Privacy Policy

Beta 1.0

Version: Beta 1.0

Last updated: August 2026

Regulation: EU GDPR — Regulation (EU) 2016/679

Beta notice: InShape is currently in beta testing. This Privacy Policy applies to all beta users. Some features described below may evolve before the public release, and this document will be updated accordingly. Continued use of the app following any update constitutes acceptance of the revised policy.

1. Data Controller

The data controller responsible for processing your personal data is:

Andrea Giacomo Crucinio

trading as Giacarta Consulting

Via Lomellina, 47 · 20133 Milan (MI) · Italy

Email: inshapecoach2026@gmail.com

VAT number (P.IVA): IT14866870968

If you have any questions about this Privacy Policy or how your data is handled, contact us at the email address above.

If the volume or nature of data processing requires it under Art. 37 GDPR, InShape will appoint a Data Protection Officer (DPO). The DPO's contact details will be published here when applicable.

2. What Data We Collect

2.1 Account Data

  • Name and surname
  • Email address
  • Sign-in identifier from your chosen provider (Google, Apple, or Microsoft) — authentication is handled by the provider and we never receive or store your password
  • Date of birth
  • Profile photo (optional)

2.2 Health and Fitness Data

Special Category — Art. 9 GDPR

  • Body weight and height
  • Body Mass Index (BMI) and body composition estimates
  • Physical activity data (workout type, duration, frequency, intensity)
  • Steps, calories burned, and exercise history
  • Personal fitness goals (weight loss, muscle gain, endurance, etc.)
  • Self-reported health conditions relevant to training (e.g. injuries, chronic conditions) — provided voluntarily
  • Nutritional data: daily food diary entries, caloric intake, and macronutrient breakdown (proteins, carbohydrates, fats) — entered manually by the user
  • Dietary preferences, restrictions, or goals (e.g. target calorie intake, macro targets) — provided voluntarily
Health and nutritional data are considered sensitive personal data under Article 9 of the GDPR. We process this data only on the basis of your explicit consent, which you provide when you first set up your InShape profile. You may withdraw this consent at any time (see Section 7).

2.3 Apple Health / Health Connect Data

Optional — off by default, enabled only from Profile → Health

If you turn on Health synchronisation in your profile, InShape exchanges data with Apple Health (iOS) or Health Connect (Android). Both are on-device system frameworks: they are not our servers, and nothing is sent to us through them.

What we write to Health

  • Workouts: activity type, start and end time, per-exercise and per-round segments, distance and elevation where applicable, and the workout title
  • Estimated calories burned — only if you leave that option enabled; it is turned off automatically when another wearable already records them
  • Meals: energy, protein, carbohydrates, fat, sugars, saturated fat, fibre and sodium, one entry per meal

What we read from Health

  • Heart rate and active energy, limited to the time windows of your own workouts, to show measured effort next to our estimate
  • Body weight, to keep calorie and energy estimates accurate
  • Workouts recorded by other apps or devices, so your training history is complete. Records written by InShape are excluded at source, never re-imported
Data read from Apple Health or Health Connect is never used for advertising or marketing, is never sold, rented, or shared with third parties, and stays on your device. It does not reach our servers unless you separately enable “Sync Health data to the cloud” in your profile — a distinct, explicit, and revocable consent. You can withdraw it at any time from that toggle, or revoke our access entirely from the Apple Health / Health Connect settings on your device. Turning Health synchronisation off stops all further exchange; entries already written to Health remain there and can be deleted from the Health app itself.

2.4 Device and Technical Data

  • Device type, operating system, and app version
  • IP address (collected at login, not stored persistently)
  • App usage data and feature interaction logs (for bug fixing and improvement)
  • Crash reports and diagnostic information

2.5 Data You Provide Voluntarily

  • Messages sent to support
  • Feedback and survey responses
  • Any content you choose to share within the app (notes, photos, progress logs)

3. Legal Basis for Processing

We process your personal data only when we have a valid legal basis. The basis varies by data type:

Data CategoryLegal BasisGDPR Reference
Account dataPerformance of a contractArt. 6(1)(b)
Health and fitness dataExplicit consentArt. 6(1)(a) + Art. 9(2)(a)
Technical / device dataLegitimate interest (security, bug fixing)Art. 6(1)(f)
Support communicationsPerformance of a contract / legitimate interestArt. 6(1)(b)(f)
Analytics and improvementLegitimate interest (product development)Art. 6(1)(f)

Where we rely on legitimate interest, we have assessed that our interest does not override your rights and freedoms. Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

4. How We Use Your Data

  • Service delivery: To create and manage your account, provide personalised workout plans, track your physical activity and nutritional intake, and display your fitness and dietary data.
  • Personalisation: To tailor recommendations, goals, and content to your fitness and nutrition profile — including calorie and macronutrient targets based on your goals.
  • Product improvement: To analyse how users interact with the app during the beta phase, identify bugs, and improve features.
  • Safety and security: To detect and prevent fraudulent activity, unauthorised access, or misuse of the platform.
  • Communication: To send you important service notifications, updates to this policy, or responses to your support requests.
  • Legal compliance: To comply with applicable laws and regulations.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.

5. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this policy:

Data TypeRetention Period
Account dataUntil account deletion, then 30 days
Health and fitness dataUntil account deletion, then 30 days
Technical / device logs90 days on a rolling basis
Support communications2 years from last interaction
Crash reports90 days

When the retention period expires, data is permanently deleted or anonymised so it can no longer be linked to you.

6. Sharing Your Data with Third Parties

We do not sell your personal data. We may share it with:

6.1 Service Providers (Processors)

We use trusted third-party providers to operate InShape, including:

  • Cloud hosting: Vercel Inc. (Standard Contractual Clauses for any transfer outside the EEA)
  • Database & authentication: Supabase
  • Push notifications: Google Firebase Cloud Messaging
  • Sign-in providers: Google, Apple, and Microsoft (OAuth)
  • Analytics / crash reporting: None at this time
  • Apple Health / Health Connect: on-device system frameworks, not processors — no data is transmitted to us through them unless you enable cloud sync (see Section 2.3)

All providers are bound by Data Processing Agreements (DPAs) and are only permitted to process your data on our documented instructions.

6.2 Legal Obligations

We may disclose your data if required by law, court order, or governmental authority, or if necessary to protect our legal rights.

6.3 Business Transfers

If InShape is acquired, merged, or its assets are transferred, your data may be transferred as part of that transaction. You will be notified in advance, and your rights under this policy will continue to apply.

7. International Data Transfers

InShape is designed for users in the European Union. If any of our service providers are located outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable

You can request information about the specific safeguards in place for any transfer by contacting us at inshapecoach2026@gmail.com.

8. Your Rights Under the GDPR

As a user in the EU, you have the following rights regarding your personal data:

RightWhat It Means
Right of access (Art. 15)You can request a copy of all data we hold about you
Right to rectification (Art. 16)You can ask us to correct inaccurate or incomplete data
Right to erasure (Art. 17)You can ask us to delete your data ("right to be forgotten")
Right to restriction (Art. 18)You can ask us to limit how we process your data
Right to data portability (Art. 20)You can request your data in a machine-readable format
Right to object (Art. 21)You can object to processing based on legitimate interest
Right to withdraw consentYou can withdraw consent for sensitive data at any time

To exercise any of these rights, contact us at inshapecoach2026@gmail.com. We will respond within 30 days. We may need to verify your identity before processing the request.

If you are not satisfied with our response, you have the right to lodge a complaint with your national supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).

9. Data Security

We take the security of your data seriously, particularly given the sensitive nature of health information. Our security measures include:

  • Encryption in transit: All data is transmitted over HTTPS/TLS.
  • Encryption at rest: Health data is encrypted at the database level.
  • Delegated authentication: Sign-in is handled by trusted OAuth providers (Google, Apple, Microsoft); we never store passwords.
  • Access controls: Only authorised personnel with a need-to-know basis can access user data.
  • Regular security reviews: We conduct periodic assessments of our infrastructure and code.

Despite these measures, no system is completely immune to risk. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by Art. 33–34 GDPR.

10. Children's Privacy

InShape is not intended for users under the age of 16. We do not knowingly collect personal data from minors. If we become aware that a user under 16 has provided us with personal data, we will delete it promptly. If you believe a minor has registered on InShape, please contact us at inshapecoach2026@gmail.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last updated" date at the top of this document
  • Notify you via email or in-app notification if changes are material
  • In the case of significant changes to how we process sensitive data, request renewed consent where required

12. Contact Us

For any privacy-related questions, requests, or complaints:

Andrea Giacomo Crucinio

trading as Giacarta Consulting

Email: inshapecoach2026@gmail.com

Address: Via Lomellina, 47 · 20133 Milan (MI) · Italy

VAT number (P.IVA): IT14866870968

This Privacy Policy was drafted in compliance with EU Regulation 2016/679 (GDPR). It does not constitute legal advice. Before public launch, InShape recommends legal review by a qualified data protection professional.