Privacy policy
What Course collects, and what it doesn’t.
Last updated August 2026. COURSE (“we”, “the app”) is a personal nutrition and fitness tracker. This policy describes what data the app collects, how it is used, and your choices.
Data we collect
| Category | Examples | Purpose |
|---|---|---|
| Account | Email address, Firebase user ID, sign-in provider (Sign in with Apple, Google Sign-In, or email/password) | Authentication and cloud sync |
| Health & fitness | Meals, calories, macros, weight, body composition, exercise logs | Core app functionality |
| Apple Health | Workouts, active energy, resting energy, steps (read); weight and body composition (optional import) | Exercise credit and optional body import |
| Food catalogs | Search terms and barcodes you look up | USDA FoodData Central and Open Food Facts lookups |
| User content | Recipes, shopping lists, food logs | Stored locally and synced to your account |
| Recipe import | Recipe URLs and optional captions you submit | Optional personal recipe-import service (when you configure it) |
| Crash diagnostics | Crash stack traces and breadcrumb logs (PII scrubbed) | Stability via Firebase Crashlytics |
We do not sell your data. We do not use advertising or cross-app tracking.
Where data is stored
- On your device: Encrypted SQLite (SQLCipher). Sensitive fields synced to the cloud are encrypted client-side before upload.
- Cloud (optional): If you sign in, data syncs to Firebase Firestore under
/users/{your-uid}/, protected by security rules so only you can read/write. Sign-in uses Firebase Authentication (Apple, Google, or email). - Third-party APIs: Food search (USDA FoodData Central, Open Food Facts), store prices (Kroger, when connected), and shopping links (Instacart, when used) receive only the queries you trigger. Release builds send USDA, Kroger, and Instacart traffic through our backend proxy. DEBUG builds may call USDA directly with a key compiled into that debug binary.
- Recipe-import service: If you enable it, the app sends the URL (and optional caption) you paste to your configured recipe-import backend so it can return a structured draft. We do not operate a public hosted import website as part of this app.
HealthKit
We read and write only the Apple Health types you authorize in the system permission sheet. Health data is not shared with third parties for marketing.
- Workouts, energy, and steps are read to credit exercise toward your calorie budget. Those readings stay on this device and are not uploaded.
- Weight and body composition can be imported separately in Settings. Imported values are stored in the app and sync when you have an account.
Manual exercise you log yourself can sync; Health-sourced workout rows do not.
Crashlytics
Firebase Crashlytics may receive crash reports and developer breadcrumbs. App logs are passed through a scrubber that redacts email addresses, long digit runs, and quoted display names before they leave the device. Crashlytics is crash reporting, not advertising analytics.
Your rights
- Export: Settings → Data → Export my data (JSON).
- Delete account: Settings → Account → Delete account. This removes your Firebase account, cloud data, and all local app data on this device.
- Sign out: Clears session tokens on device; local logs remain until you delete the account or uninstall.
Contact
For privacy questions, email [email protected].
Changes
We may update this policy. Material changes will be reflected in the “Last updated” date above.