- Corely does not sell your personal information or health data.
- Corely does not use Apple Health or Health Connect data for advertising or marketing.
- Connecting Apple Health or Health Connect is optional, and you choose which permissions to grant.
- If you sign in, certain Corely data is automatically synchronized and backed up using Google Firebase so it can be restored across devices or after reinstalling the app.
1. Who we are
Corely is a fitness, workout, nutrition, fasting, and progress-tracking application. For purposes of applicable privacy laws, Corely is the controller of personal information processed through the Corely app and website, except where a third-party service acts as an independent controller under its own terms.
Privacy questions and requests can be sent to corely.fit.corely@gmail.com.
2. Information we collect
- Account and authentication information. If you create or sign in to an account, Corely may process your email address, Firebase user identifier, authentication provider, and related sign-in information.
- Profile, goals, and preferences. Information you choose to provide or configure, such as fitness goals, training preferences, available equipment, workout-plan preferences, units, notification preferences, and other app settings.
- Workout information. Workout sessions, exercises, sets, repetitions, load/weight, duration, completion information, session feedback, estimated or imported calories, and related progress information.
- Nutrition information. Foods and meals you log, calories, protein, carbohydrates, fat, serving information, favorites/recent foods, and other nutrition-tracking information.
- Fasting information. Fasting plans, schedules, fasting sessions, timing information, and related preferences and progress.
- Body and weight information. Information you enter manually, such as weight and, where supported, body-fat percentage, lean mass, or basal metabolic information.
- Optional health-platform information. If you connect Apple Health on iOS or Health Connect on Android, Corely may read the specific health and fitness data types you authorize, as described below.
- Purchase and subscription information. Subscription product, entitlement/status, renewal or expiration information, purchase history/status, and identifiers used to associate a subscription with your Corely account. Corely does not receive your full payment-card number from Apple or Google.
- Barcode information. When you use the nutrition barcode scanner, Corely uses the camera to read the barcode. The barcode number may be sent to Open Food Facts to retrieve product and nutrition information. Corely does not need to upload a photo of the product to perform this lookup.
- Device, diagnostics, analytics, and notification information. App version, operating-system/device information, crash and error diagnostics, basic app-use events, and push-notification tokens or delivery information used to operate, secure, troubleshoot, and improve Corely.
- Support and feedback information. Information you include when contacting support or submitting feedback.
3. Apple Health and Health Connect
Connecting a health platform is optional. Corely requests only the permissions needed for the features you choose to enable. Depending on your selections and what is available from your device/provider, Corely may read:
- workouts and exercise sessions;
- steps;
- active calories and related workout-energy information;
- weight;
- body-fat percentage;
- lean body mass; and
- basal metabolic rate (BMR), where available.
If you enable Write Corely workouts, Corely may also write workouts you complete in Corely, including workout timing and calorie information, back to Apple Health or Health Connect.
Corely uses this information to show activity and body-metric history, match workout activity, improve calorie/activity context, personalize fitness-related features, and provide progress views. Corely does not use information obtained through Apple Health or Health Connect for advertising, marketing, or sale to data brokers.
You can grant, deny, or revoke individual health permissions through Apple Health/iOS settings or Health Connect/Android settings. Revoking permission prevents future access through that health platform, but information that was previously imported into Corely may remain in Corely until you delete it or your Corely account, subject to the retention terms below.
Cloud note for signed-in users: certain imported workout/activity records and summarized activity information may be stored in Corely and may be included in Corely cloud backups so your Corely data can be restored. Corely does not use this information for advertising or marketing.
4. Cloud synchronization and backup
Corely is designed so signed-in users can recover important app data. When you are signed in, certain data is automatically synchronized or backed up using Google Firebase. This is not limited to a separate manual “cloud sync” switch.
- Firestore synchronization may include workout sessions and sets, nutrition day logs and entries, fasting sessions, and related fasting-day records.
- Cloud backups may include workout, nutrition, fasting, imported workout/activity records, activity summaries, and app preferences/settings used to restore your Corely experience.
Some information remains local to your device and is not necessarily included in every sync or backup. Signing out stops new authenticated synchronization from that account, but previously stored cloud data remains associated with the account until it is deleted under the account-deletion process or otherwise removed under this policy.
5. How we use information
- Provide the workout, nutrition, fasting, weight, progress, and coaching features you request.
- Generate and personalize workout plans, exercise selections, progression guidance, nutrition targets, fasting schedules, and progress insights.
- Synchronize and restore signed-in user data.
- Manage subscriptions and determine access to Corely Pro features.
- Send reminders and push notifications you have enabled.
- Operate, secure, diagnose, maintain, and improve Corely.
- Prevent abuse, investigate technical problems, and protect users and the service.
- Respond to support requests and communicate important service, security, or policy updates.
- Comply with legal obligations and enforce our Terms of Service.
Corely may use automated rules and algorithms to personalize fitness and wellness recommendations. These recommendations are intended to assist you and do not make legal or similarly significant decisions about you.
6. Service providers and sharing
Corely does not sell your personal information. We may provide information to service providers that help us operate the app, subject to their role and applicable terms. Current services may include:
- Google Firebase — authentication, Firestore database, cloud storage/backups, analytics, crash diagnostics, push notifications, app integrity/security, and related infrastructure.
- RevenueCat — subscription and entitlement management. Corely may associate a RevenueCat customer/app-user identifier with your Corely/Firebase account identifier and subscription status.
- Apple App Store and Google Play — purchase processing, subscription billing, receipts, renewals, cancellations, and store-level transaction records.
- Open Food Facts — product and nutrition lookup when you scan or look up a supported food barcode.
We may also disclose information when reasonably necessary to comply with law or legal process; protect the rights, safety, and security of Corely, our users, or others; investigate fraud or abuse; enforce our agreements; or in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law.
Health information obtained through Apple Health or Health Connect is not shared for advertising, marketing, or data-broker purposes.
7. Analytics, diagnostics, and notifications
Corely uses Firebase Analytics for limited product/usage measurement, Firebase Crashlytics for crash and error diagnostics, and Firebase Cloud Messaging for push notifications. These services may process app/device identifiers, technical information, event information, crash details, and notification tokens as needed to provide those functions.
Crash reporting is configured primarily for release builds. Notification permissions are controlled through your device settings, and you can disable notifications at any time.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including providing Corely, maintaining account continuity, meeting legal obligations, resolving disputes, and protecting the service.
- Account and Corely cloud data generally remains associated with your account while the account is active.
- Fitness, nutrition, fasting, and optional health-derived information may remain locally on your device and, where described above, in Corely cloud systems until deleted, replaced by newer backups, or removed through account deletion.
- Purchase and transaction records may be retained by Apple, Google, RevenueCat, or Corely as necessary for subscription management, fraud prevention, accounting, tax, dispute, or legal obligations.
- Analytics and diagnostic information is retained according to the applicable service configuration and provider retention settings and only as long as reasonably necessary for the stated purposes.
When deletion is requested, we delete or de-identify Corely-controlled personal data within a reasonable period unless retention is required or permitted by law. Information held independently by Apple, Google, or other third parties may be subject to their own retention rules.
9. Security
We use reasonable technical and organizational safeguards designed to protect personal information, including authenticated access controls and encrypted network transmission where supported by our service providers. We also use Firebase App Check and platform integrity mechanisms to help reduce unauthorized access. No method of electronic transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your choices and controls
- You can use many Corely features without connecting Apple Health or Health Connect.
- You can change or revoke health permissions at any time in your device settings.
- You can control push-notification permission through device settings and Corely notification preferences.
- You can sign out of your account to stop new authenticated synchronization for that account.
- You can request deletion of your Corely account and associated Corely-controlled data.
- Depending on where you live, you may also have rights to access, correct, export, restrict, object to certain processing, or delete personal information.
11. Account and data deletion
You can use Corely’s account-deletion feature or the instructions on our deletion page. We may need you to sign in again or verify your identity before completing a deletion request for security reasons.
Deleting Corely does not automatically cancel an App Store or Google Play subscription. Subscription cancellation is handled through the store where the purchase was made.
12. EEA, UK, and similar privacy rights
If the GDPR, UK GDPR, or a similar law applies to you, Corely processes personal information under one or more of the following legal bases:
- Performance of a contract — to create and maintain your account, provide requested Corely features, synchronize data, and manage subscription access.
- Consent — for optional permissions and processing where consent is required, including optional access to Apple Health or Health Connect and, where applicable, processing health-related information as special-category data. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
- Legitimate interests — to secure, troubleshoot, maintain, and improve Corely, prevent abuse, and understand basic service performance, where those interests are not overridden by your rights.
- Legal obligations — when processing is required to comply with applicable law, tax/accounting requirements, legal process, or enforceable requests.
Where these laws apply, you may have the right to request access to your personal data, correction, deletion, restriction of processing, data portability, and objection to certain processing. You may also have the right to lodge a complaint with the data-protection authority in the country where you live, work, or believe a violation occurred.
Corely and its service providers may process information in the United States and other countries where they operate. Where required, international transfers are handled using legally recognized safeguards made available by Corely’s service providers or other lawful transfer mechanisms. You may contact us for more information about applicable safeguards.
13. U.S. state privacy rights
Depending on your state of residence and subject to applicable exceptions, you may have rights to know or access personal information, correct inaccuracies, request deletion, obtain a portable copy, and opt out of certain forms of sale, sharing, or targeted advertising. Corely does not sell personal information and does not use Apple Health or Health Connect data for targeted advertising.
To exercise a privacy right, contact us at corely.fit.corely@gmail.com. We may need to verify your request before acting on it.
14. Children’s privacy
Corely is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If a higher minimum age or parental-consent requirement applies where you live, you should use Corely only if those requirements are satisfied. If you believe a child has provided personal information in violation of applicable law, contact us so we can review and take appropriate action.
15. Third-party services and links
Third-party services used by or linked from Corely have their own privacy practices. Their handling of information may be governed by their own policies and terms. Corely is not responsible for the privacy practices of third-party websites or services that operate independently of Corely.
16. Changes to this policy
We may update this Privacy Policy as Corely changes or as legal requirements evolve. If we make material changes, we will update the effective date and provide additional notice where required.
17. Contact
For privacy questions, requests, or complaints, contact corely.fit.corely@gmail.com.