Privacy Policy
Last updated: July 2026
1. Controller
The controller responsible for data processing is:
Elias Enghauser (Visin) · [email protected]
This policy covers the “Visin” app (iOS & Android) and the website visin.fit.
2. What data we process – and why
We only process data required to operate the app or that you actively provide:
- Account data: name, email address and profile picture at registration/login via email, Google or Apple. Purpose: account management. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Fitness & nutrition data: workouts, sets/reps, HIIT/interval and outdoor sessions, meals, macros and calories, body measurements and weight you enter yourself. Legal basis: Art. 6(1)(b) GDPR.
- Health data from Apple Health / Health Connect: if you opt in, we sync sleep, steps, weight, calories, workouts and nutrition with Apple Health or Google Health Connect (read & write). This data is stored in your Visin account like any other app data, including on our servers for cross-device sync. Legal basis: your explicit consent as a special category of personal data, Art. 9(2)(a) GDPR – revocable at any time via your device permissions.
- Cycle tracking: only if you enable period tracking in Settings, we process the cycle entries you log to show you personalised insights (e.g. correlations with training or sleep). Legal basis: your explicit consent, Art. 9(2)(a) GDPR – the feature is off by default and revocable at any time.
- Location data: when you use outdoor run/ride tracking, we record route, distance, pace and elevation via GPS – at your request also with the screen locked (background location), so tracking doesn’t stop e.g. in an armband. Location is only collected during an active recording session. Legal basis: Art. 6(1)(b) GDPR, plus your consent for background location, Art. 6(1)(a) GDPR.
- Camera & photos: photos of meals or recipes are sent to an AI service (Google Gemini, see section 3) for automatic recognition. Barcode scans are processed locally on your device. Legal basis: Art. 6(1)(b) GDPR.
- Microphone & speech recognition: when you dictate a meal, your speech is converted to text via your operating system’s speech recognition. Legal basis: Art. 6(1)(b) GDPR.
- Bluetooth: connecting to heart-rate monitors/fitness trackers to record your heart rate during workouts. Legal basis: Art. 6(1)(b) GDPR.
- Motion sensors: your device’s step-counter/activity data to show cadence/steps during outdoor activities. Legal basis: Art. 6(1)(b) GDPR.
- Device & connection data: a random device ID, IP address, and OS/app version. Purpose: bug fixing, stability, and abuse/spam prevention (e.g. banning malicious accounts). Legal basis: legitimate interest, Art. 6(1)(f) GDPR.
- Push notifications: a device token (Firebase Cloud Messaging) for reminders (e.g. rest timers) and messages from friends. Legal basis: Art. 6(1)(b) GDPR, can be disabled in device settings.
- Social & community data: friendships, direct messages, feed posts, publicly shared recipes/training plans, ratings, and your display name/avatar, if you use these features. This content is visible to other users, or to anyone visiting a shared link if made public. Legal basis: Art. 6(1)(b) GDPR.
- Purchase data: for a Visin Pro subscription, we process your purchase/subscription status via RevenueCat and the App Store/Google Play. Your payment details (card etc.) are handled exclusively by Apple/Google and never reach us. Legal basis: Art. 6(1)(b) GDPR.
- Usage & diagnostic data: pseudonymous app usage events and crash reports via the analytics provider PostHog (EU-hosted), linked to an internal user ID. Legal basis: legitimate interest, Art. 6(1)(f) GDPR. You may object at any time via the contact address in section 9.
3. Sharing with third parties / recipients of your data
We do not sell your data. To operate the app, we use the following processors/third-party providers, each strictly limited to the purpose stated:
- Google Firebase (Google Ireland Ltd. / Google LLC): login (Authentication) and push notifications (Cloud Messaging).
- Google Sign-In & Sign in with Apple: optional login methods, if you choose them.
- Google Gemini API (Google LLC): AI analysis of food/recipe photos and text, and the optional chat coach.
- PostHog (EU server location): app analytics and crash reporting.
- RevenueCat, Inc.: subscription/purchase status management.
- Apple App Store / Google Play: payment processing for purchases.
Where any of these providers process data outside the EU/EEA – in particular in the US – this is based on EU Standard Contractual Clauses (Art. 46 GDPR) or an adequacy decision, where applicable. Beyond this, we only disclose data to third parties where legally required or explicitly requested by you (e.g. visible social content, see section 2).
4. Retention period
Your data is stored for as long as your Visin account is active. If you delete your account – possible directly in the app under “Delete Account” – your personal data, including fitness, nutrition, health and location data, is removed from production systems immediately; residual copies in backups persist for a maximum of 30 days before being automatically overwritten. Publicly shared content (e.g. recipes, training plans, feed posts, chat history) that remains relevant to other users is kept but anonymised – your name and profile are removed.
5. Device permissions Visin requests
Visin only requests permissions tied to a specific feature, at the point you use it. You can revoke any permission at any time in your device settings; the app remains usable with reduced functionality.
- Camera – photos of meals/recipes
- Photo library – selecting existing photos
- Microphone & speech recognition – dictating meals
- Location, including in the background – recording outdoor runs/rides with the screen locked
- Motion & fitness/activity recognition – step counter, cadence
- Bluetooth – connecting heart-rate monitors
- Health data (Apple Health/Health Connect) – syncing sleep, weight, workouts, nutrition
- Notifications – reminders and messages
6. Website visin.fit
Our website loads fonts from Google Fonts, which transmits your IP address to Google. For reach measurement and to improve the site, we use the analytics tool PostHog (EU-hosted): pseudonymous usage events such as page views and clicks on install buttons are recorded. We do not use marketing or advertising cookies and do not share this data with third parties for advertising. Legal basis: our legitimate interest in a needs-based website design, Art. 6(1)(f) GDPR. You can object at any time via the contact address in section 9.
7. Data security
We transmit all data encrypted (TLS/HTTPS) and protect our systems using current technical and organisational measures. Complete protection against unauthorised access cannot be guaranteed.
8. Minimum age
Visin is not directed at children. Use is only permitted from age 16. Individuals under 16 may only use the app with the consent of a parent or legal guardian.
9. Your rights
Under the GDPR you have the right to:
- Access your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR) – also directly via “Delete Account” in the app
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent already given, with future effect (Art. 7(3) GDPR)
Submit requests to: [email protected]
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe the processing of your data violates the GDPR – e.g. the authority responsible for your place of residence.
11. Changes to this policy
We update this privacy policy whenever the app or legal requirements change. The current version is always available at visin.fit.