Diet2Fit Pvt. Ltd. ("Diet2Fit", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect about you when you use the Diet2Fit mobile application (the "App") and related services (collectively, the "Service"), how we use and share it, how long we keep it, and the rights you have over it. This Policy should be read together with our Terms & Conditions and forms part of those Terms.
Diet2Fit Pvt. Ltd. is a company incorporated under the Companies Act, 2013 (contact: contact@diet2fit.com). For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable laws, Diet2Fit is the Data Fiduciary (controller) in respect of the personal data described in this Policy.
This Policy applies to all personal data that you provide to us or that we collect about you when you use the App. It does not apply to data collected by third-party services that the App integrates with — those providers operate under their own privacy policies (see Section 5).
We collect the following categories of personal data:
| Category | Examples | Sensitive? |
|---|---|---|
| Identity & account | Full name, mobile number (for OTP login), age, gender, country, optional address | No |
| Health & lifestyle profile | Height, weight, BMI, fitness goal, diet preference (VEG / NON_VEG / EGG), activity level | Yes — health-related |
| Photos | Profile picture (avatar) you choose to upload | Potentially identifying |
| Activity logs | Meals consumed, workouts and sequences completed, cardio sensor data (steps, distance, cadence, calorie-burn estimates, perceived-exertion ratings), supplement / medicine intake, water consumption, weight measurements over time | Yes — health-related |
| Wellbeing & body-signal check-ins | Optional daily self-reported entries used by the premium "Insights" dashboards — mood and stress ratings and mindfulness minutes (Mind & Body); resting heart rate and, if you enter it, heart-rate variability (Heart); and sleep duration, quality and bed/wake times (Sleep). You enter these manually; the app does not read them from a wearable. | Yes — health-related (incl. mental-wellbeing) |
| Location (city) | The city you select, or that we resolve once from a coarse (approximate) device-location reading if you choose "auto-detect" during setup. We store only the resolved city name — not your precise coordinates — and we do not request precise or background location. | Approximate location |
| AI & coaching content | Your messages to the in-app AI coach (stored as conversation history) and, if you use the human-nutritionist feature, your consultation chat messages and call booking details. See Section 13. | Yes — may contain health details |
| Feedback | Messages you submit through the in-app Feedback option, and screenshots you choose to attach (these may incidentally include other parts of the App that were on screen) | Depends on content |
| Subscription & payment | Plan tier, billing cycle, transaction reference IDs from Razorpay. We do not store your full card number, CVV, or UPI PIN — Razorpay handles those directly. | No (we don't see the card data) |
| Device & technical | Device identifier (used for OTP session binding), platform (Android / iOS), app version, IP address visible to the backend during API calls, basic crash diagnostics | No |
Some data is essential — without it the App cannot work (e.g., your age, weight, and goal are needed to calculate calorie targets). Other data is optional and you can use the App without providing it (e.g., the profile picture).
We process your personal data only where we have a lawful basis to do so. The table below summarises our purposes and bases under the DPDP Act and other applicable law.
| Purpose | Data used | Legal basis |
|---|---|---|
| Authenticate you and operate your account | Mobile number, OTP, device identifier | Contract / consent |
| Generate personalised meal, workout, and nutrition recommendations | Profile (age, weight, height, diet pref, goal, activity), logging history | Contract |
| Provide the reminder, logging, and progress-tracking features | Activity logs, supplement schedule, water schedule, weight history | Contract |
| Process subscription payments | Payment instrument tokens (handled by Razorpay), plan choice | Contract |
| Investigate and respond to feedback / bug reports | Feedback messages, screenshots, account context | Consent + legitimate interest |
| Send service notifications (e.g., water reminder, supplement reminder) | FCM device token, reminder schedules | Consent (you enable reminders) / contract |
| Improve the Service via aggregate, anonymised analytics | Logging trends with personal identifiers removed | Legitimate interest |
| Comply with legal obligations (tax, accounting, lawful requests) | Account & transaction records | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not engage in profiling beyond the personalised recommendations described above.
We share personal data only with a small set of service providers ("Data Processors") that process it on our behalf strictly to operate the Service. Each is bound by contract to use the data only for the agreed purpose, maintain appropriate security, and assist us with your data rights requests.
| Recipient | What we share | Purpose |
|---|---|---|
| Amazon Web Services (AWS) | All categories (hosted in their infrastructure) | Hosting compute, database, and object storage |
| Anthropic (Claude AI) | Only the specific input a given AI feature needs: your typed message and relevant profile / log context (AI coach); a meal photo (Meal Scanner); a typed food name (custom food); or your numeric metrics for a period (Insights coaching line). See Section 13. | Powering the AI features (chat coaching, meal-photo recognition, nutrition estimates, insight summaries) |
| Agora | The real-time audio of a nutritionist call between you and your assigned coach, and call session metadata. Applies only if you book a call. | Carrying in-app audio calls with a human nutritionist |
| Razorpay | Payment instrument data (entered by you on Razorpay's screens, not handled by us), transaction reference IDs | Subscription billing |
| Firebase Cloud Messaging (Google) | Your device's push-notification token and notification payload | Delivering reminders and service notifications |
| Atlassian Jira | The feedback message and optional screenshot you submit, your user ID and mobile number, and the page you were on when you submitted | Routing feedback to our support team for triage |
We do not sell your personal data. We do not share it with advertisers. We do not share it with third parties for their own marketing purposes.
We may disclose your personal data when required by law (e.g., in response to a valid court order or law-enforcement request), to protect our legal rights, or in connection with a merger, acquisition, or sale of our business (in which case we will notify you).
Our primary databases and object storage are hosted on AWS in the Mumbai (ap-south-1) region in India, and that is where your account and health-tracking data are stored.
Some features necessarily transfer specific data outside India to the service providers listed in Section 5:
We transfer this data only to the extent needed to provide the feature, under contracts that require each provider to protect it and to use it only to perform the service for us, and subject to safeguards consistent with the DPDP Act and other applicable law. Where a feature that sends data abroad is optional, you can choose not to use it.
We protect your personal data through a layered set of technical and organisational measures:
No system is perfectly secure. We will notify you and the relevant authorities promptly if a personal-data breach materially affecting you occurs, in accordance with the DPDP Act.
Under the DPDP Act and other applicable laws, you have the following rights over your personal data:
To exercise any of these rights, email contact@diet2fit.com (see Section 14). We will respond within the timelines required by applicable law (and in any event within 30 days).
The Service is available to users aged 13 and above. Users below 18 years of age must have prior verifiable consent from a parent or legal guardian, who must also accept these Terms and this Policy on the minor's behalf. We do not knowingly collect personal data from a child below the age of 13. If we become aware that we have inadvertently collected such data, we will delete it promptly. Parents or guardians who believe their child has provided us with personal data without consent should contact us immediately at contact@diet2fit.com.
For users between 13 and 18, we do not use their data for behavioural tracking or targeted advertising, and we apply additional safeguards consistent with the DPDP Act.
The App is a mobile-only product and does not use browser cookies. We do not embed third-party advertising or analytics SDKs that track you across other apps or websites. Within the App, we use the minimum local storage needed to keep you signed in (encrypted JWT in secure keychain) and to cache your profile for fast loading.
Because the Service involves nutrition, fitness, sleep, and weight management, much of the data we collect is health-related — your weight and body-fat history, BMI, supplement schedule, workout logs, and the optional wellbeing and body-signal check-ins that power the Insights dashboards (mood and stress, mindfulness minutes, resting heart rate and HRV, and sleep). Mood and stress entries are treated as mental-wellbeing data, which we handle with particular care. We treat all of this data with heightened protection:
Diet2Fit is not a healthcare provider and the App is not a medical record system. The recommendations and metrics it provides are educational only — see the Terms & Conditions for the full medical disclaimer.
Some features of the App use artificial intelligence provided by Anthropic (the "Claude" models) as our data processor. When you use one of these features, we send Anthropic only the input that feature needs, and Anthropic returns a result to us:
| Feature | What is sent | Notes |
|---|---|---|
| AI coach (chat) | Your typed message, and relevant parts of your profile, plans, and logs needed to answer | Your conversation history is stored in your account so you can revisit it. This feature can be turned off at the service level. |
| Meal Scanner | The meal photo you take | The photo is used to identify foods and is not stored by us — it is sent, processed, and discarded; only the food names you choose to log are kept. |
| Custom food | The food name you type | Used to estimate nutrition for an item not in our catalogue. |
| Insights coaching line | Your numeric metrics for the period (scores, averages, and changes) | No free text and no name are sent; the generated one-line tip is not stored. |
Anthropic processes this data only to perform the service for us, under contract; it is not permitted to use your data for its own marketing. This processing takes place in the United States (see Section 6). These AI features are optional or can be switched off, and where a feature reveals health details in your text, that content is treated as health-related data (Section 12).
We may update this Privacy Policy from time to time to reflect changes in our practices, in the Service, or in the law. The version you accepted is recorded against your account along with the date of acceptance. Material changes will be notified through the App with at least 14 days' prior notice, and you will be asked to re-accept before continued use. Non-material changes (clarifications, typographical corrections) take effect immediately upon publication.
For any data-protection requests, questions, or complaints about this Privacy Policy or our handling of your personal data, contact us at:
In accordance with the DPDP Act and the Information Technology Act rules, you may also raise concerns about the processing of your personal data with our Grievance Officer, by writing to contact@diet2fit.com with the subject line "Grievance Officer". We will route your request to the responsible person.
We will acknowledge complaints within 7 working days and resolve them within 30 days unless a longer period is justified and explained. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.