Privacy Policy
Last updated: July 30, 2026
fuel (“we”, “us”) makes an AI health coach. This page explains what data we collect, why we collect it, who can see it, and how to delete it. If anything here is unclear, email support@get-fuel.app.
Who operates fuel
Fuel is a trading name. Fuel is operated from Dubai, United Arab Emirates, and can be contacted at support@get-fuel.app.
What we collect
- Account: email, name, password hash, sign-in provider (Apple/Google if used).
- Body & profile: your age, sex, height, weight and — if you enter it — body-fat percentage; plus your goal, diet style, training experience and how many days a week you train, your chronotype and job type, unit preference (metric/imperial), your bedtime and wake-time goal, your goal weight and target date, and any weigh-ins you log. These are what your calorie and macro targets are computed from. The body step is skippable; anything you leave blank we don't store.
- Health screening answers: onboarding asks the five SCOFF eating-disorder screening questions, and — if you told us you are female — whether you are pregnant or postpartum. We store the number of “yes” answers (0–5) and the pregnancy answer; we do not store which individual questions you answered yes to. They exist for one reason: together with your age and your BMI they produce an internal at-risk classification (under 18, age not on file, underweight, height or weight not on file, pregnancy, positive eating-disorder screen) that stops the app auto-prescribing a calorie deficit to someone it isn't safe for. That classification is also sent to the AI Coach — see “Who else can see it”.
- Health entries: meals, water, caffeine, workouts, sleep schedule, daily check-ins (including any note you type), journal entries, goals you create.
- Photos: food photos you take or choose for AI meal estimation, and an optional profile photo. Used to estimate nutrition and show your avatar — never for advertising. A food photo is sent to Google's Gemini for the estimate and is not stored on our servers: we keep the nutrition numbers it returns, not the picture. Your profile photo is stored on your profile and goes when your account goes.
- Wearable data (Whoop): when you connect Whoop, we read recovery, sleep, strain, and workouts via Whoop's OAuth API — we never have your Whoop password. We store only the derived daily metrics we compute for you — never a verbatim copy of a provider's raw data feed. (Apple Health / HealthKit is not currently connected.)
- Wearable data (Oura Ring): when you connect an Oura Ring, we get read-only access through Oura's own OAuth sign-in — we never have your Oura password, and we cannot write anything to your ring account. About once an hour we read the day's records and store the daily metrics we derive from them: readiness score, HRV, resting heart rate, sleep (score, time in bed, time asleep, efficiency, REM/deep/light/awake minutes, bedtime and wake time), respiratory rate, body-temperature deviation, and your recorded workouts (activity, start and end time, intensity, calories, distance). On first connect we pull up to 180 days of that history. As with Whoop we keep only these derived daily metrics — never a verbatim copy of Oura's raw feed — and disconnecting deletes them (see below).
- Voice input: when you tap to log or speak to Coach by voice, the phone's microphone is used to turn your speech into text. It runs only while you actively use it — never in the background — and we keep the text, not an audio recording. The transcription itself is done by iOS, not by us, and on the standard iOS path the recorded audio is sent to Apple's speech-recognition service to be turned into text. So if you speak a meal or a message to Coach, assume Apple received that audio. Only the resulting text reaches our servers — we never receive or store the recording.
- Subscription: your Apple App Store receipt and your plan tier. Pro is sold through the Apple App Store only, and Apple takes the payment — we never see your card number.
- App usage: behavioural interaction events — a screen opened, an onboarding step reached, a food logged. These go to PostHog (product analytics) so we can see where the app is failing people. Your health data is never in them: a code-level allowlist strips everything but the event name and a fixed set of non-health fields (like which step you reached) before anything leaves our server. No meals, weights, sleep, or wearable metrics. Crashes and errors are a separate pipeline with a different processor — see Sentry under “Who else can see it”.
What we don't collect
- No advertising profiles, no cross-app ad tracking, and we don't request the IDFA ad identifier.
- No location or contacts access.
- Camera and photo access only when you add a food photo or profile picture — never in the background. Microphone only during voice input you start (above).
- No selling of your data, and no sharing it with data brokers or advertisers.
- Transparency note: our sign-in library (used for Apple and Google sign-in) bundles Facebook SDK components in the app binary. We do not offer Facebook Login, do not send Facebook your data, and do not use its ad-attribution features.
How we use your data
- To compute your Fuel/Rest/Train scores and your calorie, macro and water targets, and show them back to you.
- To keep the plan safe: your age, BMI and screening answers gate whether the app is allowed to set you a calorie deficit at all. They are never used to score, rank, or profile you.
- To give Coach context — your recent logs and wearable data shape the responses.
- To send transactional email (verification, password reset). These are essential to your account, so they are sent whether or not you subscribe to anything else.
- To send updates about Fuel, only if you asked for them — by joining the waitlist or opting in. Every one carries a one-click unsubscribe, and unsubscribing never affects the account emails above. We do not sell or share your address, and we do not send you other companies' offers.
- To debug errors. We don't profile users for advertising.
Who else can see it
- Google (Gemini)— the AI features send data to Google's Gemini API. Concretely:
- Coach: your message, the last few turns of the conversation, and a summary of your context — your Fuel/Rest/Train scores, today's targets and what you've logged against them, your last 7 days of food entries (including the item names), your logged and detected workouts, your last 14 days of check-ins including any note you typed, your current and goal weight, your height/weight/max heart rate, your bedtime and wake goal, and the wearable metrics we've synced for you (for example Whoop recovery, sleep and strain).
- Your at-risk classification: when the safety screen above is active, the instruction we send with your message names the categories that apply — under 18, age not on file, underweight, height or weight not on file, pregnancy, or a positive eating-disorder screen — so the model cannot be talked into prescribing a cut. If your own message raises an eating-disorder or medical topic, that category is included too. This is sensitive health data going to Google, and it goes there for that one reason.
- Food AI: the food photo, nutrition-label photo, or food description you submit for an estimate.
- Two deliberate exceptions: the free text of your journal entries and your first name are not sent — Coach only ever sees a journal entry's date, mood and tags. And if a message looks like a self-harm or medical emergency, you get a fixed safe reply written by us and the model is never called at all.
- Whoop — we send your account's Whoop OAuth tokens to Whoop's API to read your data.
- Oura — we send your account's Oura OAuth tokens to Oura's API to read the ring metrics listed above, on connect and then roughly hourly while you stay connected.
- Open Food Facts — when you search a food by name or scan a barcode, the search term or the barcode number is sent to Open Food Facts (an open, non-commercial food database) to look up nutrition. That request goes from our server, not your phone, and carries nothing else about you — no account, no email, no health data.
- Apple — three separate things reach Apple, and only these three. Sign-in: if you use Sign in with Apple, Apple is the one signing you in, so Apple knows you have a fuel account — we only verify the token it issued. Purchases: if you subscribe, your App Store receipt is sent to Apple to be validated, and Apple takes the payment. Voice: when you use voice input, iOS sends the audio to Apple's speech-recognition service to transcribe it (see “Voice input” above) — and that audio contains whatever you said, which for us usually means what you ate.
- Google (sign-in) — if you use Google sign-in, we verify that sign-in with Google, so Google knows you signed in to fuel. That is all it is used for. Google does not handle payment for fuel: Pro is sold through the Apple App Store only.
- PostHog — product analytics. Off entirely unless a key is configured: with no key set, nothing initialises and nothing is sent. When it is on it receives the event name, the allowlisted non-health fields and your account id — never your meals, weights, sleep or wearable data (see “App usage” above).
- Sentry — crash and error reporting. This one is not conditional: the reporting endpoint is compiled into our web and server code, so error reports are sent from every production deployment. A report carries the error message, the stack trace through our own source files, and the request method and route it failed on, plus basic request metadata. Request and response bodies are not attached, and cookies and authorisation headers are filtered out — so your meals, weights, sleep and wearable data are not part of a crash report. Inside the phone app, Sentry is off unless a key is configured.
- Resend — used to send verification + reset emails.
- Hosting — Vercel (compute, and the AI gateway our food-estimate requests to Google pass through) and Turso (database). They process data on our behalf.
- Upstash — a Redis service that holds our rate-limit counters, so one account, one email address or one IP can't flood the API. Each counter is a short key naming the action plus whoever it is counting, and a number. Depending on the action, the part identifying you is your account id, your email address (sign-in, password reset, and the app-download link), your IP address (sign-up and the download link again), or the last few characters of the Apple or Google sign-in token being checked. Keys expire on their own when the rate-limit window ends — minutes for most actions, up to 24 hours for the app-download link. No health data, and nothing you have logged.
- That is the whole list. We do not sell your data and we do not share it with advertisers or data brokers.
How we protect & retain wearable data
- Connection tokens (your Whoop and Oura OAuth tokens) and your health data are encrypted in transit and at rest.
- We keep only the derived daily health metrics we compute for you — we do not build a permanent copy of any provider's raw data feed.
- Wearable data is used only to provide the app's features to you (your Fuel/Rest/Train scores and Coach). We never use it for advertising or marketing, never sell it, and never share it with data brokers.
- Disconnecting Oura deletes the tokens we hold and every metric we synced from your ring — Oura's API terms require that, so nothing of it is kept.
- Disconnecting Whoop deletes the tokens, which stops the sync immediately. Your already-synced Whoop history stays so your trends survive a reconnect; it is removed when you delete your account, or sooner if you email us.
- What disconnecting cannot do is cancel the authorisation on the provider's own side. We delete our copy of the tokens, which is all we can reach — if you also want the grant withdrawn inside your Whoop or Oura account, remove fuel there.
AI Coach limitations
Coach is an AI assistant. It can be wrong. It is not medical advice and does not diagnose, treat, or prevent disease. If you are managing a health condition, talk to a qualified clinician.
Deleting your data
You can delete your account and all its data from inside the app: Profile → Account → Delete account. You confirm by typing your account email, and the deletion runs there and then, in one operation. It removes your account and profile, your body details and screening answers, your food, water, caffeine, weight, workout and training history, your check-ins, journal and goals, your saved meals and onboarding answers, your Coach conversation and everything it remembered, your supplement log, your notification, subscription and in-app event records, your profile photo, your sign-in and refresh tokens, your Whoop and Oura connection tokens and every metric synced from them — and your address if it was ever on our waiting list.
If you'd rather we did it, email support@get-fuel.appfrom your account address and we'll delete the same set for you.
Disconnecting a wearable is not the same as deleting its data, and the two providers differ. Disconnecting Oura does purge it: the tokens and every metric we synced from your ring go. Disconnecting Whoop deletes the tokens and stops the sync, but your already-synced Whoop history stays so your trends survive a reconnect — the app says so when it asks you to confirm. To remove that Whoop history, delete your account or email us.
One honest limit: deleting your account deletes ourcopy of a wearable's access tokens, but we can't cancel the authorisation inside your Whoop or Oura account for you — remove fuel there too if you want that grant gone.
How long we keep it
We keep what you log for as long as your account exists — there is no background job that quietly deletes your older entries, so your history stays there for you. When you delete your account your data is removed within 30 days; the in-app deletion above clears it from our live database immediately. Aggregated server logs may be retained up to 30 days for security.
Children
You must be at least 13 years old to have a fuel account. Our onboarding rejects an age below 13, and we do not knowingly collect data from anyone under 13. If you are a parent or guardian and believe a child under 13 has an account, email support@get-fuel.app and we will delete the account and everything in it. If we find out ourselves that an account holder is under 13, we delete that account and its data the same way.
Separately, and for every user under 18: fuel does not set weight-loss calorie deficits for anyone whose profile age is under 18, or whose age we don't have on file. In both cases the calorie target is held at maintenance instead, and the AI Coach is instructed not to recommend a deficit, fasting, or a restrictive plan. That is a safety hold on the plan, not an age limit — under-18s can use fuel.
Contact
Questions, requests, or to exercise data rights, email support@get-fuel.app.