Legal

Privacy Policy

Last updated July 30, 2026~12 min readprivacy@getcleo.fit
01

What information do we collect?

In short:We collect the personal information you give us directly, plus some information collected automatically when you use the app.

Personal information you disclose to us

We collect personal information you voluntarily provide when you register, express interest in our products, participate in app features, or contact us. Depending on how you use Cleo, this may include:

  • Names
  • Email addresses
  • Usernames
  • Passwords

Sensitive information. When necessary — with your consent or as otherwise permitted by law — we process health data, since logging meals, weight, and workouts is core to what Cleo does.

Payment data. If you subscribe, payment is handled and stored by the Apple App Store, Google Play, and RevenueCat— we don't store your card details ourselves. Their privacy notices: Apple, Google, RevenueCat.

Social media login data. If you register using a social account, we collect the profile information that provider shares with us — see Social Logins below.

Application data. If you grant access or permission, we may collect:

  • Mobile device data — device ID, model, manufacturer, OS and version, system configuration, browser type, hardware model, carrier, and IP address.
  • Push notifications — you can turn these off any time in your device settings.

This is used to keep the app secure, functioning, and to troubleshoot and improve it.

Information automatically collected

We automatically collect some information when you use Cleo — IP address, browser and device characteristics, operating system, language preference, general location, and how you interact with the app. This doesn't reveal your specific identity on its own, and it's used for security, operation, and internal analytics.

  • Log and usage data — diagnostic and performance information, including timestamps, pages/features used, searches, and crash reports.
  • Device data — information about the device you use to access Cleo.

Google API

Our use of information from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

02

How do we process your information?

In short:To provide, improve, and administer the app, communicate with you, prevent fraud, and comply with the law — and for other purposes only with your consent.

  • Account creation and authentication — creating, logging into, and maintaining your account.
  • Delivering the service — providing the features you request.
  • Support — responding to your inquiries and resolving issues.
  • Administrative messages — updates about the product or changes to our terms and policies.
  • Orders — fulfilling and managing subscriptions, payments, and refunds.
  • Feedback — reaching out to understand your experience with Cleo.
  • Protecting the service — fraud monitoring and prevention.
  • Understanding usage trends — so we can improve the app.
  • Protecting vital interests— in rare situations where it's necessary to prevent harm.
03

What legal bases do we rely on to process your information?

In short:We only process your information when we have a valid legal reason to — consent, contract, legal obligation, vital interest, or legitimate business interest.

If you're in the EU or UK: the GDPR and UK GDPR require us to name our legal bases:

  • Consent — which you can withdraw at any time.
  • Performance of a contract — to fulfil our obligations to you.
  • Legitimate interests — e.g. analyzing usage to improve the app, diagnosing problems, preventing fraud.
  • Legal obligations — cooperating with law enforcement or regulators.
  • Vital interests— protecting someone's safety.

If you're in Canada: we rely on your express or implied consent, which you can withdraw at any time, except in specific cases permitted by law — for example fraud investigations, business transactions, insurance claims, complying with a court order, or research using de-identified data.

04

When and with whom do we share your personal information?

In short:We share information with a short list of vetted service providers under contract — never sold — plus in the event of a business transfer.

We use vendors and service providers under written contracts that limit what they can do with your information. The categories we work with:

  • AI service providers — OpenAI (for natural-language logging and insights)
  • Sign-in providers — Google and Apple, if you use social login
  • Cloud computing — Convex
  • Billing and invoicing — RevenueCat
  • Account registration & authentication — Clerk
  • App performance monitoring — Sentry

We may also share information as part of a business transfer — a merger, acquisition, or sale of assets.

05

Do we offer artificial intelligence-based products?

In short:Yes — Cleo's natural-language logging and insights run on AI, provided through third-party AI service providers including OpenAI.

As part of the app, we offer features powered by artificial intelligence and machine learning ("AI Products"). These are delivered through third-party AI service providers, including OpenAI. Your input, output, and relevant personal information are shared with and processed by these providers so the feature can work. You must not use the AI Products in a way that violates any AI provider's terms.

Our AI Products are designed for:

  • Natural language processing
  • Text analysis
  • Machine learning models
  • AI-generated insights
  • AI-powered app features

All personal information processed through AI features is handled under this notice and our agreements with those providers.

06

How do we handle your social logins?

In short:If you sign in with a social account, we receive the profile information that provider shares with us.

If you register or log in using a third-party social account, we'll receive certain profile information from that provider — typically your name, email address, and profile picture. We only use this as described in this notice. We're not responsible for how the social media provider itself handles your data — check their privacy policy directly.

07

Is your information transferred internationally?

In short:Yes — our servers and service providers are located in the United States and India, and possibly other countries.

Regardless of where you are, your information may be transferred to, stored in, and processed in the United States, India, and other countries where our service providers operate. If you're in the EEA, UK, or Switzerland, those countries may not have data protection laws as comprehensive as your own — but we take appropriate measures to protect your information, including the European Commission's Standard Contractual Clauses for relevant transfers. Details available on request.

08

How long do we keep your information?

In short:For as long as you have an account with us, unless a longer period is required by law.

We don't keep personal information longer than necessary for the purposes in this notice — generally, the length of time you have an account with Cleo. When there's no ongoing legitimate need to process it, we delete or anonymize it, or, where that isn't possible (e.g. backup archives), we securely isolate it until deletion is possible.

09

How do we keep your information safe?

In short:We use reasonable technical and organizational safeguards, though no online system can be guaranteed 100% secure.

We've implemented measures designed to protect your personal information. That said, no method of transmission or storage over the internet is completely secure — we can't guarantee that unauthorized third parties will never defeat those safeguards. Use of the app is at your own risk, and we recommend only accessing it within a secure environment.

10

Do we collect information from minors?

In short:No — Cleo isn't knowingly used by or marketed to anyone under 18.

We don't knowingly collect data from, or market to, children under 18 (or the relevant age of majority in your jurisdiction). By using Cleo, you confirm you're at least 18, or a parent/guardian consenting on behalf of a minor. If we learn we've collected data from someone under 18, we'll deactivate the account and delete the data. If you believe this has happened, contact privacy@getcleo.fit.

11

What are your privacy rights?

In short:Depending on where you live — including the EEA, UK, Switzerland, and Canada — you can access, correct, delete, or restrict use of your personal information.

In these regions, you may have the right to: access and receive a copy of your information; request correction or erasure; restrict processing; request data portability; object to processing; and not be subject to solely automated decision-making without a path to human review. To exercise any of these, contact us at the details below.

UK residents:if you're unhappy with how we've handled a complaint, you can escalate to the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

EEA residents can complain to their Member State data protection authority; Switzerland residents can contact the Federal Data Protection and Information Commissioner.

Withdrawing consentwon't affect the lawfulness of processing done before the withdrawal. You can update or delete your account any time from the app's account settings — we may retain limited data afterward to prevent fraud, resolve disputes, or meet legal obligations.

12

Controls for Do-Not-Track features

In short:We don't currently respond to browser Do-Not-Track signals, since no uniform industry standard exists yet.

Most browsers include a Do-Not-Track (DNT) setting, but there's no finalized technical standard for how sites should respond to it. We don't currently act on DNT signals — if that changes, we'll update this notice.

13

Do United States residents have specific privacy rights?

In short:Residents of many US states (CA, CO, CT, and others) have rights to know, access, correct, delete, and opt out of certain uses of their personal information.

If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights to access, correct, delete, or get a copy of your personal information, and to withdraw consent.

Categories we've collected in the past 12 months

CategoryExamplesCollected
A. IdentifiersName, email address, IP address, account name, online identifierYes
B. Customer records (CA statute)Name, contact info, education, employment, financial informationYes
C. Protected classificationsGender, age, date of birth, race/ethnicity, national origin, marital statusYes
D. Commercial informationTransaction info, purchase history, payment detailsYes
E. Biometric informationFingerprints, voiceprintsNo
F. Internet/network activityBrowsing history, search history, interactions with the appYes
G. Geolocation dataDevice locationNo
H. Audio/visual dataImages, audio, video, or call recordingsNo
I. Professional/employment infoJob title, work history, professional qualificationsNo
J. Education informationStudent records, directory informationNo
K. InferencesProfiles built from the categories aboveNo
L. Sensitive personal informationAccount login credentials and health dataYes

We only collect sensitive personal information as permitted by law or with your consent, and we don't process it to infer characteristics about you. We haven't sold personal information to third parties for a business or commercial purpose in the past 12 months.

Your rights

  • Right to know whether we're processing your data
  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to delete your personal data
  • Right to obtain a copy of data you've shared with us
  • Right to non-discrimination for exercising these rights
  • Right to opt out of targeted advertising, sale, or profiling

Some states also grant more specific rights — like lists of third parties data was shared or sold to (CA, CT, DE, MD, MN, OR), the right to correct automated profiling (CT, MN), or opting out of biometric collection via voice/facial recognition (FL).

To exercise any of these, email privacy@getcleo.fit. We may need to verify your identity first, and an authorized agent can act on your behalf with signed written permission. If we decline a request, you can appeal by emailing the same address — and if that's denied, you can escalate to your state attorney general.

California "Shine the Light" law:California residents can request, once a year and free of charge, information about what we've disclosed to third parties for direct marketing purposes.

14

Do we make updates to this notice?

In short:Yes — we'll update this notice as needed to stay compliant, and note the revision date at the top.

If we make material changes, we'll notify you by posting a prominent notice or contacting you directly. We encourage checking back periodically.

15

How can you contact us about this notice?

Email privacy@getcleo.fit, or write to us by post:

Cleo

India

16

How can you review, update, or delete the data we collect from you?

Depending on the laws of your country or US state of residence, you may have the right to request access to your personal information, ask how it's been processed, correct inaccuracies, delete it, or withdraw consent. To make any of these requests, email privacy@getcleo.fit.