Strudel Academy LLC, a Wisconsin limited liability company (“Company”, “we”, “us”, or “our”), operates the Fulminata Fitness mobile application (the “App”) and the Fulminata Fitness website (the “Site”). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our App or visit our Site. By using the App or Site, you consent to the practices described in this policy. If you do not agree with this Privacy Policy, please do not use the App or Site.
This Privacy Policy applies to the App, the Site, and our related support channels (for example, support emails). It does not apply to third-party websites or services that may be linked from the App or Site. Your use of third-party services (such as Apple TestFlight, Sign in with Apple, Google Sign-In, and platform notification services) is subject to those third parties’ privacy policies.
In short
- We collect what you enter (account, profile, workouts, food, weight) and a little about how you use the App. No location, no contacts, no ads, no tracking SDKs, and we do not read Apple Health or Google Fit.
- We never sell your data. Six service providers process it for us: Supabase, Expo, Sentry, Resend, RevenueCat, and Apple or Google for sign-in.
- Friends see your workout name, duration, volume, records, streak, and rank. Nobody else sees your workouts. Nobody ever sees your food or body weight. Turn Findable by username off in Settings → Privacy and only the friends you already have can find you.
- You can export or delete everything from Settings → Data & Account. Deletion is irreversible and starts right away.
- Consumer health data has its own policy at fulminata.app/health-data.
01 Information We Collect
Information You Provide
- Account information: email address, display name, username, and authentication credentials. If you sign in with a third-party provider (e.g., Google or Apple), we receive the identifiers that provider shares with us (typically an email address and a name/display name) from that provider. If you sign in with Google, we also receive the address of your Google profile photo and use it as your profile image until you change it; that image stays hosted by Google. If you use Sign in with Apple, we also keep the sign-in token Apple issues to us, solely so that we can revoke it when you delete your account. We record the version of the Terms of Service and Privacy Policy you accepted and when you accepted it, and your account settings (preferred units, notification preferences, and whether nutrition tracking is turned on).
- Profile information: experience level, gender, body weight and your weigh-in history, height, profile image, and in-app appearance choices (such as your figure’s hair color and skin tone). If you choose a profile image, we access only the photo you pick; it is reduced in size on your device before upload. All profile fields are voluntary.
- Workout data: exercises performed, sets, reps, weights, duration, personal records, workout history, program enrollment, scheduled training days, exercises you mark as favorites, any workout notes, effort (RPE) ratings, or mood ratings you add, and the custom exercises, workout templates, and programs you build.
- Nutrition data: foods and drinks you log, including the portion, quantity, meal, and the date and time of each entry; the calorie, macronutrient, fiber, sugar, and sodium values recorded with it; any custom foods and saved meals you create; foods you mark as favorites; and the calorie and macronutrient goals, goal weight, activity level, a typical daily step count you choose from four bands, and maintenance-calorie estimate you save. Nutrition tracking is voluntary and can be turned off at any time in Settings. The age you enter in the goal calculator is used on your device to calculate your target and is not stored.
- Social data: friend connections, workout challenges (including the set list of a completed workout you send as a challenge), programs and templates you share and receive, leaderboard participation, reactions, comments, cheers you send to friends, and any reports or blocks you submit.
- Camera (barcode scanning): if you use the barcode scanner, the camera is used only to read the barcode, and that processing happens on your device. Camera frames are never recorded, stored, or sent to our servers; a successful scan produces only the product’s barcode number, which we use to look up the food in the catalog. iOS asks your permission before the App can use the camera, and you can revoke it at any time in your device settings.
- Purchase data: purchases are made through Apple or Google, and we never receive your payment card details. If we offer paid features, whether as a subscription or a one-time purchase, we use RevenueCat to manage them: when you sign in, RevenueCat receives your account identifier and basic device information (such as device type and operating system version), and if you buy something it also receives the purchase details Apple or Google share with it, such as the product, the price, and the renewal or expiration date. We store your entitlement status (for example, which plan is active and when it expires) so we can provide what you paid for.
- Support communications: information you provide when you contact us (for example, your email address and the contents of your message).
Information Collected Automatically
- Device identifiers and push notification tokens. Push tokens are transmitted to our notification delivery provider, which forwards notifications to the platform notification service on your device. The text of a notification (for example, a friend’s display name and what they did) passes through that provider, which does not keep it after delivery; a copy of each in-app notification is kept in your notifications inbox as part of your account data. Push tokens persist until you uninstall the App, revoke notification permissions, or sign out, and we delete any token that has not checked in for 30 days.
- Crash reports and performance diagnostics, including device model, operating system version, and stack traces. These reports are not linked to your account and do not include your name, email, or workout content. They are optional: the Crash Reports switch in Settings → Privacy turns them off, and the same choice is offered during onboarding, on the step where we ask about notifications.
- Your device’s time zone, sent with requests so that workout and food-log dates, streaks, and daily totals are computed in your local time. It is not stored.
- Search and lookup requests. Food searches, barcode lookups, and friend searches are sent to our servers to return results. We keep the words you typed only when a food search returns no results, and the barcode number only when it is not in our catalog, so that we can add the missing food to our database, and we delete them within 90 days.
- Usage and interaction data: which features you open and use, workouts you start and complete, and similar in-app activity. This is tied to your account so we can measure retention and improve the App, kept for no more than 14 months, and never sold. It is optional: the Usage Analytics switch in Settings → Privacy turns this collection off, and the same choice is offered during onboarding, on the step where we ask about notifications.
- IP address and request logs. When the App communicates with our servers, our hosting, crash-reporting, update, email, and notification providers see your IP address and record standard request details in security and diagnostic logs that are kept for a short period.
- Site data (when you visit the Site): standard web log data such as IP address, browser type, device type, pages viewed, and the date/time of access.
- Cookies. The Site does not set cookies and does not use analytics or tracking. If that changes, we will update this policy and provide any notice the law requires before doing so.
On your device. The App keeps a copy of your data on your device so it works offline, and on iOS it shares your profile image and headline stats with the home-screen widget and Live Activity through a container on your device. Nothing in that container is sent anywhere.
What we do not collect. We do not collect your location, contacts, or any photos other than a profile image you choose. We do not record audio. We do not read data from Apple Health, Google Fit, or any other app. We do not use advertising or tracking SDKs.
02 How We Use Your Information
We use the information we collect to:
- Provide, operate, and personalize the App and Site
- Track your workouts, progress, and achievements
- Record the food you log and calculate the calorie and macronutrient targets you ask us to calculate
- Provide the paid features you purchase and keep your subscription status current
- Deliver push notifications you have opted into (e.g., friend requests, challenges, template shares, cheers from friends, and reactions or comments on your activity)
- Enable social features such as leaderboards, challenges, and friend activity
- Send you service messages about your account, including notice of material changes to these documents
- Review reports, enforce our Terms of Service, and keep the community safe
- Diagnose technical issues and improve App stability
- Comply with legal obligations
- Protect the App and Site, including detecting, preventing, and responding to fraud, abuse, and security incidents
Legal bases (EEA and UK users): We process your information to perform our contract with you (creating your account and providing the App and Site), with your consent (optional profile details and push notifications), for our legitimate interests (keeping the App secure, preventing abuse, and improving it), and to comply with legal obligations. Health-related information, including body metrics and the food you log, is special category data under the GDPR; where that applies, we process it on the basis of your explicit consent. You give that consent in the App: before your first food log, and before your first body-weight entry, we ask you to allow that category of data, and we record on your account the date and time you agreed. Where we rely on your consent, you may withdraw it at any time.
03 Sale of Personal Information
We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We do not use your personal information for cross-context behavioral advertising, and we do not “share” personal information for that purpose as those terms are defined under the CCPA/CPRA and analogous state privacy laws. We have never sold personal information, and we have no plans to do so. If our practices change, we will update this policy and provide any opt-out mechanisms required by law before the change takes effect.
04 Third-Party Service Providers
We share data with third-party service providers that process data solely on our behalf, including providers of:
- Cloud hosting, database, and authentication (Supabase)
- Push notification delivery and over-the-air app updates (Expo)
- Crash and error reporting (Sentry)
- Transactional email delivery (Resend), which sends your sign-in codes and account notices
- Purchase and subscription management (RevenueCat)
- Sign-in authentication (Apple and Google)
International transfers. These providers may store and process your information in the United States and other countries where they operate. When we transfer personal data from the EEA or the UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
05 Disclosure of Your Information
We may share your information only in the following circumstances:
- Service Providers. As described in Section 4, to operate and maintain the App.
- Other Users. While Findable by username is on in Settings → Privacy, any signed-in user can find you by username or display name and see your display name, username, profile image, title, equipped cosmetics, and workout count. When you turn Findable by username off, only the friends you already have can find your account in search, and we refuse a friend request from anyone else. If you send someone a friend request, they can view your profile statistics while deciding. If you accept a friend request, that friend can also see your workout statistics, current streak, rank and XP, active program, titles and cosmetics, and your recent workouts: the workout name, duration, and total volume, and for any personal record the exercise and the weight, reps, duration, or pace of the record set (but not your other sets, notes, effort ratings, or mood ratings). Leaderboards rank you only among your accepted friends; there is no public leaderboard. Comments you leave on a friend’s activity are visible to everyone who can see that activity, including that friend’s other friends. If you send a friend a workout challenge, that friend receives the full list of sets from that workout, with weights and reps, so they can repeat it; this is the only time your set list leaves your account. If you share a program or template with a friend, they receive its full content. If you share a program by link, anyone who has the link and is signed in to the App can view and copy it. While a workout is in progress, your accepted friends can also see that you are currently training and how long ago you started. Friends can send you a brief encouragement notification during a workout. Your nutrition data and body weight are never shown to other users. Profile images are stored on a publicly accessible content server. Because profile images may be hosted at a publicly accessible URL, anyone with the URL may be able to view the image. If you prefer, you can choose not to upload a profile image.
- Legal Requirements. We may disclose information if required by law, court order, or governmental request, or to protect our rights, your safety, or the safety of others.
- Business Transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
06 Health, Body, and Nutrition Data
Body weight, height, and the nutrition information you log are collected to support workout tracking, nutrition tracking, and progress visualization. We do not access Apple Health, Google Fit, or any third-party health platform. We do not use health, fitness, or nutrition data for advertising, marketing, or data mining, and we do not collect location data or use geofencing. We obtain your explicit, opt-in consent before processing your body metrics or nutrition entries as special category or sensitive personal data, wherever you live. The App asks once, in a consent step before your first food log and again before your first body-weight entry, and records on your account the date and time you agreed; that record is included in your data export. No body metrics or nutrition data are collected when you sign up. If you decline, we do not collect that category: declining nutrition simply turns nutrition tracking off, and nothing you have already logged is deleted. You can withdraw consent at any time in Settings → Privacy, where Body metrics data and Nutrition data can each be set to Not allowed; withdrawing stops further collection and deletes nothing. You can turn nutrition tracking off at any time in Settings, which hides the feature without deleting anything you have logged. You can also withdraw consent by deleting the entries in the App or by deleting your account; your nutrition data is included in data export and account deletion whether the feature is on or off.
Our Consumer Health Data Privacy Policy (also available at https://fulminata.app/health-data) describes how we handle consumer health data, including the disclosures and rights provided under Washington, Nevada, and Connecticut law.
07 Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your information. Data is transmitted using industry-standard encryption (TLS/HTTPS). Authentication credentials are stored in secure on-device storage. Access to your data is restricted by role-based security policies. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. If we determine that a security incident has resulted in the unauthorized acquisition of, access to, or disclosure of your personal information, we will notify you and, where required, applicable regulators within the timeframes prescribed by applicable law. Email to the address associated with your account is our primary method of communicating with you, including for any such notice.
08 Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide you with the App, and we delete some of it sooner on an automatic schedule: the words of a failed food search and the barcode number of a catalog miss within 90 days; usage and interaction records after 14 months; in-app notifications 90 days after you read them (unread notifications after 12 months); moderation reports 24 months after they are filed; and, if Apple declines to revoke your Sign in with Apple token when you delete your account, a record of that failure (your former account identifier and the response from Apple) for up to 24 months. Crash reports are kept by our crash-reporting provider for up to 90 days, and server request logs for a short period. Support emails are kept as long as needed to resolve your request and for our records. We need not delete information to the extent retention is required by law, regulation, or court order, or requested by a government agency. You may export your data at any time from Settings → Data & Account → Export My Data; the export includes your profile, workout, nutrition, social, and settings data.
You may permanently delete your account and all associated data from Settings → Data & Account → Delete Account. If you no longer have the App installed, you can request deletion at https://fulminata.app/delete-account or by emailing support@strudelacademy.com from the email address on your account. We will begin processing deletion promptly after you submit the request. Deletion is processed as soon as reasonably practicable and is irreversible, except where retention is required by applicable law. We may retain limited information in backups for a period of time and will delete or de-identify it when backups are rotated or as required by law. We may retain de-identified or aggregated data that cannot reasonably be used to identify you. A program you built that other users adopted stays available to them with your name removed.
09 Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal information
- Correct inaccurate personal information
- Delete your personal information
- Opt out of push notifications at any time in Settings → Notifications, or via your device settings
- Turn off usage analytics at any time with the Usage Analytics switch in Settings → Privacy
- Turn off crash reports at any time with the Crash Reports switch in Settings → Privacy
- Control whether other users can find you, with the Findable by username switch in Settings → Privacy; with it off, only the friends you already have can find your account in search, and we refuse a friend request from anyone else
- Allow or withdraw your consent to our processing of body metrics and nutrition data, with the Body metrics data and Nutrition data controls in Settings → Privacy; withdrawing stops further collection and deletes nothing
California Residents: Under the CCPA/CPRA, you have the right to know what personal information we collect, request deletion, request correction, and opt out of the sale of personal information (we do not sell). We will not discriminate against you for exercising your rights. Some of the information we collect, such as body metrics and the food you log, may be considered sensitive personal information under the CPRA. We use and disclose it only to provide the App and for the other purposes described in this policy, and never to infer characteristics about you. Because we do not use or disclose sensitive personal information beyond the purposes the CPRA permits, we are not required to offer a “Limit the Use of My Sensitive Personal Information” option; we nevertheless let you allow or withdraw consent for body metrics and nutrition data at any time in Settings → Privacy. If you use an authorized agent to submit a request on your behalf, we may require proof of the agent’s authorization and may still ask you to verify your identity directly.
Washington, Nevada, and Connecticut Residents: Our Consumer Health Data Privacy Policy describes the additional rights that apply to consumer health data, including how to appeal a decision.
EEA and UK Residents: In addition to the rights above, you may request that we restrict or stop processing your information, receive your information in a portable format (you can export your data in the App at any time), and withdraw consent where we rely on it. You also have the right to lodge a complaint with your local data protection supervisory authority.
You can exercise most of these rights directly within the App. For additional requests, contact us at the email address below. To help protect your privacy and security, we may need to verify your identity before processing certain requests (for example, by requiring that you send the request from the email address associated with your account and/or by confirming certain account details). If we deny your request, you may appeal our decision by replying to our denial message or emailing us at support@strudelacademy.com with the subject line “Privacy Appeal.” If your appeal is denied, you may submit a complaint to your state attorney general.
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please contact us at the email below.
10 Children’s Privacy
The App is not directed to children under the age of 13. During onboarding, users must confirm that they are 13 years of age or older before creating an account. The calorie and macronutrient calculator is available only to users who indicate they are 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
11 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date at the top of this page. For material changes, we will notify you in the App, and by email where the law requires it, before the change takes effect; when we ask you to accept the updated policy in the App, we keep a record of the version you accepted and when. Your continued use of the App after any changes constitutes your acceptance of the updated policy.
12 Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of Wisconsin, United States, without regard to its conflict-of-law principles.
13 Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Strudel Academy LLC
2800 E. Enterprise Ave STE 333, Appleton, WI 54913, USA
Telephone: +1 (715) 544-7830
Email: support@strudelacademy.com