Skip to content
Palpo
FeaturesProPrivacyQuestions
Get the app
FeaturesProPrivacyQuestionsGet the app
Privacy policyHealth and AIDelete your account

On this page

  1. 1. Who is responsible for your data
  2. 2. The short version
  3. 3. What we collect
  4. 4. Health data, and why we ask you to consent
  5. 5. Why we process your data, and on what legal basis
  6. 6. Who else is involved
  7. 7. Where your data is
  8. 8. How long we keep it
  9. 9. Your rights
  10. 10. Children
  11. 11. Security
  12. 12. Changes to this policy
  13. 13. Our website and cookies

Privacy Policy

Effective from 9 October 2026. Version 1.0.

On this page
  1. 1. Who is responsible for your data
  2. 2. The short version
  3. 3. What we collect
  4. 4. Health data, and why we ask you to consent
  5. 5. Why we process your data, and on what legal basis
  6. 6. Who else is involved
  7. 7. Where your data is
  8. 8. How long we keep it
  9. 9. Your rights
  10. 10. Children
  11. 11. Security
  12. 12. Changes to this policy
  13. 13. Our website and cookies

This policy explains what Palpo does with your personal data. It covers health data, which the law treats as especially sensitive, so it is more detailed than most.

1. Who is responsible for your data

Jelle Caekebeke is the data controller. Contact us about anything in this policy by email at contact@palpo.fit. That address reaches the person responsible for data protection directly, and we aim to answer within a few days and in any case within the one month the law allows.

We have not appointed a Data Protection Officer. We are a small operation and believe we are not required to.

2. The short version

  • Everything you record is stored against your account, and nobody else can see it unless you join the community and choose to share a workout there.
  • We do not sell your data, we do not share it for advertising, and we do not use it to profile you.
  • A few outside services are involved: our hosting provider, an email service for the emails your account needs, an AI service used only when you ask for a food estimate, a public food database that receives search words but nothing about you, Google if you choose to sign in with it, and a subscription service if you open the Pro screen. Section 6 names each one.
  • The community is optional, it is off until you join, and it never carries your weight, your food, your sleep or your heart rate. Showing your ranks there is off until you turn it on.
  • You can export everything or delete everything, yourself, at any time, from Settings.
  • Our website sets no advertising or tracking cookies. Section 13 says what a visit to it involves.

3. What we collect

Data you give us

Account. Your email address and password. The password is stored as a hash by our authentication provider; we never see it. If you sign in with Google instead, there is no password: Google tells us the email address of the Google account you chose, the name and the link to the profile picture on it, and an identifier for that account. Our authentication provider keeps these with your account, so that you are recognised the next time; the app doesn't show or use the name or the picture.

About you. Display name, date of birth, biological sex, height, weight, time zone, country or region, units, week start, theme, which parts of the app you have switched off, whether Quiet mode is on, and how you have arranged your home screen. Your date of birth is required: we ask it when you sign up to check that you are old enough to use the app where you live (section 10), and the app also uses it to calculate reference intakes. Sex, height and weight are optional, but the app needs them for reference intakes too; if you skip them, those figures are less accurate or unavailable.

Goals. Calorie, macronutrient, hydration, step and weight goals you set.

What you record. Meals and drinks, with their calories, macronutrients, fibre, vitamins, minerals and fatty acids; supplements and the doses you take; workouts, exercises, sets, reps, weights, distances, durations and perceived effort, and the notes you write on exercises; sleep; hydration; weight; and body measurements (waist, chest, hips).

Custom entries. Foods, recipes, exercises and supplements you create.

Products you send to the shared food catalog. If you add a product from its label, or send a fix for one, the product's details and that you sent them. Only we can see who sent a product; once we approve it, everyone sees the product, never who sent it.

In the community, if you join it. A username you choose, your visibility setting, and the date you joined. For each workout you share: its name, date, duration, exercises, sets, reps, weights, distances, times, the records it set, and a caption if you write one — a copy taken at the moment you share, so later edits to the workout do not change the post. Monthly recap cards you choose to share. The cheers and comments you leave, who you follow and who follows you, and anyone you block. Whether you show your ranks, off until you turn it on. Whether you are listed in Discover, off until you turn it on, and, if we feature you there, the short line we write about you. Your weight, your measurements, your heart rate, your sleep, your food, your water, your supplements and your location are never part of a post.

Reports you make. If you report a post, a comment or a member: what you reported, an excerpt of it, the reason you chose and anything you write.

Bug reports. If you report a problem from Settings: what you wrote, the screen you were on, the app version, your device model and operating system version, and error details where there are any.

Meal and label photos. If you ask the app to estimate a meal from a photo, or to read a food or supplement label, that photo is sent to the AI service. It is not stored in your account. See section 6.

Data from connected apps

If you connect Google Health Connect, the app can read: weight, body fat, sleep, blood oxygen, breathing rate and skin temperature while asleep, steps, heart rate, resting heart rate, heart rate variability, water, calories burned, total calories, VO2 max, workouts recorded on a watch or in another app, distance and elevation — including historical records — as recorded by your device or another app. You choose which of these sync. When several apps have recorded the same thing, only one copy is kept. It can also write back your weight, your water and your finished workouts.

What is synced is saved to your account here, and is deleted from here when you delete your account. Disconnecting stops future syncing without deleting what was already synced; deleting synced data is a separate action in the app.

If you connect a heart rate sensor over Bluetooth (such as a Fitbit Air, a chest strap, or a watch that shares heart rate), the app reads your heart rate from it while a workout, or the screen where you connect it, is open, to show it live and in that workout's summary. These readings stay on your phone, only in the app's memory: they are not saved to your account or sent anywhere, and they are gone when the app closes. The app remembers which sensor you chose on your phone only, so it can reconnect. Finding the sensor uses Android's Nearby devices permission, which the app never uses to work out your location. You can forget the sensor at any time in Settings › Connected apps.

Data we generate

Records of which version of which consent you gave, and when, and whether you later withdrew it. Technical logs from our hosting provider, which include IP addresses, needed to run the service and investigate abuse.

Streaks, records and badges, worked out from what you have already recorded, and a note of which badges you have earned.

Ranks: one for each muscle group and one overall, worked out from your best sets of 3 reps or more, compared with a standard for your body weight (or a standard body weight, if you switch that off) and the men's or women's standards you pick, with the set behind each rank. They are worked out again from what you have recorded whenever it changes.

A count of the AI estimates you have used, so the allowance can be enforced: one row per estimate, holding your account, which plan it was used on and the time — never the meal or the photo.

A count of the labels you have had read each day, so the daily limits can be enforced: for a food label sent with its barcode, the barcode and how many times it was read; for any other label, only how many were read — never the photo.

Counts of the products and fixes you send to the shared catalog each day, of the searches the app passes on to the public food database each minute, and of the new products your searches add to the catalog each day, so the limits on each can be enforced — never what you searched for.

Searches and barcodes that found nothing, with no link to you or anyone, so we know which products are missing.

Your subscription status, if you buy the paid plan: which plan, when it was bought, when it expires, whether it will renew and what the store last told us.

Your first week of the paid plan, which every new account gets once: when it started and when it ends, so it is given only once per account.

If we give you the paid plan ourselves (as a tester, say, or to put a problem right): until when, and a short note of why.

If we act on a report about your content or your account, a record of what we did and why, so we can show the decision was properly made.

The age check when you sign up, or once later for an account that has not been through it. The app works out which country's minimum age applies from your Google Play account's country, or, if Google Play can't say, your SIM card's country or your phone's time zone. That happens on your phone, for the check only, and the country is not kept. If you are below the minimum age, nothing about you is kept on our servers; a note that the check said no stays on your phone only, so that it cannot simply be repeated with another date.

If Google Play tells us an age range for your account, we use it only to check that you are old enough, on your phone, and we do not keep it.

4. Health data, and why we ask you to consent

Most of what the app holds is data about your health: what you eat, what you weigh, how you sleep, your heart rate, your body measurements, your supplementation, your sex. Under Art. 9 GDPR this is "special category" data and may only be processed on a narrow set of grounds.

We rely on your explicit consent (Art. 9(2)(a)), asked for separately from everything else, before the app can be used. You can withdraw it at any time from Settings, and withdrawing it stops the app processing that data — which in practice means the app can no longer function, so we will ask you whether you want to delete your account.

Consent for reading Google Health Connect, for sending anything to the AI service, for sharing workouts in the community and for showing your ranks are each asked for separately again, at the moment that feature is first used, and can each be withdrawn on their own. Sharing a workout with other people is itself processing of health data, which is why joining the community asks you explicitly and why leaving it withdraws that consent and deletes what you posted.

Your supplement records deserve a specific mention: what someone supplements can imply a diagnosed condition. We treat those records as health data accordingly.

5. Why we process your data, and on what legal basis

Give you an account and keep you signed in

Data involved
Email, password hash, session data
Legal basis
Contract (Art. 6(1)(b))

Store what you record, and show it back to you as totals, charts and history

Data involved
Everything in section 3
Legal basis
Contract, plus your explicit consent for health data (Art. 9(2)(a))

Check that you are old enough to use the app where you live

Data involved
Date of birth; your country and any age range from Google Play, used on your phone for the check and not kept
Legal basis
Legal obligation (Art. 6(1)(c), with Art. 8) and our legitimate interest in not holding children's data (Art. 6(1)(f))

Calculate goals and reference intakes

Data involved
Age, sex, height, weight, activity
Legal basis
Contract, plus explicit consent

Estimate a meal from your description or photo, or read a label from its photo, when you ask

Data involved
The text or photo you submit
Legal basis
Your separate explicit consent, withdrawable

Sync with Google Health Connect, when you connect it

Data involved
The data types you selected
Legal basis
Your separate explicit consent, withdrawable

Look up a food or barcode in a public food database

Data involved
Your search words or the barcode only
Legal basis
Contract (providing the search you asked for)

Show the workouts you share, and your username, to the community

Data involved
What a post carries, per section 3
Legal basis
Your separate explicit consent, withdrawable by leaving

Work out streaks, records and badges

Data involved
What you have already recorded
Legal basis
Contract

Work out your ranks

Data involved
Your finished sets, your weigh-ins or weight, your sex or the standards you pick
Legal basis
Contract, plus explicit consent for health data

Show your rank names on your community profile, when you turn it on

Data involved
Rank names
Legal basis
Your separate explicit consent, withdrawable

List you in Discover, when you turn it on, and feature creators there

Data involved
Username, follower and shared-workout counts, your rank name if you show it, and for a featured creator the line we write
Legal basis
Your community consent and the switch you turn on, withdrawable by turning it off; featuring is our legitimate interest in helping members find creators (Art. 6(1)(f)), only while your switch is on

Sell and run the paid plan, and your first week of it

Data involved
Account identifier, subscription status, first-week dates, AI estimates used
Legal basis
Contract (Art. 6(1)(b))

Handle reports and moderate the community

Data involved
The report, the content reported, the decision
Legal basis
Legal obligation (Digital Services Act Arts. 16 and 17), and our legitimate interest in a community that follows its rules

Act on a bug report you send

Data involved
What you wrote and the device details with it
Legal basis
Legitimate interests (Art. 6(1)(f)) — fixing the app

Keep the app working, secure and free of abuse

Data involved
Technical logs, IP addresses
Legal basis
Legitimate interests (Art. 6(1)(f))

Prove we obtained consent properly

Data involved
Consent records
Legal basis
Legal obligation (Art. 5(2), Art. 7(1))

We do not use your data for advertising, we do not sell it, and we do not make automated decisions about you that have legal or similarly significant effects. Ranks compare your lifts with a standard so you can see where you stand; they are shown to you, and to others only if you choose, and nothing is decided about you from them.

6. Who else is involved

Supabase — hosting, database and authentication. Stores your account and everything you record. Our database is hosted in the European Union. They act only on our instructions, under a data processing agreement.

Google — signing in, if you choose it. When you tap Continue with Google, Google shows you its own sign-in and tells us which Google account you chose (see "Account" above). Google then knows that you use Palpo, as it does for any app you sign in to with Google, under Google's own privacy policy. Nothing you record in the app goes to Google this way. If you sign up with your email instead, Google is not involved.

Brevo — account emails. Sends the emails your account needs, such as the link to confirm your email address or to reset your password, and our replies when you write to us. It receives your email address and the content of those emails, and nothing you record in the app. Brevo is a French company and keeps this data in the European Union. It acts only on our instructions, under a data processing agreement.

Google Cloud (Gemini) — AI food estimation. When you ask the app to estimate a meal or to read a food or supplement label, the description you typed or the photo you provided is sent to Google's Gemini model, on Google Cloud's Gemini Enterprise Agent Platform (formerly Vertex AI), for that one request. It is sent from our server, not from your phone. Nothing that identifies you goes with it — no name, no email, no account identifier — so Google receives the meal and nothing about whose meal it is. The photo is not stored by us, and we do not keep a copy once the answer comes back. This happens only when you ask, and only if you have given the separate consent for it.

This processing takes place in the European Union. We send these requests to Google's EU endpoint, where Google keeps the processing inside EU member states, so asking for an estimate does not send your data outside the EU. Google acts only on our instructions, under its data processing terms, and does not use your meal descriptions and photos to train its models. Google may hold a request in memory for up to 24 hours to answer repeated requests faster, and if its automated checks flag a request as possible misuse of its service, it may keep that request for up to 90 days, in the EU, only to look into the misuse.

If we ever change AI provider, we will update this policy and ask you to agree to the new consent text before the new provider is used.

Open Food Facts — public food database. When you search for a food or scan a barcode, the search words or the barcode are sent from our server to Open Food Facts. Nothing that identifies you is sent, and the request comes from us, not from your phone, so your IP address is not disclosed to them.

RevenueCat — subscriptions. Handles the paid plan's purchases and tells us whether your subscription is active, from the United States (see section 7). It receives your account identifier here, what the store says about the purchase, and the technical details any connection carries (your IP address, phone model, system and app version, and language) — nothing you have recorded and no health data. It is only started when you open the Pro screen, so if you never look at the paid plan nothing about you reaches it at all. Once you have bought or restored the paid plan on a phone, the app also starts it there when it opens, so that a purchase left unfinished can be completed. Payment itself is taken by the app store, not by RevenueCat and not by us — we never see your card details.

Other members of the community, if you join it. This is the one part of the app where another person sees your data, and only what you choose: the username you picked and the workouts and recap cards you share, with the cheers and comments you leave. Who that is depends on your visibility setting — everyone in the community, only followers you have approved, or nobody. If you turn on Show me in Discover, members who don't know your username can also come across it in Discover's lists, with your follower and shared-workout counts, and your rank name if you show your ranks. Discover only lists people who are 18 or over and not Private. You can change both settings at any time, and blocking someone stops them seeing you or reaching you. Anything already seen can have been read, copied or screenshotted, which we cannot undo; what we can do, and do, is delete your posts, comments, cheers and follows when you leave the community. A post or comment you report, or that is reported about you, is read by us so that we can decide about it.

Your ranks, if you choose to show them. Showing your ranks lets the members who can see your posts see your rank names on your profile, such as Shark, but never the step within a rank, a score, your lifts or your body weight. Ranks are worked out with your body weight, so someone who knows your lifts could roughly guess it. Under 18, only followers you approved yourself see them. Turning it off, or leaving the community, stops it at once.

Cloudflare — our website. Hosts our website, where this policy is published, and protects it from attacks and automated abuse. It receives what any visit to a website reveals and nothing you record in the app. Section 13 explains what a visit involves, including the cookies.

The app stores. If you install from Google Play or the App Store, that store knows you installed the app, and if you subscribe, the store takes the payment and holds the payment details. That is between you and them, under their own privacy policies.

Nobody else receives your data. We do not sell your data and we do not share it for advertising, ever — neither what you record nor what syncs from Health Connect. If the list above ever changes, this policy changes first and we ask you again.

7. Where your data is

Your data stays in the European Union.

Your account and everything you record are stored in the EU. AI food estimation is processed in the EU too, at Google's EU endpoint. Nothing you record and no health data is transferred outside the EU or the EEA.

The one exception is the paid plan. RevenueCat, which handles subscriptions, stores its data in the United States. If you open the Pro screen it receives your account identifier and the technical details any connection carries (section 6), and if you buy or restore the paid plan, what the app store says about that purchase; nothing you have recorded. That transfer is governed by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) in our agreement with RevenueCat. If you never open the Pro screen, nothing about you reaches it.

Two qualifications, so this is not overstated. Our hosting provider and Google are both companies with parent entities outside the EU, and in narrow cases — a support engineer diagnosing a fault, for example — staff outside the EU can in principle access systems holding data. Where that happens it is governed by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) in our agreements with them, and you can ask us for details at contact@palpo.fit. And if you install from an app store, that store is subject to its own privacy policy and its own transfers, which we do not control.

Visiting our website is separate from using the app: Cloudflare serves it from its worldwide network, as section 13 explains.

If you would still rather nothing of yours was processed by an AI service at all, do not give the AI estimation consent, or withdraw it in Settings. Every other part of the app works without it, and withdrawing it changes nothing else.

8. How long we keep it

While your account exists, we keep what you have recorded, because the point of the app is your own history. You can delete any individual entry at any time.

When you delete your account, your personal data is erased from our systems. If you bought the paid plan, what RevenueCat holds about your purchases is deleted too; the app store keeps its own record of the payment, under its own privacy policy. Some of your data survives in a form that no longer identifies you:

  • Consent records are anonymised rather than deleted, because we have to be able to show that consent was properly obtained. They are kept for five years and then removed.
  • Foods you contributed to the shared catalog stay in the catalog as factual product data, with no link to you; the note that you sent them is deleted.
  • Backups are overwritten on our provider's normal cycle, so deleted data may persist in a backup for a short period afterwards.

If you leave the community but keep your account, your posts, comments, cheers and follows are deleted, and your username is freed. Where we have hidden or deleted something of yours, or removed you from the community, we keep the record of that decision and the excerpt it was about for as long as we could be asked to account for it, because the law that requires us to give you reasons also requires us to be able to show them.

Ranks are replaced each time they are worked out again, so only the current ones are kept.

Reports are kept while they are open and for one year after they are resolved, so that the same content is not reviewed again from scratch and so that a pattern of abuse can be seen, and are then deleted.

AI estimate counts. Rows counting the paid plan's daily allowance are deleted after two days, once they can no longer affect the count.

Your first week is kept while your account exists, so that it is given only once, and is deleted with your account.

Label read counts, and the counts of catalog products, fixes and searches, are deleted after two days, once they can no longer affect the count.

Searches that found nothing are deleted after 90 days if they were seen only once, and 180 days after we have dealt with them otherwise.

Products you send to the shared catalog: the note that you sent one is kept while your account exists and deleted with it.

Bug reports are kept until the problem is dealt with, and then for one year, so we can tell if it comes back, and are then deleted.

Technical logs are kept for as long as our hosting provider retains them, which is a matter of days to weeks.

Meal and label photos sent to the AI service are not stored by us at all.

9. Your rights

You can exercise all of these free of charge, and we will respond within one month.

See your data (Art. 15)

How
Everything is visible in the app. "Export my data" in Settings gives you a machine-readable copy of all of it.

Correct it (Art. 16)

How
Edit any entry in the app, or contact us.

Delete it (Art. 17)

How
"Delete account" in Settings erases your account and data permanently. Individual entries can be deleted as you go.

Take it elsewhere (Art. 20)

How
The export is structured data you can move to another service.

Withdraw consent (Art. 7(3))

How
Each consent can be withdrawn on its own in Settings, as easily as it was given.

Restrict or object (Arts. 18, 21)

How
Contact us at contact@palpo.fit.

None of these require you to email us except restriction and objection — the rest you can do yourself, immediately, in the app.

Complaints. If you think we have handled your data wrongly, please tell us first. You also have the right to complain to a data protection authority: ours is the Belgian Data Protection Authority (www.dataprotectionauthority.be), and you may instead complain to the authority in the EU country where you live or work.

10. Children

The app is not intended for children. You must be at least 16 to use it, or 18 in the United States (and its territories), India, South Africa, Nigeria, Kenya and Mexico. We check this with the date of birth you give when you sign up; if it is below the minimum, the account is not created and what you entered is deleted. An account that has not been through this check is asked once, and is deleted with its data if it is below the minimum. We do not offer accounts with a parent's consent.

We do not knowingly collect data from anyone below the minimum age. If you believe someone below it has an account, contact contact@palpo.fit and we will delete it.

11. Security

Your data is isolated per account at the database level: every table enforces row-level security so one account's rows cannot be read by another, and our public API keys grant no access to anyone's data without a valid session. Your session token is held in your device's secure storage, not in ordinary app storage. Traffic is encrypted in transit, and our provider encrypts data at rest.

No system is perfectly secure. If a breach affects your data and puts you at risk, we will tell you and the supervisory authority as the law requires.

12. Changes to this policy

If we change this policy in a way that affects you, we will ask you to review it in the app before you carry on, and we record which version you agreed to. Minor corrections we will simply publish, with the date at the top updated.

The current version is always at https://palpo.fit/privacy.

13. Our website and cookies

You can read about Palpo, and read this policy, on our website without an account. Cloudflare hosts the website and protects it. This is what a visit involves.

What any visit reveals. Your browser sends what every website receives: your IP address, the page you asked for, the page that linked you there, and your browser and device type. Cloudflare uses this to deliver the page and to block attacks, and keeps it in its logs for a limited time.

Visit statistics. We use Cloudflare Web Analytics to count page views and to measure how quickly pages load, so we can see which pages are read and fix slow ones. It runs a small script in your browser that sends Cloudflare the page's address, your browser and system type, and how quickly the page loaded. It sets no cookie, stores nothing on your device, and does not recognise you from one visit to the next or across other websites. We see only totals, such as views per page or per country, never individual visitors.

Cookies. The website sets no advertising, analytics or tracking cookies. Cloudflare's protection against automated traffic on the website can set one cookie, cf_clearance, which records that your browser passed its check so it is not checked again on every page. It lasts up to a year and is used for nothing else. When Cloudflare suspects automated traffic it can also set __cf_bm, which lasts 30 minutes. These cookies are strictly necessary to keep the website secure, so they do not need your consent. You can delete them in your browser at any time; the website then simply checks again.

Legal basis. Our legitimate interest in running a secure website and knowing how it is used (Art. 6(1)(f) GDPR).

Where. Cloudflare is a United States company with data centres around the world, and a visit is usually handled by the one nearest to you, which can be outside the EU. Transfers to the United States are covered by Cloudflare's certification under the EU-U.S. Data Privacy Framework, and by the European Commission's Standard Contractual Clauses in Cloudflare's data processing terms, under which it acts only on our instructions.

PalpoFood and training in one calm log.

App

FeaturesProQuestionsGet the app

Legal

Privacy policyHealth and AICookiesDelete your account

Contact

contact@palpo.fit

Palpo is not a medical device and does not diagnose, treat, cure or prevent any medical condition. Talk to a healthcare professional about your health.

Jelle Caekebeke · © 2026 Palpo