Surplus — Legal

Privacy policy and legal pages for the Surplus lean-bulk tracker app (iOS and Android).

View the Project on GitHub mike43-ai/surplus-legal

Privacy Policy

Effective date: June 27, 2026 Last updated: June 27, 2026

Surplus (“we”, “us”, “our”) operates the Surplus lean-bulk tracker applications for iOS and Android (the “App”). Surplus is a personal weight-gain and nutrition tracking app for people trying to eat in a calorie surplus. It is a self-tracking tool — not medical or dietary care, and not a substitute for professional advice. This Privacy Policy explains what information the App handles and the choices you have.

1. Your data stays on your device

Your weight log, calorie and macro targets, daily checklist, food entries, streak, and stats are stored locally on your phone. We do not sell or share your personal data, and this content is not uploaded to our servers in normal use.

2. Account

The App uses Firebase Authentication so your progress can be tied to an account and your subscription recognized across reinstalls. We store only the account identifier needed to authenticate you; we do not sell your account information.

3. AI Meal Generator (optional, Pro)

When you request an AI-generated meal or meal plan, the inputs you provide (such as your calorie target, macro goals, and food preferences) are sent securely for processing by third-party AI providers — OpenRouter and Google (Gemini) — to generate meal suggestions, which are then returned to you. We send only the inputs needed to generate your meals and minimal context — never more of your identity than an account id.

Your inputs are processed only to generate your meal suggestions and are not stored on our servers afterward. We do not sell your inputs, use them for advertising, or use them to train AI models. The AI providers process the text on our behalf under their own data-use terms (OpenRouter: https://openrouter.ai/privacy).

4. Subscriptions

Optional subscriptions (Surplus Pro) are handled by the App Store / Google Play and RevenueCat. We do not receive or store your payment method, billing address, or full account details — the store confirms only whether your subscription is active.

5. Third-Party Services

Service Purpose Data received
Firebase Authentication Authenticate your account Account identifier
Surplus AI API (Cloudflare Workers) Server-side AI gateway The meal inputs you submit, plus your account id
OpenRouter + Google Gemini Generate meal suggestions Meal inputs relayed by our gateway (only when you trigger a generation)
RevenueCat Subscription management App User ID, purchase receipts
Apple App Store / Google Play In-app purchases Purchase receipt

Each provider stores data on its own infrastructure under its respective privacy policy.

6. Health disclaimer

Surplus provides calorie and nutrition estimates for general informational purposes only. It is not medical, dietary, or fitness advice. Consult a qualified professional before making significant changes to your diet or training.

7. Data Retention

8. Your Rights

You control your data directly: uninstalling the App or clearing its data removes your on-device content. For any privacy question or request, including deletion of account data, contact us at the email below; we respond within 30 days.

9. Children

Surplus is not directed to children; it is intended for adults managing their own nutrition.

10. Security

We use industry-standard measures: TLS for all data in transit, a server-side AI gateway that authenticates every request with your account identity (so AI provider keys are never embedded in the App), and encrypted storage on Apple- and Google-managed infrastructure. No system is perfectly secure.

11. International Transfers

We are based in Vietnam. When you use the optional AI Meal Generator, your inputs may be processed in the United States or other countries where our providers (Google, Cloudflare, OpenRouter, RevenueCat) operate. By using that feature you consent to such transfers.

12. Changes to This Policy

We may update this policy from time to time. We will post the new version at this URL and update the “Last updated” date. Continued use of the App after a change takes effect constitutes acceptance of the updated policy.

13. Contact

For privacy questions or data requests:

Email: support.gravita@gmail.com

We aim to respond within 5 business days.