← Back to Theron

Privacy Policy

Last updated: May 25, 2026

Your privacy matters

Theron collects health data — food logs, macros, weight, workout history. This document explains what we collect, why, and how you control it. Questions? Email support@theronapp.com

1. Who We Are

Theron ("we", "our", "us") is a fitness application developed and operated in Greece. We are responsible for the processing of your personal data as described in this Privacy Policy.

Contact: support@theronapp.com

2. Data We Collect

Account Data

Email address, display name, and account type (personal/professional).

Health Data (Special Category — GDPR Art. 9)

Food logs (meals, macros, calories), body measurements (weight, body fat percentage), workout sessions (exercises, sets, reps, duration), macro targets, and fitness goals. We only collect this data with your explicit consent.

Camera & Photos

When you use the AI food scan feature, the app accesses your camera or photo library to capture a food image. The image is sent to our server for AI analysis and then discarded. We do not store food images beyond the analysis request.

AI Training Data (Optional — Explicit Consent Required): If you opt in via the "Help Improve Theron" toggle (available during onboarding and in Settings), we store your confirmed food scan results — including the original food image URL, the AI-detected items, and the quantities you confirmed — in order to improve the accuracy of our food recognition model over time. This data is stored in our Supabase database and is never shared with third parties for training purposes. You may withdraw this consent at any time by toggling the setting off in your profile.

Usage Data

App activity, feature usage, session duration. Collected via Supabase analytics to improve the app.

Payment & Subscription Data

Subscription status and tier (Free, Fuel, Burn, Peak). In-app purchases are processed directly by Apple App Store or Google Play — we never receive your card details. Subscription management is handled by RevenueCat, which records your anonymous App User ID and entitlement history.

Device Data

Device type, operating system version, app version. Used for crash reporting and compatibility.

3. Legal Basis for Processing (GDPR)

  • Contract performance (Art. 6(1)(b)) — to provide the Theron service you signed up for.
  • Explicit consent (Art. 9(2)(a)) — for health data processing. You grant this during onboarding and may withdraw at any time.
  • Legitimate interests (Art. 6(1)(f)) — to improve the app, prevent fraud, and ensure security.

4. How We Use Your Data

  • Provide nutrition and workout tracking features
  • Generate AI-powered insights (processed via OpenAI API — OpenAI does not use your data to train its models)
  • Analyse food images using computer vision to identify nutritional content
  • Calculate and display personalised macro targets
  • Process and manage subscription entitlements via RevenueCat
  • Send transactional emails (password reset, support replies) via Resend
  • Improve the app through anonymised usage analytics
  • Improve AI food recognition accuracy — only when you have explicitly opted in. We use your confirmed scan results (food names, quantities, and image references) to train and fine-tune our food detection model. This processing has the legal basis of your explicit consent (GDPR Art. 6(1)(a)) and you may withdraw at any time.

5. Who We Share Your Data With

We do not sell your data. We share it only with the following processors, under GDPR-compliant data processing agreements:

ProcessorPurposeRegion
SupabaseDatabase, authentication, storageEU/US (SCCs apply)
OpenAIAI food scan, AI insightsUS (data not used for training)
RevenueCatSubscription management & entitlementsUS (GDPR DPA available)
Apple App StoreIn-app purchases (iOS)Apple privacy policy applies
Google PlayIn-app purchases (Android)Google privacy policy applies
ResendTransactional emailEU/US (GDPR compliant)

6. Health Data — Special Category (GDPR Art. 9)

Food logs, body measurements, and workout data constitute health data under GDPR. We process this data only with your explicit consent, granted during onboarding.

You may withdraw this consent at any time by deleting your account. Upon deletion:

  • All health data is permanently deleted immediately
  • Account data is deleted within 30 days
  • No health data is retained in any backup or archive

7. Account Deletion

You can delete your account directly within the Theron app at any time: go to Profile → Delete Account. This permanently deletes all your personal data, health data, food logs, workout history, and uploaded images. This action cannot be undone.

Alternatively, email support@theronapp.com with subject "Delete my account" and we will process the deletion within 30 days.

8. AI and Automated Processing (GDPR Art. 22)

Theron uses AI to generate nutrition and fitness insights. These insights are informational only. They do not constitute automated decision-making with legal or similarly significant effects on you. All health and fitness decisions remain with you.

You may opt out of AI processing at any time by contacting support@theronapp.com.

9. Data Retention

  • Health data — deleted immediately on account deletion
  • Food scan images — discarded immediately after AI analysis; never stored (unless you have opted in to AI training data collection)
  • AI training scan data — retained only while your consent is active. Deleted within 30 days if you withdraw consent or delete your account
  • Account data — retained for 30 days after deletion (grace period), then permanently deleted
  • Payment records — retained for 7 years (Greek tax law requirement)
  • Support tickets — retained for 2 years

10. Your Rights (GDPR Chapter 3)

You have the following rights regarding your personal data. To exercise any of these, email support@theronapp.com. We respond within 30 days.

  • Right to access — request a copy of all personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — delete your account and all associated data via the app or by email
  • Right to data portability — export your data in JSON format
  • Right to object — opt out of AI processing or analytics
  • Right to withdraw consent — withdraw health data consent at any time without affecting prior processing
  • Right to lodge a complaint — with the Hellenic Data Protection Authority at www.dpa.gr

11. Data Security

  • All data encrypted in transit using TLS 1.3
  • Database encrypted at rest (Supabase)
  • Access controls via Row Level Security (RLS) — users can only access their own data
  • AI processing (OpenAI calls) performed server-side — your API keys never exposed to clients
  • No Theron employee has direct access to individual health data
  • Authentication via Supabase Auth with secure token management

12. International Transfers

Your data may be stored and processed outside the EU/EEA, specifically:

  • Supabase — EU region where available; US transfers protected by Standard Contractual Clauses (SCCs)
  • OpenAI — processes AI requests in the US; SCCs apply; data not retained for training
  • RevenueCat — US-based; GDPR DPA signed; processes anonymous subscription identifiers only

13. Children

Theron is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact support@theronapp.com and we will delete it immediately.

14. Cookies

Theron is a mobile application and does not use browser cookies. Our website may use essential session cookies only, which do not require consent.

15. Changes to This Policy

We may update this Privacy Policy. When we do, we will notify you via email and an in-app notice at least 14 days before the changes take effect. Continued use of Theron after the effective date constitutes acceptance of the updated policy.

Questions or data requests?

Email support@theronapp.com — we respond within 30 days. For complaints, contact the HDPA at www.dpa.gr.