Privacy Policy
Last updated: 15 September 2026
This privacy policy explains how RemoFitness ("Remo", "we") processes personal data when you use our website at remofitness.com, the Remo app, or related services. Remo is a fitness and healthy-lifestyle coaching app. The app connects your diet, exercise and sleep data and turns it into personalized, partly AI-generated guidance. Remo is not a medical device, does not provide diagnoses, and does not replace medical, psychotherapeutic or clinical nutrition advice.
1. Data controller
The controller responsible for processing your personal data is:
RemoFitness Legal representative: Florian Schrödter Hardturmstrasse 161 8005 Zurich Switzerland Email: hello@remofitness.com
You can also send privacy-related requests to this email address.
We will appoint an EU representative under Art. 27 GDPR once we actively offer Remo in Germany or Austria.
2. Scope and legal bases
Processing by the Switzerland-based controller is governed in particular by the Swiss Federal Act on Data Protection (FADP). To the extent we offer goods or services to, or monitor the behavior of, people in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) applies in addition.
Under the GDPR, we rely in particular on the following legal bases:
- performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
- your consent (Art. 6(1)(a) GDPR)
- for health data or other special categories, additionally your explicit consent (Art. 9(2)(a) GDPR)
- compliance with a legal obligation (Art. 6(1)(c) GDPR)
- our legitimate interests, in particular in the secure, reliable and economical operation of our services and in privacy-friendly usage measurement (Art. 6(1)(f) GDPR)
Where processing is based on a balancing of interests, you can request further information about that balancing and object on grounds arising from your particular situation.
3. What personal data we process
Depending on the features you use, we process the following data:
3.1 Account and profile basics
- name or display name, email address and internal user ID
- password hash, login and security tokens
- language, timezone and preferred units
- account status, consent records and settings
We never store your password in plain text.
3.2 Profile, fitness and health data
- your chosen goal, e.g. fat loss, muscle gain, endurance, general fitness or better sleep
- age, sex assigned at birth, height, current weight and optional target weight
- activity level, training frequency and available equipment
- diet type, eating habits, allergies and intolerances
- injuries, movement limitations and other health circumstances you share with us
- your preferred coaching and motivation tone
- values and targets calculated from the above, e.g. basal metabolic rate (BMR), total daily energy expenditure (TDEE) and macro targets
This information may constitute health data or allow inferences about health, religion or other especially protected aspects of your life. We process it only for the features you actively use and, where required, on the basis of your explicit consent.
3.3 Nutrition data
- logged meals, foods, quantities, times and descriptions
- photos of meals
- estimated and user-confirmed or corrected calorie, protein, carbohydrate and fat values
- favorites, recently used foods and nutrition history
- AI inputs, AI estimates and your corrections
3.4 Exercise and training data
- workout type, exercises, sets, reps, weights, duration and optional distance
- perceived effort, notes and training history
- estimated calories burned
- photos of gym equipment you take for equipment recognition
- AI recognition results and your confirmation or correction
In v1, Remo does not record GPS routes and does not sync with wearables or health platforms. If we later connect, for example, Apple Health, Health Connect, Garmin, Fitbit or Whoop, this will only happen after you separately enable it and after we update this privacy policy.
3.5 Sleep data
- bedtime and wake time, or hours slept
- subjective sleep quality
- optional notes on sleep and recovery
3.6 Coaching, usage and derived data
- daily notes, weekly reviews, recipe and training suggestions, and questions you ask the coach
- trends, correlations, goal trajectories, plateaus and consistency streaks derived from your logs
- the model version, timestamp and technical metadata of an AI request
- count of AI features used, to enforce usage limits
- app version, operating system, device model, language, timezone, session and event data, and error/security logs
3.7 Subscription and transaction data
- chosen plan, subscription status and term
- app store, transaction reference, renewal and cancellation status
- information we need to verify a purchase or provide customer support
We generally never receive payment data such as full card numbers. Purchases made in the mobile app are processed by Apple or Google.
3.8 Communication data
- email address and optionally name, role and message from contact forms
- content and metadata of support requests
- email address, language and source of a waitlist signup
Please don't send us health data in ordinary emails unless it's necessary to handle your request.
4. Why we process personal data
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Create an account, secure login and provide the app | Account, profile, device and security data | Contract, Art. 6(1)(b) |
| Keep fitness, nutrition and sleep logs | Profile, health and log data | Contract, Art. 6(1)(b); for special categories, additionally explicit consent, Art. 9(2)(a) |
| Calculate goals, energy needs and macros | Body, activity and goal data | Contract; additionally explicit consent for health data |
| Recognize meals and gym equipment with AI | Photos, descriptions, profile data, AI inputs and outputs | Contract; additionally explicit consent for health data |
| Generate personal coaching guidance | Profile, nutrition, training, sleep and history data | Contract; additionally explicit consent for health data |
| Send reminders and push notifications | Push token, language, timezone and notification content | Consent, Art. 6(1)(a) |
| Manage subscriptions and verify purchases | Plan and transaction data | Contract and legal obligations, Art. 6(1)(b) and (c) |
| Provide support and answer requests | Contact, account and communication data | Contract, pre-contractual measures, or legitimate interest, Art. 6(1)(b) or (f) |
| Prevent abuse and protect our systems | IP address, device, access, error and security data | Legitimate interest, Art. 6(1)(f) |
| Understand and improve the service | Usage and diagnostic data, preferably aggregated or anonymized | Legitimate interest, Art. 6(1)(f); consent for any optional personal-level analysis |
| Use personal health data for model testing or improvement | Selected inputs, outputs and corrections | Only with separate, voluntary, explicit consent, Art. 6(1)(a) and Art. 9(2)(a) |
5. Explicit consent for health data
Before we first process health data, we ask you in the app for explicit consent, separate from the terms of service. The consent describes the data and purposes involved, in particular keeping your logs, calculating personal targets, and generating AI-assisted suggestions.
You can withdraw this consent at any time, with effect for the future, in the app settings or by emailing hello@remofitness.com. The lawfulness of processing carried out before withdrawal is unaffected. Because health data is required for Remo's core features, those features can no longer be provided after a withdrawal — you can instead have your account and data deleted.
Consent to using data to improve our own or third-party AI models is voluntary, separate, and never a condition for using the app.
6. Use of artificial intelligence
6.1 How it works
Remo uses AI in particular to:
- recognize foods and approximate portion sizes from photos or descriptions
- suggest nutrition values
- match gym equipment to an existing exercise catalog
- summarize your own logs and generate personalized coaching, recipe or training suggestions
Depending on the feature, only the content directly necessary for that request is sent to a contracted AI service. For a meal analysis, this may be the selected photo, your description, and profile data needed for context. For a weekly review, we use summarized values instead of full raw logs wherever possible.
We configure commercial AI interfaces so that submitted content is not used to train the provider's general-purpose models. We choose the shortest available provider-side retention and put data processing agreements in place. The AI providers, countries and deletion periods we use are listed in section 12.
6.2 Estimates and human review
AI outputs can be wrong or incomplete. Nutrition estimates and equipment recognition are suggestions. You can confirm or correct them before they're saved. Coaching guidance is intended solely for general fitness and lifestyle support.
Remo does not make any solely automated decision that produces legal effects concerning you or similarly significantly affects you. Automated individual decision-making under Art. 22 GDPR and Art. 21 FADP therefore does not occur, given the currently planned feature set. Should we introduce such a feature in the future, we will inform you separately in advance and ensure, in particular, human review.
6.3 Profiling
Remo connects your nutrition, exercise, sleep and goal data to identify trends and generate personal guidance. This may constitute profiling. It is not used for advertising, creditworthiness, insurance pricing, employment decisions or medical diagnosis, and is not sold to third parties for such purposes.
6.4 Improving Remo and AI models
We may use fully anonymized and aggregated insights to improve accuracy and usability. We use personal photos, health logs, AI inputs or corrections for systematic model testing, datasets, or training our own or third-party models only if you have separately and explicitly consented beforehand. You can withdraw this optional consent without losing normal use of the app. Data that has already been effectively anonymized can no longer be attributed to a person and therefore cannot subsequently be extracted.
7. Photos and camera access
Remo accesses your camera or photo library only after you grant permission. Only the image you capture or select is uploaded. Remo does not perform facial recognition or biometric identification.
Especially for gym photos, please take care not to capture other people, name tags, screens or other confidential content. Meal photos remain stored as part of your nutrition log if you choose. Photos taken solely to recognize a piece of gym equipment are deleted within 24 hours of recognition, unless you explicitly save them to a workout entry or separately consent to longer retention.
Where technically possible, we remove unnecessary image metadata such as location coordinates before permanent storage.
8. Push notifications
If you enable push notifications, we process a device-specific push token as well as the content and delivery status of the notification. Delivery goes through the Expo Push Service and, downstream, the Apple Push Notification Service or Google's Firebase Cloud Messaging.
Push notifications are optional. You can disable them at any time in the app or in your device's system settings. To avoid exposing sensitive content on a locked screen, notifications do not include detailed health, weight, nutrition or sleep data by default.
9. Subscriptions and app stores
If you purchase a subscription through the Apple App Store or Google Play, the respective store processes the purchase under its own responsibility, and its privacy terms and account settings apply in addition. We only receive the data we need to verify the purchase, term and entitlement and to provide Premium access.
10. Website remofitness.com
10.1 Technical delivery and server logs
Visiting the website processes technically required data, in particular IP address, date and time, the address accessed, data volume transferred, referrer, browser and operating system. This processing serves secure, error-free delivery and abuse prevention. Raw logs are generally deleted after 14 days, unless a security incident requires longer retention.
10.2 Our own, cookieless usage analytics
The website uses our own usage analytics via the /api/track endpoint. It loads no third-party analytics or advertising scripts and sets no advertising cookies. We may record:
- page view or named interaction
- path, referrer, language and screen resolution
- UTM source, medium and campaign
- a random session ID in sessionStorage, cleared when you close the tab
- a daily-rotating, salted one-way value derived from the session ID, IP address and user agent
The raw IP address and user agent are used to compute this daily value but are not stored as such in the analytics database. This analytics helps us understand usage and interest in Remo and improve the website. Analytics data is deleted after 13 months at the latest, or aggregated and anonymized before then.
Technically necessary sessionStorage entries, e.g. for a session ID or scroll position, persist only for the relevant browser session.
10.3 Waitlist
If you join the waitlist, we store your email address as well as the language, source and time of signup, to notify you about early access and Remo's launch. The legal basis is your consent. You can unsubscribe at any time via the link in any message or by emailing us. We delete the entry upon withdrawal, and in any case no later than six months after public launch, unless you sign up for further messages.
10.4 Contact form and email
When you contact us, we process your email address, optionally name and role, your message, and the language, source and time. We use this data to respond to and document your request. Contact data is generally deleted twelve months after the request is resolved, unless legal obligations, contractual claims or security reasons require longer retention.
11. Data sources and obligation to provide data
We receive most personal data directly from you. We receive transaction status from Apple or Google. Technical data arises from your use of our services. Derived values and suggestions are generated from your input by our rules and AI systems.
Mandatory fields are marked as such. Without account data and the data required for a given feature, we cannot provide the app or that feature. You can decline optional information, photos, notifications and consent to model improvement without losing the remaining features, as long as they don't technically depend on it.
12. Recipients, processors and international disclosures
We do not sell personal data. Staff and service providers only get access where necessary for their task. Possible recipients are:
| Recipient or category | Purpose and possible data | Location of processing / safeguard |
|---|---|---|
| Hetzner Online GmbH | Hosting of website, API, database and photos; technical logs | Data center in Helsinki, Finland (EU); data processing agreement under Art. 28 GDPR |
| Microsoft Azure, in particular Key Vault and Communication Services | Secrets management and transactional email delivery | Selected region Switzerland or EU/EFTA; possible further processing under Microsoft's agreement and documented data flows |
| AI providers for text and image analysis (candidates: OpenAI, Anthropic) | AI analysis of text and images, and generation of coaching guidance | Final choice made before AI features go live; thereafter EU and/or USA, with a data processing agreement, an adequacy decision where applicable, otherwise standard contractual clauses and supplementary measures |
| 650 Industries, Inc. (Expo) | Delivery of push notifications | USA and further technical locations; contractual guarantees and standard contractual clauses where required |
| Apple and Google | App distribution, purchases, subscriptions and push delivery | Processed under each provider's own terms; possible worldwide processing |
| Email, security, maintenance and support providers | Operation, communication, troubleshooting and protection | Only on a contractual basis |
| Authorities, courts, legal and tax advisors | Compliance with legal obligations and asserting or defending claims | Only where legally required or where an overriding legitimate interest exists |
For disclosures to a country without a recognized adequate level of data protection, we use appropriate safeguards, in particular recognized standard contractual clauses with the Swiss addendum or EU standard contractual clauses, and assess supplementary measures. Where a provider is effectively certified under a recognized data protection framework, we may also rely on the corresponding adequacy decision. Statutory exceptions remain reserved.
On request, we will share the safeguards relevant to your case.
13. Data security
We take technical and organizational measures appropriate to the risk. These include, in particular, encrypted transmission, role- and task-based access, secure password hashing, separated production and development environments, logging of security-relevant access, regular backups, updates, and incident-response procedures.
We do not use real health data for development and testing unless strictly necessary and separately secured. Despite careful measures, no electronic transmission or storage can guarantee absolute security.
14. Retention and deletion
We retain personal data only as long as necessary for the relevant purpose, legal obligations, or asserting and defending legal claims.
| Data | Standard retention |
|---|---|
| Account data and nutrition, training, sleep and coaching history | Until you delete individual entries or your account; deletion from active systems generally within 30 days of account deletion |
| Meal photos | Until you delete the photo, the entry, or the account |
| Photos uploaded solely for equipment recognition | Generally within 24 hours of recognition, unless explicitly saved |
| Temporary AI inputs and outputs at the AI provider | Shortest contractually available period, per the provider chosen in section 12 |
| Push tokens | Until deactivation, device sign-out, or account deletion; invalid tokens are removed |
| App error logs | Generally 30 days |
| Security logs | Generally 90 days; longer during and for evidence of an incident |
| Website server logs | Generally 14 days |
| Website analytics data | At most 13 months, then deletion or genuine anonymization |
| Waitlist | Until withdrawal, and no later than six months after public launch |
| Contact and support requests | Generally twelve months after resolution |
| Billing and tax-relevant records | Per statutory retention obligations, generally ten years |
| Consent and withdrawal records | As long as necessary to demonstrate lawful processing and within applicable limitation periods |
| Backups | Rolling deletion generally within 90 days; locked and used only for restoration until then |
Statutory retention obligations or a specific security or legal matter may lead to a longer period in individual cases. Data is then deleted or effectively anonymized.
15. Account deletion and data export
You can trigger account deletion directly in the app. Deletion ends access and removes your personal data within the periods described in section 14, unless a legal exception applies. Mere deactivation does not replace deletion.
Before deletion, you can request an export of the data you provided, in a common, machine-readable format. You can also reach out to hello@remofitness.com for this.
16. Your rights
Depending on the applicable law, you have in particular the right to:
- obtain information about the processing of your personal data
- have inaccurate data corrected
- request deletion or restriction of processing
- receive your provided data in a structured, common, machine-readable format, or have it transferred
- object to processing based on legitimate interests
- withdraw consent at any time for the future
- not be subject to an unlawful, solely automated decision
- lodge a complaint with a competent data protection supervisory authority
In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC). Under the GDPR, you may in particular contact the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
To prevent unauthorized access to data, we may require reasonable proof of identity. Rights may be subject to statutory limitations. We respond to requests within the applicable statutory deadline.
17. Minors
Remo is intended solely for people aged 18 and over. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, please let us know at hello@remofitness.com so we can review and, if appropriate, delete it.
18. Changes to this privacy policy
We update this privacy policy when features, service providers or legal requirements change. The current version is available in the app and at remofitness.com/en/privacy. For material changes, in particular new purposes for health data, we will notify you in advance and obtain renewed consent where required.