Privacy Policy
Effective Date: September 11, 2026
Website analytics and campaign links
On our public homepage and campaign landing pages, you can allow or decline website analytics using Privacy choices in the footer. If allowed, StatsKey records an anonymous browser visit identifier, campaign tags, page and section views, scroll milestones, public navigation clicks, video progress, device size category, and time spent viewing the page. These events help us understand how a campaign leads visitors through the website to an app-store choice. Visit records expire after 30 days and are removed by automatic retention cleanup. Aggregated campaign counts do not identify your StatsKey account.
This measurement does not record keystrokes, form contents, health records, private app screens, precise location, or recordings of your screen. Our Google Ads and Reddit advertising pixels also load only after you allow analytics on these pages. They may use cookies and similar identifiers under their own privacy policies. You can withdraw your choice at any time; browser privacy signals are respected. App stores report their own acquisition totals; a store click is not a confirmed installation.
1. Introduction
StatsKey ("StatsKey," "we," "us," or "our") operates a nutrition, fitness, and biometric tracking application. This Privacy Policy describes the information we collect, how we use and share it, and your choices. By using StatsKey you agree to the practices described here. If you do not agree, do not use the application.
2. Information We Collect
Account Information. Name (optional), email address, password (stored as a salted hash by Firebase Authentication when you sign up with email and password), federated sign-in identifiers (Apple ID or Google), and an internal user ID.
Age and Birthday Information. Birth year and birthday details you provide for your profile are private account data. We use them for age-appropriate setup, personalized features, and an in-app birthday greeting. We do not display your birthday on your public or Friends profile.
Social Profile & Friend Discovery. If you use Friends, we process the display name, username, optional profile picture, friend requests, blocks, reports, and any running goal you explicitly choose to show to friends. A phone number must be verified before it can be used for discovery and is never displayed on your profile. Verified phone numbers and emails are represented in a server-only keyed matching index rather than a public directory.
Selected Contacts. When you deliberately choose one person from Apple's system contact picker, StatsKey receives a one-time snapshot of that contact's selected phone numbers and email addresses solely to check for an opted-in StatsKey member or prepare an invitation. We do not request full address-book access, sync contacts in the background, or retain unmatched contact information.
Profile Pictures. A profile picture you select is cropped, resized, and re-encoded to remove embedded metadata such as location before upload. Google Cloud Vision SafeSearch processes the pending image to screen for objectionable content before it can be shown to other members.
Health & Fitness Data. Meals and nutrition entries, food photographs and text descriptions, exercise activities, durations, caloric estimates, weight and body metrics, custom goals, current and historical continuous glucose monitor (CGM) and glucose records, wellness logs, and — if you grant permission — Apple HealthKit (on iOS) or Android Health Connect (on Android) data (including but not limited to energy, macronutrients, weight, heart rate, glucose, and workout data).
Location Data. If you enable location services, we collect GPS data during active workout recording to track route, distance, pace, and elevation. Background location access occurs only while a workout session is in progress and ceases when the session ends or is paused. Separately, if you opt in to country-based food search, the app can use a foreground location fix and Apple’s geocoding service to determine your country. Nutrition services receive only the country code, not your coordinates or address. The country used for a food search can remain with that food’s record. Turning the option off clears the current country hint without changing existing food records.
Live Location sharing has been discontinued. StatsKey no longer accepts live-sharing location updates or makes previously shared locations available to friends. Previously stored latest-location, sharing-preference, and sharing-device records are not automatically deleted by this change. They remain protected account data under the retention policy in Section 9, and you can request access or deletion through Section 10. GPS workout recording remains available.
Subscription & Transaction Data. Purchase history, subscription status, billing channel (App Store, Google Play, or Stripe), Apple receipt tokens (for App Store subscriptions), Google Play purchase tokens (for Google Play subscriptions), Stripe customer and subscription identifiers (for web subscriptions), and limited device and application identifiers used for receipt validation, billing reconciliation, and fraud prevention. We do not store full payment card details; card data is processed and stored by Apple, Google, or Stripe.
Device & Usage Data. Device model, operating system version, application version, feature usage patterns, and performance event data.
Podcast Campaign Attribution Data. On designated public campaign pages, Podscribe may receive an IP address, user agent, device cookie identifier, page URL, referrer, and timestamp to measure podcast advertising performance. We do not send Podscribe meal, workout, glucose, wellness, Apple HealthKit, Android Health Connect, or other health and fitness records.
Diagnostics. Crash logs, error reports, and performance diagnostics.
Support Communications. Messages and attachments you send to our support channels.
3. How We Use Your Information
- Service delivery: Account creation, authentication, data synchronization, and core application functionality.
- AI-powered analysis: Processing food photographs, text descriptions, chat messages, and relevant historical health records, including glucose records, through third-party AI services to generate nutritional estimates, summaries, and conversational responses. These outputs are approximations only and should not be relied upon for medical, dietary, or clinical decisions.
- Personalization: Tailoring recommendations and goals based on your profile and historical data.
- Friends and safety: Resolving usernames and invitation links, matching a contact you deliberately select, delivering and responding to friend requests, enforcing blocks and sharing choices, moderating profile pictures, and reviewing abuse reports.
- Health integrations: Reading and/or writing Apple HealthKit (on iOS) or Android Health Connect (on Android) data strictly to power health and fitness features you explicitly enable, including using Apple Health or Health Connect as an optional source for glucose and other historical records.
- Analytics and quality: Understanding feature usage, diagnosing errors, and improving application performance.
- Campaign measurement: Measuring whether podcast advertising exposure leads to visits on designated public campaign pages, without using health and fitness records for advertising attribution.
- Security and fraud prevention: Validating purchases, preventing abuse, and protecting user accounts.
- Communications: Sending service-related notices (e.g., subscription status changes, material changes to terms). We may also send periodic product updates, tips, and promotional emails about StatsKey, and we will obtain your consent to do so where required by law. You can stop these at any time using the unsubscribe link included in every such email; service-related notices may still be sent as needed. HealthKit and glucose data are never used for marketing.
4. Apple HealthKit & Android Health Connect Disclosure
- Data accessed through Apple HealthKit (iOS) or Android Health Connect (Android) is used exclusively to provide or improve health and fitness features within the application, including importing historical glucose records when you grant the relevant Apple Health or Health Connect permission.
- This health data is never used for marketing, advertising, or data brokering and is never sold to any party.
- This health data is not shared with third parties except as necessary to process it on your behalf to provide the service, and never for independent use by those parties.
- Glucose and other health records that you choose to sync may be backed up to your StatsKey account using Firebase / Google Cloud Platform so they are available across devices and to enabled StatsKey features, including AI conversation features. Imported Apple clinical/FHIR records are handled as described below.
- You may revoke these permissions at any time through Apple Health settings (iOS) or Android Health Connect settings (Android). Revocation stops new data flows but does not automatically delete previously stored data — see Section 10 ("Your Rights").
Optional Apple clinical records. Clinical access is optional and is not required for food search or manual recording. If you grant Apple’s separate clinical-record permission and enable Private Sync for your StatsKey account on this installation, StatsKey copies the authorized records into your account. These may include allergies, conditions, immunizations, laboratory results, medications, procedures, vital signs, coverage, and clinical notes. The copy includes full provider FHIR content, which may identify you, together with dates and source information.
These imported clinical records are used to preserve your authorized health history and include it in complete-data exports you initiate. The clinical-record integration does not provide clinical interpretation or a dedicated clinical-record viewer, add these records to automatic Intelligence context, or share them through Friends or the clinician portal. You can choose to share an export yourself. Information you independently type, paste, or attach to an AI request is handled as content of that request under Section 5.
The account copy is stored in Google/Firebase Cloud Firestore in the United States. Normal app access requires signing in as the account owner. Google/Firebase provides the storage infrastructure, and StatsKey service identities or administrators with privileged cloud permissions can access the records. This is not end-to-end encryption against the service operator. The app may also retain records in its on-device Firestore cache and create local export files; the original records remain in Apple Health.
Enable this feature in Settings → Health & Body → Apple Health by granting access and separately choosing Enable and Sync for Private Sync. Turn Off Private Sync, Stop Using Apple Health, or revoking Apple Health permission stops new uploads from that installation while retaining existing copied history. Other installations have separate sync choices. Request deletion or delete your account using the controls and contact process in Sections 9, 10, and 12; files you export and share remain under your or the recipient’s control.
5. AI Processing
After your explicit permission, StatsKey may send relevant content for Intelligence chat, food photo analysis, nutrition-label scanning, fitness plans and nutrition insights to one or more of the AI processors below to build a private search index or compute a response.
- Google LLC — Gemini and Vertex AI. Google Privacy Policy.
- Anthropic, PBC — Claude, accessed through Anthropic's API. Anthropic Privacy Policy.
- OpenAI OpCo, LLC — ChatGPT models, accessed through the OpenAI API (including the Responses API for image-based food analysis fallback). OpenAI Privacy Policy.
- xAI Corp. — Grok, accessed through the xAI API. xAI Privacy Policy.
- Perplexity AI, Inc. — Sonar API for nutrition source retrieval, using relevant food descriptions, serving and ingredient details, nutrition evidence, and the optional country hint. Perplexity API Privacy & Security.
- Kimi — MOONSHOT AI PTE. LTD.
When you opt in, the country code used to find relevant food sources may also be sent with those food-search details. No coordinates or address are included in this nutrition hint.
Categories of personal content we may transmit to the providers above include: messages and prompts you type into the AI chat; photos you capture or pick for food / nutrition-label analysis; summaries of your nutrition, weight, hydration, supplement, and glucose logs; historical glucose records and related trends when relevant to your request; summaries of your workouts, pace, heart-rate, and training plan; and basic profile fields you provided in onboarding (name, biological sex, weight, height, goals). Depending on the feature and the sharing categories you enable, this may also include text extracted on-device from documents you explicitly attach to an Intelligence conversation, confirmed blood-panel values when you enable Blood Panels, and compact search-index summaries derived from enabled records.
Before we transmit any content to these processors for the first time, the app presents an in-app disclosure that names the processors and the categories of content above and asks you to grant permission. You can review or revoke this permission at any time from Settings → Privacy → Intelligence Features. Revoking permission disables every AI-powered feature in the app while leaving the rest of the app fully functional. Accepting account terms alone does not enable AI sharing.
StatsKey stores compact derived search-index summaries in your account and can refresh them after enabled records change. Disabling Intelligence requests deletion of that derived index; your saved source records remain available under this policy.
- We do not automatically add your account identifiers or contact details to AI content. Your disclosed profile information may include your name, and content you choose to share may itself identify you.
- AI-generated outputs are estimates and approximations. They may be inaccurate, incomplete, or incorrect. You should not rely on them for medical, clinical, or critical dietary decisions.
- We do not opt in to having your data used to train third-party AI models. Providers may temporarily retain data for abuse prevention and diagnostics in accordance with their respective policies.
- The set of AI providers, the specific models used, and the routing between them may change. Material changes to this list will trigger a new in-app disclosure prompt before the new provider receives any of your content.
Optional Exercise Videos
StatsKey uses YouTube API Services to find exercise technique videos after you enable this optional feature. It is available only to eligible accounts aged 13 or older. We send the exercise name to YouTube through our server; we do not send your account identifier, workout log, sets, weights, heart rate, or other recorded health data with the search. Video titles, channel names, and video identifiers may be cached for up to 24 hours. We do not request access to your YouTube account or upload your private workout clips to YouTube.
When the embedded YouTube player loads, YouTube receives connection and device information needed to display the player and may collect playback information, use cookies or similar technology, and serve third-party content, including advertisements. StatsKey uses YouTube's privacy-enhanced player and does not start playback automatically. You can disable exercise videos in the app to stop new searches and player loads.
These videos are subject to the YouTube Terms of Service and Google Privacy Policy. Contact us using the details below with questions about StatsKey's use of this feature.
6. Third-Party Service Providers
We use the following categories of service providers to operate the application:
- Firebase / Google Cloud Platform: Authentication, secure data storage, including synced historical glucose records, analytics, and crash reporting.
- Apple App Store: Subscription billing for users who subscribe through the iOS app.
- Google Play: Subscription billing for users who subscribe through the Android app.
- Stripe: Subscription billing and payment processing for users who subscribe through the website. Stripe receives card details, billing address, and an opaque user identifier; we receive only customer and subscription IDs and high-level status.
- AI Providers (Google Gemini / Vertex AI, Anthropic Claude, OpenAI ChatGPT, xAI Grok, Kimi, Perplexity Sonar): AI-powered food analysis, nutrition estimation, training plan generation, and conversational features. See Section 5 for the per-provider links and the in-app permission flow.
- Apple HealthKit & Android Health Connect: Optional health data synchronization with your explicit permission.
- CGM Providers (Dexcom, Abbott, Nightscout): Optional continuous glucose monitor data integration with your explicit permission.
- Nutrition data sources: Public or licensed databases to enrich nutritional information. We transmit only food context, not personal identifiers.
- Podscribe: Podcast campaign delivery measurement and attribution on designated public campaign pages. Podscribe receives limited device, network, and page-event data for this purpose and does not receive health and fitness records. See the Podscribe Privacy Policy.
All processors are required to protect your information and use it only in accordance with our instructions and applicable law.
7. Data Sharing
No public disclosure. StatsKey and its founder will not publish or otherwise publicly share your location data or wellness, health, or fitness information that identifies you or could reasonably be linked to you. This includes public posts, advertising, demonstrations, and case studies. You may still choose to share your own data privately with people you select. Necessary processing by service providers and disclosures required by law remain governed by our Privacy Policy.
- No sale: We do not sell your personal data. We do not share data with third parties for cross-context behavioral advertising.
- Service providers: Shared only as necessary to provide the application, subject to confidentiality and security obligations.
- Legal compliance: We may disclose information if required by law, subpoena, court order, or governmental request, or if we believe in good faith that disclosure is necessary to protect rights, safety, or property.
- Aggregated data: We may share non-identifiable, aggregated statistics that cannot reasonably be linked to any individual.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
8. Data Security
We employ encryption in transit (TLS) and at rest, access controls, least-privilege principles, and industry-standard security practices. However, no method of electronic transmission or storage is completely secure. We cannot and do not guarantee absolute security of your data. You use the application and transmit information at your own risk.
9. Data Retention
- Account data: Retained while your account is active. Requesting account deletion starts a 30-day recovery period. After that period expires, the daily cleanup removes active account data, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, financial records).
- Recovery copies and local files: Firestore recovery versions and backups expire separately from active account data: point-in-time recovery and daily backups are retained for seven days, and weekly backups for 98 days. Turning off sync or requesting account deletion does not instantly remove recovery copies, the app’s local cache, or files you or a recipient have exported.
- Purchase records: Retained as required for financial, audit, and fraud-prevention obligations.
- Analytics and diagnostics: Typically retained up to 24 months unless longer retention is required for security or legal compliance.
- You may delete individual entries (meals, workouts, photos) within the application at any time.
10. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data.
- Export your data in a common, machine-readable format.
- Withdraw consent (e.g., HealthKit permissions, location services).
- Opt out of non-essential analytics where available.
To exercise these rights, use in-app settings or contact us at the address below. We may need to verify your identity before processing a request and may decline requests where permitted by applicable law.
11. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including:
- The right to know what personal information is collected, used, shared, or sold.
- The right to delete personal information held by us.
- The right to opt out of the sale or sharing of personal information. We do not sell personal information.
- The right to non-discrimination for exercising your privacy rights.
12. Consumer Health Data (Washington, Nevada, Connecticut, and similar laws)
If you are a resident of a state with a consumer health data law — including the Washington My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut Data Privacy Act (as amended) — this section describes the additional categories of information we treat as "consumer health data" and your rights with respect to that information. Glucose values, continuous glucose monitor (CGM) records, and related metabolic data are treated as consumer health data under this Privacy Policy regardless of your state of residence.
Categories of consumer health data we collect. Glucose readings and CGM trend data (current and historical, whether imported from Apple Health, Android Health Connect, Dexcom Share, Abbott LibreLinkUp, Nightscout, or entered manually); food, beverage, supplement, and hydration logs that may reveal health condition or treatment patterns; weight, body composition, and biometric measurements; symptoms, energy, mood, sleep, and wellness logs; workout, heart rate, and other physical activity records; and any other information you provide that identifies your past, present, or future physical or mental health status, conditions, or treatments.
How we use it. Consumer health data is processed only to (i) provide the application features you have explicitly enabled, (ii) sync your data across your devices, (iii) generate the personal nutrition, wellness, and AI summaries you request, and (iv) maintain account security and prevent abuse. We do not sell consumer health data, share it with third parties for cross-context behavioral advertising, or use it to target advertising on our behalf or anyone else's behalf.
Sharing. Consumer health data is disclosed only to the processors described in Sections 5 and 6 (Firebase / Google Cloud Platform for secure storage, AI providers when you actively use AI features, and Stripe / Apple for billing — none of which receive raw glucose data for the purpose of training models on you), and only as required to provide the application or comply with applicable law.
Your rights. You have the right to (a) confirm whether we are collecting, sharing, or selling your consumer health data and access that data, (b) withdraw consent for our collection and sharing of consumer health data, (c) have your consumer health data deleted, including from our processors that hold the data on our behalf, and (d) appeal a decision we make about your request. We do not sell consumer health data, so there is no separate opt-out of sale to exercise. To exercise these rights, contact us at ryanws@statskeybiometrics.com; we will respond within the timeframes required by the applicable state law. If we deny a request, you may appeal by replying to that decision with the word "Appeal" in the subject line, and you may also file a complaint with the attorney general of your state of residence.
Geofencing. StatsKey does not use geofences around any healthcare facility, mental health facility, reproductive health facility, or similar location.
Authorization for sharing. We do not share or sell consumer health data without your prior written authorization. If you connect a CGM or HealthKit integration, you are authorizing StatsKey to retrieve and process consumer health data from that source to provide the application features you have enabled, and to store that data in your StatsKey account until you delete it. Turning off an integration in the app or revoking its device permissions stops new retrieval from that installation; it does not by itself delete previously stored account data. To withdraw consent for our ongoing collection or sharing, or to request deletion of consumer health data, contact us using the process above. Account deletion is also available in Settings. We process these requests under the rights and retention provisions in Sections 9, 10, and this section.
13. EEA/UK Residents (GDPR)
Our legal bases for processing personal data include:
- Contract: To provide the application and fulfill our agreement with you.
- Consent: For HealthKit or Health Connect access, location services, and certain analytics.
- Legitimate interests: Application safety, fraud prevention, quality improvement — balanced against your rights.
- Legal obligation: Compliance with applicable laws.
We may process and store data in the United States and other countries. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) for international transfers.
14. Children's Privacy
StatsKey is not directed to children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
15. Camera & Photos
- Camera access is used solely to capture meal photographs you choose to log.
- Photographs are processed to identify foods and generate nutritional estimates.
- Original photographs remain on your device unless you choose to synchronize them with the application.
- We do not access your photo library without your explicit permission.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the application or by other reasonable means. Your continued use of StatsKey after the effective date of any changes constitutes your acceptance of the updated policy.
17. Contact
If you have questions about this Privacy Policy or wish to exercise your rights: