1. Summary
This summary helps you find the main points. The full policy applies.
- We collect the data needed to run Gravl Macros. This includes your account, body data, food log, goals, photos and app activity.
- We do not sell your personal or health data. We do not use it for advertising or allow cross-site advertising tracking.
- Photo, voice, label and coaching features send the input needed for the feature to an AI provider. Google Gemini is the main provider. OpenAI can act as a backup provider.
- Gravl Macros and Gravl Workouts use one account. They share your identity and some body data, but Gravl Workouts cannot read your food log or meal photos.
- You can access, correct and delete your data. You can also withdraw consent for optional processing.
2. Who We Are
Controller:
GAINS COACH PTY LTD
ABN 78 671 000 801
5/45 Sir Thomas Mitchell Road
Bondi Beach NSW 2026, Australia
Email: support@gravl.ai
EU representative under GDPR Article 27:
Matias Bruno
Calle de Viloria de la Rioja
Madrid 28050, Spain
Email: support@gravl.ai
We are the data controller for the processing described in this policy. Contact us if you have a question about this policy or your personal data.
2.1. Scope
This policy covers the Gravl Macros mobile app, its limited pre-account demo, the Macros pages on gravl.ai, and related support services. We call these services the “App” in this policy.
Gravl Workouts has a separate privacy policy. Third-party services that you choose to use also have their own privacy terms.
2.2. How Our Apps Work Together
Gravl Macros and Gravl Workouts are products of the same company. They use one account identity. The two apps can read and update your shared account identity, weight entries, body measurements and progress photos.
Your meals, recipes, custom foods, water logs, nutrition targets, meal photos, check-ins and expenditure history are Macros data. Gravl Workouts cannot access that data.
3. Data We Collect
3.1. Sources of Data
We collect data from these sources:
- You — when you create an account, complete onboarding, log food or body data, upload a photo, use voice input, contact support, or change a setting.
- Your device — when you grant access to the camera, photo library, microphone, notifications, Apple Health or Health Connect. The App also stores data in an offline database and short retry queues on your device.
- Our other product — shared identity, weight, body measurements and progress photos from Gravl Workouts.
- Service providers — purchase status from app stores and RevenueCat, sign-in data from Apple or Google when you choose those methods, and food information from food databases.
- Our calculations — estimates and trends derived from the data above.
3.2. Account and Profile Data
We collect your account ID, email address and sign-in details. If you use Apple or Google sign-in, we receive the identity data that the provider lets you share.
We also collect the profile data needed to calculate and show your targets. This can include your name, birth date, age, sex or gender, height, weight, target weight, body fat, activity level, exercise frequency, diet choices, goal, preferred units and check-in settings.
3.3. Food, Nutrition and App Content
We store what you add to the App. This includes food entries, serving sizes, calories, macro- and micronutrients, water, meal times, notes, recipes, saved meals, custom foods and catalogue submissions. We also store your settings, achievements, streaks and notification choices.
If you import a recipe from a web address, we process the address and the recipe content found on that page. If you submit a custom food to the shared catalogue, the food details and selected product images can be reviewed and published for other users.
3.4. Photos, Voice and AI
The App only receives the photos that you take or select for a feature. It does not scan your whole photo library.
When you log a meal from a photo, scan a nutrition label, or use voice input, we send the selected image or the final voice transcript and related text to an AI provider. The provider identifies food or reads the label and returns an estimate. Speech recognition runs through your device operating system. Depending on your device and settings, Apple or Google can process the audio. We and our AI providers receive the transcript, not the audio recording.
If you save a photo-based meal, we keep the meal photo and the raw AI result with your entry. This lets you review the source and lets us investigate a wrong result. Progress photos are stored separately so you can compare them over time.
3.5. Generated Targets and Coaching
We derive your weight trend, estimated energy expenditure, daily calorie and macronutrient targets, check-in results and progress insights from your profile and logs. If you ask for an AI coaching explanation, the relevant check-in or expenditure facts, reason and target figures are sent to an AI provider so it can explain the result in plain language.
These outputs are estimates. They do not produce a legal or similarly significant decision about you. You can review and correct the input data and the food entries produced by AI.
3.6. Apple Health and Health Connect
Health sync is optional. If you grant permission, the App can read weight, height, body fat and steps. On Apple devices, it can also read your date of birth during onboarding. It can write weight, height, body fat and nutrition data. The exact permissions available depend on your device and the choices you make in the system permission screen.
Nutrition data written to Apple Health or Health Connect can include energy, protein, carbohydrate, fat, fibre, sugar, sodium and other nutrients recorded for a meal. We use health-store data only to provide or improve the health and fitness features that you use. We do not use it for advertising or sell it.
You can change health permissions in your device settings. Revoking a permission stops future access. It does not by itself delete data already stored in the App or records already written to your device health store. Weight and body data imported from a health store become shared Gravl records and can also be available in Gravl Workouts.
3.7. Device, Purchase and Service Data
We collect data needed to run, secure and support the App:
- device ID, platform, app version, language, health provider, notification permission and push token;
- IP address, request time and basic network data processed by our hosting and security systems;
- crash reports, error messages, app release details, a user ID and feature-level service logs. Some logs can include entry IDs, dates, food or nutrient values, weight, target or expenditure values, or a short excerpt of a failed AI result;
- AI request metadata, such as the provider, model, result status, timing and usage amount;
- subscription product, entitlement and purchase status. Apple, Google and RevenueCat process the payment. We do not receive your full card details.
Before you create an account, the limited photo demo uses a random device identifier and your IP address to prevent abuse. Macros web pages can use local browser storage for language and help-search choices, and a first-party sign-in hint to show the correct navigation.
4. How and Why We Use Data
We use personal data to:
- create and secure your account;
- store and sync your food diary, recipes and body data;
- calculate targets, trends, expenditure and check-in results;
- provide photo, voice, label, recipe and coaching features;
- connect to Apple Health or Health Connect when you ask us to;
- manage subscriptions and send service messages;
- send notifications when you opt in;
- find faults, prevent abuse and improve reliability;
- answer support and privacy requests; and
- meet legal duties and protect our rights and users.
Where the GDPR or UK GDPR applies, we rely on these legal bases:
- Contract — to provide the App features that you request (Article 6(1)(b)).
- Consent — for optional features such as health sync, notifications and catalogue submissions (Article 6(1)(a)). Where data is special-category health data, we rely on your explicit consent when required (Article 9(2)(a)).
- Legitimate interests — to secure, support and improve the App, prevent misuse, and understand service reliability without overriding your rights (Article 6(1)(f)).
- Legal obligation — when the law requires us to process or retain data (Article 6(1)(c)).
Account and profile data are required for the core service. If you do not provide them, we cannot create a working Macros account or calculate targets. Photos, voice, health sync and notifications are optional. If you do not allow them, only the related feature is unavailable.
5. Service Providers and Sharing
We share data only as needed to provide the App, follow your request, meet the law, or protect the service. The providers below process data under their terms and our contracts where applicable.
- Google — Gemini processes meal photos, label photos, voice or typed meal descriptions, recipe details and coaching inputs. Firebase manages authentication. Google also provides Google sign-in, Google Play and Health Connect when you use them.
- OpenAI — can process the same AI inputs as a backup when the main AI service cannot complete a request.
- Supabase and PowerSync — store and sync account, nutrition, settings, body data and images between your devices and our service.
- Expo — hosts App service routes and provides push token and notification delivery services.
- Sentry — receives crash reports and operational logs. We disable default personal-data collection and remove email and IP fields from Sentry events. Sentry can still receive a user ID, device and app details, performance data, and the operational values described in Section 3.7.
- Twilio SendGrid — sends account verification and service email.
- RevenueCat, Apple and Google — manage subscription status and store purchases.
- Apple — also provides Apple sign-in, device speech recognition and Apple Health when you choose those features.
- Firecrawl — retrieves and can cache a recipe page when you ask the App to import its web address.
- Typesense, USDA FoodData Central and Open Food Facts — Typesense receives food search terms and filters. Open Food Facts receives barcodes for live product lookups. USDA receives a food record ID when we request more detail. Our catalogue also includes public data from AUSNUT.
- Microsoft Azure — hosts the Gravl Workouts service that receives your authenticated Macros connection and weight-sync notices and reads shared account data.
- Cloudflare — hosts and protects gravl.ai and processes normal web request data.
We can also disclose data if required by law, to respond to a valid legal process, to protect people or the service, or as part of a merger, financing, reorganisation or sale. Any successor must protect the data under this policy and applicable law.
We do not sell personal or consumer health data. We do not share it for targeted or cross-context behavioural advertising. We do not let third parties collect consumer health data across unrelated websites or apps for advertising.
6. Consumer Health Data Notice
This section gives added detail for consumer health privacy laws, including the Washington My Health My Data Act and Nevada consumer health data law, where they apply.
Health data we collect or derive: body measurements, age, sex or gender, activity, goals, food and nutrient intake, water, meal and progress photos, voice transcripts about food, weight trends, expenditure estimates, targets, check-in results, health-store data, and other information that can reveal or infer health status.
Sources: you, your device and health store, Gravl Workouts, service providers, and our calculations. Section 3.1 gives the full list.
Why we collect and use it: to provide the nutrition, weight-management, health-sync, progress and coaching features that you request; keep those features secure and reliable; and provide support. Section 4 gives the full list.
What we share and with whom: AI feature inputs go to Google or OpenAI; App data and images go to Supabase and PowerSync; health data goes to Apple Health or Health Connect when you enable sync; shared identity and body data are available to Gravl Workouts; and operational health or nutrition values can go to Sentry as part of error and reliability logs. The other providers and purposes are in Section 5. We have no affiliate that uses this data for its own advertising.
You can confirm whether we collect your consumer health data, access it, correct it, delete it, or withdraw consent for future collection or sharing. See Sections 9 and 10. If we refuse a request, you can appeal by replying to our decision and writing “Privacy Appeal” in the subject line.
7. International Transfers
We are based in Australia. Our providers operate in Australia, the United States and other countries. Your data can therefore be processed outside the country where you live.
Where European data-transfer rules apply, we use a valid transfer mechanism. This can include an adequacy decision, standard contractual clauses, or another safeguard allowed by law. Contact us if you want more information about the safeguard used for a transfer.
8. How Long We Keep Data
We keep account and App data while your account is active because your diary, trends and targets depend on your history. A saved meal photo and its raw AI result are kept with the related App record.
We keep service, security and AI request logs only for as long as they are needed to run, secure and debug the service. The period depends on the type of log, the risk it records and the settings of the relevant provider. We keep purchase and legal records for the period required by tax, accounting, dispute or other law.
A progress photo that you delete is hidden at once. After a short undo period, the App tries to remove its stored image files. If storage deletion fails, the hidden photo can remain until we complete cleanup. Backups and cached copies can remain until they are replaced in the normal backup cycle. When we no longer need personal data, we delete or de-identify it.
Some records support security, catalogue review, purchase promotions or service operations and can remain after a Macros data deletion. These include AI request metadata, rate-limit records, recent food reference data, catalogue-review records, promo-redemption records and past Sentry events. We keep them only for the relevant operational, security, legal or audit need, then delete or de-identify them.
9. Deletion
You can delete individual food entries, recipes, body entries and photos in the App. You can also use the Macros account-deletion control to remove Macros-only data.
The Macros account-deletion control removes:
- meals, recipes, custom foods, saved meals, daily summaries, water, check-ins, expenditure history, coaching messages, programmes, achievements and streaks;
- meal-photo records and the stored meal-photo files we can locate;
- Macros settings and program or check-in target history, and an attempt to remove registered device tokens; and
- your link to unpublished custom catalogue foods.
This control does not delete the shared Gravl identity, Firebase sign-in, weight entries, body measurements or progress photos. Some account-level profile and current target values can also remain on the shared user record. These can include your email, name, birth date, sex or gender, height, onboarding weight, activity level, goal, current calorie and macro target fields, and custom nutrient goals. The App resets Macros onboarding so most profile and target values are replaced if you start again.
To delete the shared data or your full Gravl account, contact us at support@gravl.ai. We will also address any meal-photo file that the automated deletion could not remove.
Deleting App data does not cancel an app-store subscription and does not necessarily delete records already written to Apple Health or Health Connect. Manage those records and permissions in the relevant store or device settings.
An optional catalogue contribution can be detached from your account after review and publication. Once it is no longer linked to you, we may not be able to find it through an account request. Do not include a face or other personal information in a catalogue product image. Pending review records and contribution images can remain linked to your account after a Macros data deletion. Ask support to include them in a full privacy-deletion request.
10. Your Rights
Depending on where you live, you can have the right to:
- know whether we process your data and access a copy;
- correct inaccurate or incomplete data;
- delete data;
- restrict or object to processing;
- receive data in a portable format;
- withdraw consent at any time for future processing;
- appeal a refusal of a consumer health data request; and
- complain to a regulator.
We do not discriminate against you for exercising a privacy right. Some rights have legal limits. For example, we can keep data that we must retain by law or need to establish, exercise or defend a legal claim.
10.1. How to Exercise Your Rights
Email support@gravl.ai or use the support page. State that your message is a privacy request and tell us which right you want to use. To appeal a refusal, reply to our decision with “Privacy Appeal” in the subject line.
We can ask for information needed to confirm your identity. We will respond within the period set by applicable law. Under the GDPR, this is normally one month. If a request is complex, we will tell you if we need more time.
11. Security
We use technical and organisational controls designed to protect your data. These include encryption in transit, access controls, private storage rules, authentication, rate limits, monitoring and restricted staff access. No system is completely secure. We review risks and act when we find a security issue.
12. Children
The App is for people aged 18 or older and is not directed at children. Do not create an account if you are under 18. Contact us if you believe that a child has used the App. We will investigate and delete the data where required.
13. Complaints
Contact us first if you believe that we handled your data incorrectly. We will review your complaint and respond.
You can also complain to the privacy regulator where you live or work, or where the issue happened. In Australia, this is the Office of the Australian Information Commissioner. In the EU or EEA, you can contact your local data protection authority. Rights under US consumer health laws can also be raised with the relevant state attorney general.
14. Changes to This Policy
We can update this policy when the App, our providers or the law changes. We will post the new effective date here. If a change is material, we will give notice in the App, by email, or through another suitable method before the change takes effect when the law requires it. You can ask us for an earlier version.