
Graviflux Privacy Policy
Effective date: July 23, 2026 Last updated: July 23, 2026
This Privacy Policy describes how Graviflux, a sole proprietorship operated by Isaac Nathanael Hernandez-Alvarez and based in Wabash County, Indiana, USA ("Graviflux," "we," "us," or "our") collects, uses, discloses, and protects your information when you use the Graviflux mobile application, the Graviflux website at graviflux.com, and related services (collectively, the "Service").
By using the Service you acknowledge this Privacy Policy. Where consent is required (for example, for health data), we will ask for it explicitly before collecting that data.
Contact: support@graviflux.com
1. Summary (Plain-Language Highlights)
- We collect the fitness, nutrition, and wellness data you choose to log, plus account and profile information.
- We do not sell your personal data. The Graviflux mobile application does not use third-party advertising SDKs. However, on the graviflux.com website, we use Google AdSense to display advertisements, which uses cookies to serve ads based on your prior visits. In the app, the community tab may display clearly labeled sponsored content from our partners; these placements are chosen by context (for example, that you are viewing the community tab) — never using your personal or health data — and sponsors receive no personal data about you.
- Apple Health data stays on your device and in your Graviflux account; it is never used for advertising, marketing, or sold to anyone, consistent with Apple's HealthKit rules.
- Social features are opt-in by design: what other users see is controlled by your privacy setting, your follows, and what you choose to post or share.
- Coaches can only see the categories of your data you explicitly toggle on (nutrition, workouts, wellness, weight, photos), and you can revoke access at any time.
- You can export your data and permanently delete your account from within the app.
2. Information We Collect
2.1 Information you provide
Account information. Email address and password, or the name and email provided by Apple or Google if you use Sign in with Apple or Google Sign-In. A username and display name.
Profile information. Optional details you add: full name, display name, username, avatar photo, bio, pronouns, activity level, fitness goals (primary, secondary, and weight goals), starting point, calorie/macro/water/micronutrient targets, unit preferences, timezone, and theme/layout preferences.
Health and fitness data you log. Workouts and exercise sets; nutrition logs (foods, calories, macronutrients, micronutrients); recipes and saved foods; water intake; body measurements, weight entries, and body-fat estimates; progress photos.
Mental wellness data you log. Mood scores, journal entries, habit tracking, and guided-session responses. We treat this as sensitive data (see Section 6).
Social content. Posts, photos, comments, likes, follows, workout-partner connections, direct messages and attachments, shared workouts/recipes/themes, reports you file about other users, and feedback you send us.
Coaching data. If you connect with a coach: the coach–client relationship, your per-category sharing permissions, coach notes, assigned programs, workouts, and wellness tasks.
2.2 Information collected automatically
- Device and technical data: device type, operating system, app version, IP address, access times, and diagnostic information generated when the app communicates with our servers.
- Push notification token: if you enable notifications, we store a push token so we can deliver them.
- Motion data (on-device): if you use live cardio tracking, the app may use your device's accelerometer to count steps during a session.
We do not collect precise location or contacts. The mobile application does not use third-party analytics or advertising SDKs. However, on the Graviflux website, we use third-party advertising services (Google AdSense) which may collect IP addresses and use cookies for ad personalization.
2.3 Information from other sources
- Apple Health (HealthKit), iOS only and with your permission: we read heart rate and step count during live workouts and read nutrition data to keep your food log in sync; we write meals you log and workouts/steps you complete back to Apple Health. You can revoke this at any time in iOS Settings → Health.
- Sign in with Apple / Google Sign-In: name and email address, used only to create and authenticate your account.
- Open Food Facts: when you scan a food barcode, the barcode number is sent to the Open Food Facts public database to look up nutrition information. No account or personal information is sent with the request. Food data is provided under the Open Database License (ODbL) — see Section 13.
- Payment providers: subscription status from Apple App Store / Google Play (via RevenueCat) or Stripe (web purchases). We never receive or store your full payment card details.
3. How We Use Your Information
| Purpose | Data used | Legal basis (GDPR/UK GDPR) | |---|---|---| | Provide the Service: tracking, dashboards, progress analytics, syncing across devices | Account, profile, health & fitness, wellness data | Performance of a contract; explicit consent for health data (Art. 9(2)(a)) | | Social features: feeds, comments, messaging, sharing | Social content, profile | Performance of a contract | | Coaching: sharing your data with a coach you connected with | Categories you enabled | Explicit consent (revocable per category) | | Apple Health sync | Health data you authorized | Explicit consent (revocable in iOS Settings) | | Manage subscriptions and premium entitlements | Subscription status, purchase identifiers | Performance of a contract | | Send push notifications you enabled | Push token | Consent | | Security, fraud prevention, moderation of reported content, enforcing our Terms | Account, technical, reported content | Legitimate interests; legal obligation | | Respond to support requests and feedback | What you send us | Legitimate interests | | Display sponsored content in the community tab | None — placements are contextual, not selected using your personal data | Legitimate interests | | Comply with law | As required | Legal obligation |
We do not sell your data. Any sponsored content shown in the app's community tab is contextual: placements are not selected using your personal data, and never using your health, wellness, or Apple Health data. On the website, Google AdSense uses cookies for personalized advertising (see Section 12). We do not use Apple Health data for any purpose other than providing the health and fitness features you requested; it is never used for advertising, shared with data brokers, or sold — as required by Apple's Developer Program License Agreement and App Review Guidelines (§5.1.3).
We do not make automated decisions about you that produce legal or similarly significant effects.
4. How Your Information Is Shared
We share personal data only as follows:
With other users, as you direct.
- Your display name, username, avatar, and bio are visible to other users; if your profile is set to private, your content visibility is restricted accordingly.
- Content you post to the community, comments, likes, and shared items are visible to their intended audience.
- Direct messages and attachments are visible to conversation participants.
- Workout-sharing/accountability feeds are visible only to mutual connections you established.
With your coach, only per your toggles. Nutrition, workouts, wellness (including mood and journal entries), weight, and progress photos each have an independent permission you control and can revoke at any time. Revoking a permission stops the coach's access going forward.
With service providers (processors) acting on our instructions:
| Provider | Role | Data involved | |---|---|---| | Supabase | Database, authentication, file storage, backend hosting | All account and app data | | RevenueCat | In-app subscription management | Purchase/subscription identifiers, anonymized app user ID | | Apple App Store / Google Play | Payment processing for in-app purchases | Handled by Apple/Google under their own policies | | Stripe | Payment processing for web purchases | Handled by Stripe; we store customer/subscription IDs only | | Expo (push notification service) | Delivering push notifications | Push token |
Each provider is bound by contractual data-protection obligations and may not use your data for its own purposes.
With sponsors and advertisers: Sponsors of content shown in the app's community tab do not receive any personal data about you. At most, we may report aggregate, de-identified statistics to a sponsor (for example, the total number of times a placement was viewed). For website visitors, Google AdSense may collect information via cookies (see Section 12).
For legal reasons. If required by law, subpoena, or legal process; to protect the rights, safety, or property of Graviflux, our users, or the public; or to enforce our Terms of Service.
Business transfers. If we are involved in a merger, acquisition, or sale of assets, your data may be transferred; we will notify you before your data becomes subject to a different privacy policy.
We do not sell personal data. For website visitors, the use of Google AdSense may be considered "sharing" for cross-context behavioral advertising under the California Consumer Privacy Act (see Section 10.2). The mobile app does not "share" data in this manner.
5. Apple Health / HealthKit
If you enable Apple Health integration:
- Data read from HealthKit (heart rate, steps, nutrition) is used solely to provide the features you enabled.
- HealthKit data is never used for advertising or marketing, never disclosed to third parties for their own purposes, never sold, and never used to make eligibility decisions (employment, insurance, credit, etc.).
- You can revoke Graviflux's HealthKit access at any time in iOS Settings → Privacy & Security → Health, or Settings → Health → Data Access & Devices.
6. Sensitive Data (Health, Wellness, and Mental Health)
Fitness, nutrition, body-measurement, mood, and journal data are sensitive. We apply the protections in this policy to all of it, and additionally:
- We collect it only when you actively log it or explicitly authorize a sync.
- We use it only to provide the Service to you (and to a coach, only per your explicit per-category consent).
- We do not use it for advertising, do not sell it, and do not disclose it except as described in Section 4.
- Consumer health data rights for Washington State residents are described in Section 10.4.
7. Data Retention
We retain your data while your account is active. When you delete your account (Settings → Delete Account), your account and associated personal data are deleted from our production systems, subject to:
- residual copies in encrypted backups, which are purged on a rolling basis within 30 days;
- data we must retain to comply with legal obligations, resolve disputes, or enforce agreements (e.g., records of moderation reports or payment records held by Apple, Google, or Stripe);
- content you posted that other users have interacted with may be removed or anonymized rather than leaving conversations broken, where feasible we delete it.
Subscription and transaction records are retained by the relevant payment platform under its own policy.
8. Security
We use industry-standard safeguards: encryption in transit (TLS) for all communication with our servers, encryption at rest for stored data, row-level security policies restricting every database record to authorized users, and scoped access controls for file storage (photos, attachments). No method of transmission or storage is 100% secure; if a breach affecting your personal data occurs, we will notify you and regulators as required by applicable law (including within 72 hours where GDPR applies).
9. International Data Transfers
Our servers are hosted by Supabase in the United States (US East region). If you access the Service from outside that region, your data will be transferred to and processed there. Where GDPR or UK GDPR applies to transfers outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.
10. Your Rights
You can exercise most rights directly in the app:
- Access / portability: Settings → Data & Privacy → Export My Data.
- Deletion: Settings → Delete Account.
- Correction: edit your profile and logs at any time.
- Withdraw consent: revoke coach permissions in Settings; revoke Apple Health access in iOS Settings; disable notifications in system settings.
For anything else, contact support@graviflux.com. We respond within the timeframe required by applicable law (30 days under GDPR, 45 days under CCPA, extendable where permitted). We will verify your identity via your account before acting on a request. You may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights.
10.1 European Economic Area, United Kingdom, and Switzerland (GDPR/UK GDPR)
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time (without affecting prior processing). The data controller is Graviflux (sole proprietorship of Isaac Nathanael Hernandez-Alvarez, Wabash County, Indiana, USA). You may lodge a complaint with your local supervisory authority (or the ICO in the UK). Our legal bases are listed in Section 3; health and wellness data is processed on the basis of your explicit consent.
10.2 California (CCPA/CPRA)
You have the right to know, access, correct, and delete personal information; the right to limit use of sensitive personal information; and the right to opt out of sale/sharing. We do not sell personal information and we use sensitive personal information only to provide the Service. However, because the graviflux.com website uses Google AdSense, this may be considered "sharing" of internet/technical activity for cross-context behavioral advertising. You may opt out by managing your cookies or visiting Google Ads Settings. Categories collected (see Section 2): identifiers; account credentials; health and wellness information; photos; audio/visual content you upload; inferences you create via your own goals; internet/technical activity. We collect them from you, your device, and the sources in Section 2.3, for the purposes in Section 3, and disclose them only as described in Section 4.
10.3 Other U.S. state privacy laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling. We do not engage in targeted advertising, sale, or profiling (contextual sponsored content that is not selected using your personal data is not "targeted advertising" as these laws define it). Where a state provides an appeal process for refused requests, you may appeal by replying to our decision, and we will respond as that law requires.
10.4 Washington State — Consumer Health Data (My Health My Data Act)
Fitness, nutrition, and wellness data you log is "consumer health data" under Washington law. We collect it only with your consent and only to provide services you request; we do not sell it and do not share it except with processors and per your coach-sharing choices. Washington residents have the right to access, delete, and withdraw consent for consumer health data, and to a list of third parties with whom it has been shared, by contacting support@graviflux.com. If we refuse a request, you may appeal by replying to our decision; if the appeal is denied, you may contact the Washington Attorney General. [If a separate linked "Consumer Health Data Privacy Policy" page is required for your distribution footprint, host this section as its own page.]
10.5 Canada (PIPEDA), Australia, and other jurisdictions
We honor applicable access, correction, and deletion rights under your local law. Contact us at support@graviflux.com.
11. Children's Privacy
The Service is not directed to children under 13 (or the higher minimum age required in your jurisdiction, e.g., 16 in some EEA countries without parental consent). We do not knowingly collect personal data from children under 13. If we learn we have collected personal data from a child under the applicable minimum age, we will delete it. If you believe a child is using the Service, contact support@graviflux.com.
12. Third-Party Advertising (Website Only)
On the Graviflux website (graviflux.com), we use Google AdSense to serve advertisements.
- Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to our users based on their visit to our sites and/or other sites on the Internet.
- Users may opt out of personalized advertising by visiting Google Ads Settings.
- Alternatively, you can opt out of a third-party vendor's use of cookies for personalized advertising by visiting www.aboutads.info.
13. Third-Party Services and Data Sources
The Service links to or interoperates with third-party services governed by their own privacy policies: Apple (Sign in with Apple, App Store, Apple Health), Google (Google Sign-In, Google Play), Stripe, RevenueCat, and Expo. Nutrition lookup data is provided by Open Food Facts (openfoodfacts.org) and made available under the Open Database License (ODbL); barcode lookups sent to Open Food Facts contain no personal information.
14. Push Notifications
You can enable or disable push notifications at any time in your device settings or in-app settings. Notifications may include social activity, coaching updates, and reminders you configure. We do not send third-party marketing via push.
15. Changes to This Policy
We may update this Privacy Policy. For material changes we will notify you in the app or by email and update the "Last updated" date, and where required by law we will ask for renewed consent. Continued use after the effective date of a revised policy constitutes acceptance except where consent is required.
16. Contact Us
Graviflux (sole proprietorship of Isaac Nathanael Hernandez-Alvarez) Wabash County, Indiana, USA Email: support@graviflux.com
We have not appointed an EU/UK representative at this time; if GDPR Article 27 comes to require one as our EU/UK user base grows, we will designate one and update this policy.