EN RO

Privacy Policy

Last updated: July 2, 2026

Both the English and Romanian versions of this Policy are authentic. In case of inconsistency, the Romanian version prevails for users whose primary interface language is Romanian.

1. A Note About Health-Related Data

FormChase collects data that may qualify as "data concerning health" under GDPR Article 9.

This includes body measurements (weight, body fat percentage, BMI) and fitness or nutrition records linked to health-related goals (such as losing or gaining weight).

We process this data based on your explicit consent (GDPR Article 9(2)(a)), which you provide when you:

You can withdraw consent for specific data types at any time through your account settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal. When you withdraw consent for a Health Data category, we will stop processing that category and, unless we have another lawful basis to retain it (for example, a legal obligation), we will delete or anonymise it in accordance with the retention schedule in Section 6.

To meet our demonstrability obligation under GDPR Article 7(1), we record each consent grant and withdrawal (including timestamp and the scope of what was consented to) in our systems.

FormChase is a SaaS software service, not a healthcare provider, clinic, dietetic practice, medical device, or regulated health app. It does not provide medical diagnoses, treatment, medical nutrition therapy, or professional credential verification, and it does not replace professional medical or nutritional advice. The data you enter is for your personal fitness and nutrition tracking and for software features you choose to use. See our Terms and Conditions (Section 3) for important disclaimers.

2. What Data We Collect

2.1 Account Data

2.2 Authentication Data

Depending on your sign-in method:

We receive only the identifiers and email provided by Apple or Google during authentication. We do not receive your Apple ID password or Google account password.

2.3 Fitness and Workout Data

2.4 Nutrition Data

2.5 Body and Health Measurements

2.6 Apple Health Data (Optional)

If you enable Apple Health integration, we may read and/or write the following data types, only with your explicit per-type permission:

Apple Health data is:

You can disconnect Apple Health at any time in Settings → Health Integrations. Disconnecting stops future syncing but does not automatically delete previously synced data. You can delete that data through your account settings.

2.7 Professional User – Client Shared Data

If you are a Client of a Professional User (e.g., a trainer or nutritionist) and grant consent, the Professional User may view:

You control which categories the Professional User can access through granular consent toggles in Settings. Each consent grant and withdrawal is logged with a timestamp for your records.

2.8 Subscription and Billing Data

We do NOT store your full payment card details. Payments are processed by Apple or Google through their respective app stores.

2.9 Technical and Diagnostic Data

2.10 Product Analytics Data (Optional, Off by Default)

If you opt in to product analytics, we collect:

We do NOT collect through analytics:

Analytics data is processed on EU servers by our analytics provider. It is never used for advertising, your IP address is stripped before transmission, and analytics is off by default until you opt in.

2.11 Food Label Photos (OCR)

If you use the food label scanning feature, photos of food labels are sent to Google Cloud Vision API through our backend for text extraction. We send only the image; no account identifiers are attached to the request to Google. Google's processing is governed by the Google Cloud Data Processing Addendum and Google's AI/ML Privacy Commitment, under which submitted content is not used to train Google's models. The extracted text is returned to our backend and used to populate your food entry.

2.12 Push Notification Tokens

If you enable push notifications, we store a device push token to deliver workout reminders, meal reminders, and account-related notifications (e.g., new messages from your trainer, subscription updates). Push tokens are transmitted through Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and the Expo push service which routes the request to APNs/FCM.

You can revoke push permissions at any time through your device's system settings. Revoking the permission stops all further notifications from FormChase.

2.13 Questionnaire and Intake Responses

If your Professional User (trainer or nutritionist) sends you a questionnaire, we store the answers you choose to give. Built-in questionnaire templates include health-related questions (such as medical conditions, medications, injuries, or pregnancy), so your responses may include health data, which we process only with your explicit consent (GDPR Art. 9(2)(a)). Your responses are visible only to you and the Professional User who sent the questionnaire.

2.14 Messages With Your Trainer or Clients

If you use the in-app messaging feature, we store the content of the messages you exchange with your trainer or your clients, together with delivery metadata (timestamps, read status), solely to deliver the messaging feature. Messages are visible only to the participants in the conversation.

2.15 Feedback and Bug Reports

If the app hits an unexpected error, you can choose to send us a short description of what happened. We process the text you write, together with the technical diagnostic report for that error (see Section 4.5), so we can find and fix the problem. Sending a report is optional and you write it yourself, so please do not include sensitive personal details in it.

3. Why We Process Your Data and Our Legal Bases

Data Category Purpose Legal Basis (GDPR)
Account data Create and manage your account, provide the Service Art. 6(1)(b): contract performance
Authentication data Verify your identity, secure your account Art. 6(1)(b): contract performance
Fitness/workout data Provide core workout tracking features Art. 6(1)(b): contract performance
Nutrition data Provide core nutrition tracking features Art. 6(1)(b): contract performance
Body/health measurements Display your progress, calculate targets Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for health data
Apple Health data Sync health data at your request Art. 6(1)(a) + Art. 9(2)(a): explicit consent
Professional User – Client shared data Enable Professional User features Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent from the Client
Billing data Process subscriptions, comply with fiscal law Art. 6(1)(b): contract + Art. 6(1)(c): legal obligation
Analytics data Improve the Service (if you opt in) Art. 6(1)(a): consent
Error reports Diagnose and fix technical issues Art. 6(1)(f): legitimate interest (service reliability)
Security logs Detect fraud, prevent abuse Art. 6(1)(f): legitimate interest (security)
Food label photos (OCR) Extract nutritional information Art. 6(1)(b): contract performance
Push notification tokens Deliver workout/meal reminders and account notifications Art. 6(1)(b): contract performance (service reminders); Art. 6(1)(a): consent (any optional marketing-adjacent notification)
Questionnaire and intake responses Deliver trainer questionnaires you choose to answer Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for any health data in your answers
Messages with your trainer/clients Deliver the in-app messaging feature Art. 6(1)(b): contract performance
Referral codes and attribution Credit the referrer if you sign up via a referral link or participate in the trainer referral programme Art. 6(1)(f): legitimate interest (operating the referral programme)

Information required by GDPR Article 13(2)(e). Providing your email address and basic account data is a contractual requirement: we cannot create or operate an account without them. Consent for health data is optional; if you refuse or withdraw it, the only consequence is that the related features (body measurements, health integrations, sharing data with your trainer) will not be available. Consent for product analytics is entirely optional, and refusing it has no impact whatsoever on the Service.

Note on invoices. FormChase does not issue fiscal invoices for consumer App Store or Google Play subscriptions. Apple and Google are the merchants of record for those purchases (see Terms §8) and they issue and retain the fiscal records. We store only the subscription status (plan, expiry, store identifier) returned by RevenueCat, which is covered by the first rows of the table above.

4. Who We Share Your Data With

We do not sell your personal data.

We share data only with the following processors and service providers, under data processing agreements:

4.1 Supabase: Cloud Database, Authentication, and File Storage

4.2 RevenueCat: Subscription Management

4.3 Apple & Google: App Store and Google Play Billing

4.4 PostHog EU: Product Analytics (Only If You Opt In)

4.5 Sentry: Error Monitoring (Production Only)

4.6 Resend: Transactional Email

4.7 Google Cloud Vision API: Image Recognition (OCR)

4.8 Cloudflare: CDN, Web Security, Legal & Marketing Site Hosting

4.9 Open Food Facts: Open Food Database

4.10 Professional Users (Trainers/Nutritionists): Independent Controllers

If you are a Client and grant consent, your Professional User (a trainer or nutritionist) may view specific categories of your data (see Section 2.7). In this relationship:

4.10b Records About People Without a FormChase Account (GDPR Article 14 Notice)

Professional Users can store records inside the Service about clients who do not have a FormChase account, for example imported client lists (name, email, phone, notes), meal-plan share links, and invitations. For that data:

4.11 Google Gemini: Food-Data Text Processing

4.12 Expo: Push-Notification Delivery and App Updates

4.13 YouTube and Vimeo: Trainer-Attached Exercise Videos

Professional Users can attach YouTube or Vimeo videos to exercises. When you open such a video, or when its thumbnail is loaded, your device connects directly to that platform, which receives your device's IP address and applies its own privacy policy (Google/YouTube, Vimeo). FormChase does not send any account data to these platforms.

4.14 Infrastructure Endpoints

The app performs technical availability checks (network connectivity probes and requests to our status-page host). These requests expose only your device's IP address and standard request metadata; no account identifiers are attached.

5. International Data Transfers

Your data is primarily stored in the EU.

Some processors are located in the United States. For these transfers, we rely on:

You can request details about specific transfer safeguards by contacting us.

6. How Long We Keep Your Data

Data Retention Period
Account and profile data Until you delete your account; deleted immediately upon confirmed deletion
Fitness, nutrition, and measurement data Until account deletion; deleted immediately upon confirmed deletion
Apple Health synced data Until account deletion (or until you manually delete it); deleted immediately upon confirmed deletion
Questionnaire and intake responses Until you delete the response or your account
Messages with your trainer/clients Until account deletion; deleted immediately upon confirmed deletion
Feedback and bug reports Up to 90 days (linked to the diagnostic error record)
Subscription status (plan, expiry, store identifier) As long as the subscription is active; deleted immediately upon confirmed account deletion
Error/diagnostic logs 90 days
Analytics events (if opted in) 90 days
Push notification tokens Until you disable push notifications or delete your account
Security and audit logs Up to 12 months at most; reviewed periodically and deleted or anonymised when no longer needed
Consent and legal acceptance records 5 years after account deletion (legal evidence)
Public library contributions Retained in anonymised form after account deletion
DSAR request records 3 years after resolution (legal evidence)

Account deletion is immediate and cannot be cancelled once confirmed. Upon deletion, your personal data is permanently deleted or anonymised, except where retention is required by law or specified above. See the Delete Account page for full details.

If we permanently discontinue the Service (Terms of Service, Section 16.4), remaining account data is deleted within at most 90 days of the shutdown date, subject to the limited legal retention described above.

7. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

7.1 Right of Access (Art. 15)

Request a copy of the personal data we hold about you. You can do this in-app (Settings → Privacy & Data → Export My Data) or by contacting us.

7.2 Right to Rectification (Art. 16)

Correct inaccurate or incomplete data. Most data can be corrected directly in the app. For other corrections, contact us.

7.3 Right to Erasure (Art. 17)

Request deletion of your personal data. Use the in-app account deletion feature (Settings → Privacy & Data → Delete Account) or contact us. Deletion is immediate and cannot be cancelled once confirmed; a limited set of records is retained only where the law requires it (see Section 6 and the Delete Account page).

7.4 Right to Restrict Processing (Art. 18)

Request restriction of processing in certain circumstances (e.g., while we verify the accuracy of contested data).

7.5 Right to Data Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format (JSON). Available in-app via the Export feature.

7.6 Right to Object (Art. 21)

Object to processing based on legitimate interests (error reporting, security). We will stop unless we have compelling legitimate grounds.

7.7 Right to Withdraw Consent (Art. 7)

Where we process data based on your consent (analytics, Apple Health, data sharing with Professional Users), you can withdraw consent at any time in your account settings. Withdrawal does not affect processing that occurred before withdrawal.

7.8 Profiling and Automated Decision-Making (Art. 22)

To provide coaching features, FormChase analyses your logged health, nutrition and activity data to generate insights such as nutrition-adherence scores, progress trends and coaching signals. Where you have linked a Professional User (trainer), these insights are also shown to them, subject to your consent. This analysis is profiling within the meaning of Art. 4(4) GDPR. These insights support human coaching and your own decisions; FormChase does not make solely automated decisions that produce legal or similarly significant effects on you (Art. 22). Calorie and macro calculations are informational estimates. You can object to this profiling at any time (see your right to object above) or, where it relies on your consent, withdraw that consent.

7.9 How to Exercise Your Rights

We will respond without undue delay and in any event within one month of receipt of your request, as required by GDPR Article 12(3). That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you of the extension and the reasons within one month of receipt.

7.10 Right to Complain

You have the right to lodge a complaint with:

ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1

București 010336, România

Website: dataprotection.ro

Or with the supervisory authority in your EU Member State of habitual residence.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

No system is perfectly secure. If we discover a personal data breach, we will notify ANSPDCP within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay and in clear and plain language, as required by GDPR Article 34, describing the nature of the breach, the likely consequences, the measures taken to mitigate it, and a contact point for further information.

9. Children

FormChase is not intended for children under 16. Under Article 8(1) GDPR, a child can validly consent to information-society services only from the age of 16; Member States may set a lower age, but Romania has not done so. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, contact us at contact@formchase.com and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes with reasonable advance notice through in-app notification and/or email. The "Last updated" date at the top reflects the most recent revision.

11. Data Controller

The data controller responsible for processing your personal data is:

COCOȘ DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ

CUI: 54218790

Trade Register: F2026013034001

EUID: ROONRC.F2026013034001

Registered professional address: B-dul Bucureștii Noi nr. 136, et. parter, ap. 5, Sector 1, București, România

Telephone: +40 750 451 098

Email: contact@formchase.com

We process your data in accordance with the General Data Protection Regulation (GDPR), Romanian Law 190/2018 implementing GDPR, and other applicable data protection legislation.

At our current scale, we are not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy inquiries, contact us at contact@formchase.com. We will reassess this obligation as we grow.

12. Contact

For questions about this Privacy Policy or to exercise your data rights:

Email: contact@formchase.com