Privacy Policy
Last updated: 5 August 2026
3AF Fitness Club provides a fitness planning, food logging, coaching, and progress service. This policy explains what information 3AF handles, when information leaves your device, who processes it, and the choices available to you.
Information that can stay on your device
You can use the guest-first core app without creating an account. Guest plans, workouts, food and water logs, recovery check-ins, body updates, progress, and settings are stored locally on your device. This local information is not sent to 3AF unless you sign in and use sync, connect to a trainer, or deliberately submit content to an online feature such as Meal Scan or Ask 3AF.
Information we may collect
- Account information such as name, email address, user ID, role, authentication records, and profile information.
- Fitness and wellness information such as goals, experience, workout availability, workout plans, exercises, sets, reps, load, RPE, rest time, bonus training, estimated workout energy, body measurements, check-ins, daily activity, food and water logs, menstrual-cycle context when entered, and progress notes.
- Trainer-client information such as connection status, assigned trainer, trainer-created plans, trainer notes, and plan approvals.
- User content such as meal descriptions, questions sent to Ask 3AF, food preferences, halal-friendly or other ingredient requirements, recorded allergies, foods to avoid, and a meal photo you select for analysis.
- Launch-waitlist information such as your name, email address, selected interest, consent time, and campaign source when you choose to join.
- Technical and product information such as device type, app version, authentication events, AI feature actions, provider and model used, token counts, estimated service cost, latency, fallback use, and error information.
How we use information
We use information to provide and personalize the app, authenticate accounts, sync records, show assigned plans, connect clients with trainers, generate user-requested AI estimates, enforce usage limits, maintain security and reliability, understand feature quality, respond to support requests, and send updates that you explicitly requested.
Meal Scan and Ask 3AF
3AF AI features are optional. Before the first AI request, the app asks for explicit permission to share the relevant content with third-party AI providers. You can decline and continue using manual food logging.
- Meal Scan: When you tap Analyze, the selected meal photo is resized and compressed, then sent with the meal type, optional notes, and saved food preferences.
- Ask 3AF: When you send a question, 3AF may send the question, up to 12 recent conversation turns, your current food log, nutrition and water targets, current workout and completion context, plan and progress summaries, food preferences, and recorded allergies so the answer can be personalized.
- Processing route: The app sends the request to a 3AF Supabase Edge Function. The function normally routes it through OpenRouter to a Qwen model provider. OpenAI may process the request as a fallback if the main route is unavailable.
- User control: AI nutrition output is an estimate and appears as an editable draft. Nothing is added to your food log until you review and confirm it.
OpenRouter requests are configured to avoid providers that permit data collection for model training. OpenAI fallback requests are sent with response storage disabled. Providers may still temporarily process or retain request information for security, abuse prevention, and service operation under their applicable terms.
AI storage and retention
- 3AF application code does not save the raw meal image as a file in Supabase storage or the 3AF database.
- For Meal Scan reliability and duplicate suppression, 3AF stores a one-way hash derived from the photo and request context together with the structured nutrition response. This cache is marked to expire after 48 hours, is ignored after expiry, and expired rows are removed during service cleanup or account deletion.
- Ask 3AF questions and conversation text are not stored in 3AF product telemetry. They are sent to service the request.
- AI request telemetry may retain the provider, model, token counts, estimated cost, latency, and fallback status. Outcome telemetry may retain the feature action, short food labels, item counts, macro estimates, and edit or clarification counts. This information is linked to the signed-in account and used for reliability, limits, cost control, and quality review.
Launch and marketing updates
If you join the 3AF launch waitlist, we use your email address and selected interest to send relevant launch, 3AF Plus, or coaching information. Campaign-source details may be stored so we can understand which public communication led you to 3AF. You can withdraw your consent or ask to be removed at any time by contacting hello@3afitnessclub.com.
Sharing and service providers
Client data may be visible to the client’s assigned trainer and authorized 3AF personnel when needed to provide the service. 3AF uses service providers including Supabase for authentication, database, sync, and server functions, and OpenRouter, Qwen model providers, and OpenAI for optional AI processing. We do not sell personal information, use it for third-party advertising, or track you across other companies’ apps and websites.
Storage, security, and international processing
We use access controls, row-level security, encrypted network connections, and other reasonable safeguards. Our service providers may process information in countries outside Malaysia. Those locations may have different data-protection rules. If you believe information has been exposed, sent to the wrong person, or accessed without authorization, contact hello@3afitnessclub.com promptly.
Retention and deletion
Local guest information remains on your device until you remove it or delete the app. Synced account, fitness, trainer, and AI telemetry records are generally retained while your account is active or as needed to provide, secure, and support the service. You can delete your account inside the app. Account deletion removes the Supabase account and customer-owned cloud rows configured to cascade with it. It does not control information a third-party provider must temporarily retain for security, legal, or abuse-prevention purposes.
Your choices and permissions
- You can withdraw AI consent under You > Privacy & data. This blocks future AI submissions and does not remove confirmed local food logs.
- Camera permission is requested when you open Meal Scan. The camera captures a photo only when you choose to take one.
- Apple’s photo picker lets 3AF receive only the photo you select. 3AF does not request broad access to your photo library for this flow.
- Notifications and rest alarms are requested only when you choose to enable them in app settings.
- You can manage system permissions in iOS Settings.
- You may request access, correction, export, or deletion by contacting hello@3afitnessclub.com.
Health and safety
3AF stores fitness and wellness information entered by users or trainers. Nutrition values, workout energy, forecasts, and AI results are estimates. 3AF is a general wellness and fitness product, not a medical device, and does not provide diagnosis or medical advice.
Children
3AF is not presented as a children’s app and is not directed to children under 13. If you believe a child has provided personal information without appropriate permission, contact us so we can review and remove it.
Malaysia PDPA
We aim to handle personal data in accordance with Malaysia’s Personal Data Protection Act 2010 (Act 709), applicable amendments, and related requirements. This policy should be read with any applicable notices or consent forms.
Changes to this policy
We may update this policy as the product, providers, or legal requirements change. The latest version and effective date will be published on this page. If an AI data-sharing change is material, the app can require consent again before another AI request.
Contact
For privacy questions, contact hello@3afitnessclub.com.