Gorivo Privacy Policy
Effective date: 27 September 2026
1. Who we are
Gorivo is operated by Roscoe Software Ltd, registered in England and Wales, company number 17169518. Our registered office is 2 Station Road, Nafferton, Driffield, England, YO25 4LT. We are the controller responsible for personal information processed to operate Gorivo.
Contact [email protected] for privacy questions, support or requests about your information. This notice covers the Gorivo iOS and Android apps, our websites, account services, connected features and beta testing.
2. Information we collect
The information involved depends on the features you use. You do not have to create an account to browse the public website. An email address or supported sign-in identity is needed to create and secure an app account. Without the records needed by a feature, we cannot provide that feature. Some information is necessary for an account; health connections, photos, social sharing and AI features involve additional choices.
- Account and profile: account identifiers, email address, authentication details, name, username, profile and cover photos, biography, profile links, privacy preferences and settings. When you use a sign-in provider, we receive the account information that provider makes available for authentication. We do not receive your Apple, Google or Facebook password.
- Training: goals, experience, equipment, preferences, exercise definitions, workout groups, programmes, completed sessions, dates, sets, repetitions, weights, duration, distance, effort ratings (RPE), notes, personal records and achievements. This can include records imported during earlier versions; new workout-file imports are not offered in the first public release.
- Nutrition: calorie and nutrient targets, food and drink entries, water logs, recipes, ingredients, quantities, methods, meal plans, dietary preferences, allergies, exclusions and supplement entries or reminder schedules you provide.
- Body and activity: age or date of birth, sex information used for calculations, height, weight, target weight, body measurements, body fat and lean mass, progress photos, comments, steps, distance, active energy and relevant exercise records. Some of this is sensitive health information.
- Social and collaboration: posts, comments, likes, follows, invitations, shared content, reports, blocks, mutes and interaction records used for feed ordering. A shared meal planner includes the entries and participant information needed for collaboration.
- Coach and connected assistants: questions, conversation history, relevant profile, training and nutrition context, proposed changes, review decisions, connection permissions and access tokens.
- Technical and support: device/platform details, notification tokens, app version, request times, IP addresses and operational error, security and support records. If you contact us, we receive what you send, including attachments. Beta feedback may also reach us through Apple TestFlight or the testing channel you use.
- Purchases, where offered: subscription status, product and transaction identifiers and information needed to provide paid access. App-store providers handle payment information under their own policies; do not send us card details in support messages.
3. What we use it for and our legal grounds
We use account information and the records needed to deliver the features you request to perform our contract with you: signing in, saving and syncing records, displaying history, preparing reports, sharing selected content, collaborating and providing support.
We rely on our legitimate interests in keeping the service secure, diagnosing faults, preventing abuse and improving reliability, where those interests are not outweighed by your rights. We may retain information to comply with legal obligations or establish, exercise or defend legal claims.
For health information, we also need a special-category condition. For optional health, nutrition and personalised coaching features, we rely on your explicit consent. We explain the relevant processing when seeking that consent; accepting these terms or this privacy notice alone is not that consent. Withdrawing consent stops the processing covered by it, but does not make earlier lawful processing unlawful. Contact us to withdraw consent or request deletion where a control is unavailable. Affected features may then be unavailable.
Device permission prompts control access to the device or health store. They are separate from your choices about cloud storage, AI processing and public sharing.
We use records and preferences to calculate targets, trends, recommendations and interaction-based feed ordering. These are estimates or suggestions, not medical decisions. You can use chronological feed ordering where available and review proposed changes before accepting them. We do not use these calculations to make legal or similarly significant decisions about you.
Optional adaptive calorie targets use your goal, preferred pace, weight records, current targets and food logging to review progress. A suitable new weigh-in can lead to an automatic target adjustment and an explanation. You can turn this off in Fuel settings or edit your targets. Training progression similarly uses logged performance and equipment preferences to suggest future targets. These tools do not diagnose conditions or guarantee a particular result.
4. Apple Health and Android Health Connect
Connecting is optional. Supported data can include weight, height, body fat, lean mass, steps, distance, active calories and exercise-session information. Apple Health can additionally provide supported characteristics such as birthday and biological sex, and waist measurements. Android availability differs; Gorivo does not promise that every Apple field is available through Health Connect.
We read only the types you permit and use them for your personal measurements, activity history, progress and calculations. Sync may run when the app opens, returns to the foreground or receives an operating-system background update. Background and historical access depend on your permissions and device support. We use timing and source information to help reconcile overlapping activity; imported records and calorie estimates are not guaranteed complete or exact.
Imported information can be stored in your Gorivo account and synced across your devices. Importing a measurement does not itself publish it to the social feed. Sharing a body-progress post is a separate action. The current integrations read health-store records rather than write them back.
You can revoke access in Apple Health or Health Connect and disable the connection in Gorivo where available. Revoking access stops future reads; it does not automatically erase information already imported into Gorivo. Request deletion separately if you want those copies removed. Deleting Gorivo data does not delete the original records in your health app.
Health-store information must not be used for advertising, sold to data brokers, or used for unrelated marketing or credit/insurance decisions. Gorivo's permitted use is to provide the health and fitness features you choose.
5. Existing beta assistant connections
Gorivo does not currently provide an in-app AI conversation service or offer new ChatGPT connections in the public app. Existing authorised beta connections may remain active until disconnected. For those connections, ChatGPT is provided by OpenAI. Before connecting, we explain the record categories the assistant can access and ask you to allow that access. These can include training and nutrition records, goals and relevant profile settings, and may contain sensitive health information. Photos and account credentials are excluded. Only connect an account you control, and do not provide another person's private information without permission.
ChatGPT's own terms and privacy settings govern information it receives. Disconnecting in Gorivo stops future authorised access and dismisses pending proposals; it does not automatically delete conversations already held in ChatGPT. Manage those conversations and their privacy settings in ChatGPT.
Supported workout, recipe and settings changes are presented in Gorivo for your review before they are applied. The assistant cannot approve its own proposals. Do not rely on AI output for diagnosis, medication decisions, allergy safety or emergency advice.
6. Sharing, public posts and collaboration
Your audience depends on the feature, privacy setting and sharing choice. Public profiles and posts may be visible to other users, and content you share through a link may be accessible to recipients of that link. Profile identity, avatars and social actions may be visible to the people involved. Review your profile visibility and workout auto-posting preference: completed workouts can be posted automatically if that preference is enabled. Private diary or body records are not made public merely by being stored.
When you invite somebody to a meal planner, the collaborator can access the shared planner information covered by that invitation. Check the selected planner and sharing period before inviting them. Do not include information about somebody else that you are not entitled to share.
Recipients can copy, screenshot or save content. Removing a post or changing a setting cannot retrieve independent copies already made. When you use WhatsApp or another sharing app, that provider processes the message under its own policy.
7. Device access, searches and notifications
Camera and photo access support the actions you choose, such as scanning a barcode or QR code, reading a food label or attaching an image. We store photos you choose to save or upload. Image-reading and upload behaviour may differ by feature.
Nearby gym search uses your location when you request it. iOS uses Apple's mapping services; Android uses an OpenStreetMap/Overpass-based search. The provider receives the query information needed to find places, which can include coordinates and your IP address. A workout's gym label shows the selected gym name or Home Gym, rather than publishing your precise coordinates as a location field. A named gym or information in a photo can nevertheless reveal where you train.
Food searches and barcode lookups can send search terms or product codes to Open Food Facts. Third-party image, music-link and other content hosts receive ordinary network request information when content loads. Those providers operate under their own policies.
Account confirmation, password recovery and account-security emails are delivered through Resend. This involves your email address, the message content and delivery information; authentication messages can contain short-lived sign-in or verification links. These emails are used to operate and secure your account, not as marketing subscriptions.
Apple Push Notification service and Firebase Cloud Messaging deliver supported notifications using device tokens and message data. Reminders may also be scheduled locally. Notifications may appear on your lock screen; you control system notification permissions and preview visibility. Permissions and device restrictions can delay or prevent delivery.
8. Service providers and transfers
Our current technical services include Supabase for authentication and account data, Cloudflare for the public website, Vercel for hosted connector services, Resend for account and security emails, OpenAI for existing optional ChatGPT connections, Apple and Google/Firebase for platform services and notifications, and the optional identity, search and content providers described above. Staff and service providers may access information where needed to operate, support or secure the service. We may also disclose information where required by law, to protect users or rights, or as part of a business transfer with appropriate safeguards and notice.
Processing may take place outside the UK, including in the United States. Where UK data-transfer rules require protection, the relevant transfer must be covered by an applicable adequacy decision or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum, with supplementary measures where necessary. Contact us for information about the safeguards applicable to your information.
9. Retention, deletion and security
We retain account records while needed to provide your account and history. Retention also depends on your deletion requests, support needs, security investigations and legal requirements. We retain information only for as long as necessary for these purposes.
You can delete your account in Settings → Account → Delete account. After confirmation, your account and associated active database records are removed and you are signed out. There is no 24-hour recovery period. Uploaded files are queued for permanent removal and retried if storage is temporarily unavailable; previously issued download links or cached copies may take longer to expire. You can also request deletion of particular records by emailing [email protected] from your account email. We may need to verify your identity proportionately. We will explain any information that must be retained, the reason and applicable period. Copies in restricted backups may remain until the relevant backup expires; deleted information must not be restored to active use except where necessary for recovery and subject to reapplying deletions.
Uninstalling or signing out does not delete your cloud account. Disconnecting a provider does not delete the provider's records. Copies legitimately saved by other users and third-party conversations may need to be managed separately.
We use access controls and technical protections designed to protect information. No service or transmission can be guaranteed completely secure. Keep your device and sign-in details secure and tell us promptly about suspected unauthorised access.
Subscription cancellation does not delete your records. Account deletion does not cancel your Apple or Google subscription; manage recurring billing separately through the store that bills you.
10. Your rights
Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction or portability of your personal information, object to processing based on legitimate interests, and withdraw consent. You can edit supported information in the app. In-app data export is not available in the first public release; email [email protected] to request access or a portable copy of your information. We may need to verify your identity before disclosing records.
Your right to object: you can object to processing based on legitimate interests, including associated profiling, by contacting us. We will assess your request under the applicable law. If we ever use your information for direct marketing, you can object to that use at any time.
We normally respond to rights requests within one month, with extensions or exceptions only where the law allows and with an explanation. You may complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or your local supervisory authority. Please contact us if you would like us to investigate first; doing so is not a condition of your right to complain.
11. Children, websites and changes
Gorivo is intended for adults aged 18 and over. The service is not intended for children. If you believe a child has supplied information, contact us so we can investigate and take appropriate action.
The public marketing website does not run advertising pixels or visitor analytics, and does not set application cookies or use local storage to track visits. The hosting provider processes IP addresses, requested URLs, timestamps and ordinary request information to serve pages, maintain security and diagnose faults. We rely on our legitimate interests in providing and protecting the website for that processing. Our Cookie Policy explains browser caching, security technology and links to other services. Signed-in account or connector services are separate from the marketing pages.
We will date updates to this notice and give appropriate notice of material changes. A revised notice cannot replace obtaining fresh consent where the law requires it.