Legal
AIFormNote Privacy Policy
AIFormNote is a fitness, training and nutrition tracking application. AIFormNote is intended only for users aged 18 and over and is not directed to children. AIFormNote is not a medical device and is not intended to diagnose, treat, cure or prevent disease or injury, or to provide pregnancy care. Pregnancy and breastfeeding adjustments in the app are fitness and nutrition estimates only; individualized medical, pregnancy or breastfeeding advice should be obtained from a qualified healthcare professional.
1. Data AIFormNote can process
Depending on the features you use, AIFormNote can process data you enter about your profile, age, height, body weight, optional body-fat estimate, body measurements, goals and preferences, training plans and history, sets, repetitions, load, RIR/RPE, personal records, cardio, calorie and macronutrient targets, food diary, readiness/check-ins, post-workout feedback, progress photos and app settings.
Where you choose to use the relevant nutrition feature, AIFormNote may also process optional user-entered health-related information concerning pregnancy or breastfeeding, including pregnancy trimester, breastfeeding status and months postpartum. These values are used to personalize energy and nutrition estimates and are not used to provide diagnosis, treatment or pregnancy care. Depending on applicable law and the context of processing, pregnancy and breastfeeding information may constitute health data or special-category personal data.
Progress photos are first saved in app-private local storage. AIFormNote uses the system camera flow and does not request persistent camera permission.
AI Food is a Premium feature initiated only by a deliberate user action. You can type a meal description, capture a photo directly through the in-app camera flow, or deliberately choose an existing image from your gallery. A selected image is downscaled and re-encoded before upload so original EXIF metadata is not preserved in the uploaded JPEG. A photo is not sent for AI processing automatically merely because it exists on the device or in the gallery.
2. Two storage modes
Continue without sign-in
AIFormNote is fully usable without an account. Core data remains only in private app storage on that device, including any pregnancy or breastfeeding information you enter. Android automatic app-data backup and device transfer are disabled. Unless you created a manual backup, clearing app data, uninstalling the app or losing the device can make the data unrecoverable.
You can export JSON or explicitly create a complete ZIP backup containing profile, training, nutrition, progress data and progress photos. If entered, pregnancy or breastfeeding information is part of your settings in those user-created backups. AIFormNote does not encrypt that ZIP, so protect it as you would any sensitive health or fitness record.
Continue with Google
Google Identity is optional and is used only to authenticate a stable identity for AIFormNote cloud backup, restore and synchronization. Google sign-in is an identity mechanism; the synchronized app data is stored through private AIFormNote cloud infrastructure rather than in your Google Drive. AIFormNote does not create or handle an AIFormNote password and does not request access to Gmail, contacts, calendar or files in your Google Drive.
The backend verifies the Google ID token and uses the verified Google sub identifier as the account key. AIFormNote does not persist your Google e-mail address, display name or profile picture in its backend database. The one-time ID token is exchanged for an opaque 90-day AIFormNote session; Android encrypts the local token with Android Keystore and the server stores only a hash.
After you confirm connection, the local dataset and progress photos can be copied to private AIFormNote cloud storage on Cloudflare infrastructure. Data stays on the device as well. If entered by you, the synchronized cloud dataset may also contain pregnancy or breastfeeding status and months postpartum as part of your settings and nutrition profile. If local and cloud histories both exist, AIFormNote does not silently erase either side: it recommends merging where possible and requires an explicit choice for genuine conflicts. Disconnecting Google stops synchronization and keeps local data; it does not by itself delete the cloud copy.
2A. Health Connect — read-only and on-device processing
With your explicit permission, AIFormNote can read selected data from Health Connect and display it in local health and progress views. The current integration is read-only (READ). AIFormNote does not write data to Health Connect and does not request write access, background-read access, or extended-history access.
AIFormNote requests read access only to the following eight data types. Each permission is independent, so you may allow only some of them:
- Steps —
READ_STEPS: daily step count and trend. - Sleep —
READ_SLEEP: sleep duration and trend from available sleep records. - Heart rate variability (HRV RMSSD) —
READ_HEART_RATE_VARIABILITY: daily value and trend. - Heart rate —
READ_HEART_RATE: regular heart-rate measurements and relevant aggregated views or trends from available records. This is a separate data type from resting heart rate below. - Resting heart rate —
READ_RESTING_HEART_RATE: daily resting heart rate and trend. - Active calories burned —
READ_ACTIVE_CALORIES_BURNED: daily summary and information related to external activities. - Exercise sessions —
READ_EXERCISE: external activities and their duration. - Distance —
READ_DISTANCE: daily distance and information related to external activities.
AIFormNote requests only Health Connect data needed for its fitness, recovery, readiness and wellness features. Data read from Health Connect is not obtained for advertising or marketing, and AIFormNote does not sell it.
Current on-device processing. Health Connect data used directly by the app is primarily processed on the user's device for the daily health overview, activity and fitness, sleep, recovery, readiness, and training-relevant trends. This does not change the local-cache rules or current app behavior described below.
Optional use for Readiness. After you separately and explicitly enable this option in the app settings, AIFormNote may use selected Health Connect data locally not only for health and progress views, but also as an additional signal for Readiness. This may include comparing sleep duration, HRV and resting heart rate with your personal trend / baseline. Readiness is a fitness and recovery heuristic, not a medical diagnosis, and these signals are supplementary only.
Using Health Connect data for Readiness is optional and can be disabled at any time in the app settings. It requires both the relevant Health Connect permission and separate enablement of Health Connect data for Readiness. The calculation is performed exclusively on the device. These Health Connect data are not sent to the AIFormNote backend, AI Coach or Cloud AI for this feature and are not synchronized through AIFormNote cloud. They also remain excluded from AIFormNote JSON exports and ZIP backups.
Health Connect stays on-device by default; sharing with AI Coach is a separate optional choice. No Health Connect summaries are sent to Online AI Coach without separate explicit opt-in. If your app version supports it and you enable it, selected aggregated or derived values may be transmitted through the secure AIFormNote backend when you send an AI Coach message. The complete raw history, individual samples and source-app or device identifiers are not sent. Health Connect data is not included in ordinary AIFormNote cloud sync, JSON exports or ZIP backups. The separate local Readiness setting remains independent.
Local Health Connect cache
To display information quickly and avoid repeated provider queries, AIFormNote keeps a local cache tied to the current profile. The cache covers at most the most recent 30 calendar days including today and stores daily summaries, source information, and a limited overview of external activities. Raw HRV and resting-heart-rate samples are used only for local calculations in memory and are not persisted in the cache as raw samples. Missing values remain missing; AIFormNote does not replace them with an invented zero.
Health Connect is read only while you are using a relevant app screen; AIFormNote does not run its own background service or background worker for this integration. Before using cached Health Connect values and before making a new provider query, the app checks the permissions that are currently granted.
Revoking access
You can revoke permissions at any time in Android Health Connect settings. If you revoke one or more data types, on the next permission check AIFormNote stops showing the affected values and removes the corresponding entries from its local cache. Other data types that remain permitted can continue to work independently. Uninstalling AIFormNote also removes its local Health Connect cache stored in the app's private storage.
Health data and AI Coach
This is a separate opt-in capability in supported app versions. AI Coach may receive limited summarized health context from Health Connect only when the feature is available in your version, the relevant read permissions are granted, and you separately and explicitly enable sharing those summaries with AI Coach. Without this opt-in, no Health Connect summaries are sent to Online AI Coach.
If this option is available and explicitly enabled, only relevant summaries or derived values needed for a specific fitness/recovery coaching response may be used. Depending on available data and the particular feature, this may include, for example, sleep summaries, sleep duration and quality, HRV and its trend, resting heart rate and its trend, relevant aggregated heart-rate information, activity and movement summaries, personal baselines, deviations from usual values, recovery/readiness information, or other aggregated fitness/wellness metrics that the user explicitly permits. This does not mean that all of these data types are used or transmitted for every request.
Data minimization applies. For this capability, AIFormNote is intended to prefer aggregated, summarized or derived values over a complete history of individual Health Connect records. A complete raw Health Connect history is not intended to be sent automatically to AI Coach. Only the minimum health/fitness context needed for the specific feature and response is used.
After the user explicitly enables this capability, selected aggregated health information may be securely transferred from the device solely to generate an AI Coach response. Any technical or AI processing providers may process it only to provide the AIFormNote feature and under applicable contractual and security safeguards. This data is not sold, is not used for advertising, and is not provided to third parties for their own marketing. Appropriate technical and organizational security measures are used for any such transfer and processing in a manner proportionate to the nature of the data; no electronic transmission or system can be described as absolutely secure.
The purpose of this optional processing is limited to fitness coaching, explaining recovery and readiness, interpreting personal trends, adapting AI Coach responses to relevant health/fitness context, and providing safer and more relevant guidance within a wellness and fitness app. AI Coach is not a substitute for a doctor, a diagnostic tool, or a medical device, and is not intended to diagnose or treat medical conditions.
Use of Health Connect data by AI Coach is optional. The user can disable the relevant AI capability again and can revoke individual Health Connect permissions at any time in Android / Health Connect. Normal use of the basic parts of AIFormNote is not conditioned on sharing health context with AI Coach. For personal data managed by AIFormNote, the existing account and personal-data deletion mechanisms described later in this policy remain available; this section does not create a new deletion method.
This optional integration gives AI Coach context only for generating a response. It adds no Health Connect WRITE permission, does not allow AI Coach to write to Health Connect or modify your records in the app, and AI Coach remains read-only from the app's perspective.
3. AI features and medical safety boundary
Before generative AI coaching is invoked, AIFormNote applies rules intended to block individualized questions about symptoms or pain, injuries, diagnosis or treatment, medication interactions, pregnancy or breastfeeding, laboratory results, eating-disorder content, high-risk drug/PED requests and self-harm or crisis content. Individualized medical questions about pregnancy or breastfeeding are intended to be blocked before a generative model is invoked. Those questions are not intentionally forwarded to a generative model. Automated filters cannot guarantee every risky wording will be recognized.
Supported devices may offer on-device generative AI, which does not send the question or fitness context to the AIFormNote backend.
Cloud AI is optional, disabled by default and can be disabled at any time. If you explicitly enable it, a permitted fitness or wellness question, a short bounded chat history and minimized coaching context may pass through the AIFormNote backend to OpenAI with provider storage disabled. The minimized context can include recent training, active-program information, nutrition, weight/progress, measurements, cardio, readiness/check-in data and post-workout feedback. When Cloud AI is explicitly enabled, the minimized coaching context may also include pregnancy/breastfeeding status and months postpartum where you have entered those values. AIFormNote uses these values only as part of fitness and nutrition context. The user-entered profile name is excluded from the automatically built AI context, but text voluntarily typed in the question is part of the request.
AI Food is available only to entitled Premium users and every analysis is user-initiated. When you deliberately start AI Food, the specific meal description or photo you captured or selected may be sent over HTTPS through the AIFormNote backend to the AI inference provider, OpenAI, for structured food recognition and nutrition-value estimation. A photo is not sent to OpenAI automatically without the user starting AI Food. The AI result is a suggestion only; it may be inaccurate or incomplete, and you can review, edit or discard it before anything is saved.
AI output can be incomplete or wrong and is not a substitute for professional medical care. AIFormNote does not use generative AI to provide diagnosis, treatment, disease prevention or pregnancy care.
Optional AI comparison of progress photos
When you explicitly confirm a progress-photo comparison, AIFormNote sends only the two selected images, their dates, selected views and the app language through its authenticated HTTPS backend on Cloudflare to OpenAI. Before transfer, the images are resized and re-encoded as JPEG without the original EXIF metadata, including location. Selecting or viewing a photo alone does not trigger AI processing. You may decline and continue comparing photos manually.
The comparison feature does not save photo bodies in the AIFormNote backend or its logs. The original local photos and any separately enabled cloud photo backup remain governed by the existing storage and deletion controls. Technical request hashes, authentication and cost records are processed using the existing Coach infrastructure. To avoid a second charged request, the resulting text is available for replay for 24 hours; its cached content is then eligible for cleanup. The photo bodies are not part of this cache.
OpenAI is called with response storage disabled (store:false). This does not mean zero retention: default abuse-monitoring retention can be up to 30 days, with safety or legal exceptions; encrypted prompt-cache state can persist up to 24 hours. Zero Data Retention for this project has not been verified. OpenAI API data is not used to train models by default. See the provider data controls linked below.
The purpose is a cautious visual comparison of the same viewpoint, including differences in lighting, pose and framing. It is not a medical assessment or a reliable measurement of body-fat percentage or muscle mass. Comparison uses your existing shared AI entitlement and allowance. Each new comparison requires confirmation; declining prevents that upload.
4. Online food, exercise, identity and subscription services
- Google Identity processes optional sign-in using standard identity information; AIFormNote requests no Google product-data scopes.
- Open Food Facts may receive food-search queries or barcode values.
- USDA FoodData Central may receive food-search queries through the backend.
- AI Food may send a user-submitted meal description or re-encoded food photo through the AIFormNote backend to OpenAI for structured food recognition; recognized food names can then be matched against AIFormNote food sources.
- RepDB may provide exercise illustration metadata or images.
- Google Play processes subscriptions. AIFormNote does not process full payment-card numbers.
- The backend may receive a Google Play purchase token for entitlement verification and stores a SHA-256 hash rather than the raw token.
Google sign-in and Google Play Billing are separate. Signing in neither starts a subscription nor grants Premium.
5. Website and technical data
The public website is hosted by Netlify, which may process IP address, request time, requested URL and browser or device technical data during delivery. The website uses no first-party analytics or advertising trackers and intentionally sets no marketing cookies. Cloudflare and other infrastructure providers may process network and security metadata needed to deliver and protect backend requests. AIFormNote does not intentionally log Google ID tokens, cloud snapshot bodies, progress-photo bodies or raw AI Food photos.
6. Reporting an AI response
If you select Report response, AIFormNote sends the selected assistant response, source type, category, app version, an anonymous installation ID and an optional note. The full chat history and full fitness or nutrition context are not included.
7. Purposes and legal bases
- Requested app functions, optional Google-authenticated backup and sync, subscription management and user-initiated AI Food analysis: performance of a contract or steps requested by you (GDPR Art. 6(1)(b)).
- Optional Cloud AI coaching: consent (Art. 6(1)(a)); where submitted information is special-category data, explicit consent under Art. 9(2)(a).
- Security, abuse and fraud prevention, rate limiting and secure delivery: legitimate interests (Art. 6(1)(f)).
- Legal obligations: Art. 6(1)(c).
Pregnancy and breastfeeding information may constitute health data or special-category personal data. The explicit-consent statement under Art. 9(2)(a) above applies to the optional Cloud AI consent flow where such information is included in Cloud AI processing. It should not be read as stating that Google sign-in itself, the separate cloud synchronization flow, or AI Food is an Art. 9 explicit-consent flow. Do not use AI Food to submit medical records or individualized medical questions.
Cloud-AI consent can be withdrawn by turning the feature off. Disconnecting Google stops future synchronization but does not itself delete the existing cloud copy; the deletion controls described below are available for that purpose.
8. Recipients and international transfers
Where necessary, data may be processed by Cloudflare, Netlify, Google or Google Play, OpenAI when you use optional Cloud AI or AI Food, Open Food Facts, USDA FoodData Central and RepDB. Applicable transfer safeguards are used where processing involves a transfer outside the EEA. AIFormNote does not sell personal data or use it for advertising.
9. Retention and deletion
Local data remains until you delete it, clear app data or uninstall. Google-linked snapshots/photos remain until replaced or the connected cloud account data is deleted. Superseded snapshot objects are removed after a successful revision update. Authentication challenges expire after 10 minutes; opaque sessions expire after 90 days and expired rows are removed by scheduled cleanup.
Ordinary Cloud-AI questions, built coaching context and generated answers are not intentionally persisted in the D1 application database. Moderation reports are deleted after 180 days. Existing Cloud-AI usage/cost rows and inactive entitlement records may be kept for up to 730 days; active subscription records may remain while needed for the service relationship or legal obligations.
AI Food uses a separate technical usage/cost ledger for budget enforcement, replay protection, rate limiting, abuse prevention and service accounting. Raw meal text and raw photos are not stored in that usage ledger; raw photos are also not stored in the short replay cache. A successful structured result may be cached briefly (currently up to 5 minutes) solely to replay the same request without a second provider call. The current AI Food implementation does not promise a fixed public maximum retention period for its technical usage/cost ledger; those technical records are retained only as long as necessary for the stated operational purposes and applicable legal obligations. If a fixed maximum is introduced, this policy will be updated accordingly.
The in-app Delete all my data action first requests deletion of all data linked to a connected Google identity. If that deletion cannot be confirmed, the app keeps local data and the authenticated retry path instead of reporting a false success. After successful cloud deletion, it removes local profile, training, nutrition, progress and photo data and requests deletion of records linked to the anonymous installation ID. An anonymous-backend deletion failure keeps the installation identifier so that request can be retried.
Public deletion information and a request route are published at the public deletion page. Deleting AIFormNote data does not cancel a Google Play subscription; subscriptions are managed separately in Google Play.
10. User rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent where processing is based on consent. Send requests to milanweinarr@seznam.cz. You may complain to a competent supervisory authority; in the Czech Republic this is the Office for Personal Data Protection.
11. Security
Production endpoints use HTTPS. Google tokens are verified server-side for signature, issuer, audience, timing and nonce. Cloud access requires an opaque session, per-user object keys are derived from the verified identity, writes use revision compare-and-set, and Android automatic app-data backup remains disabled. AI Food validates bounded request sizes and re-encodes photos before upload; API secrets and Google Play service-account credentials stay server-side. No electronic service can guarantee absolute security.
12. Age
AIFormNote is intended only for users aged 18 and over and is not directed to children.
13. Community food catalogue
Under the current product behavior, valid custom foods created by users are automatically shared anonymously with the Community Foods catalogue. The food record is published, not your identity, diary, meal combinations or personal fitness/health context. A shared record may contain product name, brand, valid barcode/GTIN, package quantity, image URL when supplied, nutrition basis (per 100 g or 100 ml), nutrition values and flags distinguishing a known zero from a missing value. Community data is not uploaded to Open Food Facts automatically. The service uses a one-way hash derived from the installation identifier for deduplication, rate limiting and abuse controls; the raw installation identifier is not stored in the community contribution tables.
14. Anonymous backend credential
For server-backed features available without a Google account, the app maintains a random public installation ID and a separate cryptographically random per-installation secret. Sensitive anonymous operations such as backend data deletion require proof of that secret. The backend stores a one-way verifier rather than the secret itself. Legacy installations can establish this credential on their first updated authenticated request.
15. Community food metadata
Your custom food remains available locally even if community publication fails. The linkage between a community contribution and an installation is removed through the relevant installation-data deletion path; an aggregated food record may remain as non-personal catalogue data without a link to a specific user.
16. Community Recipes
Validated AI-generated recipes may be published anonymously in Community Recipes for other users. A community recipe may include its title, ingredients and amounts, method, serving count, preparation time, estimated nutrition, classification tags and technical metadata required for deduplication and moderation. The community catalogue does not publish your identity, original prompt, ingredient photos or personal fitness/health context. Recipes can be reported for inaccurate nutrition, inappropriate content or unusable results. Favorites are selected manually by the user.
17. Voice dictation
The microphone is used only when you start voice dictation. Audio is passed to the Android system speech-recognition service, which converts it to text; AIFormNote does not store the audio itself or send it to the AIFormNote backend. Depending on the device, the system speech-recognition service may process audio online. The recognized text is then handled like typed input for the relevant feature.
18. Changes and contact
This policy may be updated when functionality, providers or data handling changes. The current version is published here.
Milan Weinar, IČO 29921139, Procházkova 172, 336 01 Blovice, Czech Republic · +420 777 420 913 · milanweinarr@seznam.cz