Controller
The controller is Bastien Vanhove EI, 78, Avenue des Champs-Élysées, Bureau 326, 75008 Paris, France.
For privacy questions: contact@shredy.app.
Data collected by Nalko, processing purposes, providers, retention periods, and user rights.
Updated on July 28, 2026.
The controller is Bastien Vanhove EI, 78, Avenue des Champs-Élysées, Bureau 326, 75008 Paris, France.
For privacy questions: contact@shredy.app.
Nalko collects only the data needed to run the app, secure the service, provide support, and manage premium rights.
On iOS, Nalko accesses Apple Health through HealthKit only after Apple asks for your permission for each individual data type. This access is optional: you can deny or limit any permission without losing access to the core training and nutrition features.
When authorized, Nalko may read step count, walking and running distance, active energy, body weight, body fat percentage, lean body mass, resting heart rate, heart-rate variability (HRV), and VO2 max. These values are used only to display your activity, trends, and fitness progress inside Nalko.
When separately authorized, Nalko may write your body weight, strength workouts and their active energy, and logged nutrition data to Apple Health: dietary energy, carbohydrates, protein, total fat, fiber, sugar, saturated fat, monounsaturated fat, polyunsaturated fat, and sodium.
HealthKit data is never used for advertising, marketing, advertising profiling, or resale, and is never provided to data brokers. It is not sent to RevenueCat. Some values may be stored locally by Nalko and, when you are signed in, synchronized with the Nalko backend for backup, progress tracking, and multi-device use. Technical providers may access it only as needed to host and secure this service.
You can change or revoke Nalko permissions in Apple Health settings at any time. Revocation stops future access but does not automatically erase data already saved in Nalko. You can delete that data and your account from the app or by contacting support. Samples written by Nalko to Apple Health remain under your control in Apple Health.
Nalko does not collect or store bank card details. Payments are made exclusively in the mobile app through Apple App Store or Google Play.
RevenueCat may process technical subscription data to verify premium rights, restore purchases, and synchronize access between the app and Nalko backend.
Processing is based on contract performance when data is required to provide the app, synchronize data, manage the account, process support, or activate purchases.
Some processing relies on consent, including notifications, access to Apple Health or Health Connect, and marketing communications if introduced.
Security logs, abuse prevention, and technical analytics rely on Nalko’s legitimate interest in maintaining a reliable and secure service. Billing and accounting requirements rely on legal obligations.
Your data is never sold. It may only be shared with providers needed to operate the service.
The app uses SQLite as a local source of truth for some data and Expo Secure Store for authentication tokens. Tokens are not stored in SQLite.
When signed in, some data may synchronize with the Nalko backend for backup and multi-device use.
On the showcase website, opening signed-in support may temporarily store authentication tokens in browser session storage. They are removed on logout or when the session closes; any legacy tokens found in local storage are migrated and removed from it.
On mobile, an older session may be upgraded by exchanging its legacy access token for a rotating access-and-refresh-token pair. The old token stops being used after the new session is confirmed, or on its expiration or revocation.
When you are signed in, profile, activity, support, search, and purchase data may be linked to your Nalko account. An installation identifier may also be used before sign-in to count a first open and secure or measure the service.
Nalko does not sell your data, show targeted advertising, or use it to track you across apps or websites owned by other companies.
You may exercise access, rectification, erasure, restriction, objection, and portability rights where applicable.
You can use app features when available or write to contact@shredy.app. You may also lodge a complaint with the CNIL.
Nalko uses technical and organizational measures to protect data: password hashing, token authentication, secure mobile token storage, access restrictions, and secure hosting.
Some providers, including Apple, Google, RevenueCat, or Expo, may process data outside the European Economic Area. Such processing is subject to applicable data-transfer rules; further information may be requested at contact@shredy.app.
This policy may change to follow app, backend, or legal developments. The update date appears at the top of the page.