Privacy Policy
Kupaʻa, a product of Kupaa Labs LLC
Effective date: 7 July 2026 · Last updated: 26 July 2026
Applies to the Kupaʻa app for Android (package com.kupaa.app) and to this website.
The short version
- You can use Kupaʻa without creating an account. Anonymous use is a first-class option, and your data stays on your device until you choose to sync or sign in.
- What you record in Kupaʻa (your weight, your meals, your workouts, your sleep) is health data, and we treat all of it as sensitive personal information, whatever country you live in.
- We do not sell your data. We do not show ads. We do not use your health data to advertise to you, and we never share it with anyone for their advertising. We have no analytics or crash-reporting tools in the app, and no analytics or cookies on this website.
- If you use the AI food features, the photo or the sentence you submit is sent to Anthropic to read it, is used only to produce your nutrition result, and is not stored on our servers. See Section 4.
- We ask for your explicit, separate consent before processing any health or fitness data. It is never bundled into accepting these terms, and the switch starts off. You can withdraw it at any time in Settings → Your data, as easily as you gave it.
- You can export everything (JSON or CSV) and delete your account and data from inside the app at any time. One thing does not come back: a food you chose to publish to the community pantry, because it no longer carries your identity. Label photos are different: they are deleted within 30 days, and immediately when you delete your account. See Section 6 and Section 14.
The full detail is below.
1. Who we are and what this covers
Kupaʻa is an adaptive fitness and nutrition coaching app operated by Kupaa Labs LLC (“Kupaʻa,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect through the Kupaʻa mobile app and this website (together, the “Service”), how we use and protect it, and the choices and rights you have.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
For privacy questions or requests, contact us at privacy@kupaa.fit.
2. Information we collect
We try to collect as little as possible, and to keep as much as we can on your device.
a. Information you give us directly
- Profile basics you enter during onboarding: sex, date of birth (used to confirm you are old enough to use the Service and to calculate your starting targets), height, units, daily movement level, current weight, and optional goal weight.
- Your name, only if you choose to share it. It is optional, and it is used so your coach, Kaʻi, can greet you.
- Health and body metrics you log over time: weigh-ins, waist and other measurements, body-fat estimates, and the resulting trends and forecasts.
- Training data: workouts, sets, reps, weights lifted, failed and completed sets, personal records, exercise substitutions, cardio duration and distance, and the days you tell us you can train.
- Nutrition data: food diary entries, portions, custom foods you create, calories, macronutrients, micronutrients, and water intake.
- Fasting data, if you use the Caldera: your chosen eating window, and the fasts you start and complete.
- Sleep hours you enter by hand, if you do not connect a wearable.
- A brief well-being screening (a short standard questionnaire, the SCOFF questions) used only to keep the Service safe for you, for example to make certain modes and calorie targets unavailable when they would not be appropriate. Your answers are used for safety and personalization and are treated as sensitive health information (see Section 8).
- Coaching-quiz answers (your goal, experience, preferred style, minutes available) used to rank which programs to recommend.
- Your settings and preferences, including units, theme, language, notification preferences, daily targets, and step and water goals.
- A record of the agreements you accepted: that you acknowledged the medical disclaimer, and when you accepted these Terms and which version of them, so we can answer that question accurately rather than by inference.
- Anything you send us, such as support messages or feedback.
b. Information from your device and connected apps
- Health Connect (Android), if you choose to connect it. We read only the data types you grant: steps, active calories burned, weight, and sleep. With your permission we also read your step count in the background, roughly every half hour, so a home-screen widget can stay current and so we can congratulate you when you hit your step goal while the app is closed. We write one thing back to Health Connect: a strength-training exercise session when you finish a workout in Kupaʻa. We do not write your steps, weight, or sleep back to Health Connect. You can revoke any permission at any time in Health Connect settings, and Kupaʻa keeps working with whatever you allow. See Section 9.
- Imports you start yourself. If you import your history from MyFitnessPal, you choose the exported files with your device’s file picker, and we read the nutrition, exercise (including step counts), and measurement summaries in them. We do not browse your files; we only read the files you hand us.
- A device identifier we generate. When you first open the app, we create a random identifier for that installation and store it on your device. It is included with the backup of your data on our servers so we can tell your devices apart, detect a stale copy, and avoid overwriting newer data with older data. It is not an advertising identifier, it is not shared with anyone, and it is not linked to any identifier from your phone or from other apps.
- Basic technical information needed to run and secure the Service, such as app version, device type and operating system, and the general region inferred from your IP address when your device contacts our servers.
- We do not use any analytics or crash-reporting product. There is no Google Analytics, Firebase Analytics, Sentry, Crashlytics, or similar SDK in the app, so we do not collect usage analytics, behavioural event streams, or automatic crash reports.
We do not collect precise location, advertising identifiers, or contacts. We access your camera only when you use a feature that needs it (scanning a barcode, photographing a nutrition label, or photographing a plate). We do not request microphone access and the app does not record audio. We do not request access to your photo library; photos can only come from the live camera in the moment you take them.
c. Subscription and purchase information
- Kupaʻa Pro is sold through the Google Play Store (and, in future, the Apple App Store) and managed with RevenueCat. Your payment is processed by the app store; we never receive or store your card or bank details. We receive your subscription status (active, expired, entitlement, product, period, expiry) so we can unlock Pro features. Your Kupaʻa account identifier is shared with RevenueCat so your subscription can be matched to your account.
d. Anonymous use
- If you use Kupaʻa without an account, your data is associated with a local or anonymous identifier rather than a name or email, and nothing is uploaded until you choose to sign in. If you later create an account, your existing data can carry over.
3. What is stored where
Kupaʻa is offline-first, so most of your data lives on your device and is mirrored to your account when you are signed in.
- On your device: everything you log, plus a snapshot used to draw your home-screen widgets, and (for up to about 30 days) a local safety copy of your data taken before a sign-in replaces it, so a bad sync cannot cost you your history. If a write to our servers is rejected, the rejected item is also kept on your device so it is not silently lost; if you ask us for help, you may choose to send it to us as part of a support conversation.
- On our servers, if you are signed in: your account, your logs, and a complete backup of your app state (everything in Section 2a) so you can restore it on a new device.
- Home-screen widgets display your calories, macros, water, fasting state, steps, and daily progress outside the app, on your home screen, where anyone holding your phone can see them. You choose whether to add a widget.
4. AI-assisted food features and Anthropic
Three optional Kupaʻa Pro features use a third-party AI provider, Anthropic, to read what you submit:
| Feature | What is sent to Anthropic |
|---|---|
| Snap a nutrition label | The photo you take |
| Snap your plate | The photo you take, plus a two or three letter code for your market or language, so portions and products are interpreted for the right region |
| Describe a meal in words | The text you type, plus the same market or language code |
What you should know about these:
- Nothing that identifies you is sent. We do not send your name, email, account identifier, device identifier, weight, goals, diary history, or any other health data with these requests. Anthropic receives the photo or the sentence and nothing else. Because the request reaches Anthropic from our servers, your IP address is not exposed to them either.
- The photo and the text are processed transiently. They are used to produce the nutrition result and are not stored on our servers, not written to any database, and not written to any log. Only the resulting nutrition entry in your diary is kept, as part of your normal food log.
- Anthropic does not use this content to train models. Anthropic’s Commercial Terms of Service, which govern our use of its API, state plainly that it may not train models on customer content.
- Anthropic keeps a copy for up to 30 days, then deletes it. That window exists so Anthropic can investigate safety and security problems, and it is the standard retention for its API. It is the one place a photo or sentence lives on beyond the moment, so we would rather state it than let “not stored” imply more than it should.
- A photo can contain more than food. A plate photo may include your table, your home, or other people. Consider what is in frame before you take it.
- What you type is free text. If you type personal details into a meal description, that text is sent to Anthropic along with the description.
- We keep a count, not content. So these features cannot be abused and our costs stay predictable, we store a per-day count of how many AI captures your account has made, subject to a daily fair-use cap. That record is a number and a date. It contains none of your photos, text, or results.
- Camera photos linger in your phone’s cache. When you take a label or plate photo, your device writes temporary image files in the app’s own private cache area, which the operating system reclaims over time. These never leave your device except as the request described above.
- Label photos you choose to publish are the one exception to “not stored,” and even those are kept for only 30 days. See Section 6.
- These features are optional. Barcode scanning, food search, and manual entry never involve an AI model.
5. Food databases and food search
Our own food database. Kupaʻa hosts its own food corpus so most lookups never leave our servers. It is built from public and openly licensed sources:
- Open Food Facts, used under the Open Database License (ODbL).
- USDA FoodData Central (Foundation, SR Legacy, Branded, and FNDDS Survey datasets), which is United States public-domain data.
- The Swiss Food Composition Database (Federal Food Safety and Veterinary Office), used with permission and with acknowledgement of the source.
- The French CIQUAL table (ANSES), used under the Etalab Open Licence 2.0.
Attribution for these sources appears in the app under You → Settings → About, and in the footer of this site, along with the date our copy of the data was last updated.
What happens when you search or scan. Your search text or barcode is sent to our servers, over an authenticated connection, so it arrives associated with your session. We do not log, store, or profile your searches. There is no search-history table, no query log, and no analytics product recording what you look for.
When a lookup reaches a third party. If our own database has no answer, the lookup falls back to Open Food Facts:
- For barcodes, the fallback normally happens on our servers, so Open Food Facts receives only the barcode digits and does not see your IP address.
- In some cases (for example if you are signed out, or our service is unreachable), your device queries Open Food Facts directly. In that case Open Food Facts receives your search text or barcode and, as with any direct internet request, your IP address. No account identifier, name, or health data is ever attached.
Popularity. When you log a food, we increment a counter on that food so commonly eaten items rank better for everyone. The counter records only that a food was logged. It carries no user identifier, no timestamp, and nothing from your diary.
We do not use MyFitnessPal’s database, and we do not send anything to MyFitnessPal.
6. The community pantry (foods you publish)
If you create a food from a barcode or a nutrition-label photo, Kupaʻa may offer to share it so the next person who scans that product finds it ready. Publishing is entirely optional and never happens unless you tap to share. If you do:
- What becomes visible to others is the food record itself: the name, barcode, nutrition per 100 g, micronutrients, and serving sizes. Your identity is not shown. Other people, including people who are not signed in, can see the food but never see who submitted it.
- We keep an internal link to your account for that submission, in a restricted table only our systems can read, so we can handle moderation, correct bad data, and deal with abuse. So published foods are pseudonymous to other users, not anonymous to us.
- The label photo you attach as evidence is stored in a private area that only you and our systems can access, and is used to verify the entry and lift it to a verified tier. Unlike the AI features in Section 4 it is stored rather than transient, but only for 30 days. The photo’s job is done once the entry has been checked against it: after that we keep the result of that check (a record that the entry was verified by evidence), never the image. Deleting your account, or resetting your data, deletes your photos straight away rather than waiting out the 30 days.
- Publishing is effectively permanent. Submitting the same food again updates your submission, but there is currently no way to withdraw a published food, and the published record does not get deleted when you delete your account, because it no longer carries your identity and other people’s food entries depend on it. Please treat publishing as a permanent, one-way contribution to a shared database.
- You can report an entry, and we can remove one. Reporting a food sends it to us for review; it never removes or hides the food on its own, so no number of reports can make a common food disappear for everyone else. We review reports and can correct, remove, or leave an entry as it is. Separately, our own checks may hide an entry automatically when submissions for it disagree with each other beyond what a measurement difference explains.
7. How we use your information
We use your information to:
- Provide the coaching: build and adapt your training and nutrition plan, estimate your energy needs, predict your next sets, track your trends, and give you one clear next step each day;
- Sync your data across your devices if you sign in, and keep an offline-safe copy so the app works in the gym without signal;
- Keep the Service safe and appropriate for you, including the well-being safeguards described above;
- Show you the notifications you have asked for (see Section 12);
- Provide support and respond to your messages;
- Maintain, secure, and improve the Service (fix bugs, prevent abuse, understand reliability); and
- Comply with the law and enforce our Terms.
Some coaching calculations run on your device, and some run on our own servers. When they run on our servers, the calculation is sent your training and nutrition history, your body metrics, your goal, and (for program recommendations) whether the well-being screening flagged a risk, because that is what the calculation needs in order to be safe and personal. This processing happens on our own infrastructure and is not sent to any AI provider.
We do not use your health or fitness data to profile you for advertising, and we do not make solely automated decisions that have legal or similarly significant effects on you.
8. Sensitive and health data
Most of what Kupaʻa handles (body metrics, nutrition, sleep, fasting, and well-being information) is health data, treated as special-category data under the GDPR and as sensitive personal information under laws like California’s. We handle it with extra care: we collect it only to provide the coaching you asked for, we never sell it, and we never use or share it for advertising.
Because it is special-category data, we ask for it separately rather than bundling it into these terms. During setup you get a step of its own, with a switch that starts off and that we cannot pre-tick for you; you cannot continue until you turn it on. We record which version of that wording you agreed to and when, so if we ever change what we process we ask again rather than assuming an old yes still covers it.
You can withdraw that consent at any time under You → Settings → Your data, where it appears first, because withdrawing has to be as easy as giving. Withdrawing stops the processing it authorised. We keep a dated record that the consent existed and when it ended, because a deleted record could never show when our authority to process began or stopped; that record is separate from your health data, which you can export or erase whenever you like.
If you are in Washington or Nevada, see also our Consumer Health Data Privacy Policy, which adds the specific rights those states require. It sits alongside this section and does not replace it.
9. The legal bases we rely on (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we process your information on these bases:
- Explicit consent (Article 9(2)(a)) for health and other special-category data, asked for on its own during setup rather than bundled into these terms, as described in Section 8. Separate consent also covers connecting Health Connect, the optional AI food features, and publishing to the community pantry. You can withdraw any of them at any time (this will not affect processing already carried out, and see Section 6 for the one thing that cannot be pulled back).
- Performance of a contract: to provide the Service you asked for under our Terms.
- Legitimate interests: to secure, maintain, and improve the Service, in a way that does not override your rights.
- Legal obligation: where we must process data to comply with the law.
10. Google Health Connect
Kupaʻa’s use of Health Connect data follows Google’s Health Connect permissions policy, including its limited-use requirements.
- We access only the data types you explicitly grant.
- We use that data solely to provide and personalize your coaching features, as described in this policy.
- We do not use Health Connect data for advertising or marketing, and we do not sell it or share it with third parties for their own purposes.
- We read steps, active calories, weight, and sleep. With background permission we read today’s step count while the app is closed, so widgets stay current and step-goal celebrations arrive on time.
- We write back only a strength-training exercise session when you complete a workout.
- You can review, change, or revoke Health Connect permissions at any time in your device’s Health Connect settings, and you can disconnect within Kupaʻa. Revoking access stops future reads; data already used to inform your plan can be removed by deleting the relevant entries, resetting your data, or deleting your account.
11. How your information is shared
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We share information only in these limited situations:
- Service providers (sub-processors) who run parts of the Service under contract and may only use the data to provide services to us:
- Supabase: database, authentication, file storage, and the server functions that run our coaching and food lookups;
- PowerSync: data synchronization between your device and your account;
- RevenueCat: subscription management (receives your account identifier and subscription status);
- Google Play / Google LLC: app distribution and payment processing;
- Anthropic: transient AI processing of the label photos, plate photos, and meal descriptions you choose to submit (see Section 4); not used to train models;
- Open Food Facts: receives a barcode or search text on fallback lookups (see Section 5);
- Resend: delivery of account emails such as confirming your address or resetting your password.
- Legal and safety: if required by law, regulation, legal process, or to protect the rights, safety, or property of you, us, or others.
- Business transfers: if Kupaa Labs LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will require the recipient to honor this policy or notify you of any material change.
- With your direction: for example when you export your data, import from another app, or publish a food to the community pantry.
12. Notifications
Kupaʻa’s notifications are local to your device. We have no push infrastructure: no push token is ever created, stored, or sent to us, and we cannot send you a message remotely. Notifications are scheduled on your phone from your own data, and cover the end of a fast, a step-goal celebration, your weekly check-in, and (only if you turn it on) a training-day briefing. Your notification preferences are part of your settings and are included in the backup of your app state. We do not send marketing, re-engagement, or “you have been away” notifications.
13. Your accounts, devices, and sessions
- One active device at a time. When you deliberately sign in on a device, we end your sessions on your other devices. Your data stays on those devices, but they stop syncing until you sign in again.
- Signing out. If you sign out without having synced, your data stays on that device. If a different account then signs in on the same device, we clear the previous account’s data first, so nothing leaks between people who share a phone.
14. How long we keep your information, and how to erase it
We keep your information for as long as your account is active or as needed to provide the Service.
Under You → Settings → Your data, you have two separate tools:
- Export my data produces a full JSON archive of everything Kupaʻa holds about you, or a human-readable CSV, which you can save or share wherever you like.
- Reset my data clears your logs and history but keeps your account, so you can start over. It deliberately keeps your subscription and membership.
- Delete my account and data erases your account and your records from our servers, and clears the app on your device. Our database backups are kept for 7 days, so a copy in a backup ages out within a week; those backups hold no photos. There is no undo.
If your account goes quiet, we do not keep it forever either. If you have not opened Kupaʻa for 30 months, we send a warning email; if 60 days pass after that with no sign-in, we delete the account and its data the same way as if you had asked us to. Signing in at any point, including right up to the deadline, cancels the deletion and nothing is lost.
Two things are not erased, and you should know before you rely on deletion:
- Foods you published to the community pantry, and the label photos attached to them, remain (see Section 6).
- Local safety copies and rejected sync items on your own device may persist for up to about 30 days, or until you uninstall the app or clear its storage. These never leave your device unless you send them to us in a support conversation.
If you cannot use the app, email privacy@kupaa.fit and we will complete the same export or deletion within 30 days.
15. Your rights and choices
Wherever you are, you can:
- Access and export your data as JSON or CSV from within the app;
- Correct your information by editing it in the app;
- Reset your logs while keeping your account, or delete your account and data entirely;
- Disconnect Health Connect and revoke device permissions at any time;
- Withdraw consent for optional processing, including the AI food features.
If you are in the EEA, UK, or Switzerland, you also have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to lodge a complaint with your local supervisory authority.
If you are in California, you have the right to know, access, correct, and delete your personal information, to data portability, and to limit the use of sensitive personal information. We do not sell or “share” personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights. Other U.S. states provide similar rights.
To make a request, use the in-app tools or email privacy@kupaa.fit. We may need to verify your identity before acting. You may use an authorized agent where the law allows.
16. International data transfers
Your account and your logs are stored in the European Union, in our database provider’s Ireland region. Kupaa Labs LLC is a United States company, and some of our providers (subscriptions, account email, and the AI reading described in Section 4) process data in the United States, so information about you does cross borders. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the equivalent UK and Swiss addenda, incorporated into our agreements with the providers listed in Section 11. If you would like to know where a particular part of your data is stored, ask us at privacy@kupaa.fit and we will tell you.
16a. If you are in Quebec or Brazil
Two places give you a named person to write to, so we name them.
- Quebec. Under Quebec’s private-sector privacy law, the person in charge of the protection of personal information at Kupaa Labs LLC is the founder and person exercising the highest authority in the company, reachable at privacy@kupaa.fit. Before we transfer personal information outside Quebec we assess whether it will receive adequate protection where it is going, and we keep a record of that assessment. You can also complain to the Commission d’accès à l’information du Québec.
- Brazil. Our encarregado (data protection officer) under the LGPD is Zahra Haider, reachable at privacy@kupaa.fit, in Portuguese if you prefer. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD). Where we transfer your data out of Brazil we use the standard contractual clauses approved by the ANPD, or another basis the LGPD allows.
Both of these sit alongside, and do not replace, the rights described in Section 16.
17. Children’s privacy
Kupaʻa is for people aged 16 and over, and it is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has provided us information, contact us and we will delete it.
Kupaʻa’s built-in safety screening restricts coaching by age on top of that: the more aggressive protocols, including intermittent fasting and aggressive calorie deficits, are not offered to anyone under 18, regardless of what they ask for.
If you are under the age at which you can consent to this kind of processing on your own in your country, please ask a parent or guardian to agree with you before you use Kupaʻa.
If you are younger and reading this yourself, here is the short version: everything you log stays yours. We use it only to coach you, never for anything else. We never show you ads, and we never sell what you log. Nobody else can see your logs unless you choose to publish a food to the community pantry, and even then your name is never attached to it. You can download everything or delete everything, any time, in Settings. That is the whole deal.
18. Security
We use technical and organizational measures designed to protect your information, including encryption in transit and at rest, per-user database access rules so one account cannot read another’s data, restricted internal access, and secret scanning in our build pipeline. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to any incident. Our Terms describe the limits of what we can promise about availability and security.
19. This website
This website is a static marketing site. It sets no cookies, runs no analytics, embeds no tracking pixels, and has no sign-up form. Fonts and videos are served from the site itself rather than from a third-party network, so simply reading these pages does not report your visit to anyone else.
20. Third-party services and links
The Service integrates with and links to third parties (such as the app stores and Health Connect) that have their own privacy practices. This policy does not cover those third parties; please review their policies.
21. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you through the Service or by other reasonable means and update the “Last updated” date above. We will never quietly weaken how your health data is treated.
22. Contact us, and the people who represent you to us
Kupaa Labs LLC 8 The Green, #26526 Dover, DE 19901 United States
Privacy requests: privacy@kupaa.fit Security reports: security@kupaa.fit Everything else: support@kupaa.fit
Because we are a United States company handling data about people elsewhere, several places require us to give you someone closer to home to deal with. You are welcome to use any of these, or to write to us directly at the address above. You never have to go through them.
Data protection officer · GDPR Article 37
The Data Protection Officervia privacy@kupaa.fit
Anywhere. Our DPO oversees how we handle your data and can be contacted about anything in this policy.
Representative in the EU · GDPR Article 27
Dimas JanssenTosaristraat 91019 RT AmsterdamNetherlands
The European Economic Area. You may address them instead of us on any matter about your data.
Representative in the UK · UK GDPR Article 27
Jawwad Haider133 Cowick RdLondon SW17 8LJUnited Kingdom
The United Kingdom. You may address them instead of us on any matter about your data.
Encarregado · LGPD Article 41
Zahra Haidervia privacy@kupaa.fit
Brazil. Correspondence in Portuguese is welcome.
Person in charge of personal information · Quebec Law 25
The foundervia privacy@kupaa.fit
Quebec, under its private-sector privacy law.
You can always complain to your own supervisory authority as well: in the EEA, the authority for your country; in the UK, the Information Commissioner’s Office; in Quebec, the Commission d’accès à l’information; in Brazil, the ANPD.