Privacy policy

In effect from 9 August 2026

This is what FitMess knows about you, why it knows it, who else sees it and how you erase it. No fine print — if it is not written here, we do not do it.

Who processes your data

FitMess is run by Marko Bera, a natural person in Serbia. That same person is the data controller under the Serbian Data Protection Act and the General Data Protection Regulation (GDPR). For anything to do with your data, write to markobera749@gmail.com — we answer within 30 days, usually the same day. The full business address is shown on the app's App Store and Google Play listings.

What we collect

Only what the app actually uses. Nothing is collected “just in case”.

Account

The email address and phone number you enter when signing up, and your password — which we never see, as it is stored as a cryptographic hash by Supabase Auth. If you sign in with Google, all we receive from Google is your email address.

Body and nutrition data

From the questionnaire: sex, age, height, weight, activity level and goal. From everyday use: the meals you log (name, amount, calories, macronutrients), water, steps, workouts, weigh-ins, checked habits and your answers about your day. This is health data and we treat it more strictly than the rest — see the section below.

Photos and voice

When you photograph a meal or a label, or say out loud what you ate, that image or recording is sent for AI processing to estimate the calories. Voice recordings are not kept — they are processed and discarded. A meal photo is kept briefly alongside that entry (about one day) so we can show you its card, then deleted automatically.

Technical data

Cookies the app cannot work without (sign-in, chosen language, chosen theme), and a record of when you first reached certain steps in the app — which we use to see where people get stuck. If you turn on reminders, we also store a device token so we can send the notification. We have no Google Analytics, no Facebook pixel, and no third-party advertising or analytics SDK of any kind.

Why, and on what legal basis

  • To make the app work — your account, your daily budget, your progress. Legal basis: performance of the contract you entered into by accepting the terms of use.
  • For body and nutrition data, for AI processing of photos and voice, and for sending notifications. Legal basis: your explicit consent, given by entering that data or switching that option on. You can withdraw it at any time — stop logging, turn reminders off, or delete your account.
  • For the security of the service and to prevent account abuse. Legal basis: legitimate interest.

We make no automated decisions about you that produce legal effects, and we build no advertising profile. The plan the app calculates is arithmetic from general formulas, not an assessment of who you are.

Health data

Your weight, your food intake and a goal of losing or gaining are a special category of personal data — health data. So we process them solely on the basis of your explicit consent, use them only to calculate and show you your plan, and never sell them or hand them to insurers, employers or anyone else. Withdraw consent by deleting your account, and the data goes with it.

Who else sees your data

Four companies, each for exactly one job, all under a data-processing agreement. None of them may use your data for themselves.

  • Supabase — the database and account sign-in. Your data physically sits on servers in Ireland (European Union).
  • Vercel — the server that delivers the app.
  • Google (Gemini API) — calorie estimation from photos, labels and voice. The image or recording does not go from your phone straight to Google: it reaches our server first, and our server forwards it to Gemini together with the question — with no name, email address or account identifier attached, so Google cannot tell whose it is. We use the paid tier, on which submitted content is not used to train Google's models. Google processes the image and returns an estimate; it does not keep it as your content afterwards, and makes no lasting copy on our behalf. The only copy that stays anywhere is ours — a small thumbnail beside that meal, for about a day (see “How long we keep things”). Voice recordings stay neither with us nor with them.
  • Resend — sending email (account confirmation, password reset).

That is the whole list. We do not sell data, trade it, or pass it to ad networks. We would give data to a state authority only where the law obliges us to.

Transfers outside Europe

The database is in Ireland. Vercel and Google may also process data on servers outside the European Economic Area; where they do, the transfer is covered by the European Commission's standard contractual clauses, the instrument provided for exactly this.

How long we keep it

  • Account, profile and your plan — for as long as you have an account.
  • Logged meals — the app shows you the last 30 days, and the database keeps them for 3 months before a scheduled job deletes them automatically.
  • Meal photos — about one day, then deleted automatically.
  • Voice recordings — not stored at all.
  • When you delete your account — everything goes immediately. Data may survive in database backups for at most 30 days, until those backups are overwritten.

Your rights

By law you have the right to: see your data, correct what is wrong, erase it, receive it in a portable form, restrict or object to processing, and withdraw consent.

You can do most of that yourself, immediately, without writing to anyone: in Settings, “My data” shows everything we store and downloads a copy as a file, “Personal details” and “Goal & plan” change your data, and “Delete account” erases all of it.

For anything else, write to markobera749@gmail.com.

If you think we are getting something wrong, you have the right to complain to a supervisory authority: in Serbia that is the Commissioner for Information of Public Importance and Personal Data Protection, and if you live in the European Union, the authority in your own country.

Age

FitMess is meant for people aged 16 and over. We do not knowingly create accounts for anyone younger; if we learn that an account belongs to a younger person, we delete it. If you are a parent and believe your child has an account, write to markobera749@gmail.com.

Cookies

We use only the ones the app cannot work without: the sign-in cookie, your chosen language, your chosen theme, and a marker that you have finished initial setup. There are no tracking cookies, which is why there is no banner asking you about them.

Security

All traffic goes over HTTPS. Passwords are stored as cryptographic hashes. The database has row-level security enabled, which means one user's query technically cannot reach another user's row — it is a rule in the database itself, not a matter of care when writing code.

Changes

If this changes, we change the date at the top. If a change is significant — a new kind of data, a new processor — we will tell you in the app before it takes effect.

Contact

Marko Bera, Serbia. Email: markobera749@gmail.com.