Workforit is a fitness and dieting app for iOS and Android. It is operated by an independent developer and is referred to in this policy as "Workforit" ("we", "us", or "our"). If you have any question about this policy or about your data, you can reach us at the email in the Contact section below.
This policy explains what data the app collects, how we use it, who we share it with, and the choices and rights you have.
Your login session is stored on your device so you stay signed in.
When you complete onboarding and use Settings, we store:
We store your date of birth, not your age; your age is calculated on your device when needed. Height and weight are always stored in metric units; your unit preference only changes how values are shown to you.
Each meal you log stores a food name (free text you type), calories, protein, carbohydrate, fat, the meal type (breakfast, lunch, dinner, or snack), the source of the entry (photo, manual, or a saved favorite), and the time. Because the food name is free text, please avoid typing sensitive personal information you do not want stored.
Meals you save for one-tap logging store a name and the calories and macros for that meal.
See "Food photo AI analysis" below for how photos are analyzed and stored.
Each exercise entry stores the activity name, its MET value, duration, calories burned, the source of the entry, and the time. For workouts imported from Apple Health or Google Health Connect, we also store a per-workout identifier provided by that health platform (for example the HealthKit workout sample identifier, or the Health Connect record identifier), which we use only to avoid importing the same workout more than once. Entries can be added manually or imported from a connected health platform (see the Apple Health and Google Health Connect sections).
If you record a weigh-in, we store the weight and the date, keeping one weigh-in per day.
If you subscribe, we store a record of your subscription status (for example active, trialing, in a grace period, or expired), the product you purchased, the billing period type, and the expiry, along with identifiers used to match the subscription to your account. We do not store your payment card, billing address, or any other payment details; those are handled by Apple, Google, and RevenueCat (see the processors table).
Some information is kept only on your device: your login session tokens, and a flag recording whether you have connected a health platform.
We use the data above to:
We do not use your data for advertising or marketing, and we do not sell it.
When you log a meal by photo, you take a picture with your camera or choose one from your photo library. The image, together with any optional free-text note ("hints") you add, is sent to our backend and forwarded to Anthropic's Claude AI (api.anthropic.com) to estimate the calories and macros of the meal. Only the image and your optional note are sent for analysis; your name, email, and account identifiers are not included in that request. By choosing to log a meal by photo, you consent to that image, and any note you add, being sent to Anthropic for analysis. If you prefer not to send an image, manual entry is always available instead.
The result is an estimate. The app presents it as an estimate, and you can review and edit the values before saving. The saved food log stores the final numbers you confirm, not the raw AI output.
Separately from the analysis, the app also attempts to save the original photo to our private storage (see "Where photos are stored" under Data retention). This upload is best effort, so a photo may occasionally not be saved.
Anthropic processes the image as our service provider, under its commercial API terms, and we send it only for the purpose of producing your nutrition estimate.
If you connect Apple Health on iOS, the app reads the following data on a read-only basis:
We request read access only. The app never writes, changes, or shares any data back into Apple Health. Only discrete workout sessions are imported; all-day active energy is not imported.
Imported workouts are stored in your account on our backend (Supabase) as exercise entries, so they appear alongside your other exercise history. Each imported workout also stores a per-workout identifier provided by the health platform (for example the HealthKit workout sample identifier), which we use only to avoid importing the same workout more than once. This health data is never used for advertising, marketing, or any use-based data mining. It is never sold, is never transferred to data brokers, resellers, or advertising platforms, and is never used to determine your creditworthiness, insurance eligibility, employment, or lending. It is not shared with any third party without your explicit consent, other than being stored with our backend provider as described in this policy. The app requests only the health data types needed for its user-facing features (importing your workouts and the energy burned during them). Health sync only runs when you have connected a platform, are signed in, and have an active pro entitlement, which includes the free trial.
You can withdraw your consent to health syncing at any time by turning off the health connection in the app's Settings, or by revoking the app's access in the iOS Settings under Privacy and Security, then Health. Once you revoke access, no further workouts are imported; workouts already imported stay in your account until you delete them or delete your account.
If you connect Google Health Connect on Android, the app requests these permissions, on a read-only basis:
android.permission.health.READ_EXERCISE (your recorded workouts: activity name, start time, and duration).android.permission.health.READ_ACTIVE_CALORIES_BURNED (active energy burned during those workouts).We read these values only. The app never writes, changes, or shares any data back into Health Connect. Only discrete workout sessions are imported; all-day active energy is not imported.
As with Apple Health, imported workouts are stored in your account on our backend (Supabase) as exercise entries. Each imported workout also stores a per-workout identifier provided by Health Connect (its record identifier), which we use only to avoid importing the same workout more than once. This health data is never used for advertising, marketing, or any use-based data mining. It is never sold, is never transferred to data brokers, resellers, or advertising platforms, and is never used to determine your creditworthiness, insurance eligibility, employment, or lending. It is not shared with any third party without your explicit consent, other than being stored with our backend provider as described in this policy. The app requests only the health data types needed for its user-facing features (importing your workouts and the energy burned during them). Health sync only runs when you have connected a platform, are signed in, and have an active pro entitlement, which includes the free trial.
You can withdraw your consent to health syncing at any time by turning off the health connection in the app's Settings, or by revoking the app's permissions in Health Connect through the Android Settings. Once you revoke access, no further workouts are imported; workouts already imported stay in your account until you delete them or delete your account.
We share data with the service providers below only as needed to run the app. We do not sell your data, and we do not share it for advertising.
| Processor | What it receives | Why |
|---|---|---|
| Supabase | Your account (email, password, display name), body information and goals, food logs, favorite meals, exercise logs (including imported workouts and their per-workout health-platform identifiers), weight logs, subscription status, and your food photos. | Hosts our database, authentication, file storage, and backend functions. |
| Anthropic (Claude AI) | The meal photo you submit and any optional free-text note. No account identifiers are sent. | Estimates the calories and macros of the meal in the photo. |
| RevenueCat | Your account's user identifier and your purchase and entitlement events. No payment card details. | Manages and reports your subscription status. |
| Apple (App Store) | Your purchase transaction and, if you use Apple Health, health access on your device. | Processes App Store subscription payments; provides HealthKit. |
| Google (Play, Health Connect) | Your purchase transaction and, if you use Health Connect, health access on your device. | Processes Google Play subscription payments; provides Health Connect. |
Each processor handles your data under its own privacy terms and applicable data protection law. We share with each processor only the data listed above, and only for the stated purpose; none of them receives your data for advertising.
The app does not include any third-party advertising, analytics, tracking, or crash-reporting SDKs. The third-party services your data can reach are exactly the ones in the table above.
We keep your account data and your logged data for as long as your account exists, so the app can show your history and progress. You can delete individual entries at any time, and you can delete your whole account (see Account and data deletion).
Where photos are stored. Meal photos that upload successfully are kept in private storage, in a folder reserved for your account, until you delete your account. Deleting an individual food log removes that log entry, but a stored photo is removed only when you delete your account.
We do not set a fixed calendar retention window for other data; it is retained until you delete it or delete your account. When you delete your account, the data we hold is deleted as described below. Copies may persist for a limited time in our backend provider's routine database backups before those backups expire and are deleted. Data already sent to Anthropic for analysis, and records held by RevenueCat, Apple, and Google, are governed by those providers and are not covered by our deletion process.
You can delete your account and its associated data at any time.
In the app: open Settings and choose to delete your account, then confirm. This runs a secure server function that:
Deleting your account also removes the login record that holds your email, password, and display name.
By email: if you cannot use the in-app flow, email us at workforit.dev@aaawesomepossum.com and ask us to delete your account and associated data. Tell us the email address on your account so we can identify it.
On the web: you do not need the app to request deletion. This page is publicly available on the web, and you can start a deletion request from any device by emailing the address above. This section describes which data is deleted (everything listed in the in-app flow) and what may temporarily remain (backup copies, as described under Data retention).
Please note: deleting your account removes your data from our systems. It does not, by itself, cancel a subscription billed by Apple or Google (manage that through the App Store or Google Play), and it does not delete records that Apple, Google, RevenueCat, or Anthropic hold under their own policies. If keeping your subscription active is not what you want, cancel it through the store first.
Your data is protected by database access rules that let each signed-in user read and change only their own records, and meal photos are kept in a private storage area scoped to your account. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
If you are in the EU, the UK, or a similar jurisdiction (GDPR and UK GDPR): you have the right to access your data, to correct it, to delete it, to restrict or object to processing, and to receive a copy in a portable form. Our lawful bases are your consent (for example, for health data and food photos), performance of our agreement to provide the app, and our legitimate interests in running and securing the service. You can withdraw consent for the health connection at any time by disconnecting it in the app's Settings or by revoking the permission in your device's OS settings, and you can exercise your other rights using the in-app tools or by emailing us.
If you are in California or a similar US state (CCPA and comparable laws): you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information. We do not sell or share your personal information or health data, so there is nothing to opt out of.
Much of your data is available to view and edit directly in the app, and you can delete all of it by deleting your account.
We and our processors may store and process your data in countries other than the one you live in, including where those providers operate their infrastructure. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum). If you would like more detail about where your data is processed, contact us.
The app is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Because the app includes calorie targets, weight tracking, and other weight-management features, it is not intended for anyone under 18 without the involvement and consent of a parent or guardian. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy from time to time. When we do, we will change the "Last updated" date above and, where appropriate, notify you in the app. Continued use of the app after an update means you accept the revised policy.
For any privacy question or request, email: workforit.dev@aaawesomepossum.com