Privacy Policy
Anatome, operated by NextSolutions. Effective 13 August 2026.
The short version
- Your training log is yours. We do not sell it and we do not train AI models on it.
- You can use most of Anatome without an account, and without telling us who you are.
- Delete something and it disappears from every screen immediately. You can undo that for 30 days.
- After that it moves to a backup we hold for 30 more days, so we can still get it back if you write in. Then it is gone.
- Pictures and files follow the same clock: withdrawn from serving at day 30, deleted at day 60.
Anatome is a workout and nutrition log you talk to through an AI assistant. This policy covers anatome.dev and the app at client.anatome.dev. Two other things carry the Anatome name and are not covered here: the open-source exercise wiki at wiki.anatome.dev, and the developer platform at platform.anatome.dev, which has its own terms for the companies building on it.
Who we are
Anatome is operated by NextSolutions, established in Poland. For the data you log here we are the data controller under the GDPR. We have not appointed a Data Protection Officer; privacy questions go to support@anatome.dev. Servers are in the EU (Hetzner, Falkenstein, Germany), with Cloudflare in front of them. The lead supervisory authority is the Polish DPA (UODO); you may also complain to the authority where you live.
What we store
If you never sign in
Exercise search, muscle diagrams, food lookup and the calculators work with no account and no key. We do not create a record for you. We do log the request itself - the endpoint, the HTTP method and status, a timestamp, your IP address, your user-agent string and a request id - because that is what rate limiting, abuse detection and debugging run on. Those logs are covered by the retention table below and are never joined to a person, because there is no person to join them to.
If you use a free key without signing up
Minting a key at /v1/demo/key creates an anonymous record so your log can persist between
conversations. It holds no name, no email and no password - just the key and whatever you log against
it. We cannot tell you who you are, and neither can we identify you if you lose the key, which also
means we cannot give the log back to you. An anonymous record with no activity for 60 days
may be deleted along with everything in it.
If you sign in
- Your account: email address, and - if you signed in with Google or GitHub - the identifier and display name that provider returns. Passwords, where used, are stored only as a slow one-way hash, never as text.
- Your log: workouts and sets, meals and water, cardio, body metrics, supplements, goals, notes, recipes and check-ins. If you pass them to an AI plan, also allergies, injuries, pregnancy, medications and medical conditions. Log only your own health data.
- Your sessions: sign-in times with the IP address and user-agent, so you and we can spot a session that is not yours.
- Files and pictures, if photo storage is switched on for your account - see below.
Files and pictures
Progress photos, workout video and any other file you upload are handled differently from the rest of your log, so they get their own section.
- Photo storage is off unless it has been switched on for your account. When it is off, uploads are refused outright and nothing is stored.
- The file itself is stored separately from the record that points at it, on our upload
service at
uploads.nextsolutions.studio. The record holds the caption, the size, the dimensions and the link; the bytes live at the other end of that link. - Identical files are stored once. Files are addressed by a hash of their content, so if two people upload the same image there is one copy on disk with two records pointing at it. This matters for deletion, and the next section says how.
- A meal photo you ask the assistant to read is not the same as a stored photo. It is sent to the AI provider for analysis, and what comes back - the foods and the macros - is what gets logged. We do not keep the image unless photo storage is on and you saved it.
How long we keep things, and what deletion does
Deleting anything in Anatome starts a clock rather than erasing it on the spot, because far more people delete something by accident than need it gone this second. Here is exactly what happens.
| When | What has happened | Can it come back? |
|---|---|---|
| Straight away | Gone from every screen, every API response, every export and every share link. Nobody - you, a coach you shared with, anyone holding a link - can see it any more. | Yes, by you. |
| Day 30 | Removed from the live database and copied into a restore backup. If it was a file, the file is withdrawn from the servers that serve it and moved somewhere nothing can reach. | Yes, if you ask us. |
| Day 60 | The backup entry is deleted and the file is deleted. This is irreversible and we cannot undo it for you, however nicely you ask. | No. |
The 30-day restore window is fixed when your data enters the backup, so if we ever shorten the retention period it cannot shorten a window you were already given.
Some things run on their own clock:
| Data | Kept for | Then |
|---|---|---|
| Request logs (endpoint, status, IP, user-agent) | 90 days | Reduced to hourly counts per endpoint. The counts contain no IP address, no user-agent and no personal content, and we keep them indefinitely for capacity planning. |
| AI usage records (which model, how many tokens, what it cost) | Kept for billing | Never contains the content of what you asked or what came back. |
Repeat-request cache (Idempotency-Key) | 24 hours | Deleted. |
| Anonymous keys with no activity | 60 days | May be deleted with everything logged against them. |
| Backups of the database as a whole | Until the next rotation | We cannot reach into an existing snapshot to remove one person's rows; snapshots expire on rotation. This is the "reasonable processing time" allowed by GDPR Article 17(3)(b). |
Share links
You can mint a link that shows a coach your log or a picture without giving them an account. Two things are worth knowing before you send one:
- Anyone with the link can open it. There is no password on it. The link contains 256 bits of randomness, so it cannot be guessed, but it can be forwarded.
- A share link does not expire on its own. It works until you revoke it or delete what it points at. Revoking stops the link immediately.
- For a picture, revoking the link stops the link, not every copy of the file. The link redirects to the file's own address, and someone who saved that address - or the image itself - can still open what they saved for as long as the file exists, which means until the last record pointing at it is deleted and the 60-day clock runs out. Treat sharing a picture as handing over a copy of it.
Who else sees your data
We do not sell personal data, and we do not use your log to train AI models. These companies process some of it so that Anatome can work:
| Who | What they get | Why |
|---|---|---|
| OpenRouter | The text or image you asked the assistant to analyse, including any health constraints you typed, and nothing else from your log | Routes it to the AI model that reads it |
| Cloudflare | Request metadata. Some of that processing is in the US, under Standard Contractual Clauses | Serves the site and absorbs attacks |
| Hetzner | Everything, at rest | Hosts the servers, in Germany |
| Google or GitHub | The identifier and display name they return, only if you sign in with them | Lets you sign in without a password we store |
| Stripe | Billing details, if you ever pay for something | Takes the payment. We never see your card number. |
The assistant you connect Anatome to - ChatGPT, Claude, Cursor or another MCP client - is not ours. When you connect it, whatever you say to it and whatever Anatome sends back passes through that company's systems under their privacy policy. Anatome cannot see or control what they retain.
Why we are allowed to hold it
- Your account and your log: to give you the service you asked for - GDPR Article 6(1)(b).
- Health-adjacent and special-category entries (body metrics, allergies, injuries, pregnancy, medications, medical conditions): your explicit consent under Article 9(2)(a), given when you choose to log them or pass them into an AI plan. You withdraw consent by deleting the entry; it then follows the ladder above. We do not infer these from other data.
- Request logs: our legitimate interest in keeping the service up and unabused - Article 6(1)(f).
AI meal and workout plans are suggestions. They are not solely automated decisions with legal or similarly significant effects (GDPR Article 22). Confirming a plan does not create a medical record and does not replace a clinician.
What you can ask us to do
- Get a copy. Export your whole log yourself, in a machine-readable format, from the app or the API. No need to ask.
- Fix something. Edit any entry, any time.
- Delete it. Delete individual entries or the whole account. The ladder above applies.
- Get something back that you deleted within the last 60 days - email us.
- Object, restrict, or complain. Email us. You can also complain to UODO (Poland) or to your local data protection authority.
We answer within 30 days. There is no charge.
Security
Each person's data is separated at the database level by row-level security, not merely by careful queries - the database refuses to return another person's rows even if the application asks for them. That separation is tested automatically before every deploy. API keys are stored only as hashes, so a copy of our database does not yield working keys.
Children
Anatome is not for under-16s and we do not knowingly hold their data. If a child's data has ended up here, email us and we will remove it.
Changes
If we change something material - what we collect, how long we keep it, who else sees it - we will say so on this page and give 30 days' notice before it takes effect. The date at the top always reflects the current version.
Contact
Privacy questions, data requests and restore requests: support@anatome.dev.