VolumeApps Privacy Policy
Effective Date: February 14, 2026
Linus Westling, operating as VolumeApps ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, retain, and safeguard information when you use our mobile applications, including VolumeLogic and VolumeMacros (together, the "Apps").
The Apps are designed to be local-first where possible. Some features work entirely on your device. Other optional features, such as account sync, subscriptions, health-platform integrations, AI-assisted weekly workout insights, AI-assisted food analysis, crash reporting, and support requests, may involve processing data outside your device as described below.
1. Information We Collect
1.1 Data collected in both Apps
- Account data: If you create an account or sign in where account features are available, we may process your email address, authentication identifiers, and related account metadata for sign-in, sync, account recovery, and support.
- Preferences and settings: We store app preferences such as language, theme, units, notification settings, privacy consent choices, and feature settings.
- Subscription data: If you purchase or restore a subscription, our subscription provider receives app store transaction data and entitlement status so we can unlock paid features.
- Device and app information: We may process device type, operating system version, app version, and crash or error context for compatibility, debugging, and support.
- Support communications: If you contact us, we process the information you choose to include in your message so we can respond.
1.2 VolumeLogic data
- Health and body profile: VolumeLogic may collect weight, height, age, and gender. This data is used to calculate Basal Metabolic Rate (BMR), estimate calorie expenditure, and personalize fitness insights.
- Fitness activity: VolumeLogic stores workout logs, exercises, sets, weights, reps, rest periods, workout history, progression data, programs, and related training analytics.
- Sensor and health-platform data: With your permission, VolumeLogic may read selected data from Apple HealthKit or Google Health Connect. Step count may be read on demand for daily activity display and is not uploaded to our cloud systems. Heart-rate samples may be attached to cardio or workout sessions and stored locally; if cloud sync is enabled, heart-rate data tied to synced sessions may also be synced to your account.
- Location and outdoor activities: For outdoor activities such as walking, running, and cycling, VolumeLogic may use precise location/GPS when you grant permission. This is used to record route, distance, pace, and related workout metrics. Some outdoor session information may sync to our cloud database if you enable cloud sync; richer location detail may remain only on your device depending on the feature and settings.
- Workout share photos: When you choose to create a workout share image, VolumeLogic may use the camera for a selfie or let you select a photo from your library. The selected photo is used on your device to compose a share image with a workout-statistics overlay. VolumeApps does not upload or store the selected photo. The photo and generated share image are held only in temporary on-device or system cache while the share flow is in use and are cleared after they have served that purpose. The generated image is sent outside the App only if you choose a destination through your device's share sheet.
- AI-assisted weekly workout insights: When you use the weekly AI coaching feature, VolumeLogic sends a structured summary containing only workout details and statistics from the preceding week through an authenticated VolumeApps edge function to a third-party AI model provider. The feature does not provide a free-text prompt or chat interface, and VolumeLogic does not send your name, email address, account identifiers, profile details, support messages, photos, or other images to the AI model provider. The provider uses the weekly workout statistics only to generate the requested coaching summary and recommendation. VolumeApps does not store the submitted weekly workout statistics in the AI report database or include them in application logs or crash reports; only the generated coaching report and limited operational metadata may be stored so you can view report history and so we can operate and protect the feature.
- Product analytics: VolumeLogic may use limited product analytics to understand a small set of app usage events, such as app opens, onboarding completion, first workout creation/completion, total workout completion count, last active screen, and last seen timestamp. We do not use these analytics to collect workout contents, exercises, heart-rate values, health metrics, personal profile values, or location.
1.3 VolumeMacros data
- Nutrition and macro tracking: VolumeMacros stores food logs, consumption entries, recipes, recipe ingredients, custom foods, portion labels, macro totals, micronutrient data where available, nutrition goals, phase goals, and related diary history.
- Body metrics and goal inputs: VolumeMacros may store body weight, height, age, sex, activity level, goal settings, calorie targets, macro targets, and related settings used to calculate and display nutrition goals.
- Local-first storage and account features: VolumeMacros stores user nutrition data primarily in an on-device SQLite database. Some features, including AI-assisted food analysis and subscription access, may require a Volume account and limited cloud-side account metadata. Nutrition diary cloud sync remains unavailable unless and until a synced account feature is expressly enabled.
- Health-platform data: With your permission, VolumeMacros may read body weight and step count from Apple HealthKit or Google Health Connect, and may write calories, macros, and supported nutrient data from logged meals to those platforms. These integrations are optional and controlled by your device permissions and in-app settings.
- Camera, meal photos, and barcode scanning: VolumeMacros may use your camera when you choose to scan a food barcode or photograph a meal for AI-assisted food analysis. Camera access is used only for the feature you select and is not used for unrelated tracking.
- AI-assisted food analysis: When you choose AI Log, VolumeMacros sends the meal description and/or meal photo you provide through an authenticated VolumeApps edge function to a third-party AI model provider. The request is used to estimate a food name, calories, protein, carbohydrates, and fat for you to review. The request content and model response pass through the edge function and are not stored by VolumeApps in Supabase, application logs, or crash reports. A processed photo is held temporarily in the App's cache for the request and cleared after it has served that purpose. If you review and save an estimate, the resulting nutrition entry is stored according to the ordinary VolumeMacros storage settings.
- AI request and quota metadata: AI Log requires authentication. To verify access, enforce daily limits, prevent duplicate requests, and protect the Service against abuse, we store limited account-linked metadata such as your user identifier, a request identifier, request date, request count, and timestamps. This metadata does not contain your submitted description, photo, or the AI-generated nutrition estimate.
- Notifications: VolumeMacros may schedule local reminders, daily recaps, weekly recaps, or meal-time notifications if you enable notifications. Notification preferences and delivery state may be stored locally on your device.
- Crash reporting: VolumeMacros uses Sentry for error and crash monitoring when configured. Non-fatal crash/error reporting is gated by your crash-reporting consent. We instruct developers not to include food names, diary entries, search queries, body metrics, email addresses, tokens, or raw database payloads in crash reports.
- Product analytics: VolumeMacros product analytics are currently deferred. The app does not currently use a product analytics event pipeline such as PostHog, Amplitude, or Mixpanel.
- Tracking consent: VolumeMacros includes a settings-controlled iOS App Tracking Transparency (ATT) consent flow for possible future advertising identifier or ad-network use. Personalized ads are not enabled unless the relevant feature is introduced and the required consent and platform requirements are satisfied.
Health, fitness, nutrition, body metrics, and precise location data can be sensitive personal data. We process this data only for the purposes described in this Policy, and we do not sell it or use it for third-party advertising.
2. How We Use Your Data
We use your information to:
- Provide core app functionality, including workout tracking, nutrition tracking, progress visualization, goal calculation, and history views
- Process the preceding week's structured workout statistics when you use VolumeLogic's AI coaching feature and return a generated weekly coaching report
- Process meal descriptions and photos you choose to submit for AI-assisted nutrition estimates and return the estimate for your review
- Authenticate AI-assisted requests, manage feature eligibility and request limits, prevent duplicate processing, and protect the Service against abuse
- Compose workout share images on your device using a selfie or photo you select and send them to a destination only when you use the device share sheet
- Record and display outdoor workouts in VolumeLogic when you choose to use GPS-based features
- Read from or write to Apple HealthKit / Google Health Connect when you grant permission
- Store local app data and, where available and enabled, sync data across devices via secure cloud storage
- Process subscriptions and manage premium feature access
- Send local reminders or service-related notifications when enabled
- Debug crashes, fix bugs, improve app reliability, and provide customer support
- Improve app features using limited, privacy-conscious analytics where analytics are enabled for a specific app
- Comply with legal, security, fraud-prevention, accounting, and dispute-resolution obligations
3. Third-Party Services
We use trusted third-party services to operate the Apps:
- Supabase: Provides authentication, edge-function processing, and secure cloud database hosting where account and sync features are available. VolumeLogic uses Supabase for account data, synced workout data, health profile data, outdoor activity data you choose to sync, passing weekly workout-statistics requests to the AI model provider, and storing generated coaching reports and limited operational metadata. VolumeMacros uses Supabase for authentication and limited account-based features, including passing AI Log requests to the AI model provider and storing request/quota metadata. User nutrition cloud sync remains deferred unless and until a synced account feature is enabled.
- AI model provider: When you use VolumeLogic's weekly AI coaching feature, our third-party AI model provider receives only the structured workout details and statistics for the preceding week and generates a coaching report; it does not receive free-text input, personal details, photos, or other images from VolumeLogic. When you use VolumeMacros AI Log, the provider receives the meal description and/or photo you choose to submit and generates a nutrition estimate. The provider processes this content on our behalf to provide the requested feature. Under the terms applicable to the AI model service we use, prompts, images, and responses are not used to improve the provider's products. The provider may temporarily log request content and responses for safety, abuse-prevention, and legal purposes and may process them outside the EU/EEA using applicable transfer safeguards.
- RevenueCat: Processes subscription status, app store transaction metadata, and premium feature access. RevenueCat does not need access to your workout contents, nutrition diary, health metrics, or location data.
- Sentry: Provides crash and error monitoring. Sentry may receive technical diagnostic information such as app version, device/OS information, error stack traces, and privacy-safe tags. VolumeMacros gates non-fatal reporting behind crash-reporting consent. We avoid sending sensitive fitness, nutrition, health, or location contents in crash reports.
- PostHog: Provides limited product analytics for VolumeLogic only where enabled, as described in Section 1.2. VolumeMacros does not currently use PostHog product analytics.
- Apple HealthKit and Google Health Connect: Provide optional health-platform integrations controlled by your device permissions. Data obtained from HealthKit or Health Connect is used only to provide the app features you enable. It is never sold, used for advertising, or shared with third parties for their own purposes.
- Apple App Store and Google Play: Handle app downloads, in-app purchases, subscriptions, refunds, and certain app-store account processes under their own terms and privacy policies.
These services operate under their own privacy policies and are expected to provide appropriate protection for personal data they process on our behalf.
4. Data Security and Storage
We use reasonable technical and organizational safeguards, including:
- Encryption in transit for network communications
- Encrypted cloud database storage where cloud storage is used
- Secure authentication protocols for account features
- Access controls and Row Level Security policies for cloud data where applicable
- Local-first design where practical, so many features can operate using on-device storage
Cloud data is stored on secure infrastructure in Europe where available through our cloud provider. Local app data remains on your device unless you enable or use a feature that syncs, submits, or shares it. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
VolumeLogic weekly AI coaching transmission. The structured weekly workout-statistics request and generated response are encrypted in transit. VolumeLogic does not offer free-text access to this AI feature and does not send personal details, photos, or other images to the AI model provider. VolumeApps excludes the submitted weekly workout statistics from the AI report database, application logs, Sentry, and other crash-reporting records. The generated coaching report may be stored in your account so you can view report history. The AI model provider may retain or cache request content and responses temporarily as described in Section 3.
AI Log transmission. AI Log request content is encrypted in transit. VolumeApps does not store the submitted meal description, meal photo, or AI response on its servers. Request bodies and model responses are excluded from our Supabase database, application logs, Sentry, and other crash-reporting records. The AI model provider may retain or cache content temporarily as described in Section 3.
5. Data Retention and Deletion
Active account. Where account features are available, we keep account data and synced user content for as long as your account remains open and the data is needed to provide the service.
Inactive account. If you stop using an account-enabled app but do not delete your account, we may delete personal data after your account has been inactive (no successful sign-in) for up to two (2) years, unless we need to keep it longer for legal, security, accounting, fraud-prevention, or dispute-resolution reasons.
Local device data. Data stored only on your device remains until you delete it in the app, clear app data in your device settings, uninstall the app, or use an in-app wipe/delete function where available.
Account deletion. If you delete your account through an account-enabled app, personal data tied to that app account is permanently deleted from our active systems within 30 days of confirmed deletion, except where a longer period is required or permitted by law. Backup copies are purged within 90 days.
AI-assisted weekly workout insights. VolumeApps does not retain the weekly workout statistics submitted to the AI model provider as part of the generated report. We may retain the generated coaching report and limited account-linked operational metadata, such as report identifiers, week identifiers, generation limits, model information, and timestamps, while needed to provide report history, operate the feature, and protect it against abuse. This stored information is removed in accordance with the applicable account-deletion process, subject to legal and security exceptions. The AI model provider may retain or cache request content and responses for a limited period for safety, abuse-prevention, legal, and service-operation purposes.
AI-assisted food analysis. VolumeApps does not retain the meal description, meal photo, or AI response after the request has been completed. A temporary processed photo is removed from the App's cache after it has served its purpose. The AI model provider may retain or cache prompts and responses for a limited period for safety, abuse-prevention, legal, and service-operation purposes. Account-linked AI request and quota metadata is retained while needed to operate and protect the feature and is removed in accordance with the applicable account-deletion process, subject to legal and security exceptions.
VolumeMacros local data controls. VolumeMacros supports local export and local data wipe flows for local-only nutrition data. These flows remove user-created nutrition data from the device while preserving bundled/reference food databases where appropriate. Account-based metadata used for authentication, subscriptions, AI Log, or other enabled cloud features is handled separately and may require an account-deletion request or in-app account deletion where available.
Separate app scopes. VolumeLogic and VolumeMacros data are separate product scopes. Deleting VolumeMacros nutrition data is not intended to delete VolumeLogic workout data, and deleting VolumeLogic workout data is not intended to delete VolumeMacros nutrition data, unless a future shared-account flow clearly tells you otherwise and you confirm that broader deletion.
Analytics, crash, billing, and legal records. Limited analytics, crash reports, subscription records, billing/tax records, support records, and security logs may be retained as long as reasonably necessary for product improvement, support, legal, accounting, or security purposes.
How to request deletion. Use the in-app settings where available. If you cannot access the app, email privacy@volumelogic.se from the email address registered to your account, if applicable, and use the subject line Account Deletion Request. We will process verified requests as soon as reasonably practicable, typically within 48 hours of confirming your identity.
6. Your Rights and Data Control
Depending on your location, including if you are in the European Union or European Economic Area, you may have the right to:
- Access personal data we hold about you
- Correct inaccurate or incomplete information
- Delete your account or associated data, subject to legal exceptions
- Export your data in a portable format where export is available
- Object to or restrict certain processing
- Withdraw consent for optional permissions, analytics, crash reporting, health-platform integrations, tracking, notifications, and location access
You can revoke device permissions at any time through your device settings. Revoking permission may limit related features but does not automatically delete data already saved in the app. To exercise your rights, use the in-app settings or contact us at privacy@volumelogic.se.
VolumeLogic's weekly AI coaching feature produces an informational coaching report from the preceding week's workout statistics. VolumeMacros AI Log produces an estimate for you to review and edit before saving. Neither feature makes decisions that have legal or similarly significant effects on you.
7. International Users and Data Transfers
The Apps may be available worldwide. Where cloud data is processed, we aim to use European cloud infrastructure where practical. AI-assisted request content may also be processed by our AI model provider or its subprocessors in countries outside the EU/EEA. If personal data is transferred outside the EU/EEA, we use appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other legally recognized transfer mechanisms.
For European Union users (GDPR), our lawful bases may include:
- Contract performance - account features, subscriptions, sync, workout tracking, nutrition tracking, user-requested AI-assisted weekly workout insights and food analysis, and support
- Consent - sensitive health data, health-platform integrations, precise location, camera and photo-library access, tracking permissions, optional crash reporting, and notifications where required
- Legitimate interests - app security, fraud prevention, limited product improvement, service diagnostics, and crash/error analysis where permitted
- Legal obligation - tax, accounting, consumer-protection, and compliance records
8. Cookies and Tracking Technologies
Our mobile apps do not use web browser cookies for normal app functionality. The Apps may use:
- Local storage and local databases: To save your preferences, diary data, workout data, recipes, settings, and session state on your device
- Analytics SDKs: Only where enabled for a specific app and limited to the events described in this Policy
- Crash-reporting SDKs: To identify and fix bugs and crashes, subject to the app-specific controls described above
- Platform tracking permission flows: Where required before accessing advertising identifiers or tracking users across apps and websites
9. Children's Privacy
The Apps are not intended for children under 13 years of age, and AI-assisted features are not intended for anyone under 18 years of age. We do not knowingly collect personal information from children under 13 or knowingly process AI-assisted requests from anyone under 18. If you are a parent or guardian and believe a child has provided us with personal data, please contact us at privacy@volumelogic.se, and we will delete such information where required.
10. Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will take appropriate steps, which may include:
- Notifying affected users where required by law
- Describing the nature of the breach and the categories of data involved
- Explaining steps we are taking to address the breach
- Providing guidance on how you can protect yourself
- Notifying relevant authorities where required
11. Marketing Communications
We do not sell your personal information to advertisers or marketing companies. We may send service-related messages, support replies, or important account notices. If we send non-essential marketing communications, you can opt out where required by law.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Apps, data practices, legal requirements, or third-party services. We will notify you of material changes by posting the updated policy on this page, updating the "Last Updated" date, and, where appropriate, sending an in-app notice or email.
Your continued use of the Apps after a policy update means the updated Privacy Policy applies to your use of the Apps, to the extent permitted by law. Where a change requires consent, we will request that consent before relying on it for the relevant processing.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Privacy and data inquiries: privacy@volumelogic.se
- Technical support: support@volumelogic.se
- Legal questions: legal@volumelogic.se
- Business address: Kungsgatan 38A, Uddevalla, Västra Götaland County, Sweden
© 2026 Linus Westling, operating as VolumeApps. All rights reserved.