Download our App NOW !!

Privacy Policy

Privacy Policy

Effective date: July 12, 2026

This Privacy Policy explains how ELDEB Fitness processes personal data in connection with the application, website, support, payments, and service-related communications. It does not apply to independent external websites that you choose to visit.

1. Data We May Collect

Account Data

Name, phone number, email address, age, and profile image, for account creation, verification, and communication.

Subscription and Payment Data

Plan, transaction value, transaction date, payment status, and reference number, for activation, billing, and fraud prevention. Payment card details are generally processed by a specialized payment gateway, and the Service does not store full card details unless otherwise disclosed and handled in accordance with applicable requirements.

Fitness and Health Data

Height, weight, measurements, injuries, medications, allergies, and goals, for program personalization and safety.

Content Data

Food images, uploaded images, messages, answers, and similar content needed to provide features, follow-up, and support.

Device and Usage Data

IP address, device identifier, operating system, sessions, failures, login attempts, security events, device patterns, and account-related watermarks, for security, diagnostics, service improvement, and investigation of sharing, leakage, hacking, or fraud.

Communication and Marketing Data

Support messages, complaints, consents, messaging preferences, and interaction with communications, for problem resolution, proof of requests, and marketing where there is a valid consent or other lawful basis.

2. Sources of Data

Data may come directly from you through registration, questionnaires, uploads, and communications; automatically through necessary application and device logs and disclosed tools; from payment gateways and app stores through transaction confirmations; from the coach or support team through professional service notes; and from lawful sources where necessary to prevent fraud or comply with legal orders.

3. Purposes of Processing

We may process data to create accounts and provide programs, personalize workouts and plans, manage subscriptions and payments, run food analysis and other automated features you choose, protect accounts and content, detect leakage, hacking and fraud, fix technical issues and improve performance, comply with legal and tax obligations, preserve evidence and defend rights, and send direct marketing only where permitted by applicable law and subject to an easy opt-out.

4. Legal Bases and Consent

Processing may be based on performing the subscription contract, complying with a legal obligation, protecting a balanced legitimate interest such as system security and fraud prevention, or obtaining explicit consent where required for health or sensitive data, marketing, or use of images for model training. Consent should be specific, clear, provable, and withdrawable. Withdrawal does not affect the lawfulness of prior processing, but may prevent a feature that depends materially on the data.

5. Health and Sensitive Data

Health information, measurements, and images that reveal physical condition are treated as highly sensitive data. Access is restricted and such data is used only to provide the Service, support safety, and fulfill disclosed purposes. Health data is not sold to data brokers or used for targeted advertising by the Service. Where required, explicit separate consent is obtained before collection, together with information about the categories, purposes, retention, and recipients. Users are not required to provide data that is not actually necessary for the Service.

6. Food Images and AI Processing

The food-analysis feature may use computer vision and automated models. Before the feature is used, the user should be informed whether images are processed on-device or sent to an external server or provider, where processing occurs, how long images are retained, and whether they are used to improve models. The operationally safe assumption is that user images are not used to train general-purpose models unless separate, clear, and withdrawable consent is obtained. Users should avoid including faces, documents, location information, or other people in food images whenever possible and remove unnecessary data.

7. Cookies, Analytics, and SDKs

If the website uses non-essential cookies, measurement tools, or SDKs, an appropriate consent mechanism should explain the categories and allow non-essential tools to be refused. Necessary tools may be used for login and security. Actual analytics, advertising, and notification providers should be listed in the privacy center and updated when a new provider is added.

8. Sharing and Recipients

Data may be shared only to the extent necessary with hosting, support, notification, payment, analytics, artificial intelligence providers, professional advisers, and competent government authorities where there is a legal basis. Processors should be bound by contracts addressing purpose, confidentiality, security, deletion, and breach reporting. The Service does not sell personal data and does not permit third parties to use health data for their own advertising. Where a third party acts as an independent controller, users should be informed of the third party and its policy before transfer when required.

9. International Data Transfers

Some cloud or artificial intelligence services may be located outside Egypt. Cross-border transfer or access should occur only after checking the applicable legal and regulatory requirements, protection level, contracts, safeguards, and required permissions, and informing users of material destinations or destination categories. Where a suitable legal basis cannot be provided, a local provider should be used or the relevant processing disabled rather than relying on vague blanket consent.

10. Data Retention

Data should be retained only for as long as needed for its purpose or a legal obligation. Account and subscription data may be kept for the account term followed by a reasonable closure period, with deletion or anonymization after the purpose and disputes end. Financial and invoice records may be retained for the legally required tax and accounting periods. Health data and plans may be retained while the Service is being provided and for a short follow-up period, then deleted upon a valid request or when the purpose ends unless retention is legally required. Food-analysis images should be kept for the shortest period necessary for analysis unless the user chooses retention. Security logs may be retained proportionately to security and investigation needs, and complaint or dispute records until the complaint and applicable claim periods end.

11. Information Security

The Service applies organizational and technical measures proportionate to the nature of the data and risks, such as encryption in transit, access controls, authentication, event logging, backups, updates, authorized vulnerability testing, vendor management, and training for people who access data. No internet-connected system can guarantee absolute security. The Service therefore does not promise that hacking is impossible, but it undertakes reasonable care, incident response, and legally required breach reporting.

12. Data Breaches

When a breach is suspected, the Service may contain, investigate, document, restore, and assess the impact and notify regulators and affected users within the timeframes and circumstances required by law. Notifications may include the nature of the incident, affected data, preventive measures, and a contact channel.

13. Your Data Rights

Subject to applicable law, you may have the right to know what data is processed, its purposes and recipients; request access or a copy; request correction or completion of inaccurate data; request deletion or restriction of processing where legally available; object to direct marketing and withdraw consent; submit a complaint to the Service or the competent regulator; and request review of an impactful automated decision where one exists and the law provides such a right. Requests may require reasonable identity verification and should be handled within legal time limits. A request may be refused or restricted where it conflicts with a legal obligation, third-party rights, or evidence required for a dispute, with reasons provided where permitted.

14. Account and Data Deletion

A clear method should be available to request account deletion through the application or privacy channel. Deletion removes access to the account, plans, and records that are not legally required to be retained. Deleting the application from a device does not by itself delete the account or cancel an app-store subscription. Limited data may be retained after closure to meet financial or legal obligations, prevent fraud, or defend claims, subject to isolation and restricted use.

15. Direct Marketing

Promotional electronic messages are sent only in accordance with applicable legal requirements, with identification of the sender and purpose and a free, easy method to opt out. Refusing marketing does not affect the ability to use a paid Service.

16. Children’s Privacy

The current Service is not intended for persons under 18 and does not knowingly collect their data. When a minor account is identified, the Service may suspend it and delete unnecessary data after verification, with communication to a parent or guardian where required.

17. Changes to This Privacy Policy

This Policy may be updated because of changes in law, operations, or service providers. The version number and effective date should be recorded, and users should be notified of material changes in a reasonable period before they take effect. New consent should be obtained where an amendment changes the purpose of processing health data or adds a use that legally requires consent.