Privacy Policy

Last updated: 2026-08-27

metrIQ cares about your privacy. We've tried to write this in plain language because we believe you deserve to understand what happens with your personal information — what we collect, how we use it, how we keep it safe, and the rights you have over it.

metrIQ is operated by Z Development EE, based in Thessaloniki, Greece. We comply with the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.

1. Data controller

Z Development EE
Karakasi 24, Thessaloniki, Greece
support@metriq.fitness

We act as the data controller — we determine how your personal data is processed and we're responsible for it.

2. Information we collect

2.1 Information you provide

  • Account credentials (email, and a password if you set one)
  • Profile details (birthdate, gender, height, weight, activity level, nutrition preferences)
  • Meals, workouts, and weight measurements you log
  • Your conversations with Sophia, your AI coach
  • Saved foods and meals for quick logging

2.2 Health-related data

Some of the data you provide is considered “special category” data under GDPR because it relates to your health. We process it on the basis of your explicit consent (Article 9), which you give by checking a consent box at signup, before you can create an account. You can withdraw that consent at any time by deleting your account from the You tab.

2.3 Information collected automatically

  • Device information (type, operating system)
  • Usage patterns showing how and when you interact with features

We do not collect location data, your contacts, or data from other apps on your device.

3. How we use your data

3.1 Delivering the service

We use your profile and logged data to calculate personalised macro targets, generate daily reports, provide AI coaching through Sophia, and track your progress.

3.2 Improving the service

We look at aggregate usage patterns — never individual data — to find opportunities to make the app better for everyone.

3.3 Communicating with you

We may send you emails about your account, important service updates, or changes to our terms. Marketing communications require your opt-in consent, and you can opt out at any time.

3.4 Improving our AI

We may use anonymised and aggregated data to improve our AI systems. Individual data is never used to identify a specific person when improving Sophia's capabilities.

4. Legal basis for processing

Under GDPR, we rely on three legal bases:

  • Consent — for processing health data and for marketing communications (withdrawable at any time).
  • Contract — for the data necessary to provide the service once you create an account.
  • Legitimate interest— for service improvement and security, where our interests don't override your rights.

5. How we share your data

5.1 Service providers

We rely on a small number of sub-processors to run the service, each bound by a data processing agreement that requires them to protect your data and only use it for the purposes we specify:

  • Neon — our database host and authentication provider; stores your account and app data.
  • Vercel — hosts the application and provides cookieless usage and performance analytics (Vercel Web Analytics and Speed Insights), across the whole site including signed-in screens. They record which page was loaded and how fast, never what you logged, and store nothing on your device. To tell repeat visits apart within a day, Web Analytics derives a temporary hash from the request itself and discards it after 24 hours; Speed Insights uses no identifier at all. See section 10.
  • Google— Google Analytics, on our public marketing pages only. It never runs on the app's own screens, so it never receives your health data. It only runs at all if you agree to it, and you can change your mind at any time from “Cookie choices” in the footer.
  • Anthropic— provider of the Claude API. Your health data and chat context are sent to Anthropic to generate Sophia's AI coaching.
  • ElevenLabs — provides speech-to-text for voice input. Your voice audio, and the language you told us you speak, are sent to them when you use the microphone.
  • Resend — sends transactional email (account and service notifications).
  • Sentry — error and performance monitoring, across the whole site including signed-in screens. It receives the error itself, the screen or route it happened on, and — while you are signed in — your account identifier, so a fault can be traced back to the report. The diagnostic detail attached to a failure can occasionally describe what was being processed, such as the name of a meal whose calculated calories did not add up. It sets no cookie, records no session replay, and never receives your name, your email, or your IP address.
  • Stripe — processes subscription billing.

These providers are based in the United States. Where your data is transferred to them, we rely on Standard Contractual Clauses and their respective data processing agreements to ensure it remains protected to EU standards.

5.2 Legal requirements

We may disclose data if required by law or court order, and we'll notify you unless we're legally prohibited from doing so.

5.3 We never sell your data

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Period.

6. How we protect your data

  • HTTPS/TLS encryption for data in transit
  • Industry-standard password hashing
  • Access controls that limit who can access your data
  • Regular reviews of our security systems

While we do our best to protect your data, no method of transmission over the internet or electronic storage is 100% secure.

7. Data retention

We keep your app data (profile, logged meals and workouts, weigh-ins, and conversations with Sophia) for as long as your account exists, and delete it immediately when you delete your account from the You tab. Two narrow exceptions apply: administrative audit-log entries are retained under legitimate interest for accountability and security, and billing/tax records held by Stripe are retained for as long as the law requires. Anonymised, non-identifiable data may be kept indefinitely for statistical purposes.

8. Your rights under GDPR

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data (most of it is editable directly in the app).
  • Right to erasure — delete your account, and with it your data, at any time.
  • Right to restrict processing — limit how we use your data in certain circumstances.
  • Right to data portability — receive your data in a machine-readable format.
  • Right to object — challenge processing based on legitimate interests.
  • Right to withdraw consent — at any time (previous processing remains lawful).

Erasure is self-service and immediate: go to You → Delete my account and your app data is deleted right away. Access and portability requests are handled by email — write to privacy@metriq.fitnessand we'll provide a complete copy of your data within 30 days. To exercise any other right — including rectification, restriction, objection, or withdrawing consent without deleting your account — email us at privacy@metriq.fitness. You also have the right to lodge a complaint with the Hellenic Data Protection Authority at www.dpa.gr.

If you are in the United States — Washington, Nevada and Connecticut in particular — your health data carries its own separate rights and its own policy. See Your Health Data.

9. International data transfers

For any transfers outside the EEA, we ensure appropriate safeguards are in place through Standard Contractual Clauses, adequacy decisions, or other legally approved mechanisms.

10. Cookies and similar technologies

metrIQ always sets strictly-necessary cookies — authentication and session cookies that keep you signed in and the app working — and, only if you agree to it, the cookies Google Analytics sets on our public pages. There are no others. We also use Sentry for error and performance monitoring; it sets no cookie, uses no session replay, and never receives your name, your email, or your IP address — but it does receive the account identifier of a signed-in session along with the screen an error or a slow request happened on (see section 5.1). We rely on legitimate interest for this essential monitoring.

To understand how the app is used and how fast it loads, we use Vercel Web Analytics and Speed Insights. Neither sets a cookie, stores anything on your device, or tracks you across other websites, and both collect only aggregated, anonymous measurements — never personal or health data. To tell repeat visits apart within a day, Web Analytics derives a temporary hash from the request itself and discards it after 24 hours; Speed Insights uses no identifier at all.

With your agreement, we also use Google Analyticsto understand which channels bring people to metrIQ. It runs on our public pages only — never on the app's own screens — and the page address we report is reduced to the page's path, so anything you type into a calculator is dropped before it is sent. It is off until you say yes, we ask before loading anything, and Cookie choices in the footer lets you change your answer as easily as you gave it. We honour Global Privacy Control automatically.

11. Children's privacy

metrIQ is for adults: you must be 18 or older to hold an account. We do not knowingly collect personal data from anyone under 18 — sign-up asks for your date of birth and refuses one that puts you under that age. Where we learn that we hold a child's data, we delete it promptly.

12. Changes to this policy

We may update this policy from time to time. For significant changes, we'll notify you in the app or by email before they take effect. The “Last updated” date at the top indicates when the policy was last revised.

13. Contact us

Z Development EE
support@metriq.fitness for general enquiries, or privacy@metriq.fitness for data access, portability, or other privacy requests
Karakasi 24, Thessaloniki, Greece