Privacy Policy
Last updated September 11, 2026
Be Serious (“we”, “us”) operates the Be Serious iOS app and the beserious.app website. This policy explains what data we collect, why, and what your choices are. The short version: we collect what the app needs to work, plus the product-analytics and ad-measurement data described below; we don’t show ads in the app, we never ask to track you, and we never sell your data.
What we collect
Account. You sign in with Apple or Google. We receive a unique account identifier and, if you choose to share them, your name and email address (Apple lets you hide your real email behind a private relay address, and only shares your name the first time you authorize the app). We never receive your Apple or Google password.
Health and activity data you log. The app stores what you put into it: your selected goals and their order, fasting sessions and chosen schedule, daily streak check-ins and relapse dates, workouts (including type, duration and estimated calories), food and calorie entries with their macros, ingredients and serving counts, saved meals, weight entries, and the profile details you enter during onboarding (gender, birth year, height, weight, and your calorie and step targets), along with preferences like units and appearance.
Apple Health. If you connect Apple Health, the app reads your step count to show daily steps and, optionally, to add the calories you burn to your daily goal. This is read on your device only — we never write to Apple Health, don’t store your step data on our servers, and never use it for advertising.
App blocking (Screen Time). If you turn on Earn Screen Time, the app uses Apple’s Screen Time tools (Family Controls) to keep the apps you choose locked until you complete your daily habits, and to meter the minutes you earn and spend. All of that lives on your device only: your selection is stored as opaque system tokens, the earned and spent minutes are counted on the device, and none of it is uploaded to our servers — we never see which apps you block. The same is true of a food-delivery selection you block during fasts. The feature is off until you grant the Screen Time permission, and you can withdraw that permission in iOS Settings at any time. What does leave the device is only what you tell us yourself: your answers to the onboarding questions about how much time your phone takes and which kinds of apps take it, which are part of the analytics described below.
Photos you add. If you attach a photo to a meal, we store that photo so it appears on the meal wherever you’re signed in: it’s cached on your device and uploaded to a private storage bucket that only your account can read. The same applies to a profile picture or a group-chat picture, with one difference: those are readable by the other members of the chats you’re in, because they’re meant to be seen there. Sharing a logged meal into a chat stores a copy of its photo that the members of that one chat can read, so the card you posted keeps its picture. Your original meal photo stays private to you either way, and because the shared copy is separate, deleting the meal from your log won’t remove it from the chat. Nothing here is visible to Be Serious users you don’t share a chat with, and a shared meal photo is visible only in the chat you posted it to. Photos you take for a one-off nutrition-label scan are not stored. The app never reads your photo library: you pick individual photos through Apple’s picker, or take them with the in-app camera.
AI meal and workout estimates. When you scan a meal or nutrition label, describe a meal, or describe a workout, we send that photo or text to our AI gateway (OpenRouter), which passes it to the model provider that produces the estimate of calories, macros and ingredients. We ask for your permission the first time, and you can decline and log everything manually instead. The result is returned to you and saved with your log. The photo or text is used only to generate the estimate — we don’t keep a server-side copy of it, and it isn’t used to train third-party models. We do keep a per-day count of how many estimates you’ve run, to enforce a fair-use ceiling that exists to stop abuse.
Barcode lookups. If you scan a product barcode, we send only the barcode number to OpenFoodFacts, an open food database, to look up its nutrition. Nothing that identifies you leaves with it.
Chat. If you use group chat, we store your chosen @username, your display name (taken from the name on your account, if you shared one) and profile picture, your current activity streak, the chats you create or join, the messages you send, the reactions you add, and any logged entry you choose to share into a chat as a card (a meal, a workout, a fast, a check-in, or your whole day). Sharing an entry is always a deliberate tap: nothing you log is posted automatically. Messages are visible to the other members of that chat. If you report a message we store a snapshot of it (the message text, its sender and the chat); if you block someone, or mute a chat, we store that too (a mute is visible only to you). Messages and usernames pass through an automated filter that rejects slurs and profanity before they post. A chat has admins, starting with whoever created it, and an admin can rename the chat and remove a member. If someone is removed we keep a record of it (the chat, who was removed and who removed them) so the invite code can’t be used to walk straight back in.
Subscription and purchases. Purchases are processed entirely by Apple — we never see your payment details. Because a subscription is what gives your account access to the app, and that access has to follow you onto every device you’re signed in on, we use RevenueCat, a subscription-management service, to verify the purchase with Apple and keep your subscription status current. RevenueCat receives Apple’s transaction identifiers and the product, price and currency Apple reports — never your payment details — keyed by your account identifier, and notifies us of subscription events (purchases, renewals, cancellations, refunds, expirations), which we log to keep entitlements correct and to understand our own revenue.
Product analytics. To see which parts of the app work and where people get stuck, the app sends usage events to PostHog, our analytics provider, hosted in the United States: which screens and onboarding steps you reached, which goals you picked, your answers to the onboarding questions about your phone use, that features like meal scanning or app blocking were used — including, if Earn Screen Time is on, whether you granted the Screen Time permission, how many apps and categories you chose to lock (never which ones), that a daily habit was completed and earned minutes, that your earned minutes ran out, or that a food block started — and crash reports when the app breaks. Events carry basic device information (model, iOS version, app version) and are tied to your account identifier, together with the name and email you shared at sign-in. They never contain the detail of your logs: no meal contents, weights, fast schedules, workout entries, relapse records, photos, or chat messages.
Technical data. Our hosting providers keep standard service logs (for example IP address, timestamps and requested endpoints) for security, abuse prevention and debugging. We don’t use them to profile you.
Advertising measurement. We run ads for Be Serious on Meta (Facebook and Instagram), and to know which of them actually lead to installs and subscriptions the app includes Meta’s SDK. It reports a small set of events to Meta: that the app was installed and opened, and that a trial or subscription started, with the product and price Apple reports. It does not send your health data, your logs, your photos or your chat content. We deliberately do not ask for permission to track you, which means the app never reads your device’s advertising identifier and Meta receives these events without it. Measurement therefore happens in aggregate, through Apple’s SKAdNetwork and Meta’s aggregated reporting, rather than by tying a subscription to you personally.
What we don’t collect: location, contacts, your photo library, or advertising identifiers. There are no ads inside the app, and we do no tracking of you across other apps or websites.
How we use your data
- To provide the app’s features: tracking, charts, streaks and AI estimates.
- To sync your data to your account so it’s restored when you sign in on another device or reinstall the app.
- To operate group chat, screen content, and act on reports of abusive behavior.
- To confirm your subscription is active — which is what gives your account access to the app — and to keep that record accurate across your devices.
- To keep the service secure, prevent abuse and enforce the fair-use ceiling.
- To understand how the product is doing, using aggregate counts (like total signups or active subscriptions) — never individual profiles sold or shared for advertising.
- To see where the app helps and where it loses people, using the product-analytics events described above, so we can fix what isn’t working.
- To measure how our own ads perform, using the aggregate app events described above, so it costs us less to reach the next person who needs the app.
- Reminders (like fast-complete or streak check-in notifications) are scheduled locally on your device — they never leave it.
- To notify you about group-chat messages. If you allow notifications, your device’s push token is stored with your account and used to send you a notification when someone posts in a chat you’re in. The notification includes the sender, the chat name and the message text (or a summary of a shared card), so it can appear on your lock screen. It is delivered through Apple’s Push Notification service. You can silence any single chat from its menu, or turn notifications off entirely in iOS Settings; signing out removes the token for that device.
What other people can see
Your tracked health data is private to your account. Chat is the exception, by design: members of a chat see your @username, display name, profile picture, current activity streak (on the chat leaderboard), and the messages and reactions you post there. If you choose to share a logged entry into a chat, that entry’s details go with it: a meal’s name and calories (and its photo, if it has one), a workout, a fast, or a check-in. Your @username and profile picture are readable by the people you share a chat with, and not by Be Serious users you don’t. Anyone with a chat’s invite code can join it, so share codes, and personal information, thoughtfully.
Everything you don’t share stays private to your account: your meals, workouts, fasts, weight and check-ins are readable only by you, and nobody outside a chat you are in sees any of it.
Where your data lives
Your data is stored on your device and mirrored to our backend, hosted by Supabase (Postgres) on servers in the United States. Data travels over encrypted connections (TLS) and is encrypted at rest, and server-side access rules scope every record to your account. If you use the app from outside the United States, your data is transferred there; where the law requires a transfer mechanism (for example the EU/UK), we rely on our providers’ standard contractual clauses.
Sharing
We share data only with the service providers needed to run Be Serious: Apple (sign-in, purchases and subscription status), Google (sign-in), Supabase (data and photo hosting), RevenueCat (subscription verification and status), PostHog (product analytics), OpenRouter and the model provider it routes your request to (AI meal and workout estimates), OpenFoodFacts (barcode lookups), Meta (the install and subscription events used to measure our ads), and Vercel (website hosting and analytics) plus Resend (waitlist email). Chat messages and your public chat profile are shared with members of your chats by design. We may disclose data if legally required, or to investigate abuse and protect people’s safety. We never sell personal data, and the only advertising-related sharing is the app-event data described above: your health data, your logs, your photos and your chat content are never shared for advertising.
Retention and deletion
We keep your data for as long as your account exists. You can delete your account at any time in the app under Profile → Delete Account — and if you don’t have an active subscription, the same option (with a one-tap export of your data) is on the subscription screen, so neither deletion nor access ever depends on being subscribed. That deletes your account and, with it, your profile, every log (fasts, workouts, meals, saved meals, weight, check-ins, relapses), your chat memberships and every message and reaction you posted, your @username, and your stored meal, profile and shared-card photos. It can’t be undone. One thing to know: a group chat you created is not deleted along with you. It stays for the other members, with no owner, and your messages in it are gone.
Four things deliberately survive deletion. Purchase records (Apple’s transaction identifiers and the subscription events RevenueCat processed) are kept for tax, accounting and refund purposes. If someone reported a message you sent, the snapshot taken at the time of that report is kept as a moderation record. The install and subscription events already reported to Meta stay with Meta: they carry no advertising identifier and only ever exist there in aggregate, so there is no profile of you for us to delete. And the analytics events already recorded with PostHog remain, keyed to your account identifier — email support@beserious.app and we’ll erase those too. None of the purchase, moderation or Meta records contains your health data, and the analytics events contain at most what the product-analytics section above describes — never your logs.
Deleting your account does not cancel an Apple subscription — cancel that in your device’s subscription settings. Signing out removes your data, including cached photos, from the device.
Why we’re allowed to process it (EU/UK)
Where the GDPR applies, we rely on: performance of our contract with you — which, because Be Serious is a subscription app, covers most of what we do (running your account, giving your subscription access to the app, syncing your data, operating chat); your consent for the health data you choose to log, for Apple Health access, for the Screen Time permission behind Earn Screen Time, and for sending a photo or description to our AI provider — which you can withdraw at any time by stopping use of those features or deleting your account; and our legitimate interests in keeping the service secure, preventing abuse, understanding how the app is used (the product analytics above), and measuring the performance of our own ads in aggregate. Purchase records are kept to meet legal obligations.
Your rights
Depending on where you live (for example the EU/EEA and UK under the GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, export or delete your personal data, to withdraw consent, and not to be discriminated against for exercising those rights. Export and deletion are built into the app and reachable whether or not you’re subscribed; for anything else, email us and we’ll help — we won’t make you jump through hoops. EU/EEA and UK users may also complain to their local data protection authority.
Security
Accounts are protected by Sign in with Apple or Google, so there is no password for us to lose. Data is encrypted in transit and at rest, and row-level security rules on the database restrict every record to the account that owns it. No system is perfectly secure, but we keep the amount of data we hold deliberately small.
Children
Be Serious is not directed at children under 13 and we don’t knowingly collect data from them. If you believe a child has given us data, email us and we’ll delete it.
The website
If you join the waitlist on beserious.app we store your email address with Resend and send you a confirmation email. The site uses Vercel’s anonymous, cookieless analytics, and briefly processes your IP address to rate-limit signups. Email us to be removed from the waitlist.
Changes
If we change this policy we’ll post the new version here and update the date above.
Contact
Questions? Email support@beserious.app. See also our Terms of Use.