SculptR Privacy Policy

Last updated: 27 August 2026

This Privacy Policy explains what personal data the SculptR mobile app ("SculptR", "we", "us", "our") collects, how and why we use it, who we share it with, and the rights you have. It is written to meet the requirements of the UK GDPR and the EU General Data Protection Regulation (GDPR).

Who we are (data controller)

SculptR is operated by SCUPTR LTD, a company registered in England and Wales ("the controller"). For any privacy question or to exercise your rights, contact us at support@sculptr-app.com.

Information we collect

Legal bases for processing

Under the GDPR we rely on the following legal bases:

How we use your information

Teams (sharing with other users)

Teams is optional and off unless you create or join one. It is the only feature in SculptR that makes any of your information visible to another person. Nothing is shared with anyone until you take a deliberate action, and nothing is ever public: what you share is visible only to the members of the team or teams you belong to, never to other SculptR users, and never on the open internet.

Two kinds of information become visible to your teammates:

Photos and videos on posts. Anything you attach to a team post is uploaded to private storage hosted by Supabase and is served only through short-lived signed links to members of that team. Access is enforced by the storage layer itself, not just by the app. Deleting the post deletes the files with it, and you can delete your own posts at any time. Please do not attach anything you would not want your teammates to keep a copy of, since they can screenshot or save what they can see.

Reporting and blocking. Because members can put content in front of each other, every post has a report action and every comment can be reported by pressing and holding it, and you can block a member so their posts and comments disappear for you across every team you share. When you report something we record what you reported and why, and it is hidden from you immediately. We review reports and act within 24 hours, which may mean removing the content or removing the member's access. You can also email support@sculptr-app.com.

Because a published workout and a training streak can say something about your health, we treat this sharing as processing of special-category data and rely on your explicit consent, given by the act of joining a team and, for each post, by choosing to publish it.

What teams never expose. Your weight and weigh-in history, your body metrics, your food and calorie logs, your meal and workout plans, your check-in answers, your conversations with the AI coach, and your email address are never readable by other members. This is enforced in the database itself with row-level security, not only in the app: a team grants access to the counters and posts described above and to nothing else.

Your control. You can delete any post or comment you have made, and the team owner can remove posts from their team's page for moderation. Leaving a team removes you from its member list and stops your counters being shared with it. Deleting your account removes your posts, comments, likes, memberships and counters, and deletes any team you own along with its content. Note that other members may have already seen or copied what you published, which we cannot undo.

How and where your data is stored

Your account and synced data are stored using Supabase, our backend and database provider, over encrypted connections and with access restricted to your own account. Some data is also cached on your device so the app works offline.

Sub-processors we use

SupabaseAuthentication, database, cloud backup/sync, and private storage for photos and videos attached to team posts.
AnthropicAI model that generates plans, coaching replies and meal-photo estimates.
RevenueCatManages subscription entitlements and purchase status.
AppleSign in with Apple, Apple Health (opt-in), and App Store payment processing.
GoogleSign in with Google and Google Play payment processing (Android).
Open Food FactsLooks up product nutrition when you scan or enter a barcode.
US Department of Agriculture (FoodData Central)Looks up nutrition for generic whole foods.
ExpoDelivers push notifications to your device, for example when a teammate tags you.

We do not sell your personal data, and we do not use it for third-party advertising.

International data transfers

Some of our providers (including Anthropic and RevenueCat, and, depending on the hosting region, Supabase) process data on servers in the United States. Where your data is transferred outside the UK/EEA, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses (and the UK Addendum) and, where applicable, the providers' certification under the EU-US Data Privacy Framework.

Data retention

We keep your account and associated data for as long as your account is active. Team posts, their attached photos and videos, comments and likes are kept until you delete them, until the team is deleted, or until you delete your account, whichever comes first; leaving a team stops your counters being shared with it. Your profile picture is deleted when you remove it or delete your account. When you delete your account, we remove it from our live systems immediately and from encrypted backups within 30 days. Content sent to our AI provider may be retained by that provider for a limited period (up to around 30 days) to detect misuse, after which it is deleted. We may keep minimal records where required to comply with a legal obligation.

Your rights

Subject to the GDPR, you have the right to:

How to exercise your rights

Security

We protect your data with encrypted connections, database row-level security that limits each record to its owner, and server-side controls on sensitive actions. Photos, videos and profile pictures are held in private storage and are served through links that expire, rather than through public addresses, so they cannot be fetched by anyone outside the team they were shared with. No system is perfectly secure, but we work to protect your information.

Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and we will inform affected users without undue delay where the risk is high.

Children

SculptR is not directed to children under 13, and we do not knowingly collect their data. In the EU, where the applicable digital-consent age is higher than 13, users below that age should only use SculptR with the consent of a parent or guardian.

Complaints and disputes

If you are unhappy with how we have handled your personal data, tell us first at support@sculptr-app.com and we will try to put it right. You always have the right to complain to a data protection regulator: in the UK that is the Information Commissioner's Office (ico.org.uk), and in the EU it is the supervisory authority for the country where you live. Nothing in this policy or in our Terms of Use takes that right away.

Disputes about the app itself, including how they are resolved and the arbitration terms that apply to users in the United States, are covered by section 13 of our Terms of Use.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, notified in the app.

Contact

Questions about this policy or your data? Email support@sculptr-app.com.

SculptR · Back to support