🇬🇧 EN
Privacy Policy

Strenqo Privacy Policy

Current publication-ready legal information for the Strenqo mobile app.

Version 1.1.1 · Last updated: 2026-07-11

Version: 1.1.1

Last updated: 2026-07-11

Language: English (the Italian version is canonical in case of discrepancy)

1. Who we are

The controller of personal data collected through Strenqo is:

2. Categories of data we process

2.1 Account and profile data

We process email address, hashed password through Supabase Auth, user UUID, authentication provider, optional name, date of birth and age-gate proof, sex, country, language, profile photo, preferences and subscription entitlement state.

2.2 Health, fitness and nutrition data

Strenqo processes health/wellness data needed for fitness and nutrition functionality, including:

Apple Health / Health Connect data remains on-device unless you associate it with a Strenqo feature such as a workout, recovery/strain/sleep analysis or daily snapshot. Cloud wearable integrations use OAuth; tokens are stored encrypted in Supabase and sync may occur on a server schedule while the app is closed. Garmin is prepared in the codebase but subject to provider approval/availability; until Garmin connection is available and completed by the user, Strenqo does not import Garmin cloud data.

2.3 AI and user content

If AI data consent is enabled, Strenqo may send to Google Gemini the text of your messages, selected photos/files and relevant context such as profile, recent workouts, nutrition, weight and recovery/strain/sleep snapshots to generate replies, plans, estimates, notifications or briefings. The AI toggle is on by default and can be disabled in Profile -> Support, privacy and legal. Coach memory is a separate preference where available.

User-uploaded photos/files may include body check-in photos, food photos and workout media. Storage buckets are private and access is scoped to the owning user.

2.4 Technical data and permissions

We process technical information such as device model, OS, app version, push token, internal anti-abuse counters, audit logs for privacy-sensitive actions and IP address for market geolocation when local fallbacks are insufficient.

The app may request camera, photo library, location, Bluetooth, notifications, HealthKit/Health Connect and Apple/Google Sign-In permissions. Strenqo does not request contacts, calendar, microphone, IDFA, Android Advertising ID, or App Tracking Transparency.

The current production build does not include Sentry or another third-party crash-reporting SDK. Any platform crash diagnostics collected by Apple or Google are governed by your OS/store settings and their policies.

3. Purposes and legal bases

PurposeDataLegal basis
Account creation and managementaccount/profile dataContract performance
Core fitness/nutrition featureshealth, fitness, nutrition dataExplicit consent for Art. 9 GDPR data + contract performance
AI Coach, plans and AI notificationsconversations, photos/files, profile and contextExplicit consent; AI data toggle
HealthKit / Health Connect / cloud wearable synchealth/wearable data and provider tokensExplicit consent through OS permissions or OAuth
Pro subscription managementuser UUID, subscription stateContract performance
Security, abuse prevention, audittechnical identifiers and logsLegitimate interest
Technical stabilityminimal server logs and platform diagnosticsLegitimate interest / platform settings
Country/market geolocationIP address if neededLegitimate interest
Legal compliance and privacy requestsrelevant account dataLegal obligation
Transactional emailsemail addressContract performance / legal obligation

At signup, Strenqo records acceptance of Terms, this Policy and processing of health/wellness data needed for the service. Additional processing is governed by separate toggles, OS permissions or OAuth flows.

4. Recipients and processors

Strenqo relies on the processors listed in the Subprocessor List, including Supabase, Google Gemini, RevenueCat, Resend, Apple, Google, WHOOP, Oura, Garmin, OpenFoodFacts, IP-geolocation fallbacks and Expo.

Strenqo does not sell personal data, does not share data for cross-context behavioral advertising and does not use advertising, attribution, third-party analytics, behavioral tracking or third-party crash-reporting SDKs in the current build.

5. User-controlled choices

6. Retention

CategoryRetention
Active account dataFor the duration of service use
Audit logs90 days
Completed/failed/cancelled privacy requests30 days
Pending privacy confirmation tokens24 hours for export / 1 hour for deletion
Rate-limit countersUntil the relevant window expires
Photos and uploaded filesFor the duration of the account; deleted on account deletion
OAuth tokens and wearable snapshotsUntil provider disconnection or account deletion
Sub-processor dataAccording to the applicable provider policy

On account deletion, personal data in Strenqo database and storage is deleted in cascade, except short residual audit records needed to document completion.

7. International transfers

Some processors are located in the United States or otherwise outside the EU. Transfers rely on adequacy decisions, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses and transfer-impact assessments.

8. Your rights

You may exercise GDPR rights of access, rectification, erasure, restriction, portability, objection and consent withdrawal.

Requests may be sent to strenqo-support@strenqo.eu or andreasmondo@ultracert.it. We respond without undue delay and within one month unless a justified extension applies.

9. Security

Security measures include Row-Level Security on Supabase tables, TLS, password hashing through Supabase Auth, rate limiting, audit logs, input validation, webhook signature verification and encrypted storage of wearable OAuth tokens. The current build does not include a third-party crash-reporting SDK.

10. Minors

Strenqo applies an age gate. Thresholds as of 2026-07-02:

Parents or guardians may request deletion of a minor's account by writing to strenqo-support@strenqo.eu.

11. Automated processing and health disclaimer

AI Coach, plan generation and AI notifications are automated features. They do not produce legally binding decisions, are not medical diagnosis or treatment, and may be incomplete or wrong. You can disable them at any time through the AI consent controls.

For the fitness and medical disclaimer, see Health Disclaimer.

12. Changes and contact

Material changes will be notified in-app and/or by email where required. Change history is available at https://strenqo.eu/legal/privacy-policy-changelog.html.

End of document.