STRICS IT GmbH
Privacy Policy
Version 2.3 - Effective July 26, 2026
This policy explains how STRICS IT GmbH processes personal data through strics.at, our iOS and iPadOS apps, and their supporting cloud services. Product-specific notices may supplement this policy where an app uses additional data or providers. The details below cover myInsurances policy documents and AI Chat, 99Fit fitness, meal, ranking and Pro AI features, and advertising in Fridgtain.
Controller and contact
The controller is STRICS IT GmbH, Florian-Gmainer-Strasse 4, 4240 Freistadt, Austria. For privacy requests, data export, deletion or support, contact hello@strics.at.
This policy covers data processed by us. Apple, Google, OpenAI, Vercel and other providers also process data under their own privacy terms when you use their services.
App accounts, security and technical data
Some STRICS apps, including 99Fit, use Firebase Anonymous Authentication. Firebase creates a random account identifier without requiring your name, email address or password. This identifier links cloud requests and records to one installation or account unless an app separately offers an identified sign-in method.
Firebase App Check and Apple App Attest may process device-attestation assertions to distinguish genuine app requests from automated abuse. Backend infrastructure can receive the account identifier, IP address, request time, endpoint, app and operating-system version, user agent, response status, duration and limited error details. Firestore, Cloud Functions and Google Cloud operational logs process the data needed to deliver, secure, rate-limit and troubleshoot cloud features.
99Fit does not use an advertising identifier or sell personal data for advertising. We use security and operational data to prevent fraud, enforce fair-use limits, investigate failures and control service costs.
myInsurances local policy library
myInsurances stores imported insurance-policy PDF files, extracted policy text, insurer and policy names, policy types, premiums, status and extracted contact details in the app's local container on your iPhone. Text extraction, search, policy organization and supported Apple Intelligence suggestions take place on the device. STRICS, Google and OpenAI do not receive the complete PDF files, and the app does not upload the policy library to Firebase Storage or Firestore.
This local policy information can contain personal, financial, health or other sensitive insurance information. You control which PDFs are imported, can edit generated metadata, and can delete or mark policies inactive in the app. Removing the app also removes its local container, subject to Apple's device and backup behavior.
myInsurances AI Chat permission and data sharing
Insurance Chat does not send policy or conversation data until you are shown a dedicated permission screen and tap Allow and Continue. If you choose Not Now, the local policy collection remains available and no Chat data is transmitted. The permission choice is stored on the iPhone, and data is sent only when you submit a Chat question.
For each submitted question, myInsurances sends the current question, up to 10 recent Chat messages, and up to 20 relevant passages selected from active policies. Each passage can include extracted policy text, insurer and policy names, policy types and page numbers. Extracted phone numbers, email addresses or websites can also be included when contact options may help answer the request. This submitted content may contain personal or sensitive insurance information.
The data is sent over encrypted HTTPS to a Google Firebase Cloud Function operated by STRICS IT GmbH. The function forwards the submitted data to the OpenAI API solely to generate the requested insurance answer, source references and relevant contact actions. OpenAI requests use store: false. Google Firebase and OpenAI are the recipients of this data and may process or temporarily retain limited request or security data as required to deliver, secure and monitor their services under their applicable business terms.
STRICS does not save Insurance Chat request content in Firebase Storage or Firestore. Operational logs may contain limited technical request information needed for delivery, security, abuse prevention, rate limiting and troubleshooting, but are not intended to contain the complete submitted policy passages. We require Google and OpenAI to apply privacy and security safeguards that are the same as or equivalent to the protections described in this policy. Processing can occur outside Austria or the EEA under the transfer safeguards described below.
Health, fitness and on-device data
If you grant permission, 99Fit can read selected HealthKit data such as active energy, walking distance, body mass, height and health profile details, and can write body-mass or workout records that you deliberately save. Apple controls HealthKit permissions, and you can change them at any time in the Health app or system settings.
Your complete HealthKit database is not uploaded to STRICS. Health and fitness values stay on your device unless a value is deliberately sent for a feature you invoke or enable, such as submitting a burned-calorie total to a rank. We do not use HealthKit data for advertising, data brokerage or unrelated profiling.
Meals, workouts, goals, fasting settings, progress and app preferences are primarily stored on your device using Apple platform storage. Selected summaries may be shared with the app's widgets through its private app group. Removing the app or its local data can remove information that has not been written to HealthKit or synchronized to a cloud feature.
99Fit meal text, photos and Pro AI
99Fit's manual meal logging, saved-food search and core tracking do not require an AI request. When you actively request a new Pro estimate from meal text, a recipe or a food photo, the app sends the submitted content and necessary language or request context through an authenticated Firebase Cloud Function. A matching cache or food record may answer the request without contacting an AI provider.
When a new estimate or optional template enrichment requires AI, the backend sends the meal text, recipe details or prepared image to the OpenAI API to generate estimated foods, portions, calories and macronutrients. A photo may be resized or compressed before upload. Do not submit images or text containing personal, confidential or third-party information that is not needed for the estimate.
AI nutrition results are estimates and may be wrong or incomplete. They are not medical, nutritional or other professional advice. Review and correct the result before saving it, especially where health conditions, allergies or professional treatment are involved.
Saved foods, shared templates and thumbnails
A food, product, recipe or meal template that you save may be synchronized to a shared Firestore catalog so it can be searched and reused. A record can include its normalized name, language, calories, protein, carbohydrates, fat, portions, units, ingredients, category, source and quality or moderation metadata. Do not put names, faces, addresses or other personal information into a shared template.
If you attach an image, 99Fit can remove its background on your device and upload a small foreground thumbnail with the template. The original full-resolution meal photo is not stored as the shared catalog thumbnail. Other users may see shared template information and its thumbnail in search results.
Incomplete templates can be stored with the information you supplied. Optional AI enrichment is performed only when a verified Pro entitlement is available; otherwise the record is saved without AI filling missing fields.
Subscriptions and entitlement verification
Apple processes App Store payments. We do not receive your complete payment-card details. StoreKit provides product, transaction, renewal, expiration, refund and revocation information needed to determine whether a paid feature is active.
For 99Fit, the app sends a signed StoreKit transaction (JWS) with requests that may perform paid AI estimation or optional AI enrichment. Our backend and Apple's verification services use it to validate the Pro entitlement, prevent access fraud and apply subscription limits. The credential can contain transaction, product, purchase, expiration and revocation information associated with the app purchase.
Pseudonymous ranks
If ranks are enabled, 99Fit sends the relevant burned-calorie total, ranking window and limited locale or update context to the backend. The public ranking record uses a domain-separated hash derived from the anonymous Firebase identifier rather than your name, email address or raw account identifier.
Other users receive rank positions, participant counts and comparable aggregate values, not your identity or HealthKit history. Rate limits and plausibility bounds are used to reduce manipulation and excessive background updates.
Fridgtain advertising and consent
The free version of Fridgtain uses the Google Mobile Ads SDK (AdMob) to display banner advertising. An active Fridgtain Pro subscription removes these ads. After any required Google consent message, Fridgtain may request App Tracking Transparency permission. The advertising identifier is available to Google only if you grant that system permission.
Before requesting ads, Google's User Messaging Platform may show a privacy message where required. You can consent, decline, or manage individual options. When a privacy-options entry point is required, you can revisit or withdraw your choice from Privacy Choices in Fridgtain Settings. If you decline Google consent or Apple tracking permission, Google may serve non-personalized or limited ads where available.
Google Mobile Ads may process an IP address to estimate general location, non-user-related crash logs, user-associated performance data, device or app identifiers, advertising data such as ads shown, and product interactions such as app launches, taps or video views. Google may use this information for ad delivery, advertising and analytics, fraud prevention, diagnostics and service performance under its applicable terms and privacy information.
Website data and analytics
When you visit strics.at, the hosting and delivery infrastructure receives ordinary connection data such as IP address, date and time, requested page, referrer, browser, device and response information. The site uses Vercel hosting and Vercel Analytics to understand aggregate page usage and maintain reliability.
The website may store technically necessary language, session or preference information in local storage or cookies. Embedded or linked third-party content is governed by the third party's own policy when you choose to load or visit it.
Purposes and legal bases
We process app account, feature, subscription and submitted-content data to perform our contract with you and provide the functions you request under Article 6(1)(b) GDPR. We process proportionate security, diagnostics, fraud-prevention, ranking-integrity and cost-control data for our legitimate interests in a secure and reliable service under Article 6(1)(f) GDPR.
Where consent is required, including device permissions or optional processing, we rely on Article 6(1)(a) GDPR and applicable local law. You may withdraw consent through the app, system permission controls or by contacting us, although the affected feature may stop working. Billing, accounting and legally required records are processed under Article 6(1)(c) GDPR.
Providers and international transfers
We use Apple for app distribution, StoreKit and HealthKit platform services; Google Firebase and Google Cloud for authentication, App Check, Firestore, Cloud Functions and operational infrastructure; OpenAI for requested AI estimates and enrichment; and Vercel for website hosting and analytics. A product-specific notice may identify additional providers.
Providers process data under their applicable agreements and data-protection commitments. Processing may occur outside Austria or the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses or another lawful safeguard. You may contact us for more information about applicable safeguards.
Retention and deletion
On-device records remain until you delete them, reset the app or remove its local data, subject to records separately written to HealthKit. Cloud account and feature records remain while needed to provide the service and are then deleted, anonymized or aggregated, unless security, accounting, dispute or legal obligations require longer retention.
AI request results, cache records, entitlement checks, rate-limit records and technical logs are retained only for the period reasonably needed for delivery, abuse prevention, troubleshooting and legal compliance, subject to provider retention. Short-lived rank records are replaced or expire with their ranking window. Shared food templates may remain as a de-identified catalog contribution where other users rely on them; identifying links are removed or the record is deleted where required by law or a valid request.
You can request export or deletion at hello@strics.at. Because an anonymous app account may not contain an email address, we may ask for the in-app account identifier or another verification step to locate the correct records. Deleting app data does not cancel an Apple subscription; subscriptions are managed in the Apple Account settings used for purchase.
Security
We use measures appropriate to the service, including encrypted transport, platform key storage, Firebase security rules, access controls, signed entitlement verification, App Check, request validation, quotas and rate limits. Access is limited to people and providers that need it for operation, support, security or legal duties.
No storage or transmission method is completely secure. If we identify a personal-data breach, we will assess and notify affected people and authorities where required by law.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also request a copy of data associated with your app account. Contact hello@strics.at. We may need to verify that the request concerns your account or device before acting.
You may lodge a complaint with the Austrian Data Protection Authority at dsb.gv.at or with the supervisory authority where you live or work. Mandatory rights are not limited by this policy.
Children and policy changes
Our apps and cloud services are not directed to children under 13. Where local law requires parental consent at a higher age, a parent or legal guardian must provide it before the child uses the relevant service. Contact us if you believe a child submitted personal data without the required authorization.
We may update this policy when our apps, providers or legal obligations change. The current version and effective date will remain available at strics.at/privacy. Material changes will be presented in the app or through another appropriate notice where required.