Legal
Privacy Notice
Last updated 13 July 2026
This notice describes the current invite-only Daystrong Android beta. Daystrong is operated by Artur Ferreira Cruz in the Canton of Lucerne, Switzerland. Privacy requests can be sent to support@arturf.ch. The beta will not enter Google Play closed testing until a public postal business address is designated.
Who may use the beta
The private beta is limited to invited adults aged 18 or older. It is a general wellness and tracking product, not a medical service. Do not use it for diagnosis, treatment, medication, allergies, eating-disorder care, or another decision requiring a qualified professional.
Data Daystrong stores
- Account and consent: name, email, password hash, invite state, Terms/Privacy versions and optional analytics choice.
- Profile and goals: values you provide for calorie and macro targets, height, weight, activity and training preferences.
- Nutrition: confirmed diary entries, saved meals and barcodes. Meal photos and AI prompts are sent for the requested estimate but are not written to the Daystrong database.
- Training and community: workouts, routines, exercises, notes, optional group participation and posts you create.
- Health Connect: only steps and weight after separate Android permission. When you press sync, the selected daily steps and latest weight are copied into your Daystrong account.
- Operations: structured beta feedback and an AI cost ledger containing method, model, token counts, estimated cost, latency and a safe result code—never the image or prompt.
Why it is used
Data is used to create and secure the invited account, provide the diary, training, progress, AI estimate and Health Connect features you request, enforce beta limits, answer support, export or delete your data, and operate the private beta. Daystrong does not sell personal data or use Health Connect, diary or workout content for advertising.
Current services and data boundaries
- Coolify and PostgreSQL: the API and active account database run on operator-managed infrastructure over encrypted HTTPS.
- OpenAI: receives only the text or meal image you deliberately submit for an estimate plus the instructions needed to return structured foods. Review OpenAI’s privacy policy.
- Open Food Facts: receives food-search or barcode requests and supplies collaborative product data. Review its privacy information.
- PostHog EU: receives only after opt-in, under a separate random analytics ID. A strict allowlist excludes identity, URLs, free text, food, calories, photos, body, health and workout content. GeoIP, replay, autocapture and person profiles are disabled.
- Android Health Connect: remains permission-controlled on the device; Daystrong requests only steps and weight.
Clerk Production, RevenueCat and Google Play Billing are not active in this beta and receive no Daystrong account or purchase data. They will be added to this notice before they are enabled.
Optional analytics
Product analytics is off by default. You can enable or disable it in More → Your data. Opting out resets the local analytics identity and does not affect the app, feedback, activation or beta bonus. Logout also resets analytics. The marketing website asks separately and permits only an anonymous landing view and successful application event.
Retention, export and deletion
- Account content remains in the active PostgreSQL database until you delete it. If the beta closes without continuing, Daystrong will notify testers and remove remaining beta accounts from the active database within 30 days.
- In-app deletion immediately removes the account and linked active-database rows, including diary, profile, workouts stored server-side, beta feedback, consent and AI-ledger association.
- The database is backed up every 24 hours on the same managed server. Each backup is checksum-verified, test-restored and scheduled for automatic deletion when it reaches seven days. A row deleted from the active database can remain in an older recovery-only backup until that scheduled expiry; no later backup contains it.
- Expired invite records and size-limited infrastructure logs may remain temporarily for security and abuse prevention. An encrypted off-host backup, a production restore drill, and fixed time-based infrastructure-log deletion remain mandatory before Wave 2.
- You can generate a JSON export in More → Your data or request access, correction or deletion by email.
Security and international processing
Daystrong uses encrypted transport, account-scoped access, hashed passwords, rate limits and server-side entitlements. Hosted processors may handle data outside Switzerland under their published terms and safeguards. No online service is risk-free; report suspected incidents to support@arturf.ch.
Your rights and contact
Depending on applicable Swiss or European data-protection law, you may request information, access, correction, deletion, restriction, objection or a portable copy. Contact support@arturf.ch. Identity may be verified before account information is disclosed.
This page is a plain-language summary provided for transparency while Daystrong is in early access. It is not legal advice, and it will be replaced by a full agreement before any paid plan launches. Questions? Email support@arturf.ch.