Privacy Policy

Last Updated: November 21, 2025

Effective Date: November 21, 2025

1. Introduction

Welcome to WeightGPT ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services (collectively, the "Service"). By using WeightGPT, you consent to the data practices described in this Privacy Policy.

2. Information We Collect

2.1 Personal Information

  • Name: First name and last name
  • Email Address: Used for account creation, authentication, and communication
  • Age: Used for personalized plan generation
  • Biological Sex: Used for fitness and nutrition recommendations
  • Height and Weight: Used for BMI calculation and plan customization
  • Profile Photo: Optional, if you choose to upload one

2.2 Health and Fitness Data

  • BMI (Body Mass Index): Calculated from height and weight
  • Target Goals: Weight loss, muscle gain, maintenance, etc.
  • Workout Experience: Beginner, intermediate, or advanced
  • Activity Level: Sedentary, lightly active, moderately active, very active, or extremely active
  • Sleep Patterns: Target sleep hours and completion tracking
  • Stress Levels: Self-reported stress indicators
  • Daily Steps: Step count tracking
  • Exercise Completions: Records of completed workouts
  • Meal Completions: Records of completed meals
  • Weight Entries: Historical weight tracking data
  • Progress Photos: Optional, if you choose to upload them

2.3 Dietary Information

  • Diet Type: Vegetarian, non-vegetarian, vegan, etc.
  • Food Allergies: Allergies and intolerances
  • Cooking Ability: Skill level in meal preparation
  • Budget Level: Food budget preferences
  • Regional Preferences: Cuisine preferences and regional food choices
  • Meal Preferences: Breakfast, lunch, dinner preferences

2.4 Lifestyle Information

  • Job Type: Occupation and work schedule
  • Screen Time: Daily screen time tracking
  • Smoking Habits: Smoking status and frequency
  • Alcohol Consumption: Alcohol consumption patterns
  • Lifestyle Struggles: Self-reported challenges and goals
  • Habit Completions: Tracking of lifestyle habit adherence

2.5 Authentication Data

  • Password: Encrypted and hashed (we cannot see your actual password)
  • Google Sign-In Data: If you use Google authentication, we receive:
    • Google account email
    • Google account name (given name and family name)
    • Google account profile picture (optional)
    • Google account ID

2.6 Payment Information

  • Payment Method: Processed through Razorpay (we do NOT store credit card numbers, CVV, or full card details)
  • Transaction Records: Payment history, transaction IDs, amounts, and timestamps
  • Billing Address: If required for payment processing

2.7 Technical Information

  • Device Information: Device type, operating system, device identifiers
  • App Usage Data: Features used, time spent, interaction patterns
  • Log Data: IP address, access times, error logs, crash reports
  • Location Data: General location (country/region) - we do NOT collect precise GPS location

2.8 AI-Generated Content

  • Generated Plans: Workout plans, diet plans, and lifestyle plans created by our AI system
  • Plan History: All previously generated plans
  • User Feedback: Any feedback you provide on plans (if applicable)

3. How We Use Your Information

3.1 Service Provision

  • Generate personalized workout, diet, and lifestyle plans using AI-based personalization technology
  • Track and display your progress over time
  • Provide progress insights and recommendations
  • Manage your account and authenticate your identity
  • Process payments and manage subscriptions

3.2 Communication

  • Send you service-related notifications (password resets, account updates)
  • Respond to your inquiries and support requests
  • Send important updates about the Service
  • Send marketing communications (only with your consent, and you can opt-out anytime)

3.3 Service Improvement

  • Analyze usage patterns to improve our AI models
  • Enhance plan generation algorithms
  • Fix bugs and improve app performance
  • Conduct research and analytics (data is anonymized where possible)

3.4 Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Protect our rights and prevent fraud
  • Enforce our Terms & Conditions

4. AI and RAG System

4.1 How Our AI Works

Our Service uses advanced Artificial Intelligence based personalization to generate personalized plans:

  • AI Models: We use properly trained AI models (Azure OpenAI) to analyze your profile data
  • Knowledge Base: Our AI-based personalization system retrieves relevant fitness and nutrition guidelines from our curated knowledge base
  • Personalization: Plans are generated based on your specific profile, goals, preferences, and constraints
  • Continuous Learning: Our AI models may be updated and improved over time

4.2 AI Limitations

  • AI-generated content is based on general fitness and nutrition principles
  • Plans are NOT medical advice, diagnosis, or treatment
  • AI may not account for all individual health conditions or circumstances
  • You should always consult a healthcare professional for medical concerns

4.3 Data Used for AI Training

  • We may use anonymized and aggregated data to improve our AI models
  • Personal identifiers are removed before using data for model training
  • Your individual data is NOT used to train third-party AI models

5. Third-Party Services and Data Sharing

We share data with trusted third-party service providers who assist us in operating our Service:

Google (Authentication)

Purpose: User authentication via Google Sign-In

Data Shared: Email, name, profile picture

Privacy Policy

Razorpay (Payment Processing)

Purpose: Secure payment processing

Data Shared: Payment amount, transaction details, billing information

Privacy Policy

MongoDB (Database Hosting)

Purpose: Secure data storage

Data Shared: All user data (encrypted in transit and at rest)

Privacy Policy

Microsoft Azure (Cloud Infrastructure)

Purpose: Hosting backend services, AI processing, email services

Data Shared: All user data processed through our backend

Privacy Policy

Azure OpenAI (AI Services)

Purpose: AI model processing for plan generation

Data Shared: Profile data, goals, preferences

Privacy Policy

Azure Communication Services (Email)

Purpose: Sending password reset emails and notifications

Data Shared: Email address, email content

Privacy Policy

Expo (App Development Platform)

Purpose: App building and distribution

Data Shared: App usage analytics (anonymized)

Privacy Policy

5.2 Data Sharing Limitations

  • We do NOT sell your personal information to third parties
  • We do NOT share your data for marketing purposes without your consent
  • We only share data necessary for service provision
  • All third-party service providers are contractually obligated to protect your data

5.3 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:

  • Protect our rights, property, or safety
  • Protect the rights, property, or safety of our users
  • Investigate fraud or security issues
  • Comply with legal obligations

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership.

6. Data Storage and Security

6.1 Data Storage

  • Location: Your data is stored on secure cloud servers (MongoDB Atlas, Microsoft Azure)
  • Retention: We retain your data for as long as your account is active or as needed to provide services
  • Deletion: You can request account deletion at any time (see Section 8)

6.2 Security Measures

  • Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest
  • Authentication: Secure password hashing (bcrypt) and JWT tokens
  • Access Controls: Limited access to personal data on a need-to-know basis
  • Regular Security Audits: We conduct regular security assessments
  • Secure Payment Processing: Payment data is processed through PCI-DSS compliant Razorpay

6.3 Data Breach Notification

In the unlikely event of a data breach that compromises your personal information, we will:

  • Notify you within 72 hours (or as required by applicable law)
  • Provide details about what information was compromised
  • Explain steps we are taking to address the breach
  • Recommend actions you should take to protect yourself

7. Your Rights and Choices

7.1 Access and Portability

  • Access Your Data via app profile
  • Request data export
  • Update profile information

7.2 Correction and Deletion

  • Update information in app
  • Request account deletion
  • Request specific data deletion

7.3 Opt-Out Rights

  • Opt-out of marketing emails
  • Disable push notifications
  • Disable location services

7.4 Account Controls

  • Change password anytime
  • Enable Two-Factor Authentication
  • Temporarily deactivate account

7.5 GDPR Rights (European Users)

If you are located in the European Economic Area (EEA), you have additional rights:

Right to AccessRight to RectificationRight to ErasureRight to Restrict ProcessingRight to Data PortabilityRight to ObjectRight to Withdraw Consent

7.6 California Privacy Rights (CCPA)

If you are a California resident, you have additional rights:

Right to KnowRight to DeleteRight to Opt-OutRight to Non-Discrimination

8. Children's Privacy

8.1 Age Requirement

WeightGPT is NOT intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under 13.

8.2 Parental Consent

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will delete such information upon verification.

8.3 Age Verification

By using our Service, you represent that you are at least 13 years old (or 16 in the EEA) and have the legal capacity to enter into this agreement.

9. International Data Transfers

9.1 Data Transfer

Your data may be transferred to and processed in countries other than your country of residence, including:

  • United States: Azure cloud services
  • India: Our primary operations and Razorpay payment processing
  • Other Countries: Where our service providers operate

9.2 Transfer Safeguards

We ensure appropriate safeguards are in place for international data transfers:

  • Standard Contractual Clauses (SCCs) for EEA data transfers
  • Adequate security measures and encryption
  • Compliance with applicable data protection laws

10. Cookies and Tracking Technologies

10.1 Cookies

Our Service may use cookies and similar tracking technologies:

  • Authentication Cookies: To maintain your login session
  • Analytics Cookies: To understand app usage (anonymized)
  • Functional Cookies: To remember your preferences

10.2 Tracking

  • We do NOT use third-party advertising trackers
  • We do NOT share data with advertising networks
  • Analytics are anonymized and aggregated

11. Medical and Health Disclaimers

11.1 NOT Medical Advice

CRITICAL DISCLAIMER: WeightGPT is NOT a medical service, and we are NOT doctors, medical practitioners, or healthcare professionals. Our Service provides general fitness, nutrition, and lifestyle guidance using AI technology.

11.2 Limitations

  • Our recommendations are generic and based on standard fitness and nutrition principles
  • Plans are NOT medical advice, diagnosis, or treatment
  • Plans are NOT a substitute for professional medical consultation
  • You MUST consult a qualified healthcare professional before starting any new fitness or diet program

11.3 No Liability for Health Outcomes

We are NOT liable for any injuries, health issues, or adverse effects resulting from following our plans without medical consultation, incorrect use, failure to disclose health conditions, or ignoring medical advice.

12. Data Retention

12.1 Retention Period

  • Active Accounts: Data is retained while your account is active
  • Inactive Accounts: Data may be retained for up to 3 years after last activity
  • Deleted Accounts: Data is permanently deleted within 30 days of account deletion request (subject to legal requirements)

12.2 Legal Retention

We may retain certain data longer if required by law, such as payment records, legal dispute records, and fraud prevention records.

13. Changes to This Privacy Policy

13.1 Updates

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Posting a notice in the app
  • Sending an email notification (for significant changes)

13.2 Continued Use

Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

13.3 Review

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

14.1 Privacy Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

  • Email: [Your Support Email]
  • Address: [Your Business Address]
  • App: Through the in-app support feature

14.2 Data Protection Officer

For GDPR-related inquiries, you can contact our Data Protection Officer at: [DPO Email]

14.3 Response Time

We will respond to your privacy inquiries within 30 days (or as required by applicable law).

15. Governing Law and Jurisdiction

15.1 Applicable Law

This Privacy Policy is governed by the laws of India, subject to applicable data protection laws (GDPR, CCPA, etc.).

15.2 Dispute Resolution

Any disputes regarding privacy will be resolved through:

  • First, direct communication with us
  • If unresolved, through binding arbitration in India
  • Subject to applicable data protection authority oversight

16. Consent and Agreement

By using WeightGPT, you acknowledge that:

  • You have read and understood this Privacy Policy
  • You consent to the collection, use, and disclosure of your information as described
  • You understand the limitations and disclaimers regarding medical advice
  • You agree to consult healthcare professionals when necessary
  • You accept the risks associated with using AI-generated fitness and nutrition plans

17. Additional Information

17.1 Links to Other Services

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these external services. We encourage you to review their privacy policies.

17.2 Social Media

If you connect your social media accounts (e.g., Google Sign-In), those services may collect information about your use of our Service. Please review their privacy policies.

17.3 Do Not Track

Our Service does not currently respond to "Do Not Track" signals from browsers. However, we do not use third-party advertising trackers.

By using WeightGPT, you agree to this Privacy Policy. If you do not agree, please do not use our Service.

Last Updated: November 21, 2025