Data collected by Nalko, processing purposes, providers, retention periods, and user rights.
Updated on July 17, 2026.
Controller
The controller is Bastien Vanhove EI, 78, Avenue des Champs-Élysées, Bureau 326, 75008 Paris, France.
For privacy questions: contact@shredy.app.
Data collected
Nalko collects only the data needed to run the app, secure the service, provide support, and manage premium rights.
- Account: name, email, password hash, and Apple or Google identifiers when OAuth login is used.
- Profile and onboarding: goal, level, measurements, height, weight, weak muscle points, program preferences, and other user-entered content.
- Training, nutrition, fitness, and optional health data: sessions, exercises, routines, meals, foods, recipes, steps, distance, active calories, weight and body composition, resting heart rate, heart-rate variability, VO2 max, goals, and progress. Apple Health or Health Connect is accessed only after device-level authorization.
- Support: category, subject, title, message, language, authenticated account name, email and ID, installation ID, client type, and submission date. A signed-in account is required.
- Notifications: Expo Push token, platform, and token update date when notifications are enabled.
- App activity and product interaction: internal account, installation and device identifiers, language, platform, app version, first open, last activity, product interactions, and sampled API events for internal analytics.
- Search history: food, recipe, or exercise queries and selections when recorded to provide search, recent items, and improve result ranking.
- Subscriptions and purchases: premium status, purchase history, customer, transaction and product identifiers, store and environment, price and currency, purchase and expiration dates, trial, cancellation, and RevenueCat data needed for entitlement verification and audit.
- Third-party sign-in services: the embedded Google Sign-In SDK declares account data, identifiers, a phone number, coarse location, and usage data that may be processed depending on the account and technical context. Nalko does not request a phone number or GPS permission and does not store a phone number or precise location in its backend.
Mobile payments
Nalko does not collect or store bank card details. Payments are made exclusively in the mobile app through Apple App Store or Google Play.
RevenueCat may process technical subscription data to verify premium rights, restore purchases, and synchronize access between the app and Nalko backend.
Legal bases and purposes
Processing is based on contract performance when data is required to provide the app, synchronize data, manage the account, process support, or activate purchases.
Some processing relies on consent, including notifications, access to Apple Health or Health Connect, and marketing communications if introduced.
Security logs, abuse prevention, and technical analytics rely on Nalko’s legitimate interest in maintaining a reliable and secure service. Billing and accounting requirements rely on legal obligations.
Recipients and providers
Your data is never sold. It may only be shared with providers needed to operate the service.
- Hetzner: API, database, and technical hosting.
- Apple and Google: OAuth login, app distribution, and in-app payments.
- RevenueCat: in-app purchase and subscription verification.
- Expo: push notifications when enabled.
- Google Workspace (Gmail via SMTP): used only to route, receive, and reply to support messages. Nalko currently uses it neither for marketing emails nor for automated transactional emails.
- Google (clients3.google.com/generate_204): the mobile app may send an empty HEAD request to this endpoint to check Internet access. Nalko adds no account data or user content; Google nevertheless receives technical connection data inherent in the request, including the IP address.
- Meilisearch: search software self-hosted within Nalko’s technical infrastructure for admin users, foods, recipes, and exercises when enabled; it is not a separate external recipient.
- OpenFoodFacts: public food data source, without Nalko sharing your personal data with OpenFoodFacts.
Local storage and synchronization
The app uses SQLite as a local source of truth for some data and Expo Secure Store for authentication tokens. Tokens are not stored in SQLite.
When signed in, some data may synchronize with the Nalko backend for backup and multi-device use.
On the showcase website, opening signed-in support may temporarily store authentication tokens in browser session storage. They are removed on logout or when the session closes; any legacy tokens found in local storage are migrated and removed from it.
On mobile, an older session may be upgraded by exchanging its legacy access token for a rotating access-and-refresh-token pair. The old token stops being used after the new session is confirmed, or on its expiration or revocation.
Account linkage and no advertising tracking
When you are signed in, profile, activity, support, search, and purchase data may be linked to your Nalko account. An installation identifier may also be used before sign-in to count a first open and secure or measure the service.
Nalko does not sell your data, show targeted advertising, or use it to track you across apps or websites owned by other companies.
Retention periods
- Account and synchronized data: while the account is active, then deleted on account deletion unless legal obligations require retention.
- Authentication tokens: until logout, account deletion, or technical expiration/revocation.
- Support messages: for the time required to handle and follow up the request.
- Billing data: mainly handled by Apple or Google. Required records are kept according to applicable accounting and tax obligations.
- RevenueCat events, purchase history, and technical logs: pseudonymous or audit records may remain after account deletion when needed for accounting, fraud prevention, security, or legal claims.
- Technical analytics, search history, and API events: kept according to documented product health, security, and improvement needs; the direct account link is removed when no longer needed, subject to the audit records described above.
Your rights
You may exercise access, rectification, erasure, restriction, objection, and portability rights where applicable.
You can use app features when available or write to contact@shredy.app. You may also lodge a complaint with the CNIL.
Security and transfers
Nalko uses technical and organizational measures to protect data: password hashing, token authentication, secure mobile token storage, access restrictions, and secure hosting.
Some providers, including Apple, Google, RevenueCat, or Expo, may process data outside the European Economic Area. Such processing is subject to applicable data-transfer rules; further information may be requested at contact@shredy.app.
Updates
This policy may change to follow app, backend, or legal developments. The update date appears at the top of the page.