Privacy Policy
Short version: we collect what we need to plan your meals and workouts and to help you along the way, we don’t sell it, we don’t track you, and we never hand the AI your name or account details ourselves. What you choose to tell Ember goes to it as you said it.
Last updated September 23, 2026
What we collect
Almost all of it comes from you: during onboarding, in Preferences, or when you tell Ember something. We don’t buy data about you, and we don’t run advertising trackers. We do count page views, with a cookieless measurement that tells us which pages people read rather than who read them.
Your account
- Email address
- Password (stored only as a bcrypt hash, so we never see or keep the original)
- If you sign in with Google, Apple, or Facebook: the verified email address and name they give us, and nothing else
About you
- First and last name (last name optional)
- Profile photo, if you upload one
- Date of birth, biological sex, height, current weight, and target weight
- Your goal, activity level, and chosen pace
Progress photos (encrypted, and only yours to see)
- Progress photos are encrypted where they are stored, under a key derived separately for your account
- Only your signed-in session can retrieve them: they are never public, nothing in the app can share them, and no admin screen shows them
- Honest boundary: our servers do the encrypting, so this is strong access control and encryption at rest, not a mathematical guarantee against someone holding our production keys
- Delete a photo, or your account, and the encrypted bytes are removed with it
Food and training preferences
- Allergies, dietary restrictions, and eating style
- Foods you love, foods you avoid, and preferred cuisines
- Fitness level, equipment access, movement styles, and session length
- Injuries and areas you asked us to protect
What the app creates for you
- Weekly meal plans, recipes, and grocery lists
- Weekly training plans and which sessions you completed
- Saved and favorited recipes, along with your ratings and notes
- Weigh-ins and daily step counts you log
Your food log
- Meals and snacks you log, whether you typed them, picked them from your plan, looked them up, said them, or photographed them: what the food was, roughly how much, and the calorie and nutrient estimates attached to it
- Photos of food you log by camera. The photo is kept with the entry so you can see the plate beside its numbers, along with what the app read in it and what you confirmed was there. Delete the entry and the photo goes with it; a photo you take and decide not to log is removed within a day
- Foods you logged before, kept so they can be logged again in a tap
- These are estimates. A photo cannot weigh a plate, a food database describes a typical serving rather than yours, and a recipe’s figures are per serving rather than per plateful
- Only yours. Your food log never reaches the feed, a leaderboard, or a challenge, and nothing in the app scores it
Your conversations with Ember
- What you type to Ember, and what Ember says back, kept as conversations you can reopen from the list inside Ember and delete one at a time
- The address of a recipe page you paste, and a dish you ask Ember to find online, as part of what you typed. The recipes read from those pages are shown to you and not stored
- Photos you show Ember, of a meal or a piece of gym equipment. A photo of food is kept the same way as one taken from the food log, above. A photo of equipment is not kept: only what it was read as, and a fingerprint of the file so the same photo is not charged for twice
- When you talk out loud, a transcript of the conversation. We do not store the audio; see ElevenLabs below for what they hold
- The changes Ember made to your plans on your say-so, so you can see what it did
Billing
- Your Stripe customer ID, subscription status, plan, and renewal date
- Card numbers never touch our servers: Stripe collects and stores them directly
Technical
- Push notification subscriptions, if you turn notifications on
- A private calendar-feed token, if you subscribe to your plan in a calendar app
- Token, image, and voice-minute counts per AI call, including your conversations with Ember, so we can measure what the service costs to run
About your health information
Your birth date, sex, weight, allergies, and injuries are sensitive, and we treat them that way. We collect them for one reason: the math and the safety checks don’t work without them. Your age, sex, height, and weight produce your calorie target. Your allergies and injuries become hard rules that every recipe and every workout is checked against in code before you ever see it, including anything Ember adds or changes at your request. What you log as eaten is health information too, and it gets the same treatment: it is only ever yours, it never reaches the feed, a leaderboard, or a challenge, and Ember reads it only to help you.
We are not a medical provider, and Let's Get Hot is not a medical record. We don’t share this information with insurers, employers, advertisers, or data brokers. Not ever.
How AI uses your information
Your plans are generated by OpenAI. Before anything is sent, we build a deliberately anonymous summary in a single place in our code: your nutritional targets, restrictions, allergies, injuries, preferences, and equipment. Your name, email address, and account ID are excluded by design and never leave our servers as part of a generation request.
Ember, the coach you can talk to, runs on two providers rather than one. ElevenLabs runs the conversation itself, and an OpenAI model writes the replies. When you ask Ember something, your message and the parts of your plans and food log Ember needs to answer are sent to ElevenLabs and on to OpenAI, along with that same anonymous summary. That is true whether you type or speak. We still never send your name, email, or account ID ourselves. What you write or say is sent as you said it, so if you tell Ember your name, both of them see it in your message.
Ember can read your plans and your food log, and it can change your plans when you ask. Every change passes the same allergy, injury, and equipment checks in code as a week we built for you, and nothing changes until you tap Apply. It cannot log steps or workouts, and it cannot join, score, or alter a challenge or a leaderboard, for you or for anyone else.
Talking to Ember out loud sends your microphone audio from your device to ElevenLabs, which turns it into text and turns Ember’s reply into a voice. No recording is kept and no voiceprint is made from it. ElevenLabs holds the written transcript for thirty days so a problem you report can be looked into, then deletes it. The microphone is off until you tap it, and we ask you once before the first time.
A photo you show Ember, or take from the food log, goes to OpenAI instead, to work out what is on the plate or which machine you are looking at. When you look a food up by name, that name alone goes to USDA FoodData Central, a public-domain database run by the United States Department of Agriculture, to fetch its calories and nutrients. Nothing else about you goes with it.
Food photos are kept, with the entry they made, so the plate shows beside its numbers in your log. We may also use them, together with what the app read in them and what you confirmed was on the plate, to improve how the app reads plates. That work never carries your name, your email or anything else from your account, and the photos are never shown to other members or used in marketing. Delete the entry and the photo goes with it.
Ember can also read recipes from the web, in two ways. If you paste the address of a recipe page, or ask Ember to find recipes online, our server fetches the pages and reads the recipe each one publishes as structured data, so the site sees a request from us rather than from your device. A dish you ask for online goes to OpenAI’s web search to find those pages. Only the ingredients and steps are read; they are shown to you with the site’s name and a link back, they pass the same allergy and kitchen checks as a recipe we write, and nothing from the page is stored. When a page prints no nutrition figures, its ingredient list goes to OpenAI to estimate them, and the card says the figures are an estimate.
OpenAI processes all of these requests through its business API, which does not use submitted data to train its models. Dish photos are generated from a recipe name and description only, and are cached and reused across all users. The images are not personal to you. OpenAI also checks reviews, comments, community notes, and uploaded photos against our rules before anything is published.
Who else touches your data
These are our service providers. We don’t sell your personal information, and we don’t share it for advertising or cross-context behavioural targeting.
Kroger
Prices your grocery list at a real store, and fills your cart if you link your Kroger account
Your ZIP code (if you volunteer one) and ingredient names, to find your nearest store and its shelf prices. If you connect your Kroger account, we hold an access token that can add items to your cart, encrypted at rest and deleted the moment you disconnect or delete your account. We never see your Kroger password, your payment details, or what you buy: the token can add to a cart and nothing else, and checkout happens on Kroger’s own site.
OpenAI
Generates your meal plans, workouts, and dish photos; writes Ember’s replies; identifies the food and gym equipment in photos you show Ember; checks reviews, comments, and uploaded photos against our rules
For plans: your calorie target, goal, budget, dietary restrictions, allergies, food likes and dislikes, injuries, fitness level, and equipment. For Ember: your messages, the photos you attach, a transcript of anything you said out loud, the parts of your plans and food log Ember needs to answer, a dish you ask it to find online (to OpenAI’s web search), and the ingredient list of a recipe page it read when that page prints no nutrition figures, plus that same summary. For moderation: the text or photo being checked. Never your name, email, or any account identifier from us, though anything you type or say to Ember is sent as you said it.
ElevenLabs
Runs your conversations with Ember, typed and spoken: carries the conversation to the model that answers, and speaks the replies out loud
Your messages to Ember and Ember’s replies, and the parts of your plans and food log Ember needs to answer. When you tap the microphone, your audio as well, streamed straight from your device, which means ElevenLabs also sees your device’s IP address for that connection. Nothing from your account goes with it: no name, no email, no weight, and no calorie target. No recording is kept and no voiceprint is made from your voice; ElevenLabs holds the written transcript for thirty days, then deletes it.
USDA FoodData Central
Looks up the calories and nutrients for a food you search for by name
The food name you typed, and nothing else. No account identifier, no cookie, and no other part of your log. It is a public-domain reference database run by the United States Department of Agriculture, and we cache what it returns so the same food is only ever looked up once.
MongoDB Atlas
Stores the database
Everything listed above, encrypted in transit and at rest.
Vercel
Hosts and serves the application, counts page views, and measures page speed
Standard server request logs, including IP address, plus cookieless page-view counts: the page, where the visit came from, rough device and country, and how quickly the page loaded. No cookie is set, and nothing in it names you.
Cloudflare R2
Stores the images: dish photos, any photo you attach to a review, the food photos behind your log, and your progress photos
The image files themselves, and nothing that says whose they are. Your progress photos arrive already encrypted under your own key, so Cloudflare holds bytes it cannot read. Every image is served through this app rather than from Cloudflare directly, so your browser never contacts them and they never see your IP address.
Resend
Delivers our email
Your email address and the contents of the message. That means password resets, weekly plan notices, and anything you send us through the contact form.
Stripe
Processes subscription payments
Your email address and payment details, which you enter on Stripe’s own checkout page.
Google (YouTube)
Serves optional exercise tutorial videos
Nothing until you tap a video. When you do, YouTube receives the request in privacy-enhanced mode.
Google (Firebase Cloud Messaging)
Delivers push notifications to the Android app
A device token that identifies your installation, plus the title and text of the notification. Nothing is sent unless you turn notifications on.
Your browser vendor
Delivers push notifications on the web
Apple, Google, or Mozilla relay the notification to your device if you enabled notifications in a browser or the installed web app.
PayPal
Pays affiliate commissions
Only for creators in the affiliate program, and only the PayPal address they gave us and the amount owed. Nobody else is ever named to PayPal.
Things you choose to share
A few features publish information on purpose, and every one is entirely up to you:
- Recipe links. Creating a link publishes that one recipe, with its name, ingredients and steps, to an unlisted web address anyone with the link can open. Nothing about you appears on the page, it isn’t indexed by search engines, and you can switch the link off at any time from the recipe.
- Recipe reviews. Posting a review publishes its text, your rating, any photo you attach, and your first name on that dish’s public recipe page. You can delete your review at any time, which removes all of it.
- Your badge page, leaderboards, and friends. One switch, off unless you turn it on in Profile. When on: an unlisted page shows your first name, profile photo, and earned badges; leaderboards rank you by effort only, meaning sessions finished, step days, meals cooked and badges, never weight or any health number; and other members can send you friend requests, which you accept or decline. Nothing is indexed by search engines, and switching it off takes the page, your board entries, and your friend visibility down immediately.
- Calendar subscriptions. The private feed URL exposes only meal or session names and dates. Treat it like a password: anyone you give it to can read it.
Your choices and rights
You can view and change everything about yourself in Profile and the settings pages in your account menu (Meal, Training, App preferences). Beyond that:
- Download your data. Profile → Your data exports everything we hold about you as a JSON file.
- Delete your account. Profile → Your data → Delete account removes your account and every record tied to it immediately. It cannot be undone.
- Turn off notifications any time on the Notifications page.
Depending on where you live, you may also have the right to correct your data, object to processing, or lodge a complaint with a data protection authority. To make any request, email support@letsgethot.app.
How long we keep it
We keep your information for as long as your account exists, because your plans and history are the product. When you delete your account, we delete your profile, plans, grocery lists, workouts, workout history, saved recipes, weigh-ins, step logs, food log and its photos, conversations with Ember, push subscriptions, profile photo, progress photos (both the encrypted images and the key that opened them), and recipe links right away.
Three things intentionally survive. Cached dish photos, which are shared across all users and contain nothing personal. Records our payment processors must retain for financial and tax compliance, governed by their own policies. And, if you took part in the creator programme, your commission history: amounts, dates and payment references are financial records, kept so that money already owed can still be paid and audited, with your name and email attached for that purpose. Your referral link stops working immediately.
There is a step-by-step guide to deleting your account, which you can follow even if you have already uninstalled the app.
Security
Passwords are hashed with bcrypt and never stored in readable form. Traffic runs over HTTPS, and the database is encrypted in transit and at rest. Access to private data is always scoped to your signed-in session on the server, never to an ID the browser can change. No system is perfectly secure, but we keep the amount of data we hold deliberately small.
Children
Let's Get Hot is not intended for anyone under 13. Signing up asks you to confirm you are 13 or older, and a date of birth younger than that is refused. If you believe a child has created an account, email us and we will remove it.
Changes to this policy
If we change how we handle your information in a meaningful way, we’ll update the date at the top of this page and tell you in the app before the change takes effect.
Questions? Email support@letsgethot.app. See also Cookies & device storage and our Terms of Service.