Last updated: July 1, 2026
Swolly LLC ("we," "our," or "us") operates the Swolly mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this policy carefully. By using Swolly, you agree to the collection and use of information in accordance with this policy.
When you create an account, we collect:
If you sign in using Google or Apple, we receive your name, email address, and profile picture (Google) or name and email address (Apple) from those services. Apple users may choose to share a private relay email address instead of their real one. We do not receive or store your Google or Apple password.
During onboarding (or later from Fuel Settings), you may provide the following profile details so the App can personalize calorie and macro targets:
This information is stored in your private account data and is not visible to other users. You can skip these prompts during onboarding; doing so disables calorie and macro tracking but does not affect the rest of the App.
If you choose to connect Apple Health (iOS) or Health Connect (Android), we may read the following data types:
On iOS, we also write workout data (from runs you track in Swolly) back to Apple Health with your permission. On Android, Swolly currently only reads from Health Connect and does not write data back.
If you join a competition that tracks fitness metrics (such as steps, calories burned, distance, active time, or body-weight change in weight-loss competitions), your competition score derived from health data may be visible to other participants on the competition leaderboard. This includes:
We do not share raw health data (individual workouts, heart rate, etc.) with other users. Only aggregated competition scores are visible on leaderboards.
If you use the run-tracking feature, we collect precise GPS location data including:
We request background location access so that run tracking continues when the App is minimized. Location data is collected only while you are actively tracking a run and is never collected passively. Your GPS route data is private and visible only to you.
When you use calorie tracking, we collect:
If you use the task feature, we collect task names, due dates, and completion status. Task reminder times are used to schedule local notifications on your device.
When you participate in competitions, we collect:
This data is visible to other participants in the same competition.
We access your camera and photo library only when you actively choose to:
We do not access your camera or photo library in the background.
Image processing: When you upload a photo, the image is re-encoded on your device before upload. This process removes EXIF metadata — including GPS coordinates, device information, and camera details — from the image file. This is done to protect your privacy; only the visible image content is stored on our servers.
We automatically collect certain information through Firebase services:
If you use the "Suggest a Recipe" feature to recommend one of your private recipes to the Swolly team, the following information is sent to us for review:
Suggestion data is stored in a private collection that only the Swolly team can access, and a notification is sent to our internal review inbox. If we publish your suggestion as a Swolly Official recipe, your display name will appear as a plain-text credit on that recipe ("Suggested by <your display name>"). We will not link to your profile or expose any other personal information.
You can request deletion of a submitted suggestion at any time by emailing support@swolly.io.
If you send us feedback through More > Send Feedback, we collect the message you write along with your user ID, email address, display name, operating system, and app version (so we can respond to you and reproduce reported bugs). Feedback is stored in a private collection that only the Swolly team can access, and a copy is emailed to our support inbox. Feedback submissions are deleted when you delete your account.
| Purpose | Data Used |
|---|---|
| Provide and maintain the App | Account info, fitness data, nutrition data |
| Enable competition features and leaderboards | Activity posts, scores, rankings, social interactions |
| Track your runs with GPS mapping | Location data |
| Sync with your device's health app | Health data (with your permission) |
| Send push notifications | FCM token, notification preferences |
| Send transactional emails (password reset, verification) | Email address |
| Diagnose bugs and improve the App | Crash reports, analytics, performance data |
| Track your nutrition and calorie goals | Food entries, macro data, barcode lookups |
| Provide AI-powered fitness and nutrition suggestions | Your messages to Swolly AI, profile data (fitness goals, dietary preferences, height, weight, age, gender, activity level), and — when needed to answer your question — your meal logs, nutrition summaries, recipes, tasks, and workout plans |
| Respond to feedback and bug reports | Feedback message, email address, display name, OS and app version |
We do not use your data for advertising. We do not sell your personal information to third parties. We do not use health data for any purpose other than providing fitness tracking features to you.
Swolly includes an AI companion feature powered by Google's Gemini API. When you use the AI companion:
The following information is visible to other Swolly users:
The following information is never shared with other users:
We use the following third-party services to operate the App:
| Service | Provider | Purpose |
|---|---|---|
| Authentication, Database, Storage | Google Firebase | Core infrastructure |
| Analytics | Firebase Analytics (Google) | Usage metrics |
| Crash Reporting | Firebase Crashlytics (Google) | Bug detection |
| Performance Monitoring | Firebase Performance Monitoring (Google) | App startup and network latency metrics |
| Push Notifications | Firebase Cloud Messaging (Google) | Delivering notifications |
| Maps | Google Maps | Displaying run routes |
| Nutrition Lookup | Open Food Facts | Barcode product lookup (no user data sent) |
| Email Delivery | Gmail SMTP | Transactional emails from no-reply@swolly.io |
| Subscription Management | RevenueCat | Processing in-app subscriptions and purchase validation |
| AI Assistant | Google Gemini API | Powering the Swolly AI companion for personalized fitness and nutrition suggestions |
These providers process data on our behalf and are bound by their own privacy policies and data processing agreements.
When you subscribe to Swolly Pro, subscription management is handled by RevenueCat, Inc. The following data is shared with RevenueCat:
RevenueCat does not receive your name, email, health data, fitness data, or any content you post in the App. For more information, see RevenueCat's Privacy Policy.
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or subpoena).
Your data is stored on Google Firebase servers located in the United States. We implement the following security measures:
In the unlikely event of a data breach that compromises your personal information, we will:
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes (e.g., resolving disputes, enforcing our agreements).
| Data Type | Retention Period |
|---|---|
| Account data, fitness data, nutrition data, recipes, tasks, workouts, runs | Until account deletion + 30 days |
| Feedback submissions and recipe suggestions | Until account deletion + 30 days |
| AI conversation history | Until account deletion + 30 days |
| Content moderation reports | 12 months after resolution (for pattern detection); indefinitely if unresolved |
| Data export files | Available until account deletion; download links remain active until the file is deleted |
| Firebase Analytics data | 14 months (Google's default retention), then automatically deleted |
| Firebase Crashlytics data | 90 days (Google's default retention) |
| Anonymized/aggregated data | Indefinitely (cannot be used to identify you) |
| Inactive accounts | Accounts inactive for 24 months may be deleted after email notification |
If your account has been inactive (no logins) for 24 consecutive months, we may send you an email notification at the address on file. If you do not log in within 30 days of that notification, we may delete your account and all associated data. This helps us comply with data minimization principles and reduce unnecessary data storage.
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
| CCPA Category | Examples | Sold? |
|---|---|---|
| A. Identifiers | Name, email, unique user ID | No |
| B. Personal Information (Cal. Civ. Code § 1798.80(e)) | Name, email address | No |
| C. Protected Classifications | Gender and age (date of birth), collected during onboarding to personalize calorie and macro targets | No |
| D. Commercial Information | Subscription purchase history, subscription status | No |
| F. Internet/Network Activity | App usage data, feature interactions, crash logs | No |
| G. Geolocation Data | Precise location (only during active run tracking, with your permission) | No |
| K. Inferences | Fitness preferences, dietary goals (derived from profile data) | No |
We do not collect Category E (biometric data), Category I (professional information), or Category J (education information). Fitness data synced from Apple Health or Health Connect (steps, calories, distance, workouts) may fall within Category H (sensory data) depending on the source device. This data is collected only with your explicit consent and is used solely for the fitness tracking features described in Section 1.2.
Under the CPRA, the following categories of data we collect are classified as Sensitive Personal Information (SPI):
Swolly uses Sensitive Personal Information only to provide the App's features as described in this Privacy Policy. We do not use SPI for cross-context behavioral advertising or any purpose other than providing the services you expect. You have the right to limit the use of your Sensitive Personal Information — contact us at support@swolly.io to exercise this right.
To exercise any of the above rights, contact us at support@swolly.io.
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out. Contact us at support@swolly.io to exercise these rights.
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws.
We process your personal data on the following legal bases:
| Lawful Basis | Processing Activity |
|---|---|
| Contract Performance (Art. 6(1)(b)) | Providing the App, managing your account, processing subscriptions, enabling competition and social features |
| Legitimate Interests (Art. 6(1)(f)) | Analytics and crash reporting (to improve the App), fraud prevention, security monitoring |
| Consent (Art. 6(1)(a)) | Location tracking during runs, push notifications |
| Explicit Consent for Special Category Data (Art. 6(1)(a) + Art. 9(2)(a)) | Health data integration (Apple Health/Health Connect), health and profile data sent to the AI companion (height, weight, age, gender, fitness goals, dietary preferences, and — when relevant to your question — meal logs, nutrition summaries, recipes, tasks, and workout plans), health data shared on competition leaderboards (including body-weight change in weight-loss competitions). Health and fitness data is classified as special category data under GDPR Article 9. Separate explicit consent is obtained via dedicated consent dialogs before each of these processing activities begins. |
Where we rely on consent, you may withdraw it at any time by adjusting the relevant settings in the App or your device, or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to:
To exercise any of these rights, contact us at support@swolly.io. We will respond within 30 days.
Your data is stored on Google Firebase servers in the United States. For transfers of personal data from the EEA, UK, or Switzerland to the US, we rely on the following safeguards:
You may request a copy of the applicable safeguards by contacting us at support@swolly.io.
Swolly LLC does not currently have a designated Data Protection Officer. For privacy-related inquiries, data access requests, or complaints, you may contact us at support@swolly.io.
Swolly is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. Users must confirm they are at least 18 years old when creating an account.
If we learn that we have collected personal information from a person under 18, we will promptly delete that information. If you believe someone under 18 has created an account, please contact us at support@swolly.io.
The App may contain links to third-party websites or services (e.g., recipe URLs). We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any personal information.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy in the App and updating the "Last updated" date. Your continued use of the App after changes are posted constitutes your acceptance of the revised policy.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Swolly LLC
Lehi, UT 84043
Email: support@swolly.io
Website: swolly.io