← Back to Constance
Privacy Policy
Last updated: 17 August 2026
Constance is a sports and nutrition coaching app. This page explains, in accordance with the General Data Protection Regulation (GDPR), what data we collect, why, on what legal basis, for how long, with whom it is shared, and how to exercise your rights.
1. Who is the data controller
Constance is the controller of the data collected through the app, within the meaning of Article 4 of the GDPR. For any question or request regarding your data, contact us at the address shown in the app (Account > Support page).
2. The data we collect
- Account: email, password (encrypted, never stored in plain text), first/last name, language, subscription status and history, technical identifiers linked to your payment method (Stripe, PayPal or Apple depending on the platform — never the card number itself).
- Profile (health and fitness data): age/date of birth, sex, height, weight, fitness level, goal, available equipment, priority areas, target training frequency. This information is used to calculate your metabolism and calorie needs.
- Daily tracking: logged meals (description, calories, macronutrients), generated and validated sessions, manually added personal sessions, declared deviations, weight recorded over time, validated days (consistency).
- Connected health data (optional): if you enable the connection to Apple Health (iPhone) or Health Connect (Android), your daily step count and your recorded workouts (activity type, date, duration, estimated calories burned). See section 6.
- Progress photos (optional): if you enable this feature, photos you choose to upload to track your physical evolution.
- Body scan (optional, one-off): if you use this paid feature, the photo you send for analysis, the sex, weight, height and goal you declare, and the resulting estimate (scores and body-fat range). This data stays private and encrypted, is never shared with other users, and can be deleted at any time (see sections 9 and 10).
- Profile photo (optional): a photo you may add to your account, visible to other users according to your privacy setting.
- Community data: username, display name, chosen privacy level (World / Friends / Private), activities and photos you choose to share, likes and comments, friend relationships, follows (following an account, without reciprocity) and blocks, the post you pin to your profile, and reports you submit or that target you.
- Private messages between users: if you message a friend, the content of your messages, the photos you attach, the sessions and recipes you send, and their sent and read timestamps. These messages are readable only by you and your recipient (see section 8).
- Recipes: the recipes you save (name, ingredients, quantities, nutritional values, photo if you add one) and those you copy from someone else's profile. A recipe keeps its original creator's username, including through several successive copies (see sections 8 and 9).
- Messages: messages exchanged with support, and for Max plans, messages exchanged with your assigned human coach.
- App usage: screens viewed and time spent on each, elements tapped, subscription funnel steps (opening the plans screen, moving to the payment page, hitting a paid feature), app version and platform. This information is linked to your account. What you type is never recorded by this tracking: no text, search or password field is read.
- Notifications (if you enable them): a technical device identifier (notification token) and your time zone, used solely to send you push notifications (see section 5).
- Referral: referral code, points earned, the PayPal email address you provide to receive a payout.
- Technical data: IP address at login (security, fraud prevention), session identifiers stored locally on your device (see section 11).
- Advertising measurement — mobile app only: if you install the app after seeing one of our ads, technical device and install identifiers (an install identifier generated by our measurement provider, your device model and OS version, your country, and on Android the install referrer passed by Google Play) are used to link that install to the ad concerned. Two details that matter: on iPhone this measurement goes through SKAdNetwork, Apple's mechanism that only returns aggregated data — we do not show you the "App Tracking Transparency" prompt and we do not use the IDFA; on Android, we do not use the Google advertising ID, the corresponding permission has been removed from the app. None of this data is used to profile you or to show you targeted advertising: it tells us which campaigns work. See section 8.
3. Why we use this data and on what legal basis
- Performance of the contract: calculating your personalized nutrition and training program, tracking your progress, running the anti-drop-off system, enabling follow-up by your human coach for Max plans, managing your subscription and the associated payments.
- Consent: AI analysis of your progress photos, body scan analysis (triggered only by you), reading of your Apple Health / Health Connect data, sharing content in the Community space, exchanging private messages with your friends, publishing recipes on your profile, push notifications, the referral program — explicitly optional features that can be enabled and disabled at any time.
- Legitimate interest: service security (fraud, abuse and account-takeover prevention), moderation of shared content (see section 12), service improvement, measuring app usage — knowing which screens are actually used and where the subscription journey breaks down, so we can fix what blocks people —, aggregated and anonymized usage statistics, and the production of irreversibly anonymized datasets for study, research or commercial purposes (see section 8), and measuring how well our advertising campaigns perform — knowing which ads actually bring sign-ups, rather than paying blind (see section 8). You may object to usage measurement and to advertising measurement at any time (see section 10).
- Legal obligation: retention of certain billing data for our accounting and tax obligations.
Suggestions of similar profiles. In the Community space, Constance may suggest accounts that "look like you". This ranking is computed on our servers from data you already entered in your profile: sex, height, weight, age, goal, level and activity types. None of these values is shown to other people: they only see a general reason (for example "similar build" or "same goal"), never your figures. This suggestion relies on your consent to Community sharing; if you choose Private mode, your account is never suggested to others. No automated decision producing legal effects or similarly significantly affecting you is made on this basis (Article 22 GDPR): it only affects display order.
4. Artificial intelligence (Google Gemini)
Several features rely on the Google Gemini API, which receives only the data needed to generate the requested response (never your email or password):
- generating your training program and estimating calories burned, based on your fitness profile;
- estimating the calories and macronutrients of a described or photographed meal;
- body scan analysis (the photo you send, plus the sex, weight, height and goal you declare) — only when you start a scan yourself;
- anti-drop-off system messages (reaction to a deviation, suggestion of a suitable meal, progress summary);
- comparative analysis of your progress photos — only if you explicitly enable this consent, photo by photo; without this consent, no photo is ever sent to a third-party service and you simply compare your photos yourself.
Google processes this data solely to produce the requested response; it is not used to train Google's models within this API. Google Gemini is a service operated by Google LLC, located outside the European Union; this transfer is governed by the European Commission's standard contractual clauses or an equivalent mechanism recognized as adequate.
5. Push notifications
If you enable notifications, the app stores a technical device token and your time zone in order to send you: daily reminders (at your local time), Community-related notifications (for example a friend request), and messages the team sends you. These notifications are delivered through the operating systems' notification services:
- Apple Push Notification service (APNs), operated by Apple Inc., for iOS devices;
- Firebase Cloud Messaging (FCM), operated by Google LLC, for Android devices.
Consent is requested on first launch, and you can disable notifications at any time from your device settings. As Apple and Google are located outside the European Union, this transfer is governed by the European Commission's standard contractual clauses or an equivalent mechanism recognized as adequate.
6. Apple Health (Fitness) and Health Connect data
If you enable the health connection in Account > Privacy > "Health data", Constance reads from your device, read-only and only after you have granted the corresponding system permissions:
- your daily step count, shown in your daily overview;
- your workouts (activity type, date, duration, estimated calories burned), recorded for example with the Fitness app or your smartwatch: they are automatically added to your Program tab and count towards your calories burned for the day.
This data comes from Apple Health (HealthKit) on iPhone and from Health Connect on Android. Constance never writes anything to Apple Health or Health Connect and reads no other category of health data than the two above. Once imported, it is treated exactly like the workouts you log manually: stored on our servers with the rest of your daily tracking, never used for advertising nor shared with third parties, and subject to the same access (section 8), retention (section 9) and deletion (section 10) rules.
You can disable the connection at any time from the same setting: Constance then immediately stops all reading. You can also revoke the permission at the system level (Settings > Privacy & Security > Health on iPhone; the Health Connect app on Android), and individually delete each imported workout from the app (it will not be re-imported).
7. Payments and subscriptions
Depending on the platform from which you subscribe:
- Web and Android: payment is processed by Stripe or PayPal.
- iOS: in accordance with App Store rules, the subscription is processed through Apple in-app purchase (StoreKit). Apple then processes the payment, manages automatic renewal and, where applicable, cancellation and refunds from your Apple account.
In all cases, we never receive or store your card number. We only keep technical subscription identifiers (and the PayPal email you voluntarily provide to receive a referral payout), needed to recognize your subscription and its status. For iOS subscriptions, we receive a signed transaction confirmation and renewal/expiration notifications from Apple, without any banking data.
8. Who has access to your data
- You: full access to your own data from your account.
- Constance's technical team: access to the servers for maintenance, never reviewing your personal content (photos, messages) without a justified technical need.
- Your human coach (Max plans only): solely for personalized coaching, your coach can access the messages you send them as well as the tracking data you choose to share — profile and goals, nutrition, training and consistency, weight and progress, and progress photos. You control exactly what your coach sees from Account > Privacy > "Sharing with my coach": each category can be turned on or off at any time (on by default), and only a coach Constance has explicitly assigned to you can access it.
- Other users: only the content you explicitly choose to share (username, profile photo, activities, recipes) in the Community space, according to the privacy level you set yourself. You can change this setting or block a user at any time.
- The recipient of a private message: the person you write to sees the content of your messages and the photos, sessions or recipes you send them. They may keep them or, for a session or a recipe, save it to their own account. Only you and your recipient can access a conversation; our servers re-check this membership every time an exchanged photo is opened.
- People who copy one of your recipes: a copied recipe keeps its original creator's username, and that attribution carries over to subsequent copies. Concretely, if someone copies your recipe and a third person then copies it from them, your username remains displayed as the creator. So only put in a recipe what you accept seeing travel with your username.
- Advertising platforms (TikTok): if you come to Constance from one of our ads, we send the platform the fact that a sign-up, a completed questionnaire or a subscription took place, together with the ad click identifier that same platform passed to us when it sent you our way, and the amount in the case of a subscription. This lets it measure how well its campaigns perform. We never send your name, your email address, or your content (meals, photos, messages, coach conversations). You can object to this at any time (see section 10).
- AppsFlyer (app install measurement): AppsFlyer Ltd. is our processor for one thing only: linking a mobile app install to the ad that preceded it, and reporting to the advertising platforms concerned that a sign-up, a completed questionnaire or a subscription (with its amount) followed. It receives the technical identifiers described in section 2, never your name, your email address or your content. It acts solely on our instructions and may not use this data for its own purposes. As AppsFlyer is located outside the European Union, this transfer is covered by the European Commission's standard contractual clauses or an equivalent mechanism recognised as adequate. This measurement exists only in the mobile app: the website carries no such tool. As above, you can object at any time (see section 10) — we then switch off both the server-side transmission and the on-device measurement.
- Google (Gemini API): see section 4.
- Payment providers: Stripe and PayPal (web and Android), Apple (in-app purchases on iOS). See section 7.
- Notification services: Apple (APNs) and Google (Firebase Cloud Messaging) to deliver push notifications, if you enable them. See section 5.
- Resend: provider for sending our transactional emails (password reset, email change confirmation, support replies).
- Research and market-study partners: we may produce, use and share — including commercially — irreversibly anonymized statistics and datasets: never any name, email or identifier, values grouped into ranges, overly small groups removed, free text filtered. This data can never be traced back to you, directly or by cross-referencing, and is therefore no longer personal data within the meaning of the GDPR.
- Competent authorities: only where required by law.
9. How long we keep your data
- Account and tracking data (profile, meals, sessions, weight): kept as long as your account is active.
- Reference photo (your very first progress photo): kept indefinitely, as long as your account exists.
- Intermediate progress photos: automatically deleted after one month, except the most recent of each month, which becomes a monthly milestone kept for your progress timeline.
- Body scan: photo and analysis kept as long as your account exists; can be deleted at any time via the "Disable AI analysis and delete my photos" button in your account, and permanently deleted with your account.
- Content shared in the Community: kept until you delete it yourself or until your account is deleted; deleting a meal or session automatically removes its associated post.
- Private messages between users: kept as long as both accounts exist. When you delete your account, all your messages are permanently erased — including those displayed to your correspondents — along with the photos attached to them.
- Recipes: kept until you delete them or until your account is deleted. If you delete your account, your username automatically disappears from copies held by other people: the recipe stays with them, but with no named creator.
- App usage log: automatically erased after 180 days. The only entries kept longer are subscription-funnel ones (360 days), so conversion can be analysed over a full year. This purge runs daily and automatically.
- Reports: kept for the time needed to handle them, then as evidence in case of repeated abuse; the reported person's username is detached from the report if their account is deleted.
- Support and coaching messages: kept as long as your account is active, to ensure continuity of coaching.
- Notification token: kept while notifications are enabled; it is deleted on logout, when it becomes invalid, or when you disable notifications.
- Billing data: kept for the period required by our accounting and tax obligations, even after the account is deleted.
- Account deletion: all other data is permanently and immediately deleted (see section 10).
10. Your rights and how to exercise them
In accordance with the GDPR, you have the following rights over your data: access, rectification, erasure, restriction of processing, objection, and portability. In practice, from the app:
- Rectification: edit your profile and personal information directly from the Account page.
- Partial erasure: delete a photo, meal, session or post individually, from the relevant screen.
- Withdrawal of consent: disable AI analysis of your photos (which immediately deletes all your progress photos), disable Community sharing from the privacy settings, adjust or turn off the data you share with your coach from Account > Privacy > "Sharing with my coach", or disable notifications from your device settings.
- Full erasure: permanently delete your account and all associated data from Account > Danger Zone. This action is irreversible. Cancelling a subscription purchased on iOS is, however, managed from your Apple account.
- Objection to advertising measurement: you can object to the transmission to advertising platforms described in section 8 by writing to us at the address shown in the app: we then immediately stop sending them anything about you. Your subscription and the service keep working exactly the same way.
- Objection to usage measurement: you can object to the usage log described in section 2 by writing to us at the address shown in the app: we then stop feeding it for your account and erase the entries already recorded. The service keeps working normally.
- Community settings: from Account > Privacy you control who sees your profile (World / Friends / Private), what you share, and whether you want private-message notifications. You can block someone at any time: blocking is immediate and mutual (no visibility and no messaging in either direction).
- Access and portability: to obtain a structured copy of your data, contact us at the address shown in the app.
If you believe your rights are not being respected, you may lodge a complaint with the French Data Protection Authority (CNIL) — www.cnil.fr — or the data protection authority of your country of residence within the European Union.
11. Cookies and local storage
Constance does not use advertising cookies or third-party commercial trackers. The app uses your browser's local storage only to keep your login token and display preferences, which is strictly necessary for the service to function and does not require consent under the ePrivacy Directive.
The advertising measurement described in sections 2 and 8 relies on no cookie at all: it exists only in the mobile app, where it uses the mechanisms Apple and Google provide for this purpose (SKAdNetwork, Google Play install referrer). The website itself carries neither an advertising pixel nor a third-party tracker.
12. Security, moderation and reporting
Passwords are encrypted (hashed), progress photos as well as photos exchanged in private messages and those attached to recipes are stored encrypted on our servers in a private storage area not publicly accessible, and communications with the app are encrypted (HTTPS). Access to data is limited to those who strictly need it for their role. A photo exchanged in a private message is served only to the two participants of the conversation: the server re-checks that right on every display, never trusting the device that requests it.
User-generated content. The Community, private messages and recipes let people publish content. Every post, comment, recipe and account can be reported from within the app, in a couple of taps. Reports are reviewed by our team; content breaching our Terms of Use may be removed and the account concerned warned, suspended or closed. You can also block anyone at any time: blocking is immediate and mutual (no visibility and no messaging in either direction). These processing activities rely on our legitimate interest in providing a safe space and, where applicable, on our legal obligations.
13. Minors
Constance is not intended for minors. Registration is reserved for adults, or for individuals with the consent of a holder of parental authority where applicable law allows it at a lower age. Social features — posts, private messages, recipe and session sharing — are reserved for accounts meeting this condition. If we learn that an account was created by someone below the required age, it is deleted along with the associated data.
14. Changes to this policy
This policy may be updated to reflect changes to the service or to regulations. The last-updated date appears at the top of this page; any material change will be notified to you in the app.
15. Contact us
For any question about this policy or to exercise your rights, contact us at the address shown in the app (Account > Support page). See also our Terms of Use.