Legal

Privacy Policy

Effective 15 August 2026
Version 1.0
Plain language on purpose — if anything is unclear, email us.

ONEMETAL is operated by ONEMETAL, India (“ONEMETAL”, “we”). This policy covers the ONEMETAL app and website. Contact: onemetal.pratham@gmail.com.

01

What we collect

You give us:

  • Account data: email, password (hashed), name if you add it, age confirmation (16+), mobile (optional), gender, physical activity levels.
  • Google Sign-In data (only if you sign in with Google): if you create or access your account using Sign in with Google, Google shares your name, email address, and profile picture with us. We use them only to create your account, sign you in, and contact you about your account. We request no other Google scopes and access no other data in your Google Account. You can revoke our access at any time at myaccount.google.com/permissions.
  • Health & fitness data (sensitive — collected only with your explicit consent): workouts, sets/reps/weights, body weight and measurements you add, nutrition logs, mindset session activity (which sessions you did, duration — not your thoughts; we don’t record mindset audio).
  • Voice recordings & photos (only if you enable AI logging): voice clips and food photos, used solely to create log entries.
  • Apple Health / Health Connect data (only if you connect it): the data types you approve (e.g., workouts, weight, steps). Governed additionally by Section 8.

Collected automatically: device type, OS version, app version, crash logs, and basic usage events (feature opened, session completed) to fix bugs and improve the app. No advertising identifiers. No location tracking.

02

What we do with it

We use your data to: run the app’s strength, nutrition, and mindset features; convert your voice/photos into log entries; sync with Apple Health/Health Connect if connected; process subscriptions; fix crashes; respond to support; and meet legal obligations.

What we never do

Sell your data; share it for advertising; use health data for marketing; profile you for third parties. If that ever changes, we’ll ask you first — but our position is that it won’t.

04

Who processes your data (our processors)

We use a small set of service providers, each under a data processing agreement:

  • Supabase — database and authentication (hosted on Asia Pacific, SouthEast)
  • Railway — backend hosting (California, US WEST)
  • AI providers — OpenAI and Anthropic — process voice clips and food photos to create log entries, only if you enabled AI logging. Our API agreements prohibit them from training models on your data. Clips/photos are not retained by us after processing beyond 1 day for debugging, then deleted.
  • Apple / Google — subscription billing (we never see your card details), and, if you use it, Sign in with Google authentication
  • posthog — crash reporting and product analytics

We add or change providers only after updating this policy and, where the change involves your health data, asking for renewed consent.

05

International transfers

We operate from India; our processors run in US, EU, SEA. Where data leaves the EEA/UK, we rely on Standard Contractual Clauses with our processors. Where it leaves India, we transfer only to countries not restricted under the DPDP Act.

06

Retention

  • Account and health data: kept while your account is active. Delete your account (in-app: Settings → Privacy → Delete account) and your data is deleted within 30 days, except: consent records (pseudonymized) and records we must keep by law.
  • Voice clips and photos: deleted after processing (1 day max).
  • Crash logs: 30 days
07

Your rights

Everyone, regardless of region: access, correct, export (JSON), delete your data, withdraw any consent — all from Settings → Privacy, or by email. We answer within 30 days.

EEA/UK (GDPR): additionally — restriction, objection, portability, complaint to your supervisory authority.

California (CCPA/CPRA): right to know, delete, correct, and opt out of sale/sharing. We do not sell or share personal information as defined by the CPRA, and we do not use sensitive personal information beyond what’s necessary to provide the service. No “Do Not Sell” link is required because there is nothing to opt out of; we honor Global Privacy Control signals regardless. We do not discriminate for exercising rights.

Washington & similar state health-privacy laws (MHMD): we collect consumer health data only with your separate consent (onboarding Step 2), never sell it, and you may withdraw consent and request deletion as above.

India (DPDP Act 2023): rights to access, correction, erasure, grievance redressal, and nomination. Grievance Officer: Pratham, onemetal.pratham@gmail.com. If unsatisfied, you may approach the Data Protection Board of India.

08

Apple Health & Health Connect

If you connect them: we read only the data types you approve and write only what you log. Health data obtained from HealthKit or Health Connect is never used for advertising or marketing, never sold, never shared with third parties except processors strictly necessary to provide the features you asked for, and never used for any purpose you haven’t consented to. Disconnect anytime in your OS health settings; we stop syncing immediately.

08A

Coaches and creator programs

If you enrol in a Coach’s program, we share with that Coach only the data you consented to at enrolment — typically your workouts and progress, nutrition logs, body stats you’ve added, and your check-ins and messages with them. We do not share your mindset session content.

The Coach is an independent controller of that data, not our processor. They decide how they use it and are responsible for it under their own privacy practices and applicable law. Ask them directly about how they store and handle it. Coaches are contractually required by our Coach Terms to use client data only to deliver coaching, to keep it secure, and never to sell it or use it for advertising — but they, not we, answer for their compliance.

Revoke a Coach’s access anytime in Settings → Coaches. We stop sharing immediately. Data they already received or exported stays with them; direct deletion requests for that copy to the Coach.

Your rights under Section 7 apply to us. For data held by a Coach, exercise those rights with the Coach; we’ll pass on requests where we can.

09

Security

Encryption in transit (TLS) and at rest, row-level security on the database, access limited to the founder and systems that need it, secrets managed outside code. No system is unbreakable; if a breach affects your data we will notify you and regulators as required by law (including within DPDP/GDPR timelines).

10

Children

ONEMETAL is for users 16+. We don’t knowingly collect data from anyone under 16; if we learn we have, we delete it. Parents/guardians: contact us at the email above.

11

Changes

Material changes (new data types, new processors touching health data, new purposes) → in-app notice and, where required, fresh consent before the change applies to you. Minor edits → updated date above.

12

Contact

EntityONEMETALAddressIndiaEmailonemetal.pratham@gmail.com

This policy works alongside the ONEMETAL Terms of Use. If a translated version of this page conflicts with the English original, the English version governs.