Spriwa

Privacy Policy

Last updated 28 September 2026

This Privacy Policy explains how Spriwa ("Spriwa", "we", "us" or "our") collects, uses, discloses and protects personal information when you use the Spriwa mobile application and the related websites and services (together, the "Service"). It applies to everyone who uses the Service. Capitalised terms used in this Policy have the meaning given to them here or in our Terms of Service.

Spriwa is a health, nutrition and training application. Much of the information you give us describes your body and your health, and we treat it accordingly: in this Policy, "Health and Fitness Data" means information about your body, physical condition, activity, nutrition and training, and "Personal Data" means any information that relates to an identified or identifiable individual, including Health and Fitness Data.

Contents

  1. Summary
  2. 1. Who we are and how to contact us
  3. 2. The data we process
  4. 3. Where the data comes from
  5. 4. Why we process your data, and our legal bases
  6. 5. Artificial intelligence
  7. 6. Apple Health and Health Connect
  8. 7. Photographs
  9. 8. Voice and audio
  10. 9. Location and weather
  11. 10. Notifications
  12. 11. Subscriptions and payments
  13. 12. Service providers
  14. 13. International transfers
  15. 14. How long we keep data
  16. 15. Deletion and a copy of your data
  17. 16. Your rights
  18. 17. Residents of United States jurisdictions
  19. 18. Children
  20. 19. Security
  21. 20. Changes to this Policy
  22. 21. Contact

Summary

  • We process your data to operate the Service for you, and for no other purpose. We do not sell it, we do not share it for advertising, we do not build profiles of you for our own purposes, and we do not use it to train artificial-intelligence models.
  • We keep your data only while your account exists. Delete the account and it is erased, apart from the narrow, time-limited records set out in section 14.
  • Health and Fitness Data is sensitive. We hold only what you choose to enter, and what you release to us from Apple Health or Health Connect through your device's own permission dialog. You can stop at any time by disconnecting the source or deleting your account.
  • Some features send your content to artificial-intelligence providers so that they can answer you, analyse a photograph of a meal or transcribe your speech. Those providers act on our instructions and are not permitted to use your content to train their models.
  • Photographs you take of your own body stay on your device. Photographs of food and of nutrition labels are transmitted for analysis and are deleted from our systems within seven days.
  • You can erase your account permanently, at any time, from within the app, and you can ask us for a copy of everything the Service holds about you by writing to privacy@spriwa.com.
  • Our primary systems are hosted in the European Union. Some providers we rely on are located outside it; where that is the case, we rely on the transfer safeguards described in section 13.
  • Spriwa does not give medical advice. Nothing in the Service is a diagnosis, a treatment recommendation or a substitute for professional care.

1. Who we are and how to contact us

Spriwa is operated by Ishit Panchal, Abhi Suthar and Parth Kharadi, who are jointly the controllers of the Personal Data described in this Policy. You can reach us about any privacy matter, including any request to exercise the rights described in section 16, at privacy@spriwa.com. For anything else, write to support@spriwa.com.

2. The data we process

Account and identifiers. An account identifier created for you by our authentication system; the public key and identifier of any passkey you register; the identifier your provider gives us if you sign in with Apple or with Google, together with the name or email address that provider chooses to release to us; device and session identifiers used to keep you signed in; and records used to confirm that a request comes from a genuine installation of the app.

Profile. The details you give us when you set up and adjust your account, which may include your name, sex, year of birth, height, dietary pattern, allergies and food restrictions, training experience and equipment, goals, language, units, country and time zone.

Health and Fitness Data. Body measurements and weight logs; body-composition figures you enter from a scan; your training programme, sessions, exercises, sets and loads; meals, recipes, portions, water and the nutrition values derived from them; energy and macronutrient targets calculated for you; activity, heart rate, heart-rate variability, sleep-related and workout information read from Apple Health or Health Connect if you connect them; and, only if you switch the feature on, menstrual cycle information you enter.

Images. Photographs of meals and of nutrition labels that you submit for analysis, and barcodes you scan. Photographs you take to track your own physical progress, and the thumbnails shown beside your meal entries, are held in your device's own private storage and are not uploaded to us.

Voice and audio. Recordings of your speech when you dictate into a text field, and the audio of a live voice conversation with the in-app coach, together with the resulting transcripts; and, when you log a set by voice, including through Siri, the words recognised from what you said, as described in section 8.

Conversation content. The messages you exchange with the in-app coach, the notes it keeps in order to remember what you have told it, and the plans, reports and suggestions generated for you.

Purchase and subscription data. Your subscription and entitlement status, the store you purchased through, and the identifiers our payments provider uses to recognise your purchase. We never receive or store your card or bank details; those are handled entirely by Apple or Google.

Device, diagnostic and usage data. Application version, operating system, device model, language, crash reports, performance measurements, error diagnostics and records of requests made to our servers, including the model, cost and latency of artificial-intelligence requests made for you. Crash reports can include your internal account identifier so that we can investigate affected accounts. We remove direct contact information and redact sensitive diagnostic fields; this does not make account-linked reports anonymous. Launch-performance reports omit the account identifier.

Error recordings, only if you turn them on. If you choose to share them, when you set up your account or later under Profile, then Privacy and data, the app keeps a short, continuously replaced recording of its own screens and your taps on the device, and sends the moments before an error to our diagnostics provider when the app runs into one. As each frame is captured, the app blacks out all text, images, charts and the body figure, so a recording shows the layout of the screens and where you tapped, never what you typed, logged or photographed. Nothing is sent unless an error happens. The choice is off unless you turn it on, it is not offered in every version of the app, and turning it off takes full effect the next time you open the app.

Time zone and location. Your device's time zone is used to place your logs, plans and reminders on the correct local day. The app sends your approximate location only if you turn on weather-based suggestions, as described in section 9.

Notification data. If you enable notifications, the push token issued to your installation by Apple, Google or Expo, and a record of what we have sent you.

3. Where the data comes from

Most of the data described above comes from you: what you enter, capture, say or upload. Some is generated by the Service as you use it, such as calculated targets, plans and diagnostic records. Some comes from sources you connect, namely Apple Health or Health Connect, your app store and our payments provider (subscription status), and public reference sources used to look up nutrition information for barcodes and foods.

4. Why we process your data, and our legal bases

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases.

  • To provide the Service under our contract with you (Article 6(1)(b)): creating and maintaining your account, calculating targets, building and adjusting training programmes, recording what you log, answering you through the in-app coach, providing subscription access and customer support.
  • Your consent (Article 6(1)(a)): every feature that needs a device permission — the camera, the microphone, speech recognition, the photo library, approximate location, notifications, and access to Apple Health or Health Connect. Your operating system asks you for each one separately, you may refuse any of them and still use the rest of the Service, and you can withdraw any of them later in your device settings. The error recordings described in section 2 also rest on your consent, which you give by ticking a separate box and can withdraw at any time under Profile, then Privacy and data.
  • Our legitimate interests (Article 6(1)(f)): keeping the Service secure and available, preventing fraud and abuse, diagnosing faults, understanding aggregate usage in order to improve the Service, and enforcing our Terms of Service. We process only what is necessary for those purposes and balance them against your interests.
  • Compliance with a legal obligation (Article 6(1)(c)): responding to lawful requests and meeting our accounting, tax and regulatory duties.

Health and Fitness Data. Spriwa cannot coach you without information about your body, so this data is the substance of the Service you have asked us to provide, and we process it to provide it (Article 6(1)(b)). You supply it yourself, one feature at a time and only as far as you want to: a weight you type in, a meal you log, a session you record, a cycle setting you switch on. Nothing about your body is taken from your device unless you entered it or connected a health source. Where the data comes from Apple Health or Health Connect, it reaches us only because you granted that access in your device's own permission dialog, and it stops reaching us the moment you withdraw it there; if you additionally switch on background sync, your device may refresh those figures while Spriwa is closed. You can delete individual entries in the app, disconnect a source, or delete your account, which erases all of it.

Purpose limitation. Your Personal Data is processed to deliver the Service to you, and to nothing else. We do not sell it or share it for advertising or cross-context behavioural advertising; we do not use it to build profiles of you for our own commercial purposes; we do not use it to train artificial-intelligence models, and our providers are not permitted to do so either; and we do not keep it beyond the life of your account except for the narrow records listed in section 14. A food or product you submit to the shared catalogue becomes part of that catalogue for other people, under the name and nutrition values you give it and without anything that identifies you, and is withdrawn when you delete your account. Where you correct a portion estimate, that correction also updates aggregate statistics about how a dish is typically served, which carry no identifier and are not traceable to you.

Sharing you choose. When you use a sharing feature, the selected recipe, report, image or exported file is passed to the app or recipient you choose. Instagram story sharing opens Instagram's editor with the selected image; it does not connect your Instagram account to Spriwa or read your Instagram profile. Review the content before sharing. Information you send outside Spriwa is handled under the recipient's own policies, and deleting your Spriwa account does not remove copies you have shared elsewhere.

5. Artificial intelligence

Several features of the Service are delivered with the help of artificial-intelligence models operated by third parties. When you use those features, the content necessary for the task is sent to the relevant provider. This may include the text of your message, a summary of your profile and relevant Health and Fitness Data, a photograph of a meal or a nutrition label, or the audio of your speech.

Those providers process that content solely to return a result to us. They act as our processors, under contract, and are not permitted to use your content for their own purposes. Requests we send through our inference provider reach only model providers that do not retain the content or use it to train their models: we require this on each request where the inference provider supports it, and otherwise use only models run solely by such providers. Live voice conversations run directly against the realtime provider named in section 12 and are processed under our agreement with it.

All nutritional and physiological calculations shown to you, including energy targets, macronutrient totals and training progression, are produced by our own deterministic engine, not by a language model.

Output produced by an artificial-intelligence model may be inaccurate or incomplete. It is not medical, nutritional or clinical advice, and it does not involve a decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 of the GDPR. You remain responsible for decisions you take about your own health; see our Terms of Service.

6. Apple Health and Health Connect

If you connect Apple Health (iOS) or Health Connect (Android), the Service reads the categories of information you approve, which may include steps, active and basal energy, distance, exercise time, heart rate, resting heart rate, heart-rate variability, estimated VO2 max and recorded workouts. The phone app reads this information and does not write to Apple Health or Health Connect. You choose which categories to share and can change or revoke that choice at any time in your device settings.

Information obtained from Apple Health or Health Connect is used only to provide the features you use in the Service, such as recovery, training and energy guidance. We do not use it for advertising or marketing, we do not use it for data mining, we do not sell it, and we do not disclose it to any third party other than the processors listed in section 12 acting on our instructions to deliver those features. It is not used for any purpose other than health, fitness and wellness management, and it is deleted when you delete your account.

7. Photographs

Photographs of meals, of nutrition labels and any photograph you choose to attach to a conversation with the in-app coach are sent to our servers and to the artificial-intelligence provider that analyses them. The submitted image is held with its analysis job and deleted from our systems no later than seven days after submission. The nutrition information derived from it remains in your log until you delete it.

Photographs you take to track your physical progress, and meal thumbnails shown in your own history, remain in the app's private storage on your device. They are not uploaded to our servers, are not sent to any artificial-intelligence provider and are not included in a copy of your data. They are removed when you delete your account from that device or uninstall the app.

8. Voice and audio

When you dictate into a text field, the recording is sent to our servers and from there to a speech-to-text provider, which returns a transcript.

When you log a set by voice during a workout, your phone recognises the words on the device where it can, and then the audio does not leave it; on a phone that cannot, the recording goes to the speech-to-text provider as it does for dictation. The recognised words are sent to our servers, which ask an artificial-intelligence provider to read them as the weight and repetitions to record. If you switch on hands-free logging, the phone listens only while the workout screen is open, and the speech recognition runs on your device: no audio is recorded, kept or sent, only the recognised words, as for any set logged by voice. If you log a set with the Siri shortcut, Siri turns what you say into text under Apple's own terms and privacy policy; we receive only that text, which is handled in the same way.

When you hold a live voice conversation with the in-app coach, your device connects directly to a realtime speech provider using short-lived credentials issued by our servers, and your audio is streamed to that provider for the duration of the conversation. We retain the resulting text where it forms part of a log or conversation you have kept; we do not retain the underlying audio.

9. Location and weather

Weather-based suggestions are off unless you turn them on, and they are not offered in every version of the app. If you turn them on and allow location access, the app reads your approximate location, never your precise position, while it is open, and sends it, rounded to about a kilometre, to our servers, which use it only to ask our weather provider for the local forecast. The location is not stored, it is never sent to an artificial-intelligence provider, and we do not keep a location history or track your movements. You can turn the feature off in the app, or withdraw location access in your device settings, at any time. Your device's time zone is used for local dates and scheduling; it is not a geographic position.

10. Notifications

If you enable notifications, we store the push token for your installation so that we can send you the messages you have asked for, such as your weekly report, or a note that a training plan you asked for is ready. Notifications are sent through Apple's, Google's or Expo's push services. You can turn them off at any time in the app or in your device settings.

11. Subscriptions and payments

Purchases are processed by Apple or by Google under their own terms and privacy policies. We receive confirmation of your purchase and your entitlement status through our subscription management provider. We never receive your card number, bank details or billing address.

12. Service providers

We use a small number of providers to operate the Service. Each processes Personal Data only on our documented instructions and under a written data protection agreement. They fall into the following categories.

  • Hosting and application delivery (Vercel): serving the application and its interfaces. Primary processing region: European Union.
  • Database, authentication and file storage (Supabase): storing your account and the data described in section 2. Primary processing region: European Union.
  • Artificial-intelligence inference (OpenRouter, which passes each request to the model we name, currently models made by OpenAI, Google, Microsoft and DeepSeek, run by their makers or by hosting providers under the conditions in section 5; and OpenAI directly for live voice conversations): generating the responses, analyses and transcriptions described in sections 5 and 8.
  • Subscription management (RevenueCat): validating purchases made through Apple or Google and maintaining your entitlement status.
  • Email delivery (Brevo): delivering the support message you send us from within the app, together with any reply address you give, and the acknowledgement we send back to that address. It receives nothing else.
  • Diagnostics and crash reporting (Sentry): recording errors and performance measurements, and, only if you turn them on, the masked error recordings described in section 2. Crash reports and recordings may include an internal account identifier; launch-performance reports omit it. Processing region: European Union.
  • Weather (Open-Meteo): only if you turn on weather-based suggestions, receives an approximate location, with no identifier, and returns the local forecast, as described in section 9.
  • Content delivery (Cloudflare): delivering the food catalogue, imagery and other application content. This service receives requests for content; it does not receive your logs, conversations or Health and Fitness Data.
  • Application updates and push delivery (Expo, Apple, Google): delivering application updates and notifications.
  • Food reference data (Open Food Facts and comparable public nutrition sources): looking up products and nutrition values. Barcode and product queries are not linked to your identity. Open Food Facts database content is available under the Open Database License and Database Contents License; its product images are licensed under CC BY-SA 3.0. We adapt names, serving units and nutrition presentation. These third-party licences govern that material and are not restricted by our Terms of Service.

We may also disclose Personal Data where we are required to do so by law, where it is necessary to establish, exercise or defend legal claims, or to protect the rights, safety or property of any person. If the Service is ever transferred to another operator, we will transfer Personal Data only with the Service, and we will tell you before it happens.

13. International transfers

Our hosting, database, storage and diagnostics are located in the European Union. Some of the providers listed in section 12, in particular those providing artificial-intelligence inference and subscription management, process data outside the European Economic Area and the United Kingdom, including in the United States. Where that is the case, the transfer is made under the data protection terms agreed with that provider, which are intended to provide the safeguards required by Chapter V of the GDPR, in most cases the European Commission's standard contractual clauses together with supplementary measures such as encryption in transit. You may ask us for further information about the safeguards applying to a particular transfer.

14. How long we keep data

  • Account, profile, Health and Fitness Data, logs and conversations: for as long as your account exists. When you delete your account they are erased as described in section 15.
  • Images submitted for analysis: no longer than seven days after submission, after which the analysis job and the image it carries are deleted automatically.
  • Records of artificial-intelligence requests (which model answered, what it cost, how long it took and whether it succeeded, never the content): for as long as your account exists.
  • System backups: our database provider keeps rolling backups for a maximum of seven days. Erasure is replayed against a restored backup before it is returned to service, so a deleted account cannot come back through one.
  • Deletion records: after your account is erased we keep a record that the erasure happened. It carries your former account identifier for eight days, so that credentials issued before deletion can be refused and so that erasure can be replayed against a backup; the identifier is then removed, and the remaining record, which identifies nobody, is deleted thirty days after completion.
  • Introductory-trial records: a keyed, irreversible hash marking that a device has already used the free introductory period, kept until that period would have expired and used for nothing but preventing repeat trials.
  • Payment reconciliation messages from our subscription provider: thirty days after they are processed.
  • Diagnostic and crash reports, and error recordings: for the limited period applied by our diagnostics provider, no longer than 90 days. They can retain an internal account identifier as described in section 2.
  • Aggregate statistics about how dishes are typically served, described in section 4: indefinitely. They contain no identifier and cannot be traced to you.
  • Records we must keep by law, such as those required for tax or accounting purposes: for the period the relevant law requires.

15. Deletion and a copy of your data

You can permanently delete your account at any time from the app, under Profile, then Privacy and data. Deletion removes your profile, your logs, your training and nutrition history, your conversations, your notification tokens, your sign-in credentials and any food or product you contributed to the shared catalogue, together with any image still held for analysis and any file stored for you, and it removes the app's local data, including your photographs, from the device you delete from. Your record with our subscription provider is erased with it, and any connection you authorised to another provider is revoked. Deletion begins immediately; where cleanup work continues on our servers, the app reports it as in progress until it has finished. There is no recovery period and we cannot restore a deleted account. What survives, and for how long, is limited to the deletion, trial and backup records listed in section 14. Deleting your account does not cancel a subscription purchased through Apple or Google; you must cancel that in your store account.

A complete copy of the data held for your account is provided on request. Write to privacy@spriwa.com and we will send it to you in a structured, commonly used and machine-readable format, which you may keep or pass to another service, within one month of your request, as the law requires. We will tell you if we need longer because a request is complex.

16. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to obtain confirmation of whether we process your Personal Data and to access it; to have inaccurate data corrected and incomplete data completed; to have your data erased; to receive the data you provided in a structured, commonly used and machine-readable format and to have it transmitted to another controller; to restrict processing in certain circumstances; to object to processing based on our legitimate interests; and to withdraw your consent at any time without affecting the lawfulness of processing carried out before you withdrew it.

You can exercise some of these rights directly in the app: correct your profile and your logs where they are shown, delete individual entries, and delete your account, which erases your Health and Fitness Data with it. You can withdraw a device permission, including access to Apple Health or Health Connect, at any time in your device settings. For anything else, or if you would prefer us to act on your behalf, write to privacy@spriwa.com. We will respond within one month, and will tell you if we need longer because a request is complex.

You also have the right to lodge a complaint with the data protection authority of your country of residence, or of the country where you work or where you believe an infringement has taken place. We would ask you to raise the matter with us first at privacy@spriwa.com, which is usually the quickest way to resolve it.

17. Residents of United States jurisdictions

Where state privacy laws such as the California Consumer Privacy Act apply, the following applies in addition to the rest of this Policy. In the preceding twelve months we have collected the categories of personal information described in section 2, from the sources described in section 3, for the purposes described in section 4, and have disclosed them to the categories of service provider described in section 12.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by those laws. We do not use or disclose sensitive personal information, including health information, for any purpose other than performing the Service, and we do not use it to infer characteristics about you.

Subject to the conditions of the applicable law, you have the right to know what personal information we have collected and how we have used and disclosed it, to obtain a copy of it, to request its correction or deletion, and not to be discriminated against for exercising those rights. Use the deletion feature described in section 15, or write to privacy@spriwa.com for a copy of your information. If an authorised agent makes a request for you, we will require proof of authorisation.

18. Children

The Service is intended for adults. It is not directed to children, and we do not knowingly collect Personal Data from anyone under the age of 16. If you believe a child has provided us with Personal Data, write to privacy@spriwa.com and we will delete it.

19. Security

We protect Personal Data with measures appropriate to its sensitivity. All traffic between the app and our servers is encrypted in transit; data is stored on infrastructure that encrypts it at rest; every record is bound to its owner and access is enforced at the database level so that one account cannot read another's; administrative access is restricted to those who need it; and credentials for our providers are held only on our servers and never in the app. No system can be guaranteed to be completely secure, and we cannot guarantee the security of information you transmit to us.

20. Changes to this Policy

We may update this Policy. The current version is always the one published at spriwa.com/privacy and shown in the app under Profile, and the date at the top records when it last changed. When it changes, the app shows you the updated Policy and asks you to agree before you carry on, and your account records which version you agreed to and when. A change takes effect when it is published, and applies to your continued use of the Service from that point. If you do not agree with an updated Policy, stop using the Service and delete your account, which erases your data as described in section 15.

21. Contact

Questions about this Policy, or about how we handle your Personal Data, should be sent to privacy@spriwa.com.

Terms of ServiceBack to spriwa.com