Privacy Policy
Last updated: 22 July 2026
I'm the person who built and runs Metabolistic, and I'm the one responsible for your data (the "data controller", in legal terms). This page explains what the app collects, why, who else touches it, and how you can see or delete any of it.
I've tried to write it the way I'd want it written for me: honestly, and without hiding the important bits under ten paragraphs of throat-clearing.
The short version
- I collect the email you sign up with, the weight and calorie numbers you log, and a few settings so the app remembers how you like it.
- Your weight and body-composition figures are health-adjacent data, so I treat them as sensitive and don't share or sell them — ever.
- I use a small number of service providers (Supabase, Google sign-in, Vercel, Resend) to actually run the app. They process data on my behalf, under contract.
- I run two privacy-friendly, cookieless analytics tools (Vercel Analytics and PostHog) that count page visits without tracking you across the web or building a profile.
- No advertising cookies. No behavioural tracking. No selling data. No data brokers.
- You can export or delete everything yourself, from inside the app, at any time.
What I collect, and why
Your account. When you create an account, I store your email address and an authentication record (handled by Supabase Auth — see below). If you sign in with Google, I receive your email address and basic profile info from Google so I can create and recognise your account. I never see your Google password.
The data you log. The heart of the app: the dates, body-weight, and calorie figures you enter or import, plus diet periods you define. If you enter a body-fat percentage, that's stored too. This is the data the whole tool exists to analyse for you — I can't give you your TDEE without it.
Weight, calorie intake and body-fat figures say something about your health. Under EU data-protection law that makes this sensitive personal data, and I handle it accordingly: it's only ever used to run your analysis, it's never shared with advertisers or data brokers, and you can wipe it at any time.
Your settings. Small preferences that make the app yours — your theme, your linked spreadsheet reference, and similar. Stored so the app remembers you between visits.
When you contact me. If you use the in-app contact or feedback form, I store the message and the email you gave, so I can read it and reply. The form has basic spam protection (a honeypot field and rate-limiting); it doesn't profile you.
Functional storage on your device. The app keeps a few small values in your browser's local storage so it can work and remember your choices — your theme, the last page you were on, a remembered body-fat estimate, and (once you're logged in) your sign-in session. These stay on your device, aren't used to track you, and are the kind of storage that's strictly necessary to run the app. That's why you won't see a cookie-consent pop-up: I don't set the kind of tracking or advertising cookies that would require one. (More on analytics below.)
Analytics
I want to know how many people visit and which pages help, so I can make the app better. For that I use two cookieless analytics tools — Vercel Analytics and PostHog (the latter hosted in the EU). Both are deliberately privacy-friendly and cookieless: they count page views and rough traffic patterns without using tracking cookies, without following you across other websites, and without building an advertising profile of you. PostHog runs in a cookieless, anonymous mode — it doesn't set cookies, doesn't store an identifier on your device, and its counts aren't tied to your account. Neither tool stores data that personally identifies you.
That's a conscious choice. Plenty of apps reach for Google Analytics or a Facebook pixel and then bolt on a consent wall to make it legal. I'd rather use analytics that respect you by default, so there's nothing to consent your way out of.
Who else processes your data
To actually run the app I rely on a handful of trusted providers. They act as my processors — they handle data on my instructions, under a data-processing agreement, and can't use it for their own purposes:
| Provider | What it does | What it touches | |---|---|---| | Supabase | Database + authentication — where your account, logged data and settings live | Account, logged weight/calorie data, settings | | Google | Optional "Sign in with Google" | Your email + basic profile, only if you choose Google sign-in | | Vercel | Hosting, and cookieless analytics | Page requests; aggregate visit stats | | PostHog | Cookieless, anonymous analytics (page visits only), EU-hosted | Page requests; aggregate visit stats | | Resend | Sends transactional email (e.g. replying to a contact-form message) | The email address + message involved |
That's the whole list. I don't add advertising networks, data brokers, or social-media trackers.
Your account and logged data are stored in the European Union — the database is hosted in the Supabase Europe (Ireland) region. Some of the other providers (such as Google sign-in, or email delivery) may process limited data outside the EU; where that happens, it's covered by the standard safeguards those providers offer, such as the EU Standard Contractual Clauses.
The legal basis (for the EU/GDPR-minded)
- Running your account and analysing your data — because it's necessary to provide the service you asked for (contract).
- Your sensitive health-adjacent data — processed on the basis that you provided it yourself to get the analysis, and you can withdraw it by deleting it at any time.
- Cookieless analytics and basic security — my legitimate interest in keeping the app working and understanding roughly how it's used, balanced so it stays non-intrusive.
How long I keep it
Your logged data and account stay for as long as your account exists — the whole point is a long-term record you can compare against later, so I don't quietly age it out. When you delete data or your account (see below), it's removed. Contact-form messages are kept only as long as I need them to handle your enquiry.
Your rights, and the buttons that honour them
You have the right to access, correct, export, and delete your data, and to object to or restrict how it's processed. What matters more than the legal list is that the app actually gives you the controls:
- Export — your logged data lives in a table you can copy out, and if you linked a spreadsheet, it's already yours.
- Delete all your data — one control in your account wipes every figure you've logged while keeping the account itself.
- Delete your whole account — a second control removes the account and everything attached to it.
If you'd rather I handle any of this by hand, or you want to exercise a right the buttons don't cover, just contact me (below). If you're in the EU and think I've mishandled your data, you also have the right to complain to your national data protection authority — though I'd appreciate the chance to put it right first.
Security
Data is stored with Supabase's row-level security, so one account can't read another's data, and access is protected by your sign-in. No system is perfectly secure, but I keep the surface small on purpose — fewer providers, no needless data collection, nothing sold on.
Children
Metabolistic isn't intended for children under 16, and I don't knowingly collect their data.
Changes to this policy
If I change how data is handled, I'll update this page and move the "last updated" date. If a change is significant — say, a new analytics tool that would need your consent — I'll ask for that consent rather than sneak it in.
Contact
Questions about your data, or want something deleted by hand? Use the contact form in the app — it reaches me directly, and it's the best way to get hold of me about anything privacy-related.