Privacy Policy
In brief
- You can reach us any time at support@fitzzapp.com.
- We collect what you type in (account, body measurements, training profile) and what you do (workouts, sets, records), plus the device details needed for reminders.
- Body and training data can reveal your physical condition, so we treat it as health data and process it only with your explicit consent.
- Everything is stored in the United States on Supabase. Analytics is off until you turn it on. We show no ads, use no advertising identifiers and never sell your data.
- Payments go through Apple and Google. Card details never reach Fitzz.
- You can delete your account in the app at any time. One record of the deletion is kept, and this policy says exactly what it contains.
1. Who we are
Fitzz is a fitness app for iOS and Android, and the website fitzzapp.com ("Fitzz", "we", "us"). For the purposes of the EU and UK General Data Protection Regulations ("GDPR"), Fitzz is the data controller of the personal data described here.
support@fitzzapp.com
Write to this address for anything in this policy. It is printed as text on purpose: this page also opens inside the app, where tapping an email link does nothing.
↑ Contents2. What this policy covers
This policy covers the Fitzz mobile app for iOS and Android and the website fitzzapp.com, including the pages the app opens for email confirmation and password reset.
It does not cover Apple's or Google's own processing when you buy a subscription or sign in with them, RevenueCat's processing of your purchases, or any third-party site you reach from Fitzz. Their own privacy policies apply to that.
↑ Contents3. What we collect
The table lists every category we hold, where it comes from, and what it contains. We do not collect anything that is not on this list. In particular, Fitzz does not read data from Apple Health, Google Fit or any other health service, does not access your contacts, photos or location, and does not use advertising identifiers.
| Category | Source | What it contains |
|---|---|---|
| Account and identity | You, or Apple / Google when you sign in with them | Email address, username, first and last name, date of birth, gender, whether your email is confirmed. With Sign in with Apple or Google Sign-In we receive the name and email address (and, from Google, a profile picture link) that the provider shares; Apple may give us a private relay address instead of your real one. |
| Body measurements | You | Weight, height and your preferred units (kg or lb, cm or ft). |
| Training profile | You | Experience level, training history, primary and secondary goals, training days per week, session length, where you train, the equipment you have, body areas to avoid, muscles you want to emphasise or focus on, and birth year. |
| Workouts and performance | Created as you use the app | Your workouts and custom workouts, the exercises in them, sets, reps and weights, duration, estimated calories, the muscles trained and when, personal records, exercise preferences, your position in a program, and the per-muscle fatigue and recovery estimates the app derives from your training. |
| Device, reminders and language | Collected automatically | A push-notification token and platform, whether you allowed notifications, your time zone and UTC offset, the app language, and for each notification we send: its title, body, scheduling, delivery status and whether you read it. |
| Subscription | RevenueCat, Apple and Google | A RevenueCat app user ID, whether you hold the Premium entitlement, the product, the expiry date, whether it will renew and the last billing event type. No card numbers, billing addresses or bank details: Apple and Google keep those. |
| Support and feedback | You | The category and text of feedback you send from the app, and any email you write to us. |
| Privacy choices | You | Whether you allowed product analytics, whether crash reporting is on, and when you last changed either. |
| Product analytics | Collected automatically, only if you opt in | Which screens and features are used, device model, operating system version, app version and coarse region, keyed to a random app-instance identifier. Never your workouts or personal details. |
| Crash reports | Collected automatically, on by default, can be turned off | Stack traces, the device model and OS version, and the app's state at the moment of a crash. |
| Website visits | Collected automatically by Cloudflare | fitzzapp.com is a static site with no cookies and no analytics of our own. Cloudflare, which serves it, processes IP addresses and request logs to deliver and protect the site. The confirmation and password-reset pages receive a one-time code in their web address; the page uses it only to open the app on your device and does not send it anywhere or store it. |
4. Health and fitness data
Your weight, height, training profile, workouts and the recovery estimates derived from them say something about your physical condition. We therefore treat them as health-related data, a special category under Article 9 of the GDPR, and we process them only on the basis of your explicit consent (GDPR Article 9(2)(a)).
You give that consent when you enter these details in the app, and you can withdraw it at any time by editing or removing the data in Profile › Account, or by deleting your account (section 13). Withdrawing consent means Fitzz can no longer build workouts around your body and training history, because that is what the data is for.
We use health-related data for one purpose only: to run the service for you, that is, to build and log workouts and show you your training and recovery. We do not use it for advertising, do not sell it, do not use it to make decisions with legal or similarly significant effects about you, and share it only with the processors listed in section 9 under contracts that bind them to process it on our instructions.
↑ Contents5. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Running your account and the app: signing you in, building and logging workouts, showing your history, records and recovery, syncing across your devices, sending confirmation and password-reset emails | Account, training profile, workouts, device | Performance of our contract with you (GDPR Art. 6(1)(b))(c)). For health-related data, your explicit consent (section 4). |
| Workout reminders and messages about your account or subscription | Push token, time zone, notification settings | Your consent, given when you allow notifications; withdraw it at any time (section 7). |
| Selling and honouring Premium subscriptions and the free trial | Subscription | Performance of our contract with you. |
| Product analytics | Analytics | Your consent, off until you give it (section 6). |
| Fixing crashes and keeping the app working | Crash reports | Our legitimate interest in a working product (GDPR Art. 6(1)(f))(f)), balanced by the fact that reports contain no workouts or personal details and can be switched off. |
| Answering support requests and feedback | Support and feedback, account | Performance of our contract; our legitimate interest in improving Fitzz. |
| Preventing abuse, for example repeated free trials from deleted and re-created accounts, and keeping a record of deletion requests | The deletion log (section 11) | Our legitimate interest in preventing abuse and demonstrating that we honoured your request; legal obligations where they apply. |
| Complying with the law, responding to lawful requests, protecting our rights | Whatever the request lawfully requires | Legal obligation (GDPR Art. 6(1)(c))(a)). |
Fitzz does not use your data for marketing to third parties, profiling for advertising, or any purpose not listed above.
↑ Contents6. Analytics and crash reporting
Product analytics is off until you turn it on. When you first use Fitzz we ask, on a dedicated screen, whether you want to share anonymous usage of screens and features so we can see what needs fixing. If you say no, or say nothing, nothing is sent. You can change your answer at any time in Profile › Settings › Privacy; the change applies immediately.
Crash reporting is on by default so that we learn about crashes and can repair them. Reports contain diagnostics about the crash, never your workouts or personal details. You can switch it off in the same Privacy screen.
Both services are provided by Google (Firebase Analytics and Firebase Crashlytics). We do not use advertising identifiers with them: the Android advertising-ID permission is removed from the app, and on iOS the app never asks for tracking permission, so no tracking identifier is available to it.
↑ Contents7. Push notifications
If you allow notifications, Fitzz can send you a reminder on your training days, at most once a day, and occasionally a message about your account or your subscription, for example if a subscription lapses. To send them we store a push token for your device (issued by Apple or Google), your time zone so the reminder arrives at a sensible hour, and a record of each notification and whether you opened it.
You can stop notifications at any time in your device's Settings under Notifications › Fitzz, or in the app under Profile › Settings. Delivery uses Firebase Cloud Messaging (Google) and, on iOS, Apple Push Notification service.
↑ Contents8. Subscriptions and payments
Fitzz Premium is sold through the Apple App Store and Google Play. Your payment details never reach Fitzz. Apple or Google takes the payment and tells RevenueCat, our subscription service, whether your subscription is active, when it renews or expires and which product you bought. RevenueCat passes that status to us so the app can unlock Premium. That is the whole of what we hold about your purchases.
Refunds, receipts and payment problems are handled by Apple or Google under their terms.
↑ Contents9. Who we share data with
We share personal data only with the service providers below, who process it on our behalf and under our instructions, and only as far as each one needs to do its job. We do not sell personal data and do not share it for cross-context behavioural advertising.
| Provider | What it does for Fitzz | Where |
|---|---|---|
| Supabase | Database and sign-in (authentication). Holds every category in section 3 except analytics, crash reports and website logs. | United States (AWS, N. Virginia) |
| Google Firebase | Push-notification delivery; product analytics if you opted in; crash reports unless you opted out. | United States |
| RevenueCat | Subscription status from Apple and Google. | United States |
| Apple | Sign in with Apple; App Store payments and push delivery on iOS. | Per Apple's policy |
| Google Sign-In; Google Play payments. | Per Google's policy | |
| Resend | Sends our transactional emails: email confirmation and password reset. | United States |
| Cloudflare | Hosts fitzzapp.com and routes email sent to our domain. | Global network; United States |
We may also disclose data when the law requires it, to respond to a lawful request from a public authority, to protect the rights, safety or property of Fitzz or its users, or, if Fitzz is ever transferred to a new operator, to that operator under this policy.
↑ Contents10. Where your data is stored; international transfers
Fitzz's database runs on Supabase in the United States (Amazon Web Services, N. Virginia). Firebase, RevenueCat and Resend also process data in the United States. This means your personal data is stored and processed outside the European Economic Area and the United Kingdom.
If you are in the EEA or the UK, these transfers rely on the safeguards in Chapter V of the GDPR. Each of our providers (Supabase, Google Firebase, RevenueCat, Resend and Cloudflare) has a data processing agreement that forms part of its terms of service and incorporates the European Commission's Standard Contractual Clauses together with the UK Addendum. Google, Resend and Cloudflare are additionally certified under the EU–US Data Privacy Framework and its UK extension.
You can ask us for a copy of the safeguards that apply to a given provider using the contact details in section 17.
↑ Contents11. How long we keep it
We keep your data for as long as your account exists. When you delete your account (section 13), the following are deleted immediately and permanently from our database: your profile and sign-in identity, training profile, body measurements, workouts, sets, records, recovery data, custom workouts, exercise preferences, notification records, subscription status, feedback and privacy choices.
What we keep after deletion. We keep one entry in a deletion log: your user ID, your email address, the date and time of the deletion, and the reason you chose. We keep it to prevent abuse of the free trial through deleted and re-created accounts, to resolve disputes about a deletion, and as a record that your request was carried out. It is kept for 24 months after the deletion and then deleted.
Other retention periods:
- Backups. Our database is backed up on a short rolling window that expires automatically; deleted data disappears from backups when the window passes.
- Crash reports are kept by Google for 90 days. Analytics event data is kept for the period configured in our Firebase project, at most 14 months.
- Transactional email delivery records are kept by Resend for a short period for deliverability and abuse prevention, then deleted.
- Purchase records are kept by Apple, Google and RevenueCat under their own policies; we cannot delete a store's transaction history.
- Support emails are kept for as long as needed to resolve the request and for up to two years afterwards.
12. Your rights
Wherever you live, you can ask us to tell you what personal data we hold about you, to correct it, to delete it, to give you a copy, or to stop using it in a particular way. The details depend on the law that applies to you.
If you are in the EEA or the UK (GDPR Articles 15–22)
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, the right to withdraw consent at any time without affecting processing that already happened, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Fitzz's workout suggestions are automated but have no such effects, and you are always free to change or ignore them.
If you are in California (CCPA/CPRA) or another US state with a privacy law
You have the right to know what personal information we collect and how we use and share it, to delete it, to correct it, and to opt out of its sale or sharing. Fitzz does not sell or share personal information as those laws define it, and we will not treat you differently for exercising a right.
How to exercise them
Most of this you can do yourself in the app: edit your details in Profile › Account, change privacy switches in Profile › Settings › Privacy, and delete your account as described in section 13. For anything else, email support@fitzzapp.com from the address on your account. We may ask you to confirm your identity. We answer within 30 days (GDPR Article 12, which allows a two-month extension for complex requests that we would tell you about). Requests are free unless they are manifestly unfounded or excessive.
↑ Contents13. Deleting your account
You can delete your account yourself, at any time, with immediate effect:
- In the app, open Profile › Account and choose Delete account.
- Tell us why, if you like, and confirm. Deletion is permanent and cannot be undone.
If you no longer have the app, the same instructions and an email route are on our website at fitzzapp.com/DeleteAccount, or you can email support@fitzzapp.com from the address on your account and we will delete it for you.
Deleting your account does not cancel a subscription. Subscriptions are billed by Apple or Google and must be cancelled in your App Store or Google Play account settings, ideally before you delete the account. Fitzz cannot cancel a store subscription for you.
What is deleted and what is kept is described in section 11.
↑ Contents14. Children
Fitzz is for people aged 13 or over. If you are under 18, a parent or guardian must agree to you using Fitzz, and where the law of your country sets a higher age for consenting to the processing of your own data (up to 16 in parts of the EEA), that parent or guardian must give the consents described in this policy on your behalf. We do not knowingly collect personal data from anyone younger, and if we learn that we have, we delete the account. The age rating shown in the app stores describes the app's content, not who the service is intended for. If you believe a child has created an account, contact us and we will remove it.
↑ Contents15. Security
Your data is encrypted in transit (TLS) and at rest. Database access is governed by row-level security rules so that an account can read and write only its own rows. Passwords are stored only as salted hashes by our sign-in provider; if you sign in with Apple or Google we never see a password at all. Administrative access is limited to the operator. No system is perfectly secure; if you believe your account has been compromised, contact us at once and change your password in the app.
↑ Contents16. Changes to this policy
When we change this policy we publish the new version here with a new "Last updated" date. If a change materially affects how we use your data, we tell you in the app or by email before it takes effect. Earlier versions are available on request.
↑ Contents17. Contact and complaints
support@fitzzapp.com
If you are unhappy with how we handled your data or your request, you have the right to complain to a supervisory authority:
- EEA: the data protection authority of the country where you live or work.
- United Kingdom: the Information Commissioner's Office (ICO), ico.org.uk.
We would appreciate the chance to resolve the matter directly first.
↑ Contents