The marketing site has no advertising or product-analytics code. A local workspace remains on your device. Account mode stores the data you add in a private, owner-scoped cloud workspace. AI is optional: data is sent to Ollama Cloud only after the relevant send or Generate action. We do not sell personal data or use it for targeted advertising.
1. Scope and privacy roles
This Policy applies to the public website, mobile and Web apps, authentication, synchronization, private media, support, and the optional AI operations described below. It does not cover websites or services operated independently by another company.
Perform Loop is the operator responsible for deciding why and how Perform Loop processes personal data. Our infrastructure and AI providers process data for us under their own contractual and legal obligations.
Contact us at support@performloop.com
Public website
The source for this marketing site includes no account form, comment form, advertising SDK, marketing tracker, product-analytics SDK or non-essential cookie. Like most websites, the hosting and network providers may process request and security logs such as IP address, requested URL, timestamp, referrer, user agent, response status and abuse signals. Following the Open app link takes you to the separate application origin, app.performloop.com.
The language selector stores one first-party functional cookie containing only the selected supported language for up to one year; it is not used for tracking.
2. Personal data we collect
We receive data from you, your device, the identity provider you choose, and the service itself as it synchronizes and secures your workspace. You choose whether to add most fitness content.
| Category | Examples | When collected |
|---|---|---|
| Account and identity | Email address, email-verification state, selected sign-in provider, provider identifier, authentication and session metadata | When you register, sign in, recover or secure an account |
| Profile and preferences | Display name, fitness goal, experience level, training days, session duration, schedule preferences, IANA timezone, language and onboarding state | When you configure an account workspace |
| Training and nutrition | Personal exercises, programs, active-plan choices, diet plans, meals, nutrition estimates, meal occurrences, workout sessions and exercise outcomes | When you plan, log, edit, complete or synchronize activity |
| Measurements and health-related fitness data | Dated weight, body-fat, waist and other measurements, goals, trends and related history | Only when you enter or import it |
| Private photos and media | Meal and progress photos; capture date and angle; MIME type, dimensions, size, checksum, thumbnail and upload state | When you capture, select or upload media |
| AI inputs and results | An explicitly submitted meal photo; permitted measurements and progress photos; requested language; nutrition estimate, confidence or progress-insight report | Only when you initiate an optional AI operation |
| Device, sync and security data | Client-generated record IDs, versions, change cursors, timestamps, deletion markers, queued-operation state, bounded error codes, session and integrity metadata | As needed to authenticate, synchronize, retry, resolve conflicts and protect the service |
| Support communications | Your email, message and any diagnostic or content you choose to send us | When you contact us |
Curated exercise and plan templates are operator content, not your personal data. Device-only theme and notification authorization are not synchronized as general account preferences. We do not ask for payment-card data in the current product.
3. How and why we use personal data
We use personal data to:
- create and secure accounts, restore sessions, verify identity and respond to account requests;
- store, display, synchronize and delete the fitness content you choose to add;
- maintain owner-scoped caches, retry interrupted writes and uploads, detect stale edits, and surface conflicts rather than silently overwrite them;
- perform an AI operation you expressly initiate and return its reviewable result;
- prevent fraud, misuse and unauthorized access; diagnose failures; and maintain availability;
- respond to support, privacy and legal requests; and
- meet legal obligations and establish, exercise or defend legal claims.
Depending on where you live, our legal bases are performance of our agreement with you, your consent for optional AI processing or device permissions, our legitimate interests in operating and securing the service, and compliance with law. Where consent is the basis, you may withdraw it for future processing without affecting processing that already occurred lawfully.
4. Local mode, account mode and reconciliation
Local mode
A no-account workspace stores exercises, plans, meals, schedules, measurements, photos and preferences in application storage on your device or browser. It is not implicitly attached or uploaded to an account. Browser storage is managed by the browser and may be subject to eviction and quota limits. Your device platform may retain backups or copies according to its settings; you control those systems, not us.
Account mode
After sign-in, supported cloud data is canonical. Account records, caches, files and queued mutations are scoped to the immutable account identifier. Native devices may retain a small session secret in secure storage, account-scoped records in a local cache, bounded media caches, and durable photo sources needed to recover interrupted uploads.
Moving between them
Local and cloud libraries are not silently merged. If both sides have portable data, Perform Loop asks which side to keep and requires a machine-readable ZIP safety checkpoint before replacing the other side. The archive can include sensitive plaintext records and original media. It is user-managed and must be protected or deleted by you. The checkpoint lowers risk but does not guarantee recovery.
5. Optional AI processing and Ollama Cloud
Perform Loop does not send private fitness data to AI in the background. Administrator-configured Ollama Cloud models are called from our authenticated backend only after the action described for each feature. Provider credentials and model configuration are not included in the client app.
Meal-photo analysis
When you choose “Send for analysis” or the equivalent Save-and-send action, our backend verifies that the uploaded meal photo belongs to your account, retrieves that original from private storage, and sends the photo plus a structured nutrition prompt and your supported language to every enabled meal-analysis model. Numeric results are combined and the returned dish, serving, item, assumption, nutrition and confidence fields are stored with your meal so you can review and edit them. One request may therefore send the same photo to multiple configured models.
Progress insights
Measurements and progress photos have separate permission switches. A provider call occurs only after at least one source is enabled and you press “Generate.” The bounded evidence can include:
- up to 36 measurements, selected from recent record dates and recently updated rows;
- up to 8 progress photos, using thumbnails when available, otherwise originals, with per-image and total size limits;
- photo capture date and angle; and
- your semantic goal, experience level, training days per week, session duration and requested output language.
The progress payload excludes your name, email, account and record identifiers, check-in notes, photo notes, filenames, private object keys and signed URLs. Enabled models receive the bounded evidence to produce candidates; a successful model can receive those candidates and the same evidence again for a consensus check. The final report and source counts are saved to your account, but the report record does not store raw measurement payloads or image bytes.
Provider handling and diagnostics
Ollama’s published Privacy Policy states that Cloud prompts and responses are processed transiently, are not retained, and are not used to train models; it also describes limited server metadata such as IP address, user agent, model use, token counts, timestamps and performance metrics. Provider practices can change. Read the current provider documents before using AI features: Ollama Privacy Policy · Ollama Terms
Our AI operational journal records workload, configured model, outcome, confidence, stable failure information and timing. It has no user, account, photo, media key, private prompt or generated-result reference and is scheduled for deletion after 90 days. AI results can be incomplete, inconsistent or wrong and are not medical advice.
Disabling a progress source prevents its use in future generations. It does not recall a completed provider request or silently erase an existing report. Delete the applicable record or account if you want stored results removed, subject to the deletion details below.
6. When data is disclosed
We disclose data only as needed for the following recipients and purposes:
- Supabase provides authentication, PostgreSQL, private object storage, realtime notifications and server functions.
- Ollama Cloud receives the bounded content described above only when you initiate an AI operation.
- Google or Apple receives and returns authentication data if you choose its sign-in method, under that provider’s policy.
- Hosting, network and security providers process request and operational data needed to deliver and defend the website and service.
- Professional advisers, authorities or transaction parties may receive limited data when reasonably necessary to comply with law, protect rights and safety, or complete a lawful business reorganization subject to appropriate safeguards.
Provider documents: Supabase Privacy Policy · Supabase Data Processing Addendum
We do not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. The current product contains no advertising SDK and no general product-analytics SDK. Catalog administrators can manage public content and AI configuration but are not granted access to private user records or photos.
7. Retention and deletion
- Local workspace: remains in the device or browser storage until you remove it, clear that storage, uninstall, reset, or the platform evicts it.
- Account data: live records and deletion markers remain while the account is active as needed to provide synchronization, history and explicit conflict handling.
- Private media: remains until its record is deleted or the account is deleted; cleanup is retryable so interrupted object deletion can finish.
- AI reports and meal estimates: remain with their account records until removed through the available record or account controls. Revoking future permission alone does not erase an existing result.
- Anonymous AI operational diagnostics: are scheduled to be purged after 90 days.
- Deletion-operation receipt: the completed, content-free operation receipt expires after 24 hours. A pending operation remains until cleanup succeeds so writes stay frozen.
- Support and security records: remain only as long as reasonably needed for the request, abuse prevention, disputes and legal obligations.
In-app account deletion freezes new account-cache writes, removes the private account graph and objects, and then removes the authentication user. If the response is interrupted, the operation is designed to resume. Provider backups may retain restricted copies for a limited restoration or legal period before aging out; they are not restored as an active user account. Records may also be retained where law requires it or as necessary to establish, exercise or defend claims.
Account deletion does not delete local-only workspaces, device/browser copies, ZIP exports you control, or copies previously shared outside Perform Loop. See: Delete an account
8. Security
Safeguards include owner-scoped database policies, private object storage, authenticated server functions, account-scoped caches and mutation queues, small-session-secret secure storage on supported platforms, upload integrity metadata, administrative access controls, deletion write fences, and HTTPS in production. Access rules are tested using separate users.
No safeguard, device, transmission, provider, backup or storage system is completely secure or guaranteed to preserve data. Protect your devices and credentials, keep independent copies of important records, and contact us if you suspect unauthorized access.
9. Your choices and privacy rights
You can:
- use local mode without creating an account;
- edit profile, preferences and fitness records through the app;
- decline meal-photo analysis and independently disable each progress-insight source;
- download and protect a reconciliation backup when the app offers one;
- sign out locally or globally and delete your account; and
- contact us to request access, correction, deletion, portability, restriction or objection, or to withdraw consent, where your law provides those rights.
We may need to verify your identity and clarify the request. We will respond within the period required by applicable law and will explain if an exemption applies. Authorized agents must provide proof of authority. You may also complain to your local data-protection or consumer-protection authority. We will not discriminate against you for exercising a privacy right.
U.S. state privacy notice
The categories collected and business purposes are listed in Sections 2 and 3; recipient categories are in Section 6. We do not sell or share personal data for cross-context behavioral advertising. We use health-related fitness data and account credentials only to provide, secure and support the service as described here, not to infer traits for advertising. Where state law provides an appeal right, reply to our decision or email us with “Privacy appeal” in the subject line.
10. International processing
Perform Loop and its providers may process data in countries other than the one where you live. Those countries may have different data protection laws. Where required, we rely on contractual protections, adequacy decisions, consent or another lawful transfer mechanism. Provider locations and subprocessors can change; the linked provider notices contain current details.
11. Age limits and sensitive fitness data
Perform Loop is for adults 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided data, contact us so we can investigate and delete it.
Measurements, meal records and progress photos may be treated as health or sensitive data under some laws. Perform Loop is offered as a direct-to-consumer fitness tool and is not intended to receive protected health information on behalf of a healthcare provider or health plan. Do not assume healthcare-specific confidentiality laws such as HIPAA apply. Do not upload another person’s sensitive data without their informed permission.
12. Changes and contact
We may update this Policy when the product, providers or law changes. We will post the revised policy, update its effective date, and give additional notice or request consent when required. Materially new AI data uses require an updated disclosure and appropriate user choice.
Privacy questions or requests: support@performloop.com