Privacy Policy
Last updated: July 17, 2026
fuel (“we”, “us”) makes an AI health coach. This page explains what data we collect, why we collect it, who can see it, and how to delete it. If anything here is unclear, email support@get-fuel.app.
What we collect
- Account: email, name, password hash, sign-in provider (Apple/Google if used).
- Health entries: meals, water, caffeine, workouts, sleep schedule, daily check-ins, goals you create.
- Photos: food photos you take or choose for AI meal estimation, and an optional profile photo. Used to estimate nutrition and show your avatar — never for advertising.
- Wearable data (Whoop): when you connect Whoop, we read recovery, sleep, strain, and workouts via Whoop's OAuth API — we never have your Whoop password. We store only the derived daily metrics we compute for you — never a verbatim copy of a provider's raw data feed. (Apple Health / HealthKit is not currently connected.)
- Voice input: when you tap to log or speak to Coach by voice, we use the microphone to convert your speech to text. It runs only while you actively use it — never in the background — and we keep the text, not an audio recording.
- Subscription: Apple/Google receipt + plan tier. Apple/Google handle payment — we never see your card number.
- App usage: behavioural interaction events — a screen opened, an onboarding step reached, a food logged. We send these to PostHog (product analytics) and Sentry (crash reporting) to understand and fix the app. Your health data is never sent to them: a code-level allowlist strips everything but the event name and a fixed set of non-health fields (like which step you reached) before anything leaves the app. No meals, weights, sleep, or wearable metrics.
What we don't collect
- No advertising profiles, no cross-app ad tracking, and we don't request the IDFA ad identifier.
- No location or contacts access.
- Camera and photo access only when you add a food photo or profile picture — never in the background. Microphone only during voice input you start (above).
- No selling of your data, and no sharing it with data brokers or advertisers.
- Transparency note: our sign-in library (used for Apple and Google sign-in) bundles Facebook SDK components in the app binary. We do not offer Facebook Login, do not send Facebook your data, and do not use its ad-attribution features.
How we use your data
- To compute your Fuel/Rest/Train scores and show them back to you.
- To give Coach context — your recent logs and Whoop data shape the responses.
- To send transactional email (verification, password reset). No marketing email.
- To debug errors. We don't profile users for advertising.
Who else can see it
- Google Gemini — when you use the AI Coach, your messages plus a summary of your recent health context (your Fuel/Rest/Train scores, recent logs, and connected Whoop metrics such as recovery, sleep, and strain) are sent to Google's Gemini API to generate replies. This is health data leaving the app; it powers Coach and nothing else. Google's API terms apply.
- Whoop — we send your account's Whoop OAuth tokens to Whoop's API to read your data.
- PostHog & Sentry — product-analytics and crash-reporting processors. They receive behavioural event names and non-health context only (never your meals, weights, sleep, or wearable data — see “App usage” above). Off entirely unless configured.
- Resend — used to send verification + reset emails.
- Hosting — Vercel (compute) and Turso (database). They process data on our behalf.
- That's it. We do not sell your data and we do not share it with advertisers.
How we protect & retain wearable data
- Connection tokens (e.g. your Whoop OAuth tokens) and your health data are encrypted in transit and at rest.
- We keep only the derived daily health metrics we compute for you — we do not build a permanent copy of any provider's raw data feed.
- Wearable data is used only to provide the app's features to you (your Fuel/Rest/Train scores and Coach). We never use it for advertising or marketing, never sell it, and never share it with data brokers.
- Disconnecting a device (for example “Disconnect Whoop”) deletes that provider's tokens and the metrics we synced from it.
AI Coach limitations
Coach is an AI assistant. It can be wrong. It is not medical advice and does not diagnose, treat, or prevent disease. If you are managing a health condition, talk to a qualified clinician.
Deleting your data
Sign in and email support@get-fuel.app from your account email asking us to delete. We remove your account row, profile, food log, water log, workouts, check-ins, journal, goals, wearable connection tokens (Whoop, and any others you connect), and the health metrics synced from them. You can also purge a single provider at any time by disconnecting it in the app. Aggregated server logs may be retained up to 30 days for security.
Children
fuel is not designed for people under 16. Don't use it if you are.
Contact
Questions, requests, or to exercise data rights, email support@get-fuel.app.