PRIVACY POLICY
Last updated: August 8, 2026
SCOPE
This policy explains how Fierro Innovations handles personal data through both:
- the Specimen iOS app; and
- the Specimen website, including email signup, support, analytics, and website purchases.
The app and website use different data systems. The sections below identify which processing applies to each one.
1. SPECIMEN APP DATA
A) Data sent for AI analysis (during a check-in)
When you submit a check-in, the following data is sent to the active AI provider to generate your analysis:
- Photo — a downscaled copy of your check-in photo. Your face may be visible in the transmitted image. Your full-resolution photo is never transmitted and is stored only on your device.
- Single-pose mode: max 1024px, ~85% JPEG quality
- Multi-angle mode: max 1268px per image, ~65% JPEG quality
- Gemini debug mode (see Section 4): max 1536px, 75-85% JPEG quality
- Health metrics — biological sex, age, height, weight, and calculated BMI.
- Training context — your goal (for example: bulk, cut, recomp), experience level, self-assessed weakness, and target physique archetype if set.
- Body measurements — proportional measurements derived on-device using BlazePose and Apple Vision (for example shoulder width, limb ratios, body region percentages, asymmetry). Raw pixel buffers are not transmitted.
- Photo conditions — derived metadata such as distance estimate, lighting quality, sharpness, skin tone classification, overexposure flag, and shadowed body regions.
- Capture metadata (when present) — source (in-app camera vs photo library), camera position, 35mm-equivalent focal length, aperture, approximate image resolution, metadata quality rating (
full/partial/stripped).
B) Account and authentication data
If you sign in with Apple, Specimen stores and uses:
- Supabase user ID (UUID) — your stable account identifier.
- Email (if provided by Apple) — may be an Apple private relay address.
- Display name (if provided by Apple) — used in your profile.
We do not collect your Apple password.
C) Cloud sync data (when signed in)
If you are signed in, check-in metadata is synced to our Supabase backend, including:
- Check-in ID and timestamp
- Pose type
- Overall score and muscle score breakdown
- Weight, body fat estimate, and FFMI (when available)
- AI feedback text
- Derived photo context metadata
- Check-in sequence number and sync timestamp
Your full-resolution photos are not synced to Supabase by this flow.
Specimen does not currently download synced check-in history onto a new device or after reinstall. Local Export Backup / Import Backup, or re-capturing, is required to move history between devices.
D) Subscription and entitlement data
We use RevenueCat to manage subscription status. RevenueCat may process:
- App User ID (anonymous RevenueCat ID before sign-in, then your Supabase UUID after sign-in)
- App and OS version
- Device model and platform identifiers
- App Store transaction and receipt data
No check-in photos are shared with RevenueCat.
E) Product analytics (funnel and reliability)
Specimen logs limited product events to Supabase so we can measure onboarding completion, paywall presentation, and analysis reliability. These events do not include check-in photos, AI feedback text, muscle scores, body measurements, or onboarding answers such as experience, frequency, height, weight, or archetype.
Onboarding funnel (onboarding_events) — may be recorded before Sign in with Apple:
- RevenueCat App User ID, which is anonymous until you sign in
- Optional Supabase user ID after sign-in
- Step name or number and event type, such as viewed, advanced, back, skipped, sign-in succeeded, or baseline started, completed, abandoned, deferred, or retried
- Optional attempt context, such as capture route, attempt number, scan angle, or failure category
- App version, build, and install channel, such as development, TestFlight, or App Store
Account profile (profiles) — after Sign in with Apple, we store an optional display name plus the last-seen install channel, app version, build, and bundle ID.
Synced check-in metadata (check_ins) — includes whether a check-in is a baseline and the install channel for the device that synced it. Photos are not stored in this table.
Paywall events (paywall_events) and analysis events (analysis_events) — operational events for subscription UI and analysis success or failure, such as request outcome and duration. Image payloads and prompts are not stored in these tables.
F) Advertising attribution (optional, ATT-gated)
Specimen uses Meta (Facebook) App Events and related measurement for advertising attribution and campaign performance. When you allow tracking via Apple’s App Tracking Transparency prompt, we may process:
- Device advertising identifiers (for example IDFA) and Meta anonymous identifiers
- App open / activation events and limited product funnel events (for example paywall shown)
- Subscription-related conversion signals sent via RevenueCat’s server-side Conversions API (not as client purchase logs)
If you decline ATT, we do not enable advertiser tracking identifiers for that purpose. Some aggregated / SKAdNetwork measurement may still occur as allowed by Apple and Meta without identifying you across apps.
No check-in photos are shared with Meta.
2. SPECIMEN WEBSITE DATA
Using the website does not send your Specimen check-in photos, physique analysis, or in-app health data to the website analytics systems.
A) Website analytics
The Specimen website uses HeyCatch and Vercel Analytics to understand site usage, improve the website, and measure campaign performance. These services may process:
- Site visits, sessions, page navigation, clicks, and form submission events (not the contents typed into form fields)
- Device and browser information, IP address, and approximate location
- Campaign attribution parameters
- Signup and payment events
HeyCatch processes website analytics on our behalf and may use its own subprocessors to provide that service. No Specimen check-in photos or AI analysis results are shared with HeyCatch or Vercel Analytics.
B) Email signup and communications
If you submit your email address on the website, we use Supabase and Resend to store and manage the signup and send requested product communications. We may process:
- Email address
- Signup date and subscription status
- Campaign, segment, or signup tags associated with the form or link you used
- Delivery, bounce, and unsubscribe events
You can unsubscribe using the link in an email or contact us using the address in Section 9.
C) Website purchases
Stripe processes payment details for purchases made through the website. Specimen does not receive or store your full payment card number. We may receive and store:
- Purchaser email address
- Stripe checkout session and payment status
- Product or plan purchased, amount, and currency
- The email used to match a website purchase to an in-app account
- Entitlement fulfillment and refund status
When a website purchase is completed, we may send a purchase-completion event to HeyCatch and associate it with a stable internal purchaser ID and purchase details. No check-in photos or AI analysis data are included.
3. WHAT WE DO NOT COLLECT OR DO
- We do not sell your personal data.
- We do not use your check-in photos for advertising.
- On-device pose/measurement processing occurs locally. Raw pixel buffers from on-device processing are not uploaded by that processing pipeline.
- Specimen does not provide any feature where users can browse other users' check-in photos.
- The Specimen team does not manually review check-in photos submitted for analysis as part of normal operations.
- Our operational logs are designed to capture diagnostic metadata (for example request success/failure and token usage), not image payload contents.
Specimen uses paid commercial API tiers for AI processing. Under Anthropic's current commercial API terms, inputs and outputs are not used to train Anthropic's generative models by default. Anthropic's standard commercial retention is to delete API inputs and outputs within about 30 days, except where longer retention is required for safety, abuse enforcement, legal compliance, or a different contractual arrangement. Specimen does not promise a shorter provider-side deletion window.
If Gemini debug mode is enabled on a development build, Google's paid Gemini API terms similarly state that prompts and responses are not used to improve Google's products. Google may still log them for a limited period for abuse and safety monitoring. App Store production builds do not expose a user-facing control to send check-ins to Gemini.
AI providers process submitted photos automatically to produce analysis output. Any provider-side personnel access is governed by the provider's privacy/security terms and legal obligations, not by a Specimen human review workflow.
4. THIRD-PARTY SERVICES
Supabase — account authentication (Sign in with Apple token exchange) and cloud storage for signed-in profile/check-in metadata. https://supabase.com/privacy
Anthropic — default AI analysis provider for check-ins. https://www.anthropic.com/legal/privacy
Google (Gemini API) — alternate AI provider available only behind a hidden debug toggle in development builds. App Store production builds do not expose this toggle. If the toggle is not enabled, check-in analysis is not sent to Google. https://policies.google.com/privacy
RevenueCat — subscription and entitlement management; may also forward limited conversion events for Meta advertising measurement. https://www.revenuecat.com/privacy
Meta (Facebook) — advertising attribution and App Events measurement (ATT-gated where required). https://www.facebook.com/privacy/policy/
HeyCatch — website product analytics and campaign attribution. HeyCatch acts as a data processor for site visitor events. https://heycatch.ai/privacy
Vercel — website hosting and website analytics. https://vercel.com/legal/privacy-policy
Stripe — payment processing for purchases made through the website. https://stripe.com/privacy
Resend — email delivery and contact management for website signups and transactional messages. https://resend.com/legal/privacy-policy
Apple — Sign in with Apple, App Tracking Transparency, and App Store purchase infrastructure. https://www.apple.com/legal/privacy/
5. DATA RETENTION
Local device data
Check-in photos and local analysis history remain on your device storage unless you delete them or remove the app. Photos are stored in the app container (not automatically saved to the Photos library).
Cloud account data
When signed in, your profile and synced check-in metadata are retained in Supabase until you delete your account or request deletion, subject to records we must retain for legal, security, fraud-prevention, or transaction purposes. Signing out does not delete your cloud records.
Account deletion in Settings removes your Supabase authentication user and owned app rows such as synced check-ins, profile, paywall events, and analysis events associated with your user ID. Pre-authentication onboarding funnel rows that contain only a RevenueCat App User ID may remain as anonymous funnel aggregates. RevenueCat subscription and transaction records, App Store records, and AI-provider operational logs are retained according to those processors' policies and legal obligations.
Website data
Email signup data is retained until you unsubscribe or request deletion, subject to limited suppression records used to respect your unsubscribe request. Website purchase and refund records may be retained for transaction, tax, accounting, fraud-prevention, and support purposes. Website analytics data is retained according to our configuration and the applicable processor terms.
Third-party processor retention
RevenueCat, Supabase, HeyCatch, Vercel, Stripe, Resend, and AI providers may retain operational logs or records according to their own retention policies and legal obligations.
6. YOUR CHOICES
- You can decline Apple App Tracking Transparency permission. Specimen will not enable advertiser tracking identifiers when permission is declined.
- You can unsubscribe from marketing email using the link in an email.
- You can request access, correction, or deletion of personal data by contacting us.
- You can delete a signed-in Specimen account from the app's account settings.
- Deleting the app removes local data in the app container. It does not by itself delete cloud account records. Signing out does not delete cloud records. Reinstalling does not restore local photos or local check-in history from the cloud.
Some rights vary based on where you live. We may need to verify your identity before completing a request.
7. SECURITY
We use reasonable administrative and technical safeguards intended to protect personal data. No storage or transmission system can be guaranteed to be completely secure.
8. CHILDREN
Specimen is intended for adults. We do not knowingly collect personal data from children. The minimum age for use is under legal review; the current product accepts ages 16 and up for profile calibration, and this policy, product UI, and store disclosures will be aligned after that review.
9. CONTACT
Privacy questions or requests: matt@fierroinnovations.com