What leaves your phone, and when.
Galb holds photographs of your body and data about your health. That is the most personal category of data there is, so this page says exactly what is collected, exactly what is sent where, and exactly how to destroy all of it. It describes what the app actually does, not what a template says a fitness app might do.
The short version
- Your data lives on your phone and in your own account, hosted in Paris, France (AWS eu-west-3).
- Nothing goes to the AI coach until you say yes on a screen that names what goes. You can withdraw at any time, and tracking keeps working fully without it.
- Your data is never used to train AI models, never sold, never used for advertising.
- No third-party analytics SDK, no ad network, no tracker. Galb records its own usage counts (never content), and you can switch those off.
- Deleting your account destroys everything, including your photos, after 30 days, irreversibly.
Who is responsible
FALL SERVICES is the data controller for the Galb app and this site. Questions, or to exercise any right below: contact@fallencompany.com.
Registered address: 10 rue Ernest Luisetti, 91200 Athis-Mons, France
Company registration: 911 573 061
What Galb collects
Everything below is data you enter or choose to connect. Galb has no hidden collection: it does not read your contacts, your location, your photo library, or your other apps.
Account
Your email address. Sign-in is a one-time code sent to that address. Galb never asks for or stores a password. Your session is kept in the iPhone Keychain.
Profile and body data
First name, biological sex, date of birth, height, body weight, body-fat percentage, body measurements (waist, neck, chest, biceps, thigh, calf), training experience, goal, available equipment, and any injury notes you write.
Check-in photos
The front, back and side photos you choose for a check-in. You pick each one through the system picker. Galb is never granted access to your photo library as a whole.
Training and nutrition
Your workouts (exercises, weights, reps, RPE, notes), your programs, your nutrition log, and anything you type to the coach.
Apple Health (only if you turn it on)
Galb reads body mass, body-fat percentage, lean body mass, height, heart-rate variability, heart rate, step count, sleep analysis, workouts, and your date of birth and biological sex. It writes finished strength sessions and active energy back to Health so they appear in Activity and Fitness. Health data is never used for advertising and is never sold. It is shared with the AI coach only under the separate consent described below.
Derived data
Results the coach produces about you: per-muscle development ratings, estimates of your skeletal proportions read from your photos, session recaps, and weekly insights.
The contact form on this site
If you write to us through the form on the contact page, we store your name, your email address and your message so we can reply, for two years. To stop the form being flooded by a bot we also store a one-way hash of your IP address, salted with a value that changes every day: it cannot be turned back into an address, or matched to you tomorrow. None of this is linked to a Galb account, and none of it is used for anything but answering you.
Sensitive data, and the legal basis for it
Your photos, body measurements, weight, body-fat percentage, injury notes and Health data are special-category data under Article 9 of the GDPR: data concerning health. Galb processes it on the basis of your explicit consent under Article 9(2)(a), asked for separately from the terms, never bundled, and never pre-ticked.
Otherwise:
- Running the app you asked for. Storing your log, syncing your account across your devices, building your program: performance of our contract with you (Art. 6(1)(b)).
- Sending anything to the AI coach. Your consent (Art. 6(1)(a)), plus explicit consent under Art. 9(2)(a) for the health parts.
- Security, abuse prevention and diagnostics. Our legitimate interest in keeping the service working and not being defrauded (Art. 6(1)(f)).
Where your data is stored
On your phone. Once you sign in, also in your own account on Supabase, hosted in Paris, France (AWS eu-west-3). Your check-in photos are stored as files in that same region. Every row and every file is bound to your user ID by database row-level security, so your account can read your data and no other account can.
Signing in is what turns on cloud storage. If you never sign in, your data never leaves your device except to the AI coach, and only then with your consent.
What the AI coach sees
Galb's coach is Claude, made by Anthropic PBC, which processes in the United States. Nothing reaches it until you grant consent in the app, and every request is gated on that consent, including internally, so a bug in one screen cannot leak data past a withdrawn consent. Here is every kind of request Galb makes and what each one carries:
- Physique analysis. The check-in photos you selected. Images are downscaled before sending.
- Photo angle detection. The same photos, to work out which is front, back and side.
- Coach chat. Your recent messages, your goal and experience, your current program, your recent training volume, your weight, height, age, sex and body-fat percentage, your readiness figures (heart-rate variability and sleep, from Apple Health), your step counts, and the proportions previously read from your photos.
- Weekly insights. Your last seven days of training, your most recent physique analysis, stalled lifts, your nutrition log for the week, and step counts.
- Session recaps. The sets, reps and weights of the session you just finished.
- Muscle guidance. When you tap a muscle: its analysis result, your recent volume for it, your goal, experience, equipment, and injury notes.
Anthropic PBC acts as our processor and does not use this data to train its models. Requests are relayed through our own server so that no API credentials ship inside the app, which also means the request is attributable to your account for the rate limits described below.
Withdrawing consent stops all of it. Profile → Data & AI privacy, at any time. Every AI feature fails closed the moment you withdraw; logging, programs, progress and the body map keep working. If we ever change AI provider, existing consents are invalidated automatically and you will be asked again before anything is sent.
Diagnostics, app health and usage counts
When something goes wrong, Galb records a diagnostic entry in your account (the error, the app version, the device model, and your user ID), so a failure you report can actually be found. These entries do not contain your photos, your chat content, or your profile fields.
Galb also records a small stream of product-analytics events so we can tell how the app is behaving and where people get stuck: which screens and features you open, whether onboarding finished, whether a coach call succeeded and roughly how long it took (a bucket like "3–6s", not a precise timing), whether a sync failed, whether the previous run ended in a crash, and how many times an error occurred by category. Purchase events record only which plan and the outcome, never payment details.
These events are counts, never content. They carry no photo, no message you typed, no weight, body-fat figure, heart-rate variability or sleep value. They are processed on our legitimate interest in keeping Galb working and understanding which parts of it are worth building on.
There is still no third-party analytics SDK. These events go to your own account on our database, the same place as everything else, and nowhere else. You can turn them off entirely in Profile → Units & privacy → "Share usage data"; switching it off also discards anything queued but not yet sent, and Galb works exactly the same without it.
For each AI request, Galb records the model used, the feature that triggered it, the response status and the number of tokens consumed. Those are counts only: no prompt or reply content is stored. This exists to measure cost and to enforce a daily limit per account, which stops a compromised account from running up unbounded spend.
Subscriptions
Galb Pro is billed by Apple through your App Store account. Apple handles the payment; Galb never sees or stores your card, your billing address, or your App Store receipt. The only thing recorded in your account is whether you are subscribed and the date you first subscribed, which we use to understand how many people find Galb worth paying for.
Who else can see your data
- Supabase. Database, file storage and authentication, in Paris, France (AWS eu-west-3).
- Anthropic PBC. The AI coach, in the United States, only with your consent.
- Apple. App Store distribution, subscription billing, and (if you enable it) Health, iCloud backup of your device, and push notifications.
- Google Cloud. Hosting for this website only. The site sets no cookies, uses no analytics product, and loads no fonts or scripts from anyone else, so visiting it does not hand your IP address to a third party. Like any web server, the host records the requests it serves: the page, the time, the referring site and the browser string. We read those logs to count how many people visit and from where. Nothing is added to your browser to make that possible, and there is no way for us to recognise you on a second visit.
That is the complete list. There is no analytics provider, no advertising network, no crash reporting service, and no data broker. We do not sell your data, and we will not.
Transfers outside the EU
Your account data stays in the EU. The exception is the AI coach: when you consent, the data listed above is sent to Anthropic PBC in the United States. That transfer is covered by the European Commission's Standard Contractual Clauses, and it happens only because you chose it. You can use Galb as a tracker without ever making one.
How long it is kept
Your data is kept while your account exists, because it is the record you are building. A two-year-old check-in is the point of a progress photo.
When you delete your account (Profile → Delete account), the request is recorded and your data is erased from the device immediately. After 30 days it is destroyed permanently: your photos are deleted from storage, and your account and every row attached to it (profile, workouts, check-ins, programs, analyses, chat, nutrition logs, diagnostics and usage counts) are deleted with it. Signing back in before those 30 days are up cancels the deletion. After that it cannot be undone, by you or by us.
Two things sit outside that, and both are worth saying plainly. If you turned on Apple Health, the workouts Galb wrote into it stay in your Health app: they are yours, on your device, and deleting your Galb account does not reach into Apple’s store to remove them. You can delete them yourself in the Health app. Apple also keeps its own record of any subscription, as the seller, which is outside our reach entirely.
One thing survives on our side, and we would rather say so than let you find out: at the moment of deletion we write a single anonymous line about the departure, so we can tell whether people leave in the first week or the sixth month. It records the month you signed up, the month you left, roughly how much you logged (a range such as “10–49 workouts”, never an exact figure), and whether you had used photo analysis, imported a history, or subscribed. It contains no identifier, no link to your account, no dates more precise than a month, no photographs, no body figures and nothing you typed. There is deliberately nothing in it that could be joined back to you, which is why it is not personal data and does not outlive the erasure as an exception to it.
Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to how it is used, receive it in a portable form, and withdraw consent at any time without affecting what was lawful before. Withdrawing AI consent takes one tap in the app; erasure is the delete-account flow above.
For anything else, email contact@fallencompany.com and we will respond within one month. A portable export of your data is available on request; a self-service export button is not yet in the app, and until it ships we will produce the export for you.
If you think we have handled your data badly, please tell us first. You always have the right to complain to the CNIL (Commission nationale de l'informatique et des libertés), or to the supervisory authority where you live.
Security
Data is encrypted in transit and at rest. Your session lives in the iPhone Keychain. Access to your rows is enforced by the database itself rather than by the app, so a bug in the app cannot expose another user's data. AI credentials are held on our server and never ship inside the app. No system is perfect; if we ever have a breach that puts you at risk, we will tell you and the supervisory authority as the law requires.
Children
Galb is not for people under 16. We do not knowingly collect data from anyone younger, and will delete it if we learn we have.
Changes
If we change what is processed or why, we will update this page and, where the change matters to you, ask again in the app rather than relying on you re-reading a policy. A change of AI provider always re-asks.
Effective 3 August 2026. Controller: FALL SERVICES. Privacy contact: contact@fallencompany.com · General support: contact@fallencompany.com
← Back to galb.app