Legal

Privacy Policy

Effective: 11 September 2026 Last updated: 11 September 2026 Applies to: Transform 75 by Sikora v2.3.5 and later

The short version

Transform 75 has no user accounts and no servers holding your challenge. Your photos, weight, food log, journal and everything else stay on your device, and sync — if you switch it on — through your own private iCloud, which the developer has no access to. There is no advertising, no third-party analytics and no tracking of any kind. Two features deliberately reach the network, and both are opt-in and described in full below: Cloud Coach and the accountability partner.

1. Who this policy is from

Transform 75 by Sikora ("the app") is developed and published by Szymon Stephan-Sikora, an independent developer ("we", "us"). This policy explains how the app handles information. It covers the iPhone, iPad and Apple Watch apps, the widgets, complications, Live Activity, Control Center control and Siri/Shortcuts actions.

It does not cover Apple's own services (iCloud, the App Store, Apple Health, Sign in with Apple), which are governed by Apple's Privacy Policy.

2. What is stored on your device

The app is built around a local database on your device. Everything you record is written there first, and for most people that is the only place it ever exists. That includes:

  • Your profile — name, optional avatar, birthdate, height, starting and goal weight, gender, units, commitment level
  • Your challenge — start date, current day, your task list, completions and timestamps, sealed days, skipped days, rest days and streak freezes
  • Progress photos and any annotations you draw on them
  • Weight entries, body measurements, water entries and workouts
  • Journal entries, moods, energy ratings, voice-memo transcripts and your stated reasons for starting ("your why")
  • Nutrition — logged meals, custom foods, recipes, meal templates, meal plans and goals
  • Achievements, milestones and completed-round history
  • Your settings, including theme, notification times and preferences
  • Coach conversations, archived locally so a chat survives a relaunch

Photos you capture inside the app are stored inside the app's own storage. They are not written to your photo library unless you explicitly tap Save.

3. iCloud sync

Sync is optional. You are asked once during setup, and you can change the answer at any time in Settings → iCloud Sync.

When it is on, your challenge data is mirrored to the private database of your own iCloud account using Apple's CloudKit. This is the same mechanism Apple's own apps use. The data is associated with your Apple Account, not with us: we operate no server in this path, and we cannot read, list or recover your records. Apple's terms and privacy policy govern that storage.

Sync can also be disabled for a single device while remaining on elsewhere. Because iCloud mirroring is attached when the app launches, turning sync on or off fully takes effect the next time you open the app — the app tells you so at the moment you change it.

A small set of preferences (theme, units, notification settings and similar) also syncs through iCloud Key-Value Storage, and a summary of today's progress is shared with the widgets and the Watch app through a private app group on your device.

4. Apple Health

Apple Health integration is entirely optional and is off until you grant it. With permission, the app can:

  • Read body mass (for example from a smart scale) and workouts, so you don't have to enter them twice
  • Write the weight, water and workouts you log in the app, so your other health apps see them

Health data is read directly from and written directly to HealthKit on your device. It is never transmitted to us or to any third party, and it is not included in the data sent to Cloud Coach. You can review or revoke the app's access at any time in the Health app under Sharing → Apps.

Deleting the app does not delete your Health data

Anything the app wrote to Apple Health stays in Health, because that data belongs to you and Apple's model is that you manage it there. Even "Delete All Data" inside the app deliberately leaves it alone. To remove it, use the Health app.

5. Camera, photos, microphone and speech

Each of these is requested only at the moment a feature needs it, and each can be declined without breaking the rest of the app.

PermissionUsed forWhere the data goes
Camera Progress photos, meal photos, scanning food barcodes Stored in the app. Barcode digits are looked up in a food database; the image is not uploaded.
Photo library (read) Choosing an existing photo as a progress photo or avatar A copy is stored in the app. Your library is not scanned or indexed.
Photo library (add) Saving a share card, comparison, collage, time-lapse or certificate Writes only what you asked to save. Add-only access — the app cannot read your library with this permission.
Microphone & speech recognition Voice journal entries Transcribed on your device. Audio and transcripts stay local.
Face ID / Touch ID App Lock Handled by iOS. The app is told only "authenticated" or "not authenticated"; your biometrics are never available to it.
Notifications Reminders and partner nudges Scheduled on your device. See §9.

If you set an App Lock PIN it is stored in the device Keychain, marked so that it never syncs to your other devices and is only readable while the device is unlocked. We never see it, and there is no way for us to recover it.

6. Food databases

When you search for a food or scan a barcode, the app queries two public, open databases: Open Food Facts and USDA FoodData Central.

Only the search term or the barcode number is sent. No name, no account, no device identifier, no other part of your log. Results you have seen are cached on your device so the same food works offline next time. Those providers may log the request in their own server logs under their own policies. If you never search for a food, the app never contacts them.

7. The AI coach

There are two engines, and they have materially different privacy properties.

On-device Coach (default)

On supported hardware, Coach runs on Apple's on-device foundation model. Your data is given to a model running on your iPhone and nothing leaves the device — not the question, not the answer, not the data behind it. The same is true of the meal parser that reads a typed meal description, and of the on-device transcription used for voice journals.

Cloud Coach (Premium, opt-in)

Cloud Coach sends your question to a larger model (Anthropic's Claude) through a proxy we operate, which exists so that an API key is not shipped inside the app. You choose it deliberately; it is never the silent default.

What is sent:

  • Your question and the conversation so far
  • A derived summary of your tracked data — day number, streak, completion counts and rates, water and nutrition totals and averages, weight and measurement figures, and per-day records of that a journal was written along with its mood and energy rating

What is deliberately withheld, and cannot be sent even by mistake:

  • Your journal text. Never transmitted, in any form.
  • Your stated reasons for starting ("your why") — the most personal free text in the app.
  • Your name. Stripped from the profile summary before the request is built.
  • Photos, audio and Health data. None of it is part of the snapshot at all.

The exclusion is implemented as an allow-list — each field has to be consciously added for it to be sent — precisely so that adding a new kind of data to the app cannot quietly start shipping it to a server. The proxy verifies your App Store purchase to check you are entitled, enforces a daily usage cap, and passes the request to Anthropic. We do not use your conversations to train any model, and we do not build a profile of you from them. Anthropic processes the request under its own terms as our service provider.

Coach is not a doctor, a dietitian or a therapist

It describes data you recorded. It is not medical, nutritional or psychological advice, and it can be wrong. If something is worrying you, talk to a qualified professional.

8. Accountability partner

This is the one feature that shows your information to another person, so it is worth reading closely. It is entirely optional and off unless you pair with someone.

Pairing works through an invite code. Because two different iCloud accounts have to read the same record, the pairing uses the public CloudKit database for this app rather than your private one. While a partnership is active, the following is readable by your partner:

  • The display name you chose for the partnership
  • Your current day number and streak
  • Whether you completed today
  • Messages and nudges you send

Your photos, journal, weight, measurements and food log are not shared with a partner, ever. Use a display name you are comfortable with a specific other person seeing.

Either side can end the partnership at any time. When you do, the app tells your partner, deletes the records it is permitted to delete, and queues the rest so the teardown completes even if you were offline when you ended it. Ending a partnership is deliberately durable rather than best-effort, because it is an obligation to someone else.

Messages are between two people who chose each other. If a partner sends you something abusive, end the partnership and use the report option — see Acceptable Use.

9. Notifications

Reminders — morning, evening, water, meals, trial notices and comeback nudges — are scheduled locally by your device. Their content is composed on-device from your own data; no server is involved and nothing is sent anywhere in order to deliver them.

Partner nudges are the exception: they are delivered through CloudKit's push notifications, which means Apple's servers carry them.

10. Purchases

All purchases are handled by Apple through StoreKit. We never see your card, your billing address or your Apple Account email. The app reads only whether a valid subscription or lifetime purchase exists, and records the state of your free trial on your device and in your Keychain so that reinstalling does not hand out a second trial.

11. Diagnostics and analytics

There is no analytics SDK, crash-reporting SDK, advertising SDK or attribution SDK in this app. The app's privacy manifest declares no tracking and no tracking domains.

The app does keep two local records to help you when something goes wrong: an event log used to diagnose data problems, and a small set of counters recording that you reached certain milestones. Both live only on your device, are never uploaded, and are only ever visible to anyone else if you generate a diagnostics report and choose to send it to us. Apple may separately provide us with anonymised crash statistics if you have opted into sharing analytics with Apple in iOS Settings.

12. What is never collected

  • No advertising identifier (IDFA), and no tracking across apps or websites
  • No contacts, calendars, reminders or location
  • No behavioural profile, and no data sold or shared with data brokers
  • No account, email address or password — there is nothing to sign up for
  • No copies of your photos, journals or Health data on any server we run

13. Your controls

You want to…Where
Stop syncing to iCloudSettings → iCloud Sync (per device, or for the account)
Revoke Health accessApple Health app → Sharing → Apps → Transform 75
Revoke camera, photos, microphone or notificationsiOS Settings → Transform 75
Stop using Cloud CoachCoach → engine menu → on-device, or switch Coach off entirely
End a partnershipSettings → Accountability Partner → Remove Partner
Turn off nutrition tracking completelySettings → Nutrition Tracking
Lock the app behind Face ID or a PINSettings → App Lock
Take your data with youSettings → Export Data (JSON, PDF report, journal text)
Erase everythingSettings → Delete All Data

14. Retention and deletion

Your data is kept for as long as it is on your device or in your iCloud account — we have no copy of it and therefore no retention schedule to apply to it.

Delete All Data removes, on the device you run it on:

  • Every record in the app's database — and, if sync is on, the deletions propagate to iCloud and to your other devices
  • Progress and onboarding photos held on disk, and the thumbnail cache
  • Local backup snapshots and any staged recovery data
  • The archived Coach conversation
  • Your App Lock PIN from the Keychain
  • Saved settings, widget data and donated Siri actions
  • Any alternate app icon, restored to the default

It deliberately keeps a small number of things: the record that your free trial has already been used (so the wipe is not a way to restart it), your per-device sync preference, and a marker recording that the deletion happened so your other devices act on it correctly. It does not touch data written to Apple Health (see §4) or anything you have already exported or saved to your photo library.

Deleting the app removes its local storage. If sync was on, the copy in your iCloud account remains until you delete it — use Delete All Data first, or remove the app's data in iOS Settings → [your name] → iCloud → Manage Account Storage.

15. Children

The app is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect information from them. Some content is further age-gated: the blunt "sassy" coaching voice is only offered to users whose stated birthdate makes them 18 or over.

16. Your legal rights

Depending on where you live, you may have rights to access, correct, export, delete or restrict the processing of your personal data, and to object to it. Because the app stores your data on your own device and in your own iCloud account, you can exercise almost all of these yourself and immediately, using the controls in §13 — access and portability via Export Data, erasure via Delete All Data, correction by editing any entry.

Where we do act as a data controller — essentially: an email you send us, and a Cloud Coach request while it is in flight — our lawful basis is the performance of our agreement with you and our legitimate interest in providing and supporting the app. We do not sell personal information and we do not "share" it for cross-context behavioural advertising as those terms are defined under US state privacy laws. If you would like help exercising a right, or want to complain, write to us at the address below; you may also complain to your local data protection authority.

17. Changes to this policy

If this policy changes materially — in particular if the app ever starts sending something new off your device — the date at the top of this page will change and the app's release notes will say so. Continuing to use the app after a change means you accept the updated policy.

18. Contact

Questions about privacy, or a request about your data:
hello@szymonstephansikora.com

Szymon Stephan-Sikora, independent developer, publisher of Transform 75 by Sikora. We aim to reply to privacy requests within 30 days.