Slimr

Your data stays on your phone.

Slimr is a private health companion built for the GLP-1 generation. We designed it so most of your information never leaves your iPhone — and so the small amount that does is anonymous, encrypted, or both. This page explains exactly what happens with your data.

Effective date: May 1, 2026 · Last updated: May 1, 2026

1. Introduction

This Privacy Policy describes how Slimr (the "App") handles information about you when you use it on your iPhone or interact with our backend services. Slimr is published by Ian Fernández ("Slimr", "we", "us"). The App is distributed through the Apple App Store and is intended for personal, non-clinical use.

We built Slimr around a simple principle: your health data should belong to you, live on your device, and never be the product. This policy is meant to be readable, not exhaustive legalese — if anything is unclear, write us at support@slimr.health.

2. Information we handle

It helps to think of your information in three layers, from most private to least.

2.1 On your device

Almost everything you log in Slimr is stored locally on your iPhone using Apple's SwiftData framework. We — Slimr the company — cannot read it, because it is never sent to a server we operate. This includes:

2.2 In your private iCloud

So your data follows you between your iPhone and iPad, the App syncs the same on-device records through your private CloudKit database, which is part of your Apple iCloud account. Apple manages this storage with end-to-end encryption tied to your Apple ID. Apple cannot read it. We cannot read it. If you turn off iCloud or sign out of iCloud, sync stops and your data stays on the local device only.

2.3 On our backend

To validate your subscription status, run rate-limit logic for Slimr AI, and protect against abuse, we operate a small backend on Cloudflare Workers + D1. The only information that ever reaches it is:

The backend does not store the contents of the documents, photos, scans, or text you submit to Slimr AI (see §6).

3. Information we do not collect

To remove all ambiguity, here is a non-exhaustive list of things Slimr never collects:

4. How we use information

The limited information that does reach our backend is used only to:

We do not use your information to:

5. Third-party services

Slimr is built on top of services we did not build ourselves. Each one receives a narrow slice of information for a specific purpose.

5.1 Apple iCloud (CloudKit)

Stores the synchronized copy of your on-device data in your private database. Subject to Apple's Privacy Policy. Apple cannot read end-to-end encrypted CloudKit data.

5.2 Apple App Store & In-App Purchase

Handles all billing for monthly, annual, and lifetime purchases. Apple receives whatever payment information you choose to give them. Slimr never sees your payment method. Subject to Apple's Privacy Policy.

5.3 RevenueCat

Receives your anonymous App Store transaction events and reports your entitlement (Pro / Free) back to our backend. RevenueCat receives the App Store transaction identifier, your country, and your purchase status — never your content. Subject to RevenueCat's Privacy Policy.

5.4 Cloudflare

Hosts our backend (Workers + D1) and acts as a CDN. Cloudflare processes the network traffic between your device and our backend (IP address, request headers, timing). It does not have access to the encrypted iCloud data described in §2.2. Subject to Cloudflare's Privacy Policy.

5.5 Anthropic (Slimr AI only)

When and only when you use Slimr AI (see §6), the input you submit is sent through our backend to Anthropic's API to produce the output we return to you. Subject to Anthropic's Privacy Policy. Anthropic operates under a commercial agreement that prohibits using API inputs and outputs to train its models.

5.6 Sentry and TelemetryDeck (planned)

We may, after launch, add Sentry for crash reporting and TelemetryDeck for privacy-preserving usage analytics. Sentry would receive technical crash data only — no health data. TelemetryDeck would receive aggregated, anonymous signals such as "feature X was opened" with no personal identifiers and no IDFA. We will update this policy and post a notice in the App before either service is enabled.

6. Slimr AI

Slimr offers two kinds of AI:

When you use Slimr AI, this is exactly what happens:

  1. Your input (the PDF, photo, or text you choose to submit) is uploaded to our Cloudflare Worker over TLS, attached to an App Attest assertion proving the request came from your real Slimr install.
  2. The Worker forwards the input to Anthropic's API.
  3. Anthropic returns the structured result.
  4. The Worker returns the result to your iPhone.
  5. Our Worker logs only metadata about the request: timestamp, model, token counts, success/error. The input and the output are not stored on our backend.
  6. Anthropic, under its enterprise commercial terms, does not retain inputs or outputs for model training.

If you do not want any data to leave your device, simply do not use Slimr AI. Everything else in Slimr keeps working.

7. Apple HealthKit

If you grant permission, Slimr can read selected metrics from Apple Health (e.g. body weight, BMI, body composition) and write the values you log in Slimr back to Apple Health. HealthKit data is governed by Apple's policies and stays on your device or in your iCloud — it does not pass through our backend. You can revoke HealthKit permissions any time from Settings → Privacy & Security → Health → Slimr.

8. Profile sharing

When you share a profile with a coach, nutritionist, or physician, the data is encrypted end-to-end on your device before it leaves. Only the recipient can decrypt it — the decryption key travels with the share link to their device and never reaches our backend, Apple, or anyone in between.

You choose what to share (a subset of metrics plus a small avatar — never your full-size progress photos), and the recipient gets read-only access. You can revoke the share at any time from your iPhone, and it stops working immediately.

9. Data retention

10. Your rights (GDPR & CCPA)

Depending on where you live, you may have the right to access, correct, delete, restrict the processing of, or port your personal information; to object to processing; and to lodge a complaint with a supervisory authority.

For Slimr these rights are largely satisfied by the architecture itself: most of your data lives only on your devices and inside your iCloud, so you can view it (in the App), correct it (in the App), delete it (in the App or by removing the install), and export it (PDF export from the App).

For the limited backend data described in §2.3 — your anonymous UUID, entitlement, and request counters — you can request access or deletion by emailing support@slimr.health with the device UUID shown in Settings → About → Device ID. Because we have no other identifiers tied to you, we may need this UUID to act on the request. Your iCloud-stored data is unaffected; manage it from your Apple ID directly.

We do not sell or share personal information for cross-context behavioral advertising. California residents have the right to opt out of any future "sale" or "sharing" — though, again, we do neither.

The legal basis under GDPR for the backend processing described in §2.3 is our legitimate interest in operating the service, preventing abuse, and providing the Pro features you have purchased. Where Slimr AI is used, the legal basis is the performance of the contract with you.

Users in the European Union may contact their national data-protection authority. If our legal entity is based in Italy, the supervisory authority is the Garante per la protezione dei dati personali.

11. Children's privacy

Slimr is not directed to children under 16, and we do not knowingly collect information from children under that age. If we discover that a child has used the App, we will deactivate the corresponding backend records on request from a parent or guardian.

12. Changes to this policy

If we make material changes we will update the "Last updated" date at the top of this page and, when appropriate, surface a notice inside the App before the changes take effect. Continuing to use Slimr after a change indicates acceptance of the new policy.

13. Contact

Questions, requests, or concerns about your privacy: support@slimr.health.

Slimr is not a covered entity under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and we are not a healthcare provider. The information you store in Slimr is health-related but is not medical record data created in the course of treatment.