GoGetup helps you track meals, water, weight, fasting, and diet plans, and reads lab reports and step data to help you understand your nutrition — using AI to do the heavy lifting. This page explains exactly what we collect, why, who else ever sees it, what rights you have wherever you live, and how to delete it.
GoGetup is developed and operated from India, so this policy is written to meet India's Digital Personal Data Protection Act, 2023 (DPDPA) first, alongside the major international frameworks (GDPR, CCPA/CPRA) that apply to our users elsewhere.
This app handles sensitive health information — blood markers, medical conditions, meals, and body metrics. India's DPDPA and the EU/UK GDPR both single out data like this for extra protection ("special category" data under GDPR), and a growing number of US states regulate consumer health data specifically, separately from general privacy law. We treat everything in Section 1 marked health-related with that higher standard throughout this policy, not just in name.
We only collect what the app needs to do the things you ask it to do.
Your email address, and whether you signed in with Google or email/password. If you use Google Sign-In, we receive your Google account's name, email, and profile photo — nothing else.
Age or date of birth, sex, height, weight, diet type, allergies, dislikes, medical conditions you choose to tell us, and lifestyle context (sleep, activity level, cooking time, focus areas) used to personalize diet plans.
Meals you log — including any photo you take of a plate or barcode — water intake, weight entries, fasting sessions, and any medications, reminders, or weekly tasks you set up.
Photos or PDFs of lab reports you upload, and the marker values (like blood sugar or haemoglobin) our AI extracts from them.
If you log something by voice, the recording is sent for transcription and is not stored by us afterward — only the resulting text is saved.
If you allow it, we tag a best-effort GPS location on photo or barcode scans. This never blocks logging — it's skipped silently if you decline permission.
If you connect Android Health Connect, we read your step count to estimate calories burned. Nothing is read unless you explicitly grant that permission.
Google AdMob shows in-app banner ads and, on the free daily limit for a feature like meal scanning, an optional rewarded ad that unlocks one extra use for the day. AdMob uses your device's advertising ID to do this. We do not send your health, nutrition, or profile data to AdMob, and we do not use it to build an advertising profile of you.
A push-notification token (so reminders can reach your device) and basic crash/error logs.
We do not sell your data or share it with data brokers, and we never use your health information to train a general-purpose AI model. The app does show ads through Google AdMob (Section 3) — AdMob receives your device's advertising ID to do this, but never your health, nutrition, or profile data, and that data is never used to target ads.
Certain features send data to specialised outside services to do their job — for example, a meal photo has to reach a vision model to be identified. Each provider only receives what that specific feature needs, and only to fulfil your request in the moment.
| Provider | What it receives | Why |
|---|---|---|
| AI processing partners | Meal & barcode photos, blood-report photos and PDFs, voice recordings, profile/goal text | Meal detection, diet-plan generation, blood-report reading, voice transcription |
| Google Sign-In | Your Google account info, if you choose this sign-in method | Authentication |
| USDA / Nutritionix / Open Food Facts | Food names or scanned barcodes | Looking up nutrition facts |
| Google AdMob | Your device's advertising ID | Serving in-app banner and rewarded ads |
| Supabase | Everything you store in the app | Our database, file storage, authentication, and backend functions |
Each of these providers has its own privacy policy governing how it handles what it receives. We choose providers with clear no-training/no-retention terms where possible, but we don't control their infrastructure directly.
Your data lives in a Supabase-hosted database and file storage, encrypted in transit (HTTPS/TLS) and encrypted at rest on your device for your session credentials. Every table and every file is access-controlled at the database level so that you can only ever read or write your own data — not another user's, and not us casually browsing it. Meal photos and blood reports sit in private storage buckets that are never publicly accessible.
If a data breach ever puts your information at risk, we will notify affected users and the relevant regulators without undue delay, as required by applicable law.
Under India's DPDPA, 2023, our primary basis for processing is your consent — given as a "Data Principal" when you create an account and actively use each feature (this notice, together with the in-app permission prompts for camera, location, and Health Connect, is how we give you notice before collecting anything). Where other privacy law requires a different named basis (for example, the EU/UK GDPR), we rely on:
View or edit almost everything you've entered directly in the app — profile, goals, meals, reminders, and more.
Export a CSV of your full meal, water, and weight history any time, from Progress → Export everything.
Delete individual items — any meal, reminder, medication, weekly task, or blood report — with a tap, right where you see it.
Delete your entire account from Progress → Account → Delete account. This is immediate, permanent, and removes every row of your data — there's no recovery window.
Wherever you live, you can also ask us directly (Section 12) to:
If you're in the EU, UK, or another jurisdiction with its own data-protection authority, you also have the right to lodge a complaint with that authority directly — you don't need to contact us first.
GoGetup is a small team and doesn't currently have a statutorily-required EU/UK representative or Data Protection Officer appointed — our contact email (Section 12) is your point of contact for every privacy matter in the meantime, and we'll appoint one if our EU/UK user base grows to where the law requires it.
As a Data Principal under the DPDPA, you have the right to: obtain a summary of the personal data we hold about you and what we're doing with it; correct, complete, update, or erase your data; withdraw consent as easily as you gave it; nominate another individual to exercise these rights on your behalf if you become incapacitated or die; and file a grievance with us first, and with the Data Protection Board of India if you're not satisfied with our response. For grievances under the DPDPA, our Grievance Officer can be reached at the email in Section 12.
We do not sell your personal information. In-app ads are served through Google AdMob using a consent flow (Google's User Messaging Platform) shown before any ad request — you control ad personalization there and in your device's ad settings. You have the right to know what's collected, delete it, correct it, opt out of the sale or sharing of personal information and the use of sensitive personal information for advertising, and limit use of sensitive personal information — and we will not discriminate against you, with reduced service or a worse experience, for exercising any of these rights.
Washington's My Health My Data Act specifically protects "consumer health data" like the nutrition, weight, and blood-marker information this app collects. In addition to the rights above, Washington residents can withdraw consent to our collection or sharing of consumer health data at any time (Section 12), and we do not use geofencing around any healthcare facility for advertising, tracking, or data collection.
For Canadian residents, our legal basis is your meaningful consent — express, given by actively signing up and using each feature. You have the right to access and correct the personal information we hold about you, and to challenge our compliance with Canadian privacy law by contacting us (Section 12) or the Office of the Privacy Commissioner of Canada.
AI-generated diet plans and blood-marker flags are informational suggestions, not automated decisions that produce legal or similarly significant effects on their own — nothing in the app automatically approves, denies, or restricts anything for you without a human (you, or a doctor you consult) making the actual call.
GoGetup is developed and operated from India, and is available worldwide — your data may be processed and stored on servers outside your own country, wherever our providers (Section 3) operate their infrastructure. India's DPDPA generally permits transferring personal data outside India, except to a small list of countries the Indian government may specifically restrict from time to time. Where other law requires a specific safeguard instead (for example, transfers of EU/UK personal data outside the EEA/UK), we rely on the mechanism our provider has in place for that transfer, such as Standard Contractual Clauses.
We keep your data for as long as your account is active, so the app can keep showing you your own history. Deleting a single item (a meal, a report, etc.) removes it immediately. Deleting your account removes everything, everywhere, right away — we don't keep a backup copy "just in case."
GoGetup is an informational wellness tool, not a medical device or a substitute for professional care. AI-extracted blood markers and AI-generated diet plans can be wrong or incomplete. We refuse to generate a diet plan when a blood report shows critical values and tell you to see a doctor instead — but that safeguard is not a diagnosis, and it doesn't replace one. Always confirm anything health-related with a qualified professional.
GoGetup is not directed at children under 18 — the highest of the age thresholds used by major privacy laws we're subject to, including India's DPDPA (18, with verifiable parental consent required below that age), COPPA (13) in the US, and GDPR (13–16, depending on country) in the EU — and we do not knowingly collect data from anyone under that age. If you believe a child has created an account, contact us (Section 12) and we'll delete it.
If we materially change how we handle your data, we'll update the effective date above and let you know inside the app before the change takes effect.
Questions, requests, or concerns about your data — including any of the rights in Section 6, and DPDPA grievances (Section 6) — reach us at privacy@gogetup.app. For general support, support@gogetup.app. We're a small team, but a real person reads and responds to every message.