🇬🇧 EN
Strenqo Privacy Policy
Current publication-ready legal information for the Strenqo mobile app.
Version: 1.1.1
Last updated: 2026-07-11
Language: English (the Italian version is canonical in case of discrepancy)
1. Who we are
The controller of personal data collected through Strenqo is:
- Controller: Andreas Mondo
- Registered office: Via Pianezza 16, 10040 Givoletto (TO), Italy
- Contact email: strenqo-support@strenqo.eu
- PEC: andreasmondo@ultracert.it
- DPO: not designated. The controller periodically reviews whether designation becomes required.
2. Categories of data we process
2.1 Account and profile data
We process email address, hashed password through Supabase Auth, user UUID, authentication provider, optional name, date of birth and age-gate proof, sex, country, language, profile photo, preferences and subscription entitlement state.
2.2 Health, fitness and nutrition data
Strenqo processes health/wellness data needed for fitness and nutrition functionality, including:
- body metrics such as weight, height, body measurements, body check-in photos and body composition;
- workouts, exercises, sets, duration, perceived intensity, calories, heart rate and strain;
- outdoor cardio data, including optional GPS route with GPS Clip;
- meals, foods, macros, calories, hydration, recipes, goals, allergies/intolerances and diet preferences;
- Apple Health / HealthKit and Google Health Connect data when you grant OS permission, including heart rate, HRV, resting heart rate, SpO2, sleep, sleep stages, wrist/skin temperature, steps, distance, active/basal calories, weight, height, body fat, waist circumference and menstrual flow where available;
- daily health/wearable snapshots saved by Strenqo for app, widget and notification functionality;
- BLE heart-rate monitor data during a workout;
- cloud wearable data from WHOOP, Oura or Garmin if the provider integration is available and you connect it.
Apple Health / Health Connect data remains on-device unless you associate it with a Strenqo feature such as a workout, recovery/strain/sleep analysis or daily snapshot. Cloud wearable integrations use OAuth; tokens are stored encrypted in Supabase and sync may occur on a server schedule while the app is closed. Garmin is prepared in the codebase but subject to provider approval/availability; until Garmin connection is available and completed by the user, Strenqo does not import Garmin cloud data.
2.3 AI and user content
If AI data consent is enabled, Strenqo may send to Google Gemini the text of your messages, selected photos/files and relevant context such as profile, recent workouts, nutrition, weight and recovery/strain/sleep snapshots to generate replies, plans, estimates, notifications or briefings. The AI toggle is on by default and can be disabled in Profile -> Support, privacy and legal. Coach memory is a separate preference where available.
User-uploaded photos/files may include body check-in photos, food photos and workout media. Storage buckets are private and access is scoped to the owning user.
2.4 Technical data and permissions
We process technical information such as device model, OS, app version, push token, internal anti-abuse counters, audit logs for privacy-sensitive actions and IP address for market geolocation when local fallbacks are insufficient.
The app may request camera, photo library, location, Bluetooth, notifications, HealthKit/Health Connect and Apple/Google Sign-In permissions. Strenqo does not request contacts, calendar, microphone, IDFA, Android Advertising ID, or App Tracking Transparency.
The current production build does not include Sentry or another third-party crash-reporting SDK. Any platform crash diagnostics collected by Apple or Google are governed by your OS/store settings and their policies.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation and management | account/profile data | Contract performance |
| Core fitness/nutrition features | health, fitness, nutrition data | Explicit consent for Art. 9 GDPR data + contract performance |
| AI Coach, plans and AI notifications | conversations, photos/files, profile and context | Explicit consent; AI data toggle |
| HealthKit / Health Connect / cloud wearable sync | health/wearable data and provider tokens | Explicit consent through OS permissions or OAuth |
| Pro subscription management | user UUID, subscription state | Contract performance |
| Security, abuse prevention, audit | technical identifiers and logs | Legitimate interest |
| Technical stability | minimal server logs and platform diagnostics | Legitimate interest / platform settings |
| Country/market geolocation | IP address if needed | Legitimate interest |
| Legal compliance and privacy requests | relevant account data | Legal obligation |
| Transactional emails | email address | Contract performance / legal obligation |
At signup, Strenqo records acceptance of Terms, this Policy and processing of health/wellness data needed for the service. Additional processing is governed by separate toggles, OS permissions or OAuth flows.
4. Recipients and processors
Strenqo relies on the processors listed in the Subprocessor List, including Supabase, Google Gemini, RevenueCat, Resend, Apple, Google, WHOOP, Oura, Garmin, OpenFoodFacts, IP-geolocation fallbacks and Expo.
Strenqo does not sell personal data, does not share data for cross-context behavioral advertising and does not use advertising, attribution, third-party analytics, behavioral tracking or third-party crash-reporting SDKs in the current build.
5. User-controlled choices
- Health data consent: collected at registration for the core service and through OS permissions for HealthKit/Health Connect.
- AI data consent: separate toggle in Profile -> Support, privacy and legal. On by default; disabling it blocks AI features and AI-personalized notifications.
- Coach memory: separate preference where available.
- Notifications: controlled by OS permission and in-app reminder settings.
- Wearable providers: WHOOP/Oura can be disconnected in the app and should also be revoked at the provider if you want to remove source-side access. Garmin follows the same rule only after the integration is approved/available and connected by the user.
6. Retention
| Category | Retention |
|---|---|
| Active account data | For the duration of service use |
| Audit logs | 90 days |
| Completed/failed/cancelled privacy requests | 30 days |
| Pending privacy confirmation tokens | 24 hours for export / 1 hour for deletion |
| Rate-limit counters | Until the relevant window expires |
| Photos and uploaded files | For the duration of the account; deleted on account deletion |
| OAuth tokens and wearable snapshots | Until provider disconnection or account deletion |
| Sub-processor data | According to the applicable provider policy |
On account deletion, personal data in Strenqo database and storage is deleted in cascade, except short residual audit records needed to document completion.
7. International transfers
Some processors are located in the United States or otherwise outside the EU. Transfers rely on adequacy decisions, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses and transfer-impact assessments.
8. Your rights
You may exercise GDPR rights of access, rectification, erasure, restriction, portability, objection and consent withdrawal.
- Access/portability: Profile -> Export my data. The export returns a machine-readable JSON. For storage files, the export contains storage paths; short-TTL signed download URLs are generated only through an explicit user action.
- Erasure: Profile -> Account -> Delete account, with email confirmation. See Account deletion.
- Restriction/objection/withdrawal: disable AI, memory, personalized notification and OS/wearable permissions where available, or write to strenqo-support@strenqo.eu.
- Complaint: you may contact the Italian Data Protection Authority or your local EU/EEA authority.
Requests may be sent to strenqo-support@strenqo.eu or andreasmondo@ultracert.it. We respond without undue delay and within one month unless a justified extension applies.
9. Security
Security measures include Row-Level Security on Supabase tables, TLS, password hashing through Supabase Auth, rate limiting, audit logs, input validation, webhook signature verification and encrypted storage of wearable OAuth tokens. The current build does not include a third-party crash-reporting SDK.
10. Minors
Strenqo applies an age gate. Thresholds as of 2026-07-02:
- EU / EEA / Italy / Switzerland: 16 years
- United Kingdom, United States, Canada: 13 years
- Australia: 15 years
- Unrecognized country: 16 years
Parents or guardians may request deletion of a minor's account by writing to strenqo-support@strenqo.eu.
11. Automated processing and health disclaimer
AI Coach, plan generation and AI notifications are automated features. They do not produce legally binding decisions, are not medical diagnosis or treatment, and may be incomplete or wrong. You can disable them at any time through the AI consent controls.
For the fitness and medical disclaimer, see Health Disclaimer.
12. Changes and contact
Material changes will be notified in-app and/or by email where required. Change history is available at https://strenqo.eu/legal/privacy-policy-changelog.html.
- Email: strenqo-support@strenqo.eu
- PEC: andreasmondo@ultracert.it
End of document.