Privacy Policy
Your privacy isn't just a feature, it's our foundation.
Last updated: April 2026
Data Controller
The data controller responsible for this privacy policy, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:
Cloak Disciplines OÜ
Ruunaoja tn 3, Lasnamäe linnaosa
11415 Tallinn, Harju maakond
Estonia
Registry code: 17494928
Email: privacy@disciplines.app
Our Privacy Commitment
Disciplines is built on a simple principle: your wellness data belongs to you and only you. We operate no backend servers at all. We cannot see what you track, how you use the app, or anything about your wellness journey. We have no access to your personal information because it never leaves your device.
What Data We Collect
None.
Disciplines does not collect, transmit, or store any personal data. We operate no backend servers for the app. All data you enter, including tracking data, goals, preferences, settings, and custom entries, is stored exclusively on your device. It is encrypted at rest and inaccessible to other apps.
We do not have access to your wellness metrics, usage patterns, device information, location, or identity.
iCloud Sync (Optional)
If you choose to enable iCloud sync:
- Your data is stored in your personal iCloud account, managed by Apple
- Apple encrypts this data end-to-end
- We have no access to your iCloud data
- You can disable sync at any time
- Deleting the app removes all local data. iCloud data is subject to Apple's retention policies
Content Library Downloads (Optional)
Disciplines includes an optional Content Library where you can download additional food databases into the app. These downloads are delivered through Cloudflare, which acts as a data processor on our behalf.
- Your device only sends the name of the file you are requesting. No user ID, device ID, account information, or wellness data is included.
- Cloudflare sees your IP address, as is the case with any internet request, and processes it briefly to deliver the file. It is not used by us to identify or track you.
You can use the app fully without ever downloading from the Content Library; the core food database is bundled with the app and works entirely offline.
Third-Party Services
Aside from Cloudflare, which is used solely to deliver optional Content Library downloads as described above, we do not use any third-party services in our app. There are no analytics SDKs, no advertising networks, no social media trackers, and no crash reporting services. We do not share any data with third parties for marketing, profiling, or tracking purposes.
Diagnostic Logs
Disciplines includes an optional offline diagnostic log feature to help troubleshoot issues. If you choose to use it, the app generates a log stored entirely on your device containing only your iOS version, app version, and device model. No wellness data, personal information, or usage history is included. The app has no capability to send these logs. If you choose to share them with us, you can do so manually by pasting the log content into our contact page.
Data Export & Portability
Every user, whether you are on the Free tier or on Premium, can trigger a "Download My Data" action directly from the app at any time, at no cost to you, with no subscription, paywall, quota, or need to contact us. This is how we fulfill your GDPR right of access (Article 15) and your right to data portability (Article 20).
The resulting file is a structured, portable, human-readable JSON copy of the personal data you have entered into the app: profile details, logged meals, activities, measurements, habits, moods, and so on. It does not include data inferred or computed by the app (such as BMR estimates or nutrition breakdowns derived from the food database), and it cannot be re-imported to restore your data into the app.
Premium users additionally get CSV export and encrypted raw backups. Unlike the JSON export, these include the full dataset (both user-entered and app-computed data such as analytics, trends, and derived nutrition breakdowns) and are designed for in-depth analytics, transferring data between devices, and full backup/restore.
Data Deletion
Because all data is stored on your device:
- Deleting the app removes all local data permanently
- We have no data to delete on our end
- If you use iCloud sync, you can remove iCloud data through Apple's standard process
Under applicable data protection laws, you have the right to request deletion of your personal data. Because we do not collect or store any personal data, there is nothing for us to delete. You are in full control of your data at all times.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access and portability: You can download a complete copy of your data directly from the app at any time (see Data Export & Portability above)
- Deletion: You can delete all data by removing the app from your device
- Rectification: You can edit any data directly within the app
- Objection and restriction: Because we do not process your data on our servers, these rights are inherently fulfilled
If you believe your privacy rights have not been addressed, you have the right to lodge a complaint with your local data protection authority.
Children's Privacy
Disciplines is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please reach out through our contact page and we will take appropriate action.
Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you through the app. Our core commitment will never change: your data stays on your device.
Contact
If you have questions about this privacy policy or our data practices, or wish to exercise any of the rights described above, you can reach us through our contact page (select "Privacy Concern" as the category) or by email at privacy@disciplines.app.
Website Privacy
This website (disciplines.app) follows the same privacy principles as our app:
- No analytics: We do not use any visitor tracking or analytics services
- No cookies: This website does not set any cookies
- No fingerprinting: We do not track your browser or device
- No third-party trackers: There are no advertising pixels, social media scripts, or marketing tools
Language Detection
This website reads your browser's language preference to display content in the appropriate language. This information is not stored, logged, or transmitted to any server.
Contact Form
When you submit the contact form, your message is sent to our support system. We use your email address solely to respond to your inquiry. Contact form submissions are automatically deleted after 180 days.
Security
If you discover a security vulnerability, please report it through our contact page. Our security contact information is also available at /.well-known/security.txt.