Privacy policy
Privacy Policy - Athlon
Last updated: October 7, 2026
At a glance
- Athlon tracks fitness and nutrition.
- Your account, profile, food, workouts and activity serve features you request.
- Health synchronization, AI sharing, analytics and ad attribution have separate choices.
- Health data is never used for advertising.
- We do not sell personal data. Stores and RevenueCat process payments; we do not receive banking details.
- Change choices in Profile > Preferences and account > Privacy and consents, delete your account in Profile > Preferences and account, or write to contact@neziakstudio.com.
1. Who is responsible for your data?
The data controller for your personal data is:
Neziak Studio, a French société par actions simplifiée (simplified joint-stock company) with a share capital of EUR 1,000 Registered office: 144 avenue Charles de Gaulle, 92200 Neuilly-sur-Seine, France Registered with the Nanterre Trade and Companies Register under number 107 967 606 Contact: contact@neziakstudio.com
Any request regarding your personal data can be sent to the email address above. We commit to responding within one month maximum, in line with applicable regulations.
2. What data do we collect?
2.1 Information you provide
Account: email, name or nickname and Firebase identifier. Firebase manages passwords; Apple and Google sign-in are supported. Apple may supply a relay email address.
Profile: birth date or age, declared sex, height, weight, optional body fat, goals and declared activity. Tracking: food, meals, recipes, water, routines, workouts, loads, repetitions and RPE.
AI assistant: messages, preferences, meal photos you choose, useful context and responses. These may include health information and are shared with the AI provider only after explicit permission.
2.2 Optional Health and activity
After permission for Athlon server synchronization and system permissions, we may import steps, active calories and body weight from Apple Health / Health Connect. The pedometer may supply daily steps. Health imports may cover three years. Dates and technical sample identifiers prevent duplicates. Manual tracking remains available without permissions.
2.3 Technical information and purchases
IP addresses and operational logs; app, device and system information; purchase products, transactions and entitlements via Apple / Google Play and RevenueCat when purchases are enabled. Rest alarms are local notifications.
Firebase Analytics and Meta receive the events described in section 9 under your choices. Firebase, RevenueCat and Meta identifiers are synchronized according to those permissions. IDFA also requires ATT on iOS. Local choices are stored with date and text version.
2.4 Limits
Athlon servers do not receive passwords or banking details. Marketing events exclude weights, food, loads, photos, AI messages and imported Health records. The app does not request contacts or precise location.
3. Why do we collect this data?
| Purpose | Information | Applicable basis |
|---|---|---|
| Account and requested tracking | Account, profile, food, workouts | Service performance |
| Health synchronization | Steps, energy, weight and dates | Explicit consent for health processing and system permissions |
| AI assistance | Messages, photos, useful context | Requested service and prior sharing permission; explicit consent for health information |
| Purchases | IDs, products, entitlements | Service performance and legal duties |
| Security | Logs and IP | Legitimate interest |
| Firebase analytics | Usage events and IDs | Separate consent |
| Meta attribution | Conversion events and advertising IDs | Separate consent and ATT on iOS |
Health and AI permissions are independent from analytics and advertising. Declining optional processing does not block manual tracking.
4. Who do we share your data with?
| Provider | Role |
|---|---|
| Apple / Google | Social sign-in and store purchases |
| Google Firebase | Authentication; analytics after permission |
| Oracle Cloud Infrastructure (OCI) — eu-paris-1 (Paris, France) | Athlon server and PostgreSQL hosting |
| Sovinfra (FPLC SAS, Paris), whose servers are in the European Union | AI assistance and analysis after explicit permission |
| RevenueCat | Purchases, receipts, entitlements and consented analytics integrations |
| Meta Platforms | Campaign attribution after consent and iOS ATT |
| Google AdMob / UMP | Ads when enabled for free users and privacy preferences |
The free plan of Athlon shows Google AdMob ads. Their personalisation depends on your choice in Google’s consent form (UMP) and, on iOS, on tracking authorisation (ATT). Pro subscribers see no ads. Meta attribution is independent from displaying ads.
AI provider retention: none. The content of each request (text, photo) is processed in memory for the time needed to produce the answer, then discarded; it is not logged, retained or used to train models (Sovinfra privacy policy). Your conversation history is kept by Athlon on its own servers until the conversation or the account is deleted. We do not sell your information.
5. International transfers of your data
Some providers may process data outside the European Economic Area. Applicable safeguards: the server, database, their backups and the AI assistant (Sovinfra) stay in the European Union. For providers established outside the EEA (Google Firebase, Meta, RevenueCat, Apple, Google Play): European Commission adequacy decision for companies certified under the EU–U.S. Data Privacy Framework and, failing that, the European Commission's standard contractual clauses. Write to contact@neziakstudio.com for information or a copy of applicable safeguards.
6. How long do we keep your data?
Account information and tracking histories serve the account while it exists. In-app deletion removes associated Athlon data and the Firebase account. For Apple, the app reauthenticates and revokes access before deletion.
| Information | Retention |
|---|---|
| Server backups | 37 days |
| Technical logs | 30 days |
| AI provider data | none. The content of each request (text, photo) is processed in memory for the time needed to produce the answer, then discarded; it is not logged, retained or used to train models (Sovinfra privacy policy). Your conversation history is kept by Athlon on its own servers until the conversation or the account is deleted |
| Firebase Analytics | 14 months at most for event- and user-level data (Google Analytics retention setting); only aggregated statistics are kept beyond that |
| Meta and advertising integrations | under Meta's Business Tools Terms, 2 years at most for app events; consent can be withdrawn at any time in Profile > Preferences and account > Privacy and consents |
| Local permission records | Until withdrawal, logout or local storage deletion |
Purchase records retained by stores and providers follow their duties and retention settings. We process erasure requests with relevant providers. Account deletion does not cancel subscriptions. Permission withdrawal does not automatically delete earlier imports or Apple Health records.
7. Your rights
Under applicable regulations, you have the following rights regarding your personal data:
- Right of access: obtain a copy of the data we hold about you
- Right to rectification: correct any inaccurate information
- Right to erasure ("right to be forgotten"): request deletion of your account and data
- Right to restriction: request that processing of your data be suspended
- Right to data portability: receive your data in a structured format (JSON)
- Right to object: oppose certain processing activities, including direct marketing
- Right to withdraw consent at any time
How to exercise your rights
By email: write to contact@neziakstudio.com. Specify your request and include proof of identity if necessary.
In the app: two actions are directly in your hands.
- Profile > Preferences and account > Privacy and consents: change or withdraw your consent, purpose by purpose, at any time.
- Profile > Preferences and account > Delete my account: delete your account and your data. This action is irreversible.
Response time: one month maximum, extendable by two months if your request is complex (we'll let you know).
Right to complain: if you believe your rights aren't being respected, you can file a complaint with the relevant supervisory authority (see Appendices based on your country of residence).
8. Security of your data
Production communications use HTTPS. Firebase authenticates your identity; the server enforces account ownership. Access to services and backups is restricted to authorized people. Hosting is described in section 4. In case of a breach, applicable notification obligations apply.
9. Your choices: privacy, notifications, analytics, and advertising
9.1 Independent choices
Usage analytics and advertising and attribution are offered separately on first access. No tracking starts before permission, regardless of country. Accept all, decline all or save your choices are available. Closing the screen does not accept. Change choices in Profile > Preferences and account > Privacy and consents; SDK tracking is disabled at logout.
9.2 Notifications
Rest notifications and system permissions are optional and can be managed in device settings.
9.3 Firebase Analytics
With consent, we measure onboarding completion, Pro offer views and selections, paywall closing, free access start, first workouts, completed workouts and account deletion. Technical IDs can link events to your account and RevenueCat conversions. Events exclude Health data and the content of food diaries and conversations. Configured RevenueCat integrations emit payment, trial and renewal events, without intentional app-side duplication.
9.4 Meta and ATT
Meta is inactive before advertising and attribution permission. iOS App Tracking Transparency permission is also required. If either is declined, the SDK is not initialized and manual Meta events are blocked. IDFA requires both permissions. Withdrawal stops new events and removes corresponding RevenueCat conversion identifiers; it does not erase past transmissions.
9.5 Health and AI
Health synchronization and AI sharing permissions are collected separately before reading/importing or transmitting data. Withdraw them in Profile > Preferences and account > Privacy and consents. An already running AI generation may continue until stopped in the chat. Write to contact@neziakstudio.com to request deletion of previously shared data.
9.6 AdMob ads
When ads are enabled, Google UMP collects required preferences. These can be accessed in the subscription screen and, when available, Privacy. Health records are never used for advertising or targeting.
10. Minors
Minimum age: 13 years, subject to local rules and required parental authorization. Athlon is not intended for the App Store Kids category. Contact contact@neziakstudio.com if data was supplied in breach of applicable rules.
11. Changes to this policy
We may update this privacy policy to reflect:
- Changes in our data practices
- New features of the app
- Changes in applicable law
In the event of a substantial change, we'll notify you via in-app notification and/or email. The current version, with its last updated date, is always available at:
https://athlon.neziakstudio.com/en/privacy.html
Our Terms of Use are available at https://athlon.neziakstudio.com/en/terms.html.
12. Contact us
For any question regarding your personal data or this policy:
Email: contact@neziakstudio.com Mail: Neziak Studio, 144 avenue Charles de Gaulle, 92200 Neuilly-sur-Seine, France
Jurisdictional Appendices
Appendix A: California Residents (CCPA / CPRA)
If you are a resident of the State of California (USA), you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of data collected (under the CCPA)
We collect the following categories of personal information:
- Identifiers: Firebase ID, email, device identifiers
- Commercial information: subscription and transaction history
- Approximate location information: inferred from your IP address (country)
- Internet usage data: interactions with the app, analytics events
- Inferences: tracking estimates derived from your preferences
Health and nutrition information may be sensitive. It is limited to requested features and never used for advertising.
Sale and sharing of your information
We do not sell your personal information. We also do not share it for cross-context behavioral advertising without your explicit consent.
If you enable ad tracking (ATT), certain information (IDFA, pseudonymized purchase events) is shared with Meta for attribution purposes. You can opt out at any time by revoking your ATT authorization in your iPhone Profile > Preferences and account > Privacy and consents > Tracking.
How to exercise your opt-out
The Profile > Preferences and account > Privacy and consents screen in the app is the designated opt-out channel for California residents. It lets you turn off usage analytics and advertising and attribution at any time, independently of each other. No prior step or proof of identity is required, and exercising this right does not affect your access to the service.
You may also write to us at contact@neziakstudio.com with the subject "CCPA Request".
Your CCPA/CPRA rights
- Right to Know: know what information we hold about you
- Right to Delete: request deletion of your information
- Right to Correct: correct inaccurate information
- Right to Opt-Out: decline sale or sharing of your information. You can decline advertising processing; the Profile > Preferences and account > Privacy and consents screen nevertheless lets you turn off usage analytics and ad tracking.
- Right to Limit: limit use of certain sensitive information under applicable rules
- Right to Non-Discrimination: we will not penalize you for exercising your rights
To exercise these rights, write to contact@neziakstudio.com with the subject "CCPA Request".
You may also file a complaint with the California Attorney General's Office or the California Privacy Protection Agency.
Appendix B: European Union, United Kingdom, and European Economic Area users
This appendix supplements the main policy for users protected by the General Data Protection Regulation (GDPR) or UK GDPR.
Your supervisory authority
You may file a complaint with the relevant supervisory authority in your country:
- France: Commission nationale de l'informatique et des libertés (CNIL), cnil.fr
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk
- Belgium: Autorité de protection des données, autoriteprotectiondonnees.be
- Other EU member states: see the list at edpb.europa.eu
Automated decisions
We do not carry out any automated decisions producing legal effects or significantly affecting you within the meaning of GDPR Article 22. The personalization of your program does not constitute an automated decision under the regulation: it is the direct result of your choices declared during onboarding.
Data Protection Officer (DPO)
Given the size of our structure and the nature of our processing, we have not appointed a DPO. All requests must be sent to contact@neziakstudio.com.
Appendix C: Canadian users
Quebec residents (Law 25)
In accordance with Law 25 modernizing the provisions on personal information protection (Quebec), you have the following rights:
- Right to access your personal information
- Right to rectification
- Right to portability (since September 2024)
- Right to erasure (right to be forgotten)
- Right to be informed in case of a confidentiality incident
Person responsible for personal information protection: the President of Neziak Studio, reachable at contact@neziakstudio.com
Other Canadian provinces (PIPEDA)
In accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), you have equivalent rights. You can file a complaint with the Office of the Privacy Commissioner of Canada, priv.gc.ca.
Appendix D: Australian users
As a user residing in Australia, your personal data is protected by the Privacy Act 1988 and the Australian Privacy Principles (APPs).
You have the following rights:
- Access to your personal information
- Correction of inaccurate information
- Withdrawal of consent
- Filing a complaint with the Office of the Australian Information Commissioner (OAIC), oaic.gov.au
Appendix E: New Zealand users
As a user residing in New Zealand, your personal data is protected by the Privacy Act 2020 and the New Zealand Information Privacy Principles (NZIPPs).
You have the following rights:
- Access to your personal information
- Correction of information
- Filing a complaint with the Privacy Commissioner, privacy.org.nz