Privacy Policy
The short version
- Radical Fat Loss is local-first: your profile, food logs, weight and the health data the app reads from Apple Health live on your device. Your app content also syncs privately through your own iCloud so it's on your other devices and comes back after a reinstall — sensitive fields end-to-end encrypted, and the data read from Apple Health is kept out of iCloud (§4). We don't run a server that stores any of it.
- We never sell your data, never use it for advertising, and don't track you across other apps or websites.
- AI runs on your iPhone where the hardware supports it. Cloud AI is optional and off until you turn it on, and it uses your own API key: it sends only the content of the action you take (a meal photo, a food description, a coach message with the numbers that ground it) directly to the AI provider, Anthropic, under your own account — we run no server in that path and never see it.
- Radical Fat Loss is a membership, billed by Apple. When you claim an earned rate, the app sends one request to our signing service carrying only your subscription's purchase details — never your health data, and never how you've trained; whether you've earned the rate is worked out on your device (§6.5).
- You stay in control: edit or delete anything in the app, export a backup, or delete the app to remove your local data.
1Who we are
The data controller for Radical Fat Loss and this website is Radical Health OÜ (Estonian registry code 17536495), located in Estonia ("we", "us", "Radical Health").
For any privacy question, or to exercise your rights, contact us at privacy@radicalhealth.app.
2What this policy covers
This policy explains how the Radical Fat Loss app and the Radical Health website handle personal data, the legal bases we rely on under the EU General Data Protection Regulation (GDPR), and your rights. It reflects the app as designed at the effective date above; if we change how data flows (for example, by enabling cloud sync), we will update this policy first.
3Our privacy model
Radical Fat Loss is built around a simple principle: your data is yours and lives with you, not with us. It originates and lives on your device; most of the app — logging, targets, fasting, trends, the coach's deterministic insights, and the Apple Watch and widget views — works entirely on-device with no network connection and no account. Your app content additionally syncs through your own private iCloud (Apple's CloudKit) under your Apple ID, so it reaches your other devices and survives a reinstall; this is your iCloud, not a service we run, and you can turn it off in iOS Settings (§4). Data read from Apple Health is deliberately excluded from that sync (§5).
We do not operate a database that holds your health or weight data — your synced content sits in your iCloud, which we cannot read. There is, by design, very little for us to "have": even the membership signing service that applies an earned rate (§6.5) is stateless, keeping no record of you, and your eligibility for that rate is computed on your device and never uploaded.
4The data the app handles, and where it lives
The following is created and stored locally on your device (using Apple's on-device SwiftData storage). It is not transmitted to us:
| Category | Examples | Where it lives |
|---|---|---|
| Profile & settings | Age, biological sex, height, goal weight, diet/mode preferences, your stated "reason," app toggles | On device + your private iCloud (sensitive fields end-to-end encrypted) |
| Food & nutrition | Logged meals and macros, meal photos, scanned barcodes, eating-window/fasting history, saved foods | On device + your private iCloud (sensitive fields end-to-end encrypted) |
| Body metrics | Weight and waist you enter, and progress photos (if you add them) | On device + your private iCloud (end-to-end encrypted) |
| Health & activity | Data read from Apple Health (see §5) and the insights derived from it — trends, recovery, projections, weight/body-fat history | On device only — never put in iCloud by us (Apple Health syncs its own data) |
| AI key | If you use cloud AI with your own key, the API key you provide | Device Keychain (may sync via your iCloud Keychain, under your Apple ID) |
| Membership claim request | If you claim an earned rate: the subscription plan/offer being claimed, a random membership identifier, and Apple's app transaction ID (§6.5) | Sent to our stateless signer only at the moment you claim — not stored on any server; the identifier lives in your device Keychain |
We have no account system and assign no advertising or cross-app tracking identifier. We receive at most two identifiers, each random and generated on your device: the per-installation analytics identifier (§6.4, only if you opt in to analytics) and a membership identifier (§6.5, only if you subscribe and claim an earned rate). They are never linked to each other — neither is derived from you or your hardware, and nothing connects one to the other. Your app content syncs through your own Apple iCloud account (Apple's CloudKit private database), under your Apple ID and Apple's terms — not a cloud service we operate, and not something we can read: sensitive fields are end-to-end encrypted, so their keys stay in your Apple account and Apple cannot read them either. The data the app reads from Apple Health (the "Health & activity" row above) is deliberately excluded from this sync. You control it in iOS Settings → [your name] → iCloud, and it uses your iCloud storage.
5Apple Health (HealthKit)
With your permission — granted per data type in iOS — the app reads health and activity data from Apple Health to power its features, including: steps and walking metrics, body mass, body-fat %, lean body mass, height, sleep analysis, heart-rate variability, resting and active heart rate, respiratory rate, sleeping wrist temperature, active and basal energy, workouts, VO₂ max, time in daylight, dietary sodium, mindful sessions, date of birth and biological sex. Some types are requested only if you use the related feature — for example menstrual-cycle data, blood glucose (when a CGM writes it to Health), and mood ("State of Mind").
With your permission, the app writes the following back to Apple Health: the four macros for meals you log, water and sodium intake, completed walks/workouts, and a mindful-session record for the in-app breathing prompt.
6Optional features, and what leaves your device
Four things in the App send data to us or a third party, and each is in your hands: the optional cloud AI features, which are off until you enable them (§6.1); a barcode lookup, when you scan a product (§6.2); product analytics, which stay off until you opt in (§6.4); and, if you subscribe, a membership claim request when you apply an earned rate (§6.5). Separately, your app content — including any restaurant location you save (§6.3) — syncs to your own iCloud (§4); that is your data in your own Apple account, handled by Apple under your agreement with them (§10), not data we share with anyone for our own purposes. Restaurant location is never sent to us or looked up on a server.
6.1 AI: on your device by default, in the cloud only if you enable it
Where your iPhone supports Apple's built-in on-device model, the coach and the type-a-meal parser can run entirely on the device: the prompt, the summary of your numbers that grounds it, and the answer all stay on the phone, and no AI company receives anything about you.
Cloud AI is optional and off by default. If you enable it, then — only for the action you take — the relevant content is sent over an encrypted connection to the AI provider, Anthropic, PBC (United States), to generate a response. Depending on the feature, that content may include: a meal or menu photo (with the restaurant name, if you typed one), a text or voice description of food, your message to the coach, and/or a summary of your numbers (such as targets, today's totals, recent history and weight trend) used to ground the answer. This happens only after a one-time, explicit, full-screen consent per feature area, which you can withdraw at any time in the app's Settings; until you consent, the app fails closed — nothing is sent. Cloud AI is unavailable on profiles under 18 (§14). Anthropic's commercial/API terms state that inputs and outputs submitted through the API are not used to train its models.
Cloud AI uses your own API key: you paste a key from your own Anthropic account, and the app talks to Anthropic directly — no server of ours is involved, we receive nothing, and your use of the AI service is also governed by your own agreement with Anthropic. The key is stored in your device's Keychain (§13). Without a key, every AI feature runs on the on-device model or a manual path, and nothing AI-shaped leaves your device.
6.2 Barcode lookup
When you scan a product barcode, the app may query the open food database Open Food Facts to fetch nutrition information. Only the barcode number is sent — no personal data.
The app also downloads a public food-composition dataset to keep its offline food database current. That is a plain download: nothing about you is sent with it, and the request carries no identifier beyond what any HTTPS request necessarily reveals to the host (such as your IP address).
6.3 Restaurant logging & location
If you use restaurant meal logging, the app may use your approximate location (with your iOS location permission) to identify nearby restaurants. Location is used on the device only: it is matched against places you have logged before, is never sent to us or to any third party, and is not used to look anything up on a server. Arrival reminders, if you switch them on, are scheduled locally by iOS. (A restaurant name you type yourself can accompany a menu photo you send to cloud AI — that is part of §6.1, not your device location.)
6.4 Product analytics (opt-in)
Analytics are local-only unless you opt in. If you opt in, the app sends minimal, privacy-preserving usage events — which features you use and where you hit friction — to our analytics processor, PostHog, on its EU-hosted infrastructure. These events never include your health data, food content, photos, or free text. You can opt out at any time in Settings.
The analytics identifier. So that the events from one installation hang together, they carry a random identifier the app generates on your device when analytics start. It is not your name, email, Apple ID, phone number, advertising identifier (IDFA) or any device serial number; it is not derived from your hardware or from anything you have told the app, and on its own it cannot identify you. We never call PostHog's "identify" function, so no person profile is created, and the identifier is never linked to your health profile, weight, food log or Apple Health data — none of which leave your device at all. It is not used to track you across other apps or websites. Withdrawing consent in Settings deletes the identifier together with any events still queued on the device, so a later opt-in begins from a new one; reinstalling the app also produces a new one. This is what the App Store privacy label reports as "Device ID — collected for Analytics, not linked to you, not used for tracking."
6.5 Membership & earning your rate
Radical Fat Loss is a paid membership. The subscription is sold and billed by Apple — we never see or handle your payment details. Whether you qualify for the lower Active rate (Terms §6) is worked out entirely on your device, by counting your own active days from your own log; that count, and the fact of whether you trained, never leave your phone.
The only thing that leaves your device is the moment you apply an earned rate. When you tap to claim it, the app sends one request to our signing service (offersign.radicalhealth.app, run on Cloudflare) carrying only three things: the subscription product and offer you are claiming, a random membership identifier (a UUID your device generates and keeps in its Keychain, used only to rate-limit requests), and Apple's app transaction ID for your purchase. That is purchase state only — no health data, no food logs, no weight, no messages, and nothing about how or whether you have trained.
The service signs the offer so Apple will honour it, then returns it; Apple applies the lower rate at your next renewal. The signer is stateless — it stores nothing about you or your request (it keeps only short-lived, in-memory counters to rate-limit abuse). There is no account and no server-side membership record: the trial, the meter, and your eligibility all live on your device.
7What we never do
- We never sell your personal data.
- We never use your data — including Apple Health data — for third-party advertising.
- We use no advertising SDKs and perform no cross-app or cross-site tracking (no IDFA / App Tracking Transparency tracking).
- We send no push notifications from a server — all reminders are scheduled locally on your device.
- We never store the content of your AI requests — with your own key they go directly to Anthropic and never touch a server of ours.
- Our membership signer never receives your health data or how you've trained — only your subscription's purchase details, and it stores nothing (§6.5).
8This website
The Radical Health website is a static site. It sets no advertising cookies, runs no ad trackers, and does not track you across other websites.
For website analytics we use Mixpanel, configured to be cookieless and privacy-preserving so we can see which pages are useful and improve the site. Specifically, it: stores no cookies and no browser storage and assigns no persistent identifier (so your visits aren't linked across pages or sessions); does not use your IP address for geolocation; sends event data to Mixpanel's EU data-residency servers; and respects your browser's "Do Not Track" setting — when it is on, no analytics are loaded at all. Because this is cookieless and not used to identify you, we rely on our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving the site; you can opt out entirely by turning on Do Not Track.
As with any website, our hosting provider may keep short-lived technical server logs (such as IP addresses) for security and reliability; these are not used to profile you.
9Legal bases for processing (GDPR)
- To provide the features you request (on-device app functionality, and syncing your content through your own iCloud so it reaches your devices): performance of a contract with you (Art. 6(1)(b)) and our legitimate interest in providing a working product (Art. 6(1)(f)). The iCloud sync runs in your own Apple account under Apple's terms; you can switch it off in iOS Settings.
- Health and other special-category data: processed on your device under your control; where processing it requires a basis, your explicit consent (Art. 9(2)(a)).
- Optional features that transmit data (cloud AI, barcode lookup, analytics): your consent (Art. 6(1)(a)) — and your explicit consent (Art. 9(2)(a)) for any health-related content you choose to send through cloud AI.
- The membership (§6.5): performance of a contract with you (Art. 6(1)(b)) — providing the subscription and applying the rate you've earned is what you buy. Apple processes the payment; whether you qualify for the Active rate is computed on your device, so we process no engagement or health data to bill you. Our legitimate interest (Art. 6(1)(f)) covers rate-limiting the signing service against abuse.
Where we rely on consent, you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.
10Processors & international transfers
We use a small number of service providers — for the optional app features above and for website analytics (§8):
| Provider | Purpose | Location / transfer |
|---|---|---|
| Anthropic, PBC | Cloud AI responses (§6.1) — coach, photo and menu reading, food parsing | United States — cloud AI uses your own API key, so the app talks to Anthropic directly under your own agreement with them; we are not the data exporter and receive nothing |
| Cloudflare, Inc. | Signs the promotional offer that applies your earned membership rate (§6.5) | Stateless worker at offersign.radicalhealth.app; receives only your subscription's purchase details at the moment you claim and stores nothing (short-lived in-memory rate-limit counters only); provider is US-based |
| Open Food Facts | Barcode → product nutrition lookup (§6.2) | EU (open database); only the barcode is sent |
| PostHog | Opt-in product analytics (§6.4) | EU-hosted; data stays in the EU/EEA |
| Mixpanel, Inc. | Cookieless website analytics (§8) | EU data residency — events stored in the EU; provider is US-based, with transfers safeguarded by Standard Contractual Clauses |
| Apple | HealthKit, the on-device AI model, App Store delivery, auto-renewable subscription billing for the membership (§6.5), and iCloud (CloudKit) sync of your app content (§4) | Under your own Apple ID and Apple's terms — iCloud sync runs in your account, with sensitive fields end-to-end encrypted so Apple cannot read them; Apple handles payment and we never see your payment details |
11Retention
Your app data lives on your device, so we don't hold it and therefore don't retain it. It persists locally until you delete individual entries, or delete the app (which removes its local data). Content that syncs to your iCloud (§4) is retained by Apple in your account under your control — it persists across your devices until you delete it in the app (which removes it everywhere it has synced) or manage it in iOS Settings → [your name] → iCloud; we cannot retain or delete it for you because it is in your account, not ours. Backups you export are stored wherever you choose, under your control. Opt-in analytics data is retained by our analytics processor for 12 months; you can request its deletion via privacy@radicalhealth.app.
The membership adds nothing that we retain: Apple keeps your subscription and billing records under your Apple ID (not us), our earned-rate signing service stores nothing (§6.5), and whether you've earned the rate is computed on your device and never uploaded. There is no server-side membership record for us to keep — or to delete.
12Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to withdraw consent. Because your data is on your device, you can exercise most of these directly:
- Access & rectification — view and edit any entry in the app.
- Erasure — delete entries in-app, or delete the app to remove all local data.
- Portability — export your data as a backup file from the app.
- Consent — turn cloud AI, location features or analytics off at any time in the app's Settings.
- Membership — manage or cancel your subscription any time in your Apple settings (Terms §6). We hold no membership record to access or erase: the signer stores nothing and your eligibility is computed on your device (§6.5).
For any data held by us or our processors (for example, opt-in analytics), contact privacy@radicalhealth.app and we will respond within the time the GDPR requires (normally one month).
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee); you may also contact the authority in your own EU/EEA country.
13How we protect your data
- Local-first storage keeps personal data on your device rather than on our servers.
- Content that syncs to iCloud goes to your own private CloudKit database, with sensitive fields marked for end-to-end encryption — their keys live in your Apple account, so neither Apple nor we can read them. Data read from Apple Health is excluded from this sync entirely.
- Backups you export can be encrypted with a passphrase you choose.
- Your AI key (if you use one) and your membership identifier are held in the iOS Keychain.
- Cloud AI is gated by explicit, fail-closed consent, and every request the App makes — AI, barcode lookup, analytics, and the membership claim request (§6.5) — uses encrypted (HTTPS/TLS) connections.
- We minimise what leaves your device by design. No method is perfectly secure, but the less we transmit and the less we store, the less is ever at risk.
14Children
Radical Fat Loss is not directed to children and is intended only for adults aged 18 or older. We do not knowingly process the data of anyone under 18. The app enforces this rather than merely stating it: when the date of birth on a profile is under 18, personalized weight-loss targets, fasting guidance, cloud AI, AI coaching and opt-in analytics are all switched off, so a minor's profile sends no personal content to us or to any third party. (iCloud sync, if the device uses iCloud, keeps that content inside the young person's own Apple account, exactly like a normal device backup — it does not send it to us.) The app concerns weight and eating; it is not intended for anyone for whom that would be inappropriate (see also the in-app safety guidance). If you believe we hold data relating to someone under 18, contact privacy@radicalhealth.app and we will delete it.
15Changes to this policy
We may update this policy as the app evolves. We'll post the new version here with an updated effective date, and surface material changes in the app.
16Contact
Radical Health OÜ
Estonia · registry code 17536495
Privacy: privacy@radicalhealth.app