trimester, hormone therapy and details.
- Contact and account: email address, and (if you use Google Sign-In) the identity data Google returns.
[!CAUTION] Much of the above β particularly injuries, medical conditions, allergies and reproductive health β is sensitive personal data. See "Open legal questions".
3.2 Information you generate by using the app
- Workout history: sessions, exercises, sets, reps, weight, duration, perceived intensity, notes.
- Nutrition records: meals and foods logged, with calories and macronutrients; water intake.
- Body metrics over time: weight, BMI, body-fat percentage, lean mass, fat mass, BMR, TDEE.
- Goals, achievements, streaks and progress.
- AI coach chat history and AI memories β facts the assistant has derived about you.
3.3 Information read from Health Connect
Only with your explicit permission, and read-only, we access:
| Health Connect permission | What it provides |
|---|---|
| Steps | Daily step counts, used to prefill and display activity |
| Sleep | Sleep sessions, used in the recovery view |
| Exercise | Exercise sessions |
| Height | Used to prefill your profile |
| Weight | Used to prefill your profile and body metrics |
| Body fat | Used to prefill your body metrics |
We also use the activity-recognition permission on Android 10+ because the platform requires it to read the step counter.
What we do with it: we import the values into your profile and daily records so you do not have to type them, and display them alongside your training data. We do not write to Health Connect, and we do not use Health Connect data for advertising. You can revoke these permissions at any time in Health Connect or in Android settings; the app will stop reading.
3.4 Information collected automatically
- Authentication identifiers. Firebase issues a user ID; we map it to an internal account identifier so your records can be linked without using your Firebase ID directly as a key.
- Crash and diagnostic reports. We use Firebase Crashlytics for crashes and errors. The reporting pipeline is deliberately configured to exclude personal data: application logs are filtered and redacted before they reach Crashlytics (identifiers, meal names, health values and user-entered text are suppressed), so crash reports contain technical diagnostics rather than your content.
- We do not use advertising SDKs, and we do not sell your data.
3.5 Approximate location (gym search)
This is new in Beta 1.1.
When it is used. Only when you open the "find your gym" feature and choose Use my location. Location is requested one time, in the foreground, while you are looking at that screen. Fyvorin does not read your location in the background, does not monitor it over time, and does not use it for anything except the gym search you asked for.
What we request. Fyvorin requests approximate location only (ACCESS_COARSE_LOCATION).
We deliberately do not request precise location, because listing nearby gyms does not need it.
You may decline; the feature then works by typing a city or area name, and nothing about your
location is used.
Where it goes. Your approximate coordinates are sent, over an encrypted connection, from your device to our backend, which passes them to Google's Places API to return nearby gyms. The coordinates travel in the body of an encrypted request; they are not placed in the request URL (which infrastructure may log), and our backend does not store them. They are used for that single lookup and then discarded. Client and server logs are configured to exclude them.
What we keep. After you pick a gym, Fyvorin stores:
- the gym's Google place identifier β a public identifier for a place, which Google's terms permit storing without a time limit, and which we use as the stable key; and
- a short-lived display copy of the gym's name and address, so the card can be rendered offline. Google's terms do not grant the right to store a place's name or address indefinitely, so this copy is refreshed periodically and is tied to the gym identifier rather than kept as a permanent record.
We do not store your coordinates, and we do not build a location history. The gym identifier and its display copy are part of your Training Environments and are deleted with your account like everything else.
When gym data is shown, it is attributed to Google Maps, as Google's terms require.
4. Why we use it
- To provide the service: storing your records, syncing them, and showing them back to you.
- To generate workout plans, meal plans and coaching, which involves sending relevant context to an AI provider (see Β§6).
- To look up recipes, ingredients, exercises and media from data providers.
- To find nearby gyms, using your approximate location, when you ask it to (see Β§3.5).
- To authenticate you and keep your account secure.
- To diagnose crashes and fix defects.
[COUNSEL: articulate the legal basis for each purpose (consent / contract / legitimate interests), and confirm how consent for sensitive data is captured. Location is a separate, arguably lower-risk category, but confirm whether the in-app pre-prompt plus the Android permission constitute sufficient consent in the jurisdictions you serve.]
5. Where your data is stored
| Where | What |
|---|---|
Google Cloud Run (us-central1, United States) |
Our API service that receives and serves your data |
Google Cloud SQL for PostgreSQL (us-central1, United States) |
Your profile, records and content |
| Firebase Authentication (Google) | Your sign-in record (email, or Google identity) |
| Firebase Crashlytics (Google) | Crash reports and non-fatal errors, filtered to exclude personal data |
| On your device | A local database and preferences, so the app works offline; the Coach voice cache; the gym identifier and its bounded name/address display copy |
Access to the database is restricted, and the database is not publicly reachable.
[!NOTE] Location is deliberately not in this table. Your approximate coordinates are transient β they are not written to Cloud SQL, Firebase or any log, so there is nowhere for them to be stored. The only gym-related data we persist is the identifier and the bounded display copy described in Β§3.5, and that lives on your device and, as part of your environments, in Cloud SQL.
6. Third parties that process your data
To generate plans and coaching, our backend sends the relevant context to third-party providers using our own credentials. Your sign-in token and password are not sent to them.
| Provider | What it receives | Why |
|---|---|---|
DeepSeek (api.deepseek.com) |
AI prompts that include your health context β profile, goals, training and nutrition summary, equipment, injuries, medical conditions, dietary preferences and allergies; and the text of your chat messages | Generating workout plans, meal plans, coach replies |
Google β Google Maps Platform (Places API) (places.googleapis.com) |
Your approximate location (a single coordinate pair), or your typed city/area query, and a gym identifier when refreshing a selected gym | Finding nearby gyms, and refreshing the name/address of the gym you selected |
Spoonacular (api.spoonacular.com) |
Recipe and ingredient search terms, and dietary filters | Recipe and nutrition data |
TheMealDB (themealdb.com) |
Meal and ingredient search terms | Recipe data fallback |
ElevenLabs (api.elevenlabs.io) |
The text of coach voice lines to be spoken | Generating the coach's voice |
| RapidAPI β ExerciseDB | Exercise names | Exercise catalogue and imagery |
| RapidAPI β Muscle Group Image Generator | Muscle-group names | Generating exercise illustrations |
| Cloudflare Workers (Forge media/voice proxies) | Exercise identity and request metadata, used to route media and speech requests | Infrastructure for media and speech |
[!IMPORTANT] The DeepSeek row is the one to read carefully. To plan a workout or a meal, the prompt we send includes health context β including injuries, medical conditions and allergies. That means sensitive health information leaves our infrastructure and is processed by DeepSeek. I cannot verify from the code what DeepSeek does with it or how long it is retained (see Open legal questions).
[!IMPORTANT] The Google row is new and is location-specific. It is the only provider that receives location data, it receives it only when you use the gym-search feature, and it receives only approximate coordinates (or the text you typed). Google's own handling is governed by Google's terms and privacy policy, which we do not control β see Open legal questions.
We do not sell your personal data, and we do not share it with advertisers.
7. AI-generated content
Plans and coaching are produced by AI and are not medical advice. See Β§5 of the Beta Terms for the full statement.
8. Security
We use industry-standard measures: TLS in transit, credentials held in a managed secret store rather than in code, authentication required on every API route, per-user authorisation on every query, and a private (non-public) database. No system is perfectly secure, and this is beta software that has not been independently audited. [COUNSEL: confirm whether any breach- notification obligations apply in your jurisdictions.]
9. Retention
Data is retained while your account exists. Deleting your account deletes your data (Β§10). We do not currently implement any automatic retention limit or aged-data deletion. [COUNSEL: specify any retention periods you are required or wish to observe.]
Location retention. Approximate coordinates are not retained at all (see Β§3.5). The gym identifier is retained while you have that environment set. Its name/address display copy is short-lived and is refreshed rather than kept indefinitely, per Google's terms. All are removed when you delete your account, or when you clear or change the gym for that environment.
Cookies & Local Storage: The Fyvorin website does not use any tracking, advertising, or analytics cookies. We only utilize strictly necessary local storage and session tokens via our authentication provider (Firebase Auth) when you explicitly sign in to request account deletion. Because these are strictly necessary for security purposes, no consent banner is required.
10. Deleting your account and your data
You can delete your account at any time, two ways:
- In the app: Settings β Delete Account.
- On the web (no app required):
/delete-account.
Deletion is permanent and immediate. Within a single operation we delete:
- your profile, workouts, exercise logs, nutrition logs, water logs, meals, body metrics, goals, chat history and AI memories;
- your Training Environments, including each environment's gym identifier and its name/address display copy;
- the link between your sign-in identity and your account;
- your account record itself; and then
- your authentication account, so you can no longer sign in.
Within the app and our database there is no soft-delete and no recycle bin: the rows are removed and the operation cannot be undone from inside the product. Deleting your account is therefore immediate and irreversible as far as the service is concerned.
The database itself does maintain automated backups and point-in-time recovery (described in Β§9). That is standard operational protection against catastrophic failure, not a user-facing feature: we do not restore an individual deleted account from them, and backups age out on a fixed retention schedule. We are stating this explicitly rather than claiming no copy exists anywhere, because the infrastructure does retain backups for a bounded period. [COUNSEL: confirm whether any retention/erasure obligation requires different handling of the backup/PITR window, and whether this description of it is adequate.]
11. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your data, to object to or restrict certain processing, and to withdraw consent.
- Much of this is available directly in the app (view and edit your profile and records; delete your account).
- For anything else, contact [COUNSEL: email].
[COUNSEL: confirm the specific rights and response deadlines in each jurisdiction you serve β e.g. GDPR rights and timelines, or the ARCO rights and procedure under Mexican law.]
12. Children
Fyvorin is intended for adults. It is not directed at children, and we do not knowingly collect their data. The app does not currently verify age. [COUNSEL: confirm the applicable minimum age and whether an age gate is required.]
13. Changes to this policy
We will update this policy as the beta changes. Material changes are published as a new version, and the previous version remains available at its own URL, so you can always see the text that applied when you accepted.
If a change requires your agreement, the app asks you to accept the new version before you can continue, and records the accepted version on your device. This document is a new version for exactly that reason: adding a data category (approximate location) and a processor (Google) is a material change.
14. Contact
[COUNSEL: contact email] for privacy questions and data requests.
Open legal questions (flagged, not guessed)
- Sensitive data and the lawful basis. Injuries, medical conditions, allergies and reproductive-health data are sensitive categories. Whether the existing single acceptance checkbox is legally sufficient β and whether separate explicit consent is required β is a legal question. I did not invent an answer.
- Provider retention and training. I cannot verify from this repository what DeepSeek, Spoonacular, ElevenLabs, the RapidAPI providers or Google do with submitted data, or how long they keep it. The Privacy Policy therefore describes what we send, and deliberately does not promise what those providers do with it.
- International transfers. Processing occurs in the United States. Transfer safeguards may be required for Mexican or EU users.
- Retention schedule. None is implemented. If one is required, it must be built.
- Breach notification. Applicable duties and timelines are jurisdiction-specific and not currently documented anywhere in the repository.
- Mexican "Aviso de Privacidad". If your users are primarily in Mexico, the document may need to take the form of an Aviso de Privacidad with the content the LFPDPPP prescribes (controller identity and address, primary and secondary purposes, transfers, and the procedure for exercising ARCO rights). The Spanish version of this document is drafted with that structure in mind but has not been validated by a Mexican data-protection lawyer.
- Health Connect policy. Google's Health Connect policy imposes its own requirements on apps that read health data, including restrictions on use and onward disclosure. UNKNOWN β needs verification against the current Play policy for Health Connect data.
- Location as a separate category (new in Beta 1.1) β DECIDED, form still to be filled. Approximate location is a distinct data category for Play's Data Safety form. We have chosen to declare it as Collected (purpose: App functionality; not for advertising or tracking). This is the conservative option: whether a transient, never-stored server-side passthrough would qualify for the ephemeral-processing treatment depends on Google-side behaviour we cannot verify, and under-declaring is what gets apps removed, so we declare rather than rely on the narrower reading. The remaining action is procedural β completing the Data Safety form β not a decision. [COUNSEL / TO CONFIRM: that the declaration as filed matches this choice, and that the in-app pre-prompt plus the Android permission satisfy the prominent-disclosure requirement.]
- Google Maps Platform terms flow-down (new in Beta 1.1). Google's Maps Platform terms govern our use and storage of Places content, including which fields may be cached and for how long. [COUNSEL / UNVERIFIED: confirm that storing the gym identifier indefinitely, with name/address held only as a bounded display copy, is the correct reading of the current Maps Service Specific Terms, and confirm the required attribution presentation.]