Fuse Privacy Policy
Last updated: September 15, 2026
This privacy policy explains which personal data the fitness app Fuse ("Fuse", "we", "us", "our") collects, why we do so, who we share data with, how long we keep it, and what rights you have. We have tried to write this as clearly as possible, without unnecessary legal jargon.
Fuse is an app for tracking your nutrition, weight, workouts and sports activities, and for sharing workouts with people you follow.
1. Who is responsible for your data
The data controller for the personal data processed through Fuse is:
Fuse - info@fusefitnessapp.com
If you have questions about this policy or your data, please contact us using the details in section 11.
2. What data we collect
We only collect data needed to make Fuse work. The categories are listed below.
2.1 Account data
- Email address
- Username
- Password (this is stored in encrypted form, that is, hashed, by Supabase Auth; we cannot see your password)
- If you choose to sign in with Apple (Sign in with Apple), and later possibly with Google: the sign-in information these services pass to us to create your account or log you in
This account data is needed to provide the service; without it, you cannot create an account.
2.2 Body and health data (special category data)
This data says something about your health and counts as special category personal data under the GDPR (Article 9 GDPR). We process it only with your consent.
- Weight
- Height
- Date of birth and/or age
- Sex/gender
- Weight logs over time (your weight as you record it at different moments)
We use this data to calculate your calorie and macro goals (protein, carbohydrates, fats). Fuse calculates these goals automatically, but does not make automated decisions with legal effects or similarly significant effects for you.
2.3 Nutrition data
- Meals and food items you log
- Photos of food that you take to have their contents recognized automatically. For this recognition, the photo is sent from your device through our server to an external AI service from Google (the Gemini API). Our server does not store the photo and only passes it on. The photo therefore leaves your device and is processed by Google to recognize the food. See section 4 for more about this recipient.
2.4 Food database searches
- When you search for products in the app, your search query is forwarded to Open Food Facts, an external food database, to retrieve product information. See section 4.
2.5 Location data
When you start an activity such as running, walking or cycling, we record your route using GPS. This includes:
- Location (GPS coordinates)
- The route you take
- Distance
- Pace
- Elevation
We collect this location data only during an active activity, from the moment you start the activity until you stop it. To keep your route complete, tracking continues even when your screen is off or you briefly switch away from the app during the activity (background location). As soon as you stop the activity, tracking stops too. Outside an active activity we never track your location.
2.6 Social features
Fuse has a feed in which you see workouts from people you follow.
- You can follow others and be followed yourself
- You can share workouts and cardio activities and choose their visibility: private, friends only, or everyone
- Profile photo (avatar) that you can set optionally
- You can like and comment on other people's workouts and cardio activities. Your comment is stored with that workout or activity, with your name next to it
- You can join a group and take part in its weekly leaderboard. We store which groups you are a member of, what role you have in them and the score you reached that week. A group can have its own name and group photo
- Within a group you can send messages. Those messages are stored and are visible to the other members of that group
- You can block other users. We store who you have blocked, so we can keep the two of you out of each other's app
- You can report a user, a workout, an activity, a comment, a shared product, a group or a message. We store that report, with the reason you choose and a copy of what you report (for example the text of a comment and the name of the person who posted it), so we can still assess the report if the original has been removed in the meantime. When a new report comes in we receive an email; it does not contain what was reported or who reported it
- We keep track of which notifications you have received in the app (for example that someone started following you or commented on your workout) and whether you have read them
Workouts you share are visible to others according to the visibility you have set. Comments and group messages are visible to everyone who has access to that workout or that group.
2.7 Push notifications
If you turn on push notifications, we create a push token for your device and store it together with your notification preferences and your app language. Delivery of notifications runs through the push service of Expo (650 Industries, Inc., United States): your push token and the content of notifications pass through Expo's servers. See section 4 for more about this recipient. You can turn off push notifications at any time in the app or via your device settings.
2.8 Technical data and storage
Your data is stored with Supabase, which provides hosting, database, storage and authentication. Storage takes place in the European Union (Frankfurt, Germany).
2.9 Phone number and finding friends via contacts
Fuse has an optional feature for finding friends who already use the app. This feature is fully opt-in: it is only used if you turn it on yourself.
- Your own phone number (being discoverable). If you want friends to be able to find *you* through their contacts, you can provide your phone number. We do not store your number as a readable number. Your device first converts the number to a fixed form and then computes an irreversible code (a hash) from it; only that code is stored, linked to your account. You can turn this off again at any time ("Hide"), after which the code is deleted.
- Matching contacts. When you use "Search my contacts", the app asks once for permission to read your contacts. The phone numbers from your contacts are converted on your own device into that same kind of codes (hashes). Only those codes are sent to our server to compare against the codes of users who have made themselves discoverable. The actual phone numbers of you and your contacts do not leave your device, and we do not store your contacts' details (names and numbers) on our server: the comparison happens transiently during the search and the contact codes are not kept afterwards. Someone can only appear as a match if that person has also made themselves discoverable.
2.10 Training and activity data
- Workouts you log: exercises, sets, weights, duration, date, any notes and optional workout photos. Workout photos are stored privately and are only visible according to the visibility you set for the workout.
- Cardio activities you record or log (such as running, swimming or a cardio machine): the type of activity, the duration, the distance (if you measure or enter it), the average pace, the elevation gain, the time, a name and a note if you enter them, and the visibility you choose (private, followers only, or everyone). An activity is private by default.
The full GPS route of an outdoor activity stays on your device. If you choose to share an activity with your followers or with everyone, we send a shortened copy of the route to our server: the start and the end (several hundred metres on both sides, chosen at random each time) are cut off so that your departure and arrival points are not visible, and the copy only contains the line of the route, no timestamps, elevation or speed per point. The start and end time of the activity are included. For such a shared activity we also determine the place name once (town and region, never a street or postcode) at a point halfway along that shortened route, and store it. That copy and that place name are visible to the people who are allowed to see your activity according to the visibility you set. Routes shorter than one kilometre never get a map. Honest about the limit: someone who views many of your shared routes may infer a neighbourhood from the patterns; if you do not want that, keep your activities private. No copy of the route of a private activity is stored on our server.
We use this data to show your workouts and statistics, to show shared activities in your followers' feed and, if you are a member of a community, to calculate the shared scores (such as training minutes).
2.11 Apple Health integration (iPhone only)
Fuse can exchange data with Apple Health. This integration is optional and turned off by default: you turn it on yourself under Settings, Health, and iOS asks separately for your permission per type of data.
- What Fuse writes to Apple Health: your completed workouts, your running, walking and cycling activities (including the distance and the energy burned) and your weight at the moment you log it.
- What Fuse reads from Apple Health: only today's step count, to show it alongside your own statistics.
This exchange takes place entirely on your own device, between Fuse and Apple Health. No data is sent to our server as a result, and we do not share Apple Health data with anyone. You can turn the integration off in Fuse at any time, and in Apple's Health app you can revoke Fuse's access per type of data.
3. Purpose and legal basis per category
Under the GDPR we need a legal basis for each processing activity. These are listed per category below.
| Category | Purpose | Legal basis |
|---|---|---|
| Account data (email, username, password, sign-in via Apple/Google) | Create your account, log you in and make the app available to you | Performance of the contract (Article 6(1)(b) GDPR) |
| Body and health data (weight, height, date of birth/age, sex/gender, weight logs) | Calculate your calorie and macro goals and show your progress | Your explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR, because this is special category data) |
| Logged meals | Track your nutrition and follow your goals | Performance of the contract (Article 6(1)(b) GDPR) |
| Photos of food (sent to Google/Gemini) | Automatically recognize what is in the photo so you can log it more easily | Your consent (Article 6(1)(a) GDPR); you choose yourself whether to have a photo analyzed |
| Product searches (Open Food Facts) | Retrieve the product information you search for | Performance of the contract (Article 6(1)(b) GDPR) |
| Location data (route, distance, pace, elevation) | Record your activity and show your route and statistics; and, if you choose so, share a shortened copy of your route and the place name with the people you allow | Your consent (Article 6(1)(a) GDPR); location is only collected when you start an activity, and a route is only shared if you set the visibility to followers or everyone yourself |
| Training and activity data (workouts, workout photos, cardio activities: type, duration, distance, pace, elevation, name, visibility, and for shared activities the place name and the shortened route) | Track your workouts, show your statistics and calculate community scores | Performance of the contract (Article 6(1)(b) GDPR) |
| Social features (following, sharing, profile photo, feed) | Allow you to share workouts and see those of others | Performance of the contract and legitimate interest in making the social features work (Article 6(1)(b) and (f) GDPR) |
| Social interactions (likes, comments, group membership and role, group messages, in-app notifications) | Make the social features and the weekly leaderboard work | Performance of the contract (Article 6(1)(b) GDPR) |
| Blocks and abuse reports | Keep the app safe and pleasant and be able to assess reports | Legitimate interest (Article 6(1)(f) GDPR) and compliance with our obligations as a provider |
| Apple Health integration (writing workouts, activities and weight; reading steps) | Keep your data in one place and show your steps alongside your statistics | Your explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR); optional, can be turned off in Fuse and revoked in the Health app |
| Push notifications (push token, notification preferences, app language) | Send you the notifications you have turned on yourself | Your consent (Article 6(1)(a) GDPR); you can withdraw it at any time by turning notifications off |
| Phone number (as a code/hash) to be discoverable, and matching your contacts (as codes/hashes) | Let you find friends who already use the app and be found by them | Your consent (Article 6(1)(a) GDPR); fully opt-in, withdrawable by hiding yourself or revoking contacts access |
| Technical data and storage | Run the app securely and reliably | Legitimate interest and performance of the contract (Article 6(1)(f) and (b) GDPR) |
Where we rely on your consent as the basis, you can withdraw that consent at any time (see section 7). Withdrawing consent does not affect processing that took place before the withdrawal.
4. Recipients, third parties and international transfers
We do not sell your data, and we never use your body, health, nutrition or activity data for advertising, marketing or data mining. We only share data with the parties needed to make Fuse work. These are our external service providers (sub-processors):
Supabase (hosting, database, storage and authentication)
Your account and app data is stored and managed through Supabase. Storage takes place in the European Union (Frankfurt, Germany). Supabase processes this data on our behalf.
Google (Gemini API) for recognizing food photos
When you have a food photo recognized, that photo is sent from your device through our server to Google's Gemini API. Our server does not store the photo and only passes it on. Google processes the photo to determine its contents and returns the result. The photo therefore leaves your device. Google does not use the photos or the results to train or improve its products or models; they are processed solely to carry out the recognition and are logged briefly for abuse detection. Google is a US company; depending on the infrastructure used, this may involve a transfer of data outside the European Economic Area (EEA). Such transfers take place on the basis of appropriate safeguards, such as the European Commission's standard contractual clauses. If you do not send a photo, no photos are sent to Google.
Open Food Facts (food database)
When you search for a product, your search query is forwarded to Open Food Facts to retrieve product information. Open Food Facts is an external, public food database.
Expo (650 Industries, Inc.) for push notifications
If you turn on push notifications, their delivery runs through the push service of Expo (650 Industries, Inc.), a US company. Your push token and the content of notifications pass through Expo's servers. This may involve a transfer of data outside the EEA. Such transfers take place on the basis of the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
Apple (Sign in with Apple and the map during an activity)
If you sign in with Apple, that runs through Apple, and Apple passes us an identifier and, if you allow it, your name and email address. On the iPhone, the map shown during an outdoor activity uses Apple Maps; Apple processes the data needed to deliver that map view. When you share an activity, on the iPhone we ask Apple once for the place name of a single point halfway along the shortened route (from coordinates to town and region); Apple sees that one point. The Apple Health integration (section 2.11) is separate from this and stays entirely on your own device.
Google (Sign in with Google and the map on Android)
If you sign in with Google, that runs through Google, which passes us an identifier and your email address. On Android, the map shown during an outdoor activity uses Google Maps, and when you share an activity we ask Google once for the place name of a single point halfway along the shortened route. Google is a US company; transfers outside the EEA take place on the basis of the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
jsDelivr (the exercise illustrations)
The illustrations shown with the exercises are retrieved from jsDelivr, a public network that serves files. Your device connects directly to that service to do so, which means your IP address and the file requested become known to them. We do not send any account or health data along with it.
Expo (app updates)
Besides push notifications, we also use Expo to deliver updates to the app. When you open the app, it checks with Expo whether a newer version is available. Expo processes technical data in doing so, such as your IP address and the version you are using.
Vercel (our website)
Our website fusefitnessapp.com is hosted by Vercel. Vercel processes the technical data that comes with visiting a website, such as your IP address. There are no analytics or tracking services on our site.
Zoho (our mailbox) and Resend (sending email)
Email you send us, for example with a question or a request about your data, arrives at Zoho, which provides our mailbox within the European Union. To send email we use Resend, a US service; transfers outside the EEA take place on the basis of the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
Besides these service providers, we may share data if we are legally required to do so, for example based on a valid request from a competent authority.
5. How long we keep your data
We do not keep your data longer than necessary.
- Account and app data (including your nutrition logs, weight logs, health data, activities and social data) is kept for as long as you have a Fuse account.
- Photos of food are sent to Google through our server solely to carry out the recognition; our server does not store the photo. We keep a logged meal for as long as your account exists, unless you delete the meal or the account.
- Your phone number code (hash) for discoverability is kept for as long as you want to be discoverable: it is deleted as soon as you hide yourself or delete your account. We do not keep your contacts' codes; those are only used transiently during a search.
- Abuse reports are kept, together with the copy of what was reported, for at most 12 months after the report; after that they are deleted automatically. This also applies if the reported content, or the account of the reporter or of the reported person, has been deleted in the meantime. That way nobody can escape a report by quickly removing their message or account, and we can recognise repeated abuse.
- When you delete your account, we delete the personal data stored with us, except for reports as described above. Fuse provides an in-app account deletion for this, so you can do it yourself. After deletion, data may still be present in backups for a short time before those backups are overwritten on schedule.
- Data that we are legally required to keep longer is kept only for as long as that obligation applies.
6. Website waitlist
On our website you can leave your email address to join the waitlist for Fuse. We then store your email address and your language preference.
- Purpose: we use this data only to send you emails about the launch and the beta of Fuse, and for nothing else.
- Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw it at any time by unsubscribing.
- Storage and sending: the waitlist is stored with Supabase (see section 4). To send these emails we use Resend, a US email service; this may involve a transfer of data outside the EEA, on the basis of the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
- Retention: we delete the waitlist data no later than 3 months after the launch of Fuse, or earlier if you unsubscribe.
- Unsubscribing: every email we send to the waitlist contains an unsubscribe link at the bottom that takes you off the list right away. You can also send a message to info@fusefitnessapp.com and we will do it for you.
7. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access: you may request which data we hold about you. There is no button for this in the app yet; send a message to the address in section 11 and we will send you an overview.
- Rectification: you may have incorrect data corrected. You can change much of your data yourself in the app.
- Erasure: you may have your data deleted. You can delete your account yourself using the in-app account deletion.
- Restriction of processing: you may ask us to temporarily restrict the processing of your data, for example while we assess an objection or a correction request from you (Article 18 GDPR).
- Data portability: you may request your data in a common format to take to another service. You also request this through the address in section 11.
- Objection: you may object to processing based on legitimate interest.
- Withdraw consent: where we asked for your consent, you may withdraw it at any time. For food photos, location, push notifications, the Apple Health integration and being discoverable through your phone number, you do this directly in the app or in your device settings. For your body and health data (weight, height, date of birth, sex/gender) it works differently: that data is needed for Fuse to work, so you withdraw your consent for it by deleting your account. You can do that yourself in the app, and the data is then erased.
You can exercise these rights using the contact details in section 11, or where possible directly in the app. We respond within the legal time limit (in principle within one month).
If you disagree with how we handle your data, you may file a complaint with the supervisory authority. In the Netherlands this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (autoriteitpersoonsgegevens.nl).
8. Minors
You must be at least 16 years old to use Fuse. This matches the age limit in the Dutch implementation of the GDPR (Article 8 GDPR).
If you are younger than 16, you may only use Fuse with the consent of a parent or legal guardian. We do not knowingly process data of children under 16 without that consent. If we discover that we have processed such data without valid consent, we will delete it.
9. Security
We take appropriate technical and organizational measures to protect your data:
- Passwords are stored in encrypted (hashed) form via Supabase Auth and are not readable by us.
- Data is sent over encrypted connections and stored in the EU.
- We apply access control, so that only those who need access can reach the data.
No service can guarantee one hundred percent security, but we do everything we can to protect your data well.
10. Changes to this policy
We may update this privacy policy from time to time, for example when the app changes or when regulations require it. The date at the top ("Last updated") shows when we last changed the policy. For significant changes we will inform you in the app. We recommend that you review this policy from time to time.
11. Contact
If you have questions about this privacy policy or want to exercise one of your rights, please contact:
Fuse - info@fusefitnessapp.com

Don't have Fuse yet?
Your workouts, your meals, your runs and your group. One app, free.