Version 2026-09-09 · Last updated 9 September 2026
Samuel Zeidan, Gothenburg, Sweden. Contact: support@solutionsbyzeidan.se. The data controller is responsible for the processing of your personal data in Fitzli. The full postal address is available on request and is listed in the App Store under trader information.
| Category | Examples | Why |
|---|---|---|
| Account details | Email address. No password. You sign in with a one-time code sent to your inbox. | Create and protect your account |
| Profile | Sex, year of birth, height, weight, goals, activity level, and a profile picture if you add one | Calculate calorie and nutrition targets |
| Health data | Allergies, intolerances, diagnoses, weight history, sleep, hunger | Tailor your nutrition and training plan |
| Meal logs | Meal descriptions and nutritional values. If you photograph a meal the image is sent for analysis and then discarded, and we never store it | Track your intake against the plan |
| Apple Health | Steps, active energy, sleep, resting heart rate, heart rate variability (HRV), weight, blood pressure | Track movement and recovery, only if you connect Health |
| Workout logs | Exercises, weights, repetitions, session duration | Track your training and progress |
| Subscription | Status, plan type (monthly/yearly), period end date, and a purchase id from Apple, Google or Paddle depending on where you bought | Give you access to what you paid for |
| Technical data | Server logs with timestamp, path and user id | Operation, troubleshooting and security |
The app uses AI to generate nutrition and training plans, interpret meal photos and provide insights. For this to work, certain data is sent to sub-processors:
| Recipient | What is sent | Purpose |
|---|---|---|
| Anthropic | Meal descriptions and photos, allergies, diagnoses, weight history, hunger, plan adherence, calorie targets. If you have connected Apple Health, also a summary of the past week (see section 5). | Generate plans, interpret meals, provide insights |
| Unsplash | Search text for recipe images | Fetch an image for a recipe |
| Resend | Email address | Send login codes and account email |
| Apple | In-app purchases. We get back that a subscription exists, its type and end date, never who you are at Apple. | Payment, invoicing and VAT for purchases in the iPhone app |
| In-app purchases. We get back that a subscription exists, its type and end date, never who you are at Google. | Payment, invoicing and VAT for purchases in the Android app | |
| RevenueCat | Your user id with us, plus the purchase events from Apple or Google | Link a store purchase to the right account with us |
| Paddle | Email address and your user id (as a reference). Subscription status is sent back to us. | Payment, invoicing and VAT for purchases on the web |
| Fly.io | All stored data (server operation) | Hosting |
| Cloudflare | Traffic to the web app | Hosting of the app |
Your name, your email address and your user id are not sent to Anthropic or Unsplash. The content is, however, linked to you in our database and therefore counts as personal data.
The AI-generated suggestions are not medical advice. See the terms of service.
If you report AI content. In the app you can report a suggestion you find offensive, unsafe or wrong. We then store which surface it concerned, the reason you chose, any comment you wrote and a reference to the content you pointed at. For coaching text, which is not stored anywhere else, the text itself is stored. Your meal photo never accompanies a report. Reports are used to assess and adjust what the model is allowed to produce, and are kept for as long as that requires.
If you choose to connect Apple Health, Fitzli reads the following categories from Health on your iPhone: steps, active energy, sleep, resting heart rate, heart rate variability (HRV), weight and blood pressure. We only read. Fitzli never writes anything to Health.
The connection is optional and the app works without it. You decide in iOS which categories to share, and can remove access at any time under Settings → Privacy & Security → Health → Fitzli. No new data is read after that.
The values are stored on our server in Stockholm and linked to your account. When your insights and plans are generated, a summary of the past seven days is sent to Anthropic: latest weight, averages for resting heart rate, HRV, steps, active energy and sleep, plus the latest blood pressure reading. Individual measurements, your name and your email address are not sent there.
Data from Health is never used for marketing, advertising or other use-based data mining. It is not sold on and not shared with data brokers, employers or insurers. It is used solely to give you nutrition and training advice in the app.
If you delete your account, the health data is removed along with the rest of your data. What sits in Health on your iPhone we do not touch. That belongs to you and to Apple.
This section applies to iPhone only. The Android app reads no health data from the phone at all, not from Health Connect and not from any other source. The only thing we know about your health there is what you enter in the app yourself.
Payment takes different routes depending on where you buy, and that determines who handles your data.
Purchases in the iPhone app go through Apple's In-App Purchase. Apple is the seller and an independent data controller for the payment, and processes it under its own privacy policy. We never learn who you are at Apple, only that a purchase was made for a given account with us.
Purchases in the Android app go through Google Play Billing. Google is the seller and an independent data controller for the payment, and processes it under its own privacy policy. As with Apple, we never learn who you are at Google, only that a purchase was made for a given account with us.
Purchases on the web are handled by Paddle.com Market Ltd, the Merchant of Record. Paddle is likewise an independent data controller for the payment data: they need it for accounting, VAT and fraud checks.
We never see your card details. Card number, expiry date and CVC are handled solely by Apple, Google or Paddle and their payment providers, and are never stored by us. What we receive is that a subscription exists, which type it is and when the period ends.
RevenueCat sits between the store and us for in-app purchases. They receive your user id with us and the purchase events from Apple or Google, and tell our server that the subscription changed. RevenueCat is our data processor, that is, they process the data on our behalf.
For web purchases your user id is sent to Paddle so the payment can be linked to the right account, and your email address is used by Paddle to send a receipt.
Some of our sub-processors are established outside the EU/EEA. This means that data may be processed in countries that lack an adequacy decision from the European Commission.
| Recipient | Country | Safeguard |
|---|---|---|
| Anthropic | USA | Standard Contractual Clauses (SCC) |
| Unsplash | USA/Canada | Standard Contractual Clauses (SCC) |
| Cloudflare | USA | Standard Contractual Clauses (SCC) |
| RevenueCat | United States | Standard Contractual Clauses (SCC) |
| United States | Standard Contractual Clauses (SCC) | |
| Paddle | United Kingdom | European Commission adequacy decision |
| Resend | USA | Standard Contractual Clauses (SCC) |
Server operation is within the EU: the database and the API run in Stockholm.
Contact support@solutionsbyzeidan.se to exercise your rights. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
The app has no passwords. You sign in with a one-time code sent to your inbox, and the code is stored hashed, never in plain text. All traffic uses HTTPS. Access to the API requires authentication, and attempts are rate limited to counter guessing.
For material changes, the version number at the top is updated and you are informed in the app. We record which version you accepted.