Last updated: October 1, 2026
When you create an account, we store your email address, display name, and preferred weight unit (kg/lbs). All workout data — templates, sessions, exercise history, cardio logs, nutrition logs, mindfulness sessions, and program enrollments — is user-generated content that you create and control.
Social features (optional): If you enable a public profile, your display name and completed workout session summaries (duration, volume, exercise list) become visible to users who follow you in the app. We store follow relationships and emoji reactions on sessions. You can disable your public profile at any time via Profile → Public Profile toggle, which immediately removes your sessions from other users’ feeds. You can delete individual reactions and unfollow users at any time.
Workout DNA (optional): When you share a workout template via QR code, a public snapshot of that workout (name and exercise list, no personal data) is stored and accessible to anyone with the link or QR code. You can see your shared DNA codes via the workout edit page. Shared DNA does not include your name or any health data.
If you enable push notifications, we store a push notification subscription token (a device identifier issued by your browser or operating system) in your account. This token is used only to deliver the notifications you have enabled. You can disable push notifications and remove your token at any time via Profile → Notifications, or through your browser or device notification settings.
Research setting (website): the account settings page on our website (/account/settings) shows a setting labelled ‘Use my anonymised training data to improve AI programming’. It is switched on by default and you can switch it off on that page. We store your choice, and the time it was last changed, in your account. At the date of this policy no other part of our code reads this setting. The separate option to keep your training data when you delete your account is described under Data Retention.
Guest mode (Ghost Protocol) stores the records you create locally on your device rather than in an account on our servers. Guest mode does not switch off analytics. On our website, page views are still sent to PostHog while you are in guest mode, under a single guest identifier that is shared by guests on the website and with a placeholder address (ghost@fittssy.local) in place of an email address. In the mobile apps, usage events such as the app-opened event are still sent to PostHog in guest mode, without an account ID. See Analytics & Error Monitoring.
Fittssy optionally integrates with Google Health Connect (Android only) to import health and fitness data from your wearable devices (such as Garmin, Samsung, Fitbit, Pixel Watch, and others that sync to Health Connect). This integration is entirely optional and requires your explicit consent before any data is read.
Health data we may receive via Health Connect: exercise sessions (workout type, duration, calories, distance), sleep sessions (duration and stages), steps, total calories burned, resting heart rate, heart rate samples, distance, weight and body fat percentage. We request READ permissions only — Fittssy does not write to Health Connect. The records the app imports are stored in your personal Fittssy account and are protected by Row Level Security, so other users cannot read them. Weight and body fat percentage are an exception: the app asks for read access to both and reads them, but at the date of this policy our database does not accept imported records of these two types, so those readings are not saved to your account. Sleep data is sent to Anthropic when the scheduled weekly insight or monthly report described under AI-Generated Content below runs for your account.
Fittssy optionally integrates with Apple Health (iOS only) to import health and fitness data. This integration is entirely optional and requires your explicit consent, granted through the standard iOS permission prompt, before any data is read.
Health data we may receive via Apple Health: step count, walking/running distance, active energy burned (calories), heart rate, resting heart rate, body mass (weight), body fat percentage, sleep, mindful sessions and workouts. We request READ permissions only — Fittssy does not write to or modify your Apple Health data. The records the app imports are stored in your personal Fittssy account and are protected by Row Level Security, so other users cannot read them. Body mass (weight) and body fat percentage are an exception: the app asks for read access to both and reads them, but at the date of this policy our database does not accept imported records of these two types, so those readings are not saved to your account. Sleep data is sent to Anthropic when the scheduled weekly insight or monthly report described under AI-Generated Content below runs for your account.
You may also manually import fitness data by selecting .gpx (GPS Exchange Format) files in the mobile app. These files are parsed on your device and the extracted activity records are stored in your account. The files themselves are not sent to our servers.
Health Connect permissions can be revoked at any time via Android Settings → Health Connect → App permissions → Fittssy. Apple Health permissions can be revoked at any time via iOS Settings → Privacy & Security → Health → Fittssy. You can delete the wearable records imported into Fittssy at any time via Profile → Wearables → Delete Wearable Data. This deletes the imported records themselves. Sessions you chose to save from those records (workout, cardio, interval or mindfulness sessions) are not deleted with them: they keep the start time and duration taken from the wearable record and, depending on the kind of session, the end time, the calories or the activity type, and they stay in your training history until you delete those sessions or your account.
We do not use your health or wearable data for advertising. Wearable data is sent to our AI provider, Anthropic, when the scheduled weekly insight or monthly report described under AI-Generated Content below runs for your account: those requests include your sleep records for the period (the start date and time of each record and the hours slept, plus the hours of deep sleep in the monthly report). They also include your workout sessions for the period, and a workout session you saved from a wearable record is sent like any other, with the start time and duration that came from the wearable. The on-demand weekly summary treats such a session the same way when it is among the sessions it sends. Health-related details that you type yourself into an AI feature, such as an injury or a limitation, are sent to Anthropic as described in that section.
Fittssy has AI-powered features that use Anthropic’s Claude models through the Claude API. When one of these features runs, our servers send the data listed below to Anthropic so that it can generate the result. The list is grouped by feature and describes what our code places in each request.
AI program and protocol generators: when you generate a program or a single workout, we send the options you choose in the generation form — your goals or muscle-group focus, split style, training style, days per week, experience level, session length and program length — together with the identifiers of any favourite exercises you pick and anything you type into the free-text fields (your description of what you want, and the exercises or muscle groups you want to avoid). The equipment you select decides which exercises from our exercise library are listed in the request. If the model’s reply cannot be read as valid data, our servers write up to the first 500 characters of that reply to our hosting provider’s server logs for troubleshooting; that log entry does not include your account ID. The error raised in that case is also sent to our error-monitoring provider, Sentry, as is the error raised when the request our servers receive cannot be read as valid data, and the message of either error can quote a short fragment of the reply or of the request. When a generation fails for another reason, our servers write a troubleshooting entry to those server logs: a description of what was wrong with a program request, or with a model reply that did not have the expected structure; the error returned when the exercise library could not be loaded or the generated result could not be saved (for a program, together with the name the model gave the workout that could not be saved); or the unexpected error itself, which is also sent to Sentry. Our code does not add your account ID to these entries.
Program Genesis: when you generate or regenerate a starter programme, we send the answers saved in your brief — your primary and secondary outcome (the goal you pick, such as getting stronger or rebuilding after an injury), training experience, days per week, session length and available equipment — and the limitations you entered, including any injury or health detail you typed. A regeneration request also includes the programme previously generated for you. Your brief is stored in your account and can hold more than is sent: if you fill in the optional advanced fields, it also stores your height, weight, body fat percentage, average hours of sleep, estimated one-rep maximums for the squat, bench press and deadlift, how you track nutrition and the supplements you list. Our code does not include these advanced fields in the request to Anthropic. If the model’s output is still not usable after the automatic retries, our servers store the technical error message (up to 500 characters) together with your account ID, the ID of your brief and the number of attempts in our database for debugging.
Voice logging: what you say is converted to text by the speech-recognition service on your device before anything reaches us. On iOS we request on-device recognition; on Android the speech service configured on your device is used, and that service may process audio outside your device. Our servers receive the text transcript, not the audio, and send that transcript (up to 2,000 characters) to Anthropic to turn it into exercises, sets and cardio entries. For troubleshooting, our servers also write your account ID and the length of the transcript to our hosting provider’s server logs before the request is made, and afterwards whether the model’s reply could be read, the number of exercises and cardio entries in it and the length of its notes (or, if the reply could not be read, the length of the reply). These entries record lengths and counts, not the text of the transcript or of the reply. If the request body our servers receive cannot be read as valid data, an entry containing your account ID and none of the content is written to those logs. If the request to Anthropic fails, the error reported by Anthropic’s software library is also written to those logs with your account ID, and the same error is sent to our error-monitoring provider, Sentry. For the other voice-logging failures, the error sent to Sentry carries the type of the error rather than its original message. These log entries are held in the hosting provider’s logs rather than in our database: we do not set a separate retention period for them, and deleting your account or your data does not remove them (see Data Retention).
On-demand training insights: these send the figures the insight is built from. Weekly summary, when you ask for it: for each of your most recent completed workout sessions (up to 20) its start date and time, volume, number of exercises, duration and RPE, plus your streak and a total volume figure. Plateau breaker, volume advisor and nutrition insight, when one of them runs: the plateau breaker sends the exercise name and a history for that exercise (date, weight, reps and estimated one-rep max for each entry); the volume advisor sends your weekly sets per muscle group with a low, optimal or over rating, and your training goal if one is provided; the nutrition insight sends your average daily protein, carbohydrate, fat and calorie figures, your training days per week, your body weight if one is provided and your goal if one is provided. If an insight request fails with an error on our servers, that error is written to our hosting provider’s server logs and sent to our error-monitoring provider, Sentry; when the cause is a request or a model reply that could not be read as valid data, the error message can quote a short fragment of it. Our code does not add your account ID to that entry.
Scheduled weekly insight and monthly report: these are built to run automatically, without you starting them and without a separate opt-in step. Each run selects the accounts it covers by subscription status, so it covers only NETRUNNER and LEGEND accounts (accounts on a trial are not selected), and by whether AI features are enabled for the account. The weekly insight also skips an account that has already reached its monthly limit of six AI insights, unless the account is marked as unlimited. A run may select no accounts. When one runs for your account and at least one workout session was recorded in the period, it sends the following. The weekly insight sends your workout sessions that started in the past seven days (start date and time, volume, RPE and duration), the session count, total volume and average RPE, and your sleep records for those days (start date and time, and hours slept) where your account holds sleep data imported from Health Connect or Apple Health. The monthly report sends the previous month’s workout sessions (start date and time, volume, RPE, duration and status), the session count and total volume for that month and the month before it, your sleep records for the month (start date and time, hours slept and hours of deep sleep), and the weekly insights and the previous monthly report already generated for you. Neither of them filters these sessions by where they came from, so a workout session you saved from a wearable record is sent like any other; its start time and duration came from the wearable.
Bug reports and feedback: when our staff review reports with AI assistance, the request sent to Anthropic contains the text of your report, its internal ID and category, the screen or route it was sent from, the app version, the date and the email address of the account that submitted it, and, depending on the review action, browser or device details (user agent) or the status, priority and internal notes we have added. Reports submitted without an account are marked as anonymous. If the model’s reply to such a review cannot be read as valid data, the error raised is sent to our error-monitoring provider, Sentry, and its message can quote a short fragment of that reply.
Newsletter: drafts of our monthly newsletter are composed with the same provider from aggregate counts taken across accounts, such as the number of accounts and the number of completed sessions in the last 30 days.
Except for the bug-report review, these requests are built from the items listed above and we do not add your name, email address or account ID to them. Anything you type into a free-text field or dictate is sent in your own words (a long entry may be cut to a length limit), so please leave out anything you do not want processed by Anthropic.
Provider and location: these requests go to Anthropic, which may process the data in the United States (see International Data Transfers below). Anthropic provides its API under its Commercial Terms of Service (https://www.anthropic.com/legal/commercial-terms). Those terms state that ‘Anthropic may not train models on Customer Content from Services’ and that data submitted through the services is processed in accordance with Anthropic’s Data Processing Addendum (https://www.anthropic.com/legal/data-processing-addendum).
Retention by Anthropic: Anthropic’s published documentation for API customers (https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) says that it automatically deletes inputs and outputs on its backend within 30 days of receipt or generation, with the exceptions listed on that page — for example where it keeps data for longer to enforce its Usage Policy or to comply with the law. This is Anthropic’s description of its own practice rather than a commitment made by Fittssy, and it may change; the linked page is the authoritative version.
AI-generated content is clearly labelled in the app with an ‘AI’ badge. You may edit or delete AI-generated workouts and programs at any time, just like any other user-created content.
When you subscribe to NETRUNNER, purchase the LEGEND lifetime edition, buy a one-time digital product (such as a DARKFIELD monograph), or make a support donation, we record the transaction to deliver the product, honour any guarantees, and meet our accounting obligations. What we store depends on the kind of purchase. For a one-time digital product: the Stripe Checkout session ID and, where Stripe reports one, the PaymentIntent ID; the product identifier (SKU) and product name; the amount, currency and purchase time; the billing email; your account ID where the checkout was started from a signed-in account; and the storage path of the delivered file. A product delivered to you as part of a bundle gets a record of its own, which holds a reference built from the Checkout session ID and no PaymentIntent ID. For LEGEND: the Checkout session ID and, where Stripe reports one, the PaymentIntent ID; the amount, currency and purchase time; the billing email; your account ID where the checkout was started from a signed-in account; and your Operator number and an access code. A LEGEND record has no SKU field. For a support donation: the Checkout session ID, the amount, currency and time, the message you added, if any, and your account ID if you donated while signed in. A support-donation record holds no PaymentIntent ID, no SKU and no email address. A NETRUNNER subscription is recorded on your account rather than as a purchase record: we store the Stripe customer ID, the Stripe subscription ID, the subscription status and the date the current billing period ends.
We never see or store your card number, CVC, or expiry — those are collected directly by Stripe, who is PCI DSS Level 1 certified. After a successful payment, what appears in our database is the set of Stripe identifiers and payment details listed in the paragraph above for that kind of purchase.
Purchase records live in three tables: `purchases` (one-time digital products), `legend_purchases` (the LEGEND one-time edition including your issued Operator number), and `support_payments` (voluntary donations). A digital-product record holds the billing email given at checkout and, where the checkout was started from a signed-in account, that account’s ID, so you can re-download delivered products via /account/purchases (which lists the records linked to your account) or /lost-download (which looks records up by that email address). A LEGEND record holds the billing email and, where the checkout was started from a signed-in account, that account’s ID. A support-donation record is linked to your account if you donated while signed in; it holds no email address, so a donation made without signing in is not linked to an account or an email address in our database. Per the Data Retention section, these rows are retained for seven years after purchase.
Fittssy uses IndexedDB (browser local storage) to enable offline functionality and guest mode. This data never leaves your device unless you explicitly create an account and sync.
Data stored locally includes: exercises, workout templates, session logs, and app preferences. A Service Worker caches the app shell for offline access.
Fittssy does not use Facebook Pixel, ad networks, or advertising-based tracking. We do not sell your data and we do not share it for advertising. We do send data to the service providers listed under Third-Party Services, including our AI provider Anthropic, for the purposes described in this policy.
Google Analytics 4 (Google LLC): Where a Google Analytics measurement ID is configured for our website (fittssy.com), we use Google Analytics 4 in cookieless mode to understand how the website is used. The Google tag is loaded by the layout that the pages of fittssy.com share, so it is not limited to the landing page: it also loads on pages you open while signed in. The section-view (scroll), time-on-page and button-click events are sent from the landing page. No cookies are set — GA4 operates in memory only (client_storage: 'none'). No personal data is stored or transmitted to Google. Only anonymous usage statistics are collected (pages visited, scroll depth, button clicks). Our Android app is completely excluded from GA4 tracking. See Google’s Privacy Policy at https://policies.google.com/privacy.
PostHog (EU Cloud, Frankfurt, Germany) on fittssy.com and the iOS + Android mobile apps: We capture product usage events such as account registration, workout completion, feature usage, paywall interactions, and subscription state changes, and on the website the pages you open (the path and query string of each page). These events are not anonymised. While you are signed in they are linked to your account ID to understand how the app is used and improve the experience. On the website, your account’s email address is also sent to PostHog and attached to your profile there. The mobile apps do not send your email address to PostHog: they send your account ID together with the platform (iOS or Android), a subscription tier value and a language code. PostHog does not perform cross-site tracking and no data is shared with advertisers or third parties.
Sentry (EU hosting): When an error occurs, Sentry captures the error stack trace and basic browser metadata (browser type, OS version). Performance tracing is also switched on, so data is sent to Sentry when no error has occurred as well: our configuration sets a trace sample rate of 10% on the website (in the browser and on our servers) and 20% in the mobile apps, and a sample of ordinary activity, such as page loads and requests, is sent to Sentry as performance traces. What a trace contains is decided by Sentry’s software rather than by our code. IP addresses are processed transiently for geolocation and are not stored. The errors that our server code reports are sent to Sentry as well, including the AI-feature errors described under AI-Generated Content; the message of such an error can quote a short fragment of a model reply or of a request that could not be read as valid data.
Vercel Analytics: We collect anonymous, aggregated page view data. This data contains no personal information, cannot identify individual users, and is used solely to understand overall traffic patterns. No cookies are set for analytics. The website also loads Vercel Speed Insights on its pages. Where it is active for our hosting project, it sends page-load performance measurements for the pages you open to Vercel. What those measurements contain is decided by Vercel’s software rather than by our code.
All data in transit is encrypted via HTTPS with HSTS preload. Our Content Security Policy (CSP) scores 125/100 (A+) on Mozilla Observatory. Every database table uses Row Level Security (RLS) — you can only access your own data. Authentication is handled by Supabase Auth with bcrypt password hashing.
Passwords must be at least 8 characters. We recommend using a unique password that you don’t use on other services.
Your account data and user-generated content are retained for as long as your account exists. There are two ways to delete your account, and they do not do the same thing. (1) ‘Delete Account’ in the mobile app’s Profile, and the ‘Delete account’ page on our website (/delete-account), delete your account when you confirm: the data linked to your account is permanently deleted, with the exceptions described in this section. (2) The ‘Delete permanently’ button on our website’s account settings page (/account/settings, which is the page the iOS app opens for account settings) queues the request for seven days, during which you can cancel it; a daily job then processes it. That request carries an option labelled ‘Keep my training data anonymised for research’, which is ticked by default. With the option unticked, the job deletes your account and the data linked to it, with the exceptions described in this section. With the option ticked, most of your data is kept, as the next paragraph describes.
Exception — the ‘Keep my training data anonymised’ option: if you delete your account from the account settings page and leave that option ticked, your account is closed but the records in it are not deleted. The daily job replaces the email address on your account with a placeholder, removes your display name, clears the phone number and profile details held with your sign-in record and blocks further sign-in. It does not change or delete the separate sign-in identity record that our authentication provider, Supabase, keeps for a sign-in method linked to your account (for example a Google or Apple sign-in); that record is created and maintained by Supabase rather than by our code, so this policy does not list what it holds. It also does not change or delete the other records in your account, and they stay linked to the same internal account ID: for example your workout templates and sessions, cardio, nutrition and mindfulness logs, imported wearable records (until the 180-day deletion described below), Program Genesis briefs including any injury or health detail you typed, generated insights and your preferences. The in-app description of the option says the data is kept for research and AI training. Our code sets no end date for this retention. If you want these records deleted, untick the option before you confirm, use one of the two routes in (1) above, or contact us at privacy@fittssy.com.
Exception — purchase transaction records: payments you have made (NETRUNNER subscriptions, LEGEND lifetime edition, one-time digital products, and support donations) generate transaction records that we are legally required to retain for seven (7) years after the transaction date, in accordance with UK tax law (HMRC record-keeping obligations under the VAT Act 1994 and self-assessment regulations). Depending on the kind of purchase, these records hold the Stripe Checkout session ID and PaymentIntent ID, the amount, currency and purchase date, the product identifier and product name, the billing email, the storage path of the delivered file, a download count and the time of the last download, and the refund date if the payment was refunded. A LEGEND record also holds your Operator number, an access code, the time your personalised files were requested and a metadata field. A support-donation record also holds the message you added, if you added one. The records do not hold workout data or wearable data. After seven years, the records are anonymised or deleted. This retention period applies to the purchase records specifically; other personal data linked to your account is still deleted as described above, subject to the other exceptions in this section.
Exception — records held at Stripe: deleting your account does not cancel a NETRUNNER subscription and does not delete what Stripe holds. At the date of this policy our code makes no request to Stripe when an account is deleted, by either of the two routes described above. Where a Stripe customer record was created for your account, it stays at Stripe; our servers create one, with your account’s email address and your Fittssy account ID, when you start a subscription checkout or, while signed in, a support-donation checkout. A subscription that is active when your account is deleted is not cancelled by the deletion and stays active at Stripe; our Terms of Service describe how subscriptions renew. Cancel the subscription before you delete your account, through the Stripe Customer Portal that the account page on our website opens, or contact us at privacy@fittssy.com to have a subscription cancelled or a Stripe customer record removed.
Exception — records kept without your account: some records are not deleted with your account; any link to your account is removed from them and the record itself is kept. These are bug reports and feedback you sent us while signed in, Workout DNA snapshots you shared, and the contact record created if you gave us your email address through a form on our website (for example the newsletter or a waitlist). The same applies to the referral record created if you signed up through another user’s invite link: the link to your account is removed and the record is kept. It holds the inviting user’s account ID and Operator number, the time you signed up, the platform (web, iOS or Android), your browser’s user-agent string and, if a payment of yours was attributed to that invite, the date and amount of the first such payment; the commission records created from your payments (payment amount, commission and the Stripe event ID) are kept with it. The referral record and its commission records are deleted if the inviting user deletes their account. The same also applies to the log entry created if a member of our staff sends a notification to your account alone: the entry holds the notification’s type, title, text and in-app link, the time it was created and the account ID of the staff member who sent it, and the link to your account is removed from it when your account is deleted. To have any of these removed, contact us at privacy@fittssy.com.
Exception — rate-limit counters: to limit how often some requests can be made, our servers keep counters in our database. When you use the AI program generator, the AI workout generator or voice logging, the counter is keyed by the name of the feature and your account ID, and it holds the start of the one-hour window and the number of requests made in it. Asking for a lost-download link creates a counter keyed by the email address you enter, and the email-capture forms on our website (such as the newsletter and waitlist forms) and the LEGEND and support-donation checkouts create counters keyed by IP address. These counters are not linked to your account record and our code has no job that deletes them, so deleting your account does not remove them and we do not set a retention period for them. If the counter check itself returns an error, the counter’s key is written to our hosting provider’s server logs. To have these counters removed, contact us at privacy@fittssy.com.
Imported wearable records (data imported from Health Connect, Apple Health or GPX files) are deleted automatically by a daily job once the start date of the record is more than 180 days in the past. That job does not delete sessions you chose to save from a wearable record: those stay in your training history until you delete those sessions or your account.
Exception — server log entries: the troubleshooting log entries described under AI-Generated Content are held in our hosting provider’s server logs, not in our database. They are the voice-logging entries recorded with your account ID (lengths and counts rather than the transcript text, the entry written when a request body cannot be read, and the provider’s error if the request to Anthropic fails), up to 500 characters of a program or protocol generator reply that could not be read, the other generator troubleshooting entries described there, and the error written when an insight request fails. Deleting your account does not remove them, and we do not set a separate retention period for them. Where the same error is also sent to Sentry, as described under AI-Generated Content, Sentry holds its copy for the Sentry retention period stated later in this section, and deleting your account does not remove it. The title and message of that Sentry issue can also be copied into our own database by the daily staff digest described in the next paragraph.
Exception — monitoring entries copied into our database: a daily job for our staff (the signal digest) copies monitoring entries into a table in our database. When it runs with access to Sentry, it stores, for each unresolved Sentry issue seen in the previous 24 hours (up to 50), the issue’s title, the code location and error message reported by Sentry, its event and affected-user counts, its first-seen and last-seen times and a link to the issue; as described under AI-Generated Content, such a message can quote a short fragment of a model reply or of a request. When it runs with access to the logs of our database provider, Supabase, it stores, for each error-level entry from the previous 24 hours, the message text and the entry’s timestamp, path, method and status code where present; our code does not fix what such a message contains. Separately, each bug report or feedback message is copied into the same table when it is submitted: its text, category, the screen or route, the app version, the browser or device details (user agent) and, if it was sent from an account, that account’s ID. The job then emails a digest of recent entries to our staff through Resend (see Third-Party Services). This table is not linked to your account record, so deleting your account does not remove its entries, and the copy of a bug report keeps the account ID it was sent from, unlike the bug report itself (see ‘records kept without your account’ above). A weekly job deletes an entry once it has been marked resolved for more than 90 days; our code sets no retention period for an entry that has not been marked resolved. To have entries that relate to you removed, contact us at privacy@fittssy.com.
Analytics data (PostHog) is retained for 12 months and then automatically purged. Error monitoring data (Sentry) is retained for 90 days.
Guest mode data is stored locally on your device. Exiting guest mode does not delete it: the app clears what it holds in memory and the guest-mode flag, and the stored guest records stay on the device, where they are available again if guest mode is entered again on that device. The data stays there until you clear the app’s data or uninstall the app or, on our website, clear your browser’s data for fittssy.com. If you register an account (or, in the mobile app, sign in to one) from guest mode, the app copies guest records to that account on our servers and then removes guest records from the device.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
Right of access: You may request a copy of the personal data we hold about you. Your workout data, session history, and profile information are always accessible directly within the app.
Right to rectification: You may update your personal data at any time via Profile settings.
Right to erasure: You may delete your account and the data linked to it at any time via Profile → Delete Account. Deletion is processed within 30 days. Purchase transaction records (their contents are listed in the Data Retention section) are excluded from erasure and retained for seven years under UK tax law, and the other exceptions listed in the Data Retention section apply — see that section above for the full scope of what is kept and what is deleted. One of those exceptions depends on how you delete: the ‘Delete permanently’ button on our website’s account settings page (/account/settings) carries an option, ticked by default, to keep your training data, and if you leave it ticked the records in your account are kept rather than erased. If you want them erased, untick that option, use Profile → Delete Account in the mobile app, or email privacy@fittssy.com.
Right to data portability: You may export your workout data through the app’s share and export features.
Right to object: You may object to processing of your data for analytics purposes by contacting us.
Right to withdraw consent: Where processing is based on consent (e.g., Health Connect or Apple Health integration), you may withdraw consent at any time by revoking permissions in Android or iOS Settings. Revoking permission stops new imports; sleep records already imported stay in your account until you delete them via Profile → Wearables → Delete Wearable Data or until they are deleted automatically after 180 days (see Data Retention). While they are in your account, they are sent to Anthropic whenever the scheduled weekly insight or monthly report runs for your account and covers the period they fall in. Deleting wearable data does not remove insights that were already generated from it, or sessions you chose to save from a wearable record (see Health & Wearable Data).
Our legal basis for processing your data is: (a) performance of a contract (providing the app service, including the AI features described under AI-Generated Content, which run when you use them or, for the scheduled weekly insight and monthly report, automatically as part of the service — there is no separate consent step for AI features), (b) your consent (Health Connect, Apple Health), and (c) legitimate interest (analytics, error monitoring, security, and reviewing the bug reports and feedback you send us, including with AI assistance).
To exercise any of these rights, contact us at privacy@fittssy.com.
Guest mode: ‘Exit Ghost Protocol’ in your profile ends guest mode but does not delete the guest data stored on your device (see Data Retention). To delete it, clear the app’s data or uninstall the app; on our website, clear your browser’s data for fittssy.com.
Registered accounts: In the mobile app, go to Profile → scroll to the bottom → ‘Delete Account’; on our website, use the ‘Delete account’ page (/delete-account). Either one permanently deletes your account and the data linked to it when you confirm, subject to the exceptions in the Data Retention section. The ‘Delete permanently’ button on our website’s account settings page (/account/settings) works differently: it queues the deletion for seven days, during which you can cancel it, and unless you untick ‘Keep my training data anonymised for research’ it keeps the records in your account as described in the Data Retention section. Alternatively, email privacy@fittssy.com with your account email.
Wearable data only: Profile → Wearables → Delete Wearable Data deletes the Health Connect, Apple Health, and imported GPX records held in your account, without deleting your account. Sessions you chose to save from those records are not deleted by it: they stay in your training history until you delete those sessions or your account.
Supabase (database + auth) — hosted in Zurich, Switzerland. Processes your account, workout, wellness, and wearable data.
Google Analytics 4 (web only) — cookieless page-view analytics (no cookies, no personal data, no cross-site tracking). Where a measurement ID is configured, the Google tag loads on the pages of fittssy.com, including pages you open while signed in, and is not limited to the landing page; scroll, time-on-page and button-click events are recorded on the landing page. Android app excluded. Google’s privacy policy: https://policies.google.com/privacy.
Vercel (hosting + analytics) — serves the web application and collects anonymous page view analytics. The website also loads Vercel Speed Insights, which, where it is active for our hosting project, sends page-load performance measurements for the pages you open to Vercel (see Analytics & Error Monitoring). Its server logs also hold the troubleshooting entries described under AI-Generated Content: the voice-logging entries (your account ID with lengths and counts rather than the transcript text, the entry written when a request body cannot be read, and the provider’s error if the request to Anthropic fails); when a program or protocol generation returns a reply that cannot be read, up to 500 characters of that reply, and the other generator troubleshooting entries described there; and the error written when an insight request fails. They also hold the key of a rate-limit counter when the counter check returns an error (see Data Retention). The payment webhook that receives events from Stripe also writes entries to these logs. Depending on the event, an entry can hold: the Stripe identifiers involved (a Checkout session, subscription, invoice, charge, PaymentIntent or customer ID); for a digital-product purchase, or a bonus product delivered with a subscription bundle, the product SKU and the buyer’s billing email; for a LEGEND purchase, the billing email, the Operator number and the name to be printed on the personalised files; for a support donation, the amount and currency; your account ID when a purchased programme is added to your account; and, where a payment is attributed to an invite, the internal IDs of the referral and commission records. Our code does not delete these entries when you delete your account, and we do not set a separate retention period for them. Servers located in the US and EU.
PostHog (product analytics) — hosted in Frankfurt, Germany (EU). Captures usage events and, on the website, page views. While you are signed in these are linked to your account ID, and on the website your account’s email address is sent to PostHog as well; the mobile apps do not send your email address. The events are not anonymised. No cross-site tracking. No data shared with third parties.
Sentry (error monitoring and performance tracing) — hosted in the EU. Captures error stack traces and browser metadata when errors occur, and performance traces for a sample of ordinary activity such as page loads and requests (a trace sample rate of 10% on the website and 20% in the mobile apps), whether or not an error occurred. IP addresses processed transiently, not stored. It also receives the errors that our server code reports, including the AI-feature errors described under AI-Generated Content, whose message can quote a short fragment of a model reply or of a request that could not be read as valid data. Our daily staff digest reads the titles and messages of unresolved Sentry issues back from Sentry and copies them into our own database (see Data Retention).
Anthropic (AI features) — processes, via the Claude API, the data listed per feature in the AI-Generated Content section above: generator and Program Genesis inputs including the free text you type, voice-logging transcripts, training and nutrition figures for insights, sleep records and workout sessions (including sessions saved from a wearable record) when the scheduled weekly insight or monthly report runs for your account, and bug-report text together with the submitting account’s email address during staff review. Anthropic’s terms on model training and its stated retention practice are set out in that section.
Google OAuth (optional) — if you sign in with Google, Google shares your email and name with us. We store only the email and display name.
Sign in with Apple (optional) — if you sign in with Apple, Apple confirms your identity to our authentication provider, Supabase. In the iOS app, the app asks Apple for your name and email address and passes the identity token that Apple returns to Supabase. On the website and in the Android app, you sign in on Apple’s own sign-in page. When the account is created we store the email address that Apple provides and a display name: the name supplied with the sign-in if there is one, otherwise the part of the email address before the @ sign.
Google Health Connect (Android only, optional) — reads health and fitness data from your connected wearable devices when you grant permission. While you are signed in and the permission is granted, the app reads this data when you start a sync yourself and also without you starting one: when the app starts, when you return to it, after you save a cardio, interval or mindfulness session, and from a background task that the app registers with a minimum interval of 15 minutes (the operating system decides when, and whether, that task runs). The records the app imports are stored in your Fittssy account. Sleep records are sent to Anthropic when the scheduled weekly insight or monthly report runs for your account, as described under AI-Generated Content.
Apple Health (iOS only, optional) — reads health and fitness data (steps, distance, active energy, heart rate, resting heart rate, body mass, body fat percentage, sleep, mindful sessions and workouts) when you grant permission. While you are signed in and the permission is granted, the app reads this data when you start a sync yourself and also without you starting one: when the app starts, when you return to it, after you save a cardio, interval or mindfulness session, and from a background task that the app registers with a minimum interval of 15 minutes (the operating system decides when, and whether, that task runs). The records the app imports are stored in your Fittssy account. Sleep records are sent to Anthropic when the scheduled weekly insight or monthly report runs for your account, as described under AI-Generated Content. Fittssy does not write to or modify your Apple Health data.
Open Food Facts (optional) — when you use the nutrition food search feature, your search query is sent to the Open Food Facts public API (openfoodfacts.org) to retrieve nutritional data. The same query is also sent to the FoodData Central API of the United States Department of Agriculture (api.nal.usda.gov). Our code does not add your name, email address or account ID to these requests.
Stripe (payment processing) — processes NETRUNNER subscriptions, the LEGEND one-time edition, one-time digital product purchases (monographs), and support donations. All purchases (web and mobile) flow through Stripe. Stripe collects your payment card details directly — Fittssy never sees or stores your full card number. Stripe may store your email address, name, and billing address for payment receipts and fraud prevention. Stripe’s privacy policy: https://stripe.com/privacy. Stripe is PCI DSS Level 1 certified. After a successful one-time payment we store a record in our database (in the `purchases`, `legend_purchases` or `support_payments` table, depending on the kind of purchase). A digital-product or LEGEND record holds the Stripe Checkout session ID and, where Stripe reports one, the PaymentIntent ID, with the amount, currency and billing email, and your account ID where the checkout was started from a signed-in account; a digital-product record also holds the product SKU, and a LEGEND record has no SKU field. A support-donation record holds the Checkout session ID, the amount, currency, your message if you added one and your account ID if you donated while signed in; it holds no PaymentIntent ID, SKU or email address. For a NETRUNNER subscription we store the Stripe customer ID and the Stripe subscription ID on your account (see Payments & Purchases). These records are retained per the Data Retention section (seven years for tax-record purposes). Deleting your account does not cancel a subscription or delete the customer record held at Stripe (see ‘records held at Stripe’ under Data Retention). Affiliate payouts (Stripe Connect): if you start affiliate onboarding from the affiliate page of your account, our servers create a Stripe connected account for you, if you do not already have one, and send Stripe your account’s email address and your Fittssy account ID. You then complete onboarding on a page hosted by Stripe. We store the Stripe account ID, the country and default currency that Stripe reports, and the onboarding status (whether charges and payouts are enabled and whether details have been submitted) in our database.
Resend (email delivery) — Resend processes outbound email on our behalf: transactional messages (password reset, account confirmation, purchase receipts with download links, subscription lifecycle notifications) and the optional monthly FIELD REGISTER newsletter if you subscribe to it via the footer capture form on fittssy.com. It is also used for the email sent when you request account deletion from the account settings page on our website (it contains the scheduled deletion date and a link to cancel the request); for the two emails sent when you submit a claim under the 30-day PR guarantee (an acknowledgement to you, and a message to our staff address containing your account’s email address, the summary you typed, the tier recorded for the guarantee and the claim’s ID); and for a daily digest emailed to our staff addresses, which lists recent monitoring entries: the titles of unresolved Sentry issues with their event and affected-user counts, the category, the first 80 characters of the text and the screen or route of bug reports and feedback, and up to the first 200 characters of error-level entries from the logs of our database provider, Supabase (see Data Retention). Contact list: when you give us your email address through an email-capture form on our website (for example the newsletter, a waitlist or a free product download), our servers store it in a contact record in our database. That record holds the form the address came from and any details or tags that form supplied (for example a handle you typed on a waitlist form); your first and last name, country code and language if the form supplied them; whether you gave marketing consent, with the time and the version of the consent wording; and your account ID if you were signed in. When the record is first created it also stores your IP address and your browser’s user-agent string, whether or not you gave marketing consent; for a record that already exists, these two are stored again when marketing consent is newly given. When marketing consent is newly given, the record also holds a confirmation token for the confirmation email. A log entry recording the capture (the form and the details it supplied) is kept with the record. Where the contact-list sync is configured, our servers also add your email address, and your first and last name if the form supplied them, to a Resend Audience (contact list). The sync does not depend on which form you used or on whether you gave marketing consent, and the form the address came from is not sent to Resend. The newsletter is sent as a Resend broadcast to a contact list held at Resend, which is the one described here unless a different list is chosen when an issue is released. The unsubscribe link in the newsletter template in our code is supplied by Resend and is handled by Resend rather than by our code. Our code also has an unsubscribe page of its own (/unsubscribe); it needs a signed link which, at the date of this policy, our code does not put into the emails it sends. When used, it marks your record in our database as unsubscribed and, if the address belongs to an account, switches off that account’s marketing-consent setting; it does not delete the record and does not update or remove the contact at Resend. The contact record therefore stays at Resend and in our database until we remove it at your request: to have it removed, or if you still receive emails after unsubscribing, contact privacy@fittssy.com. Resend’s privacy policy: https://resend.com/legal/privacy-policy.
Expo (mobile apps: push notification delivery, optional, and app updates) — if you enable push notifications in the mobile app, the app obtains a push token for your device through Expo’s notification service and we store it in your account. When a scheduled notification is due, our servers send that token together with the notification’s title, text, type and in-app link to Expo’s push service (exp.host), which delivers it to your device. App updates: separately, and whether or not you enable push notifications, the mobile apps include Expo’s update library, configured with an update address on Expo’s servers (u.expo.dev), and our configuration does not switch it off. When that library checks for an update, the app contacts that address. When and how often it checks, and what the request contains, are decided by Expo’s software rather than by our code; as with any request, the server it contacts receives your device’s IP address. Expo’s privacy policy: https://expo.dev/privacy.
Browser push services (web push) — our scheduled-notification job can also deliver a notification through the push service run by your browser’s vendor (for example Google’s or Mozilla’s). If your account holds a browser push subscription and no mobile push token, and web push keys are configured on our servers, the job sends the notification’s title, text, type and in-app link to the push endpoint address stored in that subscription. At the date of this policy no part of our website or apps creates such a subscription, so this applies only to an account that already holds one.
GitHub (LEGEND fulfilment) — when a LEGEND purchase completes and this fulfilment step is switched on, our servers send GitHub the name to be printed on your personalised files (the name you typed for the cover at checkout or, if there is none, the billing name collected by Stripe), your email address and your Operator number. GitHub then runs an automated job (GitHub Actions) that produces the personalised PDF files, uploads them to our storage at Supabase and emails you the download links through Resend. The job writes the name, email address and Operator number into the record of that run on GitHub. GitHub may process this data in the United States. GitHub’s privacy statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement.
QR code images (api.qrserver.com) — the ‘Get the app’ tab of the account page on our website shows two QR codes that link to our Google Play and App Store listings. Your browser loads these two images directly from api.qrserver.com, a third-party QR-code image service. The address of each image contains the store link and nothing from your account; as with any image your browser loads, that service receives the request your browser sends, including your IP address.
Your primary data is stored in Switzerland and the EU (Supabase in Zurich, PostHog in Frankfurt, Sentry in the EU). Some services, including Vercel hosting, Anthropic AI, Stripe, Resend, Google, Expo and GitHub (for LEGEND fulfilment), may process data in the United States. Where personal data is transferred outside the UK, the EEA or Switzerland to a country without an adequacy decision, we rely on the safeguards in the provider’s data processing terms, such as Standard Contractual Clauses (SCCs) and, for transfers from the UK, the UK Addendum. Anthropic’s Data Processing Addendum (linked under AI-Generated Content) incorporates both to the extent required by applicable data protection law.
Fittssy is not intended for use by individuals under the age of 16. We require age verification during registration. We do not knowingly collect personal information from children. If you believe a child under 16 has provided us with personal data, please contact us at privacy@fittssy.com and we will delete the information promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will update the ‘Last updated’ date at the top of this page when changes are made. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.
Fittssy™ is available in 10 languages: English, Hungarian (Magyar), German (Deutsch), Spanish (Español), French (Français), Portuguese (Português), Russian (Русский), Chinese Simplified (中文), Japanese (日本語), and Korean (한국어).
The app language can be changed at any time via Profile → Language. Your language preference is stored as a cookie on your device. If you are signed in, your language preference is also saved to your account so it persists across devices.
All UI text, exercise library descriptions, and in-app guidance are translated. The Privacy Policy and Terms of Service are currently available in English only.
For privacy questions, data access requests, or deletion requests: email privacy@fittssy.com.
You may also use the in-app feedback tool (tap the floating button on any page, select ‘Feedback’).
Data controller: Fittssy™, operated by an independent developer based in the United Kingdom.
© 2026 Fittssy™. All rights reserved.