Data
Privacy
FitBuddy is designed so your food log and API keys live on your phone. Network calls only happen for features you use. There is no FitBuddy account.
Stored on your device
- Profile, body readings, daily targets
- Food and exercise logs, meal presets, saved foods
- AI provider choice, API keys / OpenRouter token, model preferences
- Reminder schedule
- Optional local JSON backups (optionally password-encrypted)
- Anonymous Support ID (not your name or email)
Uninstalling removes local data unless you kept an export or cloud backup under your Support ID.
Sent to your AI provider
When you analyze a meal photo or text, estimate workout calories, use Progress Coach, or request optional AI-assisted target selection, FitBuddy sends only the content needed for that feature to the provider you configured. This can include meal photos or descriptions, relevant profile details, and compressed progress metrics.
A target-selection request can include age, sex, height, current weight, selected activity, goal, current calorie and protein targets, aggregated workout/body/nutrition evidence, and each complete locally calculated candidate (ID, calories, macros, target weight, recommended activity, and adjustment). Raw body-reading rows and full food-log history are not included in that request.
Target arithmetic, safety bounds, and candidate numbers are always calculated on-device. A configured provider may select only one exact local candidate ID and add a short coaching note; it cannot supply or edit target numbers. See the calculation and AI boundary.
Choose a provider you trust — their retention rules apply. Prefer local Ollama if you want analysis on your network. FitBuddy does not upload your full history to a FitBuddy app server — there isn’t one.
Optional personal cloud backup
When enabled, FitBuddy can upload gzip-compressed, AES-256-GCM encrypted backups keyed by your Support ID. Encryption happens on-device before upload. Off by default. Details: Encryption.
Other network use
- OpenRouter OAuth — browser sign-in when you choose it
- Open Food Facts — barcode product lookup (decode is on-device)
- GitHub — release / update checks; APK opens in your browser
Optional crash reports (Sentry)
If enabled, anonymous crash/ANR data may be sent to help fix bugs. Not sent: meals, photos, API keys, freeform food text. Opt out anytime in Settings. Share your Support ID when asking for help.
Permissions (typical)
- Camera — food photos and barcodes
- Photos / media — gallery pick
- Notifications & alarms — optional daily reminder
- Internet — AI, barcode lookup, updates, optional cloud / crash reports
FitBuddy is GPL-3.0 — inspect the code.