EvrFit Privacy Policy

Draft — not approved for publication

Effective date: 1 August 2026

1. Who we are

EvrFit is provided by IntegratingMe d.o.o., registered in Bosnia and Herzegovina under number [COMPANY REGISTRATION NUMBER], with its registered office at [REGISTERED ADDRESS] ("EvrFit", "we", "us", or "our"). We are the controller of the personal data described in this policy.

Privacy contact: privacy@evrfit.app

2. Scope and age requirement

This policy applies to the EvrFit mobile app and related services. EvrFit is intended only for people aged 18 or older. By creating or using an account, you confirm that you are at least 18.

If we learn that a person under 18 has provided personal data, we will restrict the account, investigate, and delete the data unless the law requires otherwise. A parent or guardian may contact us at privacy@evrfit.app.

3. Data we collect

Depending on the features you use, we collect:

Apple Health access is optional and controlled through Apple’s permission interface. If you grant access, EvrFit reads only the categories you approve. The current app uploads derived daily summaries needed by its features to our backend; the complete Apple Health database remains under Apple’s and your device’s controls.

4. How we obtain data

We receive data directly from you, from Apple Health when you authorize access, from Google when you choose Google Sign-In, and from technical systems that operate and secure the service.

5. Why we use data and our legal bases

We use personal data to:

For ordinary account and service data, we generally rely on performing our contract with you. For special-category health data, including medical conditions, medications, HealthKit summaries, and medical reports, we rely on your explicit consent where required by law. We may rely on legal obligations or legitimate interests for narrowly scoped security, fraud prevention, and legal compliance after assessing your rights.

AI-assisted processing of health data is integral to EvrFit: plan generation, weekly reviews, food-photo analysis, and medical-report interpretation all depend on it. For this reason consent is requested once, before you begin using the app, and the app cannot be used without it.

There is no separate in-app control to withdraw this consent while keeping your account. To withdraw, delete your account from Profile → Account → Delete Account. Deletion is immediate and permanent, and erases the data described in section 9. Withdrawal does not make earlier lawful processing unlawful.

You can revoke Apple Health access separately at any time in iOS Settings, without affecting your account.

6. AI processing

When you request an AI feature, relevant content is sent from our backend to OpenRouter, which routes the request to the selected model provider. Depending on the feature, the content can include profile details, goals, food or workout information, health metrics, known conditions, medications, and extracted medical-report text.

This information is not anonymous merely because your account ID is omitted from an AI prompt: the content itself may identify you or concern your health. AI output may be incomplete or wrong and is provided for general wellness information, not diagnosis, treatment, or emergency care.

Every request we send to OpenRouter sets a data-collection policy of deny. This restricts routing to model providers that do not retain submitted content beyond serving the request. Your content is not used to train AI models, by us, by OpenRouter, or by the providers we route to. Requests currently use the model google/gemini-3.1-flash-lite and are served by Google (Google AI Studio and Google Cloud Vertex AI endpoints).

If we change models or providers in a way that alters this position, we will update this policy and, where the change concerns health data, seek renewed consent.

7. When we share data

We disclose data only as needed to operate the service, follow your instructions, protect the service, or comply with law. Current categories of recipients include:

We do not sell personal data. We do not use Apple Health or medical data for advertising, data brokerage, or marketing profiling.

8. International transfers

Some providers process data outside your country or the European Economic Area. Where required, we use an approved transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and assess supplementary safeguards.

Our Supabase project is hosted in the ap-northeast-1 region (Tokyo, Japan). Japan is covered by a European Commission adequacy decision, so transfers of EEA personal data to this region rely on that decision.

AI requests are routed by OpenRouter (United States) to Google endpoints, which may process content in multiple regions. These transfers rely on Standard Contractual Clauses in the respective providers' data processing terms.

Publication blocker: complete and record the transfer impact assessments for OpenRouter and Google, and confirm the signed DPA/SCC set for each processor.

9. Retention and deletion

We keep personal data only as long as needed for the purposes above, legal obligations, dispute handling, and security. EvrFit automatically deletes food logs and their referenced legacy photos, workout logs, water logs, weight logs, medication logs, synchronized health summaries, plans, and reviews after they are more than 90 days old. The cleanup runs daily, so an expired item may remain for up to about 24 additional hours. New food-analysis photos are not stored by EvrFit. This does not delete information held independently in Apple Health.

Medical reports, your account and profile, avatar, devices, and AI usage/credit records follow separate retention rules and are not deleted by the rolling activity cleanup. You may delete individual items where the app offers that control. Reset Preferences deletes many logs, plans, and medical reports but does not delete your account or all associated data. You can permanently delete your account and associated production data from Profile → Account → Delete Account. Limited security or billing records may be retained only where another documented legal basis requires it and are otherwise deleted or de-identified.

10. Security

We use measures intended to protect data, including authenticated access, owner-scoped database rules, private file storage, encrypted transport, and platform credential storage. No system is completely secure. Access controls protect confidentiality but do not make data anonymous.

11. Your rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, and to withdraw consent. You may also complain to [SUPERVISORY AUTHORITY] or your local data-protection authority.

Send requests to privacy@evrfit.app. We may request proportionate information to verify your identity. We normally respond within one month where the GDPR applies, subject to lawful extensions.

You can revoke Apple Health permissions in iOS settings at any time. As explained in section 5, consent to AI processing of health data is withdrawn by deleting your account, which erases your data immediately.

12. Changes

We may update this policy when our practices, providers, or laws change. We will post the updated date and provide additional notice when a change is material or requires renewed consent.

13. Contact

IntegratingMe d.o.o.
[REGISTERED ADDRESS]
privacy@evrfit.app