Privacy Policy

Last updated September 22, 2025

WHO WE ARE

Gram Fit is developed and operated by NIKOLABS PTE LTD ("we," "us," "our"). For the purposes of GDPR/UK GDPR, we are the data controller of your personal data processed in connection with the Services.


This Privacy Policy for Gram Fit ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Policy, but you can find out more details about any of these topics by using our table of contents below to find the section you are looking for.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.

In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more about when and with whom we share your personal information.

How do we keep your information safe?

We implement a layered set of organizational and technical safeguards designed to protect personal data, including encryption in transit and at rest (where appropriate), access controls, role-based permissions, logging/monitoring, secure software development practices, and vulnerability management. While we work to protect your data, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.

How do you exercise your rights? The fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose from the different data rights. In case you are looking for anything else, feel free to write to DPO at [email protected].

Want to learn more about what we do with any information we collect? Review the Privacy Policy in full.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  5. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
  6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
  7. HOW LONG DO WE KEEP YOUR INFORMATION?
  8. HOW DO WE KEEP YOUR INFORMATION SAFE?
  9. DO WE COLLECT INFORMATION FROM MINORS?
  10. LOCATION-SPECIFIC DISCLOSURES
  11. HOW TO EXERCISE YOUR RIGHTS
  12. DO WE MAKE UPDATES TO THIS POLICY?
  13. HOW CAN YOU CONTACT US ABOUT THIS POLICY?
  14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

We collect your Personal Data in a number of ways and for various purposes, including:

When you register for an account or interact with our Services

We collect Personal Data when you use or interact with our Services, including when you register for a Gram Fit account, purchase a Subscription (including processing of payment), or otherwise use the Services (e.g., browse the content available on the Services), and when you ask us to customize our Services. This Personal Data may include name, photo, username and password, email address, date of birth, gender, payment information and general location data.

When you input Fitness and Dietary Data within our Services or use our Services that collect or ingest data from mobile device sensors

"Fitness and Dietary Data" includes data you provide related to your dietary habits, dietary restrictions, fitness activity, fitness goals, lifestyle (e.g., sleeping habits), height, weight, measurements, fitness level, heart rate, sleep data, BMI, biometric data, and similar types of data relating to physiological condition and activity. We collect this data in order to provide the Services and to tailor features, advertising, and services to your interests and goals, including providing meal suggestions, reporting and analytics, workout plans, and meal planning related services, and product recommendations.

Note on Apple HealthKit Data

You can choose to connect and share your information with HealthKit and your HealthKit information with Gram Fit. The information you provide to HealthKit is then governed by the Apple Terms and Conditions and Privacy Policy. The unique information you choose to send from HealthKit is not used by Gram Fit for marketing and advertising or transferred by Gram Fit to third parties for marketing and advertising.

Note on Google Health Connect

You can choose to connect and share your information with Health Connect and your Health Connect information with Gram Fit. The use of information received from Health Connect will adhere to the Health Connect Permissions Policy, including the Limited Use requirements.

We process health and biometric-related data only with your explicit consent and only to provide the requested features (e.g., insights, plans, progress tracking). We do not use such data for advertising, and we do not sell it. You may withdraw consent at any time in the app settings; withdrawing may limit feature availability but does not affect prior lawful processing.

When we aggregate or centralize data

We aggregate and centralize Personal Data and Fitness and Dietary Data for purposes of analytics, innovation, and to provide enhanced services to our customers and end-users.

When we comply with Legal Requirements or Obligations, Law Enforcement, and for Public Safety Purposes

We may use Personal Data in order to comply with laws, regulations, court orders, or other legal obligations or to assist in an investigation, to protect and defend our rights and property, or the rights or safety of third parties, to enforce our Terms, this Privacy Policy, or agreements with third parties, or for crime-prevention purposes.

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:

  1. names
  2. phone numbers
  3. email addresses

Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information: health data

Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Google, Apple or Facebook Account. If you choose to register in this way, we will collect certain profile information about you from the social media provider, as described in the section called "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below.

Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:

  1. Mobile Device Access. We may request access or permission to certain features from your mobile device, including your mobile device's sensors, and other features. If you wish to change our access or permissions, you may do so in your device's settings.
  2. Push Notifications. We may request to send you push notifications regarding your account or certain features of the application(s). If you wish to opt out from receiving these types of communications, you may turn them off in your device's settings.

This information is primarily needed for operation of our application(s) and for our internal analytics and reporting purposes.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Information automatically collected

In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

The information we collect includes:

  1. Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
  2. Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share your personal data only (a) with your direction, (b) with service providers that act on our behalf, (c) when required by law, or (d) in connection with corporate transactions. We do not use HealthKit/Health Connect or other sensitive health data for advertising.

Service providers (processors). We use carefully selected third parties to help us operate, secure, and improve the Services. They may access personal data only to perform services for us and must protect it under contract. Common categories include:

With your direction. We share information when you ask us to, for example when you:

Legal, safety, and compliance. We may disclose information if we believe in good faith that it is necessary to:

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of all/part of our business, information may be shared or transferred to the relevant participants, subject to standard confidentiality protections. If ownership changes, we will notify you of any material changes to how your data is used.

Aggregated, de-identified, or anonymized data. We may share information that does not identify you (e.g., aggregated usage statistics) for research, analytics, marketing, or to help explain our Services. We take steps so that this data cannot reasonably be re-linked to you.

No sale or use of sensitive health data for ads. We do not sell personal data. We do not use data received via Apple HealthKit, Google Health Connect, or other sensitive health/biometric data for marketing or advertising, and we do not transfer such data to third parties for advertising.

International transfers. Some recipients may be located outside your country/region. Where this results in an international transfer, we apply the safeguards described in Section 7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

More information / list of sub-processors. To increase transparency, we maintain a current list of our key sub-processors (service providers) [link to live page or appendix]. You can contact us (see "HOW CAN YOU CONTACT US ABOUT THIS POLICY?") to request more details about specific recipients.

5. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using your third-party social media account details (like Google, Apple or Facebook Login). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, and profile picture, as well as other information you choose to make public on such a social media platform.

We will use the information we receive only for the purposes that are described in this Privacy Policy or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their Privacy Policy to understand how they collect, use, and share your personal information, and how you can set your privacy preferences on their sites and apps.

6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We may transfer, store, and process your personal data outside your country/region. When we do, we use recognized safeguards (e.g., EU Standard Contractual Clauses and the UK Addendum, and—if certified—the EU-U.S./Swiss-U.S. Data Privacy Frameworks) and take steps to protect your data.

Primary locations. The Personal Data we process—along with our Services and supporting systems—are primarily hosted in the United States. We may also engage providers or affiliates in other countries where we operate. These countries may have data-protection laws that are different from those in your country (and, in some cases, may provide a lower level of protection).

Our transfer safeguards (EEA/UK/Switzerland).

Where we transfer personal data from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland to countries that have not been found to provide an "adequate" level of protection by the European Commission/UK Government/Swiss authorities, we rely on one or more of the following safeguards:

7. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy unless otherwise required by law.

We will retain your Personal Data for as long as you maintain an account or as otherwise necessary to provide you the Services. We will also retain your Personal Data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Where we no longer need to process your Personal Data for the purposes set out in this Privacy Policy, we will delete your Personal Data from our systems.

Where permissible, we will also delete your Personal Data upon your direction to delete your account.

If you have further questions about our data retention practices or would like to make a deletion request, the fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose DSR Deletion. For other inquiries, please contact our DPO at [email protected].

8. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We implement a layered set of organizational and technical safeguards designed to protect personal data, including encryption in transit and at rest (where appropriate), access controls, role-based permissions, logging/monitoring, secure software development practices, and vulnerability management. While we work to protect your data, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

Data sharing with other websites. Please note that this Privacy Policy does not apply to the practices of companies that we do not own or control or to people that we do not employ or manage. We have no control over, do not review, and are not responsible for Third Party Sites, their content, or any goods or services available through the Third Party Sites.

9. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

The Services are intended for adults (18+). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps, including deletion where required.

If you become aware of any data we may have collected from children under age 18, please contact our DPO at [email protected].

10. Location-Specific Disclosures

Residents of the European Economic Area and the United Kingdom

If You Elect Not to Provide Personal Data

You may choose not to provide Gram Fit with your Personal Data. However, if you choose not to provide your Personal Data, this may limit your ability to use certain features of our Services.

How to Exercise Your Rights

Gram Fit takes steps to keep your Personal Data accurate and up to date. If you reside in the European Economic Area, you have certain rights to the Personal Data that we have collected about you. To exercise your rights to your Personal Data, the fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose from DSR Retrieval, DSR Deletion, or Opt Out options. For other inquiries, please contact our DPO at [email protected].

You have the following rights:

How we may disclose your Personal Data

The GDPR and national laws of European Union member states implementing the GDPR permit the sharing of Personal Data relating to users who are residents of the European Economic Area with third parties only under certain circumstances. If you reside in the European Economic Area, we will only share your Personal Data as described in our Privacy Policy if we are permitted to do so under applicable European and national data protection laws and regulations.

Health Data

Some Fitness and Dietary Data that we collect may be considered personal health data under the GDPR as interpreted by the European data protection supervisory authorities if recorded over a longer period of time. We process this type of data to provide you with additional information that you can incorporate into your evaluation of your progress toward your fitness and dietary objectives; it should not, however, be considered professional medical advice and is not intended to be used for diagnostic purposes.

Transfers of Your Personal Data to Other Countries

The Personal Data Gram Fit processes, and all associated Services and systems, including registration, are housed on servers in the United States. If you are located outside of the United States, please be aware that Personal Data we collect will be processed and stored in the United States (the data protection and privacy laws in the United States may offer a lower level of protections than in your country/region).

In order to use our Services, we may require you to agree to the transfer, storage, and/or processing of your Personal Data in the United States. In other situations where Personal Data is transferred outside of the European Economic Area (the EEA) or the United Kingdom, Gram Fit leverages other mechanisms for international data transfer including the European Commission-approved standard contractual clauses and consent. You have the right to request a copy of the applicable measure or further information by contacting us through "HOW CAN YOU CONTACT US ABOUT THIS POLICY"

Marketing Communications

Where we are legally required to do so, we ask you for your prior consent before providing you with promotional materials or information. You may revoke your consent at any time (this will not affect the processing of your Personal Data undertaken until the revocation). If you want to stop receiving promotional materials, etc., you can do so at any time by reaching out to us at "HOW CAN YOU CONTACT US ABOUT THIS POLICY"

Legal Basis for Processing Under the GDPR

In this section we provide information on the legal basis for our processing of your Personal Data as required by Art. 13 and 14 of the GDPR:

Right to Lodge a Complaint Before the Data Protection Authority

We encourage you to contact us directly and allow us to work with you to address your concerns. Nevertheless, you have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State where you reside, work or the place of the alleged infringement. You have the right to do so if you consider that the processing of Personal Data relating to you infringes applicable data protection laws.

Changes to this Privacy Policy

In order to enhance our Services it might be necessary to change this Privacy Policy from time to time. We therefore reserve the right to modify this Privacy Policy in accordance with the applicable data protection laws. Please visit our Website from time to time for information on updates to this Privacy Policy.

Residents of the United States

We don't sell Personal Data as defined by Nevada law.

Residents of California

If you are a resident of California, you have certain rights to the Personal Data that we have collected about you. Under California law, the exercise of these rights is subject to certain exemptions to safeguard the public interest (e.g., the prevention or detection of crime) and our interests (e.g., maintaining confidentially when legally required ). We will comply with your request as soon as reasonably practicable. Requests to exercise your rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and applicable law. To prevent unauthorized access to your Personal Data, we take steps to verify an individual's right to the data - including requiring users to reach out to us directly from a verified email address, pass a challenge response, and/or confirm information associated with the account. Following verification of your identity, we will notify you if we are unable to fulfill your request and outline the reasons we are unable to honor your request at this time.

Your California Privacy Rights

You have the following rights:

11. How to Exercise Your Rights

Exercise your rights (other than opt-out of "sale"): To exercise your rights to your Personal Data, the fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose from DSR Retrieval, DSR Deletion, or Opt Out options. For other inquiries, please contact our DPO at [email protected].

Exercise your opt-out of "sale" rights: The fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose Opt Out. For other inquiries, please contact our DPO at [email protected].

Additional California Rights

California Civil Code Section 1798.83 permits California residents to request and obtain from us a list of what Personal Data (if any) we disclosed to third parties for that third party's direct marketing purposes in the preceding calendar year and the names and addresses of those third parties. Requests may be made only once a year and are free of charge.

Under Section 1798.83, we currently do not share any Personal Data with third parties for their direct marketing purposes. If we do decide to share your Personal Data with third parties for their marketing purposes, you may opt-out of this disclosure at any time by submitting a request through "HOW CAN YOU CONTACT US ABOUT THIS POLICY"

12. DO WE MAKE UPDATES TO THIS POLICY?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.

13. HOW CAN YOU CONTACT US ABOUT THIS POLICY?

If you have questions or comments about this notice, you may contact our Data Protection Officer (DPO) by email at [email protected], or contact us by post at:

NIKOLABS PTE LTD
Data Protection Officer
1 RAFFLES PLACE, #34-04
ONE RAFFLES PLACE
Singapore, Singapore 048616
Singapore

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, the fastest way is via the in-app Privacy Request Center: go to FAQ → My Data and choose from DSR Retrieval, DSR Deletion, or Opt Out options. For other inquiries, please contact our DPO at [email protected].