Privacy Policy
Version 1.9 · Effective September 17, 2026
Health data is also covered by our separate Consumer Health Data Privacy Policy.
Who we are
The Idunia app is a US-only mobile app for adults (18+) that helps female athletes track nutrition and training. The app and its website, idunia.getmaxoutput.com, are operated by Max Output LLC (North Carolina). Contact: founders@maxoutput.ai.
What we collect
- Account info: email and authentication data, so you can log in.
- Health data you enter: nutrition, training, body metrics, and — only if you opt in — cycle data. Detailed in our separate Consumer Health Data Privacy Policy.
- Subscription status: your purchase and subscription state, so we can unlock the paid app and restore your access across reinstalls. Handled by our billing provider, RevenueCat (see "Subscriptions & billing" below).
- Feedback you send us: if you use the in-app Feedback feature, the text you type and any photos or screenshots you attach. Stored privately; only we can read it (see "Feedback" below).
- We do not collect precise location, advertising identifiers, or contacts.
- In the app, we do not collect diagnostics or crash logs in v1.
- What the website records is described under "This website" below.
What we DON'T do
- We do not sell your data.
- We do not share your data from the app with advertisers, analytics providers, or social platforms.
- We have no third-party advertising, analytics, attribution, or tracking software in the app.
- We do not use your data to build advertising profiles or to train models for anyone else.
Where your data lives and how it's protected
- Your cycle data is stored only on your device, in an encrypted file whose key is held by your device's operating system. It is never sent to our servers, so we cannot access it. The one exception is a photo or screenshot you deliberately choose to attach to the in-app Feedback feature: if it shows cycle information, that image is uploaded as feedback content, not as your cycle data (see Feedback below).
- Account and other data are stored on our hosted backend, provided by Supabase, Inc. as our service provider: a company we hire solely to run the app and website, contractually prohibited from using your data for its own purposes. Data is encrypted in transit (TLS) and at rest; access is limited to operating the app and website.
- With your in-app consent, meal text you type, meal photos you submit, recipe page text you share in, and training descriptions you type are processed by AWS (Amazon Bedrock), running Amazon Nova (an Amazon-built model), to structure them into entries you review (see "AI parsing" below). AWS is a service provider acting only for us.
- When you scan a food barcode, the barcode number (UPC) is sent to Open Food Facts, the public food database, to identify the product; no identity accompanies it.
- When you subscribe, your account identifier and purchase/subscription events are processed by RevenueCat, Inc., our subscription-billing provider, to manage your access (see "Subscriptions & billing" below). RevenueCat is a service provider acting only for us.
- Using a service provider to store or process your data for you is not "sharing."
How we use it
We use data from the app only to operate the app for you: authenticate you, calculate your targets and indicators, show your own history back to you, and, if you use the in-app Feedback feature, read and respond to what you send us. How the website uses what it records is described under "This website" below.
AI parsing (AWS Bedrock)
With your in-app consent (asked before first use and revocable anytime in Settings → AI meal logging), the inputs you choose to provide are sent to our AI parsing provider, AWS (Amazon Bedrock), which runs Amazon Nova, an Amazon-built model, to structure them into entries you review: the meal text you type, a meal photo you choose to submit, the text of a recipe page you share into the app, and the training description you type when you ask for a suggestion (for example, "oatmeal with a banana" becomes a list of items). Only the input you provide is sent. It is not tagged with your name or email, and no cycle or body data is included. If you decline or turn AI parsing off, manual logging keeps working in full. The nutrient numbers are looked up from our own food database; the model never produces them. Under AWS's terms, your input is not used to train Amazon Nova or any other model and is not shared with any third-party model provider; the model providers themselves cannot access it. Your input is encrypted in transit (TLS) and at rest. See AWS's Bedrock Security and Privacy page and Bedrock Data Privacy FAQ. AWS acts only as our service provider; this is not "selling" or "sharing" your data.
Subscriptions & billing (RevenueCat)
Idunia's paid subscription is managed through RevenueCat, Inc. When you subscribe, your account identifier (the same ID that identifies you to our backend) and your purchase and subscription-status events are sent to RevenueCat (api.revenuecat.com) so we can unlock the app and restore your access across reinstalls. No health data of any kind (nutrition, training, body, or cycle) is sent to RevenueCat, and RevenueCat does not collect any advertising or device identifier from you (we do not enable that feature). The payment itself is processed by the App Store or Google Play, depending on where you subscribe. RevenueCat acts only as our service provider; this is not "selling" or "sharing" your data. See RevenueCat's Privacy Policy.
Feedback
If you use the in-app Feedback feature, the text you type and any photos or screenshots you choose to attach are stored in our database (Supabase), privately. Only we can read what you send us; there is no way for anyone, including you, to read a submission back through the app after you send it. It is never shared with any third party, and it is not part of your data export (email founders@maxoutput.ai if you want a copy of something you sent us). A photo or screenshot may itself show your logged nutrition, training, or cycle information, so only attach one you are comfortable sending us.
Diagnostics
In the app, we use no background crash, analytics, or diagnostics software and collect no diagnostic or crash logs.
This website
This section covers our website, idunia.getmaxoutput.com.
- Visit statistics: Our website host, Vercel, runs Vercel Web Analytics on our home page and article pages. For each page view it records the page address, the address of the site that sent you, the time, your approximate location (country, region, and city), and your device type, operating system, and browser. It also records store button taps and, on article pages, when the app prompt or a QR code is shown and when the prompt is closed. An event on an article page carries the article's page name (the last part of its web address) and one detail: your type of device, how the prompt was closed, or which part of the page the event came from. We use these records to count visits and see which pages and buttons people use.
- Email forms: When you submit an email form on our home page, an article page, or the /race or /early page, your email address is sent to Kit, our email provider. Kit stores it with a tag naming the form you used and sends you the emails that form describes. Kit records when those emails are opened and which links in them are clicked. The home page form also sends the country selected in the form, which is preselected from the country cookie described below. On the /race and /early pages, your email address is also recorded as an invite in our database (Supabase), so Pro can be turned on when an account is created with that address, and Resend, our email delivery provider, sends you one email confirming the invite.
- Store links from articles: Google Play links from article pages carry two labels: the campaign
articlesand a source ofpinterest,google,web, orqr. Google Play reports these labels to us as counts of store visits. A QR code on an article page first opens a page on this website, which reads your phone's user agent (the description of the browser and device that every browser sends) to choose where to send you: the App Store, Google Play, or our home page. - Country cookie: The website sets a cookie named
idunia_ccthat holds the two-letter code of the country Vercel matches to your IP address. It lasts 30 days. Pages read it in your browser to show content for your country, such as the store buttons in the US or the country signup form elsewhere. - App prompt on articles: Article pages keep the state of the app prompt on your device: whether you closed it or tapped a store button, and when. That state is kept in your browser's local storage or, only when local storage is unavailable, in a cookie from this website named
idunia_prompt, which lasts 30 days after you close the prompt and up to 400 days after you tap a store button. Whether the prompt was already shown during your visit is kept in session storage or, when session storage is unavailable, in a session cookie namedidunia_prompt_visit. The source of your visit (pinterest,google, orweb) is kept in session storage. Pages read these to decide whether to show the prompt again and which source label to put on store links. - Tracking across websites: Other companies do not collect information about your activity across websites through this website: it loads scripts, fonts, and images only from its own domain, which its Content Security Policy enforces. An app's built-in browser, such as Pinterest's, is run by that app under its own policy.
Your choices and rights
- Access, export, or delete your data anytime in Settings, or email founders@maxoutput.ai. If you cannot use the app, you can request deletion from our account-deletion page.
- Deleting your account removes your server-side app data. Invite records from the website's /race and /early forms are deleted when you ask by email at founders@maxoutput.ai. Cycle data lives only on your device: deleting your account from inside the app also wipes it from that device, but a deletion requested by email cannot reach your phone, so after an email request you remove it by deleting cycle history in Settings or uninstalling the app.
- Withdraw consent: cycle tracking is optional (turn it off and delete it anytime, keep using the app); nutrition/training data is required to run the app, so to withdraw it, delete your account.
- California residents: we do not sell or share your personal information; you may access and delete your data as above.
Children
The app is for adults 18+. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it. If you believe a minor is using Idunia, email founders@maxoutput.ai.
Geography
We offer the app to US users only, and we do not target the app to users outside the United States. The app is intended for use within the US; if you use it while traveling, your data is still processed in the US.
Security & breach
We protect your data with TLS in transit, encryption at rest, and least-privilege access. If a breach affects your health data, we will notify affected users (and regulators where required).
Retention
We keep your app data until you delete it or close your account; deleted data is removed from active systems promptly and from backups within 90 days. Uninstalling the app removes on-device cycle data but does not delete your account or server-side data; use Settings → Account → Delete my account and data for that, which removes both. Cycle data is retained on your device until you delete it, delete your account from inside the app, or uninstall.
Changes
If we materially change our practices, we will update this policy and, where required, ask for your consent again before applying changes to data already collected.
Change history
- v1.9 (September 17, 2026): Added a "This website" section describing what idunia.getmaxoutput.com records, stores, and sends: Vercel Web Analytics visit statistics and button events; the email forms (Kit, including its email open and click tracking, plus Supabase and Resend for the /race and /early invites); the labels on Google Play links from articles and the QR code redirect; the
idunia_cccountry cookie; the app prompt's storage and cookies; and tracking across websites. Scoped the collection, sharing, use, Diagnostics, account deletion, and Retention statements to the app, named the website in the operator and Supabase statements, and scoped the Geography targeting statement to the app. Added that invite records from the /race and /early forms are deleted on request by email. Corrected the payment line, which named only Google Play, to name the App Store too. - v1.8 (August 16, 2026): Corrected what account deletion does to on-device cycle data. Previous versions stated that deleting your account does not remove it. That is wrong for the in-app route: deleting your account from inside the app also wipes the cycle data on that device. It remains true for a deletion requested by email, which cannot reach your phone. Both the deletion-rights bullet and the retention section now state this by route.
- v1.7 (August 16, 2026): Renamed "Meal-text parsing" to "AI parsing" and disclosed the full set of AI-parsed inputs behind the new in-app consent gate: meal text, meal photos, shared recipe page text, and training descriptions, each sent to AWS Bedrock only with your consent, revocable in Settings → AI meal logging. Previously this policy stated only typed meal text was sent. Also disclosed Open Food Facts as the recipient of barcode numbers in barcode lookups (UPC only, no identity).
- v1.6 (August 11, 2026): Added feedback review/response to the "How we use it" purposes list, and a "Feedback you send us" line to the "What we collect" summary, both matching the existing Feedback section (added v1.4) and the Consumer Health Data Privacy Policy's own Section 3 (added there in its v1.5), which already stated this purpose (Codex review rounds 11-12, PR #761, issue #708).
- v1.5 (August 11, 2026): Broadened the Feedback section and the cycle-data exception from "screenshot" to "photo or screenshot," matching that the in-app picker accepts any image, not only a screenshot of the app.
- v1.4 (August 9, 2026): Added a "Feedback" section describing the in-app Feedback feature: what is collected, that it is stored privately and not readable back through the app, and that it is not part of your data export. Removed the "v1 has no report a problem feature" statement in Diagnostics, which the new feature makes stale.
- v1.3 (June 8, 2026): Corrected the meal-text parsing provider to AWS (Amazon Bedrock), running the Amazon Nova model. The prior version named Anthropic, PBC (Claude), which no longer reflects the deployed parser. Replaced the Anthropic-term citations with AWS Bedrock's data-handling terms (not used to train models, not shared with third-party model providers, encrypted in transit and at rest).
- v1.2 (June 4, 2026): Disclosed RevenueCat, Inc. as our subscription-billing provider — it receives your account identifier and purchase/subscription events only, with no health data and no advertising or device identifier. Added a "Subscriptions & billing" section and listed subscription status under "What we collect."
- v1.1 (June 4, 2026): Disclosed Anthropic, PBC as the meal-text parsing provider. Removed the "Report a problem" diagnostics description; v1 collects no diagnostics or crash logs. Added the web account-deletion route.
- v1.0 (June 3, 2026): Initial version.
Contact: founders@maxoutput.ai