Navimum · Privacy Policy
Effective date: 2026-09-06 · Last updated: 2026-09-13
This Privacy Policy explains how Navimum Limited ("Navimum", "we", "us") collects, uses, shares, and protects your personal data when you use the Navimum app and website (https://navimum.com).
Navimum processes health-related information, for example weight, body measurements, body-fat estimates, nutrition intake, progress photos, and workout data. Under EU and UK law this is "special-category" data and we process it only with your explicit consent (see section 4). Please read this policy carefully.
1. Who is responsible for your data (Controller)
The data controller is:
- Navimum Limited, a company registered in England & Wales, company no. 17343016 (Companies House)
- Registered office: 128 City Road, London, EC1V 2NX
- Privacy contact: privacy@navimum.com
- Data Protection Officer: we have not appointed a Data Protection Officer, as one is not required at our scale. Privacy questions go to privacy@navimum.com.
- EU representative (GDPR Art. 27): we have not yet appointed an EU representative. We will publish their name and contact details here once appointed. In the meantime you can reach us on any GDPR matter at privacy@navimum.com.
- UK representative (UK GDPR Art. 27): not applicable. Navimum Limited is established in the UK, so no UK-GDPR Art. 27 representative is required.
For B2B coaching plans, your coach or trainer may be a separate or joint controller for the coaching data they access. See section 8.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email, password (hashed), date of birth or age confirmation, country, language | You |
| Profile & goals | Biological sex, height, activity level, goals, dietary preferences and allergens | You |
| Health & fitness data (special category) | Weight, body measurements, body-fat %, calorie and macro intake, meal logs, progress photos, workout logs, sleep duration and daily steps. You enter these yourself, except daily steps and sleep duration, which the app can read from your phone's health store (Health Connect on Android) if you choose to connect it. That access is optional, read-only and revocable in your phone's settings. | You |
| Subscription & transaction | Plan, trial status, purchase tokens and receipts, billing region. Payment card data is handled by Stripe. We do not store full card numbers. | You, Apple, Google, or Stripe |
| Referral data | Referral codes, referred and referring user links, payout information including tax information where required | You |
| Device & technical | Device model, OS, app version, IP address, identifiers, crash and diagnostic logs | Automatic |
| Usage & analytics | Actions our servers already record while running the service, for example a meal saved or a subscription started. Only if you allow it: which screens you open in the app. On the website: visit counts from Cloudflare Web Analytics, to country level only. | Automatic |
| Support communications | Messages you send us | You |
3. Why we use your data (purposes) and legal bases (GDPR Art. 6 and 9)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide core features (tracking, plans, macros, photos, workouts) | Account, profile, health | Art. 9(2)(a) explicit consent for health data; Art. 6(1)(b) contract for the rest |
| Create and manage your account | Account, identity | Art. 6(1)(b) contract |
| Process subscriptions, trials, renewals, refunds | Subscription, transaction | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax and accounting) |
| Operate the referral program and payouts | Referral, identity, tax information | Art. 6(1)(b) contract; Art. 6(1)(c) tax reporting |
| B2B coaching (matching and communication with a coach) | Profile, health | Art. 9(2)(a) explicit consent plus Art. 6(1)(b) |
| Security, fraud prevention, abuse detection | Technical, usage | Art. 6(1)(f) legitimate interests |
| Business records and service analytics: counting signups, subscriptions and what people save, to run and improve the service | Account, subscription, usage our servers record | Art. 6(1)(f) legitimate interests. You can opt out at any time (see "How we measure the app and website" below) |
| Screen-level usage in the app: which screens and prompts you see | Usage, device | Art. 6(1)(a) consent, asked once in the app and changeable at any time in Settings |
| Website visit statistics | Visits, pages, referring sites, country | Art. 6(1)(f) legitimate interests. Cookieless, see below |
| Remembering which campaign link brought you to the website | Campaign parameters of the link (utm_source, utm_medium, utm_campaign) | Art. 6(1)(a) consent, through the "Attribution and referral" choice in the cookie banner |
| Crash diagnostics | Diagnostic logs | Art. 6(1)(f) legitimate interests |
| Marketing emails and push, where you opt in | Account, usage | Art. 6(1)(a) consent |
| Comply with legal obligations | As needed | Art. 6(1)(c) legal obligation |
How we measure the app and website
- First party only. Our analytics are kept in our own database, run by our database provider Supabase (section 5), and are not sent to any third-party analytics vendor.
- Business records, for everyone. Our servers already process things like signups, subscriptions, and the meals, weights and workouts you save. We count these to run and improve the service, under legitimate interests. They are used in aggregate and never for advertising. You can opt out at any time by emailing privacy@navimum.com, and we will exclude your account from these counts.
- Screen-level usage, only with your consent. Which screens and prompts you see in the app is recorded only if you say yes. The app asks once, and you can change your answer at any time in Settings.
- Website visits. The website uses Cloudflare Web Analytics, which sets no cookies and stores nothing on your device. It counts visits, pages and referring sites, and records location only to country level.
- Campaign links. Only if you allow "Attribution and referral" in the cookie banner, the website remembers which campaign link brought you, in a first-party cookie kept for up to 30 days.
- Internal reports. Our internal reports show totals only, and hide any group of fewer than 10 people.
- Staff access to an individual account. Separately from those reports, a small number of authorised staff can look at an individual account where it is necessary to answer your support request, investigate fraud or abuse, or comply with a legal obligation. Access is restricted to those who need it, is logged, and is never used for advertising or sold.
You can withdraw consent at any time, for example by disconnecting health integrations, withdrawing health-processing consent, or unsubscribing from marketing, without affecting the lawfulness of prior processing. Withdrawing health-processing consent may mean core features can no longer function.
4. Special-category (health) data: explicit consent
Because Navimum's core purpose involves health and fitness data, we ask for your separate, explicit consent to process this special-category data, presented distinctly from acceptance of the Terms. We do not use health data for advertising and we do not sell it. You may withdraw this consent in settings or by contacting privacy@navimum.com. If you do, we will stop processing health data and you can request deletion (section 9).
5. Processors and sub-processors
We share data with vetted service providers ("processors") acting on our instructions under GDPR Art. 28 contracts. We do not sell your personal data.
| Processor | Function | Data categories | Region and transfer mechanism |
|---|---|---|---|
| Supabase | Database, auth, storage including progress photos | Account, profile, health, referral | Supabase, Inc. (USA). Production database hosted in the EU region. SCCs cover any US transfer. |
| Cloudflare | Web hosting and edge (Cloudflare Workers), and cookieless website visit statistics (Cloudflare Web Analytics) | Technical, usage (web). Visit statistics hold no cookies and record location to country level only. | Cloudflare, Inc. (USA). SCCs or DPF as applicable. |
| Apple (App Store, in-app purchases) | iOS distribution, in-app purchases | Subscription, transaction, identifiers | Apple Inc. SCCs or DPF. |
| Google (Play, in-app purchases) | Android distribution, in-app purchases | Subscription, transaction, identifiers | Google. SCCs or DPF. |
| Stripe | Web and card payments, billing | Transaction, billing identity. Card data is held by Stripe. | Stripe Payments Europe, Ltd. (Ireland) for EEA and UK users; Stripe, Inc. (USA) otherwise. SCCs or DPF. |
| Sentry (mobile app and backend) | Crash and error monitoring, and product-funnel counts | Diagnostic, technical, identifiers linked to your account | Functional Software, Inc. dba Sentry (USA). SCCs. |
| Resend | Transactional and opt-in marketing email | Email, name, message metadata | Resend (Plus Five Five, Inc., USA). SCCs. |
| Railway | Backend, background-worker and queue hosting | All data processed by the API, in transit and in memory | Railway Corp. (USA). SCCs. |
| Expo (Expo Application Services) | Push-notification delivery | Device push token, notification title and body | 650 Industries, Inc. (USA). SCCs. |
| Apple (APNs) and Google (FCM) | The push transport Expo relays to | Device push token, notification title and body | Apple Inc. and Google. SCCs or DPF. |
| TastyAPI | Meal-photo recognition, only when you use photo logging | The meal photo you submit. No account identifier is sent with it. | TastyAPI. Processed on our instructions under their data-processing terms. |
We do not use a third-party referral or deep-link attribution provider, a product-analytics vendor, or any advertising or retargeting provider. The Android package includes Google's Play Billing library, which declares an install-referrer permission; we do not call that API.
The table above is our current sub-processor list. We will notify you of material changes where required, and you can request the up-to-date list at any time from privacy@navimum.com. We may also disclose data to comply with law, to enforce our Terms, or in a corporate transaction, with safeguards.
6. International transfers
Where data is transferred outside the EEA or UK, we rely on appropriate safeguards: Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and the EU-US or UK-US Data Privacy Framework where the recipient is certified. You may request a copy of the relevant safeguards at privacy@navimum.com.
7. Retention
We keep personal data only as long as necessary:
- Account and health data: for the life of your account, then deleted or anonymized within 30 days of account deletion, except where law requires longer.
- Transaction and tax records: retained for the statutory period, 6 years under UK company and tax record retention rules.
- Backups: deleted records fall out of backups on our rolling backup cycle and are not restored.
- Diagnostic logs: retained for a short operational period and then deleted automatically.
Soft-deleted records are retained transiently by our deletion pipeline before permanent erasure.
8. B2B coaching (joint or separate controllers)
If you use a coaching plan, your matched coach or trainer accesses the profile and health data needed to coach you. Depending on the arrangement, the coach may act as a joint controller or an independent controller. We have agreements governing their handling of your data, and a "shadow client" arrangement (managed by a coach, with no direct Navimum use) may apply. Contact us for the essence of those arrangements.
9. Your rights
Subject to applicable law, you have the right to access, rectification, erasure (the "right to be forgotten"), restriction, data portability, to object to processing including legitimate-interest processing and direct marketing, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority. In the UK this is the ICO (ico.org.uk). Navimum has no EU establishment, so the GDPR one-stop-shop does not apply and EU users may complain to their own national data protection authority.
To exercise rights: email privacy@navimum.com or use the in-app account controls to export or delete. We respond within one month under GDPR, or the applicable statutory period. We may verify your identity first.
US state-law rights (CCPA, CPRA, and others)
If you are a US resident in a state with a comprehensive privacy law, for example California, Colorado, Connecticut, Virginia, Texas, Oregon, Utah, Montana, Delaware, New Jersey, or Maryland, you may have rights to know or access, delete, correct, opt out of sale, sharing, or targeted advertising, and to limit the use of sensitive personal information.
- We do not "sell" personal information and we do not share health data for cross-context behavioral advertising.
- Sensitive personal information, including health data, is used only for permitted purposes. You may request that we limit its use.
- Consumer health data: Washington (My Health My Data Act), Nevada, and Connecticut impose specific rules and may require separate authorization for certain sharing.
- To exercise a right, email privacy@navimum.com. We do not operate a separate rights portal, because CCPA and CPRA thresholds are not met at launch, so requests are handled by email. We will not discriminate against you for exercising your rights.
10. Security
We use technical and organizational measures including encryption in transit and at rest, row-level security, access controls, and least privilege. No method is 100% secure and we cannot guarantee absolute security. We will notify you and the regulators of breaches where legally required.
11. Children
The Service is for users 18 and older. We do not knowingly collect data from children. In the EU the digital-consent age for information-society services ranges from 13 to 16 by member state; Navimum's higher 18+ floor is a product and safety choice. If we learn we have collected a child's data, we will delete it. Contact privacy@navimum.com.
12. Cookies and similar technologies
Our website uses cookies as described in our Cookie Policy. It always sets only strictly-necessary cookies: an authentication session and a record of your cookie choice. If you allow "Attribution and referral", it also sets one first-party cookie that remembers which campaign link brought you. Website visit statistics come from Cloudflare Web Analytics, which sets no cookies. We do not use third-party analytics, advertising, or attribution trackers on the website. Where any non-essential cookie is introduced, EU and UK users are asked to consent first via our cookie consent banner, and you can change or withdraw your choices at any time from the "Cookie settings" link in the website footer.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Macro and calorie targets are algorithmic recommendations, not binding decisions, and are informational only. See our Health Disclaimer.
14. Changes to this policy
We may update this policy. Material changes will be notified in-app or by email before they take effect. The "Last updated" date shows the current version.
15. Contact
Questions or requests: privacy@navimum.com. We have not appointed a Data Protection Officer, as one is not required at our scale. Navimum Limited, 128 City Road, London, EC1V 2NX.