Privacy Policy

Last updated: March 2026

1. Data controller

In accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the controller responsible for processing your personal data is:

Manuel Amado Incera
NIF: 72078099D
Email: info@xnacks.app
Website: xnacks.app

2. Data we collect

Xnacks collects and processes the following categories of personal data:

2.1 Account data

When you sign up using Sign in with Apple, we receive an anonymised unique identifier and, optionally, your email address if you choose to share it. We never access your Apple ID password.

2.2 App usage data

We record information about your interaction with the app: completed snack sessions, exercise types performed, activity streaks, configuration preferences and associated timestamps.

2.3 Subscription data

Subscription management is handled through RevenueCat. We receive information about your subscription status (active, expired, trial period), but we never access your payment details or credit card information, which is managed exclusively by Apple.

2.4 Health data (Apple HealthKit)

With your explicit consent, Xnacks may access Apple HealthKit data, including heart rate, heart rate variability (HRV) and activity data. This data is processed exclusively on your device to personalise exercise recommendations. HealthKit data is never sent to our servers, never stored in the cloud and never shared with third parties.

2.5 Diagnostic data

Through Firebase Analytics and Firebase Crashlytics, we collect anonymised usage and diagnostic data to improve app stability and performance. This includes device information, app version and anonymised crash reports.

3. How we use your data and legal basis

We process your personal data for the following purposes:

  • Service delivery (Art. 6(1)(b) GDPR): managing your account, providing personalised exercises and maintaining your session history.
  • Subscription management (Art. 6(1)(b) GDPR): managing access to premium features and verifying your subscription status.
  • App improvement (Art. 6(1)(f) GDPR - legitimate interest): analysing aggregated and anonymised usage to improve the user experience and app stability.
  • Health data processing (Art. 9(2)(a) GDPR): access to HealthKit data is based solely on your explicit consent and is used exclusively to personalise recommendations.

4. Health data: on-device processing

Xnacks handles Apple HealthKit data differently from other personal data:

  • HealthKit data is processed exclusively on your device (iPhone and Apple Watch).
  • It is never transmitted to external servers or stored in cloud databases.
  • It is never shared with third parties, including analytics services.
  • It is never used for advertising purposes.
  • You can revoke HealthKit access at any time from your device Settings.

5. Third-party services

Xnacks relies on the following third-party services:

  • Firebase Authentication (Google LLC): user authentication via Sign in with Apple. Firebase Privacy Policy.
  • Cloud Firestore (Google LLC): storage of account and session data on servers located in the European Union (region europe-west1, Frankfurt).
  • Firebase Analytics and Crashlytics (Google LLC): collection of anonymised usage and diagnostic data.
  • RevenueCat (RevenueCat Inc.): in-app subscription management. RevenueCat Privacy Policy.
  • Apple (Apple Inc.): payment processing and authentication service. Apple Privacy Policy.

6. Data storage and security

Your personal data is stored on Google Cloud servers located in the European Union (region europe-west1, Frankfurt, Germany), ensuring compliance with GDPR data transfer requirements.

We implement appropriate technical and organisational security measures, including encryption in transit (TLS) and at rest, role-based access control and regular review of security practices.

7. Data retention

We retain your personal data for as long as you maintain an active Xnacks account. If you request account deletion, we will delete your personal data within 30 days, unless we are required by law to retain it.

Anonymised analytics data may be retained in aggregate form for statistical purposes after account deletion.

8. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): obtain confirmation of whether your data is being processed and access it.
  • Right to rectification (Art. 16 GDPR): request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR): request deletion of your personal data.
  • Right to data portability (Art. 20 GDPR): receive your data in a structured, commonly used format.
  • Right to object (Art. 21 GDPR): object to processing based on legitimate interests.
  • Right to restriction of processing (Art. 18 GDPR): request restriction of processing in certain circumstances.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at info@xnacks.app. We will respond to your request within 30 days.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or your local supervisory authority if you believe your data has not been processed in compliance with applicable regulations.

9. Children's privacy

Xnacks is not directed at children under 16 years of age. We do not knowingly collect personal data from children under this age. If you become aware that a child has provided us with personal data, please contact us at info@xnacks.app so we can delete it.

10. Cookies

The xnacks.app website is a static site that does not use cookies or tracking technologies. The mobile application does not use cookies.

11. Changes to this policy

We reserve the right to update this privacy policy to reflect changes in our practices or applicable legislation. We will notify you of any significant changes through the app or the website. We recommend that you review this policy periodically.

12. Contact

For any enquiries related to privacy or the processing of your personal data, you can contact us at:

Manuel Amado Incera
Email: info@xnacks.app
Website: xnacks.app