Privacy policy
Ryze is a health app: it knows what you eat, what you weigh and when you train. This page says exactly what is collected, where it lives and how to delete it. It is written to be read, not skimmed.
In short
- Nothing is sold. Not to an advertiser, not to a data broker, not to an insurer. The app shows no advertising.
- The database is in the European Union. Your account, your meals and your workouts are hosted there.
- Meal photos are not kept. They are sent for analysis and deleted afterwards.
- Everything erases in one move. Settings → Account → Delete my account. All of it is gone within 30 days.
The rest of this page details each of those points.
1. What we collect
What you give us
- Account: email address, and a password if you do not sign in with Apple or Google.
- Profile: age, sex, height, weight, activity level and goal. These are the values used to compute your calorie target.
- Meals: foods logged, amounts, saved recipes.
- Training: workouts, exercises, sets, loads, durations.
- Meal photos: sent for analysis, then deleted.
What is collected automatically
- Location: only during a GPS cardio session, and only if you allowed it. It draws the route; it is neither shared nor used for anything else.
- Usage: screens opened, features used, crashes. Anonymised, to fix bugs.
- Device: model, iOS version, app version.
What comes from elsewhere
- Sign in with Apple or Google: we receive your name and email address, nothing more. With Apple's Hide My Email we do not even see the real address.
- OpenFoodFacts: product entries come from that public database. No personal data is sent to it.
2. Why
- To run the app: keep your account, compute your target, show your history, sync your devices.
- To analyse a photo or a sentence: the photo or the text of a meal is sent to an analysis model that turns it into foods and calories.
- To track your progress: weight curves, projections, workout statistics.
- To fix failures: understand why a screen crashed, from anonymised data.
- To write to you when needed: reminders you chose, information about your subscription. Never unsolicited marketing.
3. On what legal basis (GDPR)
- Performance of the contract: everything needed to provide the service you subscribed to.
- Consent: analysing your photos, GPS location, notifications. Each can be withdrawn in the settings at any time, without the rest ceasing to work.
- Legitimate interest: the security of the service and fixing failures.
- Legal obligation: what the law requires us to keep, notably for accounting.
4. Who it is shared with
We sell no personal data, to anyone. The only third parties that see any are the ones that run the service:
- Supabase — the database and authentication, on servers located in the European Union.
- Google Cloud (Gemini, Vision) — analysis of meal photos and text. The image is processed and then deleted.
- Firebase — anonymised usage statistics and crash reports.
- Apple — the subscription and payment. We never see your payment method; Apple passes us a subscription status and nothing else.
- OpenFoodFacts — a lookup in a public database. Nothing leaves your side towards them.
We may also hand over data if an authority makes a lawful, founded request — not otherwise.
5. Where it is stored, and how it is kept
- Database: European Union.
- Meal photos: stored temporarily for the length of the analysis, then deleted. They are not used to train any model.
- On your phone: a local copy so the app works offline. It goes when the app goes.
- In transit: everything travels over HTTPS/TLS.
- Passwords: hashed, never readable, including by us.
For how long
- Active account: as long as the account exists.
- After account deletion: everything is erased within 30 days.
- Meal photos: deleted right after the analysis.
- Anonymised technical logs: 90 days at most.
6. Your rights
Wherever you are, you can exercise the following rights — the GDPR requires them in Europe, we apply them to everyone:
- Access: receive a copy of your data.
- Rectification: correct what is wrong.
- Erasure: delete your account and everything with it.
- Portability: get your data back in an open format.
- Objection and restriction: refuse or limit certain processing.
- Withdrawal of consent: turn off location, notifications or analysis at any time.
7. Cookies
The mobile app uses no cookies. It keeps your preferences, your offline cache and your session token locally.
This website sets no cookies and uses no advertising tracker. Fonts are served from this domain rather than by a third party: opening this page sends your IP address to nobody but the site's host.
8. Minimum age
Ryze is for people aged 16 and over. We do not knowingly collect data from a younger child. If you believe that has happened, write to privacy@coach-ryze.com and the account will be deleted.
9. Transfers outside Europe
Photo analysis goes through Google Cloud, some of whose processing takes place in the United States. Those transfers are covered by the European Commission's standard contractual clauses. The database itself does not leave the European Union.
10. If this page changes
A material change is announced in the app and by email before it takes effect, and the date at the top of the page is updated. Continuing to use the app after that date counts as acceptance.
11. Reaching us
- Personal data: privacy@coach-ryze.com
- Data protection officer: dpo@coach-ryze.com
- Support: support@coach-ryze.com
You may also complain to your country's supervisory authority — the CNIL in France, the ICO in the United Kingdom, your Land authority in Germany.