Privacy Policy
Effective 26 September 2026 · Version 2026-09-26
Omir Lazzat (Sole trader, Dombyra 7, Almaty 050010, Kazakhstan) — "we", "us" — operates the Split AI mobile application (the "App"). We are the data controller for the personal data described here. Contact: support@getsplitai.app.
Split AI is a fitness app. It is not a medical device and does not provide medical advice, diagnosis, or treatment. See the Health & Fitness Disclaimer.
1. Summary
- We collect what changes your plan: your goals, schedule, body basics, limitations, diet preferences, your gym's equipment, and what you log.
- Photos you take (gym, meals, and — only if you opt in — your physique) are sent from our servers to our AI provider for analysis. We never use your photos to train AI models, and neither does our AI provider under its terms for our business account.
- After a photo is analysed we keep the structured result, and by default we **delete the original image within 7 days** unless you choose to keep it.
- Photos are stored in private storage, encrypted, and reachable only through short-lived signed links tied to your account.
- Physique photos are optional, require your separate explicit consent, and can be withdrawn and deleted at any time.
- You can export your data and delete your account from Me in the App.
2. What we collect
2.1 Account and identity
Sign in with Apple or Google identifier (pseudonymous subject ID); the email address Google shares when you sign in with Google (Sign in with Apple shares none with us); authentication tokens. Source: you and your sign-in provider.
2.2 Profile and plan inputs
Display name (optional), age range, biological sex (optional; used only for energy-expenditure maths), height, weight, units, time zone, training experience, environment, coaching intensity, primary and specific goal, available days, session duration.
2.3 Health-adjacent information you choose to give
Injuries, movement restrictions, exercises to avoid, dietary preference, allergies, excluded foods, weight history, workout performance, and — if you opt in — physique observations. All of these are optional beyond what is needed to build a plan, and the App lets you skip sensitive fields.
Where you are in the EU/UK, some of this may be health data (GDPR Art. 9). We process it only on the basis of your explicit consent, which you can withdraw at any time.
2.4 Photographs
- Gym photos — to detect equipment. (
images.purpose = gym_photo.) - Free gym-scan preview, before you have an account — up to 10 gym photos, a quick equipment preview, and a per-device record that a preview was used. Faces we detect are blurred on your phone before upload. If you don't subscribe, we delete these photos and results from our servers within 24 hours. If you do, they move into your account for the full scan.
- Meal photos — to estimate foods, portions, and macros.
- Physique photos (front/side/back) — optional, consent-gated.
For every image we store: a private storage key, content type, byte size, dimensions, a SHA-256 hash and a perceptual hash (used to spot duplicate and repeated uploads so we don't analyse or bill the same photo twice).
2.5 Usage, logs, and diagnostics
Workout sessions and set logs, meals and corrections, check-ins, coaching messages you receive, notification preferences and push token, and pseudonymous product analytics events (not currently sent). The iOS app contains no crash-reporting SDK. Our server logs deliberately exclude image content and are configured to redact personal data.
2.6 AI operations metadata
For each AI call we record the feature, model, status, token counts, image count, latency, retries, and estimated cost, plus a hash of the request — never its content. This is how we monitor reliability and cost.
2.7 Subscription
Your plan, product ID, purchase and expiry dates, trial and renewal flags, and Apple's transaction identifiers, from the signed App Store records Apple sends us. We never receive your card or payment details — Apple sells the subscription and processes payment.
2.8 What we do not collect
Precise location, contacts, microphone audio, health records from Apple Health or Google Fit (unless and until we add such an integration, which would require a fresh permission and a policy update), advertising identifiers, or biometric identifiers used to identify you. We do not perform facial recognition, and we do not use physique photos to identify anyone. Before a gym photo is uploaded, the App looks for faces on your phone only to blur them; nothing about a face is stored or sent, and we do not try to identify anyone.
3. Why we use it, and our legal bases (GDPR / UK GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account | §2.1 | Contract (Art. 6(1)(b)) |
| Build and adapt your workout and nutrition plan | §2.2, 2.3, gym results, logs | Contract; explicit consent (Art. 9(2)(a)) for health-adjacent inputs |
| Detect equipment from gym photos | Gym photos | Contract |
| Free gym-scan preview before an account | Preview photos, per-device preview record | Steps before a contract at your request (Art. 6(1)(b)); legitimate interests for people who appear in the background, protected by on-device face blurring (Art. 6(1)(f)); legitimate interests for the one-preview-per-device limit |
| Estimate nutrition from meal photos | Meal photos | Contract; explicit consent where treated as health data |
| Physique analysis and comparison | Physique photos + observations | Explicit consent only (Art. 6(1)(a), 9(2)(a)) |
| Reminders, check-ins, coaching messages | §2.5 | Consent (push); legitimate interests for in-app messages |
| Manage subscriptions and enforce tier limits | §2.7 | Contract |
| Product analytics and improvement | Pseudonymous events | Consent where required; otherwise legitimate interests |
| Crash and error diagnostics | Diagnostics | Legitimate interests (a working, secure app) |
| Abuse prevention, rate and cost limiting | §2.6 | Legitimate interests |
| Legal compliance, tax, disputes | Minimum necessary | Legal obligation; legitimate interests |
Withdrawing consent stops future processing of that kind and does not affect processing already carried out. Withdrawing physique consent also deletes the associated photos and observations.
4. Automated processing and AI
Split AI uses generative AI (Google's Gemini on Google Cloud Vertex AI, called only from our servers) to interpret your photos and to personalise and explain your plan. Important limits we hold ourselves to:
- AI is not the sole source of truth. Calorie and macro targets, exercise eligibility, equipment compatibility, volume and progression limits, scheduling, and subscription limits are computed by deterministic application logic, not by the model.
- Estimates are labelled as estimates. Photo-based nutrition figures and physique observations are approximations, not measurements. We do not give you a score, a number or a rating for your body; if we ever add one, we will ask for your physique consent again first.
- Your corrections win. When you correct a detected item, food, or portion, your correction overrides the AI output and is used in future personalisation.
- We never claim medical findings. No diagnosis, no body-fat percentage from a photograph, no guaranteed results.
- These processes do not produce legal or similarly significant effects on you within the meaning of GDPR Art. 22. You can always edit inputs, correct outputs, or stop using a feature.
5. Photographs: how they are handled
- The App may resize or compress a photo on your device before upload.
- Upload goes directly to private object storage using a signed URL valid for at most 10 minutes. No bucket is public and no image is served from a guessable address.
- Our server sends the image to the AI provider for a single analysis and stores the **structured result** (items, categories, capabilities, confidences, macros, observations).
- The original is then subject to your retention setting: by default it is deleted after 7 days; if you turn on "keep originals" it is kept until you delete it, your account, or the relevant record.
- Historical images are re-sent to the AI only where a visual comparison genuinely requires it (for example a same-view physique comparison) and only if the original still exists.
- Preview photos taken before you have an account follow the same path, with two differences. Faces we detect are blurred on your phone first. And if you don't subscribe within 24 hours, the photos and their results are deleted from our servers.
- No model training. We do not train models on your photos and our AI provider is contractually barred from using our content to train its models.
Nothing is shared from the App. There is no share card or share button for physique photos; the only way a copy leaves the App is your own data export (§9).
6. Sharing
We do not sell personal data and we do not "share" it for cross-context behavioural advertising as those terms are used in the CCPA/CPRA. We use these processors:
| Processor | Purpose | Data | Notes |
|---|---|---|---|
| Google Cloud (Gemini on Vertex AI) | Image and text analysis | Images sent for analysis; assembled context | Processor under the Google Cloud Data Processing Addendum, which includes the EU Standard Contractual Clauses; Google is certified under the EU-US Data Privacy Framework. Google does not use our content to train its models. The AI analysis may run in Google data centres outside the United States. |
| UpCloud | Running our servers; managed Postgres database; private photo storage | Images; account, profile, logs, results; all data our servers process | Processor (UpCloud Oy, Finland; US data centres operated by UpCloud USA Inc.). Encrypted in transit and at rest; region United States |
| Google (Sign-In) | Sign in with Google, if you choose it | Google account ID and verified email | Independent controller for your Google account |
| Apple | In-app purchase, Sign in with Apple, push delivery (APNs), App Attest for the free preview | Purchase and delivery data; Apple ID token and revocation at deletion; a device attestation key | Independent controller for payment and Apple ID |
| Our email provider (if configured) | Service email, such as the notice before your data is erased | Email address, the message | Processor |
| Our team alert channel (if configured) | Internal cost and abuse alerts to our team | Pseudonymous user ID, feature, cost figures; never content | Processor |
| PostHog | Product analytics — not active in the current app: no events are sent. We only call its deletion API when you delete your account | Pseudonymous events, no PII | We will update this policy before turning it on |
| Cloudflare | Our website getsplitai.app and its domain name system; forwarding email sent to our support address | Website visitors' IP address and request details; emails you send us | Processor. Data from the App does not pass through Cloudflare |
We may later move our servers, database or photo storage to another provider, such as Cloudflare. If we do, we will update this list before your data moves, and if you are in the EEA, the UK or Switzerland the App will show you the updated notice in §8a and ask you to confirm it again.
We may also disclose data to comply with law, to enforce our Terms, or in a merger or acquisition (with notice to you).
8a. Where your data goes, and transfers from the EEA, UK and Switzerland
We run Split AI from Kazakhstan. Your data is stored by our providers in the United States (UpCloud and Google). When Google's Gemini AI analyses your photos and requests, Google may process them in its data centres in other countries, including countries outside the EEA and the UK. We can access your data from Kazakhstan to run and support the App. Kazakhstan, the United States (except for providers certified under the Data Privacy Framework) and some of the countries Google may use are not covered by an EU or UK adequacy decision, so for data from the EEA, the UK and Switzerland we rely on:
- with our providers: the European Commission's Standard Contractual Clauses (and the UK Addendum / Swiss amendments) in each provider's data processing terms, or the provider's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions where it holds one;
- for our own access from Kazakhstan: the GDPR and UK GDPR apply to us directly as the operator (we offer the App to you in the EEA/UK), and we apply the security measures in §8 — encryption in transit and at rest, access limited to what support requires, no one browsing your photos.
Laws in these countries may allow public authorities to request data, and your rights there may be harder to enforce than at home. You can ask support@getsplitai.app for a copy of the clauses that apply. If you are in the EEA, the UK or Switzerland, the App asks you to confirm you have read this before you create an account; that confirmation is a record that you were told, not the legal basis for the transfer, and declining it means we cannot provide the App to you.
7. Retention
See our Data Retention and Deletion schedule for the full schedule. In outline: gym-scan preview photos and results are deleted within 24 hours unless you subscribe, and the per-device preview record (no photo, hash or equipment list, never linked to an account) is kept for up to 12 months; original photos default to 7 days; structured results and logs live for the life of your account; deleted accounts are erased within 30 days after a 7-day grace period; AI cost-ledger rows are kept 24 months in a de-identified form. App Store purchase and tax records are kept by Apple, which sells the subscription. After your account is deleted we keep only a minimal purchase record — the product, dates, and a one-way code in place of Apple's transaction number, with nothing linking it to you — for up to 7 years, to handle refunds and fraud and for our accounts. If you deleted an account that used Sign in with Apple, we also keep a one-way code of that Apple identity for up to 7 years so the deleted account is not recreated by mistake.
If your subscription ends and you do not return, we do not keep your history forever. Counting from the day your paid access actually expires (not the day you cancel):
| What | Erased after |
|---|---|
| Your AI memory summary — the profile we build of your habits to personalise coaching | 6 months |
| Physique observations | 3 months |
| Meal history and your corrections | 6 months |
| Workout, weight, and check-in history, and coach notes | 12 months (coach notes: 6 months) |
| Your saved gyms and confirmed equipment | 12 months |
We tell you in the app 30 days before anything is erased, and we also email you if we have your email address (we do when you sign in with Google; Sign in with Apple gives us none). The notice has one tap to export your data and one tap to keep it by resubscribing. If you resubscribe at any point, the clock resets and nothing is erased. If you never subscribed, we measure the same periods from your last activity. None of this affects an active subscription, and it does not change your right to delete your account at any time.
If you do not want the App to keep a summary of your habits to personalise coaching, contact support@getsplitai.app and we will delete it and stop building it; your plan still works without it.
8. Security
Encryption in transit (TLS) and at rest; private buckets with no public access; short-lived signed URLs; least-privilege service credentials; hashed refresh tokens; per-user scoping on every API route; rate limits and per-user cost budgets; logs that exclude image bytes and redact personal data; separate development, staging, and production environments. No system is perfectly secure, and we will notify you and the relevant regulator of a qualifying breach as required by law.
9. Your rights
Wherever you live, you can: access your data, export it, correct it, delete your account and data, withdraw any consent, and turn off notifications. In the EEA/UK you additionally have rights to restriction, objection, portability, and to complain to your supervisory authority. In California you have the rights to know, delete, correct, and to limit use of sensitive personal information, and we will not discriminate against you for exercising them. If you live in Washington State or Nevada, our Consumer Health Data Privacy Policy (getsplitai.app/health-data) describes your additional rights over health-related data, and we apply it to everyone in the United States.
Use Me → AI consents & data and Me → Delete account in the App, or write to support@getsplitai.app.
Your export. Me → AI consents & data → Export makes a file with your data. Photo links in an export work for 7 days for anyone who has the file (physique photo links: 24 hours); deleting your account or withdrawing the photo consent disables them. Keep the file private. We respond within 30 days (45 days in California, extendable once with notice), and we verify requests through your signed-in account.
10. Children
The App is for people aged 16 and over (18 and over for physique analysis). See our Minors Policy. We do not knowingly collect data from children below that age; if we learn we have, we delete it.
11. Changes
We will post any change here and bump the version. For material changes affecting how we use your photos or health-adjacent data we will notify you in the App and, where required, ask for consent again before the change applies to you.
12. Contact
Omir Lazzat, Dombyra 7, Almaty 050010, Kazakhstan · support@getsplitai.app · Governing law: the Republic of Kazakhstan, with the courts of Almaty.