Privacy Policy

At Fueld we take your privacy very seriously. Please read this privacy policy carefully as it contains important information on who we are and how and why we collect, store, use and share your personal information. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint.

This privacy policy is divided into the following sections:

  • Who we are
  • Personal information we collect and how we use it
  • Health data
  • Who we share your information with (our processors)
  • Google user data
  • Garmin Connect data
  • Transfer of your information out of the UK and EEA
  • Cookies and similar technologies
  • Marketing
  • Your rights
  • How long we keep your information
  • Keeping your information secure
  • How to complain
  • Changes to this privacy policy

Who we are

This Service is operated by Fueld AI Ltd ("we", "us", "our" or "Fueld"), a company registered in England and Wales. We collect, use and are responsible for certain personal information about you as a "data controller" under applicable data protection laws. Please contact us if you have any questions about this policy or the information we hold about you:

Email: data_protection@fueld.ai

Personal information we collect and how we use it

We collect personal information about you when you access our app or website, register with us, use our services, contact us, send us feedback or complete surveys. We collect it directly from you, indirectly through your use of the Service (see "Cookies" below), and from third parties such as the health services and wearables you choose to connect.

Information we collect

  • Identity Data — name, title, date of birth and sex.
  • Contact Data — address, email address and telephone number.
  • Account & Profile Data — username, password, interests, preferences and goals.
  • Payment Data — payment method and billing details (handled by our payment processor; we do not store full card numbers).
  • Health Data — information you provide (such as height, weight, dietary requirements, allergies, conditions and goals) and data from Apple Health and any wearables or health services you connect.
  • Technical Data — device identifiers, IP address, approximate location, browser type and version, time zone, operating system and platform.
  • Usage Data — information about how you use our app, website and services, including survey responses.
  • Marketing & Communications Data — your marketing preferences and communications with us.

Legal bases for processing

We process your personal information on the following legal bases:

  • Consent — where you have given clear consent for a specific purpose (including for health data and marketing).
  • Contract — where processing is necessary to provide the Service you have requested.
  • Legal obligation — where processing is necessary to comply with the law.
  • Legitimate interests — where processing is necessary for our legitimate interests or those of a third party, and your rights do not override those interests.

Health data

Some of the information we process is health-related and is treated as a special category of personal data under UK GDPR. We process this data with your explicit consent and to provide the Service to you. You can withdraw your consent, disconnect a connected data source, or delete your data at any time through the app or by contacting us.

Who we share your information with (our processors)

We do not sell your personal information. We share it only with trusted service providers (processors) who help us operate the Service and who are contractually required to protect it and use it only on our instructions. Our key processors are:

ProviderWhat we use them forWhere data may be processed
Google / Firebase (Google Cloud)Hosting, database, authentication, file storage, app analytics and performance monitoringUK / EEA / USA
Apple; GoogleSign-in (authentication) when you choose those optionsUK / EEA / USA
StripeProcessing payments and managing website subscriptionsUK / EEA / USA
Apple App Store; Google PlayProcessing in-app purchases and subscriptionsUK / EEA / USA
RevenueCatManaging subscription entitlements across platformsUSA
PostHog (EU)Product analytics, usage events and error diagnosticsEEA
Meta Platforms (Conversions API)Measuring advertising effectiveness using hashed identifiers only (no health data)USA
MailerSendSending transactional and marketing emailsEEA / USA
ipapi.coDeriving approximate location from IP address to tailor contentEEA / USA
Google MapsDisplaying professional locations in our directoryUK / EEA / USA
Google (Gemini API)Generating insights, reports and answers from the data you share with Fueld, including connected wearable dataEEA / USA
OpenAI (OpenAI API)Generating insights, reports and analysis from the data you share with Fueld, including connected wearable dataUSA
Anthropic (Claude API)Generating summaries and narrative content from the data you share with Fueld, including connected wearable dataUSA
Apple Health & connected wearables (e.g. Apple Watch, Oura, Whoop, Garmin, Fitbit)Importing the health and activity data you choose to connectOn your device / the provider's region

We may also share information with professional advisers, auditors, law enforcement or regulators where legally required, and with a buyer or successor in the event of a business sale or reorganisation. Where you grant a health professional access through our portal, we share the data you authorise with them.

Google user data

This section explains how Fueld accesses, uses, stores, shares and deletes information we receive when you connect a Google account to Fueld. It applies to practitioners using the Fueld professional portal and to anyone who signs in to Fueld with Google.

What we access

We only request the Google permissions needed for the features you choose to use:

  • Google sign-in — your name, email address, profile picture, Google account ID and, for Google Workspace accounts, your organisation's domain. We use these to identify you and to confirm which Google account runs your sessions.
  • Google Calendar (if you connect a calendar) — the list of your calendars, and events on the calendars you choose to show in Fueld. We also create, update and delete events for sessions you book through Fueld.
  • Google Meet (if you run sessions) — we create a Meet meeting for each session you book, and read that meeting's details, participants, transcripts and Gemini meeting notes. We only access meetings that Fueld created, never your other Google Meet calls.
  • Google Docs (if you host sessions in your own Google Workspace) — read-only access, used only to read the meeting-notes documents that Google Meet creates for sessions booked through Fueld.

How we use it

We use Google user data only to provide the features you use in Fueld:

  • showing your calendar and adding booked sessions to it;
  • creating meeting links for your sessions;
  • importing session transcripts and notes into the client record in your practice's Fueld portal, for your review;
  • confirming that transcription and notes are running during a session.

We do not use Google user data for advertising, we do not sell it, and we do not use it to build user profiles for any other purpose. We do not use Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine-learning models.

Who can see it

Imported transcripts and notes are part of the client's record in your practice. They are visible only to practitioners in your practice who have access to that client, and to the client where your practice chooses to share them.

Our staff do not read your Google user data unless you ask us to help with a specific problem, it is needed for security (such as investigating abuse), the law requires it, or the data has been aggregated and anonymised for internal operations.

We share Google user data only with the processors that host and run the Service (Google Cloud and Firebase) and as required by law. It is never transferred to data brokers or information resellers.

How we store and protect it

The access tokens Google gives us are encrypted before we store them, and only the Fueld services that need them can use them. Imported transcripts and notes are stored in Fueld's Google Cloud (Firebase) systems in Europe, with access limited as described above.

When Fueld hosts a session meeting, Google saves the transcript and notes in a Fueld-managed Google account. We delete those copies shortly after importing and checking them in the client record. When you host sessions in your own Google Workspace, the original transcript and notes stay in your Google Drive under your organisation's own policies; Fueld does not move or delete them.

How long we keep it

We keep imported transcripts and notes for as long as they form part of the client's record under your practice's retention policy. We delete them when the record is deleted, or when the client or practice asks us to under data protection law. We delete stored Google access tokens when you disconnect the related feature in Fueld, and remove all your connections if you delete your Fueld account.

How to stop access

You can disconnect Google Calendar in Settings → Calendar, and disconnect Google Workspace hosting or unlink your Google account in Settings → Sessions. You can also remove Fueld's access at any time from your Google account at myaccount.google.com/permissions. After you disconnect, Fueld stops accessing your Google account. Records already imported into a client's file remain part of that record, and you can ask us to delete them using the contact details above.

Limited Use

Fueld's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Garmin Connect data

This section explains how Fueld collects, uses, stores, shares and deletes data we receive from Garmin when you connect your Garmin Connect account to Fueld. We only receive Garmin data after you connect your account and approve the data you want to share on Garmin's own consent screen.

What we collect

Depending on the permissions you grant, we receive:

  • Daily summaries — steps, distance, calories burned, intensity minutes and heart rate.
  • Sleep — sleep duration, sleep stages and sleep scores.
  • Stress and recovery — stress levels, Body Battery and heart rate variability (HRV).
  • Heart, breathing and temperature — blood oxygen (pulse ox), respiration rate, skin temperature changes, blood pressure readings and Health Snapshot results.
  • Body composition — weight, body fat percentage, BMI, muscle mass, bone mass and body water.
  • Menstrual cycle tracking — if you track your cycle in Garmin Connect: period dates and length, cycle day and length, cycle phase and fertile window predictions.
  • Fitness metrics — such as VO2 max and fitness age.
  • Activities and workouts — activity type, duration, distance, calories and the detailed samples Garmin provides for the activity, such as heart rate and, where your device records it, location.
  • Account details — your Garmin user ID, the permissions you granted and your device model.

How we use it

We use Garmin data only to provide the Fueld features you use:

  • showing your activity, sleep, stress and recovery in the Fueld app;
  • combining it with your nutrition data to calculate energy balance and calorie targets;
  • using menstrual cycle data, if you share it, to provide cycle-aware insights. Cycle data is shared with a health professional only if you separately switch on cycle sharing for them;
  • generating personalised insights, reports and answers to your questions in Fueld;
  • sharing it with health professionals you choose to connect with through the Fueld portal, limited to the data categories you allow them to see.

We do not sell Garmin data, we do not use it for advertising, and we do not use it to train artificial intelligence or machine-learning models.

Third parties and AI processing

Garmin data is stored and processed on Google Cloud (Firebase) in Europe. To generate insights, reports and answers, we send the relevant parts of your Garmin data to AI services that act as our processors: Google (Gemini API), Anthropic (Claude API) and OpenAI (OpenAI API). We use these services under commercial terms that allow them to process the data only to return a result to us, and that do not allow them to use it to train their models.

Apart from these processors and the health professionals you choose to share with, we do not share Garmin data with any third party, except where the law requires it.

How long we keep it and how to stop sharing

We keep Garmin data as part of your health record while your Fueld account is active. You can disconnect Garmin at any time in the Fueld app under Settings → Wearables, or by removing Fueld from the connected apps in your Garmin Connect account.

When you disconnect, we ask Garmin to stop sending us data and delete the Garmin access tokens we hold for you. Data already imported stays in your record until you delete it or ask us to delete it using the contact details above. If you delete your Fueld account, we delete your Garmin data with it.

Transfer of your information out of the UK and EEA

Some of our processors are located outside the UK and European Economic Area (for example, in the United States). Where we transfer your personal information internationally, we ensure appropriate safeguards are in place — such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses, or an adequacy decision — so that your information remains protected. Please contact us if you would like more information.

Cookies and similar technologies

A cookie is a small text file placed onto your device when you use our app or website. These help us recognise you and your device, remember your preferences, and understand and improve how the Service is used. We ask for your consent before placing non-essential cookies. For further information, including how to manage cookies, please see our Cookie Policy.

Marketing

Where we have your consent or it is in our legitimate interests to do so, we may send you information about products, services, offers and updates by email, telephone, text message or post. You can opt out of marketing at any time by emailing opt-out@fueld.ai, updating your preferences in the app, or using the 'unsubscribe' link in our emails. You will still receive service messages (such as billing or account updates) where necessary.

Your rights

Under applicable data protection law you have the following rights, free of charge:

  • Access — to be provided with a copy of your personal information.
  • Rectification — to require us to correct mistakes in your information.
  • Erasure — to require us to delete your information in certain situations.
  • Restriction — to require us to restrict processing in certain circumstances.
  • Portability — to receive your information in a structured, commonly used, machine-readable format, and to have it transmitted to a third party in certain situations.
  • Objection — to object at any time to processing for direct marketing, and in certain other situations.
  • Automated decisions — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise any of these rights, please contact us using the details above. We may need to verify your identity before responding.

How long we keep your information

We will not keep your personal information for longer than necessary for the purposes set out in this policy. When it is no longer needed, we will delete or anonymise it. If you purchase services from us, we generally keep your information while we provide those services and thereafter as long as necessary to respond to queries or claims, to demonstrate we treated you fairly, and to keep records required by law.

Keeping your information secure

We have appropriate technical and organisational measures in place to prevent your personal information from being accidentally lost, or used or accessed unlawfully. We limit access to those who have a genuine business need, and they are subject to a duty of confidentiality. We also have procedures to deal with any suspected data security breach and will notify you and any applicable regulator where legally required.

How to complain

We hope we can resolve any query or concern you raise about our use of your information. You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office, which you can contact at https://ico.org.uk/concerns or on 0303 123 1113.

Changes to this privacy policy

We keep this privacy policy under regular review to make sure it stays up to date. If we change it, we will post the details here and, where appropriate, notify you.

Last updated: 29 September 2026