Slimmy
Privacy Policy - Slimmy App

Privacy Policy - Slimmy App

Last update: 22 June 2026

1. Data Controller

The data controller of personal data is:

Nova Service FCO S.r.l.
Via della Foce Micina 10/L
00054 Fiumicino (Rome) - Italy
Privacy email: privacy@slimmy.app
General email: info@slimmy.app

Hereinafter referred to as "Controller", "Company", "We" or "Our".

2. Scope

This Privacy Policy describes how Slimmy App collects, uses, stores, and protects the personal data of users who use the application, the website, and related services.

By using Slimmy App, the user declares to have read and understood this notice.

3. Types of Data Collected

3.1 Registration and Account Data

  • First and last name
  • Username or nickname
  • Email address
  • Password in encrypted or protected form
  • Profile picture, if provided by the user
  • Date of birth, if requested or provided
  • Gender, if provided by the user
  • Language, country, and account preferences

3.2 Weight, Wellness, and Personal Goals Data

  • Body weight and history of recordings
  • Height
  • Personal goals set by the user
  • Progress, statistics, and trends over time
  • Food preferences, allergies, or information voluntarily entered by the user
  • Declared or calculated physical activity level

3.3 Physical Activity and Geolocation Data

  • GPS location during walks or tracked activities, only if authorized by the user
  • Routes, distance, duration, speed, and activity-related information
  • Background location data, if the user grants the relevant permission
  • Technical data necessary for the proper functioning of tracking

3.4 Data from Apple Health and Google Health Connect

Upon the user's explicit consent, Slimmy may access data from Apple Health on iOS and Google Health Connect on Android.

  • Daily steps
  • Distance covered
  • Active calories
  • Workouts and physical activities
  • Body weight and other data expressly authorized by the user

3.5 User-Generated Content

  • Posts, texts, and comments published in the social feed
  • Photos uploaded by the user
  • Progress photos
  • Content shared in challenges or in the community
  • Voice messages or audio content, if used in the available features
  • Images submitted for any AI transformation features

3.6 Camera, Microphone, and Photo Library Data

  • Camera access to take photos to publish or use within the app's features
  • Photo library access to select images to upload
  • Microphone access to record voice messages or use audio features

3.7 Technical and Usage Data

  • IP address
  • Device type
  • Operating system and app version
  • Technical identifiers of the device or installation
  • Access logs, diagnostics, errors, and crashes
  • Push notification tokens
  • Information on the use of the app's features

3.8 Subscription and Purchase Data

  • Premium subscription status
  • Type of plan purchased
  • Activation, renewal, and expiration dates
  • Technical information provided by Apple, Google, or RevenueCat to verify the subscription

4. Purposes of Processing

Personal data is processed for the following purposes:

4.1 Service Provision

  • Creation and management of the user account
  • App access and authentication
  • Weight and progress tracking
  • Management of personal goals
  • Management of the community, social feed, comments, and challenges
  • Tracking of walks and physical activities
  • Integration with Apple Health and Google Health Connect
  • Activation and verification of Premium subscriptions

4.2 AI Features

  • Generation of dietary suggestions or recipes
  • Image processing for Premium features
  • Personalization of the user experience

4.3 Communications

  • Sending service-related push notifications
  • Technical and administrative communications
  • Communications regarding updates, security, or changes to the terms
  • Newsletters or promotional communications only with prior consent, where applicable

4.4 Security and Improvement

  • Prevention of fraud, abuse, and unauthorized access
  • Resolution of technical problems
  • Aggregate statistical analysis of app usage
  • Development and improvement of new features

4.5 Legal Obligations

  • Tax and accounting obligations
  • Responding to requests from competent authorities
  • Protection of the rights of the Company or third parties

5. Legal Basis for Processing

  • Contract performance: to provide the service requested by the user.
  • Consent: for health data, Apple Health, Google Health Connect, geolocation, push notifications, camera, microphone, and promotional communications, where required.
  • Legitimate interest: for security, fraud prevention, technical improvement of the service, and protection of rights.
  • Legal obligation: for tax, accounting obligations, or requests from authorities.

6. Special Categories and Health-Related Data

Some data processed by Slimmy, such as weight, physical activity, goals, data from Apple Health or Google Health Connect, and information related to personal wellness, may be considered special categories or health-related data under the GDPR.

Such data is processed exclusively on the basis of the user's explicit consent and only to provide the requested features.

The user may withdraw consent at any time from the device settings, the app settings, or by contacting the Company.

7. Apple Health and Google Health Connect

Slimmy may integrate features with Apple Health and Google Health Connect only upon the user's consent.

Data obtained through these platforms:

  • is used exclusively to display statistics, progress, and information related to the user's wellness;
  • is not sold to third parties;
  • is not used for advertising, behavioral marketing, or advertising profiling;
  • is not shared with data brokers;
  • can be revoked at any time through the Apple Health, Google Health Connect, or device settings.

8. Geolocation and Activity Tracking

The App may request access to the device's location to track walks, routes, distance, and physical activities.

If the user authorizes background location, Slimmy may continue to collect GPS data during an activity even when the app is not visible on screen or the device is locked.

The user can disable location access at any time from the device settings.

9. Camera, Microphone, and Photo Library

Slimmy may request access to the camera, microphone, and photo library to allow the user to use specific features.

  • The camera can be used to take photos to publish or process.
  • The photo library can be used to select images to upload to the app.
  • The microphone can be used to record voice messages or use audio features.

These permissions are optional and can be revoked at any time from the device settings.

10. Push Notifications

Slimmy may send push notifications related to the service, activities, challenges, reminders, the community, and important updates.

Services such as Firebase Cloud Messaging, OneSignal, or similar technical providers may be used to send notifications. The user can disable notifications from the device settings.

11. Subscriptions, Payments, and RevenueCat

Purchases made through the iOS app are managed by Apple via the App Store's In-App Purchase system.

Slimmy may use RevenueCat or similar services to verify subscription status, manage renewals, expirations, purchase restoration, and access to Premium features.

The Company does not store the user's full payment card details.

12. Providers and Data Processors

Data may be processed by technology providers necessary for the provision of the service, including, by way of example:

  • MongoDB Atlas: database hosting and data infrastructure.
  • OpenAI: AI processing for suggestions and intelligent features.
  • Fal.ai: image processing and visual AI features.
  • Firebase: push notifications, diagnostics, or technical services.
  • OneSignal: push notification management, if enabled.
  • RevenueCat: subscription management and verification.
  • Google: authentication, Android services, or Health Connect, where used.
  • Apple: In-App Purchase, Apple Health, iOS services.
  • Resend or email providers: sending transactional emails.

These providers process data in accordance with their respective terms, policies, and applicable data processing agreements.

13. Visibility of Content in the Community

Content published by the user in the social feed, challenges, or public areas of the app may be visible to other users.

The user is responsible for the content they choose to publish and can avoid sharing personal or sensitive information in public areas.

14. Data Transfers Outside the EU

Some providers may have their headquarters or infrastructure outside the European Union, including the United States.

In such cases, the transfer of data takes place on the basis of suitable legal instruments, such as adequacy decisions, the Data Privacy Framework, Standard Contractual Clauses, or other appropriate safeguards provided for by the GDPR.

15. Data Retention

  • Account data: until account deletion or for the period necessary to manage the service.
  • Weight, wellness, and activity data: until account deletion or a deletion request.
  • HealthKit / Health Connect data: until consent withdrawal or account deletion, unless otherwise chosen by the user.
  • GPS data: until deletion of the activity or the account.
  • Tax or administrative data: for the period required by law, normally up to 10 years.
  • Technical and security logs: for a limited period, normally up to 12 months, unless required for security or protection of rights.
  • Marketing data: until consent withdrawal.

16. Account Deletion

The user can delete their account directly from the app via the "Delete Account" function available in the profile settings.

Deletion entails the removal of personal data associated with the account, except for that which the Company is required to retain for legal obligations, tax purposes, fraud prevention, security, or protection of its rights.

17. User Rights

Under the GDPR, the user can exercise the following rights:

  • Access to personal data
  • Rectification of inaccurate data
  • Erasure of data
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Withdrawal of consent
  • Lodging a complaint with the supervisory authority

To exercise these rights, the user can write to: privacy@slimmy.app.

18. Data Security

The Company adopts appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit via HTTPS/TLS
  • Access control measures
  • Backups and monitoring systems
  • Restriction of data access to authorized personnel and providers
  • Security procedures to prevent unauthorized access, loss, or disclosure of data

19. Cookies, Local Storage, and Similar Technologies

The app and the website may use cookies, localStorage, sessionStorage, or similar technologies to maintain the login session, store preferences, improve performance, and ensure the proper functioning of the service.

We do not use such technologies to sell personal data or for third-party behavioral advertising.

20. Minors

The service is not intended for individuals under the age of 16. We do not knowingly collect personal data from individuals under 16.

If a parent or guardian believes that a minor has provided us with personal data, they can contact us to request its deletion.

21. Changes to the Privacy Policy

This Privacy Policy may be modified or updated. Significant changes will be communicated through the app, the website, or other appropriate channels.

22. Complaints

The user has the right to lodge a complaint with the Italian Data Protection Authority:

Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Rome, Italy
Website: www.garanteprivacy.it
Email: protocollo@gpdp.it

23. Contact

For any questions regarding this Privacy Policy or the processing of personal data, you can contact us:

Nova Service FCO S.r.l.
Via della Foce Micina 10/L
00054 Fiumicino (Rome) - Italy

Privacy email: privacy@slimmy.app
General email: info@slimmy.app

© 2026 Slimmy.com - All rights reserved