Privacy Policy — Asidu
Asidu ("the App") is developed under the brand Studio Flysch, operated by:
Nicolas Burri Studio GmbH
Flüelastrasse 16, 8048 Zürich, Switzerland
Commercial register no. CHE-470.128.392
Responsible person: Nicolas Burri
Contact: [email protected]
This policy explains what data the App processes, why, where it is stored, and what rights you have. It is written for the App as published on the Apple App Store and applies to all versions unless a version-specific notice says otherwise.
1. Summary
- No account. The App does not require registration, login, e-mail address, or any identity information.
- Your data stays on your device. Food entries, weight, profile settings, targets, favourites, and calculated values are stored locally on your iPhone. If you enable iCloud sync (where offered), they are stored in your personal iCloud account, which we cannot access.
- Health data is read only with your permission. The App reads selected categories from Apple Health and writes nutrition and weight entries back only if you allow it. Health data is never sent to our servers, never sold, and never used for advertising.
- Calendar access is optional and off by default. If you select calendars in Profile → Training Calendar, only event title, start time, and duration are read — never notes, locations, or attendees. Titles are used to recognise planned workouts (see Section 4).
- AI features and food lookups use external services. When you use AI meal recognition, meal suggestions, PDF import, barcode lookup, or food search, the specific input you provide (text, a photo, a PDF, a barcode, or a search term) is sent through our server to a third-party provider. No name, no health history, and no identity is attached.
- An anonymous device identifier is used to enforce usage limits on AI features. It is not linked to you personally.
- No advertising, no tracking across apps, no sale of data.
2. Data stored on your device
The App stores the following locally on your iPhone (and, if you enable it, in your iCloud account via Apple CloudKit):
- Profile: age, height, sex, body-fat percentage (optional), goal type, target rate, dietary targets and preferences.
- Nutrition log: meals, ingredients, quantities, nutritional values, timestamps, favourites and recurring-meal rules.
- Weight entries you enter in the App.
- Calculated values: energy expenditure estimates, calibration factors, weekly budget, readiness indicators, and their history.
- App settings, reminders, dashboard layout.
- A locally cached copy of food product data you have scanned or searched.
- If Calendar access is enabled: which calendars you selected, and a local cache of workout classifications by event title (so the same title is not re-classified).
- If you use Recovery Mode: the periods you log (injury, illness, or training break), their start/end dates, and any optional note you add. This never leaves your device.
This data is under your control. You can export it as a file (Profile → Data → Share Backup), import it, or delete all App data at any time (Profile → Data → Delete All Data, or by deleting the App). We have no copy of it.
If you enable iCloud sync, Apple's iCloud terms and privacy policy apply to the synchronised copy. We cannot read, access, or restore iCloud data on your behalf.
3. Apple Health (HealthKit)
With your explicit permission, the App reads the following categories from Apple Health:
- Active energy burned, resting energy burned
- Workouts (type, duration, energy)
- Body mass, body-fat percentage
- Heart rate variability (HRV), resting heart rate
- Sleep analysis
- VO₂ max
With your permission, the App writes:
- Dietary energy, protein, carbohydrates, fat, and other logged nutrients
- Body mass entries you record in the App
Health data is processed only on your device to calculate targets, trends, and readiness indicators. In accordance with Apple's HealthKit rules:
- Health data is never transmitted to our servers or to any third party.
- Health data is never used for advertising, marketing, or data mining.
- Health data is never sold or shared.
You can revoke any Health permission at any time in iOS Settings → Privacy & Security → Health → Asidu. Revoking permissions limits the related features but does not affect your other data.
3.1 Cycle tracking (optional, off by default)
The App can optionally read menstrual flow data from Apple Health to reduce the effect of typical perimenstrual water retention on your weight trend and weekly calibration. This is a separate, additional permission from the Health categories above.
- This category is never read unless you explicitly turn it on in Profile → Cycle Tracking. It is never enabled or assumed based on your sex, profile, or any other data.
- It is processed entirely on your device to detect the approximate timing of your cycle and, if the data is regular and recent enough, to reduce the weight given to the days around your period when calculating your weight trend and calibrating your energy estimate. If your data is irregular, incomplete, or too old, the App automatically stops applying this correction rather than guessing.
- It has no effect on your calorie, macro, or readiness targets.
- Cycle data is never transmitted anywhere — not to our servers, not to any third party. It never leaves your device.
- You can turn this off at any time in Profile → Cycle Tracking, or revoke the permission in iOS Settings → Privacy & Security → Health → Asidu.
4. Calendar (EventKit)
With your explicit permission, the App reads events from the calendars you select in Profile → Training Calendar (Settings). No calendar is read by default.
- Only title, start time, and duration are read. Notes, locations, attendees, and other calendar data are never accessed.
- Event titles are sent via our server to Anthropic, PBC (USA) to classify whether the event is a workout and, if so, its sport, intensity, and estimated MET value (see Section 5.1). The result is cached on your device by event title, so the same recurring title is not sent again.
- Calorie estimates for planned workouts are calculated on your device (MET × weight × duration) and never sent anywhere.
- Calendar data is never used for advertising, never sold, and never shared other than the single title sent for classification as described above.
You can change or revoke calendar access at any time in iOS Settings → Privacy & Security → Calendars → Asidu, or by deselecting calendars in Profile → Training Calendar.
5. Data sent to our server and to third-party providers
Some features require processing that cannot happen on the device. For these, the App sends a request to a server operated by us on Cloudflare Workers (Cloudflare, Inc., USA, with global edge locations including in Europe), which forwards the request to the relevant provider. In each case only the minimum data needed for that single request is sent.
5.1 AI meal recognition, meal suggestions, PDF import, and workout classification
When you type a meal description or take a photo of a meal or a nutrition label, that text or image is sent via our server to Anthropic, PBC (USA) for analysis. The response (recognised foods and estimated nutritional values) is returned to the App and stored locally.
- What is sent: the text you typed or the photo you took, plus an optional short context (e.g. "portion for one person"). Photos are downscaled before sending.
- What is not sent: your name, profile, health data, targets, previous entries, or any identifier that could link the request to you as a person.
- Under Anthropic's commercial API terms, inputs submitted through the API are not used to train Anthropic's models. Please refer to Anthropic's own privacy documentation for their retention practices.
- Photos are not stored on our server. Do not photograph other people, documents, or anything you would not want processed by an AI provider.
- Meal suggestions: when you ask the App to suggest a meal, it sends your remaining calorie/protein/fat targets and your chosen dietary preference (e.g. "vegetarian") to Anthropic via our server. No personal identifiers or health data are included.
- PDF import: when you upload a nutrition export from another app, the PDF is sent once via our server to Anthropic to extract daily nutrition totals for the last 30 days. The file is not stored on our server and is discarded after processing. Do not upload documents that contain other people's data.
- Workout classification: when Calendar access is enabled (Section 4), the title of a calendar event is sent via our server to Anthropic to determine whether it is a workout and, if so, its sport and intensity. Only the title and its duration are sent — no other calendar data.
5.2 Barcode lookup and food search
When you scan a barcode or search for a food product, the barcode or search term is sent to one or both of:
- Open Food Facts (association, France) — queried directly from the App; Open Food Facts may see your IP address as with any web request.
- FatSecret Platform API (FatSecret, Australia) — queried via our server.
Only the barcode or search term is sent. Results are cached locally on your device.
5.3 Swiss Food Composition Database
Generic food values from the Swiss Food Composition Database (Federal Food Safety and Veterinary Office) are bundled inside the App and used offline. No request is made.
5.4 Anonymous device identifier and usage limits
To prevent abuse of AI features and to control costs, the App generates a random identifier (UUID) on first launch and stores it in the device keychain. This identifier is sent with requests to our server, which keeps a counter of requests per identifier per day for a short period (currently 48 hours) in Cloudflare KV storage. If no identifier is available, the server uses the request's IP address for the same purpose.
The identifier is random, is not derived from your Apple ID, device serial number, or any personal attribute, and is not linked to your name or health data. It cannot be used by us to identify you. It is deleted when you delete the App and reset the keychain, or it simply expires from our counters after 48 hours of inactivity.
5.5 Usage and cost metering
To operate the service sustainably we record, per anonymous device identifier and calendar day: request count, token count of AI requests, and which model was used, so we can track approximate cost. This is technical metering, not profiling. No request content is stored for this purpose. Records expire automatically after 7 days.
5.6 Server logs
Cloudflare may retain standard technical logs (timestamp, route, status code, IP address, error messages) for operational security and debugging, for a limited period. We do not use these logs to identify individual users.
6. Analytics and crash reporting
The App does not use any analytics, tracking, or crash-reporting SDK from third parties. Apple may provide us with aggregated, anonymised crash and usage statistics if you have enabled "Share with App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements; this is controlled by you and by Apple, not by us.
7. Subscriptions and payments
Asidu offers optional paid features via auto-renewable subscriptions purchased through the Apple App Store, including a free trial period where offered. All payment processing is performed by Apple. We do not receive your payment details, card numbers, or billing address. Apple provides us with an anonymised transaction record (receipt) that the App uses to unlock paid features on your device and, where necessary, our server uses to verify subscription status. Manage or cancel subscriptions in iOS Settings → Apple ID → Subscriptions. Apple's terms and privacy policy apply to the purchase.
If we offer referral or promotional codes, redeeming a code creates a record linking the code to the anonymous device identifier so that the benefit can be applied. No personal data is involved.
8. Notifications
Reminders (logging, meals, supplements, weigh-in) are local notifications scheduled on your device. No push server is involved and no data leaves the device for this purpose.
9. Legal basis and international transfers
We process data in accordance with the Swiss Federal Act on Data Protection (FADP/nDSG). For users in the EU/EEA and the UK, the GDPR / UK GDPR applies, and our legal bases are: performance of the contract (providing the App features you use, Art. 6(1)(b) GDPR), our legitimate interest in preventing abuse and operating the service securely (Art. 6(1)(f)), and your consent for Health data access (Art. 9(2)(a)), which you give through the iOS permission dialog and can withdraw at any time.
Requests to AI and food-data providers are transferred to the USA (Anthropic, Cloudflare) and Australia (FatSecret). These transfers concern only the individual request content described in Section 5, never your health or profile data. The providers are bound by contractual data-protection terms. Switzerland and the EU recognise the USA under the respective Data Privacy Frameworks for certified organisations; where a provider is not certified, standard contractual clauses apply.
10. Retention
- Data on your device: until you delete it or the App.
- Rate-limit counters on our server: 48 hours.
- Usage metering records: 7 days, then automatically deleted.
- Server logs: as retained by Cloudflare, typically up to 7 days.
- AI request content: not stored by us; refer to the provider's policy for transient processing.
11. Your rights
Because the App does not hold personal data about you on our servers beyond the anonymous identifiers described above, most rights (access, correction, deletion, portability) are exercised directly by you on your device: export, import, or delete your data under Profile → Data.
You may nevertheless contact us at [email protected] to ask what data, if any, we hold in connection with your anonymous device identifier, to request its deletion, or to object to processing. EU/EEA users have the right to lodge a complaint with a supervisory authority; Swiss users may contact the Federal Data Protection and Information Commissioner (FDPIC).
12. Children
The App is not intended for persons under 16 years of age and we do not knowingly collect data from them. Calorie and body-weight tracking is not appropriate for children and adolescents without professional supervision.
13. Changes
We may update this policy when features change. The current version is always available at asidu.app/privacy.html and inside the App under Profile → Legal. Material changes will be indicated in the App.
14. Contact
Nicolas Burri Studio GmbH
Flüelastrasse 16, 8048 Zürich, Switzerland
[email protected]