HERMES+
Privacy Policy — Last updated: May 16, 2026
1. Introduction
Hermes+ ("we", "our", "the app") is operated by Bálint Kenyeres, a private individual based in Hungary (not a registered business entity). Contact: balint@hermesplus.app. Hermes+ is a fitness training application that provides personalized workout programs, AI-powered nutrition planning, fitness coaching chat, and progress monitoring. We are committed to protecting your privacy and handling your personal data transparently.
This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
2. Data We Collect
We collect the following categories of personal data:
Account Information
- Email address (for authentication and communication)
- Full name (display name within the app)
- Password (securely hashed, never stored in plain text)
Profile & Fitness Data
- Age, gender, height, weight, and target weight
- Body fat percentage (if provided)
- Fitness goal (e.g., muscle gain, weight loss)
- Experience level and training preferences
- Equipment availability
Workout Data
- Generated workout plans and exercise logs
- Exercise preferences (liked/disliked exercises)
- Workout completion history and progress
- XP points, rank, and leaderboard position
Nutrition Data
- Food photos uploaded for AI-based nutritional analysis
- Food log entries (calories, macronutrients)
- AI-generated meal plans and dietary preferences
- Allergy and cuisine preference information
AI Chat Data
- Messages sent to the AI fitness coaching chatbot
- Chat history within the current session (not permanently stored)
Payment Data
- Subscriptions are purchased through Apple’s In-App Purchase. Apple processes the transaction; we never see or store card numbers, bank details, or other payment information.
- We use RevenueCat to check whether a subscription is active. It receives your app user ID and the purchase record from Apple, and returns whether your access is valid. We store only your subscription status.
Technical Data
- Device type and browser information (for app optimization)
- Local storage data (workout preferences, UI settings)
3. How We Use Your Data
- Personalized Workouts: Your fitness profile is used to generate tailored workout programs suited to your goals, experience, and available equipment. Workout generation uses professionally designed, rule-based programming logic — not AI.
- AI Meal Plans: Your macronutrient targets, dietary preferences, allergies, and cuisine preferences are used to generate personalized meal plans via AI.
- AI Fitness Chat: Your fitness profile and conversation messages are sent to AI services to provide personalized coaching responses. Chat messages are not permanently stored.
- Nutrition Analysis: Food photos are sent to a third-party AI service (OpenAI) for nutritional estimation. Photos are processed in real-time and are not permanently stored by the AI service.
- Progress Tracking: Workout logs and XP data are used to track your fitness journey, rank progression, and leaderboard position.
- Payment Processing: Subscription payments are processed by Apple, and subscription status is managed through RevenueCat.
- Communication: Your email is used for account-related communications such as password resets and access request confirmations.
- App Improvement: Aggregated, anonymized usage data may be used to improve the app experience.
4. Third-Party Services
We use the following third-party services to operate the app:
- Supabase (database and authentication) — Your account and fitness data is stored securely on Supabase servers. Supabase Privacy Policy
- OpenAI (food image analysis and meal plan generation) — Food photos and meal plan requests are sent to OpenAI's API. Data is processed per OpenAI's data usage policies and is not used to train their models via API. OpenAI Privacy Policy
- Anthropic (AI fitness coaching chat) — Chat messages and fitness profile data are sent to Anthropic's API for AI-powered coaching responses. Data is not used to train models. Anthropic Privacy Policy
- Apple (payment processing) — All subscription transactions are handled by Apple through In-App Purchase. We never have access to your payment details. Apple Privacy Policy
- RevenueCat (subscription management) — Receives your app user ID and Apple purchase record to determine whether your subscription is active. RevenueCat Privacy Policy
- Netlify (web hosting) — The app is hosted on Netlify's infrastructure. Netlify Privacy Policy
- Resend (transactional emails) — Used to send account-related emails. Resend Privacy Policy
- Sentry (error monitoring — EU/Frankfurt region) — If the app crashes or throws an unhandled error, technical diagnostic data (stack trace, browser version, anonymous user ID, page URL with any tokens redacted) is sent to Sentry so we can fix bugs. Email addresses, IP addresses, and typed text are stripped before the event leaves your device. Data is hosted in the EU (Frankfurt) and never leaves the EEA. Sentry Privacy Policy
- ipwho.is (login location lookup) — When you sign in, your IP address may be queried against ipwho.is to determine the city and country shown in the "new login" security alert email. Only the result (City, Country) is stored; the lookup itself is not logged.
5. Data Storage & Security
- All data is transmitted over encrypted HTTPS connections.
- Passwords are hashed using industry-standard algorithms (bcrypt) and are never stored in plain text.
- Database access is protected by Row Level Security (RLS) policies, ensuring users can only access their own data.
- Authentication tokens are managed securely by Supabase Auth.
- Food photos are processed in real-time and are not permanently stored on our servers.
- Payment information is handled entirely by Apple and never touches our servers.
6. Data Retention
- Account and fitness data is retained as long as your account is active.
- Workout logs and progress data are retained to provide continuous progress tracking.
- AI chat messages are session-based and are not permanently stored.
- AI-generated meal plans are stored as long as your account is active or until you regenerate a new plan.
- You can permanently remove your account and all associated personal data at any time via Profile → Privacy & your data → Delete my account. Production data is erased immediately; encrypted backup copies are purged within 30 days.
7. Your Rights (UK GDPR, EU GDPR & CCPA)
You have the following rights regarding your personal data under the UK GDPR, the EU GDPR, and the California Consumer Privacy Act:
- Access & Portability: Download a complete, machine-readable (JSON) copy of all personal data we hold about you. You can do this yourself instantly from Profile → Privacy & your data → Download my data.
- Correction: Update or correct inaccurate personal data via your profile settings.
- Erasure ("Right to be Forgotten"): Permanently delete your account and all associated data. You can do this yourself from Profile → Privacy & your data → Delete my account. Deletion removes your data from our production systems immediately. It does not cancel your subscription — an Apple subscription can only be cancelled by you, in your Apple Account settings. Residual copies in encrypted backups are purged within 30 days.
- Objection: Object to certain types of data processing.
- Withdraw Consent: Withdraw consent for data processing at any time.
- Complaint: Lodge a complaint with your local data protection authority — in the UK the ICO, in Hungary the NAIH.
Most rights can be exercised self-service from your profile. For any other request, email
support@hermesplus.app — we will respond within 30 days.
8. Children's Privacy
Hermes+ is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
9. Cookies & Local Storage
Hermes+ does not use tracking cookies. We use browser local storage solely to:
- Maintain your authentication session
- Store workout preferences and UI settings locally on your device
- Cache workout data for offline functionality
No data from local storage is shared with third parties or used for advertising purposes.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify users through the app or via email. The "Last updated" date at the top of this page reflects the most recent revision.
11. Employer-Provided Access (Corporate Programs)
When your employer or organization provides Hermes+ as part of a wellness or benefits program, the following applies in addition to the rest of this policy:
- Your employer does not have access to your personal data. Your health, training, nutrition, progress, body-measurement, and chat data are private to you and are never shared with your employer.
- We do not report your individual activity, performance, or whether you use the app to your employer.
- To set up your access, your organization may provide us with limited contact details (such as your work email) solely to create or activate your account.
- Any information shared back with the providing organization is limited to aggregate, anonymized figures (for example, the total number of activated accounts) and never includes personal or identifiable data.
- In all other respects, this Privacy Policy applies to you as an individual user, and you retain all the rights described in this policy.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
← Back to Hermes+