Last updated: 12 September 2026 · Contact: gcbtur@gmail.com
Qfit is an offline-first calorie, diet and fitness tracker. We respect your privacy. This policy explains what data the app handles.
Your profile (name, age, height, weight, sex, activity, goals) and your logs are stored locally on your device. This includes food, water, weight, exercise and fasting entries, body measurements, progress photos, and — if you use the wellness section — your menstrual cycle dates and symptom notes. Unless you use the AI meal logging feature, the online food search or the optional cloud backup described below, these records are not sent to our servers. The optional usage statistics described below never contain these records — only anonymous counts.
If you create an account, your email address and display name are processed by Google Firebase Authentication to sign you in. You can use the entire app without an account. Signing in also enables the optional cloud backup described in the next section.
If you sign in, Qfit can keep a backup of your logs so you can restore them on a new phone. The backup contains your profile (age, height, weight, sex, activity and goals) and your food, water, weight, exercise, body measurement and fasting entries. Progress photos and meal photos are never backed up; they stay only on your device.
Where it goes: the backup is written over an encrypted (HTTPS/TLS) connection to Google Firebase Firestore, which acts as our processor. It is stored under your account and Firebase security rules allow only your signed-in account to read or write it. We do not use the backup for advertising, profiling or any other purpose.
Control: automatic backup can be switched off from the Profile screen, and the app works fully without it. Using Qfit without an account means no backup is ever created. Deleting your account deletes the backup as well.
Qfit has an optional feature that turns a meal description or a meal photo into food entries. It only runs when you tap the AI button on the AI logging screen; nothing is sent in the background.
What is sent: only the text you typed, or the single photo you chose or captured for that request. Your profile, weight, health data, cycle data and other logs are never included.
Where it goes: the request travels over HTTPS to our own Cloudflare Workers endpoint, which forwards it to the Anthropic API for analysis and returns the recognised food items to your device. Anthropic acts as our processor for that request and is subject to its own terms.
Retention: we do not store your meal text or your photos. They are held only in memory for the duration of the request and are not written to any database or log by us. The resulting food entries are saved on your device, not on our servers. A copy of the meal photo you attached is kept only on your device next to those entries (so you can see it in your diary) and is deleted together with them.
AI logging uses credits earned by watching rewarded ads. For that, a random, app-generated identifier (not your email, name or advertising ID) is sent to our endpoint so the reward can be credited to the right device.
When you search for a packaged product or scan a barcode, Qfit queries the public Open Food Facts database. The search term or barcode you entered and your IP address reach Open Food Facts as part of that request. No profile, health, weight or log data is sent, and the request is not linked to any account. Searching only the built-in food catalogue works fully offline.
With your permission, Qfit reads only your step count, active calories burned, and exercise session data through Android Health Connect. This data stays on your device: it is not sent to our servers, not shared with third parties, not sold, and never used for advertising or profiling. Qfit does not write any data to Health Connect, and does not request background or historical health data access. You can revoke this permission at any time from the Health Connect app, and the rest of Qfit keeps working without it.
Phone step sensor (fallback). If Health Connect is not connected or not installed, Qfit can read today's step count from your phone's own step sensor instead (Android “Physical activity” permission, iOS “Motion & Fitness”). The permission is requested once; if you decline, it is not asked again and Qfit simply shows no steps. Sensor readings stay on your device, are not sent to our servers, not included in the cloud backup, not written to Health Connect and not used for advertising. On Android the sensor counts only while the app is running, and the source is labelled “Steps (phone sensor)” in the app.
The free version shows ads via Google AdMob. AdMob may collect your device advertising identifier and app-interaction data to serve and measure ads. In the EEA/UK we request consent (Google UMP) before personalized ads.
To see which parts of Qfit are used and where the app fails to keep people, the app counts four events on your device: app opens, screen views, meals logged, and ads shown. Once a day it sends a single aggregated summary — the number of opens, the five most viewed screens, the number of meals logged and the number of ads shown for that day, plus the app version, platform and app language.
What is not included: no name, e-mail, account ID, advertising ID, device ID or IP-based location is attached; no food, weight, health, cycle or Health Connect data; no timestamps of individual actions. A random, per-day batch number is used only to discard duplicate deliveries and cannot identify you or your device.
Where it goes: to our own Cloudflare Workers endpoint. We do not use any third-party analytics SDK (no Google Analytics, no Firebase Analytics).
How to turn it off: Profile → “Send usage statistics”. It is on by default, the app tells you about it once on first launch, and turning it off also discards any counts not yet sent.
We do not sell your data. We do not share your Health Connect data (steps, active calories, workouts) with anyone. We do not use health data for advertising or profiling. We do not use any third-party analytics SDK (no Google Analytics, no Firebase Analytics); the only usage measurement is the anonymous, aggregated daily count described under “Usage statistics”, sent to our own server, and you can turn it off. Apart from the optional step count from your phone's own step sensor described above (which stays on the device), we do not read health data from device sensors, and we do not write any data to Health Connect. Apart from the optional AI feature, the online food search and the optional cloud backup described above, your logs never leave your device.
You can delete your account from inside the app, from the Account card on the Profile screen. This removes your account identity and clears the data stored on the device. If a cloud backup exists, it is deleted together with the account. You can also delete local data at any time by clearing the app's data or uninstalling it.
Full instructions, including how to request deletion by email, are at quantkod.com/qfit-account-deletion.html or write to gcbtur@gmail.com. Signing out is not deletion — it only ends the session.
Qfit is not directed at children under 13.
Qfit is not medical advice; calorie and nutrition values are estimates. Consult a professional for health decisions.
Son güncelleme: 12 Eylül 2026 · İletişim: gcbtur@gmail.com
Qfit, çevrimdışı öncelikli bir kalori, diyet ve fitness takip uygulamasıdır. Gizliliğinize saygı duyuyoruz.
Profilin (ad, yaş, boy, kilo, cinsiyet, aktivite, hedefler) ve kayıtların cihazında yerel olarak saklanır. Buna yemek, su, kilo, egzersiz ve oruç kayıtları, vücut ölçüleri, ilerleme fotoğrafları ve — sağlık bölümünü kullanıyorsan — adet döngüsü tarihlerin ve semptom notların dâhildir. Aşağıda anlatılan AI ile öğün kaydı özelliğini, çevrimiçi besin aramasını ya da isteğe bağlı bulut yedeği kullanmadığın sürece bu kayıtlar sunucularımıza gönderilmez. Aşağıda anlatılan isteğe bağlı kullanım istatistiği bu kayıtları hiçbir zaman içermez — yalnızca anonim sayılar.
Hesap oluşturursan e-posta adresin ve adın, giriş için Google Firebase Authentication tarafından işlenir. Uygulamanın tamamını hesapsız da kullanabilirsin. Giriş yapmak, bir sonraki bölümde anlatılan isteğe bağlı bulut yedeğini de açar.
Giriş yaparsan Qfit, kayıtlarını yeni bir telefonda geri yükleyebilmen için yedekleyebilir. Yedek profilini (yaş, boy, kilo, cinsiyet, aktivite ve hedefler) ve yemek, su, kilo, egzersiz, vücut ölçüsü ve oruç kayıtlarını içerir. İlerleme fotoğrafları ve öğün fotoğrafları hiçbir zaman yedeklenmez; yalnızca cihazında kalır.
Nereye gider: yedek, şifreli (HTTPS/TLS) bağlantıyla veri işleyicimiz olan Google Firebase Firestore'a yazılır. Hesabının altında saklanır; Firebase güvenlik kuralları yedeği yalnızca giriş yapmış kendi hesabının okuyup yazmasına izin verir. Yedeği reklam, profilleme ya da başka bir amaçla kullanmayız.
Denetim: otomatik yedek Profil ekranından kapatılabilir; uygulama yedeksiz de eksiksiz çalışır. Hesapsız kullanımda hiçbir yedek oluşmaz. Hesabını sildiğinde yedek de silinir.
Qfit'te, yazdığın öğün açıklamasını veya çektiğin öğün fotoğrafını besin kayıtlarına çeviren isteğe bağlı bir özellik var. Yalnızca AI kayıt ekranındaki butona bastığında çalışır; arka planda hiçbir şey gönderilmez.
Gönderilen veri: yalnızca o istek için yazdığın metin ya da seçtiğin/çektiğin tek fotoğraf. Profilin, kilon, sağlık verilerin, döngü verilerin ve diğer kayıtların hiçbir zaman eklenmez.
Alıcı zinciri: istek HTTPS üzerinden kendi Cloudflare Workers ucumuza gider, oradan analiz için Anthropic API'ye iletilir ve tanınan besinler cihazına döner. Anthropic bu istek için veri işleyicimizdir ve kendi koşullarına tabidir.
Saklama: öğün metnini ve fotoğraflarını saklamıyoruz. Yalnızca isteğin süresince bellekte tutulurlar; tarafımızdan hiçbir veritabanına veya kayda yazılmazlar. Ortaya çıkan besin kayıtları sunucularımıza değil, cihazına kaydedilir.
AI kaydı, ödüllü reklam izleyerek kazanılan kredilerle çalışır. Bunun için uygulamanın ürettiği rastgele bir kimlik (e-postan, adın veya reklam kimliğin değil) ucumuza gönderilir; böylece ödül doğru cihaza yazılır.
Paketli bir ürün arattığında veya barkod okuttuğunda Qfit, herkese açık Open Food Facts veritabanını sorgular. Bu istekle birlikte yazdığın arama terimi ya da barkod ve IP adresin Open Food Facts'e ulaşır. Profil, sağlık, kilo veya kayıt verisi gönderilmez ve istek hiçbir hesapla ilişkilendirilmez. Yalnızca uygulama içindeki besin kataloğunda arama yapmak tamamen çevrimdışı çalışır.
İzin verdiğiniz takdirde Qfit, Android Health Connect üzerinden adım sayısı, aktif kalori ve egzersiz oturumu verilerinizi yalnızca okur. Bu veriler cihazınızda kalır: sunucularımıza gönderilmez, üçüncü taraflarla paylaşılmaz, satılmaz ve reklam ya da profilleme amacıyla kullanılmaz. Qfit Health Connect'e veri yazmaz; arka planda veya geçmişe dönük sağlık verisi erişimi de istemez. İzni dilediğiniz zaman Health Connect uygulamasından geri alabilirsiniz; Qfit'in geri kalanı bu izin olmadan da çalışmaya devam eder.
Telefon adım sensörü (yedek). Health Connect bağlı ya da kurulu değilse Qfit, günün adım sayısını telefonun kendi adım sensöründen okuyabilir (Android “Fiziksel aktivite” izni, iOS “Hareket ve Fitness”). İzin bir kez istenir; reddederseniz tekrar sorulmaz ve Qfit adım göstermez. Sensör okumaları cihazınızda kalır: sunucularımıza gönderilmez, bulut yedeğe girmez, Health Connect'e yazılmaz ve reklam için kullanılmaz. Android'de sensör yalnızca uygulama açıkken sayar; kaynak uygulamada “Adımlar (telefon sensörü)” olarak belirtilir.
Ücretsiz sürüm Google AdMob ile reklam gösterir. AdMob, reklam sunmak ve ölçmek için cihaz reklam kimliğini ve uygulama etkileşim verisini toplayabilir. AB/Birleşik Krallık'ta kişiselleştirilmiş reklam öncesi onay (Google UMP) isteriz.
Qfit'in hangi bölümlerinin kullanıldığını ve uygulamanın insanları nerede kaybettiğini görmek için uygulama cihazında dört olayı sayar: açılış, ekran görüntüleme, öğün kaydı ve reklam gösterimi. Günde bir kez tek bir toplu özet gönderilir: o günün açılış sayısı, en çok görüntülenen beş ekran, kaydedilen öğün sayısı ve gösterilen reklam sayısı; yanında uygulama sürümü, platform ve uygulama dili.
İçermeyenler: ad, e-posta, hesap kimliği, reklam kimliği, cihaz kimliği veya IP tabanlı konum eklenmez; yemek, kilo, sağlık, döngü veya Health Connect verisi yoktur; tek tek işlemlerin zaman damgası yoktur. Güne özel rastgele bir parti numarası yalnızca tekrarlanan gönderimleri ayıklamak için kullanılır; seni ya da cihazını tanımlayamaz.
Nereye gider: kendi Cloudflare Workers ucumuza. Üçüncü taraf analitik SDK'sı kullanmıyoruz (Google Analytics yok, Firebase Analytics yok).
Nasıl kapatılır: Profil → “Kullanım istatistiği gönder”. Varsayılan olarak açıktır; uygulama ilk açılışta bunu bir kez bildirir ve kapattığında henüz gönderilmemiş sayılar da silinir.
Verilerinizi satmıyoruz. Health Connect verilerinizi (adım, aktif kalori, egzersiz) hiç kimseyle paylaşmıyoruz. Sağlık verilerini reklam ya da profilleme amacıyla kullanmıyoruz. Üçüncü taraf analitik SDK'sı kullanmıyoruz (Google Analytics yok, Firebase Analytics yok); tek kullanım ölçümü, "Kullanım istatistiği" bölümünde anlatılan, kendi sunucumuza giden anonim günlük toplam sayımdır ve kapatılabilir. Yukarıda anlatılan, cihazda kalan isteğe bağlı telefon adım sensörü okuması dışında cihaz sensörlerinden sağlık verisi okumuyoruz ve Health Connect'e veri yazmıyoruz. Yukarıda anlatılan isteğe bağlı AI özelliği, çevrimiçi besin araması ve isteğe bağlı bulut yedek dışında kayıtlarınız cihazınızdan çıkmaz.
Hesabını uygulama içinden silebilirsin: Profil ekranındaki Hesap kartı. Bu işlem hesap kimliğini siler ve cihazda tutulan verileri temizler. Yerel verini dilediğin zaman uygulama verisini temizleyerek veya uygulamayı kaldırarak da silebilirsin. Bulut yedek varsa hesapla birlikte o da silinir.
E-posta ile silme talebi dâhil ayrıntılı yönerge: quantkod.com/qfit-account-deletion.html ya da gcbtur@gmail.com. Çıkış yapmak silme değildir; yalnızca oturumu kapatır.
Qfit 13 yaş altı çocuklara yönelik değildir.
Qfit tıbbi tavsiye değildir; kalori ve besin değerleri tahminîdir. Sağlık kararların için bir uzmana danış.