Version: Beta 1.0
Last updated: August 2026
Regulation: EU GDPR — Regulation (EU) 2016/679
1. Data Controller
The data controller responsible for processing your personal data is:
Andrea Giacomo Crucinio
trading as Giacarta Consulting
Via Lomellina, 47 · 20133 Milan (MI) · Italy
Email: inshapecoach2026@gmail.com
VAT number (P.IVA): IT14866870968
If you have any questions about this Privacy Policy or how your data is handled, contact us at the email address above.
2. What Data We Collect
2.1 Account Data
- Name and surname
- Email address
- Sign-in identifier from your chosen provider (Google, Apple, or Microsoft) — authentication is handled by the provider and we never receive or store your password
- Date of birth
- Profile photo (optional)
2.2 Health and Fitness Data
Special Category — Art. 9 GDPR
- Body weight and height
- Body Mass Index (BMI) and body composition estimates
- Physical activity data (workout type, duration, frequency, intensity)
- Steps, calories burned, and exercise history
- Personal fitness goals (weight loss, muscle gain, endurance, etc.)
- Self-reported health conditions relevant to training (e.g. injuries, chronic conditions) — provided voluntarily
- Nutritional data: daily food diary entries, caloric intake, and macronutrient breakdown (proteins, carbohydrates, fats) — entered manually by the user
- Dietary preferences, restrictions, or goals (e.g. target calorie intake, macro targets) — provided voluntarily
2.3 Apple Health / Health Connect Data
Optional — off by default, enabled only from Profile → Health
If you turn on Health synchronisation in your profile, InShape exchanges data with Apple Health (iOS) or Health Connect (Android). Both are on-device system frameworks: they are not our servers, and nothing is sent to us through them.
What we write to Health
- Workouts: activity type, start and end time, per-exercise and per-round segments, distance and elevation where applicable, and the workout title
- Estimated calories burned — only if you leave that option enabled; it is turned off automatically when another wearable already records them
- Meals: energy, protein, carbohydrates, fat, sugars, saturated fat, fibre and sodium, one entry per meal
What we read from Health
- Heart rate and active energy, limited to the time windows of your own workouts, to show measured effort next to our estimate
- Body weight, to keep calorie and energy estimates accurate
- Workouts recorded by other apps or devices, so your training history is complete. Records written by InShape are excluded at source, never re-imported
2.4 Device and Technical Data
- Device type, operating system, and app version
- IP address (collected at login, not stored persistently)
- App usage data and feature interaction logs (for bug fixing and improvement)
- Crash reports and diagnostic information
2.5 Data You Provide Voluntarily
- Messages sent to support
- Feedback and survey responses
- Any content you choose to share within the app (notes, photos, progress logs)
3. Legal Basis for Processing
We process your personal data only when we have a valid legal basis. The basis varies by data type:
| Data Category | Legal Basis | GDPR Reference |
|---|---|---|
| Account data | Performance of a contract | Art. 6(1)(b) |
| Health and fitness data | Explicit consent | Art. 6(1)(a) + Art. 9(2)(a) |
| Technical / device data | Legitimate interest (security, bug fixing) | Art. 6(1)(f) |
| Support communications | Performance of a contract / legitimate interest | Art. 6(1)(b)(f) |
| Analytics and improvement | Legitimate interest (product development) | Art. 6(1)(f) |
Where we rely on legitimate interest, we have assessed that our interest does not override your rights and freedoms. Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. How We Use Your Data
- Service delivery: To create and manage your account, provide personalised workout plans, track your physical activity and nutritional intake, and display your fitness and dietary data.
- Personalisation: To tailor recommendations, goals, and content to your fitness and nutrition profile — including calorie and macronutrient targets based on your goals.
- Product improvement: To analyse how users interact with the app during the beta phase, identify bugs, and improve features.
- Safety and security: To detect and prevent fraudulent activity, unauthorised access, or misuse of the platform.
- Communication: To send you important service notifications, updates to this policy, or responses to your support requests.
- Legal compliance: To comply with applicable laws and regulations.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion, then 30 days |
| Health and fitness data | Until account deletion, then 30 days |
| Technical / device logs | 90 days on a rolling basis |
| Support communications | 2 years from last interaction |
| Crash reports | 90 days |
When the retention period expires, data is permanently deleted or anonymised so it can no longer be linked to you.
6. Sharing Your Data with Third Parties
We do not sell your personal data. We may share it with:
6.1 Service Providers (Processors)
We use trusted third-party providers to operate InShape, including:
- Cloud hosting: Vercel Inc. (Standard Contractual Clauses for any transfer outside the EEA)
- Database & authentication: Supabase
- Push notifications: Google Firebase Cloud Messaging
- Sign-in providers: Google, Apple, and Microsoft (OAuth)
- Analytics / crash reporting: None at this time
- Apple Health / Health Connect: on-device system frameworks, not processors — no data is transmitted to us through them unless you enable cloud sync (see Section 2.3)
All providers are bound by Data Processing Agreements (DPAs) and are only permitted to process your data on our documented instructions.
6.2 Legal Obligations
We may disclose your data if required by law, court order, or governmental authority, or if necessary to protect our legal rights.
6.3 Business Transfers
If InShape is acquired, merged, or its assets are transferred, your data may be transferred as part of that transaction. You will be notified in advance, and your rights under this policy will continue to apply.
7. International Data Transfers
InShape is designed for users in the European Union. If any of our service providers are located outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
You can request information about the specific safeguards in place for any transfer by contacting us at inshapecoach2026@gmail.com.
8. Your Rights Under the GDPR
As a user in the EU, you have the following rights regarding your personal data:
| Right | What It Means |
|---|---|
| Right of access (Art. 15) | You can request a copy of all data we hold about you |
| Right to rectification (Art. 16) | You can ask us to correct inaccurate or incomplete data |
| Right to erasure (Art. 17) | You can ask us to delete your data ("right to be forgotten") |
| Right to restriction (Art. 18) | You can ask us to limit how we process your data |
| Right to data portability (Art. 20) | You can request your data in a machine-readable format |
| Right to object (Art. 21) | You can object to processing based on legitimate interest |
| Right to withdraw consent | You can withdraw consent for sensitive data at any time |
To exercise any of these rights, contact us at inshapecoach2026@gmail.com. We will respond within 30 days. We may need to verify your identity before processing the request.
If you are not satisfied with our response, you have the right to lodge a complaint with your national supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).
9. Data Security
We take the security of your data seriously, particularly given the sensitive nature of health information. Our security measures include:
- Encryption in transit: All data is transmitted over HTTPS/TLS.
- Encryption at rest: Health data is encrypted at the database level.
- Delegated authentication: Sign-in is handled by trusted OAuth providers (Google, Apple, Microsoft); we never store passwords.
- Access controls: Only authorised personnel with a need-to-know basis can access user data.
- Regular security reviews: We conduct periodic assessments of our infrastructure and code.
Despite these measures, no system is completely immune to risk. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by Art. 33–34 GDPR.
10. Children's Privacy
InShape is not intended for users under the age of 16. We do not knowingly collect personal data from minors. If we become aware that a user under 16 has provided us with personal data, we will delete it promptly. If you believe a minor has registered on InShape, please contact us at inshapecoach2026@gmail.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this document
- Notify you via email or in-app notification if changes are material
- In the case of significant changes to how we process sensitive data, request renewed consent where required
12. Contact Us
For any privacy-related questions, requests, or complaints:
Andrea Giacomo Crucinio
trading as Giacarta Consulting
Email: inshapecoach2026@gmail.com
Address: Via Lomellina, 47 · 20133 Milan (MI) · Italy
VAT number (P.IVA): IT14866870968
This Privacy Policy was drafted in compliance with EU Regulation 2016/679 (GDPR). It does not constitute legal advice. Before public launch, InShape recommends legal review by a qualified data protection professional.