Privacy Policy
Last updated: August 30, 2026
This policy explains what data Camber collects, how it's used, and what rights you have. We've written it in plain language on purpose. If something isn't clear, email us at admin@camber.fit.
Who we are
Camber is a nutrition, meal planning, and fitness app operated by Blauer Hund Holdings LLC ("BHH"), a Wyoming limited liability company. References to "Camber," "we," "us," or "our" in this policy refer to BHH. Contact: admin@camber.fit
What we collect
Account information
Authentication is handled by Clerk. When you sign up, Clerk provides us with your primary email address and, if you sign in with Google or Apple, your name. We store this to identify your account and, if you opt in, send you product updates.
Profile and health data
To calculate your macro targets and filter what we show you, we ask for: height, weight, date of birth, biological sex, activity level, primary goal, health focus areas, sport or training style, and diet preferences. You can skip most of these. Pronouns are optional, used only to address you correctly, and never used in any calculation. This is health-related data and is treated accordingly (see the Health Data section below).
Allergens and intolerances get special handling: allergen selections are hard exclusions (we never surface those recipes), and we treat them as elevated-sensitivity data internally. They are never written to application logs.
Daily logs and measurements
If you log them, we store daily wellness entries: sleep, water, mood, energy, soreness, body weight, and body measurements, each with the time it occurred. These exist so you can see trends and so the app can adapt your plan to how you're actually doing.
Food and nutrition logs
When you log something you ate, we store what it was and its nutrition values (calories, protein, carbs, fat, and alcohol where relevant) frozen at the moment you logged it. This is a dietary record and is treated as health data.
To find what you ate, the app looks products up by name or barcode in USDA FoodData Central and Open Food Facts. A lookup sends the search term or the barcode number, never your identity. If you describe a meal in words, that text is processed by Google's Gemini API only to split it into items; the nutrition values come from USDA, not from the AI. If a product is in neither database and you fill in its label yourself, the product's name and nutrition (not your name or account) become available to other Camber users who scan the same barcode.
Workout data
Workout sessions and their contents: session type, date, duration, per-set load and reps, effort ratings (RPE/RIR), failure markers, cardio sessions, and any free-text notes you attach. Notes are treated as health data regardless of what you write in them, because only you know what they contain.
Coaching suggestions we generate
When you report soreness or pain, Camber may generate a recovery suggestion: for example, a proposed training modification, and in some cases a prompt to consider seeing a physical therapist. These generated suggestions are stored with your account and treated as health data, because they are inferences about you. They are wellness suggestions, not medical advice, diagnosis, or treatment.
Connected health services (Apple Health, Health Connect)
If you connect Apple Health or Health Connect, the app reads steps, active energy, workouts, sleep, and weight to show you your own measured day next to what you logged. By default that data stays on your phone: nothing is sent to our servers and nothing is stored by us.
If you turn on activity backup in Settings, we store daily totals plus your workouts: steps and active calories per day, and each workout's type, start time, length, steps, and calories. Not routes, not locations, not heart rate, and never the sleep or weight readings from your device. Turn it off any time; when you do, we offer to erase everything that was backed up. Data from connected health services is never shared with any third party, never used for advertising, and never read by the AI features described below. That last separation is enforced in our code and covered by automated tests.
Photos you take or choose
Three features work from an image: reading a nutrition label when a product is not in any database, reading a recipe from a photo of a page, and importing your history from screenshots of another app. In each case the image is sent to our server and processed by Google's Gemini API to read it. Label and recipe photos are held in memory only for that request and are not stored. History screenshots are deleted as soon as you finish the import, or within 24 hours if you step away; keeping them for the full 24 hours is an option you choose per import. We do not share your photos with anyone other than Google for that processing pass.
Screenshots may incidentally contain other people’s information (for example a social feed or a family member's data). Such data is processed transiently with the same care as your own and is deleted on the same schedule.
Scanning a barcode uses the camera, but no image leaves your phone: the barcode is decoded on the device and only its digits are sent, to look the product up.
Imports from other apps
When you upload an export file from MyFitnessPal, Cronometer, Strong, Hevy, Apple Health, Strava, or similar services, we parse it to compute your baseline and store the results. Raw upload files are not retained after processing.
Session and device data
We store a session identifier and your preferences (unit system, theme, time format). If you enable reminders or notifications in the mobile app, we store a push token for your device so we can deliver them; notification content is deliberately generic and never includes health details. We do not collect device identifiers for tracking, IP addresses for tracking, or advertising IDs.
Account state and consents
Whether your account is active, paused, or scheduled for deletion; which version of the Terms you accepted and when; and a record of any data consents you grant or withdraw in Settings. We use these to decide what we're allowed to store, whether to send you outbound messages, and whether to run a scheduled deletion. See "Data retention and your right to deletion" below.
What we deliberately do not collect
As of the date above, Camber does not accept logging of menstrual-cycle data, GLP-1 or other medication data, or supplement data. This is not just a missing feature: our server actively rejects these categories, and that rejection is covered by automated tests. If we add support for any of them later, it will be opt-in behind its own explicit consent step, and this policy will be updated first.
AI processing
Some features send data to Google's Gemini API so the app can work: images you submit (nutrition labels, recipe pages, and screenshots of your history) are processed to read them; a meal you describe in words is processed to split it into items; and when you report soreness or pain after a workout, a de-identified summary (body region and intensity, never your name or account details) is processed to generate recovery suggestions. We use Google's paid API tier, and under its terms Google does not use your data to train or improve its models; Google may retain requests briefly for abuse monitoring and service security. Your medication and other sensitive health entries, and any data from connected health services, are never sent to any AI system; that separation is enforced in our code and covered by automated tests.
Health data
Camber handles consumer health data as defined by the FTC Health Breach Notification Rule (HBNR). This includes body metrics, nutrition and dietary logs, wellness logs, fitness activity, generated coaching suggestions, and any data you import from connected health services.
We do not sell health data. We do not share health data with advertisers. Health data is never used to target you with ads, inside or outside the app.
Data read from Apple Health or Health Connect carries one more commitment: it is never shared with any third party for any purpose, and it is never used by our AI features.
In the event of a data breach affecting your health information, we will notify affected users within 60 days, consistent with FTC HBNR requirements.
Usage analytics
We collect a small, fixed set of named in-app events, such as which screens you visit and key actions like logging a food, to understand where the app helps and where it gets in your way. This data goes only to our own servers. It is never shared with or sold to anyone, never used for advertising, and never includes the content of sensitive records such as medication logging or consent choices, which produce no analytics events at all.
You can turn usage analytics off at any time in Settings, on the web and in the app. Raw event data is deleted after 90 days.
How we use your data
To run the app
Calculate your macro targets, generate meal plans, build your shopping list, track your training.
To adapt to you
Your logs drive plan adjustments and recovery suggestions, so the app can meet you where you are.
To improve the app
Anonymized, non-identifiable usage patterns (which features are used, not your health values) help us understand what works and what to build next.
To contact you
If you provide an email, we may send product updates or respond to your feedback. You can opt out anytime.
For legal compliance
To meet our obligations under FTC HBNR, CCPA, and applicable law.
We do not use your data for advertising, profiling for third-party marketing, or any purpose not listed above.
Third-party services
Running Camber requires a small number of trusted infrastructure providers. Each receives only the data necessary to perform their function.
- ClerkAuthentication. Handles sign-in, sign-up, and session management. Receives your email and name; no health data.
- NeonPostgreSQL database hosting. Stores your account, profile, and log data on our behalf.
- RenderBackend API hosting. Processes app data, including uploaded import media, on our behalf.
- VercelFrontend hosting.
- ResendTransactional email (feedback confirmations, product updates).
- GoogleGemini API reads the images you submit (nutrition labels, recipe pages, history screenshots), splits meals you describe in words into items, processes recipe text when we extract nutrition, and processes de-identified soreness summaries to generate recovery suggestions. We do not send your name, email, or account identity to Gemini. We use the paid API tier, under which Google does not use the data to train its models. See the AI processing section above.
- USDA FoodData CentralPublic nutrition database run by the US Department of Agriculture. Receives the food name you search for or the barcode you scan; no account identity.
- Open Food FactsPublic, community-maintained product database. Receives the barcode you scan; no account identity.
- SentryError monitoring for the website and backend. Receives error reports and stack traces; request bodies and variable contents are disabled, so health values do not ride along.
- PostHogProduct analytics on the website only (the mobile app ships no analytics). Receives which features are used, as event names, tied to your user ID. It does not receive health values, log contents, or profile details.
- BetterStackApplication log drain. Receives our backend logs, which include your Clerk user ID alongside which API endpoints you hit and how long they took. No health values, no profile contents. Used for debugging and incident response only.
We do not sell data to any third party. We do not use data brokers. The mobile app contains no third-party analytics, advertising, or tracking SDKs.
Affiliate links
Some links in Camber are affiliate links. When you purchase through them, we may earn a small commission at no extra cost to you. This is one of the ways we keep the app running.
Affiliate relationships never influence what we recommend or how we rank anything. If you prefer a link with no affiliate tracking, contact us and we'll provide one.
Data retention and your right to deletion
Camber offers two ways to step away from the app:
Pause your account
Reversible. We stop sending you any emails, push notifications, or texts; if you have a paid subscription, billing pauses too. Your data stays put. Sign in any time to reactivate. Paused accounts that stay inactive for one year are automatically converted to a delete request; we'll email you eleven months in if you're approaching that window.
Delete your account
Permanent. By default there's a 24-hour grace period; sign in any time during those 24 hours to cancel. There's an opt-out checkbox for immediate deletion if you'd prefer no waiting period.
When you delete, we permanently remove: your name, email, profile, meal plans, shopping lists, daily logs, food logs, workout history, generated coaching suggestions, push tokens, activity backed up from connected health services, usage analytics events, any import photos still within their retention window, and any connected integration data.
What we keep, with your identity removed:
- Recipes you submitted are kept and attributed as "[Previous User]"; the recipe is a contribution to the community, your identity isn't.
- Recipe ratings you gave are kept and counted in community averages, but the link to your account is removed.
- Product feedback you submitted is kept (we use it to improve the app), but your name and email are removed.
What we keep that's still identifying, and why: a one-line internal record (your Clerk user ID, email, and deletion timestamp) is retained as legal proof that we honored your deletion request. This record contains no health data and is never used for any other purpose.
To delete or pause: Settings → Account. You can also email admin@camber.fit and we will process the deletion manually within 5 business days.
California residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it's used
- Request deletion of your personal information
- Opt out of the sale of your personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise any of these rights, email admin@camber.fit. We will respond within 45 days.
Children's privacy
Camber is intended for adults (18+). It is not directed at children under 13 (or 16 in the EEA and similar jurisdictions), and we do not knowingly collect personal information from children under those ages. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
Changes to this policy
We may update this policy as the app evolves. Material changes will be communicated via in-app notice or email if you have one on file. The "last updated" date at the top of this page reflects the most recent revision.
Contact
Questions, requests, or concerns: admin@camber.fit