Legal
Privacy Notice
Last updated 7 August 2026
This notice describes the current Daystrong public release. Daystrong is operated by Ferreira Cruz Digital, owned by Artur Ferreira Cruz, 6260 Reiden LU, Switzerland. Privacy requests can be sent tosupport@arturf.ch.
Who may use Daystrong
Daystrong is available to adults aged 18 or older. It is a general wellness and tracking product, not a medical service. Do not use it for diagnosis, treatment, medication, allergies, eating-disorder care, or another decision requiring a qualified professional.
Data Daystrong stores
- Account and consent: name, email, Clerk account and session identifiers, Terms/Privacy versions and optional analytics choice. Clerk handles authentication credentials.
- Profile and goals: values you provide for calorie and macro targets, height, weight, activity and training preferences.
- Nutrition: confirmed diary entries, saved meals and barcodes. Meal photos and AI prompts are sent for the requested estimate but are not written to the Daystrong database.
- Training and community: workouts, routines, exercises, notes, optional group participation and posts you create.
- Health Connect: only steps and weight after separate Android permission. When you press sync, the selected daily steps and latest weight are copied into your Daystrong account.
- Operations: structured support feedback and an AI cost ledger containing method, model, token counts, estimated cost, latency and a safe result code—never the image or prompt.
Why it is used
Data is used to create and secure your account, provide the diary, training, progress, AI estimate and Health Connect features you request, enforce service limits, answer support, export or delete your data, and operate Daystrong. Daystrong does not sell personal data or use Health Connect, diary or workout content for advertising.
Current services and data boundaries
- Appwrite Sites: hosts and delivers the static marketing website over encrypted, globally distributed infrastructure. Standard connection data, such as IP address and browser request information, may be processed to deliver and protect the site. No Daystrong account, diary, health or workout data is stored in the website files. Review Appwrite’s privacy policy.
- Appwrite Cloud: private TablesDB and Storage in Frankfurt are authoritative for account-linked nutrition, fitness, health-consent and progress-photo data. The trusted API accesses that private data on the user's behalf.
- Operator-managed PostgreSQL auxiliary store: holds community posts and memberships, support feedback, analytics consent, entitlements and subscription-event records, and the privacy-minimal AI cost ledger. It is not a second authority for the Appwrite domains.
- Clerk Production: provides account authentication and receives the name, email address, authentication credentials and session-security data needed for sign-up and sign-in.
- OpenAI: receives only the text or meal image you deliberately submit for an estimate plus the instructions needed to return structured foods. Review OpenAI’s privacy policy.
- Open Food Facts: receives food-search or barcode requests and supplies collaborative product data. Review its privacy information.
- PostHog EU analytics: receives data only after opt-in, under a separate random marketing ID on the website and a pseudonymous random analytics ID in the app. A strict allowlist permits coarse feature-use and sync outcomes but excludes identity, URLs, free text and all food, calorie, photo, body, health and workout content or values. GeoIP, replay, autocapture and person profiles are disabled.
- Self-hosted Umami analytics: receives website data only after the same marketing-site opt-in. It records page paths without query strings, normalized link and button interactions, section views, scroll-depth thresholds and coarse 30/60/120-second engagement milestones. It does not receive performance telemetry, form content, account identifiers, email or phone values, health, food, workout, photo or free-text content.
- PostHog EU release flags: are checked independently of analytics consent under a separate random installation ID that is not linked to an account. Checks use only environment, platform, app version and a coarse release ring, send no analytics events and fail closed after a six-hour offline cache window. Flags may change UI ordering or algorithms, never permissions, billing, migrations or data writes.
- Android Health Connect: remains permission-controlled on the device; Daystrong requests only steps and weight.
Billing is disabled. Clerk Billing, RevenueCat and Google Play Billing receive no Daystrong purchase data. This notice will be updated before a paid offering is enabled.
Optional analytics
Product analytics is off by default. You can enable or disable it in More → Your data. Opting out stops future capture, rotates the app analytics identity and does not affect the app, feedback or account access. It does not automatically delete events already received by PostHog; contact support for a deletion request. Logout clears the analytics identity locally. The marketing website asks separately and permits only allowlisted, content-free events through PostHog EU and the operator's self-hosted Umami instance.
Retention, export and deletion
- Nutrition, fitness, health-consent and progress-photo content remains in the active Appwrite data platform until you delete it. PostgreSQL auxiliary records remain while the corresponding account is active.
- In-app deletion removes the Clerk account; private Appwrite TablesDB rows, mutation records and referenced Storage objects; and account-linked PostgreSQL auxiliary rows, including community posts and memberships, support feedback, analytics consent, entitlements, subscription events and AI cost-ledger records. A shared community group may remain with its creator link removed.
- Encrypted recovery artifacts for either data platform may retain deleted data only until their scheduled recovery-window expiry. They are not active application data.
- Size-limited infrastructure logs and a privacy-minimal deletion-control record may remain where needed for security, abuse prevention and to prevent a deleted identity from recreating data.
- You can generate a JSON export in More → Your data or request access, correction or deletion by email.
Security and international processing
Daystrong uses encrypted transport, Clerk authentication, account-scoped access, rate limits and server-side entitlements. Hosted processors may handle data outside Switzerland under their published terms and safeguards. No online service is risk-free; report suspected incidents tosupport@arturf.ch.
Your rights and contact
Depending on applicable Swiss or European data-protection law, you may request information, access, correction, deletion, restriction, objection or a portable copy. Contactsupport@arturf.ch. Identity may be verified before account information is disclosed.
Questions about this notice or Daystrong? Emailsupport@arturf.ch.