Privacy Policy

Data & Privacy

Substrato operates on a Local-First architecture. Your nutritional protocols, meal history, and body metrics are stored on-device via SwiftData. We do not maintain external user accounts. Your data is your property.

​

Accounts & Cloud Sync

An account is optional and off by default. If you choose to sign in — with your email address through our authentication provider, Supabase — your protocols and profile can sync across your devices and be restored after reinstalling. What this involves:

  • What we store: your email address, your synced protocols and profile, and, if you set one, a profile photo. Nothing more.
  • How it travels: data is encrypted in transit (TLS) and at rest.
  • Deletion: you can delete your account from inside the app at any time. This permanently removes your account and its associated data from our systems.

​

If you never sign in, none of the above applies — your data stays on your device.

​

Coaching: Trainers & Athletes

Substrato lets a trainer prepare protocols for an athlete, and an athlete follow a trainer. This sharing is explicit and consensual:

  • A trainer invites an athlete using the athlete's email address, which serves only as a key to link the two accounts once the athlete accepts — no marketing email is ever sent.
  • After an athlete accepts an invitation, the trainer can create, send, and see the protocols associated with that athlete. A trainer never sees an athlete's private, self-authored protocols — only what belongs to the coaching relationship.
  • Either side can end the relationship. A trainer can cancel a pending invitation, which invalidates the invite link. Declining or removing severs the link and stops further sharing.
  • Push notifications (invitations, accepted plans) are delivered through Apple's Push Notification service if you enable them.

Your own personal protocols always remain separate from anything created in a coaching context.

​

Optional Profile Data

​

Two profile fields — date of birth and biological sex — are optional and blank by default. Their sole purpose is to enable the Evaluations feature: when a trainer is connected to your account, they can combine these values with caliper skinfold measurements they log for you to calculate body-composition metrics such as body-fat percentage.

​

  • These fields are visible only to you and to trainers you have explicitly accepted invitations from.
  • They are never used for advertising, analytics, or third-party sharing.
  • Leaving them blank simply disables the body-composition calculation; every other feature still works.
  • You may edit or clear them at any time from your Profile settings, and — if you have an account — deleting your account removes them along with the rest of your data.

​

Subscriptions & Payments

Some features are offered through a paid subscription. Payments are handled entirely by Apple through the App Store:

  • We never receive, see, or store your payment card or billing details. Apple processes the transaction.
  • We store only a record of whether your account holds an active entitlement, so the app can unlock the corresponding features. This status is delivered to us by Apple's App Store Server Notifications.
  • Subscriptions are managed, renewed, and cancelled through your Apple account settings, subject to Apple's terms.

​

The Accuracy Standard

  • Raw-to-Cooked Logic: All batch calculations utilize a moisture-loss coefficient derived from user-input weights. Precision is limited to the accuracy of your scale.
  • Rounding: Macros are displayed as integers. Calculations are performed to two decimal places to prevent aggregate drift in weekly views.

​

Telemetry

We do not use third-party trackers. Minimal, anonymous crash reporting is utilized solely to ensure database stability. We do not sell, trade, or export your habits.

​

Your Controls

  • Access & portability: your data lives on your device; synced data is tied to your account.
  • Deletion: delete your account in-app to erase your synced data, or simply remove the app to clear local data.
  • Notifications: manage push permissions in your device settings.
  • Rights: depending on where you live (including the EU/EEA under the GDPR), you may have rights to access, correct, or erase your personal data. Contact us to exercise them.

​

User Conduct

Substrato is a technical instrument. It assumes a baseline understanding of macronutrient therapy. It is not a medical advisor.

​

Changes & Contact

We may update this policy as the app evolves; the effective date above reflects the latest revision. Questions or requests: policy@substrato.app.

Privacy Policy

Data & Privacy

Substrato operates on a Local-First architecture. Your nutritional protocols, meal history, and body metrics are stored on-device via SwiftData. We do not maintain external user accounts. Your data is your property.

​

Accounts & Cloud Sync

An account is optional and off by default. If you choose to sign in — with your email address through our authentication provider, Supabase — your protocols and profile can sync across your devices and be restored after reinstalling. What this involves:

  • What we store: your email address, your synced protocols and profile, and, if you set one, a profile photo. Nothing more.
  • How it travels: data is encrypted in transit (TLS) and at rest.
  • Deletion: you can delete your account from inside the app at any time. This permanently removes your account and its associated data from our systems.

​

If you never sign in, none of the above applies — your data stays on your device.

​

Coaching: Trainers & Athletes

Substrato lets a trainer prepare protocols for an athlete, and an athlete follow a trainer. This sharing is explicit and consensual:

  • A trainer invites an athlete using the athlete's email address, which serves only as a key to link the two accounts once the athlete accepts — no marketing email is ever sent.
  • After an athlete accepts an invitation, the trainer can create, send, and see the protocols associated with that athlete. A trainer never sees an athlete's private, self-authored protocols — only what belongs to the coaching relationship.
  • Either side can end the relationship. A trainer can cancel a pending invitation, which invalidates the invite link. Declining or removing severs the link and stops further sharing.
  • Push notifications (invitations, accepted plans) are delivered through Apple's Push Notification service if you enable them.

Your own personal protocols always remain separate from anything created in a coaching context.

​

Optional Profile Data

​

Two profile fields — date of birth and biological sex — are optional and blank by default. Their sole purpose is to enable the Evaluations feature: when a trainer is connected to your account, they can combine these values with caliper skinfold measurements they log for you to calculate body-composition metrics such as body-fat percentage.

​

  • These fields are visible only to you and to trainers you have explicitly accepted invitations from.
  • They are never used for advertising, analytics, or third-party sharing.
  • Leaving them blank simply disables the body-composition calculation; every other feature still works.
  • You may edit or clear them at any time from your Profile settings, and — if you have an account — deleting your account removes them along with the rest of your data.

​

Subscriptions & Payments

Some features are offered through a paid subscription. Payments are handled entirely by Apple through the App Store:

  • We never receive, see, or store your payment card or billing details. Apple processes the transaction.
  • We store only a record of whether your account holds an active entitlement, so the app can unlock the corresponding features. This status is delivered to us by Apple's App Store Server Notifications.
  • Subscriptions are managed, renewed, and cancelled through your Apple account settings, subject to Apple's terms.

​

The Accuracy Standard

  • Raw-to-Cooked Logic: All batch calculations utilize a moisture-loss coefficient derived from user-input weights. Precision is limited to the accuracy of your scale.
  • Rounding: Macros are displayed as integers. Calculations are performed to two decimal places to prevent aggregate drift in weekly views.

​

Telemetry

We do not use third-party trackers. Minimal, anonymous crash reporting is utilized solely to ensure database stability. We do not sell, trade, or export your habits.

​

Your Controls

  • Access & portability: your data lives on your device; synced data is tied to your account.
  • Deletion: delete your account in-app to erase your synced data, or simply remove the app to clear local data.
  • Notifications: manage push permissions in your device settings.
  • Rights: depending on where you live (including the EU/EEA under the GDPR), you may have rights to access, correct, or erase your personal data. Contact us to exercise them.

​

User Conduct

Substrato is a technical instrument. It assumes a baseline understanding of macronutrient therapy. It is not a medical advisor.

​

Changes & Contact

We may update this policy as the app evolves; the effective date above reflects the latest revision. Questions or requests: policy@substrato.app.

Privacy Policy

Data & Privacy

Substrato operates on a Local-First architecture. Your nutritional protocols, meal history, and body metrics are stored on-device via SwiftData. We do not maintain external user accounts. Your data is your property.

​

Accounts & Cloud Sync

An account is optional and off by default. If you choose to sign in — with your email address through our authentication provider, Supabase — your protocols and profile can sync across your devices and be restored after reinstalling. What this involves:

  • What we store: your email address, your synced protocols and profile, and, if you set one, a profile photo. Nothing more.
  • How it travels: data is encrypted in transit (TLS) and at rest.
  • Deletion: you can delete your account from inside the app at any time. This permanently removes your account and its associated data from our systems.

​

If you never sign in, none of the above applies — your data stays on your device.

​

Coaching: Trainers & Athletes

Substrato lets a trainer prepare protocols for an athlete, and an athlete follow a trainer. This sharing is explicit and consensual:

  • A trainer invites an athlete using the athlete's email address, which serves only as a key to link the two accounts once the athlete accepts — no marketing email is ever sent.
  • After an athlete accepts an invitation, the trainer can create, send, and see the protocols associated with that athlete. A trainer never sees an athlete's private, self-authored protocols — only what belongs to the coaching relationship.
  • Either side can end the relationship. A trainer can cancel a pending invitation, which invalidates the invite link. Declining or removing severs the link and stops further sharing.
  • Push notifications (invitations, accepted plans) are delivered through Apple's Push Notification service if you enable them.

Your own personal protocols always remain separate from anything created in a coaching context.

​

Optional Profile Data

​

Two profile fields — date of birth and biological sex — are optional and blank by default. Their sole purpose is to enable the Evaluations feature: when a trainer is connected to your account, they can combine these values with caliper skinfold measurements they log for you to calculate body-composition metrics such as body-fat percentage.

​

  • These fields are visible only to you and to trainers you have explicitly accepted invitations from.
  • They are never used for advertising, analytics, or third-party sharing.
  • Leaving them blank simply disables the body-composition calculation; every other feature still works.
  • You may edit or clear them at any time from your Profile settings, and — if you have an account — deleting your account removes them along with the rest of your data.

​

Subscriptions & Payments

Some features are offered through a paid subscription. Payments are handled entirely by Apple through the App Store:

  • We never receive, see, or store your payment card or billing details. Apple processes the transaction.
  • We store only a record of whether your account holds an active entitlement, so the app can unlock the corresponding features. This status is delivered to us by Apple's App Store Server Notifications.
  • Subscriptions are managed, renewed, and cancelled through your Apple account settings, subject to Apple's terms.

​

The Accuracy Standard

  • Raw-to-Cooked Logic: All batch calculations utilize a moisture-loss coefficient derived from user-input weights. Precision is limited to the accuracy of your scale.
  • Rounding: Macros are displayed as integers. Calculations are performed to two decimal places to prevent aggregate drift in weekly views.

​

Telemetry

We do not use third-party trackers. Minimal, anonymous crash reporting is utilized solely to ensure database stability. We do not sell, trade, or export your habits.

​

Your Controls

  • Access & portability: your data lives on your device; synced data is tied to your account.
  • Deletion: delete your account in-app to erase your synced data, or simply remove the app to clear local data.
  • Notifications: manage push permissions in your device settings.
  • Rights: depending on where you live (including the EU/EEA under the GDPR), you may have rights to access, correct, or erase your personal data. Contact us to exercise them.

​

User Conduct

Substrato is a technical instrument. It assumes a baseline understanding of macronutrient therapy. It is not a medical advisor.

​

Changes & Contact

We may update this policy as the app evolves; the effective date above reflects the latest revision. Questions or requests: policy@substrato.app.