Last updated: 13 July 2026
Overview
Fitnessage ("we", "our", "us") provides separate member, trainer, and gym-owner applications for fitness assessments, workout and nutrition planning, coaching, gym operations, and community challenges. This policy explains what each app collects, why it is used, who can access it, and how to exercise your privacy rights.
Data we collect
- Account and profile data: name, email address, hashed password, authentication tokens, age, sex, height, weight, goals, preferences, selected gym, trainer or owner role, and push-notification token.
- Health and fitness data: injuries, health conditions, allergies, body measurements, body-fat estimates, fitness assessments, biological-age-style wellness estimates, strength calibration, workouts, meals, hydration, and progress history.
- Content and interactions: challenge and head-to-head entries, display names, comments, trainer notes, plans, recommendations, bookings, availability, package descriptions and rates, gym suggestions, product descriptions, branding, and facility, equipment, or floor-plan information.
- Uploads: gym owners may upload branding, product, equipment, or floor-plan images. Member body-scan and camera-assessment images are processed on the device and are not uploaded; only derived measurements or test results are sent when you save them.
- Transactions: when an enabled physical-goods or real-world-service flow is used, we process order contents, fulfilment status, delivery/contact information, purchase history, and a payment-provider identifier. We do not receive or store the full payment-card number.
- Usage and technical data: app interactions, app version, operating system, randomly generated analytics identifier, request/error information, and security logs. We do not use advertising SDKs or sell behavioural profiles.
How we use your data
- Provide requested features, personalise plans, calculate wellness estimates, track progress, connect members with authorised trainers or gyms, fulfil enabled orders, and operate support and moderation.
- Send account, booking, coaching, challenge, order, security, and other transactional communications. Marketing communications require a separate opt-in where required.
- Measure product performance using first-party analytics, diagnose errors, secure accounts, prevent fraud and abuse, and enforce our Terms.
- Comply with legal obligations and respond to valid rights requests. Optional research or filming use requires an explicit consent record and does not default to granted.
Sharing with third parties
- Cloudflare and Neon provide hosting, security, edge compute, and database infrastructure.
- Google AI services process the limited profile, plan, exercise, or food context needed to produce a requested AI output. We do not intentionally send passwords, payment-card data, or unrelated private records in AI prompts.
- Expo and platform notification services (Apple or Google) process device tokens and notification delivery data when notifications are enabled.
- Authorised trainers can access the member data needed to coach assigned clients, including relevant profile, assessment, plan, workout, nutrition, comment, and booking data. Gym owners access gym operations and aggregated or gym-scoped member information exposed by their role.
- Stripe and fulfilment partners receive the minimum payment, contact, address, and order information needed only when an enabled physical-goods or real-world-service transaction is used.
- We do not sell personal data or share it for cross-context behavioural advertising.
Your rights
- Access and portability — request a copy of the personal data associated with your account by emailing support@fitnessage.ai. We will respond within the period required by applicable law.
- Correction — update inaccurate data via the in-app Profile screen at any time.
- Deletion — start and confirm deletion through the in-app account settings or at fitnessage.ai/delete-account. Confirmation immediately revokes account access and begins backend erasure; it does not mean every backup and legally retained record disappears at that instant.
- Consent — withdraw optional marketing, research, or filming consent. Withdrawal does not affect processing that lawfully occurred before it.
- EU residents (GDPR) and California residents (CCPA) have the additional rights granted by those laws and can exercise them through the same channels.
Data retention
We retain account data while the account is active. After confirmed deletion, access is revoked immediately and active-system erasure is normally completed within 30 days. Limited transaction, tax, dispute, fraud-prevention, security, or legal records may be retained for the period required by law or legitimate legal need and then deleted or de-identified. Encrypted disaster-recovery backups expire on their normal rotation, which may take up to 90 days, and are not restored for ordinary product use. Aggregated data that can no longer reasonably identify a person may be retained.
Security
We use encryption in transit, password hashing, role-based access controls, secret management, and monitoring designed to protect personal data. No system is perfectly secure; we investigate suspected incidents and provide legally required notices.
Age eligibility
Fitnessage accounts are for adults aged 18 or older. We do not knowingly allow a person under 18 to create an account. If you believe a minor has provided personal data, contact support@fitnessage.ai so we can investigate and delete it where appropriate.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The "Last updated" date below reflects the most recent revision.
Contact
Privacy questions, requests, or complaints: support@fitnessage.ai. Include the account email and the app or role involved, but never send a password or payment-card number.