Privacy Policy
1. Who we are
FitnessData ("we", "us", "our") is a SaaS platform for personal trainers and their clients, owned and operated by Chichi Denis William (sole proprietorship), registered in Italy, VAT no. IT03544140985, registered office: Via Amatore Sciesa, 20021 Bollate (MI), Italy.
Contact: [email protected]
Data Protection Officer (DPO): not appointed — a DPO is not mandatory at the current scale; one will be designated if processing of health data reaches the scale that requires it under Art. 37 GDPR.
2. What data we collect
- Personal Trainers (account owners): name, email, phone, billing info via our payment provider (Polar).
- Clients (end users): name, age, contact, body measurements, workout history, photos/videos, medical/anamnesis data (Article 9 GDPR — "special categories").
- Technical: IP, device, browser, session logs (audit, security).
3. Legal basis
- Contract (Art. 6.1.b GDPR) for trainer account.
- Explicit consent (Art. 9.2.a GDPR) for client health data — collected at first portal access via mandatory consent popup.
- Legitimate interest for security logs, fraud prevention.
4. How we use it
To provide the service: coaching, scheduling, payment tracking. No selling, no advertising. Polar processes payments under its own privacy policy.
5. Sharing & sub-processors
- Supabase (EU region, Frankfurt) — database hosting.
- Cloudflare — CDN, edge worker, file storage (R2).
- Polar — payment processing (merchant of record).
- Anthropic / Google — AI for workout parsing (anonymized text only).
- In-app purchases on iOS: if you consent in Settings, when a refund is requested we send Apple (Apple Distribution International Ltd, Ireland / Apple Inc., USA — Standard Contractual Clauses) your account identifier, how much the purchase was used, the account status, the platform and our preference on the refund. Legal basis: consent, revocable with one tap.
- Google Calendar (optional): if you connect your calendar from Settings, we read and write only the events of your appointments with clients, through the Google Calendar API. Your Google data stays on Google's servers; we store only the access tokens Google issues, which you can revoke at any time from Settings or at myaccount.google.com/permissions. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Scope requested: https://www.googleapis.com/auth/calendar. We never share Google Calendar data with third parties, never sell it and never use it for advertising or to train models; the tokens are deleted as soon as you disconnect the calendar from Settings.
All sub-processors are bound by DPA (Data Processing Agreements).
6. Data retention
- Active accounts: for the duration of the subscription.
- On account closure you choose: (a) deactivate & keep — data retained up to 12 months so you can return, then automatic permanent deletion; or (b) delete everything now — immediate, irreversible deletion.
- Backups: purged on a rolling basis (within 30 days).
- Anonymized phone hash: 12 months (anti-fraud).
- Audit logs: 6 months.
7. Your rights (GDPR Articles 15-22)
- Access: request a copy of your data (response within 30 days).
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): delete your account from app settings or write us.
- Portability: export your data in JSON format.
- Object/Restrict: limit certain processing activities.
- Withdraw consent: at any time (does not affect prior lawful processing).
- Complaint: lodge with your supervisory authority (e.g. Garante Privacy IT, CNIL FR, ICO UK).
8. International transfers
The primary database (Supabase) and media storage are hosted in the EU. Some sub-processors are based in the United States — Polar (payments) and Anthropic / Google (AI workout parsing, Google Calendar). Transfers to these US providers are covered by Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework.
9. Security
TLS 1.3 in transit, AES-256 at rest, RLS (Row Level Security) on database, biometric authentication on mobile, encrypted local storage. Regular security audits.
10. Children
The digital-consent age is 14 in Italy (16 in some EU countries, 13 in the US under COPPA). Clients below the applicable threshold (under 14 in Italy) require a parent's or guardian's consent, obtained by the trainer before their data is entered.
11. Google user data (Google Calendar)
This section applies only if you choose to connect Google Calendar from the app's Settings. The connection is optional: the app works fully without it, and you can end it at any time.
- Data we access: the list of your calendars (only to find or create the dedicated calendar named "FitnessData") and the events of that dedicated calendar: title, date, time, duration and notes of the appointments the app has created there. We do not access events in your other calendars and we do not read your contacts, e-mails or any other Google data.
- How we use it: to copy the appointments you schedule in the app to your Google Calendar, to keep them updated when you move, rename or cancel them in the app, and to show in the app the changes you make to those appointments in Google Calendar. There is no other purpose.
- What we store: only the access and refresh tokens issued by Google, encrypted at rest on our server (Cloudflare Workers KV). We do not keep a copy of your Google Calendar events on our servers: the appointments live in your FitnessData account and in your Google Calendar.
- Sharing: Google Calendar data is never shared with, sold or transferred to third parties, is never used for advertising, profiling or to train artificial-intelligence models, and is not read by people, except with your explicit permission for support, or where required by law or for security.
- Retention and deletion: the tokens are deleted immediately when you disconnect Google Calendar from Settings, when you delete your account, or when Google revokes them. You can also revoke our access at any time at myaccount.google.com/permissions. The "FitnessData" calendar and its events remain in your Google account, under your control: you can delete them from Google Calendar whenever you wish.
- Permission requested (OAuth scope): https://www.googleapis.com/auth/calendar — needed to create the dedicated "FitnessData" calendar and to manage the events in it.
FitnessData's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Changes
We'll notify you of material changes via email + in-app notice. Continuing use after notice = acceptance.