Legal · Privacy
Privacy Policy
Effective and last updated: 19 July 2026
This policy explains how the operator of Mruk ("Mruk", "we", "us") handles personal data across the iOS app, the AI coach, mruk.app, support, and the TestFlight beta list. It also explains what can leave your device. We do not sell personal data, run ads, or use HealthKit data for advertising.
Privacy at a glance
- Apple Health is optional and controlled through iOS permissions.
- We use your data to provide your account, planning, coaching, safety, support, and security—not for advertising.
- AI processing occurs only when needed for the coach or another AI-assisted feature you use.
- Authorized service providers process data for us; optional bring-your-own-key features can send data directly to the provider you choose.
- You can request access, correction, export, restriction, objection, or deletion at hello@mruk.app.
1. Controller and contact
The operator of the Mruk service is the data controller for the processing described in this policy. "Mruk" is the service and trading name used in this policy. For privacy requests, the operator's current legal identity details, or any question about this policy, contact hello@mruk.app. No data-protection officer has been designated.
We may need to verify that a request relates to you before acting on it. We will not ask for more information than is reasonably necessary to verify the request.
2. Scope and our roles
This policy covers the Mruk iOS app, its server APIs, the website and beta list, support messages, push notifications, and optional AI or Apple Health features. It does not cover third-party sites or services you visit independently. Apple, TestFlight, the App Store, and a provider you connect using your own API key may also act as independent controllers under their own terms.
3. Data we process
The data we receive depends on the features you choose. Because fitness and health information can be sensitive, this list is intentionally specific.
Account, authentication, and consent
- The email address from Sign in with Apple — typically the Apple private-relay address you choose to share. Sign in with Apple is the only way to create an account.
- The identifier Apple provides (apple_sub), user identifier, account timestamps, and session/security records.
- Consent and policy-version records, permission choices, and account-control requests.
Profile, goals, health, and fitness
- Age or date-of-birth range, sex-related physiology inputs, height, weight, body-composition information, goals, units, and preferences you provide.
- Food, meals, photos, calories and macronutrients; water; weigh-ins; workouts; training schedule; steps; readiness; sleep; heart-rate variability; resting heart rate; active energy; and related trends.
- Health context you choose to provide, which may include conditions, medication, injuries, pregnancy or breastfeeding, allergies, eating-disorder history or risk indicators, mood, stress, symptoms, blood markers, and blood-test images.
- Calendar or schedule information you add or connect for planning.
Coach and content
- Messages, prompts, replies, feedback, preferences, coach memories, plan changes, and summaries used to maintain context.
- Meal, label, avatar, profile, or bloodwork images you upload, plus extracted or generated descriptions.
- AI-provider choice and, if you enable bring-your-own-key mode, an encrypted copy of the provider credential needed to make your requests.
Purchases, notifications, and device operations
- App Store product and transaction references needed to validate optional in-app tips or purchases. Apple handles payment-card details; Mruk does not receive them.
- Push-notification tokens, notification preferences, app version, device/platform information, and delivery results.
Diagnostics, product events, website, and support
- App events, screen identifiers, interaction or tap coordinates, timestamps, feature outcomes, error details, latency, and AI usage/cost counters.
- IP address and user-agent information used for security, abuse prevention, hosting, and request operations.
- Crash and performance reports if production diagnostics are enabled. We aim to avoid unnecessary personal data, but reports can contain technical context.
- Beta-list email, signup time, bounded campaign attribution, and browser user agent.
- Support messages and any information or attachments you send with them.
Where data comes from
Most data comes from you. Other sources are Apple Health when you authorize it, Sign in with Apple, App Store purchase validation, device and server telemetry, Open Food Facts when you look up a food, and inferences generated from the information above—for example, a trend, readiness summary, or risk flag.
4. Apple Health (HealthKit)
Connecting Apple Health is optional. iOS shows the specific categories requested and lets you grant or revoke each permission. Depending on your choices and the current feature set, Mruk may read steps, sleep, heart-rate variability, resting heart rate, active energy, and related workout or body measurements.
Selected Apple Health readings may be copied into Mruk's protected local state and synchronized to your private account on our servers so features work across sessions. Relevant summaries may be included in a coach request when you use the AI coach. We do not sell HealthKit data, use it for advertising, or disclose it to data brokers. We do not write to Apple Health unless a feature and action clearly request it.
You can change Apple Health access in iOS Settings or the Health app. Revoking access stops new collection but does not automatically erase data already copied into Mruk; use account deletion or contact us to remove that data.
5. Why we process data and our legal bases
| Purpose | Examples | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Provide the service | Account, sync, logs, plans, coach, photos, exports, notifications you request. | Performance of our contract; steps requested before entering it. |
| Process health data | Health profile, HealthKit readings, health summaries, sensitive intake, bloodwork. | Your explicit consent for special-category data; contract where appropriate for non-special-category elements. |
| Personalize coaching | Trends, plan adjustments, selected memories, relevant AI context. | Contract and, for health data, explicit consent. |
| Safety and integrity | Risk signals, rate limits, fraud prevention, account security, incident investigation. | Legitimate interests in a safe and secure service; legal obligations where applicable. Health data is used only with an applicable special-category condition, normally explicit consent. |
| Improve reliability | Diagnostics, aggregate product events, latency, feature success, model quality and cost. | Legitimate interests in operating and improving the service, balanced against your rights; consent where local law requires it. |
| Beta communication | Invite availability and essential beta updates you requested. | Your request/consent and our legitimate interest in administering the beta. You can opt out at any time. |
| Legal and support | Respond to rights requests, disputes, support, and valid legal process. | Legal obligation, contract, and legitimate interests. |
Where we rely on consent, you may withdraw it for future processing without affecting processing that was lawful before withdrawal. Where we rely on legitimate interests, you may object; we will assess your request against any compelling grounds we must continue.
6. The AI coach and automated processing
Mruk clearly identifies its coach as AI. When you use an AI-assisted feature, we send the prompt and the context needed to answer it to the selected AI provider. Context can include recent logs, plan details, preferences, memories, and health or fitness summaries. We aim to minimize context to what is relevant, but you should not enter information you do not want processed for that reply.
AI replies are probabilistic and may be inaccurate, incomplete, or inappropriate. They are wellness suggestions, not diagnosis, treatment, or professional advice. Mruk does not use AI to make decisions that produce legal or similarly significant effects about you. Safety rules and risk signals may limit features or recommend human support, but they do not determine access to employment, insurance, credit, healthcare, or another legal right.
By default, AI requests may be processed through Google Cloud Vertex AI using Google or Anthropic models. If you actively configure a bring-your-own-key provider, requests can instead go directly to the provider you select, such as Anthropic, Google, or OpenAI, under that provider's terms and privacy practices.
7. Service providers and disclosures
We disclose data only as needed to operate the service, follow your instructions, protect users or the service, comply with law, or complete a business transfer subject to appropriate safeguards. Authorized support or operations personnel may access account data when necessary for support, security, privacy requests, or reliability; access should be limited and logged.
| Provider/category | Role and data involved |
|---|---|
| Vercel | Website and serverless API hosting, request operations, private blob/photo storage, and cookieless website analytics if enabled. |
| Turso | Hosted libSQL database for account, state, event, coach, and operational records. |
| Google Cloud / Vertex AI | The default coach, using Google or hosted Anthropic models. Processes your coach queries and the relevant context to generate the coach's replies. Acts as a processor on our behalf; your content is not used to train their models for their own purposes. |
| Your own AI provider — optional (BYOK) (Anthropic, OpenAI, or Google) | If you choose to attach your own API key, your coach queries and their context are sent directly to that provider, under your own account and that provider's terms, instead of via Vertex AI. This is off unless you add a key, and removing the key stops it. |
| Apple | Sign in with Apple, TestFlight/App Store distribution, in-app purchase processing, push notifications, and Apple Health permissions/data on your device. |
| Sentry | Crash and performance diagnostics when configured for a production build. |
| Resend | Delivery of beta confirmation, invite, and operational email. |
| Open Food Facts | Food/barcode lookup you request; the service receives the lookup and ordinary network data such as IP address. |
| Professional advisers and authorities | Only where reasonably necessary for legal advice, claims, security, or a binding legal obligation. |
Provider availability and model routing can change. If a change materially affects your privacy, we will update this policy and provide additional notice where required.
8. Website analytics, cookies, and local storage
The public landing page does not currently set advertising cookies or use cross-site advertising trackers. Vercel Web Analytics may collect cookieless, aggregated visit information such as page, referrer domain, device/browser class, and country-level location. The beta form sends the campaign parameters shown in the page URL and only the referring site's hostname—not its full URL.
The app and authenticated services use device storage, secure keychain/keystore storage, and session credentials that are necessary to provide the service. If we introduce optional non-essential cookies or similar technologies, we will update this section and request consent where required.
9. Retention and deletion
We keep personal data only while needed for the purposes above, subject to legal, security, and backup requirements.
- Account and logged data: normally while your account is active. An account-deletion request removes the live account and schedules associated private blobs for deletion; transient provider failures may delay completion.
- Product events: raw product events are normally pruned after 180 days and raw tap-coordinate records after 90 days. Aggregated statistics may be retained when they no longer identify you.
- Rate-limit/security attempts: short-lived attempt records are pruned after the applicable security window, unless needed to investigate abuse or an incident.
- Beta list: until beta access is sent, the beta program closes, the address is no longer needed, or you ask us to remove it. Confirmation emails explain how to make that request.
- Support and legal records: as long as reasonably necessary to respond, document the request, comply with law, or resolve a dispute.
- Backups and provider logs: copies can persist until overwritten on the provider's normal protected-backup or security-log cycle. They are isolated from ordinary use and not restored except for recovery.
Deleting the app from your phone does not delete the server account. Use the in-app deletion control or email us. Revoking a permission stops future collection through that permission but does not itself erase prior copies.
10. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, receive a portable copy of, delete, restrict, or object to processing; withdraw consent; and appeal or complain to a privacy authority. You may also ask for information about recipients and international-transfer safeguards.
| Control | How to use it |
|---|---|
| Apple Health | Change individual permissions in iOS Settings or the Health app. Contact us or delete the account to erase copies already held by Mruk. |
| Export | Use the export control in Settings or email us for an access/portability request. Some provider or audit records may need a separate request. |
| Correction | Edit available profile/log fields in the app or contact us. |
| Account deletion | Use Delete account in Settings or email us. We may need to verify account ownership. |
| AI provider/key | Change or remove the optional provider configuration in app settings. |
| Beta email | Email hello@mruk.app to be removed. |
| Other rights | Email hello@mruk.app with the request. We will respond within the period required by applicable law. |
If GDPR applies, you may complain to the supervisory authority where you live, work, or believe an infringement occurred. Contacting us first is welcome but not required.
11. International transfers
Mruk and its providers can store or process data in the United States and other countries outside your own. Those countries may have different privacy laws. Where European data-transfer rules apply, we rely on an available lawful transfer mechanism—such as an adequacy decision, an applicable Data Privacy Framework certification, or European Commission Standard Contractual Clauses—together with supplementary protections where required. Contact us for the mechanism relevant to a particular provider and processing activity.
12. Security
We use measures intended to protect personal data, including encrypted transport, protected device storage for account state and credentials, signed sessions, private object storage, access controls, rate limiting, and deletion workflows. No service can guarantee absolute security. Protect your device and account credentials, and contact hello@mruk.app if you suspect unauthorized access.
13. Age limits
Mruk is for adults aged 18 and over. It is not directed to children, and people under 18 must not create an account or provide personal data. If you believe a person under 18 has used Mruk, contact us so we can investigate and delete the information as appropriate.
14. Changes to this policy
We may update this policy as the beta and its providers change. We will revise the effective date and, for a material change, provide an in-app or email notice where appropriate and request renewed consent when the law or the changed processing requires it. Earlier versions can be requested by email.