metrIQ is in open beta — every plan is half price for your first 6 months.

Privacy Policy

Last updated: 2026-07-24

metrIQ cares about your privacy. We've tried to write this in plain language because we believe you deserve to understand what happens with your personal information — what we collect, how we use it, how we keep it safe, and the rights you have over it.

metrIQ is operated by Z Development EE, based in Thessaloniki, Greece. We comply with the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.

1. Data controller

Z Development EE
Karakasi 24, Thessaloniki, Greece
support@metriq.fitness

We act as the data controller — we determine how your personal data is processed and we're responsible for it.

2. Information we collect

2.1 Information you provide

  • Account credentials (email, and a password if you set one)
  • Profile details (birthdate, gender, height, weight, activity level, nutrition preferences)
  • Meals, workouts, and weight measurements you log
  • Your conversations with Sophia, your AI coach
  • Saved pantry items for quick logging

2.2 Health-related data

Some of the data you provide is considered “special category” data under GDPR because it relates to your health. We process it on the basis of your explicit consent (Article 9), which you give by checking a consent box at signup, before you can create an account. You can withdraw that consent at any time by deleting your account from Settings.

2.3 Information collected automatically

  • Device information (type, operating system)
  • Usage patterns showing how and when you interact with features

We do not collect location data, your contacts, or data from other apps on your device.

3. How we use your data

3.1 Delivering the service

We use your profile and logged data to calculate personalised macro targets, generate daily reports, provide AI coaching through Sophia, and track your progress.

3.2 Improving the service

We look at aggregate usage patterns — never individual data — to find opportunities to make the app better for everyone.

3.3 Communicating with you

We may send you emails about your account, important service updates, or changes to our terms. Marketing communications require your opt-in consent, and you can opt out at any time.

3.4 Improving our AI

We may use anonymised and aggregated data to improve our AI systems. Individual data is never used to identify a specific person when improving Sophia's capabilities.

4. Legal basis for processing

Under GDPR, we rely on three legal bases:

  • Consent — for processing health data and for marketing communications (withdrawable at any time).
  • Contract — for the data necessary to provide the service once you create an account.
  • Legitimate interest— for service improvement and security, where our interests don't override your rights.

5. How we share your data

5.1 Service providers

We rely on a small number of sub-processors to run the service, each bound by a data processing agreement that requires them to protect your data and only use it for the purposes we specify:

  • Neon — our database host and authentication provider; stores your account and app data.
  • Vercel — hosts the application and provides privacy-friendly, cookieless usage and performance analytics (Vercel Web Analytics and Speed Insights), which collect only aggregated, anonymous data and no personal information.
  • Anthropic— provider of the Claude API. Your health data and chat context are sent to Anthropic to generate Sophia's AI coaching.
  • Resend — sends transactional email (account and service notifications).
  • Sentry — error monitoring; does not receive personal or health data.
  • Stripe — processes subscription billing.

These providers are based in the United States. Where your data is transferred to them, we rely on Standard Contractual Clauses and their respective data processing agreements to ensure it remains protected to EU standards.

5.2 Legal requirements

We may disclose data if required by law or court order, and we'll notify you unless we're legally prohibited from doing so.

5.3 We never sell your data

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Period.

6. How we protect your data

  • HTTPS/TLS encryption for data in transit
  • Industry-standard password hashing
  • Access controls that limit who can access your data
  • Regular reviews of our security systems

While we do our best to protect your data, no method of transmission over the internet or electronic storage is 100% secure.

7. Data retention

We keep your app data (profile, logged meals and workouts, weigh-ins, and conversations with Sophia) for as long as your account exists, and delete it immediately when you delete your account from Settings. Two narrow exceptions apply: administrative audit-log entries are retained under legitimate interest for accountability and security, and billing/tax records held by Stripe are retained for as long as the law requires. Anonymised, non-identifiable data may be kept indefinitely for statistical purposes.

8. Your rights under GDPR

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data (most of it is editable directly in the app).
  • Right to erasure — delete your account, and with it your data, at any time.
  • Right to restrict processing — limit how we use your data in certain circumstances.
  • Right to data portability — receive your data in a machine-readable format.
  • Right to object — challenge processing based on legitimate interests.
  • Right to withdraw consent — at any time (previous processing remains lawful).

Erasure is self-service and immediate: go to Settings → Delete my account and your app data is deleted right away. Access and portability requests are handled by email — write to privacy@metriq.fitnessand we'll provide a complete copy of your data within 30 days. To exercise any other right — including rectification, restriction, objection, or withdrawing consent without deleting your account — email us at privacy@metriq.fitness. You also have the right to lodge a complaint with the Hellenic Data Protection Authority at www.dpa.gr.

9. International data transfers

For any transfers outside the EEA, we ensure appropriate safeguards are in place through Standard Contractual Clauses, adequacy decisions, or other legally approved mechanisms.

10. Cookies and similar technologies

metrIQ uses only strictly-necessary cookies — authentication and session cookies that keep you signed in and the app working. We also use Sentry for error monitoring; it does not use cookies to identify you, collects no personal data, and does not use session replay. We rely on legitimate interest for this essential monitoring.

To understand how the app is used and how fast it loads, we use Vercel Web Analytics and Speed Insights. These are privacy-friendly and cookieless: they store nothing on your device, do not track you across other websites, and collect only aggregated, anonymous measurements — never personal or health data.

Because we set no analytics, advertising, or tracking cookies, and this measurement collects no personal data, there is nothing non-essential to ask your consent for — so we don't show a cookie consent banner.

11. Children's privacy

metrIQ is intended for users aged 18 and over. We do not knowingly collect information from minors without parental consent. Greek Law 4624/2019 requires parental consent for users under 15; users aged 15–18 may use the service, and we recommend they discuss it with a parent. Where we learn that we have collected a child's data without proper consent, we delete it promptly.

12. Changes to this policy

We may update this policy from time to time. For significant changes, we'll notify you in the app or by email before they take effect. The “Last updated” date at the top indicates when the policy was last revised.

13. Contact us

Z Development EE
support@metriq.fitness for general enquiries, or privacy@metriq.fitness for data access, portability, or other privacy requests
Karakasi 24, Thessaloniki, Greece