Privacy Policy
Plated Fitness · Last updated 24 September 2026
Plated Fitness (“Plated”, “we”, “us”) is a nutrition and training app. This policy explains what we collect, why, who else sees it, and how you get rid of it. It covers the Plated iOS and Android apps and the accounts behind them.
The short version. We collect what the app needs to work: your account details, the food and workouts you log, and anything you choose to post. We do not sell your data, we do not run ads, and we never use your health data for marketing. Sensitive things like your GPS routes and heart rate sync privately to your own account and are never shown to other users. You can delete your account and everything in it from inside the app, immediately, without asking us.
1. Who we are
Plated Fitness is operated by the developer identified on our App Store listing. For any privacy question, or to exercise any right described below, contact us at support@plated-fitness.com. We answer privacy requests within 30 days, and content reports within 24 hours.
2. What we collect
Information you give us
| Data | Why we have it |
|---|---|
| Email address and password | To create and secure your account. Passwords are hashed by our authentication provider; we never see or store the plain text. |
| Display name and username | To identify you to other users in the feed, on your profile, and in comments. |
| Date of birth | To confirm you are old enough to use Plated, and as an input to calorie and macro calculations, which depend on age. |
| Height, weight, sex, activity level and goals | To calculate your calorie and macro targets and to chart progress over time. |
| Profile photo | Shown on your profile and beside your posts. Optional. |
Health and fitness information
This is the heart of the app, and we treat it as sensitive:
- Nutrition — the foods you log, portion sizes, meals, calories and macronutrients, and your logging streak.
- Training — workouts, exercises, sets, reps, weights, cardio sessions, duration and distance.
- Body metrics — body weight history and any measurements you record.
- Heart rate — read live during a workout from a connected Bluetooth chest strap, or from Apple Health if you grant permission.
Apple Health (HealthKit)
If you enable Apple Health sync on iOS, Plated reads your heart rate so it can be displayed during a workout, and writes completed workout sessions back to Apple Health so they appear alongside your other activity.
Data obtained through HealthKit is never used for advertising, marketing, or use-based data mining; is never sold; and is never shared with any third party or data broker. It is used only to provide the features described here. Heart-rate readings recorded during a workout sync to your own private account so your training history follows you between devices — they are never stored in iCloud and never shown to other users. You can revoke Plated’s Health access at any time in the iOS Settings app under Privacy & Security → Health.
Location
When you start an outdoor cardio session, Plated uses your precise location — including in the background, so the run keeps recording with your phone locked — to draw your route and measure distance and elevation.
Location is only recorded while a cardio session is actually running — never in the background at any other time, and never merely because the app is open.
Your route syncs to your own private account so it survives losing or replacing your phone. It is stored in a row only you can read, enforced at the database level, and route coordinates are deliberately stripped out of anything visible to other users: when your workout appears on your profile or in the feed, other people see the summary — distance, pace, duration, elevation — and never the breadcrumb trail of where you actually were. We do not use your location for advertising, and we never sell or share it.
Photos, video and content you post
Photos and videos you attach to a post, a food entry, a custom exercise, or a feedback report are uploaded to our storage so they can be displayed. Posts, comments, likes, follows, reports and blocks are stored so the social features work. Photos you scan with the AI label scanner are sent for analysis (see section 4) and are not retained afterwards.
Information collected automatically
- Push notification token — a device identifier issued by Apple or Google, used only to deliver notifications you have opted into.
- Basic request metadata — IP address and timestamps are processed by our hosting provider as part of serving requests, and used to enforce rate limits and detect abuse.
Plated contains no analytics or tracking SDKs. We do not track you across other companies’ apps or websites, and we never use the Advertising Identifier for personalised advertising. Our App Store privacy label lists a device identifier under third-party advertising because the ad SDK is present on the free plan; the next section says exactly what it receives and what it does not.
Advertising on the free plan
If you use Plated without a Pro subscription, small banner advertisements appear on the Feed, Nutrition and Progress screens. They are served by Google AdMob and are non-personalised: we request ads that are not based on your behaviour or interests, and we never ask iOS for permission to track you. To serve and measure an ad, Google receives a device identifier that is not your Advertising Identifier, your IP address (from which it may infer an approximate location), and the fact that an ad was shown or tapped. Google does not receive your name, email address, food or workout logs, or anything from Apple Health. Advertising is removed entirely by subscribing to Plated Pro. Users in the European Economic Area and the United Kingdom are shown a consent form before any ad is requested, and can revisit that choice at any time from Profile → Settings.
3. What we do with it
- Provide the app: store your logs, compute targets, sync across your devices, and show your content to the people you have chosen to share it with.
- Operate the social features: feed, profiles, follows, comments, notifications.
- Keep the service safe: rate limiting, spam prevention, and reviewing reported content.
- Fix problems: respond to the feedback you send us.
- Handle subscriptions: confirm whether your Pro entitlement is active.
We do not use your personal data to target advertising, we do not sell it, and we do not share it for cross-context behavioural advertising. The banner ads on the free plan are described above.
4. Who else sees it
We use a small number of service providers, each with a narrow job. They process data on our instructions and may not use it for their own purposes.
| Provider | What it handles |
|---|---|
| Supabase | Our database, authentication, file storage and server functions. Nearly all your data lives here. |
| Google (Gemini API) | Powers the AI label scanner, AI food lookup, and the first-pass triage of reported content. Receives the photo or text of the item being analysed. Not used to train Google’s models. |
| FatSecret | Licensed food and restaurant nutrition database, queried by search term through our own server. It receives the search query, not your identity. |
| Open Food Facts, USDA FoodData Central | Public food databases we query by barcode or search term. They receive the search query, not your identity. |
| Expo | Delivers push notifications and app updates. |
| Google AdMob | Serves the non-personalised banner ads shown on the free plan. Receives a device identifier, IP address and ad interaction data; see “Advertising on the free plan” above. Not used if you subscribe to Pro. |
| Apple, RevenueCat | Process and validate in-app subscription purchases. We receive only whether your subscription is active and when the period ends. |
| Stripe | Processes subscription payments made outside the iOS app. |
We never receive your payment card details. Purchases made in the iOS app are handled entirely by Apple.
We may also disclose information where we are legally required to, or where it is genuinely necessary to protect the rights or safety of our users.
5. What other users see
Your profile, posts, comments and the workout and achievement summaries on your profile are visible to other users. You control the reach of this with the Profile Visibility setting in the app: set to Private, only your followers see your posts and stats. Your email address, date of birth, food logs, body measurements, heart-rate history and GPS route coordinates are never shown to other users — the last two are removed from your workouts before anything is published to a profile or feed.
6. Keeping it, and deleting it
We keep your data for as long as your account exists. You can delete your account from inside the app — Profile → Delete Account — and it takes effect immediately, with no request to us and no waiting period.
Deleting your account removes your profile, logs, media, posts, likes, follows and subscription record. Comments you left on other people’s posts are anonymised to [deleted] rather than removed, so that other people’s conversations do not collapse into holes. Backups are purged on a rolling 30-day cycle.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to processing, and to withdraw consent. Most of these you can exercise directly in the app; for anything else, email us and we will action it within 30 days, free of charge. If you are in the EEA or UK, our legal bases are performance of a contract (providing the app), your consent (Health data, location, notifications), and our legitimate interests (security and abuse prevention). You have the right to complain to your local data protection authority.
8. Security
All traffic between the app and our servers is encrypted in transit with TLS. Data is protected at rest by our hosting provider. Access to your rows is enforced at the database level by row-level security policies, so one user’s account cannot read another’s. Subscription entitlements can only be granted by a verified payment webhook, never by the app itself. No system is perfectly secure, but we take this seriously and fix what we find.
9. Children
Plated is not intended for children under 13, and we do not knowingly collect data from them. We ask for your date of birth at signup for this reason. If you believe a child has given us personal data, email us and we will delete it.
10. International transfers
Our providers operate in the United States and elsewhere. Where data is transferred out of the EEA or UK, it is protected by Standard Contractual Clauses or an equivalent safeguard.
11. Changes
If we change this policy materially we will update the date above and notify you in the app before the change takes effect. Continued use after that means you accept the revised policy.
12. Contact
Questions, requests, or complaints: support@plated-fitness.com.