Skip to content
MuscleScope
← MuscleScope

Privacy Policy

Version 2 · effective 2026-09-03

**Provisional text.** In force from today, but under legal review and to be replaced by a full version. It accurately describes what the app does today; the outstanding points are marked. ## 1. What we collect **Account** — email, name, hashed password, language, role. **Body and health** — height, weight, date of birth, sex, circumferences, body-fat percentage, progress photos, sleep, energy, mood and pain logs, medical history, injuries, medication, allergies and intolerances. > This is **special-category data** under Article 9 GDPR. We process it because it is necessary for the service you asked for and on the basis of your consent, which you can withdraw by deleting the data or your account. **Training and nutrition** — programs, workout logs, sets and reps, meal plans, goals. **Communication** — messages, voice notes, form-check videos, notifications. **Payments** — amounts, subscription states, transaction identifiers. **We do not store card numbers.** **Technical** — IP address, device, browser, error logs. ## 2. Why To run the service, to bill, to keep accounts secure, and to support you. ## 3. Who processes it on our behalf | Provider | What it does | |---|---| | Supabase | accounts, database, file storage | | Stripe | payments and subscriptions | | Brevo | system email | | OpenRouter | routing requests to AI models | | Browser push services | delivering notifications | **What goes to the AI:** when a program or meal plan is generated, the data the calculation needs is sent — goals, body metrics, preferences, injuries and health declarations. Calories and macros are computed by the app, not by the model. ## 4. Your rights Access, rectification, erasure, restriction, objection, portability. Two of these you can exercise **yourself inside the app**: export all your data, and delete your account. For the rest: **[email protected]**. You also have the right to complain to your supervisory authority. ## 5. Security Data is transmitted encrypted and access is scoped by role: a trainer sees only their own clients. *Outstanding in the full version: full controller details, retention periods per category, storage locations and transfer safeguards outside the EEA, minimum age.*