Fuel8

Fuel8 — Privacy Policy

Last updated 18 September 2026

The short version

Food and workout logging works without an account. Fuel8 has no analytics or advertising. Your log stays on this iPhone unless you enable account sync. Optional network features, including AI Coach and progress-photo uploads, each require a separate action and are described below.

Your meal, workout, weight and target records stay on this iPhone. Barcode lookups, optional photo estimates, sharing and Apple subscription features are described below.

What Fuel8 stores on this iPhone

Your food and water log, hours slept, weight and body-fat history, profile and targets, saved plates and personal recipes, workout routines, unfinished sessions, completed sets, cardio sessions and training goals. Structured workouts also retain activity targets, actual results, timing, substitutions, corrections and equipment locations. These follow the same optional account-sync choice as other workout records.

Your records are held in Fuel8's private container with iOS file protection, which makes them unreadable while the phone is locked. Local logging does not upload your records. Optional network features send only the data described below. System device backups may include app data according to your Apple backup settings.

If you supply an API key for an AI provider — Anthropic, OpenAI or Google — it is held in the iOS Keychain, device-only, in a separate item per provider, and is never included in an iCloud Keychain sync or a device backup.

One thing is not encrypted at rest: a small preferences file holding which AI provider and model you chose, which providers you have given permission to, and a count and rough cost of the estimates you have made. It holds no food, weight or health data.

The developer cannot read or recover your local records. Signing in to a Fuel8 account does not by itself upload your diary. Sync, progress-photo uploads and AI Coach have separate controls. Keep this in mind before deleting the app or changing phones.

Open Food Facts

When you scan a barcode, Fuel8 asks world.openfoodfacts.org about that barcode. The request carries the barcode digits, a fixed list of the nutrition fields the app uses, and the app's name and version. That is all.

It carries no device identifier, no advertising identifier, no account and nothing from your log. Fuel8 refuses cookies from this host and keeps no copy of the response on disk, so one lookup cannot be tied to the next. As with any request over the internet, Open Food Facts sees the address your connection comes from.

Photo estimates and your own API key

Fuel8 can estimate a meal from a photograph. It is off unless you turn it on, and turning it on takes two deliberate steps: accepting a consent notice, and pasting an API key for the AI provider you choose, which you obtain and pay for yourself.

This optional feature sends personal data when a photograph leaves your phone. If you have done both, taking an estimate sends the photograph, a fixed instruction asking what food is in it, and your key to the provider you have chosen: api.anthropic.com (Anthropic), api.openai.com (OpenAI) or generativelanguage.googleapis.com (Google) — a third party, under your own account and on your own bill. Fuel8 asks for your permission separately for each provider, and switching provider does not carry that permission across.

The photograph is redrawn before it is sent, which removes GPS coordinates, capture time, camera make and model and every other metadata tag. Fuel8 never writes the original to disk.

Nothing else goes with it. Not your weight, targets, goal, age, name or anything read from Apple Health — the request has no field able to carry them.

What that provider does with the image is governed by their terms and the settings on your own account with them. Fuel8 is not a party to it and never receives your key. Requests to OpenAI are sent with response storage disabled.

Settings, then Photo estimates, then Revoke & delete removes the key and the consent record together, in one tap.

Apple Health

Fuel8 works fully without Apple Health and asks only when you first use a feature that needs it.

With your permission it reads your body weight, active energy and steps, and writes the calories, protein, carbohydrates and fat of the meals you log. An estimate from a photo is never written to Health unless you confirm it first.

Apple Health activity stays on this iPhone unless you separately enable Share steps and active energy in Account, Sync & Coaching while account sync is on. That choice sends daily steps and active energy, with the date and time zone, to www.getfuel8.com for you, authorised coaches and administrators to view. Turning it on or choosing Send now reads up to 90 days; automatic refreshes cover the last seven days. Imported weigh-ins become part of your diary and follow your record-sync choice. Health data is never used for advertising or marketing and never reaches share cards. Settings, then Apple Health, lets you refresh readings, disconnect or reconnect Fuel8, open Health permissions, and remove only the samples Fuel8 wrote.

Camera, microphone and speech

The camera and photo library are used when you choose a meal photograph for an estimate or select progress photos. Meal estimates do not save the original. Progress photos are uploaded only after you review the selection and choose Save privately or Save & share.

Speech recognition runs on this iPhone. Fuel8 refuses to start dictation on a device that cannot recognise speech locally, so your voice is not sent to Apple or to anyone else. The recognised words fill an editable draft for you to review. Starting another recording appends to the text. No food or set is committed by recognition alone, and the audio is discarded.

Sharing and Apple Pro features

Sharing opens the iOS share sheet only after you choose to share. Food cards preview their contents; nutrition is off until you enable it. Workout shares contain the recorded session numbers shown to you. Data read from Apple Health, body weight and account details are not included.

Signing in uses Sign in with Apple. Fuel8's own service at www.getfuel8.com receives Apple's confirmation of who you are, and your name and email address only if you choose to share them; Apple lets you hide your email. The account holds when you signed in, which devices are signed in and whether you have Pro. Apple handles in-app subscription purchases and restoration. Fuel8 verifies signed purchases on its backend and associates subscription status and transaction identifiers with your Fuel8 account. Where web purchases are enabled, Stripe hosts checkout and payment management; Fuel8 stores the Stripe customer and subscription identifiers, product, status and renewal date. Card details are entered with the payment provider and are not stored by Fuel8. You can add or edit a display name and contact email in Account details in the app or on the website, including when Apple has not shared those details. These optional details are stored in your Fuel8 account and shown to authorised coaches and administrators. Contact email is self-reported, is not verified, and never changes your Apple identity or account permissions.

Sync and coaching

Sync is off until you turn it on in Settings, then Account, Sync & Coaching, and it works only while you are signed in. When it is on, your food and water diary, hours slept, weigh-ins, targets and profile, saved plates and workouts are sent to www.getfuel8.com under your account. Your time zone and start of week keep dates and summaries consistent with this iPhone. Progress photos and AI Coach use their own explicit controls, independently of diary sync.

On the website's account page you can read every record the service holds, exactly as stored, remove any of it or all of it, and see who has access. The developer holds it to show it back to you and to anyone you share it with, and for nothing else: no advertising, no sale, and no training of anything.

A coach sees your records through an active coaching link. You can create that link by entering their code under Connect with a coach in the app or on your web account page; an administrator can also create a link, which is recorded on your account. You can end access in the app or on the website; the coach can end it on their dashboard. A linked coach or administrator can send a workout to your app inbox. You decide whether to add or dismiss it; receiving workouts does not turn on diary uploads. Assigned exercises are stored as a fixed snapshot, and responses are shown to the sender. Administrators can view synced records to support the service; opening raw sync documents is recorded in your account events.

Deleting your account, in the app or on the website, removes the account, every synced record and every coaching link, and tells Apple to stop listing Fuel8 under your Apple Account. Records on this iPhone are unaffected. Turning sync off stops sending but leaves what was already sent; remove it on the website.

Private progress photos

Progress photos are optional and require a signed-in account. Review selected images, capture dates, poses and notes before uploading. Fuel8 resizes and re-encodes the images to remove location and camera metadata. The service stores the sanitised images privately and does not publish public image links. The app keeps a protected local copy while an upload or coach check-in is pending so you can retry after losing a connection. Cancelling the upload or using Delete all data removes that local copy.

Automatic coach check-ins are on by default for new photo sets in the app. Before saving, Fuel8 lists all currently connected coaches who will receive that set and its note. Choosing Save & share grants those coaches access and creates their check-ins after the photos upload. Turn off Automatic coach check-ins to save privately and stop pending shares. Earlier private photos are never shared automatically, and connecting a new coach does not share earlier sets. Automatic comparisons show your latest two dates for the same pose and can also be turned off. These choices are remembered on this iPhone for each account. Ending a coaching link or revoking a photo grant prevents further access. Turning off automatic check-ins does not revoke grants already sent; use the photo access controls to do that. Administrators do not receive blanket access to photos. A person who already viewed a shared image may have kept their own copy.

Deleting a photo immediately removes access and queues its stored image for deletion. Account deletion also queues image cleanup independently of the account record. Failed cleanup is retried. Turning off diary sync does not delete uploaded photos. Photos are not sent to AI Coach by this release.

Fuel8 AI Coach

AI Coach is an optional automated assistant powered by Anthropic through Fuel8's backend. It uses a service API key held on the backend, separately from the personal API keys used for meal-photo estimates. You do not need to use AI Coach to log food, train or connect to a human coach. AI Coach is switched on per account by Fuel8 and stays hidden until it is. While you are signed in, the app asks your account whether it has been switched on for you; that request carries your sign-in and none of your records.

Before sending a request, choose which categories AI may use. Requests include your message, relevant conversation history, preferences you explicitly confirmed and the permitted synced records needed for that task. Requests go to api.anthropic.com under the service's Anthropic account and are subject to its provider terms and retention settings. Progress photos and raw Apple Health samples are not included. Missing or unsynced records remain unknown.

Fuel8 stores conversations, proposals, explicit memory, consent choices and usage counts in your account. You can revoke data choices, forget preferences and delete conversations. Revocation invalidates earlier AI proposals. Deleting an account removes these account records. Sending data to a provider cannot be undone by deleting a local conversation.

AI suggestions are labelled and can be wrong. A suggested workout requires your acceptance before it becomes a personal workout. Recipe suggestions do not create food intake. AI does not alter human coach assignments or mark them reviewed.

What Fuel8 does not do

No analytics, telemetry, third-party crash reporting or attribution. No advertising or ad identifiers. No tracking across apps or websites, which is why you are never shown a tracking prompt.

No third-party libraries are included in the iPhone app. Fuel8 does not sell or rent your information.

Deleting your data

Settings, then Delete all my data, erases local records without a network connection: your food and water diary, hours slept, weight history, targets and profile; saved plates, personal recipes and cached foods; workout routines, drafts, completed sessions and goals; saved AI provider API keys and consent; estimate counters; local account sign-in and records left by earlier versions. If any part cannot be deleted, Fuel8 reports it so you can retry.

It offers separately to remove the Health samples Fuel8 wrote, so you can wipe the app and keep your Health history. Deleting the app removes its container; use the in-app deletion controls to remove Keychain credentials too. An online account must be deleted separately while connected, in the app under Account, Sync & Coaching or on the website, and subscriptions must be cancelled separately through the provider that sold them: Apple Account settings for App Store purchases or Stripe payment management for web purchases. Deleting your Fuel8 account does not cancel provider billing.

Age

Fuel8 is for adults. Calorie tracking is not appropriate for under-18s without clinical supervision, and the app is not designed or intended for children.

Changes to this policy

If a future version changes what leaves this device, this page changes first and the app tells you before the new behaviour applies. Any new destination or new category of data is presented for you to accept rather than buried here.

Contact

Questions or corrections about this policy: marketing@letsgrowmore.com

Your account page shows synced records. AI Coach and Progress photos show their separate records and deletion controls. If you use only offline logging without account or network features, Fuel8 holds no server copy of that log. Deletion is the one-screen button described above rather than something you have to write in and ask for.

Your rights under UK and EU data protection law

Not repeated in the app, because it would be a wall of legal text on a phone to say "none of this applies".

Offline logging without account or network features keeps the log on your device. The rights the law gives you — access, rectification, erasure, portability, restriction, objection — are exercised directly on the device: the app shows you everything it holds, lets you edit any of it, and deletes all of it in one screen.

For records held by Fuel8 account features, Grow More Services L.L.C-FZ is the controller. The lawful basis is your consent, given by the switch, and withdrawn by turning it off and removing the records or deleting the account. Body weight and Apple Health activity are health data, and are held only because you chose to send them. Every right above is exercised on the website's account page, where the records are shown in full, removable one at a time or together, and the account can be deleted; a coach's access is listed there and ends when you say so. Records are kept until you remove them or delete the account, and for no fixed period otherwise.

The exception is the photo-estimate path. If you enable it, you send images to the AI provider you chose under your own account; your relationship there is with that provider and your rights are exercised through them.

Appendix — what someone with your locked phone can obtain

Included because a policy that only lists good intentions is not much use, and because the honest answer is not "nothing".

Your food log, weight history, targets and profile are stored with iOS Complete Data Protection. While the phone is locked, those files are encrypted with a key that is not in memory. The same class is now the default for every file the app or the system creates on its behalf, including the screen images iOS records for the app switcher — and the app covers its own interface before those are taken, so the picture is of a logo rather than of your dinner.

Each AI provider's API key is in the Keychain, in its own item, as WhenUnlockedThisDeviceOnly: unavailable while locked, and excluded from iCloud Keychain and from device backups.

What is readable on a locked-but-previously-unlocked phone is the preferences file: a provider and model name, the date you gave each provider permission, some counters and two invite codes. It reveals that the app is installed and roughly how often the photo-estimate feature was used. It contains no food, no weight and no health data.

This page is the same text shown inside the app at Settings → Privacy → Privacy policy, where it renders offline.