← Back to home

Privacy

Privacy policy

Last updated: 4 August 2026

At 12×7 you entrust us with sensitive data about your health and habits. We take that seriously. Below you can read, in plain language, exactly what we process, why, who we share it with and how you stay in control of it yourself. Everything is based on what the app actually does.

01Who is responsible for your data

12×7 is provided by ALC Dynamics, with its registered office at Laarnebaan 109, 9070 Heusden, Belgium, company number BE 1023.184.308. ALC Dynamics is the controller for all personal data described in this policy.

Questions about your data or this policy can be asked through the contact block at the bottom of this page. We respond within one month.

02What we process about you

12×7 processes the following categories of personal data:

  • Account data: your email address, your password (stored encrypted by our login service) or your Google account link if you sign in with Google, and the status of your email verification.
  • Profile data: your name, age, sex, height, activity level, start date, profile photo (if you set one) and your preferences such as theme, colour and coach style.
  • Free text that you enter yourself, such as "extra info" on your profile (for example injuries, allergies or goals), day notes and your weekly self-review.
  • Health and lifestyle data: your starting, goal and current weight and your full weight history; body measurements (waist, thigh, arm); your meals with estimated calories and macros; water intake; hours of sleep; your mental and physical wellbeing scores; sport and exercise; and habits such as meditation.
  • Progress photos of your body, only if you take them yourself: an optional starting photo and one photo per weekly review. The photo is resized on your own device and stored as a compact JPEG in your own record in our database. Only you can see these photos, never your friends. They are included in your data export and are deleted together with your account.
  • AI content: your conversations with the 12×7 Coach (stored per day with your diary) and the daily and weekly AI feedback generated for you.
  • Social data: friend requests and friendships (for which the email address and name of both persons are recorded), your sharing choices per friend (which parts you share with whom) and shared weekly menus.
  • Strava data, only if you connect Strava: the connection keys (tokens) and, per imported activity, the name, distance, duration and date.
  • Push notifications, only if you switch them on yourself: the notification key (token) of your device and your reminder preferences, stored in your own record. If you switch notifications off in your Profile, they are deleted.
  • Support and feedback: if you send a support question or feedback through the app, we store with it your user ID, your email address, your name, technical browser info (user agent) and the text you write yourself, so that we can handle your request.
  • Technical data in our database: per account a counter of your AI usage (kept for 7 days), technical log events per AI request with your user ID (kept for 30 days, then deleted automatically), a daily marker that your account was active (30 days), a "last seen" timestamp that is overwritten each time, and a marker when an account exceeds the usage limits. This serves cost monitoring, abuse detection and stability.

Meal photos that you take to log a meal are not stored: they are viewed once by the AI to estimate a description and nutritional values, and only that text is kept. Progress photos (above) are the exception: we do store those, exclusively for you. When you scan a barcode, the barcode is looked up at Open Food Facts; the result appears as text in your input field.

03What we use your data for, and on what legal basis

We only use your data for the following purposes, each with a legal basis from the GDPR (Article 6):

  • To make your account and your 12-week programme work: storing your diary, progress and settings. Legal basis: performance of the contract (Art. 6.1.b).
  • To deliver your personal AI features: estimates of calories and macros, the 12×7 Coach, daily and weekly feedback and FoodLab recipes. Legal basis: performance of the contract (Art. 6.1.b); for the health data involved, your explicit consent applies in addition (see below).
  • To process your payment and keep our administration. Legal basis: performance of the contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).
  • To send you account emails (email verification and password reset). Legal basis: performance of the contract (Art. 6.1.b).
  • To secure the service and prevent misuse (such as limits on the number of AI requests). Legal basis: legitimate interest (Art. 6.1.f).
  • To track down technical errors and keep the app stable and affordable: crash reports, AI usage counters and the technical log events from the previous section. Legal basis: legitimate interest (Art. 6.1.f).
  • To handle your support questions and feedback. Legal basis: performance of the contract (Art. 6.1.b) and legitimate interest (Art. 6.1.f).

We do not use your data for advertising, we do not sell it to anyone and we do not engage in profiling for marketing purposes. The app contains no analytics or marketing tracking. What there is: a service for crash reports (Sentry), exclusively to find technical errors and configured in a privacy-friendly way. Exactly how is explained under "Who we share data with".

04Health data and your explicit consent

Your weight, body measurements, nutrition, exercise, sleep, wellbeing scores and progress photos are health data. That is a special category of personal data under the GDPR, to which extra protection applies.

We process this data exclusively on the basis of your explicit consent (Art. 9.2.a GDPR). You give it when creating your account, through a separate, ticked declaration. Without that consent 12×7 cannot work, because the programme revolves entirely around this data.

You can withdraw your consent at any time (see "Your rights"). From that moment the processing stops; because the app can then no longer function, withdrawing in practice means that your account and data are deleted at your request.

05How AI (Google Gemini) works with your data

The smart features of 12×7 run on Google Gemini, an AI model by Google. For this, our own server sends data to the Gemini service and passes the answer back to you. Google acts as a processor here; the AI requests always run through our server, never directly from your device. In concrete terms, the following is sent along per feature:

  • Logging a meal with text: the description you type.
  • Logging a meal with a photo: the photo itself. It is processed once and not stored; only the text description and nutritional values the AI returns are kept.
  • Logging exercise: your description of the activity and your body weight (for the calorie estimate).
  • Daily feedback: a summary of your day, with your meals, water, sleep and wellbeing scores.
  • Weekly review: your name, weights, the day data of that week and the self-review you wrote yourself.
  • The 12×7 Coach: your name, starting and goal weight, your "extra info", your diary for today (meals, water, sleep, wellbeing scores), the names of your saved recipes, your full weight history and the entire ongoing conversation.
  • FoodLab: your preferences (type of meal, portions, dietary wish) and your free description. If you paste a link to a recipe, that web page is retrieved through Google Search to read the recipe.
  • Shopping list: the ingredient list of your weekly menu.

What this means for you: the texts, photos and health data above are processed by Google to generate the answer, under the terms of the Gemini API. The answers of the AI are not stored with us by Google; what is kept (such as your chat history and daily feedback) sits in your own record in our database.

06What your friends can see

You add friends yourself: someone sends a request and the other person accepts. Without an accepted request nobody can see anything of yours.

Even after accepting, nothing is shared by default. You tick, per friend, which parts that person may see: your progress, your roster, your diary and/or your recipes. Only the ticked parts are visible. This is technically enforced on our server, with a separate sharing document per part per friend, so a friend can never request more than you have switched on.

A number of things are never shared, whatever you tick: your conversations with the coach, your personal notes, the free text of your weekly reviews and your progress photos. Your Strava connection keys are never visible to friends either.

You can untick a box again at any time and you can end a friendship yourself in the app at any time; access stops immediately when you do.

07Who we share data with

We never sell your data. We only share it with the parties needed to make 12×7 work:

  • Google (Firebase and Google Cloud): sign-in and account management, our database and the server 12×7 runs on.
  • Google Gemini: the AI processing described above.
  • Sentry: our processor for crash reports (error reports), in the app and on the server. We have configured Sentry in a privacy-friendly way: by default no personal data is sent along, there is no performance tracking, and error reports are stripped of user IDs, headers and request content before they are sent. The reports go to Sentry’s European data centre; on delivery, Sentry’s infrastructure briefly processes your IP address.
  • Stripe: our payment provider. Your payment details (such as card numbers) are processed directly by Stripe; we do not see or store them.
  • Strava: only if you connect your Strava account yourself, to retrieve your activities.
  • Open Food Facts: only if you scan a barcode; your browser then requests the product directly from this open database, which sees your IP address in the process.
  • Friends you accept yourself, and then only the parts you tick per friend (see the previous section).

We conclude data processing agreements with processors. No advertising networks, analytics services or data brokers are involved. We ship the fonts of the app ourselves: no connection is made to Google Fonts or other font services.

08Where your data is stored and transfers outside the EEA

Our server and database run in the European Union (Google Cloud, region europe-west1 in Belgium). Your record is therefore stored within the EU. Crash reports also stay within the EU: they go to Sentry’s European data centre.

Some services may process data outside the European Economic Area, such as the Gemini AI processing by Google and, if you connect it, Strava (United States). For those transfers we rely on appropriate safeguards: the EU-US Data Privacy Framework and/or the standard contractual clauses of the European Commission.

09How long we keep your data

  • Your account and programme data (profile, diary, weights, wellbeing, chats, recipes): as long as your account exists. If you delete your account yourself in the app, that happens immediately; after a deletion request by email we erase everything within 30 days.
  • Coach conversations and AI feedback: the same period; per day you can also erase conversations yourself, immediately, in the app.
  • Progress photos: as long as your account exists; they are deleted together with your account.
  • Meal photos: are never kept.
  • Strava connection keys: until you ask to remove the connection or your account.
  • Notification keys and reminder preferences for push notifications: until you switch notifications off in your Profile, or until your account is deleted.
  • Friend requests, friendships (name and email address) and your sharing choices per friend: until you or your friend removes them, or until your account is erased.
  • Support tickets and feedback: as long as necessary to handle your request. If your account is deleted, they are anonymised: your user ID, email address and name are removed; only the text is kept.
  • Payment and invoice data: up to 10 years, as long as tax and accounting legislation requires.
  • AI usage counters per account: 7 days.
  • Technical log events per AI request (with user ID): 30 days, then deleted automatically.
  • Daily markers that your account was active: 30 days.
  • The "last seen" timestamp: only the most recent moment; it is overwritten each time.
  • Markers for exceeding the usage limits: as long as necessary to assess misuse and protect the service.

10What is stored on your own device

12×7 is a web app that you can install. The following is stored on your device:

  • Your login session, so that you do not have to sign in again every time (in browser storage).
  • An offline copy of your own record, so that the app also works without internet (in browser storage).
  • The app files themselves (design and code), so that the app starts quickly. No personal data is kept in this cache.
  • During registration: a temporary note of your consent tick boxes, which is removed again immediately after your account has been created.

We place no cookies for tracking or advertising and use no analytics. Everything on your device disappears when you sign out and clear your browser data.

11Your rights and how to exercise them

Under the GDPR you have the following rights. For each right we state how you use it in practice:

  • Access: you see almost all of your data directly in the app (diary, profile, progress, chats). You can also download a full overview yourself, immediately, through Profile → Privacy & account (data export). If that does not work, request it through the contact block at the bottom; you will receive it within one month.
  • Rectification: you adjust your profile, logs and notes yourself in the app. If something does not work, we adjust it after a message through the contact block.
  • Erasure: you delete individual parts (logs, chats per day, recipes, your profile photo, friendships) yourself in the app. Through Profile → Privacy & account you can also delete your entire account immediately, with everything that goes with it, including your Strava connection and the entries with friends and shared weekly menus (see "What happens when your account is deleted"). Prefer email? Then send a deletion request through the contact block; within 30 days everything is erased.
  • Restriction of processing: send a message through the contact block; we freeze the processing concerned while we handle your request.
  • Portability (export): download a digital copy of your data yourself, immediately, in a common, machine-readable format through Profile → Privacy & account. You can also request such a copy through the contact block; you will then receive it within one month.
  • Objection: you can object to processing based on legitimate interest through the contact block.
  • Withdrawing consent: you can do so at any time, without giving a reason, through the contact block. Because 12×7 cannot work without your health data, we then delete your account and data at your request.
  • Lodging a complaint: you can do so with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be). If you live in another country, you can also turn to the supervisory authority of your own country, such as the Autoriteit Persoonsgegevens in the Netherlands.

12What happens when your account is deleted

You delete your account yourself, immediately, through Profile → Privacy & account, or you send a deletion request through the contact block (we then erase everything within 30 days). In both cases the following disappears:

  • Your login account (email address and login details).
  • Your full record: profile, all 12 weeks of diary, weight and wellbeing data, coach conversations, AI feedback, progress photos and saved recipes.
  • Your Strava connection keys.
  • Your notification keys and reminder preferences for push notifications.
  • Your friend requests, friendships and sharing choices, including the mention of your name and email address with your friends.
  • Your membership of shared weekly menus.

Support tickets and feedback are anonymised on deletion: your user ID, email address and name are removed; only the text itself is kept. Technical log events disappear by themselves no later than 30 days after they were created.

We keep invoice data longer if the law requires it (see retention periods). The offline copy on your own device disappears as soon as you sign out or clear your browser data.

13Security

  • All connections are encrypted (HTTPS).
  • Strict access rules on the database: only you can read and change your record. Friends see exclusively the parts you have ticked per friend; that is enforced on the server.
  • Your Strava keys sit in a shielded part that is only accessible to you.
  • AI keys sit exclusively on our server and are never shared with your browser; limits against misuse apply per account.
  • Passwords are never stored in readable form; sign-in and password reset run through Firebase Authentication.

1418 years or older

12×7 is intended for adults only. When creating an account you explicitly confirm that you are 18 years or older. If we discover that a user is younger, we delete the account and the associated data.

15Changes to this policy

If we change the substance of this policy, we will let you know in the app or by email before the change takes effect. For changes that affect your consent, we ask for it again. The date at the top always shows the latest version.

Latest change (August 4, 2026): we brought this policy in line with what the app does today. New or clarified: progress photos, crash reports through Sentry, the technical counters and log events in our database, support and feedback, push notifications, and sharing with friends per part. Because this update touches on what you previously consented to, we ask existing users to confirm the updated declaration again on their next visit.

127

ALC Dynamics, privacy

For privacy questions and exercising your rights. We respond within one month.

ALC Dynamics · BE 1023.184.308