Privacy Policy
What we hold, and how to take it back
A fitness app asks for more than most: what you eat, what you weigh, how you slept, and sometimes photographs of your own body. This page says plainly what Exeriva stores, who else ever sees it, and how to delete all of it.
The short version
- Your data is yours. We don't sell it, rent it, or share it with advertisers or data brokers.
- There is no advertising in Exeriva, no advertising identifier is read, and nothing tracks you across other apps or websites.
- No other user sees what you log unless you choose to work with a coach — and then only the categories you switch on. The small team that runs Exeriva can see account data to support you; that is explained below rather than buried.
- A photo or a voice recording you choose to use for food logging is sent to a third-party AI service to recognise the food — only after you've agreed to it in the app. Nothing else is.
- You can delete your account and everything in it from inside the app, at any time.
What we collect
Your account
Your email address, your name, and a password. The password is stored only as a secure hash — nobody at Exeriva can read it. Optionally, a profile picture.
What you tell the app about yourself
Age, sex, height, weight, activity level and goal, plus the calorie and macro targets worked out from them. This is what makes the numbers yours rather than generic.
What you log
Meals and the foods in them, foods and meals you save or star, water, sleep, workouts set by set, body weight and measurements, and medications with their doses and reminders. Each entry keeps the time it was logged, because a log without a time is not much of a log.
Photos
All optional: a profile picture, progress photos if you keep them, and a meal photo if you attach one to a meal. Photos are stored privately and are visible only to you — and to a coach, if you have turned on photo sharing with them.
Apple Health and Health Connect
If you connect Apple Health (on iPhone) or Health Connect (on Android), Exeriva reads steps, walking and running distance, active energy, heart rate, resting heart rate and sleep. It never writes anything back. Daily totals are saved to your account so you can see them in the app on any device, including the web.
Health data is used only to show you your own figures. It is never used for advertising or marketing, never sold, never shared with a coach, and never sent to an AI service. You can disconnect at any time in your phone's Health settings.
Coaching, if you use it
Messages between you and your coach, your check-in answers, and any plans or targets they propose. A coach can also keep private notes about their work with you.
Notifications
If you allow notifications, a device token that lets us deliver them to your phone, plus the notifications themselves in your in-app inbox.
Messages to us
If you use Report a problem or email us, what you write, the app version you were using, and our reply.
How the app is used
When you sign in or open the app, and which screens you visit, recorded against your account together with the device type, the IP address of the request, and the approximate location it implies — country and region, never your precise location. When something fails, we record the error with the same details. We use this to see which parts of the app are used and which are broken, and to spot sign-ins that don't look like you. It is kept by us and not shared with any analytics or advertising company.
Photos and voice sent to an AI service
Two features use a third-party AI service to recognise food, and both run only when you use them:
- Photo logging (AI Cam) sends the picture you take or choose.
- Voice logging sends the recording of what you said, or the description you type instead.
The app asks before the first time either one sends anything, and does nothing until you agree. Your answer is saved to your account, and you can withdraw it at any time under Settings → AI food recognition; after that, we ask again before sending anything.
The service reads the photo or recording, sends back a list of foods and amounts for you to review, and that is all it is used for. We don't keep voice recordings at all, and a photo is kept only if you save it with the meal. The AI providers we use process this content under terms that don't permit them to use it to train their models; they may hold it briefly for security and abuse monitoring before deleting it.
Nothing else you log — not your weight, your health data, your progress photos or your messages — is ever sent to an AI service. If you'd rather nothing left your device this way, search, scan a barcode or type instead: every part of the food diary works without photo or voice logging.
Who else processes it
We rely on a small number of service providers to run Exeriva, each only for its part:
- Hosting and database providers store your account and everything in it and run the app's servers.
- Email delivery sends sign-up codes and password resets to your address.
- Push notification services — Apple's and Google's — deliver notifications to your phone.
- AI services recognise food in photos and voice recordings, as above.
- Public food databases answer food searches and barcode scans. They receive the search term or barcode — never your name, email or account.
Each provider processes data only to do that job for us, under contract, and not for their own purposes. There is no analytics vendor, no advertising network and no data broker. Our providers are based in North America, so your data is processed in the United States and Canada, wherever you use the app.
Who at Exeriva can see it
We can. Exeriva is run by a small team, and an administrator can open an account and see what is in it — profile and targets, meals, workouts, weights, progress photos, and messages with a coach. We would rather say that plainly than let you assume otherwise.
It exists so the app can be supported and fixed: answering "my calories look wrong", finding out why a photo failed to upload, tracking down a bug that only shows on real data. Administrator access is limited to named team members, and every time an administrator opens someone's account it is recorded. We don't browse accounts out of curiosity, and we don't use what we see for anything you haven't asked for.
Sharing with a coach
Coaching is opt-in on both sides. A coach invites you, and nothing is shared until you accept. You then choose what they can see — nutrition, workouts, weight, measurements, sleep and progress photos — one category at a time. Photos start switched off. You can turn any category off later and it takes effect straight away; removing a coach ends their access to everything at once.
A coach can never edit your diary. A plan or target they propose stays a proposal until you accept it. Coaches never see your Apple Health or Health Connect data.
How long we keep it
Everything in your account — what you log, your photos, messages and usage records — is kept for as long as your account exists, so your history is there when you come back to it. You can delete any single entry or photo at any time. When you delete your account, all of it goes, as described next.
Copies in our providers' backups expire on a rolling schedule, within 30 days. Messages you've sent us are kept until they're resolved and then for as long as they're useful for fixing the problem they describe.
Deleting your account
In the app: Profile → Settings → Delete account, then type DELETE to confirm. It works the same on the web. It happens immediately, and you don't need to email us or wait for anyone.
It removes your account and everything belonging to it: your profile, everything you've logged, saved foods and meals, health data, coaching links, messages, check-ins, notifications, usage records, and every photo you've uploaded. If you worked with a coach, your link to them is removed and they lose access to all of it.
One thing stays: if you added a product's nutrition label after scanning a barcode we didn't recognise, that label stays in the shared barcode list for everyone else who scans it. It's no longer linked to you.
It cannot be undone. If you can't sign in, email us from the address on the account and we'll delete it for you.
Keeping it safe
All traffic between the app and our servers is encrypted. Every request is checked against the account making it, so one account can never reach another's data, and photos are never publicly reachable. No system is perfect, and it would be dishonest to claim otherwise — if you find something wrong, please tell us and we'll fix it. If a breach ever affected your data, we would tell you.
Children
Exeriva is for people aged 13 and over. If you're under the age at which you can agree to this yourself where you live, a parent or guardian needs to agree for you. We don't knowingly collect data from children under 13 — if you believe a child's account exists, write to us and we'll delete it.
Your rights
You can see and correct almost everything we hold about you directly in the app, and delete all of it as described above. You can also ask us for a copy of your data, to correct or delete anything, or to stop or restrict a particular use of it. Depending on where you live — including the UK, the EU, Australia, Canada and California — these are your legal rights, and you may complain to your local data protection authority. Write to us and we'll respond within 30 days.
We handle your data to provide the service you've signed up for, with your consent where you give it (such as connecting Apple Health or using photo logging), and for our legitimate interest in keeping the app secure and working.
Changes
If this policy changes in a way that affects what we collect or who sees it, we'll tell you in the app before it takes effect, rather than quietly changing the date at the top of this page.
Contact
Questions, requests, or anything that looks wrong: support@exeriva.com. More help is on the support page.