Legal · Privacy
Privacy Policy
This policy explains what PerunForce accesses, collects, stores, uses and shares when you use the app.
Optional contributions to the shared product catalog
A separate, optional consent allows Google Gemini to read the submitted label photos again to assist the admin. Account and diary data is not sent. The private AI opinion and proposed corrections are stored with the submission and deleted with it; only a human admin can publish. Admins may also search public product names and barcodes online. Automated web comparison, when configured with a provider that permits this use, uses Brave Search snippets and Gemini, not Google Search grounding. The separate grounding rules below describe the in-app search feature.
Reading a label or saving your own product does not publish it. With separate confirmation, you can submit product data and two packaging photos for private admin review. A submission is linked to your account for handling and abuse prevention. Photos are compressed and stripped of EXIF metadata, including location; they should show only packaging. An admin may correct or reject the extracted data.
Only approved product data, such as barcode, name, ingredients and nutrition, becomes public — not photos, account identifiers or diary entries. Private submissions and photos are retained for review and later corrections, not automatically deleted after approval. Account deletion in the app removes photos and private submissions; the independent approved product entry may remain in the catalog. You can also request submission deletion at privacy@perunforce.com.
1. Introduction
PerunForce is a health, wellness, fitness, nutrition, supplements and habit-tracking application. This Privacy Policy explains what data PerunForce accesses, collects, stores, uses and shares when you use the app. If you do not agree with this policy, do not use the app.
2. Data we collect
2.1 Account and authentication data
- Google account email address
- Google display name
- Google profile photo URL
- Internal user ID
2.2 Profile data
- Name or nickname, date of birth and gender
- Height, weight and body measurements
- Diet type, health goals and preferences
- Daily goals such as protein and water targets
- Optional profile photo
2.3 Subscription and purchase entitlement data
- Current PerunForce plan and entitlement status
- Billing cycle label
- Purchase source and offer identifiers from Google Play
PerunForce does not collect or store payment card numbers. Payments and billing account management are handled by Google Play.
2.4 Health and wellness data
- Saved legacy wellness-interview answers (if recorded in an earlier version)
- Health conditions selected by the user
- Lifestyle and wellbeing entries such as sleep quality, energy, stress, caffeine, hydration, alcohol, nicotine, notes and optional user-reported changes including sexual wellbeing
- Wellness plans and lifestyle check-in entries
- Optional laboratory results and home measurements entered by the user, including dates, units, report-supplied ranges or flags, measurement context and notes
PerunForce no longer offers a prescription-medication list or a separate symptom-tracking module. Legacy records created with an earlier test version may remain in local or account storage until the user deletes the app data or account, but they are not shown, synchronized to new devices or used by AI features.
The results-and-measurements module is a record-keeping tool. It shows user-entered values, compares selected dates numerically and creates user-requested TXT, CSV or PDF exports. PerunForce does not provide its own reference ranges, classify results, diagnose conditions or recommend treatment. Results are stored locally and, when signed in, may be synchronized with the user’s PerunForce account through Supabase. Exported files leave PerunForce only after an explicit user action and may contain health data.
2.5 Nutrition data
- Meals, nutrition logs and meal notes
- Food names, brands and barcodes
- Calculated calories, macros, micronutrients and goals
- Optional meal photos submitted for AI analysis. If an analysis is interrupted, an encrypted on-device draft may retain the photo and original meal time for up to seven days so you can retry or add the meal manually. Draft photos and their local paths are not synchronized to PerunForce cloud storage and are removed after completion, manual deletion, or expiry.
- Optional food or beverage packaging, ingredient-list and nutrition-label photos submitted for data extraction
- Optional meal-description text or voice transcript submitted for AI parsing
- Optional short-lived copies of food names, portions, nutrition values and the sender display name when the sender explicitly uses the shared-meal link feature
2.6 Voice input and microphone access
Voice meal entry is optional. PerunForce requests microphone access only after you open the voice meal entry feature, review an in-app explanation and choose to continue.
- The microphone is active only while you use the voice capture control.
- PerunForce does not listen in the background and does not create or store a raw audio recording.
- Audio is processed by the Android speech-recognition service available on your device. Processing may occur locally or through the recognition-service provider.
- PerunForce receives the resulting text transcript and, when available, alternative recognition results.
- After separate confirmation for AI processing, the transcript may be sent through the PerunForce backend to Google Gemini to identify food names, amounts and portions.
- You can decline microphone access and enter the meal manually.
2.7 Supplements data
The optional web stack manager uses the same private Supabase account data as Android: your list, doses, timing, notes, package sizes, entered prices, currencies and purchase history. Web editing requires Pro and a compatible mobile sync; reading and exporting remain available after Pro expires. The public no-sign-in calculator keeps your entries in the current browser tab without uploading them. PDF/CSV generation runs locally and does not publish your list or submit it to AI. You choose whether to share a downloaded file.
- Supplement stack, dosages, schedules and reminders
- Optional supplement package-front, facts-panel, ingredients, directions and warning-label photos submitted for AI data extraction
- A reduced package-front thumbnail stored locally on the device for supplements created from a label scan. If you are signed in and account synchronization is available, a separately compressed portable preview may be stored with the supplement template in Supabase so it can be restored on another device. The original full-resolution photo and its local device path are not synchronized
- Supplement intake logs and overrides
- Supplement trials, check-ins, ratings, notes and summaries
- Personal timing observations and whether a schedule came from the catalog, the local planner or a user correction
2.8 Fitness and body data
- Workout history and workout sessions
- Body weight and measurement history
- Optional photos or screenshots of home-scale reports submitted to read the measurement date, body weight, body-fat percentage, lean body mass, body water, bone mass and muscle mass when explicitly shown. PerunForce does not store the image after analysis; values you review and approve are stored like other body measurements. BIA and vendor estimates do not automatically change BMR or calorie targets.
- Body progress entries and optional progress photos. Progress photos are encrypted locally with a device-protected app key and are not synchronized to PerunForce cloud services.
2.9 Health Connect data
If you connect Health Connect and grant access, PerunForce may read steps, sleep sessions, exercise, total and active calories burned, basal metabolic rate, distance and weight. If you separately expand access, PerunForce may also read heart rate, body-fat percentage, lean body mass and body-water mass.
PerunForce reads Health Connect data only after you grant permission. It does not write health data into Health Connect. The data is used only for user-facing wellness and fitness features inside the app. It is not sold, used for advertising or used for cross-app tracking.
Separate from Android permissions and optional cloud history, aggregated Health Connect data may be included in optional AI analyses only if you enable the separate “Health Connect in AI analyses” control. When it is off, AI requests exclude both direct aggregates and context derived from them; cached AI reports and Coach memory marked as using that source are not reused. Local, deterministic app features may continue to use Health Connect data on your device.
By default, Health Connect data is processed and stored locally. If you sign in and separately enable Health Connect cloud history, PerunForce synchronizes processed day-level summaries through Supabase. These may include activity, sleep, workout, energy, heart rate, weight and body-composition values, together with source and synchronization time. Raw point-by-point Health Connect records are not uploaded through this cloud bridge.
The same Health Connect cloud-history choice also controls synchronization of guided sleep experiments that use Health Connect. Those records contain the selected strategy, experiment status, user assessment and processed baseline/follow-up summaries; they do not contain raw point-by-point Health Connect records.
2.10 Legacy family profile data
Production builds no longer allow creating or activating family subprofiles. If you used this feature in an earlier test build, PerunForce may retain the following data until account deletion or a deliberate migration or export:
- Family profile name and relationship label
- Emoji or avatar-style identifier
- Optional date of birth and basic profile metrics
2.11 App usage and operational data
PerunForce may process limited operational metadata needed to provide paid features, enforce usage limits and improve reliability:
- Feature identifier, request count and timestamp
- Completion status and approximate token usage for AI features
- Subscription plan and entitlement status
- Interactions with optional Plus or Pro prompts
- Interactions with the guided sleep library and experiment lifecycle, such as viewing a strategy, starting, completing or stopping an experiment, and the app-calculated outcome; these events do not include raw Health Connect records or user notes
- Interactions with kitchen QR codes, such as creating, scanning, adding, undoing or printing a code. These events may include the code type, number of items, selected behavior, slot and portion percentage, but do not include food names, nutrition values, profile data or health data
- Coarse first-open, activation and sharing funnel events, such as opening the app for the first time, completing onboarding, adding the first entry, opening the first Coach insight, sharing or opening a meal, and creating or accepting a Partner invitation. These rows contain only an allow-listed event, a coarse source and a timestamp — no account, installation or device identifier, goal, food name, nutrition value, user text or health data — and are retained for up to 400 days
- For signed-in Android release users, a Google Play Integrity observation containing the account ID, app and license recognition, device-integrity labels, package name, app version and verification time. It is used only to distinguish official installations and protect service reliability. It does not prove that a person owns the account, does not affect login or app access, and is retained for up to 400 days
- A local buffer of up to 20 technical error categories or codes and redacted stack frames. It does not store exception messages, meal text, audio, photos or health notes and is not uploaded automatically. It can leave the device only after you open the report preview and explicitly choose to copy it or open your email app
Some of this metadata remains local. Coarse first-open, activation and sharing funnel events may be sent to Supabase whether or not you sign in so PerunForce can measure aggregate progression from first opening to first entry. Other limited usage or entitlement events may be stored in Supabase when you are signed in. PerunForce does not use this data for third-party advertising or cross-app tracking.
2.12 Optional Partner mode data
- Pair membership and the two members’ display names
- An optional rolling aggregate of active routine days from 0 to 7
- Manually selected fixed daily signals, their date and removal status
- One of four fixed positive support reactions selected by a member, its date and read status
- Invitation, consent, mute, disconnect and block status
Partner mode does not transfer sleep, weight, calories, grams, meals, workouts, supplements, Health Connect data, Coach outputs or the actions that formed an active day. A daily signal is only a manually selected fixed phrase without quantities or its source record. Each member controls sharing separately.
3. How we use data
We use data to:
- provide the app’s core features
- create and manage your account
- personalize nutrition, supplements and wellness workflows
- synchronize data between your devices when enabled
- display Health Connect data you authorize
- generate optional AI-powered informational outputs
- let you export, review or delete your data
- maintain app security, integrity and reliability
4. AI features
PerunForce includes optional AI features. When you use them, relevant data may be sent through the PerunForce backend to Google Gemini. In the initial wellness release, examples include distinguishing and analyzing a prepared-meal photo or food or beverage packaging and label photo, reading a photo or screenshot of a home-scale report, text or voice-transcript meal parsing, nutrition-day summaries and optional commentary explaining an app-calculated guided sleep experiment result. A scale report may contain a profile name and body measurements; its image is used only for reading, is not stored by PerunForce, and values must be reviewed before saving. If requested, AI may also explain a deterministic, user-editable supplement schedule using names, forms, proposed timing, recorded interactions and synergies, and optional personal timing observations. It cannot change doses, add products or apply the plan.
For health-related AI flows, PerunForce requests explicit in-app consent before sending relevant health data to the AI service. AI features are optional. AI-generated outputs are informational only and are not medical diagnosis, treatment or professional advice.
When you optionally locate a packaged food in public sources or compare a scanned supplement label with them, PerunForce sends the product name, brand or EAN and, for label comparison, the user-reviewed package transcription to Google Gemini with Google Search grounding. The health profile is not added to this lookup. The query, context and generated output may be retained by Google for up to 30 days under the Google Search grounding terms. The comparison does not assess whether a product is safe, suitable or correctly dosed for a person, and a food lookup does not import nutrition values.
In the initial wellness release, health conditions and lab results are not used to generate AI Coach guidance, AI-generated health plans or supplement recommendations. The app does not interpret lab results or personalize supplement protocols based on conditions or clinical symptoms. A separate Pro planner can organize timing from catalog form hints, meal requirements, recorded interactions and user corrections. The schedule is deterministic and editable; AI may explain it but cannot change doses or apply it.
To keep AI Coach outputs consistent and less repetitive, PerunForce may create a compact weekly continuity summary containing recent changes, trials, observed outcomes, rejected suggestions and the next focus. Up to eight weekly summaries are kept per profile in the app and may be synchronized with the PerunForce account. They can be deleted together with active Coach memory in the app.
PerunForce also stores a short, profile-separated Coach Journal containing deterministic Coach outputs such as noticed context, the current main step, wins, active trials and a queued next step. The app displays the most recent 14 days. Journal entries are part of the Coach event history, which is retained for up to 45 days and capped at 90 journal entries within a maximum of 240 Coach events. They may be synchronized with your PerunForce account and are removed when you clear active Coach memory in the app.
If you choose “I’ll try” on a Coach suggestion, PerunForce may later ask whether the trial helped. Your answer (“helped”, “did not help” or “still testing”) is stored as user-reported feedback and may be synchronized with your account. It reduces repetition and tailors later suggestions, but is not treated as measured proof that the suggestion caused an outcome.
If you explicitly report an AI-generated output, PerunForce sends the report to a private Supabase inbox. The report contains your account identifier, the app feature and screen source, the selected reason, an excerpt of the generated output, optional comments and timestamps. A report that cannot be sent immediately remains in an encrypted on-device queue and is retried later. Reports are used for safety review, correction and reliability work; they are not used for advertising.
5. Health Connect
PerunForce uses Health Connect only after you explicitly grant access and requests a minimal scope first. Optional recovery and body-composition access is requested separately.
You can disconnect Health Connect in the app or revoke permissions in Android Health Connect settings. You can keep Health Connect local-only or disable future cloud synchronization at any time. Disabling synchronization stops future transfers but does not automatically delete summaries already synchronized; those summaries are covered by the account and data deletion process.
6. Storage and security
6.1 Local device storage
PerunForce stores user data on the device. Sensitive local data is protected using app-side storage protections, including encrypted health-related storage where applicable. Body progress photos are encrypted locally with an app key protected by the device keystore/keychain and are not synchronized to PerunForce cloud services. Existing plaintext progress photos from an earlier build are migrated locally after their first successful read.
6.2 Cloud services
When you sign in, PerunForce may store and synchronize data using Supabase for authentication, database synchronization and selected media such as profile photos or exports. Supabase also stores short-lived, token-protected shared-meal snapshots created at the sender’s explicit request. If you enable Partner mode, Supabase also stores the pair connection, explicit sharing choices, the optional 0–7 day aggregate, fixed daily signals and support reactions. Without sign-in, app data remains local except when you explicitly use optional online features.
The web planner for trainers can be used without sign-in; in that case its draft stays in browser storage. After sign-in, Supabase may store separate client plans, invitations, nutrition-setting and supplement proposals, and their acceptance history. A client must accept the invitation and separately selects whether to share profile and goals, aggregate nutrition, weight and circumference changes, aggregate sleep, or aggregate activity.
A trainer does not receive direct access to diary rows, photos, notes or raw Health Connect records. Only a filtered snapshot of the selected scope is available. Trainer proposals never change the client account automatically: the client approves settings and chooses My stack, shopping list or skip for each supplement. Revoking the connection immediately removes the current snapshot, ends access and archives the shared plans.
6.3 Data transmission
Network traffic is encrypted in transit using TLS. No system can guarantee absolute security, but reasonable technical measures are used to protect user data.
7. Third-party services
PerunForce may use:
- Supabase for authentication, storage and synchronization
- Google Sign-In for account authentication
- Google Play Billing for subscriptions and payments
- Google Play Integrity for app, license and device-integrity verification on signed-in Android release installations
- Google Gemini for optional AI processing
- Android speech recognition for optional voice-to-text input
- Open Food Facts for food database lookups
- PubMed/NCBI and other public sources for evidence links
8. Data sharing
PerunForce does not sell personal or health data and does not use it for advertising. Data may be processed by service providers acting on our behalf when required to operate app functionality such as cloud synchronization, authentication, storage or optional AI features.
If you explicitly share a meal, PerunForce creates a random, unguessable link that lets a person you choose preview that meal’s food items, portions and nutrition values together with your display name. The link does not provide access to your profile, diary, health data or other meals. The recipient must explicitly confirm before an independent copy is saved in their own diary, and later edits do not affect your diary.
If two adults explicitly accept a Partner mode invitation, each member may separately choose to share a rolling 0–7 active-day aggregate and any combination of four manually selected, fixed daily signals. The signals contain no quantities or source records, disappear from the current view the next day and can each be removed immediately. A member may send a fixed positive support reaction. Free-text messaging is not available. A member can mute support or its notifications, withdraw daily signals or consistency sharing, disconnect or block the partner.
9. Data retention
Data is retained for as long as needed to provide app features, maintain synchronization, comply with legal obligations, resolve disputes and enforce agreements, unless you request deletion. Some technical backup or recovery copies may remain for a limited time before deletion cycles complete.
The local technical-error buffer keeps at most 20 redacted entries. Older entries are replaced automatically. You can clear the buffer from the in-app report preview; it is also removed when local app data is cleared or the app is uninstalled. PerunForce currently has no automatic remote crash-report upload.
Billing validation records contain a one-way hash of the Google Play purchase token, not the token itself. These records are scheduled for deletion after 400 days. Successfully processed Real-time Developer Notification inbox records are scheduled for deletion after 90 days; unresolved or failed records after 400 days. Deleting an account deletes user-linked billing state and validation records; short-lived RTDN replay records may retain only the hashed token until their retention period ends.
Google Play Integrity observations are retained for up to 400 days and deleted with the linked PerunForce account. Failed, unsupported, offline or unavailable checks remain unclassified and do not create a negative verdict or block the app.
PerunForce does not retain raw microphone audio. Voice transcripts submitted for optional AI meal parsing are processed to produce a result; saved meal entries contain structured nutrition data rather than an audio recording.
Food-source lookup and supplement label-verification queries and outputs are subject to the Google Search grounding retention described in section 4, including possible retention by Google for up to 30 days. PerunForce displays grounded comparisons, source links and required Google Search suggestions only in the current verification session and does not add them to its product database, saved nutrition entries or supplement stack.
AI content reports are retained while needed to investigate the reported output, improve safety and reliability, or resolve related disputes. They are linked to the reporting account and are deleted with that account, subject to limited technical backup and legal retention described above.
Shared-meal links expire after seven days. The associated server snapshot is no longer accessible after expiry and is scheduled for deletion within the following 24 hours. Deleting the sender account also deletes its active shared-meal snapshots. A recipient’s independently saved diary copy follows the recipient’s normal nutrition-data retention choices.
Partner invitations expire after 48 hours. Partner-mode connection data is retained while the connection is active. Daily signals are retained for no more than 32 days and only the current day is shown to the partner. Disconnecting ends access for both members; blocking also prevents the same accounts from reconnecting through a new invitation. Account deletion removes the deleting member’s pair data, daily signals and associated support reactions.
Trainer invitations expire after seven days. An active connection and its plans are retained while the feature is used. Revocation immediately deletes the aggregate snapshot available to the trainer, ends access for both sides and archives shared plans; archived records remain unavailable in the feature until a related account is deleted. Account deletion removes related connections and plans under the data-deletion process.
10. Deletion and user choices
You can:
- use parts of the app without signing in
- disconnect Health Connect
- decline optional AI features
- withdraw Partner-mode consistency sharing, mute support, disconnect or block the partner
- export your data
- delete your account and associated data from inside the app
Public instructions and an external request path are available at perunforce.com/account-deletion. If cloud deletion fails, the app may offer local-only device cleanup and will clearly inform you that cloud data may remain until remote deletion succeeds.
11. Children
PerunForce is not directed to children under the minimum age required by applicable law or platform policy. Production builds provide one main profile for the adult account owner and do not offer profiles for minors.
12. Your rights
Depending on your jurisdiction, you may have the right to:
- access and correct your data
- export your data
- request account and data deletion
- withdraw consent for optional processing
- object to or restrict certain processing where applicable
For privacy and data requests, contact privacy@perunforce.com. Do not send passwords, payment details or sensitive health information by email.
13. Policy availability
This Privacy Policy is published on a public, non-geofenced URL and linked both inside PerunForce and in the Google Play listing.
14. Changes to this policy
This policy may be updated as PerunForce changes. The current version is identified by the “Last updated” date above. Material changes will be reflected on this page and, where appropriate, communicated in the app.