Legal
AIFormNote Privacy Policy
AIFormNote is a fitness, training and nutrition tracking application. AIFormNote is intended only for users aged 18 and over and is not directed to children. AIFormNote is not a medical device and is not intended to diagnose, treat, cure or prevent disease or injury, or to provide pregnancy care. Pregnancy and breastfeeding adjustments in the app are fitness and nutrition estimates only; individualized medical, pregnancy or breastfeeding advice should be obtained from a qualified healthcare professional.
1. Data AIFormNote can process
Depending on the features you use, AIFormNote can process data you enter about your profile, age, height, body weight, optional body-fat estimate, body measurements, goals and preferences, training plans and history, sets, repetitions, load, RIR/RPE, personal records, cardio, calorie and macronutrient targets, food diary, readiness/check-ins, post-workout feedback, progress photos and app settings.
Where you choose to use the relevant nutrition feature, AIFormNote may also process optional user-entered health-related information concerning pregnancy or breastfeeding, including pregnancy trimester, breastfeeding status and months postpartum. These values are used to personalize energy and nutrition estimates and are not used to provide diagnosis, treatment or pregnancy care. Depending on applicable law and the context of processing, pregnancy and breastfeeding information may constitute health data or special-category personal data.
Progress photos are first saved in app-private local storage. AIFormNote uses the system camera flow and does not request persistent camera permission.
AI Food is a Premium feature initiated only by a deliberate user action. You can type a meal description, capture a photo directly through the in-app camera flow, or deliberately choose an existing image from your gallery. A selected image is downscaled and re-encoded before upload so original EXIF metadata is not preserved in the uploaded JPEG. A photo is not sent for AI processing automatically merely because it exists on the device or in the gallery.
2. Two storage modes
Continue without sign-in
AIFormNote is fully usable without an account. Core data remains only in private app storage on that device, including any pregnancy or breastfeeding information you enter. Android automatic app-data backup and device transfer are disabled. Unless you created a manual backup, clearing app data, uninstalling the app or losing the device can make the data unrecoverable.
You can export JSON or explicitly create a complete ZIP backup containing profile, training, nutrition, progress data and progress photos. If entered, pregnancy or breastfeeding information is part of your settings in those user-created backups. AIFormNote does not encrypt that ZIP, so protect it as you would any sensitive health or fitness record.
Continue with Google
Google Identity is optional and is used only to authenticate a stable identity for AIFormNote cloud backup, restore and synchronization. Google sign-in is an identity mechanism; the synchronized app data is stored through private AIFormNote cloud infrastructure rather than in your Google Drive. AIFormNote does not create or handle an AIFormNote password and does not request access to Gmail, contacts, calendar or files in your Google Drive.
The backend verifies the Google ID token and uses the verified Google sub identifier as the account key. AIFormNote does not persist your Google e-mail address, display name or profile picture in its backend database. The one-time ID token is exchanged for an opaque 90-day AIFormNote session; Android encrypts the local token with Android Keystore and the server stores only a hash.
After you confirm connection, the local dataset and progress photos can be copied to private AIFormNote cloud storage on Cloudflare infrastructure. Data stays on the device as well. If entered by you, the synchronized cloud dataset may also contain pregnancy or breastfeeding status and months postpartum as part of your settings and nutrition profile. If local and cloud histories both exist, AIFormNote does not silently erase either side: it recommends merging where possible and requires an explicit choice for genuine conflicts. Disconnecting Google stops synchronization and keeps local data; it does not by itself delete the cloud copy.
3. AI features and medical safety boundary
Before generative AI coaching is invoked, AIFormNote applies rules intended to block individualized questions about symptoms or pain, injuries, diagnosis or treatment, medication interactions, pregnancy or breastfeeding, laboratory results, eating-disorder content, high-risk drug/PED requests and self-harm or crisis content. Individualized medical questions about pregnancy or breastfeeding are intended to be blocked before a generative model is invoked. Those questions are not intentionally forwarded to a generative model. Automated filters cannot guarantee every risky wording will be recognized.
Supported devices may offer on-device generative AI, which does not send the question or fitness context to the AIFormNote backend.
Cloud AI is optional, disabled by default and can be disabled at any time. If you explicitly enable it, a permitted fitness or wellness question, a short bounded chat history and minimized coaching context may pass through the AIFormNote backend to OpenAI with provider storage disabled. The minimized context can include recent training, active-program information, nutrition, weight/progress, measurements, cardio, readiness/check-in data and post-workout feedback. When Cloud AI is explicitly enabled, the minimized coaching context may also include pregnancy/breastfeeding status and months postpartum where you have entered those values. AIFormNote uses these values only as part of fitness and nutrition context. The user-entered profile name is excluded from the automatically built AI context, but text voluntarily typed in the question is part of the request.
AI Food is available only to entitled Premium users and every analysis is user-initiated. When you deliberately start AI Food, the specific meal description or photo you captured or selected may be sent over HTTPS through the AIFormNote backend to the AI inference provider, OpenAI, for structured food recognition and nutrition-value estimation. A photo is not sent to OpenAI automatically without the user starting AI Food. The AI result is a suggestion only; it may be inaccurate or incomplete, and you can review, edit or discard it before anything is saved.
AI output can be incomplete or wrong and is not a substitute for professional medical care. AIFormNote does not use generative AI to provide diagnosis, treatment, disease prevention or pregnancy care.
4. Online food, exercise, identity and subscription services
- Google Identity processes optional sign-in using standard identity information; AIFormNote requests no Google product-data scopes.
- Open Food Facts may receive food-search queries or barcode values.
- USDA FoodData Central may receive food-search queries through the backend.
- AI Food may send a user-submitted meal description or re-encoded food photo through the AIFormNote backend to OpenAI for structured food recognition; recognized food names can then be matched against AIFormNote food sources.
- RepDB may provide exercise illustration metadata or images.
- Google Play processes subscriptions. AIFormNote does not process full payment-card numbers.
- The backend may receive a Google Play purchase token for entitlement verification and stores a SHA-256 hash rather than the raw token.
Google sign-in and Google Play Billing are separate. Signing in neither starts a subscription nor grants Premium.
5. Website and technical data
The public website is hosted by Netlify, which may process IP address, request time, requested URL and browser or device technical data during delivery. The website uses no first-party analytics or advertising trackers and intentionally sets no marketing cookies. Cloudflare and other infrastructure providers may process network and security metadata needed to deliver and protect backend requests. AIFormNote does not intentionally log Google ID tokens, cloud snapshot bodies, progress-photo bodies or raw AI Food photos.
6. Reporting an AI response
If you select Report response, AIFormNote sends the selected assistant response, source type, category, app version, an anonymous installation ID and an optional note. The full chat history and full fitness or nutrition context are not included.
7. Purposes and legal bases
- Requested app functions, optional Google-authenticated backup and sync, subscription management and user-initiated AI Food analysis: performance of a contract or steps requested by you (GDPR Art. 6(1)(b)).
- Optional Cloud AI coaching: consent (Art. 6(1)(a)); where submitted information is special-category data, explicit consent under Art. 9(2)(a).
- Security, abuse and fraud prevention, rate limiting and secure delivery: legitimate interests (Art. 6(1)(f)).
- Legal obligations: Art. 6(1)(c).
Pregnancy and breastfeeding information may constitute health data or special-category personal data. The explicit-consent statement under Art. 9(2)(a) above applies to the optional Cloud AI consent flow where such information is included in Cloud AI processing. It should not be read as stating that Google sign-in itself, the separate cloud synchronization flow, or AI Food is an Art. 9 explicit-consent flow. Do not use AI Food to submit medical records or individualized medical questions.
Cloud-AI consent can be withdrawn by turning the feature off. Disconnecting Google stops future synchronization but does not itself delete the existing cloud copy; the deletion controls described below are available for that purpose.
8. Recipients and international transfers
Where necessary, data may be processed by Cloudflare, Netlify, Google or Google Play, OpenAI when you use optional Cloud AI or AI Food, Open Food Facts, USDA FoodData Central and RepDB. Applicable transfer safeguards are used where processing involves a transfer outside the EEA. AIFormNote does not sell personal data or use it for advertising.
9. Retention and deletion
Local data remains until you delete it, clear app data or uninstall. Google-linked snapshots/photos remain until replaced or the connected cloud account data is deleted. Superseded snapshot objects are removed after a successful revision update. Authentication challenges expire after 10 minutes; opaque sessions expire after 90 days and expired rows are removed by scheduled cleanup.
Ordinary Cloud-AI questions, built coaching context and generated answers are not intentionally persisted in the D1 application database. Moderation reports are deleted after 180 days. Existing Cloud-AI usage/cost rows and inactive entitlement records may be kept for up to 730 days; active subscription records may remain while needed for the service relationship or legal obligations.
AI Food uses a separate technical usage/cost ledger for budget enforcement, replay protection, rate limiting, abuse prevention and service accounting. Raw meal text and raw photos are not stored in that usage ledger; raw photos are also not stored in the short replay cache. A successful structured result may be cached briefly (currently up to 5 minutes) solely to replay the same request without a second provider call. The current AI Food implementation does not promise a fixed public maximum retention period for its technical usage/cost ledger; those technical records are retained only as long as necessary for the stated operational purposes and applicable legal obligations. If a fixed maximum is introduced, this policy will be updated accordingly.
The in-app Delete all my data action first requests deletion of all data linked to a connected Google identity. If that deletion cannot be confirmed, the app keeps local data and the authenticated retry path instead of reporting a false success. After successful cloud deletion, it removes local profile, training, nutrition, progress and photo data and requests deletion of records linked to the anonymous installation ID. An anonymous-backend deletion failure keeps the installation identifier so that request can be retried.
Public deletion information and a request route are published at the public deletion page. Deleting AIFormNote data does not cancel a Google Play subscription; subscriptions are managed separately in Google Play.
10. User rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent where processing is based on consent. Send requests to nela.aiformnote@seznam.cz · milanweinarr@seznam.cz. You may complain to a competent supervisory authority; in the Czech Republic this is the Office for Personal Data Protection.
11. Security
Production endpoints use HTTPS. Google tokens are verified server-side for signature, issuer, audience, timing and nonce. Cloud access requires an opaque session, per-user object keys are derived from the verified identity, writes use revision compare-and-set, and Android automatic app-data backup remains disabled. AI Food validates bounded request sizes and re-encodes photos before upload; API secrets and Google Play service-account credentials stay server-side. No electronic service can guarantee absolute security.
12. Age
AIFormNote is intended only for users aged 18 and over and is not directed to children.
13. Community food catalogue
AIFormNote uploads a custom food to the shared Community Foods catalogue only when you explicitly choose to share that food. If you do, the app may contribute the food name and nutrition values per 100 g or per 100 ml, plus optional product metadata described below. The community-food service uses a one-way hash derived from the installation identifier for contribution deduplication, rate limiting and abuse reporting; the raw installation identifier is not stored in the community-food contribution tables. Your local custom food remains usable even if sharing fails. Community-food contribution linkage is removed by the installation-data deletion endpoint while the aggregated food record may remain as non-user-specific catalogue data.
14. Anonymous backend credential
For server-backed features available without a Google account, the app maintains a random public installation ID and a separate cryptographically random per-installation secret. Sensitive anonymous operations such as backend data deletion require proof of that secret. The backend stores a one-way verifier rather than the secret itself. Legacy installations can establish this credential on their first updated authenticated request.
15. Community food metadata
If you explicitly choose to share a custom food with AIFormNote Community, the shared record may include product name, brand, valid barcode/GTIN, package quantity, image URL when supplied, nutrition basis (per 100 g or per 100 ml), nutrition values and flags that distinguish a known zero from a missing/unknown value. Community data is not uploaded to Open Food Facts automatically.
16. Changes and contact
This policy may be updated when functionality, providers or data handling changes. The current version is published here.
Milan Weinar, IČO 29921139, Procházkova 172, 336 01 Blovice, Czech Republic · +420 777 420 913 · nela.aiformnote@seznam.cz · milanweinarr@seznam.cz