Privacy policy

What Course collects, and what it doesn’t.

Last updated August 2026. COURSE (“we”, “the app”) is a personal nutrition and fitness tracker. This policy describes what data the app collects, how it is used, and your choices.

Data we collect

Category Examples Purpose
Account Email address, Firebase user ID, sign-in provider (Sign in with Apple, Google Sign-In, or email/password) Authentication and cloud sync
Health & fitness Meals, calories, macros, weight, body composition, exercise logs Core app functionality
Apple Health Workouts, active energy, resting energy, steps (read); today’s dietary energy, protein, carbs, and fat (optional write); weight and body composition (optional import) Exercise credit, optional nutrition write-back, and optional body import
Food catalogs Search terms and barcodes you look up USDA FoodData Central and Open Food Facts lookups
User content Recipes, shopping lists, food logs Stored locally and synced to your account
Recipe import Recipe URLs and optional captions you submit Optional personal recipe-import service (when you configure it)
Crash diagnostics Crash stack traces and breadcrumb logs (PII scrubbed) Stability via Firebase Crashlytics

We do not sell your data. We do not use advertising or cross-app tracking.

Where data is stored

HealthKit

We read and write only the Apple Health types you authorize in the system permission sheet. Health data is not shared with third parties for marketing.

Manual exercise you log yourself can sync; Health-sourced workout rows do not.

Crashlytics

Firebase Crashlytics may receive crash reports and developer breadcrumbs. App logs are passed through a scrubber that redacts email addresses, long digit runs, and quoted display names before they leave the device. Crashlytics is crash reporting, not advertising analytics.

Your rights

Contact

For privacy questions, email support@courseapp.app.

Changes

We may update this policy. Material changes will be reflected in the “Last updated” date above.