Skip to content
PerfectMode
PrivacyTerms of useSupportDelete accountProvider information
DEPLEN

Legal information

Privacy

How PerfectMode processes data in its current technical configuration.

Effective: September 1, 2026Controller: Lukasz Urbaniak

On this page

ControllerCore modelAccountFitness & nutritionGPS runsHealthServicesDeletionYour rights

1. Controller and contact

Lukasz Urbaniak, sole proprietorship
Karlstraße 8
27711 Osterholz-Scharmbeck
Germany

Privacy requests: privacy@perfectmode.app
General support: support@perfectmode.app

2. Core processing model

PerfectMode stores app data locally on the device first. Personal profile, training, nutrition and progress data is synchronised through Supabase only when the user is signed in and has active Premium access. Completed GPS runs use the same account/Premium gate, but are stored in a separate cloud table.

Without an account and active Premium, these areas remain local. Health steps and the local chat history are not part of Cloud Sync. The external Premium AI path does, however, create account-linked server data as described below.

This website: uses no analytics, advertising, trackers, cookies, external fonts or externally processed forms. Contact is provided only through email links.

3. Account and authentication

For an account, Supabase Auth processes the email address, a technical user ID (UUID), the authentication provider used, and session, sign-in, confirmation, password-reset and PKCE data. The session is stored in protected device storage.

Email/password and Sign in with Apple are technically integrated. The user ID links cloud data, Premium entitlements and server-side usage to the account.

4. Profile, fitness, training, nutrition and progress

Profile and planning

Data can include language, age, selected sex, height, current weight, target weight, goal, activity level, manually entered steps, training level, training location and training days. Coach preferences can include training focus, dietary style, allergies, voluntary Health/Safety information and supplement preferences.

Training

Stored data includes plan and workout assignment, sessions, exercises, sets, repetitions, weights or durations, timestamps, status, progress metrics and personal records.

Nutrition

Processed data includes the nutrition diary, food snapshots, quantities, meals, calories, macronutrients, custom foods, favourites, recent foods, preferred units, saved meals, daily completions, meal plans, target snapshots and adaptive calorie values.

Body progress

Progress entries can include date, weight and optional waist, hip, chest, upper-arm and thigh measurements.

These areas are stored locally and synchronised as account-linked Supabase documents only with an account and active Premium.

5. GPS runs and precise location

When a GPS run is started, PerfectMode processes precise location points containing latitude, longitude, timestamp, accuracy and optional altitude. If background permission has been granted, recording can continue while the screen is locked.

The active draft and its points are stored locally. A completed run contains the full compressed route, point count, distance, start and end time, elapsed and moving time, pace, speed, calories, splits, timestamps, optional caption and visibility settings.

For a signed-in account with active Premium, the full run — including the complete precise route — is synchronised to the account-linked Supabase run_sessions table. Runs are private by default and are not published automatically.

6. Apple HealthKit and Health Connect

After system permission is granted, PerfectMode reads step counts only from HKQuantityTypeIdentifierStepCount on iOS or Steps in Health Connect on Android. PerfectMode does not write any data to Apple Health or Health Connect.

  • Daily values can remain for up to 30 days in a purgeable local cache.
  • Health steps are not synchronised through Cloud Sync.
  • Health steps are not sent to OpenAI.
  • Disconnecting the Health integration clears the local step cache.

7. Services and recipients

Supabase

Supabase provides authentication, database, Premium Cloud Sync and Edge Functions. Edge Functions handle account deletion, the external AI path, online barcode requests and RevenueCat webhooks, among other tasks.

RevenueCat and app stores

RevenueCat receives the Supabase UUID as its App User ID and processes offering, product, price/currency, purchase, term, renewal status, entitlement and management URL. Account-linked entitlement and event data is sent to Supabase through webhooks. Payment is handled by Apple App Store or Google Play; PerfectMode does not store payment-card data. Fitness, nutrition, GPS and Health data is not sent to RevenueCat.

Premium AI Coach, Supabase and OpenAI

If the external Premium AI path is available and a question is not answered locally, the current free-text question, up to four relevant chat turns, and selected goal, body, training, nutrition and progress context are sent to a Supabase Edge Function and then to OpenAI.

The structured OpenAI payload contains no email address, Supabase user ID or HealthKit/Health Connect steps. Free text can nevertheless contain personal information entered voluntarily. OpenAI is called with store: false. Supabase stores the account-linked request ID, model, token, cost and status data, together with the response payload, for abuse prevention, cost control and idempotency. Local chat history is not a Cloud Sync domain.

Current technical state: a separate, explicit in-app consent step specifically for external AI processing has not yet been implemented. This processing is therefore not presented as already consent-gated.

Camera, barcodes and Open Food Facts

The camera opens only in the barcode scanner. PerfectMode reads the detected EAN/UPC code; it does not capture, store or upload camera images. Known products are resolved locally. With an account and active Premium, an unknown barcode can be checked through a Supabase Edge Function, a shared product cache and Open Food Facts. Open Food Facts receives the barcode but no email address or user ID. Supabase stores account-linked request limits.

Support

If you contact us by email, we process the contact details and content you provide voluntarily to handle the request. Do not send passwords or authentication tokens.

8. Purposes and legal bases

Depending on the feature, data is processed to provide the app and account, personalise training and nutrition, analyse progress and runs, provide Premium functions, manage purchases and support, maintain security, prevent abuse and meet legal obligations.

Depending on the specific processing, the legal basis can be performance of a contract or pre-contractual steps, consent for optional device permissions and, where applicable, special-category data, legal obligations, or legitimate interests in operating a secure and economically sustainable service. Consent can be withdrawn for the future, and system permissions can be changed in device settings.

9. Retention and security

Local data generally remains on the device until deleted in the app, cleared by the relevant deletion flow or removed by clearing app data. The Health step cache is designed for a maximum of 30 days. Cloud data generally remains until individual deletion or account deletion, subject to necessary technical, contractual and legal retention.

Providers such as Apple, Google, RevenueCat, Supabase and OpenAI may apply their own retention rules. PerfectMode uses account- and user-scoped access rules and encrypted transport provided by the platforms. No system can guarantee absolute security.

10. Account deletion and remaining local data

The in-app path Profile → Account → Delete account deletes the Supabase Auth account. Database cascades remove account-linked app documents, cloud runs and routes, AI usage and response data, server-side entitlement and webhook data, and external request limits. The app then removes the local Auth session and clears the normal local Cloud Sync domains.

Currently not removed automatically: local run history, an active run and the local Health step cache. Runs can be deleted individually, Health can be disconnected, and remaining local data can be removed by clearing the app data.

A store subscription is not cancelled automatically. The Sign in with Apple authorisation or Apple token is not additionally revoked by the current process. Purchase histories and provider logs may remain under each provider's rules. See Account deletion for details.

11. Your privacy rights

Subject to the applicable legal requirements, you may request access, correction, deletion, restriction of processing and data portability, and may object to processing. Consent can be withdrawn for the future. You also have the right to complain to a competent data protection supervisory authority.

Contact privacy@perfectmode.app. To prevent unauthorised disclosure, a reasonable identity check may be required.

PerfectMode

Provider: Lukasz Urbaniak
SupportPrivacyTerms of useProvider informationAccount deletion