● LEGAL · DOC 01

Privacy & Data Handling

Your bloodwork, your bodyweight, and your training history are the most personal data you'll ever generate. Here's exactly how we handle it.

EffectiveMay 18, 2026 Last updatedSep 20, 2026 Versionv 2.13 JurisdictionIndia StatusPre-launch
SECTION 01 — DATA

What we collect.

Transform is a measurement instrument. To work, it needs measurements. We collect only the minimum required to render your mission and only with your explicit permission for each category.

  • BodyWeight, body composition, progress photos, and body-scan photos — both the one-time onboarding scan and each weekly in-app scan — plus sleep, HRV, and resting heart rate (HealthKit and manual entry). See Sharing → OpenAI below for how body-scan photos are processed and stored.
  • TrainingExercises, sets, reps, weights, RPE, rest timers.
  • NutritionMeals you log, supplements, macros computed against our food database.
  • BloodworkLab panels you upload manually as PDF or enter by hand.
  • AccountApple Sign In identifier, optional email, billing handled entirely by Apple via in-app purchase.
  • DeviceiOS version, app version. Also attribution identifiers sent to AppsFlyer (see Analytics/Sharing below) — your device's advertising identifier only if you allow the iOS tracking prompt. Crash reports and error diagnostics are sent to PostHog — see Sharing → PostHog below for exactly what that contains.
  • AnalyticsApp-usage events (app opened/backgrounded, which onboarding step you're on, how long each screen was viewed, whether you started a subscription, and the onboarding answers you pick — goal, dietary pattern such as vegan or keto (never allergens), training split and days, food-logging preference, gender, activity level) via PostHog. We do not record your screen — session replay was removed on 2026-09-20. Analytics are on by default; you can switch them off any time in Settings → Privacy → Share Usage Data. None of it is your health data. PostHog sees your device's IP address in transit, but we've switched off its location lookup, so we never know where you are.
● COACH NOTE

We do not collect contacts, location, microphone, camera roll, or browsing history. The app never asks for permissions it does not use.

SECTION 02 — USE

How we use it.

Your data drives exactly two things: (1) the readouts and visualizations inside the app, (2) the Coach insights generated from your own trends. That's the entire list.

What we never do. We do not sell data. We do not show ads in the app. We do measure our own ads: AppsFlyer tells us which campaign brought an install, and which subscription and app-funnel events followed that install (only using your device's advertising identifier if you allow the iOS tracking prompt) — it never sees your training or health data, and we never use analytics to target you with anyone else's ads. We do not train external AI models on your data. We do not share your bloodwork, training, or bodyweight data with anyone — ever — outside what's listed in the next section.

SECTION 03 — SHARING

Who sees your data.

  • YouAlways. Export available in Settings → Account → Export.
  • SupabaseOur database provider hosts the encrypted tables. They cannot read your data without our keys.
  • OpenAIAll AI features (Coach replies, meal text and photo parsing, bloodwork insights, supplement recommendations, and physique-score inference from your body-scan photos) send only the input each feature needs — an anonymized prompt or the relevant image, never your name or email — to OpenAI. Under our signed Data Processing Agreement, OpenAI does not use your inputs or outputs to train, fine-tune, or improve its models; it retains them for at most 30 days for abuse monitoring and then deletes them. Every body-scan photo is handled the same way, whether it is the one-time onboarding scan (if you complete that optional scan and subscribe) or a weekly in-app scan: it is stored in our private per-user storage, linked to your account, and kept until you delete it or your account. The onboarding photo becomes the Week 1 image of your body-scan gallery and its scores seed your first weekly entry. You can delete an individual scan's photo, or an entire scan and its scores, at any time in the App.
  • AppleSubscription billing is handled entirely by Apple via in-app purchase. We never see your card, address, or full Apple ID.
  • PostHogOur product-analytics provider. Sees app-usage events, app-lifecycle events, your app-generated user ID, standard device and environment context (app version, OS name and version, device model and type, language, time zone, network type),. As part of that product-analytics data, never your health data, meal data, progress photos, bloodwork, or Coach messages. Separately, since Sep 19, 2026, we also send PostHog crash reports and handled-error diagnostics so we can find and fix bugs. When a background sync fails to save something — a body measurement, a supplement log, a workout — we now report only which step failed and a short category (like "validation" or "network"), never the underlying error text, so that path can no longer carry a fragment of your data. Two things stay outside that protection, and we're telling you about both rather than calling this fully solved: PostHog's own crash detector catches app crashes directly at the OS level, separately from anything we send it — we've checked our code and nothing in it writes your data into a crash message, but this happens outside our filtering, so we're calling it a reviewed, accepted risk rather than an eliminated one. And our on-device filtering strips things like tokens and email addresses but can't recognize arbitrary content, so a rare decoding-error diagnostic could in principle still include a stray fragment of whatever it failed to read. We can't promise it's always fully absent.
  • AppsFlyerOur attribution and conversion-measurement provider. Sees device identifiers (the advertising identifier only if you allow the iOS tracking prompt), install and session timestamps, IP address, device model and OS version, your app-generated user ID, subscription and purchase events (product identifier, trial status, price, currency, transaction identifier), and app-funnel events (registration, login, onboarding completion, paywall view). If you decline the prompt, attribution falls back to Apple's privacy-preserving SKAdNetwork — aggregate numbers, nothing about you. Exists to answer two questions — which ad brought you here, and whether you subscribed afterwards. Never your health data, meals, bloodwork, or Coach messages. You may opt out at any time in Settings → Privacy → Share Usage Data. Doing so immediately stops all analytics collection and in-app attribution reporting. Because our subscription processor, RevenueCat (next entry below), cannot retroactively unset an attribution identifier once it has been assigned, subscription events processed through RevenueCat may remain linked to attribution data after you opt out; on request, we will submit a deletion request to AppsFlyer for attribution data collected from your device.
  • RevenueCatOur subscription-management provider, RevenueCat, Inc. Handles subscription management, purchase validation, and entitlement state, and forwards purchase events to AppsFlyer for advertising measurement on our behalf. Sees purchase and transaction data (product identifier, price, currency, trial and renewal status), your app-generated user ID, and the AppsFlyer device identifier. Never your health data, meals, bloodwork, or Coach messages.
SECTION 04 — STORAGE

Where it lives.

Encrypted at rest and encrypted in transit with TLS. Primary storage is in us-east-1 on Supabase. Transform is available only in the United States, Canada and India — we do not offer it in the EU, UK or Switzerland.

We retain your data for the duration of your subscription plus 30 days after cancellation. After that, it is purged from primary storage; database backups roll off within 90 days.

One exception: analytics and crash/error diagnostics sent to PostHog (see Sharing → PostHog above) are retained by PostHog on a rolling basis of up to 12 months, independent of your account's lifecycle — deleting your account does not, by itself, delete that data out of PostHog's systems on the same 90-day schedule.

SECTION 05 — RIGHTS

What you can do.

  • ExportDownload a JSON copy of every record we have on you, in-app, at any time.
  • DeleteWipe your account from Settings → Account → Delete. Honored within 7 days; backups within 90.
  • CorrectEdit any logged value at any time. The local history stays for audit, but you control it.
  • WithdrawCancel your subscription in Settings → Subscription (handled by Apple). Your data is retained per the policy above unless you also choose Delete.
SECTION 06 — SECURITY

How we defend it.

TLS in transit, encryption at rest at the database level (Supabase managed Postgres). Sign in with Apple — we never store or see your password. Production database access is limited to a small set of administrators.

We're a small, pre-launch team. We don't claim formal certifications we don't have. If you find a security issue, please email security@trans4m.fit — we'll acknowledge within 72 hours.

If we ever experience a breach affecting your data, we will notify you within 72 hours of confirming it, in plain language, with a list of exactly what was exposed.

SECTION 07 — TERMS

Terms of service.

Not medical advice. Transform is a measurement and tracking tool. Coach insights are statistical observations, not medical prescriptions. Always consult a licensed physician before changing diet, training, or supplementation — especially when bloodwork is involved.

Subscriptions. Billing is handled by Apple via in-app purchase. Subscriptions auto-renew until cancelled. Cancel anytime in your iOS Settings → Apple ID → Subscriptions; refunds are handled by Apple per their standard policy.

Acceptable use. Transform is for personal use. Don't reverse-engineer, scrape, or use the service to build a competing product. We may suspend accounts that abuse the API or attempt to access other users' data.

SECTION 08 — CONTACT

Talk to a human.

Privacy questions, data requests, or anything that doesn't sit right: privacy@trans4m.fit. We answer within 48 hours, and a real person — not a ticketing bot — handles it.

General questions: hello@trans4m.fit. Security disclosures: security@trans4m.fit.