Privacy Policy
Uppo is a log for your food and training that you talk to or send photos to. This policy explains what Uppo collects, where it goes and what you can do about it.
In short
- Your meals, workouts, body metrics and notes are health-related data. Uppo processes them only with your explicit consent.
- Your log is stored in the EU. Photos, text and voice are processed by Google Gemini to turn them into entries.
- Raw voice audio is not stored. Uppo keeps the transcript.
- Uppo does not sell your data and shows no advertising.
- You can export your data and delete your account at any time.
Who is responsible
The controller of your personal data is [TODO: legal entity name], [TODO: registered address], registration number [TODO: company registration number] (“Uppo”, “we”).
For any privacy question or request, write to [email protected]. [TODO: data protection officer or privacy contact, if one is appointed]
What Uppo collects
Account
You sign in with Apple or with Google. Uppo receives an account identifier from that provider, your email address (with Apple this can be a private relay address) and your name if you choose to share it. Uppo never sees your Apple or Google password.
Your log
- Meals, with the foods, calories and nutrition values estimated for them.
- Workouts, with exercises, sets, repetitions and weights.
- The body metrics and goals you enter during onboarding.
- Notes you write or dictate.
- What Uppo remembers about you, such as goals and preferences. You can see and edit this list in the app.
Photos
Photos you send, for example of a plate or a gym machine, are uploaded and stored so they can appear in your timeline.
Voice
When you talk to Uppo, your audio is streamed from your phone to Google’s Gemini Live service to understand you and to answer. Uppo does not store the raw audio. Uppo stores the transcript of the conversation and the entries created from it.
Messages
Text you type to Uppo and the answers you receive.
Subscription
Your subscription status, the plan and the renewal or expiry dates. Payment is handled by Apple or Google. Uppo does not receive your card details.
Diagnostics and usage
Crash reports and information about how the app is used, such as which screens are opened, together with basic device information like the model, operating system version and app version. If you allow notifications, Uppo also stores a push token for your device.
Support
If you write to us, we keep your email address and the content of the conversation.
Health data and your consent
What you eat, how you train and your body metrics say something about your health. Under the GDPR this is a special category of personal data. Uppo asks for your explicit consent before it processes this data, on a separate screen before you start logging.
You can withdraw your consent at any time by deleting your account or by writing to [email protected]. Uppo cannot keep a log for you without this data, so withdrawing consent ends your use of the logging features. Withdrawal does not affect processing that happened before it.
How Uppo uses your data, and on what basis
- To provide the app: create your account, turn what you say, type or photograph into entries, keep your timeline and answer questions from your own data. Basis: the contract with you, and your explicit consent for health data.
- To manage your subscription: check what your plan includes and apply its limits. Basis: the contract with you.
- To keep the app working and safe: find and fix crashes, prevent abuse and enforce usage limits. Basis: our legitimate interest in a reliable and secure service.
- To understand how the app is used: product analytics. Basis: [TODO: confirm the legal basis for analytics: consent or legitimate interest]
- To answer you: support requests. Basis: our legitimate interest in responding to you.
- To meet legal obligations: for example tax and accounting rules.
Uppo does not use your data for advertising and does not make decisions about you that have legal or similarly significant effects.
How the AI processing works
Uppo uses Google’s Gemini models to understand speech, photos and text. This means the content you send, and the parts of your log needed to answer you, are transmitted to Google for processing.
- Voice: your phone connects directly to Gemini Live for the length of the voice session.
- Photos and text: they are sent to Gemini through Uppo’s server.
- Web answers: when a question needs information from the web, Gemini may run a Google Search for it.
We have not yet confirmed that Gemini processing, and Gemini Live in particular, takes place only inside the EU. You should assume that this data may be processed outside the European Economic Area, including in the United States. See International transfers.
[TODO: confirm from Google's API terms whether content sent to Gemini is used to train Google's models and how long Google retains it, and state both here]
Where your data is stored
- Database: your account, log, transcripts and memory are stored in a database on a server in the EU, hosted by [TODO: hosting provider name and country].
- Photos: stored in Cloudflare R2 object storage with the EU jurisdiction setting, which keeps the stored objects in the EU.
- Backups: the database is backed up daily to separate storage in Cloudflare R2. [TODO: confirm the backup storage jurisdiction]
Who receives your data
Uppo shares personal data only with the service providers needed to run the app. Each of them processes it on our instructions.
- Google (Gemini)
- Processes voice audio, photos and text to understand them and to generate answers.
- Cloudflare
- Stores photos and backups (R2) and carries network traffic between the app and Uppo’s server, which involves IP addresses.
- Hosting provider
- Runs the server and the database in the EU. [TODO: provider name]
- RevenueCat
- Manages subscription status. Receives an app user identifier and purchase information.
- Sentry
- Receives crash and error reports. [TODO: confirm the Sentry data region]
- PostHog
- Product analytics, hosted in the EU.
- Apple and Google
- Sign-in, payments through the App Store or Google Play, and delivery of push notifications. They act as independent controllers under their own privacy policies.
We may also disclose data when the law requires it, or to a successor if the business is transferred, in which case this policy continues to apply to your data.
Uppo does not sell your personal data, does not share it for advertising and shows no ads.
International transfers
Some of these providers are based in the United States or may process data there. Where personal data leaves the European Economic Area, the transfer relies on a safeguard recognised by the GDPR, such as an adequacy decision or the European Commission’s standard contractual clauses.
[TODO: list the transfer mechanism per provider (Google, Cloudflare, RevenueCat, Sentry, PostHog) once the data processing agreements are signed]
How long Uppo keeps your data
- Account and log: for as long as your account exists. You can edit or delete single entries at any time.
- Raw voice audio: not stored by Uppo.
- After you delete your account: live data is deleted within [TODO: deletion period, in days].
- Backups: deleted data remains in backups for up to [TODO: backup retention period, in days], after which the backups are overwritten.
- Crash reports and analytics: [TODO: retention period for Sentry and PostHog data]
- Support emails: [TODO: retention period for support correspondence]
- Records required by law: for example accounting records, for [TODO: legal retention period].
The account deletion page lists exactly what is deleted and what is kept.
Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- correct data that is wrong;
- have your data erased;
- receive your data in a portable format;
- restrict or object to processing that is based on legitimate interest;
- withdraw consent at any time;
- lodge a complaint with a data protection authority.
Two of these are built into the app. You can export your data, and you can delete your account in Settings. Both are described on the support page. For everything else, write to [email protected]. We answer within one month.
You can complain to the data protection authority of the country where you live or work. Our lead authority is [TODO: lead supervisory authority, name and website].
Security
Data is encrypted in transit between the app, Uppo’s server and its providers. Access to the server and the database is restricted to the people who need it to run the service. No system is perfectly secure, and if a breach affects your data we will tell you and the authority as the law requires.
[TODO: confirm the security measures actually in place at launch, including encryption at rest]
Children
Uppo is not intended for anyone under [TODO: minimum age]. We do not knowingly collect data from children below that age. If you believe a child has created an account, write to [email protected] and we will delete it.
This website
uppo.app sets no cookies and runs no analytics or third-party scripts. It is served by Cloudflare, which processes IP addresses and request data to deliver and protect the site.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change is significant, we will tell you in the app before it takes effect, and ask for your consent again where the law requires it.
Contact
[email protected]
[TODO: legal entity name and postal address]