Privacy Policy
Last updated: May 24, 2026
1. Introduction
FitLifeBud ("FitLifeBud", "we", "our", or "us") is an AI-powered nutrition and meal-planning service. This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile applications (iOS and Android), our website, and related services (together, the "Service").
The Service is operated by FitLifeBud, with its registered office at Vilnius, Lithuania. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller responsible for your personal data.
Please read this policy carefully. If you do not agree with it, please do not use the Service. The Service is intended for users aged 16 and over (see Section 11).
2. Information We Collect
Account information. When you register, we collect your name, email address, and password. If you sign in with Google, we receive your basic Google profile and email.
Health and fitness data (special category data).To generate your plans we collect data you provide about your body and health, which may include height, weight, age, fitness and weight goals, dietary restrictions, food preferences (liked and disliked foods), exercise routines, and information about eating disorders or other health conditions you choose to enter. Under GDPR Article 9, data concerning your health is "special category" data, which we process only on the basis of your explicit consent (see Section 4).
Service content. Your generated meal plans, nutritional information, logged or eaten meals, and streak and progress data.
Subscription and purchase information. If you subscribe, the purchase is processed by the Apple App Store or Google Play and managed through RevenueCat. We receive your subscription status, tier, and renewal/expiry information. We do not receive or store your full payment card details.
Device and push-notification data. If you enable notifications, we store a device token, device identifier, and device type (iOS, Android, or Web) to deliver push notifications.
Usage and technical data. We automatically collect certain information when you use the Service, including IP address, device and browser type, app interactions, and diagnostic logs.
Early-access / waitlist data. If you join our waitlist or request early access on our website, we collect your email address. No payment is taken for early access.
Cookies. Our website uses strictly necessary cookies to keep you signed in and secure your session. We do not use these cookies for advertising.
3. How We Use Your Information & Legal Bases
We use your information for the following purposes. Where GDPR applies, the legal basis for each purpose is shown in brackets.
- Create and manage your account and provide the Service [performance of a contract].
- Generate personalized meal plans and recommendations from your health and preference data [your explicit consent].
- Process and manage your subscription [performance of a contract].
- Send push notifications, reminders, and service messages [consent; or legitimate interests for essential service messages].
- Maintain security, prevent fraud and abuse, and debug the Service [legitimate interests].
- Improve and analyze the Service [legitimate interests], and comply with legal obligations [legal obligation].
Where we rely on consent, you can withdraw it at any time (see Section 9); this does not affect processing carried out before withdrawal.
4. AI Processing of Your Data
FitLifeBud uses artificial intelligence to generate your meal plans and recommendations. To do this, the information you provide — including your dietary restrictions, food preferences, exercise routines, and any health conditions or eating-disorder information you enter — is sent to our AI service providers, which process it on our behalf to return a generated plan.
We rely on your explicit consent to process health (special category) data for this purpose. Under our agreements with these providers, your data is processed only to provide the response and is not used to train their models.
AI-generated content may be inaccurate or incomplete and is not medical or nutritional advice. Please review our Terms and Conditions for the medical and AI-accuracy disclaimers.
5. How We Share Your Information
We do not sell your personal information. We share it only with the service providers (sub-processors) that help us operate the Service, and where required by law:
- Cloud infrastructure provider — hosting our application, database, and backups in the European Union (Belgium).
- Authentication and database provider — managing your account and stored data.
- AI service providers — generating meal plans on our behalf (United States).
- Mobile app store platforms — subscription and payment processing.
- Push notification and sign-in providers — sending you notifications and supporting third-party sign-in.
- Legal and safety — public authorities or advisers where required by law or to protect our rights and users.
- Business transfers — a successor entity in connection with a merger, acquisition, or sale of assets.
6. International Data Transfers
Our application, database, and backups are hosted in the European Union (Belgium), so this data is stored within the European Economic Area. However, some of our sub-processors — including the AI language model providers that generate your meal plans and certain other service providers — are located in the United States, so the data we share with them is transferred outside the EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. You may request a copy of the safeguards we use by contacting us.
7. Data Retention
We retain your personal data for as long as your account is active and as needed to provide the Service. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements. Residual copies may persist in encrypted backups for up to 14 days before being automatically deleted. You can delete your account at any time from the account deletion page.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit and at rest, access controls, and a web application firewall. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your password protects your account; it is your responsibility to keep it confidential.
9. Your Rights (EU / EEA / UK)
If you are in the EU, EEA, or UK, you have the following rights regarding your personal data:
- Access a copy of your personal data;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time;
- Lodge a complaint with your supervisory authority. Our lead supervisory authority is the State Data Protection Inspectorate.
To exercise these rights, contact us using the details in Section 13.
10. Your Rights (California / United States)
If you are a California resident, the CCPA/CPRA gives you the right to:
- Know what personal information we collect and how we use it;
- Access and delete your personal information;
- Correct inaccurate personal information;
- Opt out of the "sale" or "sharing" of personal information — we do not sell or share your personal information as those terms are defined under California law;
- Not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us using the details in Section 13.
11. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date above. For material changes, we may provide additional notice.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact our data controller, FitLifeBud, at:
info@fitlifebud.com
Vilnius, Lithuania