Overview
Fuelstate combines on-device storage with optional account sync and connected services. The data that leaves your device depends on the features you choose and the actions you take.
We do not sell personal or health data, and we do not share health data with advertisers or data brokers. Fuelstate does use linked in-app analytics and product-interaction data for the purposes described below. We do not use that data for cross-app tracking or targeted advertising.
This Privacy Policy explains what data Fuelstate ("we," "us," "our") processes when you use the iOS app or fuelstate.app, how it is collected, why it is used, which service providers receive it, how long it is kept, and the choices available to you. Optional app features such as Apple Health, Weather Conditions, Strava, route maps, account sync, and feedback transmit data only when the relevant feature or action is used. Some operational services, including app analytics, diagnostics, subscription management, and push-token registration, may run automatically in a production App Store build as described below.
Data we collect
- Account & identifiers
- Sign in with Apple and service identifiers If you choose to sign in, Apple provides an account identifier and, if you share it, your email address. Fuelstate creates a Supabase account UUID and may associate that UUID with subscription and analytics providers. Before sign-in, PostHog and RevenueCat can each use their own anonymous provider identifier. Fuelstate also processes device push tokens when push-enabled Fueling Companion features are available. The app can store a legacy free-pass device hash and the name and UUID of a paired Bluetooth heart-rate sensor locally on the device.
- Profile & fueling settings
- Information you enter or authorize This can include username, body weight, fitness level, biological sex, cycle-tracking status and phase, units, sweat-rate and sodium settings, stomach sensitivity, caffeine tolerance, gut-training settings, favorite brands, GPS-watch preference, notifications, and Fueling Companion preferences.
- Plans, runs & execution
- Planning and workout records This can include planned and actual run type, distance, pace, duration, terrain, elevation and conditions; carbohydrate, sodium, fluid and caffeine guidance; race and carb-loading details; selected products, custom products, packing and timing plans; fuel-event completion; notes, ratings and GI-symptom feedback; access or pass state; and related run, workout and source identifiers.
- Workout, route & condition data
- Location and performance context With permission, Fuelstate records precise GPS during phone-tracked runs and can process route geometry, distance, pace, altitude, heart rate, cadence, splits and chart streams from Fuelstate, Apple Health or a connected Strava account. Current Fuelstate account sync includes run summaries and distance, time, pace, altitude, heart-rate and cadence streams, but not the raw latitude and longitude recorded by the phone. If an eligible run is uploaded to Strava, its GPX can include the GPS route and heart-rate data. If Weather Conditions is enabled, Fuelstate makes fresh one-shot location requests as needed and sends the resulting location to Apple WeatherKit for current temperature and humidity. Locations are cached in memory for up to 15 minutes and conditions for up to 90 seconds; the resulting conditions can be saved with the run.
- Products & interactions
- Your kit and how app features are used Fuelstate can process product names, brands, categories, nutrition values, custom-product details, favorites, loadout choices, quantities, swaps, product ratings and notes, and commerce-link destinations. It also records in-app interactions such as onboarding, screens viewed, plan generation, paywall and purchase-flow outcomes, feature use, run and fueling events, and creator or referral attribution.
- Purchases & subscriptions
- StoreKit and entitlement records Apple processes purchases. Fuelstate and its subscription providers process product identifiers, receipts or transaction state, subscription and entitlement status, expiration, renewal, grace-period, billing, refund and family-sharing state, and the Fuelstate account UUID when signed in. Fuelstate does not receive your full payment-card number.
- Diagnostics
- Crashes, hangs, performance and operational errors Diagnostic records can include stack traces, app, device and build context, feature state, purchase product and error metadata, and pseudonymous run or activity identifiers. Fuelstate disables Sentry's default personally identifiable information and network breadcrumbs. Its configured sanitizer clears user email, IP address and username, redacts token patterns, removes selected sensitive extra fields, and removes breadcrumbs in configured health, workout, location and Bluetooth categories. It does not guarantee removal of every value that arbitrary exception, tag, context or breadcrumb fields could contain. We do not describe every diagnostic record as anonymous because technical identifiers can sometimes be linkable to other records.
- Support & feedback
- Information you submit If you send feedback, Fuelstate processes the category and message, optional device information and screenshot, and—when signed in—your account email and UUID. The feedback endpoint uses your IP address for rate limiting and abuse prevention. Email support also receives the content and address you choose to send.
- Website & deletion requests
- Ordinary page delivery and actions you take Cloudflare Pages processes ordinary request data needed to deliver and protect fuelstate.app, such as the requested URL, IP address, browser and connection headers, timing and security signals. The checked-in website contains no analytics or advertising script and does not set a marketing cookie. Cloudflare dashboard, Web Application Firewall, bot-management and log-retention settings are controlled outside this source repository and require owner verification. If you request account deletion on the website, your email address is sent by POST to a Supabase Edge Function and Supabase Auth so a confirmation link can be delivered; the flow retains a SHA-256 hash of the email address and the request status as an audit record. Opening an external link sends the ordinary browser request to that destination.
HealthKit & health data
Apple controls HealthKit permission by data type. Only after you use a Health feature and approve Apple's permission sheet can Fuelstate read authorized data such as body mass, biological sex, running workouts, distance, active energy, steps, workout routes and heart rate. Fuelstate can use those values to prefill your profile, calculate fueling guidance, import or match workouts, and show run summaries. If you grant write access, Fuelstate can save completed Fuelstate workouts and routes back to Apple Health.
- If you sign in, profile values and run summaries derived from Apple Health—including workout identifiers and source, distance, duration, pace, elevation, heart rate, splits and chart streams—can be included in your Supabase account sync.
- Fuelstate does not sell HealthKit data, use it for advertising, or disclose it to advertisers or data brokers.
- You can review or revoke access in Apple Health or iOS Settings. Revocation stops future reads or writes; it does not by itself delete data already imported into Fuelstate or workouts already saved in Apple Health.
Turning off automatic workout matching stops future matching but does not revoke Apple Health permission. Unlinking a workout removes the match and workout-derived fields from that Fuelstate run. Verified web deletion removes the remote Fuelstate account and synced records; it cannot clear data from an installed app. In-app deletion also removes the core local records described under Retention & deletion below. Workouts already written to Apple Health remain under your Apple Health controls.
How we use your data
- To calculate fueling targets and turn selected products into packing, timing and live-run guidance
- To store app data locally and, after sign-in, sync and restore account data across devices
- To import, match, display, notify about or share workouts through features you enable
- To provide maps and obtain local temperature and humidity when those features are used
- To process purchases, determine access, restore entitlements and attribute Apple Search Ads or creator referrals
- To understand installs, screens, onboarding, feature use, plan and run execution, purchase flows and product interactions
- To improve the product and catalog, prepare aggregate business reporting, and evaluate potential brand partnerships or sponsored-placement pricing using product-interaction records
- To diagnose crashes, hangs, performance problems, notification delivery and operational errors
- To respond to support, prevent abuse, maintain security and record acceptance of legal terms
Fuelstate does not sell personal information or use app data for cross-app tracking or targeted advertising. The app does use account-linked product and usage analytics for the purposes stated above.
Retention & deletion
Fuelstate-controlled account records in Supabase are retained while your account is active. Local app records and preferences remain on your device until removed by an applicable in-app action or by iOS, subject to Keychain, app-container and operating-system behavior. Signing out stops Supabase account sync, logs RevenueCat out of the Fuelstate account, and resets PostHog's signed-in identity; PostHog may continue with an anonymous identifier and Sentry diagnostics may continue. Signing out does not erase local Fuelstate data, disconnect Strava, or delete the account.
You can request deletion of your Fuelstate account and Fuelstate-controlled synced records at any time:
- In-app: Settings → Account → Delete Account
- Web: fuelstate.app/delete
- Email: [email protected]
When in-app or verified web deletion succeeds, Fuelstate deletes the Supabase authentication account and app-owned Supabase records associated with that UUID, including synced profile, run, product, fuel, GI, Strava-connection, push, subscription-webhook and product-interaction records. The web flow keeps a one-way hash of the email address and request status as a deletion audit record. Web deletion removes remote account and synced records only; it cannot clear an installed app.
In-app deletion also disconnects Strava, cancels pending notifications and Live Activities, clears active shared run state, and removes core local Fuelstate profiles, runs, saved runs, carb-loading plans, products, fuel events, GI records, external-activity decisions and route-cue data. The current implementation does not guarantee removal of every app preference, cache, Keychain ledger, HealthKit anchor, pending Watch action or other integration state. A comprehensive, tested local-account cleanup service is a required app follow-up.
Account deletion does not cancel an Apple subscription, erase workouts already written to Apple Health, remove activities already uploaded to Strava, or automatically erase records held separately by Apple, PostHog, RevenueCat, Sentry, Mapbox, Resend, Cloudflare or an external merchant. Provider-side analytics, subscription, diagnostic, support and security records follow the applicable service configuration and legal or operational retention requirements. Feedback messages and IP-based abuse-prevention records are stored separately from the Fuelstate account and may remain after account deletion. Contact [email protected] if you want Fuelstate to evaluate an access, correction or provider-level deletion request.
You can limit future processing without deleting the account: revoke Apple Health, Location or notification permission in Apple or iOS Settings; turn off Weather Conditions or automatic workout matching in Fuelstate; turn off Strava Auto-Sync or disconnect Strava; use Mapbox's map attribution and telemetry controls; or sign out to stop account sync and reset the specified account linkage. Signing out is not a general collection stop, and revocation does not automatically remove records already created.
Security
Fuelstate uses HTTPS/TLS for network requests, Supabase authentication and row-level access controls for account data, and the iOS Keychain for authentication and connected-service credentials. The Supabase authentication session is stored with kSecAttrAccessibleWhenUnlockedThisDeviceOnly, so it is not included in iCloud backups or transferred to another device by iOS.
No storage or transmission method is completely secure. If you believe your account or data has been compromised, contact [email protected].
Children's privacy
Fuelstate is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Updated" date at the top of this page. For material changes, we'll notify you through the app or by email. Continued use after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or your data, contact us:
Fuelstate
San Diego, California, USA
[email protected]