Legal
Privacy Policy
Corvyn is a fitness and nutrition tracking app. This policy explains what we collect, why, who processes it, and the choices you have. We do not sell your data, and we never use health or fitness data for advertising.
What we collect
- Account: your email address and, if you use Sign in with Apple, the identifier Apple provides.
- Profile and goals: name, sex, birth year, height, weight goals, nutrition targets, training preferences and any injuries or restrictions you enter.
- What you log: food and macros, body weight and measurements, sleep, water, steps, workouts and sets, supplements, recipes and shopping lists, notes, and messages you send to the in-app coach.
- Apple Health (optional, with your permission): steps, body weight, body fat, workouts, sleep and active energy are read; food you log and weights you enter can be written back. You choose which types in iOS Settings and can turn access off at any time.
- Photos (optional): a meal photo you choose to analyse is sent for processing and is not stored by us.
- Device integrity: to protect the service from abuse, the app uses Apple's App Attest to prove requests come from the genuine app. This involves a device-generated key and Apple's attestation; it does not identify you personally.
- Usage and cost records: which AI features you use, when, and their processing cost, so we can enforce plan limits.
How we use it
- To run the app: save and sync your logs, calculate trends and targets, and show your history.
- To provide AI features you ask for (estimating food, generating workouts and recipes, answering coach questions).
- To run crews: show crew mates only what you choose to share (see below).
- To keep the service secure and within plan limits.
Who processes your data
- Supabase hosts our database, sign-in and server functions (United States). Your data is protected by row-level security so each account can only read its own records.
- Anthropic processes the text, photos and context needed for AI features you use, through its commercial API. Under Anthropic's commercial terms, these inputs are not used to train its models.
- Apple provides Sign in with Apple, Apple Health, App Attest, push notifications and TestFlight/App Store distribution.
- Expo builds the app and delivers push notifications.
- RevenueCat (if you subscribe) manages subscription status.
We don't use advertising networks, and we don't share health or fitness data with third parties for marketing. If you connect an AI assistant yourself, we share the data you approve with that assistant's company; see Connected AI apps.
Crews and sharing
Crews are private groups you join by invite. You control, per crew, whether crew mates see your weight change (as a percentage or in pounds, or not at all), whether you hit your calorie and protein targets, training, steps, notes and your cookbook. Crew mates never see your raw food log or exact numbers unless you turn that on. You can leave a crew, block a member, or report content at any time.
Connected AI apps (MCP)
You can connect Corvyn to an AI assistant made by another company, such as Claude (by Anthropic) or ChatGPT (by OpenAI), through the Model Context Protocol (MCP). Nothing is shared this way unless you set up a connection and approve it on our consent page.
- You're sharing with a third party. When you approve a connection, you direct us to send the data you approved to that company so its assistant can answer you. From then on, that data is handled under their terms and privacy policy, not ours, and we aren't responsible for how they use it.
- What it can read: your food log and daily totals compared with your targets, your weight trend, lifts, workout plans and recipes, and your targets, goals, training split and any injuries or restrictions you've entered.
- What it can do: log food, weight, water, steps, lift sets and cardio, and generate a workout, on your behalf. Entries it logs are marked as logged by a connected app. It can't delete anything except entries it logged itself, can't change your targets, meal plan or account, and can't see your crews or anything your friends share with you.
- Apple Health data is a separate choice. Steps, weight readings and workouts synced from Apple Health, and sleep times, are only shared if you tick the separate Apple Health box when you connect. Otherwise a connected app only sees what you entered yourself.
- Disconnecting: remove the connection any time in Settings → Connected apps in Corvyn, or in the assistant's own settings. This stops further access straight away; data the other company already received stays with them under their policy.
- Records we keep: we log when a connection is approved or removed, which app it was, whether Apple Health was included, and the tool calls it makes (for security and to help you if something goes wrong).
Retention and deletion
We keep your data while your account exists. You can export everything from Settings → Export and permanently delete your account and all associated data from Settings → Delete account. Deletion removes your records from our database; backups age out within 30 days.
Security
Data is encrypted in transit. AI requests require a signed-in session, are rate- and budget-limited per account, and are checked with Apple's App Attest. Our AI provider key is held only on our servers.
Children
Corvyn is for adults aged 18 and over. We don't knowingly collect data from anyone younger.
Wellness, not medical advice
Corvyn provides general wellness information and estimates. It is not a medical device and doesn't provide medical advice. See our Terms of Service.
Changes and contact
If we change this policy we'll update the date above and, for material changes, tell you in the app. Questions or requests: support@corvyn.app.