Galb · privacy policy

What leaves your phone, and when.

Galb holds photographs of your body and data about your health. That is the most personal category of data there is, so this page says exactly what is collected, exactly what is sent where, and exactly how to destroy all of it. It describes what the app actually does, not what a template says a fitness app might do.

The short version

Who is responsible

FALL SERVICES is the data controller for the Galb app and this site. Questions, or to exercise any right below: contact@fallencompany.com.

Registered address: 10 rue Ernest Luisetti, 91200 Athis-Mons, France

Company registration: 911 573 061

What Galb collects

Everything below is data you enter or choose to connect. Galb has no hidden collection: it does not read your contacts, your location, your photo library, or your other apps.

Account

Your email address. Sign-in is a one-time code sent to that address. Galb never asks for or stores a password. Your session is kept in the iPhone Keychain.

Profile and body data

First name, biological sex, date of birth, height, body weight, body-fat percentage, body measurements (waist, neck, chest, biceps, thigh, calf), training experience, goal, available equipment, and any injury notes you write.

Check-in photos

The front, back and side photos you choose for a check-in. You pick each one through the system picker. Galb is never granted access to your photo library as a whole.

Training and nutrition

Your workouts (exercises, weights, reps, RPE, notes), your programs, your nutrition log, and anything you type to the coach.

Apple Health (only if you turn it on)

Galb reads body mass, body-fat percentage, lean body mass, height, heart-rate variability, heart rate, step count, sleep analysis, workouts, and your date of birth and biological sex. It writes finished strength sessions and active energy back to Health so they appear in Activity and Fitness. Health data is never used for advertising and is never sold. It is shared with the AI coach only under the separate consent described below.

Derived data

Results the coach produces about you: per-muscle development ratings, estimates of your skeletal proportions read from your photos, session recaps, and weekly insights.

The contact form on this site

If you write to us through the form on the contact page, we store your name, your email address and your message so we can reply, for two years. To stop the form being flooded by a bot we also store a one-way hash of your IP address, salted with a value that changes every day: it cannot be turned back into an address, or matched to you tomorrow. None of this is linked to a Galb account, and none of it is used for anything but answering you.

Sensitive data, and the legal basis for it

Your photos, body measurements, weight, body-fat percentage, injury notes and Health data are special-category data under Article 9 of the GDPR: data concerning health. Galb processes it on the basis of your explicit consent under Article 9(2)(a), asked for separately from the terms, never bundled, and never pre-ticked.

Otherwise:

Where your data is stored

On your phone. Once you sign in, also in your own account on Supabase, hosted in Paris, France (AWS eu-west-3). Your check-in photos are stored as files in that same region. Every row and every file is bound to your user ID by database row-level security, so your account can read your data and no other account can.

Signing in is what turns on cloud storage. If you never sign in, your data never leaves your device except to the AI coach, and only then with your consent.

What the AI coach sees

Galb's coach is Claude, made by Anthropic PBC, which processes in the United States. Nothing reaches it until you grant consent in the app, and every request is gated on that consent, including internally, so a bug in one screen cannot leak data past a withdrawn consent. Here is every kind of request Galb makes and what each one carries:

Anthropic PBC acts as our processor and does not use this data to train its models. Requests are relayed through our own server so that no API credentials ship inside the app, which also means the request is attributable to your account for the rate limits described below.

Withdrawing consent stops all of it. Profile → Data & AI privacy, at any time. Every AI feature fails closed the moment you withdraw; logging, programs, progress and the body map keep working. If we ever change AI provider, existing consents are invalidated automatically and you will be asked again before anything is sent.

Diagnostics, app health and usage counts

When something goes wrong, Galb records a diagnostic entry in your account (the error, the app version, the device model, and your user ID), so a failure you report can actually be found. These entries do not contain your photos, your chat content, or your profile fields.

Galb also records a small stream of product-analytics events so we can tell how the app is behaving and where people get stuck: which screens and features you open, whether onboarding finished, whether a coach call succeeded and roughly how long it took (a bucket like "3–6s", not a precise timing), whether a sync failed, whether the previous run ended in a crash, and how many times an error occurred by category. Purchase events record only which plan and the outcome, never payment details.

These events are counts, never content. They carry no photo, no message you typed, no weight, body-fat figure, heart-rate variability or sleep value. They are processed on our legitimate interest in keeping Galb working and understanding which parts of it are worth building on.

There is still no third-party analytics SDK. These events go to your own account on our database, the same place as everything else, and nowhere else. You can turn them off entirely in Profile → Units & privacy → "Share usage data"; switching it off also discards anything queued but not yet sent, and Galb works exactly the same without it.

For each AI request, Galb records the model used, the feature that triggered it, the response status and the number of tokens consumed. Those are counts only: no prompt or reply content is stored. This exists to measure cost and to enforce a daily limit per account, which stops a compromised account from running up unbounded spend.

Subscriptions

Galb Pro is billed by Apple through your App Store account. Apple handles the payment; Galb never sees or stores your card, your billing address, or your App Store receipt. The only thing recorded in your account is whether you are subscribed and the date you first subscribed, which we use to understand how many people find Galb worth paying for.

Who else can see your data

That is the complete list. There is no analytics provider, no advertising network, no crash reporting service, and no data broker. We do not sell your data, and we will not.

Transfers outside the EU

Your account data stays in the EU. The exception is the AI coach: when you consent, the data listed above is sent to Anthropic PBC in the United States. That transfer is covered by the European Commission's Standard Contractual Clauses, and it happens only because you chose it. You can use Galb as a tracker without ever making one.

How long it is kept

Your data is kept while your account exists, because it is the record you are building. A two-year-old check-in is the point of a progress photo.

When you delete your account (Profile → Delete account), the request is recorded and your data is erased from the device immediately. After 30 days it is destroyed permanently: your photos are deleted from storage, and your account and every row attached to it (profile, workouts, check-ins, programs, analyses, chat, nutrition logs, diagnostics and usage counts) are deleted with it. Signing back in before those 30 days are up cancels the deletion. After that it cannot be undone, by you or by us.

Two things sit outside that, and both are worth saying plainly. If you turned on Apple Health, the workouts Galb wrote into it stay in your Health app: they are yours, on your device, and deleting your Galb account does not reach into Apple’s store to remove them. You can delete them yourself in the Health app. Apple also keeps its own record of any subscription, as the seller, which is outside our reach entirely.

One thing survives on our side, and we would rather say so than let you find out: at the moment of deletion we write a single anonymous line about the departure, so we can tell whether people leave in the first week or the sixth month. It records the month you signed up, the month you left, roughly how much you logged (a range such as “10–49 workouts”, never an exact figure), and whether you had used photo analysis, imported a history, or subscribed. It contains no identifier, no link to your account, no dates more precise than a month, no photographs, no body figures and nothing you typed. There is deliberately nothing in it that could be joined back to you, which is why it is not personal data and does not outlive the erasure as an exception to it.

Your rights

Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to how it is used, receive it in a portable form, and withdraw consent at any time without affecting what was lawful before. Withdrawing AI consent takes one tap in the app; erasure is the delete-account flow above.

For anything else, email contact@fallencompany.com and we will respond within one month. A portable export of your data is available on request; a self-service export button is not yet in the app, and until it ships we will produce the export for you.

If you think we have handled your data badly, please tell us first. You always have the right to complain to the CNIL (Commission nationale de l'informatique et des libertés), or to the supervisory authority where you live.

Security

Data is encrypted in transit and at rest. Your session lives in the iPhone Keychain. Access to your rows is enforced by the database itself rather than by the app, so a bug in the app cannot expose another user's data. AI credentials are held on our server and never ship inside the app. No system is perfect; if we ever have a breach that puts you at risk, we will tell you and the supervisory authority as the law requires.

Children

Galb is not for people under 16. We do not knowingly collect data from anyone younger, and will delete it if we learn we have.

Changes

If we change what is processed or why, we will update this page and, where the change matters to you, ask again in the app rather than relying on you re-reading a policy. A change of AI provider always re-asks.

Effective 3 August 2026. Controller: FALL SERVICES. Privacy contact: contact@fallencompany.com · General support: contact@fallencompany.com

← Back to galb.app