99Fit

Privacy Policy

Version 1.0 - Effective July 15, 2026

This policy explains what 99Fit keeps on your device, what is sent to our backend and service providers, how shared caches and food templates work, and how you can export or delete cloud data.

Controller and contact

The controller is STRICS IT GmbH, Florian-Gmainer-Strasse 4, 4240 Freistadt, Austria. For privacy requests or support, contact hello@strics.at.

This policy covers the 99Fit iOS app, its backend services and the 99Fit legal pages. It explains what stays on your device, what is sent to us or our providers, how shared caches and food templates work, and how you can export or delete cloud data.

Data on your device and Apple Health

Meals, recipes, workouts, goals, weight history, settings, estimate caches and small meal thumbnails are primarily stored on your device. The app does not keep the original selected meal photo as an app record.

After you grant access, 99Fit can read active calories, walking distance, workouts, weight, height, date of birth and biological sex from Apple Health. It writes weight or workout data only when you use the corresponding sync feature. You can change Health permissions in iOS Settings at any time.

We do not sell Health data, use it for advertising or share it with data brokers. Active-calorie totals can be sent to the burn rankings described below.

Meal AI and photo processing

When you request an estimate, your food description, recipe ingredients or meal photo is sent with the selected language through our Firebase backend to OpenAI. Before upload, a photo is converted on your device to a JPEG with a maximum dimension of 1024 pixels. Our backend forwards the request for estimation and does not write the uploaded photo itself to its database.

OpenAI processes request content under its applicable API data controls and may retain it temporarily for abuse monitoring or legal requirements. AI output is probabilistic and can be incomplete or wrong, so review calories, macros and serving information before saving.

Separately, Apple Vision performs foreground detection entirely on your device. If it succeeds, 99Fit creates a transparent 180 by 180 pixel thumbnail. The thumbnail can be stored with your local meal and, when a saved food template is synchronised, uploaded with that template. The foreground-cutout operation itself does not send the source photo to us.

Local and shared estimate caches

The on-device cache can store a readable food description or recipe, the structured estimate, language, model, timestamps, reuse count and optional small thumbnail for faster reuse.

The shared cloud cache is not keyed to your account. It stores a one-way hash of the normalised text, recipe or resized image request, mode and language, the structured nutrition result, model metadata, timestamps and reuse count. It does not store the raw food description, recipe or photo. Cache entries expire 30 days after their latest use.

Extracted food names, serving descriptions and nutrition totals can also be stored as shared food knowledge. These records may answer another user's matching request and are not included in account export or deletion because they are not stored with your account identifier. Do not include names, contact details, medical details or other personal information in food descriptions or recipes.

Saved foods and shared templates

Foods and meals saved to your local library are synchronised as structured templates when cloud access is available. The payload can contain a local item identifier and revision, name, kind, source text or ingredients, serving and nutrition values, detected items, meal type, source mode and model, locale and an optional 180-pixel thumbnail. If fields are missing, the structured template can be sent to OpenAI for enrichment.

Templates are linked to the anonymous account through one-way identifier hashes while pending moderation. They are not returned by public search until approved. Approved templates can be reused by other users. Contributions to an already approved template are recorded without replacing its protected public content.

Anonymous account, security and request data

99Fit creates an anonymous Firebase Authentication account. Its identifier and session credentials are held in the device Keychain, and backend records use one-way account or subscription-entitlement hashes where practical. Firebase App Check sends device-attestation tokens to reduce automated abuse.

Requests also expose technical data such as IP address, timestamps, headers and endpoint to Google Cloud infrastructure. IP and account or entitlement hashes are used for short-window rate limits, service security and fraud prevention.

Linked usage and diagnostic data

Operational logs can link a pseudonymous account or subscription-entitlement hash to an event or endpoint, input mode or template kind, cache hit, result count, model, request duration, token counts and estimated AI cost, quota outcome, error type and timestamp. We use this information to operate, secure, troubleshoot and control the cost of the service.

99Fit does not include an advertising SDK, third-party tracking, Firebase Analytics or Firebase Crashlytics. We do not combine this operational data with third-party data for advertising.

StoreKit purchase history

StoreKit provides product and signed App Store transaction information when you buy, restore or use a subscription. The latest verified transaction credential is stored in the device Keychain and sent with protected backend requests.

The backend verifies it and can retain a one-way hash of the original transaction identifier, product, App Store environment, purchase, signature and expiry dates, active, expired, refund or revocation state, and hashed server-notification metadata. The raw signed transaction is not stored in our database. Apple remains responsible for payment information and billing.

Burn rankings

The rolling 24-hour and 30-day rankings receive active calories, rank window, timezone and language. The backend stores a one-way owner hash, a separate rolling participant hash, score and update and expiry times. Rankings do not display your name. Each score is designed to expire after its 24-hour or 30-day window.

Purposes and legal bases

We process data to provide the app and subscription, answer your requests, synchronise templates and verify entitlements under our contract with you; to meet billing, consumer and legal obligations; and for legitimate interests in security, fraud prevention, service reliability and proportionate cost control.

Health data is accessed only with your iOS permission and, where required, explicit consent. You can withdraw Health permission at any time, although affected features will stop working. We do not use these data for advertising or cross-app tracking.

Service providers and international transfers

We use Apple for HealthKit and App Store subscriptions; Google Firebase and Google Cloud for anonymous authentication, App Check, functions, databases and operational logs; OpenAI for meal estimation and template enrichment; and Vercel for these public legal pages.

These providers process data under their applicable terms and data-protection commitments. Processing can occur outside the European Economic Area using applicable safeguards such as adequacy decisions or standard contractual clauses.

Retention

Local data remains until you delete it in the app or remove the app, subject to iOS and backup behaviour. Rank records carry 24-hour or 30-day expiry times. Rate-limit records carry short operational expiry times, while cloud logs are kept for the configured operational retention period.

Pending templates, contribution records and the anonymous account remain until deletion or until no longer needed. Shared caches, structured food knowledge and approved templates may remain while useful because they are shared and not directly account-keyed. Purchase state may be retained as needed for entitlement validation, refunds, fraud prevention, accounting or legal compliance. Data can be retained longer where law, disputes or security require it.

Export and deletion

Profile lets you export cloud contribution, template and rolling-rank records associated with your anonymous account. The export has safety limits, reports if it is truncated and may omit large thumbnail data.

Cloud deletion removes the anonymous Firebase account, contribution records, rank records and pending templates linked to it. Approved shared templates are anonymised and their ownership hashes and thumbnail are removed; non-identifying structured food information may remain.

Cloud deletion does not erase local app data, Apple Health records, Apple purchase history, shared account-independent caches, separately retained operational logs or legally required subscription records, and it does not cancel your subscription. You can delete local entries in the app and manage Health records in Apple Health. If you use cloud features again after deletion, 99Fit may create a new anonymous account.

Your rights, children and policy changes

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection and may withdraw consent. Contact hello@strics.at. You may complain to the Austrian Data Protection Authority or your local supervisory authority.

99Fit is not directed to children under 16. We may update this policy when the app, providers or law changes; the current version and effective date will remain available in the app and online.