This document explains what data the Swet app collects, why, who it is shared with, and how you stay in control of it.
Data controller:
PeakyApps Ltd, a company incorporated in England and Wales, company number 14368305
Registered office: Izabella House, 24–26 Regent Place, City Centre, Birmingham, B1 3NJ, United Kingdom
info@swet.coach
The controller is established in the United Kingdom, so the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR) apply. For users in the European Economic Area, Regulation (EU) 2016/679 (GDPR) also applies, and for users in Switzerland the Federal Act on Data Protection (FADP). UK-specific information is in section 11. Information for the creators of our affiliate programme is in section 12.
| Category | What it covers | Source |
|---|---|---|
| Account | Email address and password (stored only as a hash, never in clear text), active sessions. | You, at sign-up. |
| Profile and goals | Sex, date of birth, height, weight, activity level, goal, training experience, available days, equipment, session length. | You, during onboarding. |
| Health data 🔒 | Weight and its trend, body composition (body fat, lean mass, waist), injuries, dietary restrictions and allergies, steps, active and resting energy, heart rate (at rest and during workouts) and its variability, sleep (start, end and length of each sleep period, and whether the source records sleep stages), water intake, VO2 max, workouts and exercise sessions, and the daily energy curve the app derives from them. | You, and only with your permission, Apple Health or Health Connect. |
| Nutrition | Meal plans, meals, logged foods, supplements, calorie and macronutrient targets. | You, and assisted generation. |
| Training | Plans, sessions, exercises, sets, reps, loads, progressions. | You, and assisted generation. |
| Coach conversations | Messages exchanged and images you choose to send (menus, labels, meals). | You. |
| Notifications | Device push token, preferences, delivery history. | Your device, if you allow notifications. |
| Subscription | Subscription status, active period, AI feature usage. | Apple/Google via RevenueCat. |
| Consents | When you accepted the terms and gave consent, so we can evidence it. | Your actions in the app. |
| Invite and creator codes | The code you used, when, and whether the linked gift was delivered. The creator whose code you used sees only aggregate numbers, never who you are. | You, if you enter a code. |
| Ad attribution | A few conversion signals (install, app opens, finishing onboarding, subscription) with an anonymous identifier that Meta's SDK creates for this installation of the app, and your device's IDFA. Only if you allow the iOS tracking question; otherwise none of this is collected. | Your device, after your consent. |
| Apple Search Ads attribution | Whether you installed the app from an Apple Search Ads campaign and, if so, which campaign, ad group and keyword, and when the ad was tapped. No IDFA and no tracking question: iOS gives the app a one-off token that only Apple can read. | Apple, from the token your device provides on first launch. |
| Usage statistics | Which screens you open, which features you use, how often, what fails. Counts and categories, never values: we know you logged a meal, not which one; that you weighed yourself, not how much. | Your activity in the app, unless you turn it off. |
We do not collect your location or your contacts. Swet contains no advertising and never shows you ads.
We run ads to be found, and we need to know which ones actually bring someone in. For that, the app may send Meta (Facebook, Instagram) a small set of signals: the install, app opens, finishing onboarding, and the start and renewals of a trial or subscription, with its amount. Subscription signals do not leave your phone: RevenueCat, which manages subscriptions on our behalf, sends them to Meta, and only for people who gave consent.
Only if you let us. During sign-up, right after you accept the terms, iOS asks its own tracking question: your answer is your consent. If you decline, or have not answered yet, we send Meta nothing at all: Meta's SDK in the app is not even started. On Android the app sends nothing to Meta.
| The iOS question | What Meta receives |
|---|---|
| declined, or not answered yet | nothing |
| allowed | the signals listed above, with the anonymous installation identifier, plus your device's advertising identifier (IDFA) and identifier for vendor (IDFV), which connect your subscription to the ad you clicked |
You can change your mind at any time: withdraw your consent with one tap on the “Ad attribution (Meta)” switch in Profile → Settings → Privacy. It takes effect straight away: the app stops sending signals to Meta and RevenueCat no longer has the identifiers it needs to pass your subscription on. You can also change the iOS answer under Settings → Privacy & Security → Tracking: if you turn tracking off there, the switch in the app can no longer turn attribution back on, you have to allow it again in the iOS settings first.
What Meta never receives: your weight, your meals, your workouts, your sleep, your goals, your coach conversations, and anything you have typed or photographed in the app. The signals it gets say that something happened, not what you eat.
If you found Swet through an ad in the App Store search results, we want to know which one, to understand which campaigns bring people who stay. On first launch the app asks iOS for an attribution token (Apple's AdServices framework) and sends it to our server, which asks Apple which campaign, if any, it belongs to. The token is deleted as soon as Apple answers, and in any case within 24 hours.
This does not use the IDFA, does not need the iOS tracking question, and involves neither Meta nor any other advertising network: Apple only confirms something it already knows, the ad you tapped in its own store. We keep the campaign, ad group and keyword identifiers with your account, and the acquisition channel (for example “Apple Search Ads” or “organic”) in our usage statistics.
To understand which parts of the app actually help and where people get stuck we use PostHog, hosted in the European Union (Frankfurt), which processes them on our behalf. Usage statistics are linked to your account through your user identifier (not your email address), so they are pseudonymous, not anonymous.
No health data goes into these statistics. That is not a promise: the events the app can send are a closed list, written in the code, where a property can only be a count, a yes/no, or one entry from a fixed set. A weight, a calorie or the name of a food has no box to sit in. Besides your subscription status, the only profile information that travels is: your goal (lose weight, maintain, gain weight or recomposition), how you train (weights, other training or not right now), whether you entered your body fat (yes or no, never the number), whether you connected Apple Health or Health Connect (yes or no) and the language the app is shown in. None of these is a measurement or health data: they are answers chosen from a fixed list, and they tell us who the app is really useful to.
It is never used for advertising, never sold, and never leaves the EU. You can turn it off at any time in the app, in Profile → Settings → Privacy, with the “Usage statistics” switch. Turning it off stops both the events the app sends and those our server sends to PostHog for your account.
When the app crashes or a screen fails to load, it sends a technical report to Sentry (Functional Software, Inc.), which stores it in its European Union data region (Frankfurt) and processes it on our behalf, so we can find and fix the fault. A report contains the error and where in the code it happened, the app version, the phone model and operating system, the screen that was open, and the technical steps just before it (for example, which screen was opened or which request failed, without its content).
A report is not linked to you. It carries no user identifier, no email address and no IP address, and the app strips anything that could contain what you typed or logged: no weights, meals, messages, search terms or screenshots. The basis is our legitimate interest in keeping the app working (see section 3). Sentry deletes reports after at most 90 days.
To see where the app is slow, Sentry also receives performance measurements for a sample of operations (about one in five): how long the app takes to start, to open a screen or to get an answer from our server. A measurement contains the name of the screen or the address of the request without its parameters (where, for example, a food search would be), and follows the same rules as a report: no user identifier, no IP address, no content. The legal basis and the 90 days are the same.
With your permission we read weight, body fat, lean mass, waist (Apple Health only), steps, active and resting energy, heart rate (at rest and during workouts), heart rate variability, sleep, water, VO2 max and workouts. We never write anything to Apple Health or Health Connect. This is optional (the app works without it) and you can revoke it at any time in your operating system settings.
Sleep powers the Energy feature, which estimates your energy curve for the day; together with the other data it is also used to compute your targets and to give the coach context for its advice (see section 4).
Data obtained from Apple Health is never used for advertising or marketing, never sold, and never shared with third parties for advertising purposes or with data brokers. We use it solely to make the app work for you: targets, plans, the coach and the Energy feature.
| Purpose | Legal basis |
|---|---|
| Creating and running your account. | Performance of a contract. |
| Computing targets, generating and adapting plans, keeping your logs. | Performance of a contract. |
| Processing health data (including what is read from Apple Health or Health Connect, such as sleep and heart rate), injuries and dietary restrictions. | Explicit consent, which you can withdraw. |
| Sending notifications and reminders. | Consent, revocable in settings. |
| Managing subscriptions and usage limits. | Contract and accounting obligations. |
| Security, abuse prevention, diagnosing faults and slowness. | Legitimate interest. |
| Understanding how the app is used, in order to improve it. | Legitimate interest; you can turn it off in the app. |
| Attributing a subscription to the ad that brought it. | Consent (the iOS tracking question), which you can withdraw with the “Ad attribution (Meta)” switch. |
| Knowing which Apple Search Ads campaign brought an installation. | Legitimate interest: measuring our own advertising, without tracking you across apps. |
Coaching features use Anthropic (Claude) models. When you generate or adjust a plan, or talk to the coach, we send the model the context it needs: your profile, goals, dietary restrictions, injuries, plans and conversation messages, including any images you send. If you connected Apple Health or Health Connect, the coach also receives your 7-day averages of sleep, resting heart rate and its variability, resting energy and water, your latest VO2 max, and the energy-curve figures the app has already computed.
Anthropic acts as a processor on our behalf. Under its commercial API terms, submitted content is not used to train models.
The model does not compute the numbers. Calories, macronutrients and totals are produced by our backend from verified food data; the model composes and explains, it does not invent figures. That is a design decision, not a marketing claim.
Swet is a wellness and fitness app. It does not provide diagnosis, treatment or medical advice and is not a substitute for a healthcare professional.
We do not sell personal data and do not pass it to third parties for their own purposes. We rely on these providers:
| Provider | Role | What it receives |
|---|---|---|
| Anthropic | Coaching models | Profile context, plans, messages, images you send and, if you connected Apple Health or Health Connect, the health averages described in section 4. |
| Hetzner Online | Hosting (Helsinki, Finland, EU) | The whole application database. |
| RevenueCat | Subscription management | User identifier and subscription status. Only if you allowed the iOS tracking question, also the attribution identifiers, which it passes on to Meta with subscription events. |
| Apple / Google | Payments, push notifications and, if you choose it, Sign in with Apple or Google | Transaction data, notification tokens; for sign-in, the account identifier and the email the service shares with us. |
| Expo | Push notification delivery | Device token and notification content. |
| Resend | Sending email (address verification, password reset, account notices and, only if you turned them on, summary emails) | Email address and message content. |
| Open Food Facts, USDA FoodData Central | Food databases | Only the search term or barcode. No profile data. |
| PostHog | Usage statistics (Frankfurt, Germany, EU) | User identifier, usage events, goal, how you train, app language and two yes/no answers (body fat entered, Apple Health or Health Connect connected). No health data. |
| Sentry | Crash reports and performance measurements (Frankfurt, Germany, EU) | Technical error reports: the error, app version, phone model, open screen; for a sample of operations, how long they took. No user identifier, no health data, no content. |
| Meta Platforms | Ad attribution | Only if you allow the iOS tracking question: conversion signals with an anonymous installation identifier, the IDFA and the IDFV. No health data, no content. |
| Apple | Apple Search Ads attribution | The attribution token your device generated. Apple answers with the campaign, if any; nothing else about you is sent. |
Payments never pass through us. Apple and Google handle them: we do not see, process or store your card details.
Data is hosted in the European Union. Some providers (Anthropic, RevenueCat, Sentry, Apple, Google, Expo, Resend and, if you agreed to ad attribution, Meta) may process it in the United States under standard contractual clauses or other safeguards permitted by law. For users in the UK, see section 11. PostHog is not one of them: usage statistics stay on European servers and never leave the EU.
We keep your data while your account is active. When you delete your account, personal data is erased from our database, including health data (also what was read from Apple Health or Health Connect, such as sleep) and the records of your purchases, and we also ask the providers that know you by your identifier to delete it (PostHog for usage statistics, RevenueCat for subscription status).
We do not keep a copy of your purchases: the seller is Apple or Google, which keeps the transaction and the receipt under its own rules, and our accounts are based on the aggregate reports the store sends us. If you signed up with a creator's code, the row recording that creator's commission remains (amount, currency, date and the store transaction number, used to match a possible refund) without your identifier or any other data from your account. Aggregate statistics that cannot be traced back to you also remain. Details and periods in section 11.6.
You have the right to access your data, correct it, delete it, obtain a copy in a readable format, restrict or object to processing, and withdraw any consent at any time.
You can delete your account and all associated data directly in the app, without writing to us or asking permission. You can also export your data.
Withdrawing consent is as easy as giving it. In Profile → Settings → Privacy there is a one-tap switch for each of these: “Newsletter”, “Ad attribution (Meta)” and “Usage statistics”. On the same screen, with “Withdraw consent to health data”, you can withdraw your health-data consent: since the app cannot work without that data, withdrawing it deletes your account and your health data.
For any request: info@swet.coach. If you believe the processing breaches the law, you may contact the Swiss Federal Data Protection and Information Commissioner, your national supervisory authority (EEA) or, if you are in the United Kingdom, the Information Commissioner's Office (see section 11).
Traffic is encrypted in transit (HTTPS). Passwords are stored as hashes and are not readable by us. Access to the production database is restricted. No system is impenetrable: should a breach occur that poses a risk to your rights, we will notify you as required by law.
Swet is for adults aged 18 and over. The app does not let anyone under 18 sign up and our server rejects dates of birth below that age; we do not knowingly collect data from minors. If you believe a minor has provided us with data, contact us and we will delete it.
If we change this document we will update the date at the top. For material changes we will tell you in the app before they take effect.
Swet is offered to people in the United Kingdom, so the processing of your data is subject to the UK GDPR (the GDPR as retained in UK law), the Data Protection Act 2018 and, for what the app reads from or stores on your device, the PECR. This section adds to the ones above; where it is more specific, it prevails.
The controller is PeakyApps Ltd (company number 14368305), registered office Izabella House, 24–26 Regent Place, City Centre, Birmingham, B1 3NJ, United Kingdom. As it is established in the UK, no representative under Article 27 UK GDPR is required.
Health data (weight, body composition, sleep, heart rate and its variability, energy, water, VO2 max, workouts, injuries, allergies and dietary restrictions) is a special category of data. We process it only with your explicit consent (Article 9(2)(a)), which you give with the dedicated checkbox at sign-up and which we record with the date and the version of the text you read.
| Purpose | Basis (Article 6 UK GDPR) | Health data (Article 9) |
|---|---|---|
| Creating and running your account; service emails (verification, password reset). | Contract, Article 6(1)(b). | Not applicable. |
| Computing targets, generating and adapting plans, keeping your logs, running the coach (including sending context to Anthropic). | Contract, Article 6(1)(b). | Explicit consent, Article 9(2)(a). |
| Reading Apple Health or Health Connect (including sleep for the Energy feature). | Contract, Article 6(1)(b), only after the system permission. | Explicit consent, Article 9(2)(a). |
| Push notifications; summary or come-back emails (off until you turn them on); the newsletter, once we send one. | Consent, Article 6(1)(a). | Not applicable. |
| Subscriptions, AI usage limits, invite and creator codes. | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c), for accounting. | Not applicable. |
| Security, abuse prevention, diagnosing faults and slowness. | Legitimate interests, Article 6(1)(f). | Not applicable. |
| Usage statistics (PostHog). | Legitimate interests, Article 6(1)(f): knowing what to improve. No health data. | Not applicable. |
| Ad attribution (Meta, including through RevenueCat). | Consent, Article 6(1)(a), given through the iOS tracking question. | Not applicable. |
| Apple Search Ads attribution. | Legitimate interests, Article 6(1)(f): measuring our own advertising. No IDFA, no tracking across apps. | Not applicable. |
Where we rely on legitimate interests you can object; for usage statistics the “Usage statistics” switch in Profile → Settings → Privacy is enough. You can withdraw any consent at any time, without affecting what was done before, from the same screen: “Newsletter”, “Ad attribution (Meta)” and “Usage statistics” each turn off with one tap. Without consent to health data the app cannot compute targets or plans, so the “Withdraw consent to health data” action deletes your account and your health data.
PECR governs what an app reads from or stores on your device.
You can ask us for a copy of the safeguards used at info@swet.coach.
Some things the app does on its own: the AI coach proposes plans and answers, your calorie target can be adjusted automatically each week (within fixed limits, announced every time, and you can turn it off in Profile), and AI features have periodic usage limits. None of these is a decision with legal or similarly significant effects on you: they do not concern credit, employment, insurance, medical care or access to rights, and whether to accept the coach's proposals is up to you. If you want a person to review something the app decided for you, write to us.
| Data | How long it stays |
|---|---|
| Everything tied to your account | As long as the account exists. When you delete it in the app it is erased from the database immediately. |
| Health data, including what is read from Apple Health or Health Connect (weight, body composition, sleep, heart rate, energy, water, VO2 max, workouts) and the energy curve the app derives from it | As long as the account exists. It is erased from the database immediately when you delete your account, including through “Withdraw consent to health data”. |
| Usage statistics (PostHog) | When you delete your account we ask PostHog to delete your profile and its events; if PostHog does not answer, we retry automatically. |
| Crash reports and performance measurements (Sentry) | At most 90 days, then deleted by Sentry. They are not linked to your account, so they cannot be traced back to you. |
| Subscription status (RevenueCat) | As long as the account exists. When you delete it we ask RevenueCat to delete the customer; if it does not answer, we retry automatically. |
| Your purchases | In our database, as long as the account exists. The transaction and the receipt are kept by Apple or Google, the seller. |
| Creator commissions | The commission row remains, without your identifier or any other data from your account, for six years from the end of the financial year in which the creator was paid: it is PeakyApps Ltd's accounting record (retained for tax purposes with HMRC; the Companies Act 2006, s. 388, requires at least three). |
Under the UK GDPR you have the right to access your data, correct it, erase it, restrict its processing, receive it in a machine-readable format, object to processing based on legitimate interests, object at any time to direct marketing, withdraw consent, and not be subject to solely automated decisions with significant effects. We respond free of charge and within one month (extendable by two months for complex requests, in which case we tell you); we may ask you to confirm who you are.
If you think we are mishandling your data, please write to us first at info@swet.coach: we acknowledge your complaint within 30 days and respond without undue delay.
You always have the right to complain to the UK regulator, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, phone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Swet is for people aged 18 and over, in the United Kingdom too: the app blocks sign-up under 18 and the server rejects the dates of birth of minors.
This section concerns the creators who take part in our affiliate programme and use the creator portal on swet.coach, not the people who use the app. The controller is PeakyApps Ltd here too.
| What we process | What for |
|---|---|
| Name, email address and your creator code. | Running the programme: attributing the codes, inviting you to the portal, sending you the monthly statement. |
| Your portal account: email address and password (stored only as a hash, never in clear text). | Letting you sign in to the portal. |
| Payment details (for example IBAN or PayPal address), stored encrypted. | Paying your commissions. |
| Your commission terms, the aggregate figures of your code (redemptions, payments, commissions) and the payments we made to you (amount, date, transfer reference and, if there is one, your invoice number). | Calculating and paying commissions, the monthly statement, our accounts. |
In the portal you see only aggregate numbers, never who used your code: no names, no email addresses, no rows per person.
Legal basis: the contract between you and PeakyApps Ltd (Article 6(1)(b) GDPR and UK GDPR); for keeping the accounting records, our legal obligation (Article 6(1)(c)).
How long: the records of commissions and payments, with the name they were paid to, for six years from the end of the financial year in which they were paid, like all of PeakyApps Ltd's accounting records (see section 11.6). Everything else for as long as you take part in the programme; when you leave it, you can ask us to delete it.
Who we share them with: nobody beyond the providers in section 5 that this needs (Hetzner, which hosts the database, and Resend, which sends the invitation and the statements) and, when we pay you, the bank or PayPal that carries out the payment. Your payment details are decrypted only to show them to you in the portal and to us to make the payment; they never end up in logs or usage statistics.
Your rights are those in section 7 (and, in the United Kingdom, section 11.7); to exercise them, write to info@swet.coach.