Privacy Policy
Last updated: August 12, 2026
App records and private iCloud sync
Your medication plan, injection history, symptoms, nutrition, movement, measurements, reflections, learning progress and Coach history are stored in the app's local database. On Apple devices signed in to iCloud, those records also synchronize through the private CloudKit database of your Apple ID so they can be available on your devices.
Sculpi does not create a separate account for this sync, does not put these records in CloudKit's public database, and does not use them for advertising or tracking. In the current Android release, app records remain local to the device.
Progress photos are encrypted with a device-only key and excluded from backups and CloudKit sync by default. Device preferences, permission choices and security credentials also remain device-only unless this policy says otherwise.
Apple Health and Health Connect
If you choose to connect Apple Health, Sculpi may read steps, body mass, height, waist circumference and state of mind, and may save the categories you separately approve. On Android, Health Connect access is likewise limited to the categories you approve. You control and can revoke each permission in system settings.
Health-platform data is used only for health and fitness features. It is not used for advertising or cross-app tracking.
Subscriptions
Apple or Google processes payment details. Sculpi requests localized product terms and verifies store transactions to determine feature access; it does not receive a full card or bank-account number. Free local features remain available when a store cannot be reached.
Optional remote Coach and meal recognition
Remote AI remains off until you choose to enable it and until Sculpi has published the configured processor. A Coach request may include your prompt, up to ten recent conversation turns and only the plan, recent-log, movement or learning summaries you explicitly attach. Those summaries omit notes, record identifiers, vendor and lot details, and exact timestamps. Coach cannot change medication, dose or protocol, and permitted app actions require local review and confirmation.
Meal recognition uploads a resized, re-encoded copy only after a separate confirmation. The original is not uploaded or added to progress photos. You review any estimate before saving it.
Remote prompts, selected summaries and meal-image copies may be retained for no more than 24 hours to service and protect a request. Operational metrics may be retained for up to 30 days and must exclude prompt text, health facts and image bytes. This data is not used for model training or advertising.
Permissions and optional care connection
Camera access supports food-barcode scans or a meal image that you separately approve for remote processing. Photo-picker content stays encrypted on device. Motion access supports walk steps, and notifications are used only for reminders and walk cues you enable.
If you connect a supported care-provider account, Sculpi processes an anonymous installation identifier, an encrypted connection credential and the provider's patient identifier. The email address or phone number you enter goes to that provider to start the connection. Provider profile, prescription and shipment information is requested only when needed to display it. Disconnecting revokes and deletes the stored connection.
Medication reminders remain local. Any later care shipment notification is restricted to a short-lived random event identifier and a route to the care screen; it must not contain medication, dose, provider, carrier, tracking number, shipment status or free text.
Optional diagnostics and remote content
If you separately consent, Sculpi may upload daily operational counters limited to subsystem, operation, outcome, app version and calendar day. The payload excludes health values, prompts, photos, contact details, identifiers, free text and an IP-address field. A receiving service may still observe connection metadata such as an IP address. Uploaded counters may be retained for no more than 30 days for reliability and incident response.
Remote editorial content and feature availability are accepted only from a size-limited, expiring configuration signed by Sculpi. If signature, approval or network validation fails, the app continues with bundled content and local features.
This website
Answers entered in the setup preview are held only in the open page. They are not saved, included in a URL or sent to Sculpi. Closing or reloading the page clears them.
Website analytics is unconfigured and off by default. If a named analytics processor and HTTPS endpoint are configured, a consent choice appears first. With consent, the site sends only one of five fixed events, an allowlisted page category, calendar day and site version—never health answers, a user or device ID, query string, referrer or free text. The processor may observe connection metadata and may retain the event for no more than 30 days. Your consent choice stays in this browser and can be changed from the footer.
Security, export and deletion
Sculpi uses platform data protection, Apple's private CloudKit and Keychain, encrypted HTTPS connections, and encryption for progress photos and provider credentials. The in-app Privacy screen can prepare a local JSON archive and PDF summary; encrypted photo bytes are excluded.
The in-app deletion control deletes app-owned records locally and sends record deletions to private CloudKit. If iCloud is unavailable, local deletion is saved and sync resumes later. Device-only preferences and encrypted photos are removed on the device where deletion is requested. Apple Health records remain under Apple Health controls.
Deleting the iOS app from one device removes that installation's local data but does not, by itself, delete the private CloudKit copy or records already synchronized to another device. Use the in-app deletion control before uninstalling if you want app-owned iCloud records removed.
Sharing and your choices
Sculpi shares information only with services needed for a feature you request, such as Apple's private CloudKit and Health services, a care provider you choose, or the disclosed AI processor when you enable a remote request, and when required by law. Sculpi does not sell personal or health information and does not permit cross-app tracking.
You can revoke permissions in system settings, revoke optional consent, export or delete app-owned records in the Privacy screen, disable remote AI and meal processing, and disconnect a care provider. To stop future iCloud sync, change iCloud access in system settings; delete existing private CloudKit records with the in-app control first.
Children, changes and contact
Sculpi is intended for adults age 18 or older and is not directed to children. If this policy changes, Sculpi will update the effective date and request review when required.
Questions, access, correction or deletion requests can be sent to privacy@sculpi.fit.