Privacy Policy · Updated July 17, 2026

Privacy Policy

This page is maintained by MetaFast to answer common privacy questions about the MetaFast web app and the MetaFast iOS app.

What we collect

When you create an account, we store your email address and, optionally, a display name and avatar. When you use the app, we store the data you enter — meals, macros, fasting sessions, workouts, weight and body-composition entries, hydration logs, goals, and preferences — so we can show it back to you across devices.

We use a secure managed backend (Lovable Cloud, backed by Supabase) to store this data. Row-level security policies restrict every row to the account that created it.

Apple Health (HealthKit) data

If you use the MetaFast iOS app and tap Connect Apple Health, iOS asks your permission to share specific Health data types with MetaFast. You control which types are shared in the iOS Settings → Privacy & Security → Health → MetaFast screen, and you can revoke access at any time.

MetaFast requests read-only access to the following data types:

  • Body Mass (weight)
  • Body Fat Percentage
  • Steps
  • Active Energy Burned
  • Sleep Analysis
  • Workouts (type, duration, energy burned)

MetaFast does not write to Apple Health, does not request access to Clinical Health Records, and does not read any Health data type not listed above.

Health data is used to power features you see in the app: your weight trend, metabolic score, plateau detection, workout history, and daily activity summary. Health data is stored in your MetaFast account so those views work on other devices you sign into. Health data is never sold, never shared with advertisers or data brokers, never used for advertising or marketing, and never shared with third parties for their own purposes.

Health data is not sent to any third-party analytics service. It is only shared with AI features (for example, the AI coach and plateau insights) when you explicitly trigger a feature that needs it, and only the specific metrics required for that feature are sent to the AI provider that request.

AI features

Features like AI food logging (photo/voice), meal suggestions, coach chat, and weekly reviews send the data required for that request (for example, a food photo or your recent macro totals) to an AI provider via the Lovable AI Gateway. Requests are used only to generate your response and are not used to train third-party models.

Third-party services we use

  • Lovable Cloud / Supabase — authentication, database, storage.
  • Lovable AI Gateway — routes AI requests to language and vision models.
  • Google Sign-In — optional; used only if you choose "Continue with Google" on the sign-in screen.
  • Apple HealthKit — on iOS, if you connect it. Data flows from iOS to MetaFast, never the other direction.

Your rights and controls

  • Access & export. Contact us and we will provide a copy of your data.
  • Delete your account. Contact us at the address below to permanently delete your account and associated data.
  • Revoke Apple Health access. iOS Settings → Privacy & Security → Health → MetaFast. This stops future syncing immediately.
  • Disconnect Google. Revoke access in your Google Account settings.

Data retention

We retain your data for as long as your account exists. When you delete your account, we delete your personal data within 30 days, except where we are legally required to retain limited records (such as payment/transaction records).

Children

MetaFast is not directed to children under 13, and we do not knowingly collect data from children under 13.

Changes to this policy

We may update this policy from time to time. The "Updated" date at the top of this page reflects the latest revision. Material changes will be communicated in-app.

Contact

Questions or data requests: privacy@metafast.org

© 2026 MetaFast. All rights reserved.