privacy.
Effective date
Effective: 2026-07-24
1. Who we are
Sate is a fitness, nutrition, hydration, and wellness tracking app for iOS, together with the website at sate.fit. The data controller is Individual Entrepreneur Mikhail Dmitrievich Goroshkov (ИП Горошков Михаил Дмитриевич); registration details are available on request. You can reach us about anything in this policy, including to exercise your privacy rights, at support@sate.fit. This policy covers the worldwide Sate service, including the website at sate.fit in every language it is offered in (including its Russian-language /ru pages). The website's language is a display preference only — it does not change which policy applies or where your data is processed. The worldwide service, and the website in any language, is processed as described in this policy, with sub-processors located in the United States (see Section 7). If you use the separate Russia build of the iOS app — a distinct product from the website — a distinct privacy policy and consent framework under Russian Federal Law No. 152-FZ applies and is published with that build.
2. Data we collect
Account data — email address, password hash, and an optional display name. Birthdate — collected at sign-up to verify that you are at least 13 years old (COPPA / GDPR-K). Stored on your account and not displayed publicly. Profile data — height, weight, sex, dietary preferences, fitness goals, lifecycle status (such as pregnancy or lactation, if you choose to enter it), and time zone. Health and fitness data — including HealthKit data (Apple). When you grant permission, Sate reads the following from Apple Health: workouts, steps, heart rate, resting heart rate, heart rate variability (HRV), weight, height, body fat percentage, sleep, active energy, and dietary calories, protein, carbohydrates, and fat. Sate writes back the nutrition, hydration, and workout entries you log in the app. We do not share HealthKit data with any third party for advertising or analytics. When you enable sync, the HealthKit metrics above are uploaded to and stored on Sate's servers to power your insights and cross-device history; they are included in your data export and deleted when you delete your account. Sync is opt-in and controlled in Settings. Health and fitness data is treated as a special category of personal data and is processed only with your explicit consent (see Section 4). Logs and entries — meals, foods, recipes, hydration, workouts, exercises, sets, habits, body measurements, progress photos, mood and symptom notes, and programs you import. Photos — meal photos and progress photos. Meal photos are uploaded for AI analysis (see Section 5). Progress photos are stored on your account in encrypted object storage. Location — when you record an outdoor cardio workout, Sate collects precise location from your device's GPS, including in the background while that workout is running, and uploads the resulting route to our servers as part of the workout record so you can see your route, distance, and pace. Precise location is collected only while an outdoor workout is active, and the route is deleted when you delete the workout or your account. Sate also collects approximate location if you enable a location-triggered habit reminder. If you never start an outdoor workout and do not enable location-triggered habits, no location data is collected. Voice audio — when you use voice logging, audio is recorded on device and transcribed to text using Apple's on-device speech recognition. We do not store raw audio. Subscription data — when you subscribe, our payments processor (see Section 7) provides us with your subscription status, plan, and an anonymized purchase identifier. We never receive your full payment-card details. Device data — device model, operating system version, app version, and an anonymized identifier used for diagnostics and analytics. Crash and diagnostic data — when you consent to diagnostics, crash reports and performance traces from the iOS app are sent to Google Firebase Crashlytics to help us find and fix bugs. This is gated by the Analytics & Diagnostics setting in the app and can be turned off at any time. Website analytics — when you visit sate.fit, we collect privacy-friendly, cookieless usage analytics (page views and anonymized interaction events) and performance metrics. The site also sets one functional cookie, NEXT_LOCALE, to remember your language choice (English or Russian) between visits; it carries no cross-site identifier and is not used for tracking. No other tracking cookies are set.
3. How we use your data
We use your data to: - provide the service (log entries, compute totals, display history, generate the optional insights and estimates you request); - sync your data across your devices via our backend; - compute nutrition from text or image descriptions using AI (see Section 5); - manage your subscription and free trial; - send transactional emails such as email verification, password reset, subscription notices, and account-deletion confirmations; - diagnose crashes and performance issues, and secure the service against abuse and fraud; - comply with legal obligations. We do not sell your data. We do not share it for cross-context behavioral advertising. We do not use your data for advertising. We do not use your HealthKit data for any purpose other than the in-app features you trigger.
4. Legal basis for processing (GDPR / UK GDPR)
Where the EU or UK GDPR applies, we rely on the following legal bases: - Performance of a contract (Art. 6(1)(b)) — to create your account, provide the app, sync your data, and manage your subscription. - Explicit consent (Art. 6(1)(a) and, for health and other special-category data, Art. 9(2)(a)) — to access HealthKit and process your health and fitness data, to send meal photos and descriptions to our AI sub-processor, to collect diagnostics and analytics, and to use location-triggered reminders. - Legitimate interests (Art. 6(1)(f)) — to keep the service secure, prevent abuse and fraud, and improve the product, balanced against your rights. - Legal obligation (Art. 6(1)(c)) — to meet tax, accounting, and lawful-request obligations. You may withdraw consent at any time (see Section 9); withdrawal does not affect processing carried out before withdrawal.
5. AI image and text analysis (LLM sub-processor)
When you submit a meal photo to the photo-nutrition feature, the image bytes are forwarded to OpenRouter, which routes the request to Google Gemini for visual analysis. The response — an estimated list of foods and nutrients — is returned to Sate and to you. The original image bytes are not retained by Sate after the request completes. Sate cannot control the retention policies of OpenRouter or Google Gemini; their retention and usage are governed by their respective privacy policies. The same applies to the text-nutrition feature: the food description you type is sent to the same LLM provider chain for parsing. If you do not want your meal photos or descriptions sent to a third-party AI, disable the photo- and text-nutrition features and use manual entry, voice, or barcode scanning instead.
6. Automated processing and AI estimates
Sate automatically computes nutrition estimates, calorie and macro targets, recovery and readiness estimates, scores, and suggestions from the data you provide. These outputs are informational only, are frequently approximate, and are not decisions that produce legal or similarly significant effects about you. You can always edit, override, or ignore them. We do not use your data to make solely automated decisions with legal effect, and we do not engage in profiling for advertising. The accuracy and intended use of these outputs are described in the Health Disclaimer in our Terms of Service.
7. Sub-processors
We rely on the following sub-processors to operate Sate. Each receives only the data necessary to perform its function, and is bound by data-processing terms. - Resend (US) — transactional email. Data shared: email address and account events. - OpenRouter (US) — LLM routing gateway for AI features. Data shared: meal image bytes and food descriptions. - Google Gemini, via OpenRouter (US) — LLM model used for nutrition AI. Data shared: meal image bytes and food descriptions. - Cloudflare R2 (US) — object storage for photos and encrypted backups. Data shared: photos and encrypted backups. - Railway (US) — server hosting and managed PostgreSQL. Data shared: all API data, encrypted at rest. - Cloudflare (US) — CDN, DNS, and Turnstile bot protection for the website and API. Data shared: IP address and request metadata; for Turnstile, an anonymized challenge token. - Grafana Labs (EU) — infrastructure metrics and traces used to operate the service. Data shared: operational telemetry and request metadata; no health data and no message content. - Google Cloud Error Reporting (US) — server-side error reporting. Data shared: server error traces, which may include an account identifier. - Zoho Mail (EU) — hosting for the support@sate.fit mailbox. Data shared: the contents of any email you send us, including privacy-rights requests. - RevenueCat (US) — subscription management and receipt validation. Data shared: an anonymized app user identifier, subscription and purchase events. - Google — Firebase Crashlytics (US) for crash and diagnostic reporting from the app (data shared: crash traces, device model, app version, anonymized identifier), and Sign in with Google (data shared: Google account identifier) if you use it. - Apple (US) — In-App Purchase billing, Sign in with Apple (data shared: Apple ID identifier; an anonymized relay email if you choose Apple's email-relay option), and the HealthKit platform. - PostHog (EU) — product analytics and error monitoring for the website only (sate.fit). Data shared: anonymized usage and page-view events and error traces. Cookieless; data is stored in the EU. The iOS app does not send data to PostHog. - Vercel (US) — website hosting, privacy-friendly web analytics, and performance monitoring (Speed Insights). Data shared: anonymized page-view and Core Web Vitals metrics. No tracking cookies. We will update this list as our providers change and post the revised effective date.
8. International data transfers
Sate is operated from outside the United States and the European Economic Area, and most of our sub-processors are located in the United States. When we transfer personal data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or a provider's certification under the EU-US and UK Data Privacy Framework where available. You can request a copy of the relevant safeguards at support@sate.fit. The separate Russia build keeps Russian users' data within the Russian Federation under its own policy.
9. Your rights
Subject to applicable law, you have the right to: - Access — request a copy of your data via Settings → Export Data in the app. - Deletion — request account deletion via Settings → Delete Account. A 30-day grace period applies during which you can cancel the deletion. - Portability — Export Data returns a JSON archive (including your synced health and fitness metrics) that you can take elsewhere. - Correction — edit your profile in the app, or email support@sate.fit. - Restriction and objection — ask us to restrict or stop certain processing. - Withdraw consent — toggle HealthKit permissions in Apple's Health Settings, turn off Analytics & Diagnostics in the app, or delete your account. - Lodge a complaint with your local data-protection supervisory authority. To exercise any right, use the in-app controls or email support@sate.fit. We respond within 30 days (extendable where the law allows) and do not charge a fee except where a request is manifestly unfounded or excessive.
10. California privacy rights (CCPA / CPRA)
If you are a California resident, you have rights regarding your personal information. In the past 12 months we have collected these categories: identifiers (email, account and device identifiers); health and fitness information; commercial information (subscription status); internet/usage activity (app and website interaction); precise location (while an outdoor workout is active); and approximate location (only if you enable location reminders). We collect it for the purposes in Section 3 and share it only with the sub-processors in Section 7. We do not sell your personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the prior 12 months. You have the right to know, access, correct, and delete your personal information, the right to opt out of sale or sharing (which we do not do), and the right not to be discriminated against for exercising these rights. You may use an authorized agent. To exercise these rights, email support@sate.fit; we will verify your request against your account.
11. Analytics and your choices
Product analytics in the iOS app are first-party: event data is sent to Sate's own servers and is gated by the Analytics & Diagnostics setting, which you control. Crash diagnostics (Firebase Crashlytics) are gated by the same setting. If you do not consent, these are not collected. The website uses cookieless analytics (PostHog, stored in the EU) and Vercel performance metrics; no tracking cookies are set and you are not assigned a cross-site identifier.
12. Children
Sate is not directed to children under 13. Registration requires a date of birth, and we reject accounts where the user is under 13. If we discover that we have collected personal data from a child under 13, we will delete it. We aim to comply with COPPA (United States) and GDPR-K (European Union minimum age of 13). If you are between 13 and the age of digital consent in your country, please use Sate only with the involvement of a parent or guardian.
13. Security
We protect your data using industry-standard measures: - All data in transit is encrypted using TLS (HTTPS). - Passwords are hashed with bcrypt; we never store raw passwords. - Access tokens on iOS are stored in the system Keychain. - Server data is encrypted at rest in Railway's managed PostgreSQL; backups and photos are encrypted in object storage. - Access to production data is limited and authenticated. No method of transmission or storage is perfectly secure, but we take reasonable steps to protect your information.
14. Retention
We keep your account and content data while your account is active. When you request account deletion, we delete personal data within 30 days; encrypted backups are purged within the following 30 days. Crash and diagnostic data is retained for a limited period and then deleted or anonymized. We may retain certain records longer where required for legal, tax, or accounting purposes, or to resolve disputes and enforce our agreements. Aggregated, anonymized statistics that can no longer identify you may be retained for analytics and product improvement.
15. Data breach notification
If a personal-data breach occurs that is likely to affect you, we will notify the competent supervisory authority and, where required, affected users without undue delay and, where feasible, within 72 hours of becoming aware of it, consistent with GDPR Articles 33 and 34 and other applicable law. Our internal response follows a documented breach runbook covering detection, containment, assessment, notification, and remediation.
16. Changes to this policy
We may update this policy from time to time. We post the current effective date at the top, and we will notify you in-app and on this page of material changes. Continued use after changes take effect constitutes acceptance where permitted by law.
17. Contact
Questions, requests, or complaints: support@sate.fit. We act as the privacy contact for the worldwide Sate service.