Last updated: July 4, 2026
Alvo (“we”, “our”, or “us”) is an AI personal-trainer app for workouts and nutrition. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights — including for users in the EU/EEA/UK and California. By using Alvo you agree to this Policy.
We do not collect payment-card numbers. Subscriptions (if any) are processed by Google Play; we never receive or store your card details.
Alvo is a fitness app, so the workout, nutrition, weight and energy information you enter is health-related data. We treat it as sensitive/special-category data, process it only to provide the app’s features (building your plan, tracking progress), and store it locally on your device (see section 7). We do not read data from Health Connect, wearables, or your device calendar.
We and our service providers (Google/Firebase) may collect standard technical data such as device model, app version, language, and diagnostics/usage events to keep the app working and secure. See Google’s Privacy Policy for how Google processes such data.
When you use AI features (daily plan, chat, meal estimate), the text you provide (e.g. a meal description or chat message) plus relevant profile/plan data is sent to Google’s Gemini AI through our secure server to generate a response. If you use the meal-photo scanner, the photo you take is sent the same way to estimate the meal — it is used only to generate that estimate and is not stored on our servers. We do not sell this data or use it for ads.
Your profile, plans, meals, workouts and settings are stored on your device. So that your data follows you if you change phones, a copy of your profile settings and your workout, weight and body-measurement logs is also backed up to Google Firebase (Cloud Firestore) under your account. Access rules allow only your own signed-in account to read or write that copy.
Some things are deliberately never uploaded: your conversations with the AI coach and your progress photos stay on your device only. Account sign-in is handled by Google Firebase Authentication. All data sent off the device travels over encrypted (HTTPS) connections.
We do not sell your personal information. We share data only with:
We operate from Israel, and our providers (Google) process data in various countries including the United States. Where required, such transfers rely on appropriate safeguards (e.g. the EU Standard Contractual Clauses and providers’ adequacy mechanisms). By using the app you understand your data may be processed outside your country.
We keep your data only while your account exists. You can erase everything anytime from Profile → Delete Account, which removes your local data, your cloud backup, and your account. Your conversations with the AI coach are kept on your device only while you use them and are removed automatically after a week of not being opened. We retain only what the law requires us to keep, such as records of payments made through Google Play.
You have the right to: access your data, correct it, delete it (“right to be forgotten”), restrict or object to processing, data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority. To exercise these, use the app or email us; we respond within the legally required time (generally one month).
California residents have the right to know what personal information we collect and why, to access and delete it, to correct it, and to non-discrimination for exercising these rights. We do not sell or “share” (for cross-context behavioral advertising) your personal information. To exercise these rights, email us.
If you are elsewhere, you may have similar rights under your local law (e.g. Canada, Brazil/LGPD, Australia). Contact us and we will honor applicable rights.
We use reasonable safeguards: encrypted (HTTPS) transmission, hashed passwords / Firebase Authentication, and least-privilege access. No system is perfectly secure, but we work to protect your information and will notify you and authorities of a breach where the law requires.
Alvo is not intended for anyone under 13 (or the minimum age in your country). We do not knowingly collect data from children. If you believe a child provided us data, contact us and we will delete it.
We may update this Policy; we will change the “Last updated” date and, where required, notify you. Continued use after an update means you accept it.
Privacy questions or requests: alvocontact1@gmail.com