EN RO

Privacy Policy

Last updated: April 19, 2026

Both the English and Romanian versions of this Policy are authentic. In case of inconsistency, the Romanian version prevails for users whose primary interface language is Romanian.

1. A Note About Health-Related Data

FormChase collects data that may qualify as "data concerning health" under GDPR Article 9.

This includes body measurements (weight, body fat percentage, BMI) and fitness or nutrition records linked to health-related goals (such as losing or gaining weight).

We process this data based on your explicit consent (GDPR Article 9(2)(a)), which you provide when you:

You can withdraw consent for specific data types at any time through your account settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal. When you withdraw consent for a Health Data category, we will stop processing that category and, unless we have another lawful basis to retain it (for example, a legal obligation), we will delete or anonymise it in accordance with the retention schedule in Section 6.

To meet our demonstrability obligation under GDPR Article 7(1), we record each consent grant and withdrawal (including timestamp and the scope of what was consented to) in our systems. You can request a copy of your consent history at any time via the rights flow in Section 7.

FormChase is not a medical device, does not provide medical diagnoses, and does not replace professional medical or nutritional advice. The data you enter is for your personal fitness and nutrition tracking. See our Terms and Conditions (Section 3) for important disclaimers.

2. What Data We Collect

2.1 Account Data

2.2 Authentication Data

Depending on your sign-in method:

We receive only the identifiers and email provided by Apple or Google during authentication. We do not receive your Apple ID password or Google account password.

2.3 Fitness and Workout Data

2.4 Nutrition Data

2.5 Body and Health Measurements

2.6 Apple Health Data (Optional)

If you enable Apple Health integration, we may read and/or write the following data types, only with your explicit per-type permission:

Apple Health data is:

You can disconnect Apple Health at any time in Settings → Health Integrations. Disconnecting stops future syncing but does not automatically delete previously synced data. You can delete that data through your account settings.

2.7 Professional User – Client Shared Data

If you are a Client of a Professional User (e.g., a trainer or nutritionist) and grant consent, the Professional User may view:

You control which categories the Professional User can access through granular consent toggles in Settings. Each consent grant and withdrawal is logged with a timestamp for your records.

2.8 Subscription and Billing Data

We do NOT store your full payment card details. Payments are processed by Apple or Google through their respective app stores.

2.9 Technical and Diagnostic Data

2.10 Product Analytics Data (Optional, Off by Default)

If you opt in to product analytics, we collect:

We do NOT collect through analytics:

Analytics data is processed on EU servers by our analytics provider.

2.11 Food Label Photos (OCR)

If you use the food label scanning feature, photos of food labels are sent to Google Cloud Vision API through our backend for text extraction. We send only the image; no account identifiers are attached to the request to Google. Google's processing is governed by the Google Cloud Data Processing Addendum and Google's AI/ML Privacy Commitment, under which submitted content is not used to train Google's models. The extracted text is returned to our backend and used to populate your food entry.

2.12 Push Notification Tokens

If you enable push notifications, we store a device push token to deliver workout reminders, meal reminders, and account-related notifications (e.g., new messages from your trainer, subscription updates). Push tokens are transmitted through Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and the Expo push service which routes the request to APNs/FCM.

You can revoke push permissions at any time through your device's system settings. Revoking the permission stops all further notifications from FormChase.

3. Why We Process Your Data and Our Legal Bases

Data Category Purpose Legal Basis (GDPR)
Account data Create and manage your account, provide the Service Art. 6(1)(b): contract performance
Authentication data Verify your identity, secure your account Art. 6(1)(b): contract performance
Fitness/workout data Provide core workout tracking features Art. 6(1)(b): contract performance
Nutrition data Provide core nutrition tracking features Art. 6(1)(b): contract performance
Body/health measurements Display your progress, calculate targets Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent for health data
Apple Health data Sync health data at your request Art. 6(1)(a) + Art. 9(2)(a): explicit consent
Professional User – Client shared data Enable Professional User features Art. 6(1)(b): contract + Art. 9(2)(a): explicit consent from the Client
Billing data Process subscriptions, comply with fiscal law Art. 6(1)(b): contract + Art. 6(1)(c): legal obligation
Analytics data Improve the Service (if you opt in) Art. 6(1)(a): consent
Error reports Diagnose and fix technical issues Art. 6(1)(f): legitimate interest (service reliability)
Security logs Detect fraud, prevent abuse Art. 6(1)(f): legitimate interest (security)
Food label photos (OCR) Extract nutritional information Art. 6(1)(b): contract performance
Push notification tokens Deliver workout/meal reminders and account notifications Art. 6(1)(b): contract performance (service reminders); Art. 6(1)(a): consent (any optional marketing-adjacent notification)

Note on invoices. FormChase does not issue fiscal invoices for consumer App Store or Google Play subscriptions. Apple and Google are the merchants of record for those purchases (see Terms §8) and they issue and retain the fiscal records. We store only the subscription status (plan, expiry, store identifier) returned by RevenueCat, which is covered by the first rows of the table above.

4. Who We Share Your Data With

We do not sell your personal data.

We share data only with the following processors and service providers, under data processing agreements:

4.1 Supabase: Cloud Database, Authentication, and File Storage

4.2 RevenueCat: Subscription Management

4.3 Apple & Google: App Store and Google Play Billing

4.4 PostHog EU: Product Analytics (Only If You Opt In)

4.5 Sentry: Error Monitoring (Production Only)

4.6 Resend: Transactional Email

4.7 Google Cloud Vision API: Image Recognition (OCR)

4.8 Cloudflare: CDN, Web Security, Legal & Marketing Site Hosting

4.9 Open Food Facts: Open Food Database

4.10 Professional Users (Trainers/Nutritionists): Independent Controllers

If you are a Client and grant consent, your Professional User (a trainer or nutritionist) may view specific categories of your data (see Section 2.7). In this relationship:

5. International Data Transfers

Your data is primarily stored in the EU.

Some processors are located in the United States. For these transfers, we rely on:

You can request details about specific transfer safeguards by contacting us.

6. How Long We Keep Your Data

Data Retention Period
Account and profile data Until you delete your account + 30-day cooling-off period
Fitness, nutrition, and measurement data Until account deletion + 30-day cooling-off
Apple Health synced data Until account deletion + 30-day cooling-off (or until you manually delete it)
Subscription status (plan, expiry, store identifier) As long as the subscription is active, plus the 30-day cooling-off after account deletion
Error/diagnostic logs 90 days
Analytics events (if opted in) 2 years
Consent and legal acceptance records 5 years after account deletion (legal evidence)
Public library contributions Retained in anonymised form after account deletion
DSAR request records 3 years after resolution (legal evidence)

After account deletion, your personal data is permanently deleted or anonymised, except where retention is required by law or specified above.

7. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

7.1 Right of Access (Art. 15)

Request a copy of the personal data we hold about you. You can do this in-app (Settings → Privacy & Data → Export My Data) or by contacting us.

7.2 Right to Rectification (Art. 16)

Correct inaccurate or incomplete data. Most data can be corrected directly in the app. For other corrections, contact us.

7.3 Right to Erasure (Art. 17)

Request deletion of your personal data. Use the in-app account deletion feature (Settings → Privacy & Data → Delete Account) or contact us. Deletion is subject to a 30-day cooling-off period and legal retention obligations.

7.4 Right to Restrict Processing (Art. 18)

Request restriction of processing in certain circumstances (e.g., while we verify the accuracy of contested data).

7.5 Right to Data Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format (JSON). Available in-app via the Export feature.

7.6 Right to Object (Art. 21)

Object to processing based on legitimate interests (error reporting, security). We will stop unless we have compelling legitimate grounds.

7.7 Right to Withdraw Consent (Art. 7)

Where we process data based on your consent (analytics, Apple Health, data sharing with Professional Users), you can withdraw consent at any time in your account settings. Withdrawal does not affect processing that occurred before withdrawal.

7.8 Right Not to Be Subject to Automated Decision-Making (Art. 22)

FormChase does not make automated decisions that produce legal or similarly significant effects on you. Calorie and macro calculations are informational estimates, not decisions about you.

7.9 How to Exercise Your Rights

We will respond without undue delay and in any event within one month of receipt of your request, as required by GDPR Article 12(3). That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; in that case we will inform you of the extension and the reasons within one month of receipt.

7.10 Right to Complain

You have the right to lodge a complaint with:

ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1

București 010336, România

Website: dataprotection.ro

Or with the supervisory authority in your EU Member State of habitual residence.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

No system is perfectly secure. If we discover a personal data breach, we will notify ANSPDCP within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay and in clear and plain language, as required by GDPR Article 34, describing the nature of the breach, the likely consequences, the measures taken to mitigate it, and a contact point for further information.

9. Children

FormChase is not intended for children under 16. In Romania, Article 6 of Law no. 190/2018 (implementing the GDPR) sets 16 as the age at which a child can validly consent to information-society services, above the default 13-year threshold in Article 8(1) GDPR. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, contact us at contact@formchase.com and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes at least 30 days in advance through in-app notification and/or email. The "Last updated" date at the top reflects the most recent revision.

Previous versions of this policy are available upon request.

11. Data Controller

The data controller responsible for processing your personal data is:

COCOȘ DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ

CUI: 54218790

Trade Register: F2026013034001

Email: contact@formchase.com

We process your data in accordance with the General Data Protection Regulation (GDPR), Romanian Law 190/2018 implementing GDPR, and other applicable data protection legislation.

At our current scale, we are not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy inquiries, contact us at contact@formchase.com. We will reassess this obligation as we grow.

12. Contact

For questions about this Privacy Policy or to exercise your data rights:

Email: contact@formchase.com