FTNS Privacy Policy

The short version

Your health data lives on your device. No ads, no tracking — we never follow you across other apps or websites, and we never sell data. A few specific things can leave your device, each explained below: anonymous usage analytics (with an off-switch); your account's email plus a small account profile — your membership status, level, streak, gems, and the coach's brief about you, never your logs, plans, photos, run routes, or Apple Health data; and — only for features you explicitly turn on — the photos or daily summaries those features need to work. Your GPS run routes never leave this phone.

Who we are

FTNS is made and operated by Caleb Weinberger, an independent developer — so the “we” throughout this policy is one person, and the decisions described here about your data are that person's. For anything in this policy, email caleb@verifyblock.com.

What the app stores, and where

Your profile, goals, daily logs, meals, workouts, measurements, run routes, avatar, scores, and settings are saved in private, protected files inside the app's sandbox on this device. These files are excluded from iCloud device backups. None of it is stored on our servers, and nothing read from Apple Health ever is. Our backend keeps anonymous rate-limit counters that expire within 48 hours and — only while you are signed in — the account profile described under Your account, which does include a few health-related details you entered yourself: your sex, age, height, body weight, and your recent Life Scores.

Your account

Setting up the app creates an account — or signs you into one you already have — with an email address and password, handled by Firebase Authentication (Google); the app needs one because your membership and your progress are recognised through it on any phone you sign into. Signing in also keeps a small account profile in our database (Cloud Firestore, Google), readable and writable by your account only, so a new phone picks up where you left off and a membership bought on one device is recognised on another. The profile holds: whether your membership is active and when it renews (recorded by our server once it has verified the purchase with the App Store — never by the app itself); your level, XP, streak, streak freezes, rank badge, and gems; your name; and the coach's standing brief about you — your sex, age, height, the body weight you entered yourself, goals, pace, diet style, workouts per week, typical exercise weights, coach tone, liked, disliked, and most-used exercises, liked and recently logged meal names, this week's in-app workouts, and your recent Life Scores. It never holds your workout or meal plans, daily logs, measurements, photos, run routes, or anything read from Apple Health. Signing out stops the sync, and the app keeps working on this device with what is already here. You can delete the account — and its profile — in Settings, or, if your membership isn't active, from the membership screen the app opens on; if your sign-in session is too old for immediate deletion, the app signs you out and you can delete the account by signing in again and repeating the deletion.

Usage analytics

To understand which parts of the app people actually use, we collect a small amount of anonymous usage data through Google Analytics for Firebase. It covers: which screens you open — the page you are on, never what is on it — that you finished onboarding, and that you logged a meal or a workout: the fact of the action, never its content. Google's SDK also records standard technical details such as a random app-instance identifier it generates, your device model, OS version, country, and language. We use this only to improve the app.

It never includes your health or fitness data. Not your weight, measurements, calories, macros, food, workout type, distance, routes, streak, scores, photos, or anything read from Apple Health. Workouts imported from Apple Health produce no analytics event at all.

This data is not linked to your account or identity, is never sold or shared with anyone else, and is never used for advertising or to build a profile of you. Google processes it on our behalf as our service provider, and is required to protect it to at least the standard described in this policy. The off-switch lives in Settings › Privacy.

Apple Health

With your permission, the app reads steps, sleep, workouts, heart rate, weight, body fat, lean mass, waist, water, caffeine, and alcohol from Apple Health to fill in your trackers automatically — anything you enter yourself takes priority, and heart rate is read only during a run you are tracking. Access is read-only; the app writes nothing to Health. Apple Health data is used only on this device to power your own trackers, avatar, and scores. It is never used for advertising, marketing, or data mining, never sent to our analytics, and never stored in your account profile or anywhere on our servers. The one place a Health-derived number can leave the device is the AI coach summary described below — only if you turned the coach on, and only the day's totals and your latest weight as part of that summary. You can revoke Health access anytime in iOS Settings › Health.

Location & runs

When you start a run in Track › Running, the app uses your phone's GPS to draw your route and measure distance and pace — including while the phone is locked or in your pocket — until you finish or discard the run. The route, distance, time, pace, elevation, and, if a paired device writes it to Apple Health, your heart rate are saved on this device only, in protected files excluded from iCloud backups. Routes are never uploaded, never part of your account profile, and never sent to analytics; the run counts toward your calories and scores like any other workout. Location is used for nothing else, and you can revoke it anytime in iOS Settings › Privacy & Security › Location Services. Deleting a run deletes its route.

Photos & the real avatar

To build your real avatar, the app asks for three posed photos at sign-up. They travel through our own secure backend to our avatar-engine providers — Google (image editing) and Meshy (3D model) — and are used only to create your avatar. When the avatar engine isn't available in a build, your avatar comes from your body metrics alone and any photos stay on this device. The app does not keep the original photos after the build; what stays on this device are the finished models and the edited studio images the build produced, which the app can send back to Meshy if a build fails, so you don't have to retake your photos. Meshy holds a build's data on its servers until it is deleted — we ask Meshy to delete your build tasks when you cancel a build or delete your account. Your photos are never posted anywhere, never used to train AI, and never used for anything but your avatar. Meal photos you attach to entries stay on this device only and are deleted with the entry or your account. A nutrition-label photo you scan is different: it is sent for reading as described under AI features, and the app doesn't keep it.

AI features you switch on

Some features send data off-device to work, and each one asks for your consent in the app before its first use. Revoking consent takes effect immediately.

AI coach and plans (when available): your typed messages (roughly the last ten, plus the coach's replies between them) and a context summary go through our backend to our AI provider (Anthropic) to compose the answer. The summary can include: your sex, age, height, body weight, goals, pace, diet style, workouts per week and typical exercise weights; your coach tone and liked/disliked/frequent exercises and liked meals; the names of recently logged meals; and today's calories, protein, water, steps, and sleep — including values imported from Apple Health. It never includes your journal, photos, raw logs, or run routes. Nothing from these requests is stored on our servers; AI providers process it only to produce the reply. (If you are signed in, the standing part of that summary — without today's totals and without anything from Apple Health — is also kept in your account profile; see Your account.)

Voice food logging (when available): your speech is transcribed on this device — audio never leaves the phone. Only the resulting text is sent, the same way as a coach message, to work out the meal's macros: the AI provider looks each food up on the web, and those searches name the foods, never you. The foods it finds are kept in a food list on this device for next time; that list is never uploaded.

Food label scanning (when available): a photo you take or pick of a food's nutrition label, together with the name you typed for it, is sent through our backend to the same AI provider (Anthropic) to read the label's serving size and figures. Nothing else in the picture is used, the app never saves the photo, and our servers don't keep it; the food it reads joins the same on-device food list.

Photoreal previews (when available): the photos you pick are sent through our backend to Google's image service to generate the preview, deleted server-side immediately after, and the app shows you a deletion receipt.

How the app talks to our servers

Requests to our backend carry two things besides the feature's own data: a device-integrity token (Apple App Attest via Firebase App Check) proving the request comes from a genuine copy of FTNS — it identifies the app, not you — and a random installation identifier used only to apply fair-use rate limits. Our servers store no message content, no photos, no routes, and no health data; the server-side records are anonymous rate-limit counters keyed to that identifier, which expire within 48 hours, plus — while you are signed in — the account profile described under Your account. Deleting your account resets the identifier and the attestation identity.

Purchases

FTNS is a paid membership: a 7-day free trial, then a monthly or yearly subscription, processed entirely by Apple through the App Store — along with gem packs. We never see your payment details. If you are signed in, whether your membership is active and its renewal date can be kept in your account profile — recorded by our server once it has verified the purchase with the App Store — so a device you sign into recognises the membership you bought on another. Subscriptions renew until cancelled in your App Store account settings.

Notifications

Reminders — a daily nudge, a Sunday note that your weekly wrap-up is ready, a Monday kickoff, and a first-of-the-month check-in — are optional, generated on-device, and scheduled locally. Nothing about them touches a server. Turning them off in the app or in iOS Settings stops them completely.

Your controls

Settings › Privacy › “Share usage analytics” turns analytics off whenever you want. Switching it off stops collection immediately and clears the anonymous identifier behind it; nothing else in the app changes, and no feature is withheld either way.

Each AI feature's consent can be granted and revoked in the app, and revocation stops that feature's off-device processing immediately. Apple Health and Location access can be revoked in iOS Settings at any time; the app keeps working with what you enter yourself.

Settings › “Delete account & all data” (also offered on the membership screen whenever your membership isn't active) wipes everything the app has stored on your device — profile, logs, avatar, photos, models, run routes, scores — deletes your account profile from our database, asks Meshy to delete any avatar build tasks, deletes your sign-in account (or signs you out for a fresh-sign-in deletion, as described under Your account), and clears the analytics and installation identifiers. Usage events already sent to Google can no longer be tied back to you once that identifier is gone, and they age out at the end of the analytics retention period (at most 14 months). If you'd like us to confirm deletion, email caleb@verifyblock.com.

Age

FTNS is for people 16 and older. We don't knowingly collect anything from anyone under 16.

Not medical advice

FTNS is a game about building habits. It does not provide medical, nutrition, or mental-health advice. For personal health decisions, talk to a qualified professional.

Changes

If a future update changes what leaves your device — a new AI feature, more of your data in the account profile — this policy will be updated in the app and at the hosted policy link before that ships, and the App Store privacy labels will be updated to match.

Contact

Questions about privacy, or support of any kind? Email caleb@verifyblock.com — it reaches the person who made the app.


About this website

The policy above is the ftns.ai app's, and is published here word for word as it ships inside the app. This last part is about ftns.ai the website — run by the same person, but a different thing with different plumbing.

Website analytics. This website (not the app) uses Google Analytics 4 to measure page views and general traffic patterns. It sets first-party cookies in your browser and shares website usage data with Google, acting as our analytics provider. It is not connected to your ftns.ai account, your photos, or your Apple Health data. [TODO — counsel: consent mechanism and legal basis for EU/UK/EEA visitors, and whether analytics must be gated behind a consent banner before it loads.]

Update signups. If you enter your name and email address on the ftns.ai signup page, we store them — along with whatever you write in the "where did you hear about us" box — in this website's own database, so we can send you occasional updates about the app. That list is not connected to any ftns.ai account, is never used for advertising, and is never sold. It also holds the addresses left there before the app launched, gathered when the page offered a launch email. Email caleb@verifyblock.com to be taken off it and we will delete the entry. [TODO — counsel: consent wording, retention period, whether the pre-launch addresses may be mailed under the new purpose, and whether an unsubscribe link is required.]