Privacy

Privacy Policy

Radical Fat Loss (iPhone & Apple Watch) and this website
Effective date: 2 August 2026 · Version 1.2
Controller: Radical Health OÜ, Estonia

The short version

  • Radical Fat Loss is local-first: your profile, food logs, weight and the health data the app reads from Apple Health stay on your device. We don't run a server that stores them.
  • We never sell your data, never use it for advertising, and don't track you across other apps or websites.
  • The AI features in this version run on your iPhone — there is no cloud AI and no API key to enter. Only two things ever leave the device: a barcode lookup when you scan a product, and anonymous product analytics if you opt in.
  • You stay in control: edit or delete anything in the app, export a backup, or delete the app to remove your local data.
Looking for a different app? This policy covers Radical Fat Loss and this website. Radical Attune has its own policy: Radical Attune Privacy Policy.

1Who we are

The data controller for Radical Fat Loss and this website is Radical Health OÜ (Estonian registry code 17536495), located in Estonia ("we", "us", "Radical Health").

For any privacy question, or to exercise your rights, contact us at privacy@radicalhealth.app.

2What this policy covers

This policy explains how the Radical Fat Loss app and the Radical Health website handle personal data, the legal bases we rely on under the EU General Data Protection Regulation (GDPR), and your rights. It reflects the app as designed at the effective date above; if we change how data flows (for example, by enabling cloud sync or a cloud AI option), we will update this policy first.

3Our privacy model

Radical Fat Loss is built around a simple principle: keep your data on your device, and only send something off it when you explicitly ask us to. Most of the app — logging, targets, fasting, trends, the coach's deterministic insights, and the Apple Watch and widget views — works entirely on-device with no network connection and no account.

We do not operate a database that holds your health or weight data. There is, by design, very little for us to "have."

4The data the app handles, and where it lives

The following is created and stored locally on your device (using Apple's on-device SwiftData storage). It is not transmitted to us:

CategoryExamplesWhere it lives
Profile & settingsAge, biological sex, height, goal weight, diet/mode preferences, your stated "reason," app togglesOn device
Food & nutritionLogged meals and macros, meal photos, scanned barcodes, eating-window/fasting history, saved foodsOn device
Body metricsWeight, body-fat %, measurements, progress photos (if you add them)On device
Health & activityData read from Apple Health (see §5) and the insights derived from it — trends, recovery, projectionsOn device

We have no account system and assign no advertising or cross-app tracking identifier. The only identifier we ever receive is the random, per-installation analytics identifier described in §6.4 — and only if you opt in to analytics. We do not currently sync your app data to any cloud service we operate; if optional iCloud sync is offered in future, your data would sync through your own Apple iCloud account under Apple's terms, and this policy would be updated.

5Apple Health (HealthKit)

With your permission — granted per data type in iOS — the app reads health and activity data from Apple Health to power its features, including: steps and walking metrics, body mass, body-fat %, lean body mass, height, sleep analysis, heart-rate variability, resting and active heart rate, respiratory rate, sleeping wrist temperature, active and basal energy, workouts, VO₂ max, time in daylight, dietary sodium, mindful sessions, date of birth and biological sex. Some types are requested only if you use the related feature — for example menstrual-cycle data, blood glucose (when a CGM writes it to Health), and mood ("State of Mind").

With your permission, the app writes the following back to Apple Health: the four macros for meals you log, water and sodium intake, completed walks/workouts, and a mindful-session record for the in-app breathing prompt.

Health data read through HealthKit is processed on your device to provide app features only. We never use it for advertising or marketing, never sell it, and never share it — and it is not sent to any server at all — not to us, and not to an AI provider, because this version has no cloud AI (§6.1). You can review or revoke Health permissions any time in iOS Settings → Privacy & Security → Health.

6Optional features, and what leaves your device

Only two things in the App ever send anything off your device: a barcode lookup, when you scan a product (§6.2), and product analytics, which stay off until you opt in (§6.4). The AI features (§6.1) and restaurant location (§6.3) never leave the device at all.

6.1 AI features run on your device

This version of Radical Fat Loss contains no cloud AI. Where your iPhone supports Apple's built-in on-device model, the coach and the type-a-meal parser run entirely on the device: the prompt, the summary of your numbers that grounds it, and the answer all stay on the phone. Nothing is transmitted, so there is nothing to consent to and no AI company receives anything about you. Where a device doesn't support the on-device model, those features are simply unavailable and the App says so rather than falling back to a server.

There is no way to enter an AI provider key in this version, and no meal-photo or menu-scan AI. If a cloud AI option is offered in a future version it will be off by default and gated behind explicit, fail-closed consent — and this policy will be updated before it ships (§2).

6.2 Barcode lookup

When you scan a product barcode, the app may query the open food database Open Food Facts to fetch nutrition information. Only the barcode number is sent — no personal data.

The app also downloads a public food-composition dataset to keep its offline food database current. That is a plain download: nothing about you is sent with it, and the request carries no identifier beyond what any HTTPS request necessarily reveals to the host (such as your IP address).

6.3 Restaurant logging & location

If you use restaurant meal logging, the app may use your approximate location (with your iOS location permission) to identify nearby restaurants. Location is used on the device only: it is matched against places you have logged before, is never sent to us or to any third party, and is not used to look anything up on a server. Arrival reminders, if you switch them on, are scheduled locally by iOS.

6.4 Product analytics (opt-in)

Analytics are local-only unless you opt in. If you opt in, the app sends minimal, privacy-preserving usage events — which features you use and where you hit friction — to our analytics processor, PostHog, on its EU-hosted infrastructure. These events never include your health data, food content, photos, or free text. You can opt out at any time in Settings.

The analytics identifier. So that the events from one installation hang together, they carry a random identifier the app generates on your device when analytics start. It is not your name, email, Apple ID, phone number, advertising identifier (IDFA) or any device serial number; it is not derived from your hardware or from anything you have told the app, and on its own it cannot identify you. We never call PostHog's "identify" function, so no person profile is created, and the identifier is never linked to your health profile, weight, food log or Apple Health data — none of which leave your device at all. It is not used to track you across other apps or websites. Withdrawing consent in Settings deletes the identifier together with any events still queued on the device, so a later opt-in begins from a new one; reinstalling the app also produces a new one. This is what the App Store privacy label reports as "Device ID — collected for Analytics, not linked to you, not used for tracking."

7What we never do

8This website

The Radical Health website is a static site. It sets no advertising cookies, runs no ad trackers, and does not track you across other websites.

For website analytics we use Mixpanel, configured to be cookieless and privacy-preserving so we can see which pages are useful and improve the site. Specifically, it: stores no cookies and no browser storage and assigns no persistent identifier (so your visits aren't linked across pages or sessions); does not use your IP address for geolocation; sends event data to Mixpanel's EU data-residency servers; and respects your browser's "Do Not Track" setting — when it is on, no analytics are loaded at all. Because this is cookieless and not used to identify you, we rely on our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving the site; you can opt out entirely by turning on Do Not Track.

As with any website, our hosting provider may keep short-lived technical server logs (such as IP addresses) for security and reliability; these are not used to profile you.

9Legal bases for processing (GDPR)

Where we rely on consent, you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.

10Processors & international transfers

We use a small number of service providers — for the optional app features above and for website analytics (§8):

ProviderPurposeLocation / transfer
Open Food FactsBarcode → product nutrition lookup (§6.2)EU (open database); only the barcode is sent
PostHogOpt-in product analytics (§6.4)EU-hosted; data stays in the EU/EEA
Mixpanel, Inc.Cookieless website analytics (§8)EU data residency — events stored in the EU; provider is US-based, with transfers safeguarded by Standard Contractual Clauses
AppleHealthKit, the on-device AI model, App Store deliveryProcessed on your device / under your Apple ID, per Apple's terms

11Retention

Because your app data lives on your device, we don't hold it and therefore don't retain it. It persists locally until you delete individual entries, or delete the app (which removes its local data). Backups you export are stored wherever you choose, under your control. Opt-in analytics data is retained by our analytics processor for 12 months; you can request its deletion via privacy@radicalhealth.app.

12Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to withdraw consent. Because your data is on your device, you can exercise most of these directly:

For any data held by us or our processors (for example, opt-in analytics), contact privacy@radicalhealth.app and we will respond within the time the GDPR requires (normally one month).

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee); you may also contact the authority in your own EU/EEA country.

13How we protect your data

14Children

Radical Fat Loss is not directed to children and is intended only for adults aged 18 or older. We do not knowingly process the data of anyone under 18. The app enforces this rather than merely stating it: when the date of birth on a profile is under 18, personalized weight-loss targets, fasting guidance, AI coaching and opt-in analytics are all switched off, so a minor's profile cannot send anything off the device. The app concerns weight and eating; it is not intended for anyone for whom that would be inappropriate (see also the in-app safety guidance). If you believe we hold data relating to someone under 18, contact privacy@radicalhealth.app and we will delete it.

15Changes to this policy

We may update this policy as the app evolves. We'll post the new version here with an updated effective date, and surface material changes in the app.

16Contact

Radical Health OÜ
Estonia · registry code 17536495
Privacy: privacy@radicalhealth.app