Privacy Policy
Version 1.8 | Last Updated: March 25, 2026
This Privacy Policy describes how Novion collects, uses, processes, shares, and protects your information when you use the Novion mobile application, website, and related services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Interpretation and Definitions
1.1 Interpretation
Capitalized terms have the meanings assigned to them in this Policy. These definitions shall have the same meaning regardless of whether they appear in singular or plural form.
1.2 Definitions
For the purposes of this Privacy Policy:
- Account means the unique profile created for you to access the Service.
- Application means the mobile application titled "Novion" available on iOS and Android platforms.
- Company (referred to as "Novion," "we," "us," or "our") refers to Novion.
- Device means any device used to access the Service, including mobile phones, tablets, and computers.
- Personal Data means information that identifies or can reasonably be linked to an individual.
- Health Data means information you provide relating to your physical characteristics, health, nutrition, goals, or activity, including weight, height, food logs, workout data, and progress photos.
- Usage Data means data collected automatically through use of the Service, including device information, activity logs, and analytics data.
- User Content means photos, images, text, food entries, metadata, or other inputs you upload or submit through the Service.
- Star means a fitness creator who publishes content on the Novion platform.
- Program means a fitness or wellness program created and sold by a Star.
- Website means novionapp.com.
- You means the individual using the Service or the organization on whose behalf the Service is used.
2. Types of Data We Collect
We collect the categories of data described below. Certain categories may qualify as health information, sensitive personal information, or biometric-adjacent data under various privacy laws.
2.1 Personal Data You Provide
- Account Information: When you register, we collect your name, email address, and password.
- Profile Information: Age, height, weight, fitness goals, and other information you choose to provide.
- Health and Fitness Data: Workout details, nutrition information, and other fitness metrics you input or generate through the Application.
- Photos and Images: Food photos you upload for AI-powered nutritional analysis through our food scanning feature.
2.2 Data Collected Automatically
- Usage Information: How you interact with our Application, including features used and time spent.
- Device Information: Information about the device you use to access our Application, including device type, operating system, and unique device identifiers.
3. How We Use Your Information
We use your information for the following purposes:
- Providing and improving our Application and services
- Personalizing your experience
- Generating insights and recommendations based on your health and fitness data
- Communicating with you about your account, updates, and new features
- Analyzing usage patterns to improve our Application
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
With third-party service providers who help us operate our Application.
4.2 Legal Requirements
When required by law or to protect our rights.
4.3 Business Transfers
In connection with a merger, acquisition, or sale of assets.
5. Coaching Relationships & Data Access
Novion offers coaching features that enable Stars (coaches) to work directly with clients through the platform. This section describes how data is shared within coaching relationships.
5.1 Client Consent
When you accept a coaching invitation from a Star, you explicitly consent to sharing certain data with that coach. You must accept the Coach-Client Data Agreement before a coaching relationship is established. You may revoke this consent at any time by ending the coaching relationship.
5.2 Data Visible to Your Coach
When you are in an active coaching relationship, your coach can access the following data:
- Workout Logs: Exercise history, sets, reps, weights, and workout completion data
- Nutrition Logs: Food entries, calorie intake, and macronutrient data
- Weight Tracking: Body weight entries and trends over time
- XP Progression: Training consistency metrics and achievement data
- Progress Photos: Only if you explicitly choose to share them with your coach through the coaching interface
Your coach cannot access your account credentials, payment information, private messages with other users, or data from other coaching relationships.
5.3 Coach Obligations
- Coaches must keep all client data strictly confidential and may only use it for the purpose of providing coaching services within the Novion platform.
- Coaches may not share, export, sell, or otherwise disclose client data to any third party.
- Coaches may not use client data for marketing, research, or any purpose outside the coaching relationship without the client's separate written consent.
- Coaches who violate these obligations may have their accounts suspended or terminated.
5.4 Data Access After Coaching Ends
- When a coaching relationship ends (whether by client request, coach cancellation, or subscription expiration), the coach loses read access to the client's data immediately.
- Clients retain full access to their own fitness and health data regardless of the coaching relationship status.
- Coaching interaction records (messages, notes, assigned programs) are retained by Novion for 90 days after the relationship ends for dispute resolution purposes, after which they are deleted.
6. AI-Powered Food Analysis
When you use our food scanning feature, photos are analyzed by Google's Gemini AI to identify nutritional content and provide accurate food tracking.
6.1 How It Works
- Photos you take of food are sent to Google AI for analysis
- Google AI processes the image to identify food items and estimate nutritional values
- Only the nutritional data (calories, macros, etc.) is returned and saved to your account
- Photos are NOT stored by Google or Novion after analysis is complete
- You can choose not to use this feature and manually enter nutrition data instead
6.2 Your Consent
By using the food scanning feature, you consent to this AI processing. You are not required to use this feature and can opt to manually track nutrition instead.
6.3 Third-Party Processing
Google AI operates under Google's own privacy policies. For more information about how Google processes data, please visit Google's Privacy Policy.
7. Push Notifications and Communications
We may send push notifications to your mobile device to keep you informed about activity relevant to your account. This section describes the types of notifications we send, the data used to deliver them, and how you can manage your preferences.
7.1 Types of Notifications
We may send push notifications for the following purposes:
- Coaching Updates: Messages from your coach, new program or meal plan assignments, and coaching relationship status changes
- Subscription Updates: Changes to your subscription status, billing reminders, and renewal confirmations
- Activity Reminders: Workout reminders, nutrition logging prompts, and streak maintenance alerts
- Platform Announcements: New features, service updates, and important account notices
7.2 Data Used for Notifications
To deliver push notifications, we collect and use the following data:
- Push Token: A unique device identifier provided by Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM) when you grant notification permissions. This token does not contain personal information and is used solely to route notifications to your device.
- User ID: Your Novion account identifier, used to determine which notifications are relevant to you based on your subscriptions, coaching relationships, and activity.
Push tokens are stored securely in our database and are automatically removed when you log out, delete your account, or revoke notification permissions.
7.3 Managing and Opting Out of Notifications
You have full control over push notifications:
- iOS: Go to Settings > Notifications > Novion to disable all notifications or customize which notification types you receive.
- Android: Go to Settings > Apps > Novion > Notifications to disable all notifications or manage individual notification channels.
- Complete Opt-Out: Denying or revoking notification permissions on your device will prevent all push notifications from Novion. This does not affect your ability to use the Application or access any features.
Disabling push notifications does not unsubscribe you from essential account communications (such as password reset emails or critical security alerts), which are delivered via email.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
9. Your Rights and Choices
Depending on your location, you may have rights regarding your personal information, including:
- Accessing, correcting, or deleting your information
- Opting out of certain data collection
- Data portability
10. Star and Program Ratings
10.1 Public Rating System
Users can rate Stars and Programs on a 1-5 star scale. This information is used to maintain platform quality and help users make informed decisions.
10.2 Information Collected
- Star rating (1-5 scale)
- Optional written review
- User ID (to prevent duplicate ratings)
- Timestamp of rating submission
10.3 Public Visibility
- Individual ratings and reviews are publicly visible
- Average ratings and rating counts are displayed on Star profiles
- Your username (display name) will be shown with your written reviews
- Rating submissions are permanent and cannot be edited after 30 days
10.4 Purpose of Collection
- Maintain content quality standards
- Enable informed user decisions
- Enforce Star moderation policies
- Calculate quality-based metrics
10.5 Automated Moderation
Ratings are used in automated Star moderation systems. Stars with consistently low ratings (below 2.0 with 10+ ratings) may face temporary suspension. Critically low ratings (below 1.5 with 20+ ratings) may result in permanent account termination.
10.6 Rating Authenticity
We monitor rating activity for fraud and manipulation. Fake ratings, incentivized reviews, or rating manipulation may result in account suspension.
10.7 Data Retention for Ratings
Ratings are retained indefinitely to maintain historical quality metrics. If a Star's account is deleted, ratings are anonymized but aggregate statistics are preserved.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
11.1 Your Rights
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you, as well as the categories of sources, purposes, and third parties with whom we share it.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You may request that we correct inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale: We do not sell your personal information. However, you have the right to opt out of any future sale of your data.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
11.2 Categories of Personal Information Disclosed
In the preceding 12 months, we have disclosed the following categories of personal information for business purposes:
- Identifiers (name, email) - disclosed to authentication and database service providers
- Commercial information (purchase history) - disclosed to payment processors
- Health and fitness data - disclosed to AI service providers for food analysis (transient processing only)
- Device identifiers (push tokens) - used for push notification delivery via Apple Push Notification Service and Firebase Cloud Messaging
11.3 Submitting Requests
To exercise your California privacy rights, contact us at: novionapp+privacy@gmail.com. We will verify your identity before processing your request.
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
12.1 Legal Basis for Processing
- Contract Performance: Processing necessary to provide our services to you (account management, fitness tracking, content delivery)
- Legitimate Interests: Processing for fraud prevention, security, and service improvement
- Consent: Where you have given specific consent (e.g., AI food analysis, marketing communications)
- Legal Obligation: Processing required to comply with applicable laws
12.2 Your Rights Under GDPR
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
12.3 International Data Transfers
Your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses approved by the European Commission.
12.4 Submitting Requests
To exercise your GDPR rights, contact us at: novionapp+privacy@gmail.com. You also have the right to lodge a complaint with your local data protection authority.
13. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy:
- Account Data: Retained while your account is active. Upon account deletion request, personal data is deleted immediately.
- Workout and Nutrition Data: Deleted immediately when you delete your account.
- Food Photos: Not stored. Photos are processed transiently by AI and discarded immediately after analysis.
- Payment and Transaction Records: Retained for 7 years after the transaction date as required by tax and financial regulations.
- Ratings and Reviews: Retained indefinitely for platform quality purposes. If you delete your account, ratings are anonymized but aggregate statistics are preserved.
- Analytics Data: Anonymized and retained for service improvement purposes.
- External Subscriptions: Deleting your Novion account removes all data from our servers but does NOT cancel any active subscription billing through Apple App Store or Google Play. You must cancel subscriptions separately through your device settings.
- Coaching Data: Coaching interaction records (messages, notes, assigned programs between coach and client) are retained for 90 days after a coaching relationship ends, then permanently deleted. Client fitness and health data remains in the client's own account and is not affected by coaching relationship changes. Coaches or clients may request early deletion of coaching interaction records by contacting novionapp+privacy@gmail.com.
14. Third-Party Service Providers
We work with the following third-party service providers who may process your personal information:
- Supabase: Database hosting and user authentication
- Stripe: Payment processing for one-time purchases (programs, meal plans) and creator payouts
- RevenueCat: Subscription management for in-app purchases; receives limited purchase data from Apple and Google (subscription status, entitlements, transaction IDs) — no payment card details
- Google (Gemini AI): AI-powered food image analysis (transient processing only)
- Sentry: Error tracking and application monitoring
- Cloudinary: Media storage and content delivery
- Apple & Google: OAuth authentication services and in-app purchase processing
Each service provider is contractually obligated to protect your data and use it only for the specific purposes we engage them for.
15. Cookies and Tracking Technologies
Our Application and website may use cookies and similar tracking technologies:
15.1 Essential Cookies
Required for basic functionality, authentication, and security.
15.2 Analytics Cookies
Help us understand how users interact with our services to improve functionality.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect Application functionality.
16. Do Not Sell My Personal Information
We do not sell your personal information. We have not sold personal information in the preceding 12 months and have no plans to do so.
If this practice ever changes, we will update this Privacy Policy and provide you with the opportunity to opt out before any sale occurs.
17. Children's Privacy
Our Application is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at novionapp+privacy@gmail.com.
Users between 13 and 18 years of age may use the Application only with parental or guardian consent and supervision, as outlined in our Terms of Service.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.
19. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
Email: novionapp+privacy@gmail.com
Mailing Address: 1235 East Blvd, Ste. E #1378, Charlotte, NC 28203
For GDPR-related inquiries, EU residents may also contact their local data protection authority.