Legal
Privacy Policy
Last updated September 30, 2026
This policy explains what Holdfast collects, why, who it goes to, and the choices and rights you have. Holdfast is a nutrition and meal plan adherence app. It is a general wellness product, not a medical service.
The short version
- We never sell your personal, health, or nutrition data, and we never use it for advertising. There are no advertising or tracking tools in the app.
- Some features send what you write, photograph, or eat to an AI provider in the United States, along with a summary of your profile, your plan, and findings computed from your logged days. Those features are the coach, plan import, food photos, meal text matching, and the grocery list. Meal swaps, Fix My Day, and restaurant guidance do not use AI at all.
- AI is optional and separate from accepting these documents. You choose it during onboarding, it is off unless you turn it on, and you can turn it on or off at any time in the You tab, under AI features. With it off, nothing goes to an AI provider, and the rest of Holdfast works as usual.
- The Eating out map asks for your location and sends your coordinates to a public map data service. It does not send them to us, and we do not store them.
- You can export everything we hold, and permanently delete your account, from inside the app.
1 Who we are
Holdfast ("Holdfast", "we", "us", and "our") is operated from Ontario, Canada. We are responsible for the personal information handled through the Holdfast app and its backend service, and we remain accountable for information we pass to the service providers described below.
Privacy questions, requests to exercise the rights described below, and anything else about this policy go to holdfastappsupport@gmail.com.
2 What this policy covers
This policy covers the Holdfast iOS app, the backend service that supports it, and our public website. It does not cover the separate services we integrate with, such as Apple and Google, which have their own privacy policies. It applies to everyone who uses Holdfast. Canada's PIPEDA is our primary framework, and we also honor the rights of users in the European Union, the United Kingdom, and applicable US states, as set out under Your rights and choices.
3 Information we collect
We collect only what we need to run the app and provide the features you use.
Account and identity
- Holdfast creates an anonymous account for your device on first launch, so there is no sign up step. That account is identified by a secret stored in your device keychain, and we store only a one way hash of it.
- Your email address, when you attach a sign in method. If you sign in by email we send a one time code to that address, and we hold the code until it expires or is used.
- A sign in identifier from Sign in with Apple or Google Sign In, if you attach one.
Profile you provide
- Optional name, your birthday and age, sex assigned at birth, height, current weight, goal weight, activity level, training days, goal and chosen pace, units, meals per day, and eating window.
- Gender identity, including anything you type into the self described field, and whether you are on hormone therapy. Sex assigned at birth and hormone therapy are inputs to the equation that estimates your energy needs. Gender identity is used so the app addresses you correctly.
- Food allergens you select and anything you type in the allergen notes, and dietary patterns you follow, which include halal and kosher. We know these can reveal a medical constraint or a religious practice, and we treat them as sensitive.
- Foods you like, foods you would rather skip, and any other food notes you write.
- Who your plan came from, such as a coach, a dietitian, or a gym, and how it reached you.
- How closely you want to track, when your day starts, and answers to setup questions such as which meal you find hardest.
Health and nutrition data
- Meal plans you import as photos or PDFs. The file itself is not stored, but the text and structure the AI reads out of it are, including any coach notes and supplements it contains.
- The foods and check ins you log, your macros and calories, adherence scores, water intake, your weight over time, and streaks.
- What you ask the in app coach and what it answers, kept as a conversation.
- Foods you create yourself, including what you cooked and what went into it.
- If Apple Health is ever enabled and you connect it, body weight, activity or energy, and nutrition. See Apple Health below.
Location
- If you open the Eating out map and allow it, your latitude and longitude, used to find food places near you. See Location and the Eating out map for exactly where it goes and how precise it is.
- Your device time zone, so reminders arrive at the right hour where you are.
Notifications, usage, and technical data
- If you enable reminders, a push token and your device time zone.
- Product usage events, recorded against your account. Some are plain milestones, such as when a plan is imported or a paywall is viewed. Others carry a small amount of content or of your own answers, for example the name of a food you asked to swap, whether you were still hungry after a meal, whether you had a rough night, how many days you had been away when you came back, and how much you ate on a day the app asked you about. Every event also records your subscription status and, if you arrived through a coach referral code, that code.
- Crash and error reports when the app fails, including the error message, the stack, where in the app it happened, and technical details the app attaches. These are linked to the account that was signed in at the time. Sign in tokens and anything shaped like a password or an API key are stripped out before they are stored, and nothing else is.
- Your device IP address, which reaches our server with every request as it does with any internet service. We use it to rate limit abuse, and our hosting provider records it in the server request log. We do not keep it on your account record.
- Your subscription and entitlement status. We never receive or store your card number.
- If you use a referral code, the code you used and the code issued to you.
- Install measurement data, through AppsFlyer, so we can tell which of our own links and promotions led to an install. When the app is installed and opened, AppsFlyer receives a random install identifier it creates, Apple's identifier for vendor (an identifier shared only by apps from the same developer), your IP address, basic device details such as model, iOS version, language and app version, and when the app was installed and opened. It never receives the advertising identifier, your Holdfast account id, or any of your health, nutrition, or plan data.
If you also hold a coach account
- The email address and name you apply with, a referral code we issue you, your revenue share percentage, and the list of clients who have chosen to share their adherence with you. This is separate from your own user account, and the Your rights and choices section explains what that means when you delete.
4 How we use your information
- To create and secure your account and sign you in.
- To build and maintain your plan, logs, macros, targets, and progress.
- To power the AI coach chat, grocery lists, and plan and food photo analysis. These are the features that send your information to an AI provider.
- To compute meal swaps, Fix My Day plans, and restaurant guidance. These do not use AI. They rank a bundled list of foods against what your plan has left, on our server or on your device, and nothing is sent to an AI provider for them.
- To run streaks and rewards.
- To send the reminders and notifications you turn on. To decide which one to send, our server checks each hour when you last logged, how many days you have logged this week, and how many days you have logged in total. This runs only for accounts that have notifications switched on.
- To operate your subscription and confirm your entitlement.
- To measure and improve reliability and the experience, through our own product analytics and crash reports.
- To measure which of our own links and promotions bring people to Holdfast, through AppsFlyer, so we know which ones work.
- To keep the service safe, debug problems, and comply with the law.
We do not use your information for advertising, and we do not sell it.
If we ever want to use your information for a new purpose, we will ask for your consent first.
5 Our legal bases and your consent
Under PIPEDA we rely on your consent. You give it on the consent step during onboarding, and through the operating system prompts for notifications, camera, photos, and location.
We want to be exact about what that step does, because it matters. It holds two separate agreements. The first is required to use Holdfast: that you understand it is a wellness tool and not medical advice, and that you accept these Terms and this Privacy Policy. The second is optional and covers AI processing, which is your information being sent to our AI provider. You can accept the Terms and decline the AI. Neither box is pre ticked, declining the AI is one choice and not a separate flow, continuing is not blocked by it, and the date you agreed to each is recorded separately.
AI consent is also reversible from inside the app, at any time, in the You tab, under AI features. Turning it off takes effect immediately, and what happens then is described under Sensitive data and under Our AI features and what we send.
Two things happen before you reach that step, and we would rather say so. Holdfast creates the anonymous device account when the app first opens, and it records that first open and each app open as usage events. So an account and a small number of events exist by the time you are asked. Nothing is sent to an AI provider before you agree, and deleting your account removes all of it.
For users in the European Union and United Kingdom, our legal bases under the GDPR and UK GDPR are:
- Performance of our contract with you, to run your account and sync your plan and logs.
- Your consent, for health and nutrition data, for AI processing, and for push reminders.
- Our legitimate interests, for product analytics, install measurement, crash reports, security, and technical logs, balanced against your rights. We do not rely on legitimate interests for health data.
- Legal obligations, for billing, tax, and fraud prevention records.
6 Sensitive data
We treat your meal plans, food and weight logs, adherence scores, allergens, dietary patterns, gender identity, hormone therapy answer, and any Apple Health data as sensitive personal information under PIPEDA, special category data under the GDPR and UK GDPR, sensitive personal information under California law, and consumer health data under Washington, Nevada, and Connecticut law.
These fields are collected through the ordinary onboarding questions, on the same consent as the rest of the app, and not behind a separate health specific checkbox. We are saying so rather than implying otherwise. Sending them to an AI provider is a separate matter, and it has its own consent, which you can decline at the start and withdraw at any time.
To withdraw AI consent, turn it off in the app: You tab, then AI features. It takes effect immediately, no restart, and the app keeps working without it. We then delete the AI output we hold for your account: your coach replies, the stored results of plan and food photo readings, and the raw model response kept beside your plan. Your plan, your logs, your weigh ins and the rest of your history are yours and are kept.
What we cannot do is recall a request that has already been sent to a provider. We can delete what we hold, and we do. We say so here rather than let "we deleted it" imply something wider.
To withdraw your consent to the rest of the processing described here, delete your account in the app, which erases the data described under Your rights and choices, or write to holdfastappsupport@gmail.com and we will action it.
7 Apple Health
Apple Health is not enabled in the current version of Holdfast. The integration is built but switched off, so nothing is read from or written to Apple Health. You may still see Apple Health permission text listed in the app on the App Store, because that text ships with the build.
8 Our AI features and what we send
Several features rely on AI. To provide them we send the relevant content to a provider that processes it on our behalf and returns a result to you. Our API keys stay on our server, and your device never talks to an AI provider directly.
What goes to Anthropic (Claude)
- The content itself: your coach chat messages, the plan photos or PDFs you import, food photos you take for analysis, and meal descriptions you type.
- A summary of your profile, sent with almost every one of those requests. It contains your name if you set one, your age, sex assigned at birth, height, current weight, gender identity or the words you used to describe it, your goal, goal weight and pace, activity level, training days, meals per day, eating window, your units, your computed maintenance and target calories, your allergens and allergen notes, the dietary patterns you follow including halal and kosher, your food likes and dislikes, and any other food notes you wrote.
- Your confirmed plan, on every coach question: its daily calorie, protein, carbohydrate, fat and fibre targets, the name of every meal in it, and the name of every supplement in it.
- How today is going, on every coach question: what you have eaten so far against the target for that day, stated in the direction it actually went, including when you are over.
- Findings computed from your logged days, on every coach question. Our server reads up to the last eight weeks of your daily summaries and up to the last sixteen weeks of your weigh ins, and sends a short set of sentences drawn from them: whether your days have been landing over, under, or on plan and by roughly how much, which one meal keeps going unlogged and on how many days, how many days you tracked in the last 28 and how that compares to the 28 before it, and which way your weigh ins are trending and how fast. The underlying daily rows and individual weigh in readings are not sent, only those sentences.
- Your hormone therapy answer is not sent. It is used only inside our own energy calculation.
We send the profile summary because a suggestion that ignores an allergy or a diet is worse than no suggestion, and we send the plan and the history because a coach that cannot see your week gives generic answers. It is a large amount of information about you, so we would rather list it than call it "minimal context".
The image generation provider, which the app does not currently call
Our server has a route that asks fal.ai for an illustrative picture of a food, sending a food name and nothing else. No screen in the current version of the app requests one, so in practice nothing is sent to fal.ai today. We list it because the route exists and could be switched on. If it were, and fal.ai did not answer, the app would fall back to a placeholder image from placehold.co, which would receive the same food name and your device IP address.
Consent, and what happens without it
Every one of the features above checks your AI consent before anything is sent, including the grocery list, which used to be the exception. With AI consent off, no request is made to an AI provider for your account and no profile summary leaves our server, whichever feature you open.
They do not all refuse. Reading a plan from a photo or a PDF, reading a meal from a photo, and reading a meal you type in words genuinely need a model, so those three tell you so and offer the ways of logging that do not. The coach still answers, worked out from your plan and your logged day on our server rather than by a model. The grocery list is still built from your plan. Meal swaps, Fix My Day and restaurant guidance never used AI at all.
AI output is an estimate and may be incomplete or wrong. Review it before you rely on it, and please do not submit content you would not want processed in order to provide the feature. Holdfast makes no automated decision about your credit, employment, insurance, housing, or anything else of that kind. It calculates nutrition targets and makes suggestions, and you decide what to do with them.
We do not control how an AI provider retains what we send, beyond the contract we have with them, and we cannot promise deletion on their systems. See How long we keep it.
9 Location and the Eating out map
The Eating out screen shows food places near you. It is optional, and nothing happens until you open it and allow location access at the iOS prompt.
- When you allow it, the app asks iOS for your position at balanced accuracy rather than the highest available, which is around a hundred metres. What comes back is still a latitude and longitude, which is why the App Store listing declares precise location. If a fresh fix takes too long, which happens indoors, the app falls back to the last position iOS already had, of unknown age.
- Your device then sends those coordinates directly to a public Overpass API server, which searches OpenStreetMap data for food places nearby. The request goes to one of overpass-api.de, overpass.kumi.systems, or overpass.private.coffee. These are free, community run servers we do not operate and whose location we do not control, so this is a transfer outside Canada.
- That request identifies the app and our support address in its User Agent header, and the server sees your device IP address as any web request would.
- Map tiles are drawn by Apple Maps, which sees the part of the map you are looking at. We do not use Google Maps.
- Your coordinates are never sent to Holdfast servers and are never stored. They live in memory while the screen is open. A cache on your device holds the results for five minutes so that switching tabs does not send the same question again, and that cache is filed under a rounded version of your position, accurate to roughly a hundred metres. The rounding is what makes the cache reusable, and is not a limit on what the map server receives.
- Holdfast does not use geofencing, does not track your location in the background, and does not build a location history.
You can refuse location access, or withdraw it later in the iOS Settings app, and the rest of Holdfast works exactly as before. Restaurant guidance falls back to a curated list.
10 Widgets, Siri, and Shortcuts
These features put your nutrition figures where you can reach them without opening the app. Everything they do happens on your device, and none of it sends anything to us or to anyone else. We describe them here because they take health information out of the app and put it somewhere more visible, which is worth knowing before you add one.
- If you add a Holdfast widget, the app copies today's figures into a storage area shared with it: calories and macros eaten and remaining, protein left, water, your weekly progress, and the name and time of your next planned meal. That area sits outside the app's own storage, on your device.
- A widget on the Lock Screen shows those figures without your phone being unlocked, so anyone who can see your screen can see them. Removing the widget stops it.
- The widget's log button records a note in that shared area, and the app applies it to your day the next time you open it.
- The Siri and Shortcuts actions read a small file inside the app's own storage that holds the same figures written out as sentences, such as how many calories and how much protein you have left and what your next meal is. It is rewritten whenever your day changes.
- Siri can read those sentences out loud, and running the action goes through Apple in the same way as any other Siri request. Our servers are not involved, and the action works with the app closed.
- Deleting your account empties both, because the app immediately rewrites them from an account with nothing in it. Deleting the app removes them outright. There is nothing for us to erase on our side either way, because none of it was ever sent to us.
11 Who else your information reaches
Most of the companies below handle information in order to run Holdfast for us, rather than for purposes of their own. We receive nothing of value in exchange, which is why we do not treat it as selling or sharing your information. Several of them operate outside Canada, which Where your data is processed explains. The one recipient that is not a service provider is a human coach, and it is listed here because you would want to know.
Your coach, only if you connect one
Your coach, only if you connect one. Holdfast lets you share your adherence with a coach by entering their code. This is off by default, it is never enabled for you, and you can turn it off at any moment in the app, which stops all access immediately. While it is on, that coach can see:
- Your adherence score for the last 7 days, and whether it is rising or falling
- How often you hit your protein target over those 7 days
- How many of those days you logged, and the last day you logged one
- The name on your account, if you set one
- Which macros your plan is scored on, so the number can be read correctly
- The date you turned sharing on
Your coach cannot see:
- Individual meals, foods or photos
- Your email address
- Anything you say to the in-app coach
- Your weight, measurements or body photos
The app shows you this same list before you connect, and it is the authoritative description of what is shared. A coach is a person, not a processor, which is why they are named separately here.
We may also disclose information if required by law, or in connection with a merger or sale of the business, in which case we will let you know.
12 We do not sell your data or run ads
We do not sell your personal information, and we do not share it for cross context behavioral advertising. We never sell your health or nutrition data, we never disclose it to data brokers, and we never use it for ad targeting. There is no advertising software and no third party tracking software in the app. The one outside measurement tool is AppsFlyer, which we use only to count which of our own links and promotions lead to installs. It runs in a mode that cannot read the advertising identifier, it never receives your health or nutrition data, and it does not track you across other companies' apps or websites. Apart from that, our product analytics are our own, and the data stays in our own database and logs.
13 Where your data is processed
We may process and store information in the United States and in other locations where we or our service providers operate. Your information may therefore be transferred across borders and processed in jurisdictions that have different data protection laws from your own. Separately, if you use the Eating out map, your coordinates go from your device to a community run map server whose location we do not control.
While your information is in another country it is subject to that country's laws, and may be accessed by its courts, law enforcement, and national security authorities. Each provider handles it under the terms of service and data processing terms that provider publishes, which we accept when we use them. We name no other transfer mechanism, because none has been separately negotiated, and we would rather tell you that than list something impressive we have not signed.
14 How long we keep it
Your account, profile, plans, food logs, daily summaries, weigh ins, coach conversations, saved foods, grocery list, records of the AI jobs you ran, your registered devices, your free feature allowance counters, and your subscription record are kept for as long as your account exists. They are not aged out, because your own history is the point of the app. Deleting your account deletes them.
Everything with a fixed lifetime, in full:
- Product usage events: 400 days.
- Crash and error reports: 90 days after the last time that error was seen. If the same error happens again the clock restarts.
- Records of notifications sent: 3 days.
- AI spending counters: 48 hours.
- Water sync records: 30 days.
- Sign in sessions: replaced every time you use the app, and removed when you sign out or delete your account.
- The replacement sign in token described under How we protect your data: about a minute.
- One time sign in codes: they stop working within minutes, and the record is replaced by your next code or removed when you delete your account.
- Administrative audit records, which log a staff change to an account: kept indefinitely and on purpose, so a change to your data can be traced back to who made it.
- Meal plan photos and PDFs you import: never stored. The file is read once and discarded, and only the extracted plan is kept.
- Meal photos you take: never stored. The image is stripped before your log entry reaches our server, and so is the file path it had on your device.
Billing and receipt records held by Apple and RevenueCat are governed by their own retention, not ours. We do not operate a backup schedule of our own, so we make no promise about one.
15 Keeping your data accurate
You can review and edit your profile, goals, weight, and logs directly in the app. If something is not editable in the app and you would like it corrected, contact us at holdfastappsupport@gmail.com.
16 How we protect your data
We use administrative and technical safeguards proportionate to the sensitivity of health data. Concretely:
- All traffic between the app and our servers uses HTTPS, and the app refuses plain text connections to anything on the public internet. It still permits them to an address on the local network, which exists so a development build can reach a server on the same Wi-Fi, and which nothing on the App Store version uses.
- Your sign in tokens are held in the iOS keychain, never in ordinary app storage. On our side a session token is stored as a hash rather than as itself, it is replaced every time it is used, and reusing an old one revokes the whole chain. The one exception is a replacement token we hold for about a minute, so a request that lost its answer can be retried safely.
- Your device secret is stored only as a one way hash, in a separate collection from your account, so it cannot leak through an ordinary account response.
- Sign in tokens, and anything shaped like a password or an API key in a web address, are stripped out of our logs and out of crash reports before they are stored.
- Our AI provider keys never leave our server.
- Administrative access to accounts is limited to designated staff. We would rather describe it accurately than leave it sounding narrower than it is: through that console, staff can read your account, including your profile, your plans, your food log, and your coach conversations, and can change or delete them.
- A change or a deletion made that way writes an audit record holding a copy of the record as it was and as it became. The record is written once the change has actually completed, so it can never attest to something that did not finish, and if the audit write itself fails the failure is logged rather than the change being undone. Reading is not itself recorded, apart from exporting an account, which is.
We are not claiming more than that. We do not run our own encryption of stored data, so any protection of data at rest is whatever our hosting and database providers apply by default. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
17 Your rights and choices
Depending on where you live, you have some or all of the rights below. To exercise them, use the in app controls, or email holdfastappsupport@gmail.com. We may need to verify your identity, and we will not discriminate against you for exercising your rights.
In the app, without asking us
- Export. You tab, then Personal details, then My data. You can take a readable record of your history, or the whole account as a JSON file.
- Delete. You tab, then Personal details, then Delete account. This is permanent, and the app only clears itself once the server confirms the deletion actually happened.
- Correct. Edit your profile, goals, weight, and logs directly.
- Turn AI processing off, and on again. You tab, then AI features. It takes effect immediately, we delete the AI output we hold for your account, and the rest of the app carries on. You do not have to delete your account to stop the AI processing described in this policy.
- Notifications. Turn reminders off entirely, pause them, or set quiet hours.
- Signing out, or clearing data under My data, only clears that device. It does not delete your account from our servers.
What deleting your account removes, and what it does not
Deleting removes your account record, profile, plans, food logs, daily summaries, weigh ins, water records, coach conversations, AI job records, saved foods, grocery list, subscription record, sessions and the replacement token described above, devices, usage events, free allowance counters, AI spending counters, the record of which notifications you were sent, your sign in code, and it removes you from any coach roster you were on.
To be straight with you about the rest. Our administrative audit records, which capture a before and after copy whenever a staff member edits or deletes an account, are kept and are not erased by account deletion. Crash reports are grouped by fault rather than by person, so the report survives with your account id removed from it, and it ages out on its own after 90 days. What stays in that report is the error message, the stack, and whatever technical detail the app attached, none of which is scrubbed beyond the sign in tokens and password shaped values described above, so if something you typed made it into an error message it stays for those 90 days. Server logs holding your account id and IP address age out on our hosting provider's schedule. We do not send deletion requests to our AI, email, or push providers, and disconnecting your subscription identity at RevenueCat detaches it rather than erasing their record. Anything we cannot delete ourselves, we will not claim to.
Two smaller cases. If you also hold a coach account, that coach record is separate from your user account and deleting the app account does not remove it. If you referred somebody else, the record of that referral is kept so their credit still makes sense. Write to holdfastappsupport@gmail.com and we will remove either one by hand.
Canada (PIPEDA)
- Access the information we hold and an account of how it is used and disclosed, request correction, and request deletion. We respond within a reasonable time, generally 30 days.
European Union and United Kingdom (GDPR)
- Access, rectification, erasure, restriction, portability, objection including to legitimate interests processing, and withdrawal of consent at any time. We respond within one month.
United States (California and others)
- Know and access, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. We do not sell your personal information and we do not share it for cross context behavioral advertising, so there is nothing to opt out of. We respond within 45 days, and may extend where allowed.
You can also complain to a regulator: the Office of the Privacy Commissioner of Canada, the UK Information Commissioner's Office, or your local European data protection authority. We would rather hear from you first, at holdfastappsupport@gmail.com, so we can put it right.
18 Children
Holdfast is not directed to, and may not be used by, anyone under 18. We do not knowingly collect information from anyone under that age, and we will delete it if we learn we have. We ask for your birthday to calculate nutrition targets. The birthday picker in the app does not offer a date less than 18 years ago, and our servers refuse an age or a birthday below that as well. Neither of those is age verification: we have no way to confirm the birthday you give us is really yours.
19 Data breaches
We will keep a record of any security breach. Where a breach creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify the people affected as soon as feasible. Holdfast holds identifiable health information that you enter, and health apps holding that kind of information can fall under the US FTC Health Breach Notification Rule. Whether it applies to us has not been assessed by a lawyer. If a breach of unsecured health information occurs, we will notify affected users without unreasonable delay and no later than 60 days, and we will notify the Federal Trade Commission and the media where that rule requires it.
20 Not medical advice
Holdfast, including the AI coach, meal swaps, and Fix My Day, provides general nutrition and wellness information only. It is not medical, nutritional, or dietetic advice, and it does not create a professional relationship. Consult a qualified professional for medical or dietary decisions. Holdfast is a consumer wellness app. We are not a health care provider, an insurer, or a health plan, and we do not handle information on behalf of one, so we do not believe HIPAA or Ontario's PHIPA applies to Holdfast. That has not been confirmed by a lawyer. Either way, we protect your data as described here.
21 Changes to this policy
We may update this policy. It stays available in the app and on our website in plain language, with a last updated date. If we make a material change, we will let you know, and your continued use after the change means you accept the updated policy.
22 Contact us
Privacy questions, requests to exercise your rights, and general support all go to one address: holdfastappsupport@gmail.com.