Information we process
Account information
We process authentication and account information needed to create, secure and operate your account.
Fitness profile
This may include age, sex, height, weight, waist measurement, fitness goal, activity level, training preferences and dietary preferences you provide.
Body photos
Starting and check-in photos are uploaded by you. They are stored in private Supabase Storage with owner-scoped access. Time-limited signed URLs provide access where needed. Generated Future Body assets are also stored privately and are not public by default.
AI-assisted features
When you explicitly request Future Body generation, relevant images and minimum necessary profile data may be sent to our configured AI image provider. Body images are not written to application AI workflow logs. Minimum necessary fitness or nutrition information may be processed by OpenAI for meal-plan generation, and relevant fitness and training preferences may be processed for workout generation.
How we use information
We use information to operate accounts, calculate fitness targets, provide requested projections and plans, compare check-ins, maintain security, troubleshoot the service and respond to support requests.
Service providers and sharing
We use Supabase for authentication, database and private file storage; OpenAI for applicable AI functions; and Vercel for hosting and runtime where deployed. Razorpay will process payments once subscriptions are enabled. We do not store full card or bank credentials handled by the payment provider. We do not currently use PostHog analytics. We may add analytics later and update this policy before collection begins.
Photos are not public by default. Sharing occurs only through an explicit user action. We may also disclose information when required by law or to protect the service and its users.
Security, storage and retention
We use access controls, private storage and signed access designed to limit unauthorized access. No system is completely secure. We retain information for as long as needed to provide the service, meet legitimate operational or legal needs, and resolve disputes, then delete or de-identify it where appropriate.
Your choices and requests
You may choose not to provide optional information, although some features may then be unavailable. You may request account or data deletion, correction, or information about your data through our contact details. We may need to verify the request.
Policy changes
We may update this policy as the service changes. The effective date above identifies the current version. Material updates will be communicated through an appropriate service notice.
Contact
Questions or requests about this policy can be sent through our contact page or to support@nourvo.fit.
