GRID360

Privacy Policy

Effective from 26 August 2026

FM Negócios Inteligentes LTDA — CNPJ 49.500.229/0001-84

  • GRID360 is a training, nutrition and wellbeing app. To work, it processes data about your body and your health — what the law calls sensitive personal data.
  • You decide what you share. Background location, Apple Health or Health Connect data, face verification in challenges and progress photos are only processed if you allow it, and you can withdraw that permission at any time.
  • We do not sell your data, and we never use health data for advertising.
  • Your workout and diet plans are generated by artificial intelligence from your profile. We send AI providers only the data needed — never your name, email or any direct identifier.
  • We never see or store your card number: payments are processed by Stripe.
  • You can request access, correction, portability or deletion of your data at any time at privacy@mail.grid360app.com.

1. Who processes your data

The controller of personal data processed in GRID360 is FM Negócios Inteligentes LTDA, registered in Brazil under company number (CNPJ) 49.500.229/0001-84 ("GRID360", "we").

This Policy describes how we process personal data in the GRID360 app, on grid360app.com and through our support channels. It applies to everyone who uses the service, with or without an account.

For any privacy matter — including reaching our Data Protection Officer — write to privacy@mail.grid360app.com.

2. What we collect

We collect only what each feature needs. Not everyone provides everything: several categories below depend on you turning a feature on.

CategoryExamplesSource
Account and identityName, email, phone number, password (stored only as a hash), profile picture, country, language, referral codeYou provide it
Social sign-inGoogle or Apple account identifier, associated email (including Apple private relay addresses)Google and Apple, when you choose that sign-in
Authentication and securityEmail verification codes, two-factor codes, trusted devices, last sign-in date, IP address and device identification in access logsGenerated as you use the service
Body profile and goalsDate of birth, sex, height, current, starting and target weight, body measurements, experience level, goal, weekly availabilityYou provide it
Derived health metricsBMI, body fat percentage, lean and muscle mass, body water, basal metabolic rate, daily energy expenditure, bioimpedanceCalculated from what you provide
Health questionnaireMedical conditions, current medication, injuries, physical limitations, food allergies and intolerances, supplements, hormone useYou provide it
Routine, sleep and hydrationWake and sleep times, sleep quality and duration, stress level, meals, water and supplement intakeYou provide it, plus integrations you authorise
Menstrual cycleCycle dates, flow, cramps, mood, energy, bloating, headache, contraceptive use, polycystic ovary syndromeYou provide it, if you enable the feature
Body imagesProgress and comparison photos (front, back and sides), photos used for bioimpedance readingsYou upload them
Face biometricsA face record used to confirm it is you completing a challenge, with the consent version and a reference to the biometric templateYou upload it, under specific consent
NutritionMeal logs, photos of dishes and ingredients, barcode scans, food preferences and restrictionsYou provide it
Physical activity and locationPoint-by-point GPS track (latitude, longitude, altitude, accuracy, speed and time), distance, pace, calories, elevation, saved routesDevice sensors, during an activity you start
Approximate account locationCountry and approximate coordinates, for regional rankings, language and local contentYou provide it or the device supplies it
Device and usageDevice model, operating system, app version, time zone, push token, in-app usage events, error logsGenerated as you use the service
Subscription and paymentPlan, subscription status and billing cycle, billing history, Stripe identifiers, card brand and last four digitsStripe
SupportMessages, tickets and attachments you send to supportYou provide it

We never receive or store your full card number, expiry date or security code. Those go straight to Stripe.

3. Sensitive data and consent

Data about health, sex life and biometrics is sensitive personal data (art. 5, II of Brazil’s LGPD; art. 9 GDPR) and gets stronger protection. In GRID360 that covers:

  • your health questionnaire — conditions, medication, injuries, limitations and allergies;
  • your body, sleep and bioimpedance metrics;
  • your menstrual cycle records;
  • photos of your body;
  • your face biometric record.

We process this data on the basis of your specific, highlighted consent, collected when you turn each feature on. Consent is always separate per purpose: accepting the health questionnaire does not authorise face recognition, and vice versa.

You can withdraw any consent at any time, free of charge, by turning the feature off in the app or writing to privacy@mail.grid360app.com. Withdrawal stops processing from that point on and does not invalidate what was done before it.

We never use health data, biometrics or cycle data for advertising, campaign targeting or pricing. We do not share it with advertisers, data brokers, insurers or employers.

4. Why we use each type of data, and on what legal basis

PurposeData usedLegal basis
Create and maintain your account, authenticate accessAccount data, social sign-in, authentication dataPerformance of a contract (art. 7, V)
Generate and adjust training, diet and supplement plansBody profile, health questionnaire, routine, food preferencesConsent for health data (art. 11, I); contract for the rest
Record activities, sleep, water, meals and progressHealth data, body images, GPS trackConsent (art. 11, I)
Track your menstrual cycle and adjust recommendationsCycle recordsConsent (art. 11, I)
Verify challenge authorship through face recognitionFace biometric recordSpecific consent (art. 11, I)
Build rankings, challenges and achievementsActivity metrics, display name, profile picture, countryPerformance of a contract (art. 7, V)
Charge your subscription and issue tax documentsSubscription, payment, account dataContract (art. 7, V) and legal obligation (art. 7, II)
Send service emails and notificationsAccount data, push token, preferencesPerformance of a contract (art. 7, V)
Send marketing messagesAccount data, usage eventsConsent, withdrawable at any time (art. 7, I)
Prevent fraud and abuse, keep the service secureAccess logs, IP address, device dataLegitimate interest (art. 7, IX) and legal obligation (art. 7, II)
Measure usage, fix errors and improve the productUsage events, error logs, device dataLegitimate interest (art. 7, IX)
Measure how well app install campaigns performDevice advertising identifier, install eventConsent (art. 7, I) — on iOS, also the system tracking permission
Handle support requestsSupport messages, account and plan dataPerformance of a contract (art. 7, V)
Comply with a court or authority orderWhatever the order requiresLegal obligation (art. 7, II)

Where we rely on legitimate interest, we first assess that it does not override your rights and freedoms, and we limit processing to what is strictly necessary. You can object to those activities through the privacy channel.

5. Artificial intelligence and automated decisions

Your training, diet and supplement plans are generated automatically by artificial intelligence models from OpenAI and Google, based on your body profile, health questionnaire and preferences. Photos of meals, ingredients and menus are also analysed by those models when you use image recognition.

We send those providers only the data needed to produce the result. The content we send does not include your name, email, phone number or account identifier.

None of these automated decisions produces legal effects on you or restricts your access to the service: they are training and nutrition recommendations, which you can adjust, decline or replace with a plan of your own.

Even so, art. 20 of the LGPD gives you the right to request a review of decisions based solely on automated processing, and clear information about the criteria used. Just write to privacy@mail.grid360app.com.

6. Who we share it with

We do not sell personal data and we do not pass it to data brokers. We share it with suppliers who run parts of the service on our behalf, each bound by contract to the purpose described below:

SupplierWhat forWhere it processes
Amazon Web ServicesApplication and database hostingUnited States
CloudflareImage storage and content deliveryUnited States
StripePayment and subscription processingUnited States and European Union
OpenAIPlan generation and analysis of food and face imagesUnited States
Google (Gemini)AI content generationUnited States
ResendService emails and verification codesUnited States
Z-APIPassword recovery codes over WhatsAppBrazil
ExpoPush notification deliveryUnited States
PostHogApp usage analyticsUnited States
AppsFlyerInstall campaign measurement, subject to consentUnited States and Israel
MapboxMaps and routes in the appUnited States
Open Food FactsPublic food database lookupsFrance
Google and AppleSocial sign-in, app stores and health integrationsUnited States

We also share data in these situations: with the personal trainer or nutritionist who coaches you, if and while you are linked to them — in that case they see your profile, health questionnaire and plans; with public authorities, when required by law or court order; and with an acquirer, in a corporate reorganisation, keeping the protection of this Policy.

7. International transfers

Much of our infrastructure and many of our suppliers sit outside Brazil, mainly in the United States. That means your data is transferred to other countries.

Those transfers rely on the safeguards set out in art. 33 of the LGPD — standard contractual clauses and contractual security and confidentiality commitments with each supplier — and, where applicable, on your specific consent to the transfer. For transfers out of the European Economic Area or the United Kingdom, we rely on the European Commission’s standard contractual clauses and equivalent UK safeguards.

8. Apple Health and Health Connect

If you allow it, the app reads data from Apple Health (HealthKit) on iPhone or Health Connect on Android — steps, heart rate, sleep, workouts and energy burned, for example — to fill in your progress without manual typing.

  • We read only the data types you tick on the system permission screen.
  • You can withdraw that permission at any time in your iPhone or Android settings, without going through us.
  • Data obtained from Apple Health or Health Connect is never used for advertising or marketing, never sold, and never shared with data brokers.
  • We also do not use that data for any purpose beyond showing and analysing your progress inside the app.

9. Location

The app uses location in two distinct ways, both of which need your permission:

  • During an activity: when you start a run, walk or ride, we record the track point by point to calculate distance, pace, elevation and calories, and to draw the activity map.
  • In the background: if you grant the "Always" permission, we keep recording the track with the screen off or the app closed, so the activity is not interrupted. We use that permission for nothing else.
  • Approximate account location: country and approximate coordinates, for regional rankings, language and local content.

You can deny or withdraw location permission in your device settings at any time. Without it, GPS activity tracking stops working; the rest of the app remains available.

Recorded tracks and saved routes are visible only to you, unless you choose to share them or to join a ranking that exposes the activity.

10. Cookies, analytics and advertising

On the website we use a single strictly necessary cookie, called locale, which stores your chosen language. We use no advertising or tracking cookies on the website, which is why there is no consent banner.

To keep you signed in, your browser stores your session token in the device’s own local storage. It is not sent to third parties.

In the app, we record usage events (screens opened, features used, errors) to understand what needs improving. We also measure which campaign each install came from. On iPhone that measurement only happens if you allow tracking when the system asks; if you decline, the app works normally.

11. How long we keep it

We keep each type of data only as long as the purpose behind it requires:

DataRetention period
Account, profile, plans, training and nutrition historyFor as long as your account exists
Health data, menstrual cycle, body photosFor as long as your account exists, or until you withdraw consent
Face biometric recordUntil you withdraw consent or delete your account
Backup copies, after account deletionUp to 30 days
Application access logs6 months (art. 15, Brazilian Internet Civil Framework)
Tax and payment records5 years, as required by tax and consumer law
Usage analytics and error logs12 months

Once the period ends, data is irreversibly deleted or anonymised. We may keep for longer whatever is needed to exercise rights in judicial, administrative or arbitral proceedings (art. 16, LGPD).

12. How we protect your data

  • Encrypted traffic between the app, the website and our servers.
  • Passwords stored only as hashes — we cannot read your password, not even on request.
  • Two-factor authentication available on your account, with email codes and trusted devices.
  • Rate limiting on sign-in, password recovery and code sending, to contain automated attacks.
  • Internal access restricted to staff who need it to run the service, under a duty of confidentiality.
  • Audit logging of sensitive operations.

No system is completely immune. If a security incident occurs with material risk to your rights, we will notify you and the Brazilian data protection authority (ANPD) within a reasonable period, as required by art. 48 of the LGPD, and any other authority the law requires.

13. Your rights

The LGPD gives you the following rights over your personal data, at any time and free of charge:

  • Confirm whether we process your data, and access that data.
  • Correct incomplete, inaccurate or out-of-date data.
  • Request anonymisation, blocking or deletion of unnecessary or excessive data, or data processed unlawfully.
  • Request portability of your data to another provider.
  • Request deletion of data processed on the basis of your consent.
  • Know who we share your data with.
  • Be informed that you may refuse consent, and what refusing means.
  • Withdraw consent at any time.
  • Object to processing based on legitimate interest.
  • Request a review of decisions based solely on automated processing.

To exercise any of them, write to privacy@mail.grid360app.com or use the Privacy area of your account. We reply within 15 days, as required by art. 19 of the LGPD. We may ask for extra information to confirm your identity before acting — that protects you against requests made by someone else in your name.

If you believe your request was not handled properly, you can complain to the Brazilian data protection authority (ANPD) at gov.br/anpd.

If you are in the European Economic Area or the United Kingdom, the GDPR gives you equivalent rights, including the right to complain to your national supervisory authority.

14. Deleting your account

You can request permanent deletion of your account at any time, through the Privacy area of your account, through in-app support, or by writing to privacy@mail.grid360app.com.

Deletion removes your profile, health questionnaire, health data, photos, activity records, plans and biometric record. It is irreversible: we cannot recover anything once it is done.

Cancel any active subscription before deleting, to avoid future charges. Only the records the law requires us to keep remain, as described in the retention section.

15. Children and teenagers

GRID360 is not intended for anyone under 18. We do not knowingly create accounts for under-18s and we do not intentionally collect data from children or teenagers.

If we learn that an account belongs to someone under 18 without the specific, highlighted consent of at least one parent or legal guardian, we will delete the account and the associated data. If you are a guardian and believe this has happened, write to privacy@mail.grid360app.com.

16. GRID360 is not a medical service

The app offers automatically generated training, nutrition and wellbeing recommendations. It does not diagnose, does not prescribe treatment, and does not replace assessment by a doctor, dietitian or exercise professional.

Consult a health professional before starting any exercise programme or dietary change, particularly if you have a medical condition, are pregnant, or take medication regularly.

17. Changes to this Policy

We may update this Policy to reflect changes in the product or in the law. The effective date at the top of the page always identifies the version in force.

When a change is material — a new purpose for sensitive data, or a new supplier with access to it, for example — we will tell you by email or inside the app before it takes effect, and collect fresh consent where the law requires it.

18. Contact

Data Protection Officer: privacy@mail.grid360app.com

Controller: FM Negócios Inteligentes LTDA — CNPJ 49.500.229/0001-84

You can also reach us through the help centre, inside the app or at grid360app.com/help.

Privacy Policy — GRID360