Privacy Policy

Last updated: 15 September 2026

This privacy policy explains how RemoFitness ("Remo", "we") processes personal data when you use our website at remofitness.com, the Remo app, or related services. Remo is a fitness and healthy-lifestyle coaching app. The app connects your diet, exercise and sleep data and turns it into personalized, partly AI-generated guidance. Remo is not a medical device, does not provide diagnoses, and does not replace medical, psychotherapeutic or clinical nutrition advice.

1. Data controller

The controller responsible for processing your personal data is:

RemoFitness Legal representative: Florian Schrödter Hardturmstrasse 161 8005 Zurich Switzerland Email: hello@remofitness.com

You can also send privacy-related requests to this email address.

We will appoint an EU representative under Art. 27 GDPR once we actively offer Remo in Germany or Austria.

2. Scope and legal bases

Processing by the Switzerland-based controller is governed in particular by the Swiss Federal Act on Data Protection (FADP). To the extent we offer goods or services to, or monitor the behavior of, people in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) applies in addition.

Under the GDPR, we rely in particular on the following legal bases:

  • performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
  • your consent (Art. 6(1)(a) GDPR)
  • for health data or other special categories, additionally your explicit consent (Art. 9(2)(a) GDPR)
  • compliance with a legal obligation (Art. 6(1)(c) GDPR)
  • our legitimate interests, in particular in the secure, reliable and economical operation of our services and in privacy-friendly usage measurement (Art. 6(1)(f) GDPR)

Where processing is based on a balancing of interests, you can request further information about that balancing and object on grounds arising from your particular situation.

3. What personal data we process

Depending on the features you use, we process the following data:

3.1 Account and profile basics

  • name or display name, email address and internal user ID
  • password hash, login and security tokens
  • language, timezone and preferred units
  • account status, consent records and settings

We never store your password in plain text.

3.2 Profile, fitness and health data

  • your chosen goal, e.g. fat loss, muscle gain, endurance, general fitness or better sleep
  • age, sex assigned at birth, height, current weight and optional target weight
  • activity level, training frequency and available equipment
  • diet type, eating habits, allergies and intolerances
  • injuries, movement limitations and other health circumstances you share with us
  • your preferred coaching and motivation tone
  • values and targets calculated from the above, e.g. basal metabolic rate (BMR), total daily energy expenditure (TDEE) and macro targets

This information may constitute health data or allow inferences about health, religion or other especially protected aspects of your life. We process it only for the features you actively use and, where required, on the basis of your explicit consent.

3.3 Nutrition data

  • logged meals, foods, quantities, times and descriptions
  • photos of meals
  • estimated and user-confirmed or corrected calorie, protein, carbohydrate and fat values
  • favorites, recently used foods and nutrition history
  • AI inputs, AI estimates and your corrections

3.4 Exercise and training data

  • workout type, exercises, sets, reps, weights, duration and optional distance
  • perceived effort, notes and training history
  • estimated calories burned
  • photos of gym equipment you take for equipment recognition
  • AI recognition results and your confirmation or correction

In v1, Remo does not record GPS routes and does not sync with wearables or health platforms. If we later connect, for example, Apple Health, Health Connect, Garmin, Fitbit or Whoop, this will only happen after you separately enable it and after we update this privacy policy.

3.5 Sleep data

  • bedtime and wake time, or hours slept
  • subjective sleep quality
  • optional notes on sleep and recovery

3.6 Coaching, usage and derived data

  • daily notes, weekly reviews, recipe and training suggestions, and questions you ask the coach
  • trends, correlations, goal trajectories, plateaus and consistency streaks derived from your logs
  • the model version, timestamp and technical metadata of an AI request
  • count of AI features used, to enforce usage limits
  • app version, operating system, device model, language, timezone, session and event data, and error/security logs

3.7 Subscription and transaction data

  • chosen plan, subscription status and term
  • app store, transaction reference, renewal and cancellation status
  • information we need to verify a purchase or provide customer support

We generally never receive payment data such as full card numbers. Purchases made in the mobile app are processed by Apple or Google.

3.8 Communication data

  • email address and optionally name, role and message from contact forms
  • content and metadata of support requests
  • email address, language and source of a waitlist signup

Please don't send us health data in ordinary emails unless it's necessary to handle your request.

4. Why we process personal data

PurposeTypical dataLegal basis under GDPR
Create an account, secure login and provide the appAccount, profile, device and security dataContract, Art. 6(1)(b)
Keep fitness, nutrition and sleep logsProfile, health and log dataContract, Art. 6(1)(b); for special categories, additionally explicit consent, Art. 9(2)(a)
Calculate goals, energy needs and macrosBody, activity and goal dataContract; additionally explicit consent for health data
Recognize meals and gym equipment with AIPhotos, descriptions, profile data, AI inputs and outputsContract; additionally explicit consent for health data
Generate personal coaching guidanceProfile, nutrition, training, sleep and history dataContract; additionally explicit consent for health data
Send reminders and push notificationsPush token, language, timezone and notification contentConsent, Art. 6(1)(a)
Manage subscriptions and verify purchasesPlan and transaction dataContract and legal obligations, Art. 6(1)(b) and (c)
Provide support and answer requestsContact, account and communication dataContract, pre-contractual measures, or legitimate interest, Art. 6(1)(b) or (f)
Prevent abuse and protect our systemsIP address, device, access, error and security dataLegitimate interest, Art. 6(1)(f)
Understand and improve the serviceUsage and diagnostic data, preferably aggregated or anonymizedLegitimate interest, Art. 6(1)(f); consent for any optional personal-level analysis
Use personal health data for model testing or improvementSelected inputs, outputs and correctionsOnly with separate, voluntary, explicit consent, Art. 6(1)(a) and Art. 9(2)(a)

5. Explicit consent for health data

Before we first process health data, we ask you in the app for explicit consent, separate from the terms of service. The consent describes the data and purposes involved, in particular keeping your logs, calculating personal targets, and generating AI-assisted suggestions.

You can withdraw this consent at any time, with effect for the future, in the app settings or by emailing hello@remofitness.com. The lawfulness of processing carried out before withdrawal is unaffected. Because health data is required for Remo's core features, those features can no longer be provided after a withdrawal — you can instead have your account and data deleted.

Consent to using data to improve our own or third-party AI models is voluntary, separate, and never a condition for using the app.

6. Use of artificial intelligence

6.1 How it works

Remo uses AI in particular to:

  • recognize foods and approximate portion sizes from photos or descriptions
  • suggest nutrition values
  • match gym equipment to an existing exercise catalog
  • summarize your own logs and generate personalized coaching, recipe or training suggestions

Depending on the feature, only the content directly necessary for that request is sent to a contracted AI service. For a meal analysis, this may be the selected photo, your description, and profile data needed for context. For a weekly review, we use summarized values instead of full raw logs wherever possible.

We configure commercial AI interfaces so that submitted content is not used to train the provider's general-purpose models. We choose the shortest available provider-side retention and put data processing agreements in place. The AI providers, countries and deletion periods we use are listed in section 12.

6.2 Estimates and human review

AI outputs can be wrong or incomplete. Nutrition estimates and equipment recognition are suggestions. You can confirm or correct them before they're saved. Coaching guidance is intended solely for general fitness and lifestyle support.

Remo does not make any solely automated decision that produces legal effects concerning you or similarly significantly affects you. Automated individual decision-making under Art. 22 GDPR and Art. 21 FADP therefore does not occur, given the currently planned feature set. Should we introduce such a feature in the future, we will inform you separately in advance and ensure, in particular, human review.

6.3 Profiling

Remo connects your nutrition, exercise, sleep and goal data to identify trends and generate personal guidance. This may constitute profiling. It is not used for advertising, creditworthiness, insurance pricing, employment decisions or medical diagnosis, and is not sold to third parties for such purposes.

6.4 Improving Remo and AI models

We may use fully anonymized and aggregated insights to improve accuracy and usability. We use personal photos, health logs, AI inputs or corrections for systematic model testing, datasets, or training our own or third-party models only if you have separately and explicitly consented beforehand. You can withdraw this optional consent without losing normal use of the app. Data that has already been effectively anonymized can no longer be attributed to a person and therefore cannot subsequently be extracted.

7. Photos and camera access

Remo accesses your camera or photo library only after you grant permission. Only the image you capture or select is uploaded. Remo does not perform facial recognition or biometric identification.

Especially for gym photos, please take care not to capture other people, name tags, screens or other confidential content. Meal photos remain stored as part of your nutrition log if you choose. Photos taken solely to recognize a piece of gym equipment are deleted within 24 hours of recognition, unless you explicitly save them to a workout entry or separately consent to longer retention.

Where technically possible, we remove unnecessary image metadata such as location coordinates before permanent storage.

8. Push notifications

If you enable push notifications, we process a device-specific push token as well as the content and delivery status of the notification. Delivery goes through the Expo Push Service and, downstream, the Apple Push Notification Service or Google's Firebase Cloud Messaging.

Push notifications are optional. You can disable them at any time in the app or in your device's system settings. To avoid exposing sensitive content on a locked screen, notifications do not include detailed health, weight, nutrition or sleep data by default.

9. Subscriptions and app stores

If you purchase a subscription through the Apple App Store or Google Play, the respective store processes the purchase under its own responsibility, and its privacy terms and account settings apply in addition. We only receive the data we need to verify the purchase, term and entitlement and to provide Premium access.

10. Website remofitness.com

10.1 Technical delivery and server logs

Visiting the website processes technically required data, in particular IP address, date and time, the address accessed, data volume transferred, referrer, browser and operating system. This processing serves secure, error-free delivery and abuse prevention. Raw logs are generally deleted after 14 days, unless a security incident requires longer retention.

10.2 Our own, cookieless usage analytics

The website uses our own usage analytics via the /api/track endpoint. It loads no third-party analytics or advertising scripts and sets no advertising cookies. We may record:

  • page view or named interaction
  • path, referrer, language and screen resolution
  • UTM source, medium and campaign
  • a random session ID in sessionStorage, cleared when you close the tab
  • a daily-rotating, salted one-way value derived from the session ID, IP address and user agent

The raw IP address and user agent are used to compute this daily value but are not stored as such in the analytics database. This analytics helps us understand usage and interest in Remo and improve the website. Analytics data is deleted after 13 months at the latest, or aggregated and anonymized before then.

Technically necessary sessionStorage entries, e.g. for a session ID or scroll position, persist only for the relevant browser session.

10.3 Waitlist

If you join the waitlist, we store your email address as well as the language, source and time of signup, to notify you about early access and Remo's launch. The legal basis is your consent. You can unsubscribe at any time via the link in any message or by emailing us. We delete the entry upon withdrawal, and in any case no later than six months after public launch, unless you sign up for further messages.

10.4 Contact form and email

When you contact us, we process your email address, optionally name and role, your message, and the language, source and time. We use this data to respond to and document your request. Contact data is generally deleted twelve months after the request is resolved, unless legal obligations, contractual claims or security reasons require longer retention.

11. Data sources and obligation to provide data

We receive most personal data directly from you. We receive transaction status from Apple or Google. Technical data arises from your use of our services. Derived values and suggestions are generated from your input by our rules and AI systems.

Mandatory fields are marked as such. Without account data and the data required for a given feature, we cannot provide the app or that feature. You can decline optional information, photos, notifications and consent to model improvement without losing the remaining features, as long as they don't technically depend on it.

12. Recipients, processors and international disclosures

We do not sell personal data. Staff and service providers only get access where necessary for their task. Possible recipients are:

Recipient or categoryPurpose and possible dataLocation of processing / safeguard
Hetzner Online GmbHHosting of website, API, database and photos; technical logsData center in Helsinki, Finland (EU); data processing agreement under Art. 28 GDPR
Microsoft Azure, in particular Key Vault and Communication ServicesSecrets management and transactional email deliverySelected region Switzerland or EU/EFTA; possible further processing under Microsoft's agreement and documented data flows
AI providers for text and image analysis (candidates: OpenAI, Anthropic)AI analysis of text and images, and generation of coaching guidanceFinal choice made before AI features go live; thereafter EU and/or USA, with a data processing agreement, an adequacy decision where applicable, otherwise standard contractual clauses and supplementary measures
650 Industries, Inc. (Expo)Delivery of push notificationsUSA and further technical locations; contractual guarantees and standard contractual clauses where required
Apple and GoogleApp distribution, purchases, subscriptions and push deliveryProcessed under each provider's own terms; possible worldwide processing
Email, security, maintenance and support providersOperation, communication, troubleshooting and protectionOnly on a contractual basis
Authorities, courts, legal and tax advisorsCompliance with legal obligations and asserting or defending claimsOnly where legally required or where an overriding legitimate interest exists

For disclosures to a country without a recognized adequate level of data protection, we use appropriate safeguards, in particular recognized standard contractual clauses with the Swiss addendum or EU standard contractual clauses, and assess supplementary measures. Where a provider is effectively certified under a recognized data protection framework, we may also rely on the corresponding adequacy decision. Statutory exceptions remain reserved.

On request, we will share the safeguards relevant to your case.

13. Data security

We take technical and organizational measures appropriate to the risk. These include, in particular, encrypted transmission, role- and task-based access, secure password hashing, separated production and development environments, logging of security-relevant access, regular backups, updates, and incident-response procedures.

We do not use real health data for development and testing unless strictly necessary and separately secured. Despite careful measures, no electronic transmission or storage can guarantee absolute security.

14. Retention and deletion

We retain personal data only as long as necessary for the relevant purpose, legal obligations, or asserting and defending legal claims.

DataStandard retention
Account data and nutrition, training, sleep and coaching historyUntil you delete individual entries or your account; deletion from active systems generally within 30 days of account deletion
Meal photosUntil you delete the photo, the entry, or the account
Photos uploaded solely for equipment recognitionGenerally within 24 hours of recognition, unless explicitly saved
Temporary AI inputs and outputs at the AI providerShortest contractually available period, per the provider chosen in section 12
Push tokensUntil deactivation, device sign-out, or account deletion; invalid tokens are removed
App error logsGenerally 30 days
Security logsGenerally 90 days; longer during and for evidence of an incident
Website server logsGenerally 14 days
Website analytics dataAt most 13 months, then deletion or genuine anonymization
WaitlistUntil withdrawal, and no later than six months after public launch
Contact and support requestsGenerally twelve months after resolution
Billing and tax-relevant recordsPer statutory retention obligations, generally ten years
Consent and withdrawal recordsAs long as necessary to demonstrate lawful processing and within applicable limitation periods
BackupsRolling deletion generally within 90 days; locked and used only for restoration until then

Statutory retention obligations or a specific security or legal matter may lead to a longer period in individual cases. Data is then deleted or effectively anonymized.

15. Account deletion and data export

You can trigger account deletion directly in the app. Deletion ends access and removes your personal data within the periods described in section 14, unless a legal exception applies. Mere deactivation does not replace deletion.

Before deletion, you can request an export of the data you provided, in a common, machine-readable format. You can also reach out to hello@remofitness.com for this.

16. Your rights

Depending on the applicable law, you have in particular the right to:

  • obtain information about the processing of your personal data
  • have inaccurate data corrected
  • request deletion or restriction of processing
  • receive your provided data in a structured, common, machine-readable format, or have it transferred
  • object to processing based on legitimate interests
  • withdraw consent at any time for the future
  • not be subject to an unlawful, solely automated decision
  • lodge a complaint with a competent data protection supervisory authority

In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC). Under the GDPR, you may in particular contact the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.

To prevent unauthorized access to data, we may require reasonable proof of identity. Rights may be subject to statutory limitations. We respond to requests within the applicable statutory deadline.

17. Minors

Remo is intended solely for people aged 18 and over. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, please let us know at hello@remofitness.com so we can review and, if appropriate, delete it.

18. Changes to this privacy policy

We update this privacy policy when features, service providers or legal requirements change. The current version is available in the app and at remofitness.com/en/privacy. For material changes, in particular new purposes for health data, we will notify you in advance and obtain renewed consent where required.