Privacy Policy
Status: DRAFT — not yet published. Written 2026-07-07 as part of pre-launch checklist item
#9, updated 2026-07-19 with the operating entity (Entryze AB) and to correct sections that had
gone stale as features shipped (consent flow, self-service account deletion, diagnostic-collection
removal), and updated 2026-07-21 for the product rename from PTAI to CrestAI (name only — no
change to what data is collected, who operates the service, or how it is processed).
This is engineering-drafted text meant to accurately describe what the app actually
does. It has not been reviewed by a lawyer and must not be treated as final or legally binding
until it has been. Remaining [TBD]s: the exact Gemini paid-tier data-use citation (§5), and the
specific international-transfer safeguard Google's DPA points to (§6).
Last updated: 2026-07-21
1. Who we are (data controller)
CrestAI ("we", "us", "our") is operated by Entryze AB, a Swedish aktiebolag (org.nr 559545-3167), registered at Mölndalsvägen 87 f, 412 84 Göteborg, Sweden. Contact for privacy requests: eric.hallberg@entryze.com.
The app is not yet offered to paying customers — early testers use it free of charge under this policy and the accompanying Terms of Service.
2. What data we collect
CrestAI is a personal training journal and AI coach. All data is entered directly by you or generated by features you actively use — we do not passively track you across other websites or apps.
| Category | Examples | Where it lives |
|---|---|---|
| Account | Name, email, profile photo (via Google Sign-In) | Firebase Authentication |
| Profile | Weight, height, age, gender, activity level, calorie/macro targets | users/{uid}/profile/default |
| Training data | Workouts, exercises, sets, weights, reps, sleep notes, training plans | users/{uid}/sessions, users/{uid}/plans |
| Bodyweight log | Daily weight entries | users/{uid}/weight |
| Nutrition log | Meals, foods, macros, barcodes scanned | users/{uid}/nutrition, users/{uid}/food_cache |
| Illness periods | Self-reported illness date ranges and optional notes | users/{uid}/illness |
| Diet programs | Bulk/cut/maintenance targets and dates | users/{uid}/dietPrograms |
| AI coach conversations | Chat messages with our AI coach | users/{uid}/chats |
| AI suggestion history | A record of AI-generated workout proposals and whether you accepted them (not free-text chat messages) | users/{uid}/ai_workout_suggestions |
| AI usage | Token counts per month, used only to show you your own usage — not conversation content | users/{uid}/ai_usage |
| Legal & consent records | Confirmation of which version of these Terms/this Policy you accepted, and your health-data consent, each with a timestamp | users/{uid}/legal_acceptance, legal_acceptance_history, consent |
| Saved meals & pending plans | Reusable meal templates you've saved, and any AI workout suggestion you've saved for later | users/{uid}/saved_meals, pendingPlan |
We do not store error logs or AI-conversation telemetry on our servers — if something goes wrong, it is only ever visible in your own browser's console, never sent to us.
Some of this is health data (training performance, bodyweight, nutrition, illness periods) and is treated as a "special category" of personal data under GDPR Article 9, which requires your explicit consent before we process it — see §4.
3. How we use your data and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the core service (logging workouts, nutrition, plans) | Contract performance (6.1.b) |
| AI coaching, workout suggestions, monthly reports | Contract performance (6.1.b) + your explicit consent for the underlying health data (9.2.a) |
| Basic security, abuse prevention, error diagnostics | Legitimate interest (6.1.f) |
| Sending you service-related communications | Contract performance (6.1.b) |
We do not use your data for advertising, and we do not sell your data to anyone.
4. Special-category (health) data and consent
Training, nutrition, bodyweight, and illness data can reveal information about your health. Before
we process it, you must give explicit, opt-in consent on a dedicated screen — separate from
accepting this policy — confirming you understand and agree to health-data processing, and
confirming you are at least 13 years old. This consent is recorded, with a version and timestamp,
at users/{uid}/consent/default.
You can withdraw consent at any time from your Profile page. Because every feature in CrestAI reads health data, withdrawing consent means deleting your account (§8) — we offer you a full data export first, so nothing is lost without your say.
5. Who processes your data on our behalf (sub-processors)
| Sub-processor | What they do | Data involved |
|---|---|---|
| Google (Firebase / Google Cloud) | Hosting, authentication, database, app-runtime | All account and app data |
| Google (Gemini, via Firebase AI Logic) | Generates AI coaching responses, workout suggestions, monthly reports | Chat messages, training/nutrition data sent as context |
| Google (reCAPTCHA Enterprise, via Firebase App Check) | Confirms requests come from our real app, not a bot/script | Device/browser signals, no personal profile data |
Gemini and paid-tier data use: our Firebase project runs on the Blaze (billing-enabled) plan, which Firebase App Hosting requires. [TBD — verify precisely against Gemini API Additional Terms before publishing] Gemini API access through an active billing account is generally treated as a "Paid Service," under which Google does not use your submitted content to improve their general models — unlike the free tier. Confirm this holds for our exact configuration and state it precisely here.
Open Food Facts (openfoodfacts.org) is a public, open-data nutrition database we query when
you search for or scan a food. We send your search text or a barcode to their API; we do not send
any of your personal or account data to them. Their database is licensed under the Open Database
License, which is why food search results in the app carry an attribution notice.
6. International data transfers
Your data is stored in Google Cloud Firestore, in europe-north2 (Stockholm, Sweden) — your
data stays within the EU/EEA and does not require an international transfer safeguard for storage.
(Migrated 2026-07-07; see docs/pre-launch-checklist.md item #24 for the technical record.) Some
processing (e.g. Gemini inference) may still involve Google
infrastructure outside the EU for that specific request; this is covered by Google's Standard
Contractual Clauses / the EU-US Data Privacy Framework where applicable — verify and cite the
specific mechanism Google's DPA points to before publishing.
7. How long we keep your data
- Account and app data (sessions, plans, nutrition, weight, chats): kept for as long as your account is active. Deleted on request — see §8.
- Diagnostic data: we do not retain any diagnostic logs containing your messages or
conversation content — error and AI-performance diagnostics are not stored server-side at all
(they only ever appear in your own browser console). We do keep your AI-generated workout
suggestion history (
ai_workout_suggestions) for as long as your account is active, since it's part of your training record, not diagnostic telemetry.
8. Your rights
Under GDPR, you have the right to:
- Access your data — you can view everything in the app directly.
- Portability — download a full export of your data in JSON via the "Download my data" button on your Profile page (already built, checklist #22).
- Erasure ("right to be forgotten") — use the Delete account option in your Profile page's Danger Zone: type DELETE to confirm and we permanently erase all of your data immediately (we recommend downloading your data export first, from the same page). If you'd rather request deletion by email instead, contact eric.hallberg@entryze.com and we will delete your account and all associated data within one month, as required by GDPR Art. 12(3).
- Rectification — correct inaccurate data directly in the app, or contact us.
- Object / restrict processing — contact us.
- Withdraw consent at any time for health-data processing (§4), without affecting the lawfulness of processing before withdrawal.
To exercise any right not yet self-service in the app, contact eric.hallberg@entryze.com.
9. Children
CrestAI is not directed at children. You must be at least 13 years old to create an account — enforced both in the health-data consent flow (§4) and in profile validation.
10. Cookies and tracking
We do not currently use cookies for analytics or advertising. If that changes, this policy and a cookie consent mechanism will be updated before the change ships (checklist #45).
11. Changes to this policy
We will update the "Last updated" date above whenever this policy changes, and notify active users of material changes before they take effect.
12. Contact
Questions about this policy or your data: eric.hallberg@entryze.com.