PauseBack to Pause

Who is responsible

The controller is Simion Gorgos, an individual established in the Republic of Moldova. Contact: help@metabolicpause.com.

Website visitors

This section covers only metabolicpause.com, not the app. The site stores your versioned cookie preference in local storage. Google Tag Manager is loaded only after you affirmatively accept; nothing is requested from Google before that. Once you accept, _ga cookies are set and analytics_storage is granted. Advertising storage, ad user data, and ad personalization signals are always denied, whether or not you accept.

The Pause iPhone app: what is collected and why

The app collects the following, synced to Supabase:

  • Email, sign-in provider identity, and account ID: authentication.
  • Full name: profile.
  • Date of birth: to enforce the 18+ age gate only.
  • Unit preference, fasting plan, and goal weight: app configuration.
  • Current weight and weight history: core app function.
  • Fasting records (start/end time, goal, timezone): core app function.
  • Water entries and daily hydration goal: core app function.
  • Reminder preferences: notification scheduling.

A profile photo, if you choose to add one, is optional and is stored in a private Supabase Storage bucket.

How information is collected

Directly from you in the app; from Apple or Google when you sign in; and from Apple Health only if you grant explicit permission.

Accounts and sign-in

Accounts are handled by Supabase Auth. You can sign in with Apple (native) or Google OAuth; there is no email/password account option. Apple’s Hide My Email relay addresses are supported.

Purchases

Purchases go directly through Apple StoreKit 2. Purchase and entitlement data is used on-device only; it is never synced to our servers, exported, logged, or analyzed.

Apple Health

Apple Health access is optional. With permission, Pause reads body mass and active energy, and writes body mass and dietary water. Raw Apple Health samples, sample identifiers, source and device metadata, and your authorization state never leave your device. Active energy is display-only; it is never stored, synced, or exported. The one exception: if you import a weight from Apple Health, it becomes an ordinary Pause weight entry and syncs like any weight you enter manually. Apple Health data is never used for advertising, marketing, analytics, or diagnostics.

Profile photos

Photos are picked using Apple’s system photo picker; Pause never receives access to your photo library, only the image you choose. Before upload, the image is sanitized on-device: resized to 1024px or less on the longest edge, converted to sRGB JPEG, and stripped of EXIF and GPS metadata. It is then stored in a private, owner-prefixed storage bucket. The original picked file never leaves your device.

What Pause does not do

Pause uses no analytics processor and no analytics SDK in the app. There is no advertising identifier, no ad networks, no cross-app or cross-site tracking, and no App Tracking Transparency prompt; the app’s privacy manifest declares NSPrivacyTracking: false with an empty tracking-domains list. There is no remote crash-reporting processor: crash and error diagnostics are kept in an on-device ring buffer of scrubbed text alongside an anonymous per-install id, and nothing is transmitted off the device.

Who else receives app data

Exactly two parties receive app data:

  • Supabase: authentication, database sync, file storage, and serverless functions, hosted in the United States.
  • Apple: StoreKit and the App Store, for purchase, billing, renewal, and refunds.

Apple HealthKit is not a data transfer; as described above, it stays on-device. Each third party that receives user data is contractually required to provide the same or equal protection of user data as stated in this policy.

On-device storage and security

Local data is stored encrypted on-device and excluded from device backups. Notifications are local-only; there are no push tokens and no APNs. The Home Screen widget and Live Activity make no network calls and contain no health values or identity data. On the server side, data is protected with encryption in transit and access controls.

Retention and deletion

Data is retained while your account is active. On deletion, it is removed immediately; residual copies in encrypted daily backups are overwritten within 7 days, and service logs are retained for 7 days. Deleting your account removes your account record, all synced data (profile, fasting records, hydration, weight history, preferences, and reminders), stored profile photos, and all on-device data. Apple authorization tokens are revoked for Sign in with Apple accounts. Deletion is immediate and irreversible. Deleting your Pause account does not cancel an App Store subscription; subscriptions are managed through Apple. You can export your data as JSON or CSV from within the app before deleting.

Your choices and rights

You can disconnect Apple Health at any time in iOS Settings, delete your account from within the app, and withdraw website analytics consent using the Cookie settings control in the footer. For access, correction, export, or deletion requests, contact help@metabolicpause.com.

International transfers

App data is stored in the United States. Where information is transferred internationally, it is protected by contractual safeguards.

Age

Pause is restricted to adults aged 18 or older. Date of birth is collected solely to enforce that age gate.

Changes and contact

We may update this policy from time to time; material changes will be announced in the app or on this site before they take effect. Questions and rights requests may be sent to help@metabolicpause.com.