GDPR
Last updated: August 9, 2026
This page explains how Fastingkit handles personal data under the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. It complements our Privacy Policy.
Contact for privacy / GDPR requests: help@fastingkit.app
1. Controller
The controller for personal data processed in connection with the Fastingkit website (https://Fastingkit.app) and the Fastingkit apps (iOS, Apple Watch companion features, widgets, Live Activities, and Android where available) is the publisher of Fastingkit. For data protection requests, email help@fastingkit.app.
Where Apple, Google, or other providers process data as independent controllers (for example App Store / Google Play billing, or your Apple ID / Google Account), their own privacy notices apply.
2. Scope
This notice covers:
- Use of the Fastingkit mobile apps and related system features
- Use of the marketing website at https://Fastingkit.app
- Support and feature-request channels (email and Featurebase where you choose to contact us)
You do not need a Fastingkit account. Core fasting data is stored on your device by default.
3. Categories of personal data
Depending on how you use the Service, we may process:
- Local app data — fasting plans and sessions, water logs, schedules, notes, preferences, and similar content you enter (stored on your device)
- Optional location-related data — approximate location or a place you enter, used for sunrise / sunset / moon timing (for example daylight theme or Ramadan-related timing)
- Optional sync data — if you enable iCloud Sync (Pro), eligible data in your private Apple CloudKit container
- Purchase / entitlement data — subscription or purchase status processed via Apple, Google, and RevenueCat (we do not receive full payment card details)
- Diagnostics and ads data — crash / diagnostic data via Firebase where enabled; advertising-related data if you use rewarded ads via Google Mobile Ads
- Support data — information you send by email or via Featurebase
- Website technical data — standard hosting / server logs (for example IP address, browser type, pages requested) as needed to operate the site
We do not use Apple HealthKit.
4. Purposes and legal bases
We process personal data for the following purposes and bases under Article 6 GDPR (official text: EUR-Lex Regulation (EU) 2016/679):
- Providing the app and website (timers, local storage, widgets, notifications you enable) — Art. 6(1)(b) GDPR (contract / steps prior to contract) and, where needed for security and availability of the site, Art. 6(1)(f) (legitimate interests)
- Optional features you turn on (location for timing, iCloud Sync, biometric lock on-device) — Art. 6(1)(a) and/or Art. 6(1)(b), depending on the feature; you can withdraw consent or disable the feature.
- Purchases and subscriptions — Art. 6(1)(b); store billing is handled by Apple / Google under their terms
- Stability, configuration, and ads (Firebase, Google Mobile Ads where used) — Art. 6(1)(f) and/or Art. 6(1)(a) where consent is required for advertising / tracking under applicable law
- Support and feature requests — Art. 6(1)(f) (answering your request) and, where relevant to a contract, Art. 6(1)(b)
- Legal compliance — Art. 6(1)(c) where we must retain or disclose data to meet a legal obligation
5. Processors and recipients
Depending on features you use, data may be processed by providers such as:
- Apple (App Store, CloudKit, WeatherKit, system services) — Privacy Policy
- Google (Play Billing, Firebase, Google Mobile Ads) — Privacy Policy; Firebase: Privacy and Security; ads: Advertising technologies
- RevenueCat — Privacy Policy
- Featurebase — Privacy Policy
- Our website hosting provider (technical operation of https://Fastingkit.app)
6. Retention
- Local app data remains on your device until you delete it in the app or uninstall the app
- iCloud Sync data remains under your Apple ID until you disable sync and/or delete it from iCloud
- Purchase records are retained by Apple / Google (and related entitlement services) under their retention practices
- Support emails and Featurebase submissions are kept as long as needed to handle your request and for related legitimate records, then deleted or anonymised unless a longer legal retention period applies
- Website server logs are kept only as long as needed for security, operations, and troubleshooting
7. Your rights
If GDPR applies to you, you may have the following rights (subject to legal limits). Each article links to the GDPR text:
- Access (Art. 15) — obtain confirmation and a copy of personal data we process about you
- Rectification (Art. 16) — correct inaccurate personal data
- Erasure (Art. 17) — request deletion where applicable
- Restriction (Art. 18) — request restriction of processing in certain cases
- Portability (Art. 20) — receive data you provided in a structured, commonly used, machine-readable format where the right applies
- Object (Art. 21) — object to processing based on legitimate interests, and to processing for direct marketing
- Withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time without affecting prior lawful processing
- Complaint (Art. 77) — lodge a complaint with a supervisory authority in your Member State of residence, place of work, or place of the alleged infringement
Because much of your fasting data stays on your device (and optionally in your iCloud), many access / deletion actions are available directly in the app, system settings, or by uninstalling the app. For requests about data we control (for example support correspondence), email help@fastingkit.app.
Right to object (Art. 21)
Where we process personal data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.
If we process personal data for direct marketing, you may object at any time; we will then stop that processing.
8. Your choices
- Revoke location, notification, or tracking-related permissions in system settings
- Disable iCloud Sync when available
- Disable crash reporting when the setting is offered
- Manage or cancel subscriptions in App Store / Google Play settings
- Delete the app to remove local data
- Contact us at help@fastingkit.app
9. Children
Fastingkit is not directed to children under 13 (or the minimum age required in your country). Do not use the app if you are under the applicable age without a parent or guardian.
10. Changes
We may update this GDPR page from time to time. The “Last updated” date will change when we do. For the full description of practices, see the Privacy Policy.
11. Contact
GDPR / privacy requests: help@fastingkit.app