Privacy Policy — Day90
Controller: Blocksize One UG (haftungsbeschränkt), Oberstr. 3, 47829 Krefeld, Germany — [email protected]
1. What this app does with your data
Day90 analyzes photos of your body to generate predicted images of your physique after 30 to 90 days of training (and unlockable further milestones), and lets you compare weekly progress photos against those predictions.
2. Categories of data
- Body photos you upload (your scan photo and your progress photos). These may reveal health-related information and are treated as special-category data under Art. 9 GDPR.
- Derived estimates (e.g. body-fat estimate, physique score, generated prediction images)
- Profile inputs: age range, height, weight, training goal
- Your chosen first name (optional): if you set a display name, it is stored on our server and shown to the accountability partners you pair with (never your device identifier). You can leave it blank.
- Purchase data: subscription status via Apple (we never see your payment details)
- Technical data: app diagnostics, error logs (device identifiers only as non-reversible hashes), anonymous product analytics events (PostHog, EU Cloud — on by default, with an opt-out in Settings, see §3), subscription entitlement status (RevenueCat), and — only after you allow tracking in Apple’s prompt — ad-measurement events with hashed identifiers (Meta, see §7)
3. Legal bases
- Generation of predictions from your photos: your explicit consent (Art. 9(2)(a) GDPR), given in-app before the first scan. You can withdraw it at any time in Settings; withdrawal deletes server-side data.
- Contract performance for subscription features (Art. 6(1)(b) GDPR).
- Crash diagnostics and operational error logging: legitimate interest in a working, secure service (Art. 6(1)(f) GDPR); error records contain no photos and identify devices only by non-reversible hash.
- Anonymous product analytics: legitimate interest in a secure, well-functioning app (Art. 6(1)(f) GDPR). It is on by default and builds no cross-app profile — events carry only an anonymous per-install identifier and IP is anonymized. You can opt out at any time in Settings → Privacy.
- Ad measurement (Meta): your consent via Apple’s App Tracking Transparency prompt. If you decline or later revoke it in iOS Settings, no ad-measurement events are sent.
We record the consent you give as timestamped records: (1) photo processing (Art. 9) and (2) the no-nudity acknowledgment; we also record when you turn the analytics opt-out on or off. We store the record and its time, never the photo.
4. Processing and retention of photos
- Photos are uploaded encrypted (TLS) and used only to generate your forecast images and your body-composition estimate. Each uploaded photo is deleted from our server as soon as the forecast build it was uploaded for finishes. If a build fails or is interrupted, an automatic cleanup removes any remaining upload within 24 hours at the latest. A photo rejected by our safety filter is deleted immediately.
- The app re-uploads the photo from your device each time you request a new forecast — we do not keep a server-side copy between builds.
- Generated prediction images and your weekly progress photos are stored on your device. Optional cloud backup is off by default.
- We do not use your photos to train AI models, and our processors are contractually barred from doing so.
5. Accountability partners
If you pair with an accountability partner, they see numbers only — your daily consistency scores, streak, day counter and a “needs a nudge” flag — plus the first name you chose to display, if any. Partners never see your photos, generated images, or body data, and never your device identifier. You can remove or report a partner at any time; removing or reporting ends the pairing. Deleting your account removes your display name and all partner links.
6. Website visitors
The day90.app website is hosted on Cloudflare (CDN and edge infrastructure; connection data such as IP address is processed to deliver the site and defend against attacks — Art. 6(1)(f) GDPR). The website sets no cookies and uses no third-party requests. We measure website usage with PostHog EU in cookieless mode via a first-party proxy: no cookies, no cross-site identifiers, IP addresses are not stored (Art. 6(1)(f) GDPR). The recipe and meal-planner pages show typical nutrition values for information only; they are not dietary advice.
7. Processors / recipients
Where a provider is outside the EU/EEA, transfers rest on EU Standard Contractual Clauses (Art. 46 GDPR) and, where certified, the EU-U.S. Data Privacy Framework.
- Apple Inc. — App Store distribution, payments, push notifications. We never see your payment details.
- OpenAI, LLC (USA) — generates your forecast images, estimates body composition, and screens photos through automated content-safety checks. Photos are transmitted for processing only; OpenAI’s API terms bar use of this data for model training. DPA with SCCs.
- Cloudflare, Inc. (USA/EU) — hosting, storage and backend infrastructure for app and website (Workers, storage, database). DPA with SCCs.
- RevenueCat, Inc. (USA) — subscription management; receives purchase tokens and a device identifier, never photos. DPA with SCCs.
- PostHog EU (Germany-hosted EU Cloud) — anonymous product analytics, on by default with an opt-out in Settings; event data only, never photos, no cross-app profile.
- Meta Platforms Ireland Ltd. — ad measurement (install and subscription events with hashed identifiers), only after you allow tracking via Apple’s prompt; never photos or body data.
- Slack Technologies (USA) — internal operational alerting; error notifications contain technical details and hashed device identifiers only, never photos or personal profile data. DPA with SCCs.
- Google Ireland Ltd. (Gmail/Workspace) — support correspondence when you email us; your message and email address are processed to answer you (Art. 6(1)(b)/(f) GDPR).
- Anthropic (USA) — internal development and support tooling; may process support-request text you send us, never your photos or body data. DPA with SCCs.
8. Your rights
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent (Arts. 15–21 GDPR). In-app: Settings → Delete account & data removes all server-side personal data; Settings → Privacy turns anonymous analytics off. After account deletion we retain a non-reversible hash of your device identifier (no photos, no profile data) solely to prevent abuse of the free scan and referral system, plus aggregate technical logs that cannot be linked back to you.
You can lodge a complaint with a supervisory authority; the authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). We are not required to appoint a data protection officer; privacy inquiries: [email protected].
9. Age
Day90 is an 18+ service. We use automated checks (on-device and server-side) to reject content that appears to involve anyone under 18; such content is deleted immediately.
10. No automated decisions with legal effect
Predictions are visualizations for motivation, not decisions producing legal effects (Art. 22 GDPR).
11. Changes
We will notify you in-app of material changes.
Last updated: 14 July 2026