Skip to content

Bulk Privacy Policy

Effective date: 24 July 2026

Bulk is operated by Amibi AB (organisation number 559389-6201), Tjärhovsgatan 22, 116 21 Stockholm, Sweden (“Bulk”, “we”, “us”). We are the controller of the personal data described in this policy. Contact us at support@joinbulk.app.

This policy covers the Bulk mobile app, our website, and the related account, sync, AI, subscription, analytics, social, and notification services.

Summary

  • Meals, weight, body measurements, workouts, goals, preferences, and other app records are stored on your device and synced to our EU-hosted backend when you have an account.
  • Progress-photo image files stay on your device. Their metadata, such as date, category, tag, dimensions, and local file reference, is synced so the feature can be restored; the photo bytes are not uploaded.
  • Inputs you deliberately submit to AI logging are processed by our service providers. Anthropic prompts, model responses, and food-scan images are also kept in a private diagnostic store for a 45-day troubleshooting window.
  • PostHog receives product-usage events, diagnostics, and subscription lifecycle events forwarded by RevenueCat. Session replay is disabled; we do not record screen contents.
  • We do not sell personal data, show ads, or use personal data for cross-app advertising or tracking.
  • You can delete your account and server data inside the app.

Data we handle and why

Account and profile data

When you use Apple, Google, or email sign-in, Supabase stores an account ID, email address, sign-in information, and provider profile data that may include a name. Before sign-in, the app may create an anonymous Supabase account ID to enforce fair-use limits on AI features. We also store the public alias you choose for social features and the onboarding/profile information you provide, including birthdate, sex, height, goals, preferences, and settings.

Purposes: authentication, account security, sync, personalization, support, and service operation.

Legal basis: performing our agreement with you. Where information qualifies as health data, we rely on your consent as described below.

Nutrition, body, and fitness records

The app handles records you create or import, including:

  • meals, ingredients, food searches, calorie and macro information, saved foods, templates, and meal notes;
  • weight, body measurements, body-fat information, calorie targets, gain-rate plans, and progress goals;
  • routines, workouts, exercises, sets, strength goals, exercise notes, and workout history; and
  • app preferences, reminders, insights, recent items, and challenge progress.

These records are stored locally and synced to Supabase in the EU so they can be restored and used across your devices.

Purposes: providing the tracking, planning, sync, backup, personalization, and insight features you request.

Legal basis: performing our agreement with you and, for health-related information, your consent. You can withdraw consent by stopping the relevant feature, removing the data, revoking system health permissions, or deleting your account. Withdrawal does not affect processing already carried out.

Progress photos

Progress-photo image files are stored only in the app’s private storage on your device. We do not upload those image files. We sync the associated metadata—such as the photo date, category, tag, dimensions, camera-facing value, lighting value, and local file reference—to support the feature. Deleting your account removes the synced metadata and the app deletes its local progress-photo files.

Purpose and legal basis: providing the progress-photo feature you choose to use; performance of our agreement and your consent.

AI meal logging

When you ask Bulk to estimate a meal, the input you choose is sent through our authenticated Supabase Edge Function:

  • photos, text descriptions, and structured prompts are sent to Anthropic to estimate nutrition;
  • voice recordings are sent to Deepgram for transcription, after which the transcript may be sent to Anthropic; and
  • food-search text may be sent through our server to USDA FoodData Central. Search results may be cached.

For Anthropic requests, we keep the prompt with image bytes removed, the raw model response, status and latency information, and—when the request contained a food photo—a copy of that image in a private bucket. These diagnostic records are linked to your account and are retained for a 45-day troubleshooting window, after which they are scheduled for deletion. Account deletion removes them earlier. Voice audio is relayed for transcription and is not stored in our diagnostic log.

We instruct our AI providers to process this data only to provide the service and do not permit it to be used to train general-purpose AI models. Providers may retain limited security or abuse-monitoring records under their agreements with us.

Purposes: providing AI meal logging, investigating inaccurate estimates and failures, preventing abuse, and controlling service costs.

Legal basis: performing our agreement with you, your affirmative request to use the feature, and our legitimate interest in securing and improving it.

Barcode and food-database lookups

A barcode you scan is sent to Open Food Facts to retrieve product information. Food search text may be sent to USDA FoodData Central through our server. These requests do not include your name or email, although the providers receive ordinary network information such as an IP address.

Purpose and legal basis: returning the food information you request; performance of our agreement.

Apple Health and Health Connect

Only after you grant system permission, Bulk reads:

  • body weight, on iOS and Android; and
  • step count, on iOS only.

Bulk does not read step count on Android; it requests only body weight from Health Connect. Bulk does not write data to Apple Health or Health Connect. Imported weight records may be saved to your Bulk account. On iOS, step history is used to calculate an average for calorie estimates; Bulk does not sync the raw step-by-step history. You can revoke access in iOS or Android system settings.

Health data is used only to provide and improve health and fitness functionality. It is not used for advertising, sold, or disclosed to data brokers. Our use of Health Connect data follows the Google Health Connect Permissions policy, including its Limited Use requirements.

Purpose and legal basis: the optional health import and personalization you request; your consent.

Social content and moderation

If you choose to use Social, Supabase stores your alias, community and crew messages, direct messages, reactions, follows, crew details and membership, challenge participation, activity events, reports, and blocks. Content is visible according to the surface where you post it—for example, community messages to signed-in users, crew messages to crew members, and direct messages to participants.

Workout and reached-calorie-goal sharing are on when the community join screen first opens. You can turn either setting off before joining or change it at any time in Settings. Public crew names and member counts are visible to signed-in users. Reported content and relevant identifiers are retained for moderation and safety review.

Purpose and legal basis: providing the social features you choose to use, enforcing our rules, protecting users, and preventing abuse; performance of our agreement and our legitimate interests in safety and moderation.

Push notifications

If you allow notifications, we store an Expo push token linked to your account and your notification preferences in Supabase. Expo, Apple Push Notification service, and/or Firebase Cloud Messaging handle notification delivery and may process a sender alias, message preview, or event description in transit.

Turning a notification category off stops Bulk from sending that category; it does not necessarily delete the device token. The token is removed from your account when you sign out or delete your account. You can also disable all notifications in system settings.

Purpose and legal basis: sending notifications you enable; performance of our agreement and your consent through app and system controls.

Product analytics and diagnostics

We use PostHog EU Cloud to receive:

  • product interactions and screens viewed;
  • app version, device model, operating-system version, and language;
  • crash reports, uncaught exceptions, error events, and related diagnostics; and
  • subscription lifecycle events forwarded by RevenueCat, such as a trial starting, a purchase, a renewal, or a cancellation, so we can see how many people who reach the paywall subscribe.

PostHog data is linked to your Bulk account ID and email when you are signed in so we can investigate reported problems. Session replay is disabled, and Bulk does not send screen recordings to PostHog.

Purpose and legal basis: measuring feature use, diagnosing failures, securing the service, and improving Bulk; our legitimate interests in maintaining and improving the app.

Purchases

Apple or Google processes payment. RevenueCat receives your Bulk account ID, email address, app/store identifiers, product and entitlement information, and purchase/subscription history so purchases can be validated and restored. RevenueCat also forwards subscription lifecycle events to PostHog, linked to the same account ID, so we can measure how well the subscription flow works. We do not receive your card or bank details.

Purpose and legal basis: providing and managing Bulk Pro; performance of our agreement.

Abuse prevention

Our AI proxy uses account-level usage counters and a salted hash of the requesting IP address to enforce daily limits. We do not store the plain IP address in the usage table.

Purpose and legal basis: service security, fraud prevention, and cost control; our legitimate interests.

Waitlist sign-ups

If you submit your email address to the launch waitlist on our website, Resend stores it as a contact for us and delivers the confirmation message and the launch announcement. We do not add waitlist addresses to any other mailing, and you can unsubscribe at any time by replying to any message or emailing support@joinbulk.app.

Purpose and legal basis: telling you when Bulk is available; your consent, which you can withdraw at any time by unsubscribing or emailing support@joinbulk.app.

Providers and international transfers

Provider Role Typical processing location
Supabase Authentication, EU database, sync, storage, server functions, social features EU (Ireland)
Anthropic AI nutrition estimation United States
Deepgram Voice transcription United States
USDA FoodData Central Food-search results United States
Open Food Facts Barcode/product lookup EU and other infrastructure locations
PostHog Product analytics and diagnostics EU Cloud
RevenueCat Subscription validation and management United States
Expo Push-notification relay and app build/update services United States
Resend Waitlist contact storage and email delivery United States
Apple and Google Sign-in, store distribution, payment, health permission frameworks, and APNs/FCM delivery According to their policies

For processing outside the EEA, we use an applicable legal transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework for a participating recipient, or standard contractual clauses, together with supplementary measures where required.

Retention

  • Synced account content is kept while your account exists or until you delete the applicable data.
  • AI diagnostic prompts, model responses, and scan-image copies are retained for a 45-day troubleshooting window and then scheduled for deletion; account deletion removes them earlier.
  • Push tokens are retained while associated with a signed-in device and removed on sign-out or account deletion.
  • PostHog analytics and diagnostics are kept according to the retention period configured in our PostHog EU project and are deleted or anonymized when no longer needed.
  • Moderation records may be retained for as long as reasonably necessary to protect users, resolve reports, enforce restrictions, and establish or defend legal claims.
  • Waitlist addresses are kept until you unsubscribe or ask us to remove them, and are deleted once the launch announcement has been sent.
  • Providers and encrypted backups may keep limited copies for security, legal, or disaster-recovery periods before deletion cycles complete.

Your choices and rights

You can edit many records in the app, export an app backup, turn off optional sharing and notifications, revoke Apple Health or Health Connect access in system settings, and delete your account under Profile → Delete account.

Account deletion removes the account, synced logs and settings, social content linked to it, purchase linkage held by Bulk, AI diagnostic records, and local progress-photo files. Apple, Google, or another provider may retain records it controls under its own legal obligations. Deleting the app alone does not cancel a subscription.

Under the GDPR, you may have rights to access, correct, erase, restrict, or port your personal data, and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw that consent. Email support@joinbulk.app. We will normally respond within one month.

You may complain to your local supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY).

Children

Bulk is not directed to children. You must be at least 16 years old to create or use an account.

Security

We use access controls, encrypted transport, row-level database security, private storage, and restricted service credentials designed to protect personal data. No system can be guaranteed completely secure.

Changes

We may update this policy when the service or law changes. We will change the effective date and provide additional notice in the app or by email when required.

Contact

Amibi AB
Tjärhovsgatan 22
116 21 Stockholm, Sweden
support@joinbulk.app