Privacy Policy
Last updated: June 30, 2026
in/out ("we", "us", or "our") operates the in/out: Calorie Companion mobile application. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our app.
1. Information We Collect
We collect the following types of information:
- Account information: Email address and display name when you create an account via email or Google Sign-In.
- Profile data: Age, height, weight, sex, activity level, username, bio, and avatar you provide to calculate calorie goals and BMR and to identify you in social features.
- Health & nutrition data: Food and drink logs, calorie entries, exercise records, weight logs, sleep data, mood entries, water intake, vitamins, and step counts that you manually enter or import.
- User-generated content: Posts, comments, forum messages, shared recipes, challenge entries, and messages you send through community and coaching features.
- Social connections: Follows, accountability pods, challenges, leagues, referrals, and coaching relationships you create.
- Usage data: App interactions, feature usage, and anonymous analytics to improve the app.
- Device & technical information: Device type, operating system version, app version, and a push-notification token, used for crash reporting, support, and delivering notifications you have enabled.
2. How We Use Your Information
- To provide and maintain the app's core features
- To calculate personalized calorie goals, BMR, and nutrition insights
- To power social and community features (feeds, forums, pods, challenges, leagues, referrals)
- To enable coaching relationships and the AI Coach when you choose to use them
- To sync your data across sessions via Supabase (our backend provider)
- To process AI food analysis and AI Coach requests via our secure Edge Function proxy
- To send push notifications and optional email notifications (e.g., reminders and daily briefs) that you can disable at any time
- To improve the app based on aggregated usage patterns
3. Data Storage & Security
Your data is stored securely in Supabase (supabase.com), which provides row-level security and encryption at rest and in transit. We use HTTPS for all network communication. API keys are never exposed to the client — all AI requests are proxied through our secure backend.
Local data is also stored on your device via localStorage and is not shared with third parties.
4. Third-Party Services
- Supabase — database and authentication (supabase.com/privacy)
- Anthropic Claude API — AI food analysis and AI Coach, accessed via our backend proxy only (anthropic.com/privacy)
- Google Sign-In — optional OAuth login (policies.google.com/privacy)
- Firebase Cloud Messaging — push notification delivery (firebase.google.com/support/privacy)
- RevenueCat — in-app purchase management (revenuecat.com/privacy)
- Open Food Facts — barcode food database (openfoodfacts.org/privacy)
- PostHog — anonymous usage analytics (posthog.com/privacy)
- Spoonacular — recipe data (spoonacular.com/food-api/terms)
5. Connected Fitness Services
In/out optionally connects to third-party fitness platforms to import health data directly into your dashboard. You must explicitly authorize each connection via that service's secure OAuth login. The following services may be connected:
- Fitbit (fitbit.com/legal/privacy-policy)
- Strava (strava.com/legal/privacy)
- Withings (withings.com)
- Oura Ring (ouraring.com/privacy-policy)
- WHOOP (whoop.com/privacy-policy)
- Garmin (garmin.com/privacy)
- Samsung Health (samsung.com/privacy)
For each connected service, we collect only the data you explicitly authorize and only the minimum scopes required to display information in your dashboard (steps, heart rate, sleep, weight, and activity summaries). Specifically:
- Data from Fitbit and other connected services is not sold to any third party.
- Data from Fitbit and other connected services is not used for advertising or marketing profiling.
- Data is stored securely in your personal Supabase account and is never shared with other users or external services.
- You may revoke access at any time from Settings → Connected Services → Unlink. Revoking access removes your stored token immediately.
- We comply with each connected platform's API terms of service and developer policies.
6. Social Features & Content Visibility
in/out includes community features such as a public feed, forums, shared recipes, accountability pods, challenges, and leagues. Content you choose to post — including your display name, username, avatar, and the text or recipes you share — may be visible to other users, and public posts may be visible to anyone using the app. Please do not include sensitive personal information in content you post publicly.
You can delete your own posts at any time, and some content (such as the public feed) expires automatically. We may review, moderate, or remove content that violates our Terms & Conditions, and certain content is screened by automated safety filters.
7. Coaching & Data Sharing With Other Users
If you choose to connect with a coach — or act as a coach — you authorize in/out to share a specific, limited set of your data (such as selected logs and progress trends) with that coach so they can provide coaching to you. This sharing is scoped to what you approve and can be ended by removing the coaching relationship. Coaches are independent users, not employees of in/out, and you are responsible for choosing whom you share data with.
The AI Coach feature uses your own logged data (such as recent summaries, weight, and goals) to generate personalized responses through our secure AI proxy. This data is processed to produce your response and is not shared with other users.
8. AI Features & Data
When you use AI features (voice logging, barcode scanning, AI food analysis, or the AI Coach), the text you provide — such as food descriptions, questions, and the relevant context needed to answer them — is sent to the Anthropic Claude API via our secure backend proxy. We do not send your name, email address, or account identifiers to the AI provider. Under Anthropic's commercial terms, this data is not used to train their models. AI responses are estimates and may not be fully accurate.
9. Health Data
If you connect a wearable device or grant health permissions, in/out reads step count, heart rate, weight, and active calories burned from Android Health Connect (read-only — in/out never writes to Health Connect), or equivalent data from connected third-party services. This data is used solely within the app to populate your fitness dashboard and calculate your daily calorie balance, and is never sold or shared with advertisers. You can revoke Health Connect access at any time from your device's Health Connect settings, and deleting your in/out account (Section 11) removes any Health Connect data we've stored.
10. Your Rights & Choices
You have the right to access, correct, export, or delete your personal data. You can edit your profile and most data directly in the app, and you can delete your entire account at any time (see Section 11). We do not sell your personal information. To exercise any of these rights, contact us at inoutsupport@proton.me.
11. Data Retention & Deletion
You may delete your account and all associated data at any time from Settings → Delete Account in the app. Upon deletion, your account and personal data are removed from our live systems immediately and any residual copies in encrypted backups are purged within 30 days. If you cannot access the app, you may request deletion as described on our Delete Your Account page. Disconnecting a fitness service (Settings → Connected Services → Unlink) removes only the stored access token; any data already imported remains in your account until account deletion.
12. Children's Privacy
in/out is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe your child has provided us with personal data, please contact us to have it removed.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, please contact us at: inoutsupport@proton.me