Legal Policy

Privacy Policy

Effective Date: May 26, 2026 | Version: 4.5

Scope and RolesService Categories CoveredInformation We CollectHow We Use InformationLegal Bases (EEA/UK)How We Disclose InformationAI Features and Third-Party Model ProvidersCookies, Analytics, and Advertising TechnologiesData RetentionData SecuritySensitive and Regulated DataInternational Data TransfersYour Privacy RightsCalifornia Privacy NoticeChildrenThird-Party Sites and ServicesChanges to This PolicyContact

Systems Logic & Automation Group LLC (doing business as SYSTALOG.ai, GemFit.ai, and IronFeed) Effective Date: May 26, 2026 Version: 4.5


This Privacy Policy explains how Systems Logic & Automation Group LLC collects, uses, discloses, and protects personal information when you use our websites, applications, APIs, and related services (collectively, the "Services"). References to SYSTALOG.ai, GemFit.ai, GemFit, IronFeed, we, us, and our mean Systems Logic & Automation Group LLC unless a separate signed agreement says otherwise.

This Privacy Policy should be read together with our Terms of Service.

GemFit.ai Mobile Privacy Summary

For GemFit.ai mobile users, the short version is:

  • GemFit is private by default. Food logs, workouts, body metrics, goals, reports, and private progress logs are not public unless you choose to share something through a social feature.
  • We do not sell personal information, run third-party advertising SDKs, or use GemFit mobile data for cross-app advertising tracking.
  • Location is not required for ordinary food, workout, AI, billing, report, or private progress features. Approximate location is requested only if you choose adult social features that require state eligibility checks.
  • Apple Health, device step import, camera, microphone, and photo access are permission-based. GemFit asks for those permissions only when you use a feature that needs them.
  • AI features may send the text, image, app context, or draft data needed for your request to third-party AI, nutrition, search-grounding, or moderation providers. Do not use AI features for medical, emergency, or regulated health decisions.
  • You can use in-app account deletion or contact support@systalog.ai for access, correction, deletion, or privacy questions.

Table of Contents

  1. Scope and Roles
  2. Service Categories Covered
  3. Information We Collect
  4. How We Use Information
  5. Legal Bases (EEA/UK)
  6. How We Disclose Information
  7. AI Features and Third-Party Model Providers
  8. Cookies, Analytics, and Advertising Technologies
  9. Data Retention
  10. Data Security
  11. Sensitive and Regulated Data
  12. International Data Transfers
  13. Your Privacy Rights
  14. California Privacy Notice
  15. Children
  16. Third-Party Sites and Services
  17. Changes to This Policy
  18. Contact

1. Scope and Roles

This Privacy Policy applies to personal information processed by Systems Logic & Automation Group LLC across our Services.

Depending on context, we may act as:

  • A business/controller for account, billing, support, and platform operations
  • A service provider/processor handling customer data on behalf of business users

2. Service Categories Covered

This Policy applies to personal information processed across product areas, including:

  • AI suite tools and content-generation workflows
  • GemFit.ai and IronFeed fitness, nutrition, coaching, progress, reporting, social, and mobile/web app workflows
  • Management systems (including vendor, talent, and K9 training workflows)
  • Portals, dashboards, APIs, integrations, and related mobile/web apps
  • Support, billing, account, and trust/safety operations

3. Information We Collect

Depending on use, we may collect the following categories.

3.1 Information You Provide

  • Account and profile data (name, email, username, organization, security preferences)
  • User content (prompts, uploads, records, notes, documents, outputs, captions, and attachments)
  • Health, fitness, nutrition, and wellness-adjacent data you choose to provide, such as workouts, exercises, sets, reps, weights, workout duration, calorie-burn estimates, meals, food photos, nutrition logs, macro and micronutrient estimates, allergen/diet flags, supplements, custom nutrient trackers, goals, progress reports, body weight, body fat percentage, body measurements, step counts, and body-composition report imports
  • Progress photos and other media you upload or share, including private body-progress photos, meal photos, social feed media, and profile images
  • Social and messaging content (public/followers/private post settings, direct messages, and shared links/media)
  • Management-system records you submit (for example personnel, vendor, training, and operational records)
  • Billing/support information (subscription details, invoices, and support communications)

3.2 Information We Collect Automatically

  • Device/browser/app metadata
  • Usage and diagnostics logs
  • Security and fraud signals (including IP-derived signals and abuse telemetry)
  • Cookie/local storage identifiers and preference data
  • Interaction telemetry used for feed relevance and anti-abuse controls (for example likes, follows, and moderation signals)
  • Device sensor data you authorize in-app, currently including reviewed device step imports where available
  • AI confidence, source, estimation, and parsing metadata generated when the Services analyze food, workouts, body metrics, reports, images, prompts, or other inputs
  • Limited raw import and AI-review capture data you submit through logging, import, photo analysis, Health Sync preview, or coaching features, such as the original text or import context, parsed draft results, correction notes, source/confidence metadata, and troubleshooting metadata. We use size limits and may store photo-import metadata or AI results without storing the original image payload unless the feature itself requires image storage.

3.3 Information from Third Parties

  • Payment confirmations and billing metadata from payment processors
  • App Store and RevenueCat subscription metadata, including product, entitlement, renewal, cancellation, and receipt-related status
  • Authentication/session metadata from identity providers
  • Provider metadata required to deliver infrastructure and AI operations
  • Nutrition reference, web-grounding, moderation, app-store, and device-provider metadata used to operate requested features

4. How We Use Information

We use personal information to:

  • Provide, maintain, secure, and improve Services
  • Authenticate users and prevent unauthorized access
  • Process subscriptions, billing, credits, and support requests
  • Deliver user-requested AI features and workflows
  • Estimate, parse, summarize, and organize user-requested fitness, nutrition, training, wellness, and progress information
  • Import and reconcile user-authorized device step data while preserving manual entries where available
  • Deliver user-requested social sharing and private messaging features
  • Detect/prevent abuse, fraud, and policy violations
  • Operate ranking, personalization, and discovery features for feeds, plans, programs, playlists, reports, and recommendations
  • Enforce contractual and legal obligations
  • Conduct analytics and product performance measurement, subject to applicable law
  • Debug, evaluate, and improve food, workout, body-metric, supplement, device-import, and AI-routing accuracy using bounded import/review records

5. Legal Bases (EEA/UK)

Where required, we process personal data under one or more legal bases:

  • Contract performance
  • Legitimate interests (for security, product operations, fraud prevention, and service improvement)
  • Consent (where required for non-essential cookies/marketing)
  • Legal obligation

6. How We Disclose Information

As of the Effective Date, we do not sell personal information for monetary compensation.

We may disclose personal information to:

  • Service providers/subprocessors for hosting, identity, payments, analytics, support, and operations
  • AI model/API providers when users invoke AI features
  • App Store, RevenueCat, Stripe, and similar purchase-management providers when needed to process purchases, verify entitlements, restore purchases, handle refunds/cancellations, and support billing questions
  • Nutrition, search-grounding, moderation, storage, app platform, and device/service providers when needed to provide requested features
  • Other users and recipients you choose to share with, based on your selected visibility and messaging settings
  • Professional advisors/auditors under confidentiality duties
  • Courts, regulators, and law enforcement where legally required or necessary to protect rights/safety
  • Successors in merger, acquisition, restructuring, or asset transfer transactions

We may also disclose aggregated or de-identified information that does not reasonably identify individuals.

7. AI Features and Third-Party Model Providers

When users invoke AI features, prompts, images, files, app context, fitness/nutrition/body-metric details, and output metadata may be sent to third-party AI providers, search-grounding providers, nutrition/reference services, and moderation providers as needed to perform the requested feature.

Important:

  • Third-party providers may apply their own retention/security/training practices.
  • Their terms and privacy notices govern their processing.
  • Users should not submit sensitive or regulated data unless they have legal authorization and appropriate controls.
  • Food, workout, calorie-burn, body-composition, allergen, supplement, and health-related AI outputs are estimates for general wellness and organization only. They are not medical, dietetic, nutritional, psychological, emergency, injury, or professional advice.

AI outputs may be inaccurate, incomplete, biased, or infringing. Users are responsible for review before use.

8. Cookies, Analytics, and Advertising Technologies

We use cookies and similar technologies for:

  • Authentication and session continuity
  • Security and abuse prevention
  • Preference storage and UX
  • Analytics and campaign attribution

Where required, we obtain consent before enabling non-essential cookies or similar technologies.

9. Data Retention

We retain personal information for as long as reasonably necessary for:

  • Service delivery and account management
  • Security, fraud prevention, and reliability operations
  • Legal, tax, accounting, and contractual obligations
  • Dispute resolution and enforcement

Retention periods vary by data category and legal requirements.

For some mobile media features, we apply plan-based retention windows and storage limits. Expired or over-limit generated media may be archived, removed, or made unavailable in-app according to plan limits and operational constraints.

For raw import and AI-review capture records used for debugging and product improvement, we apply technical size limits, access controls, and a default operational retention target of up to 18 months unless deletion, legal, security, or account-support needs require a shorter or longer period.

For direct messaging and social features:

  • Message visibility can be affected by participant deletion actions.
  • Public or followers-visible posts may remain visible until removed by the publisher, moderation systems, or legal process.
  • Private progress photos are intended to be stored in non-public storage with owner-scoped access controls, but signed URLs, backups, provider logs, or legal/security retention may persist for limited periods.
  • AI request payloads, provider responses, moderation logs, billing records, and security/audit logs may have different retention periods than ordinary user-entered app records.

When deletion is requested and legally permissible, we delete or anonymize data using operational processes.

For account or data deletion requests, see Delete Account and Delete Data.

10. Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information.

No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.

11. Sensitive and Regulated Data

Unless you have a separate signed agreement with us that expressly allows a regulated use case, do not submit regulated categories of data where prohibited by law.

You are responsible for determining whether your use case requires additional contractual, legal, or regulatory controls.

GemFit.ai and IronFeed are wellness and fitness tools, not healthcare providers, medical devices, covered entities, business associates, or substitutes for licensed medical, nutrition, legal, or emergency professionals unless we have entered a separate signed agreement that expressly says otherwise. Do not use the Services to store protected health information, medical records, diagnosis/treatment information, or other regulated health data unless you have confirmed the required legal basis and signed controls with us.

12. International Data Transfers

We and our providers may process information in countries other than your own, including the United States.

Where required, we use legally recognized transfer mechanisms.

13. Your Privacy Rights

Subject to local law, you may have rights to:

  • Access personal information
  • Correct inaccurate personal information
  • Delete certain personal information
  • Restrict/object to certain processing
  • Request portability of applicable data
  • Withdraw consent where processing is based on consent

To exercise rights, contact support@systalog.ai. We may verify identity before fulfilling requests.

14. California Privacy Notice

California residents may have rights under CCPA/CPRA, including rights to know, access, delete, correct, and limit use/disclosure of sensitive personal information, subject to legal exceptions.

Where required by law, we provide notice and applicable opt-out/limitation controls through available request channels.

You may submit requests at support@systalog.ai.

15. Children

GemFit.ai accounts are not available to users under 13. GemFit.ai social, direct messaging, public discovery, posting, media sharing, and progress-photo sharing features are intended for adults only and may require age, state, and eligibility checks.

Other SYSTALOG services may have different age or account requirements depending on the product and customer agreement. If we learn we collected personal information from a child in violation of applicable law, we will take steps to delete it.

16. Third-Party Sites and Services

Our Services may contain links or integrations to third-party sites/services. Their privacy practices are governed by their own policies, not this Policy.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions are effective when posted unless otherwise stated.

We will update the Effective Date for material revisions.

18. Contact

For privacy questions or requests:

  • Email: support@systalog.ai
  • Website: https://www.systalog.ai