FitMito

Data Flows

Companion to the Privacy Policy · Last updated: July 21, 2026 · hello@fitmito.com
🟢 One page, everything

This is the honest map: every kind of data, exactly where it goes, why, the legal basis, and how long it's kept. The rule underneath it all — your progress photos never leave your device, we never sell your data, and no AI provider trains on it. A stays on device tag means it is never sent anywhere.

1. Data that powers the product

WhatLeaves your device toWhyLegal basis (GDPR)Kept
Account — email, name, Google IDSupabase (auth)Sign-in & account securityContract — Art. 6(1)(b)While your account exists
Health & habit logs — weight, meals, workouts, sleep, tape, mood, habitsSupabase Postgres (EU — Ireland) with per-user row-level security: the database itself refuses to serve one account’s rows to another. Plus a private encrypted backup and a localStorage cache on your deviceThe whole product: coaching, trends, the gameExplicit consent — Art. 9(2)(a)While your account exists; deleting your account deletes the database rows in one cascade
Wearable feed — heart rate, HRV, steps (optional)Same store as your logs (Supabase EU) — pushed by your phone with a bearer tokenReadiness & health trendsExplicit consent — Art. 9(2)(a)While your account exists
Progress photos & body-scan videosstays on device — browser IndexedDB, never uploadedYour own progress visualisation; measurements derived on-deviceUntil you clear the browser / delete them

2. What reaches an AI provider — and only these

WhatGoes toWhyLegal basisKept
Chat message + the relevant slices of your own dataGoogle GeminiGenerating the coach's replyExplicit consent — Art. 9(2)(a)Not retained by the provider for training (API terms)
Meal photoGoogle GeminiEstimating calories & proteinExplicit consentUsed for the estimate, not stored by the provider
A symptom / self-experiment topic (not your identity)Google Gemini + live web searchGrounding the answer in real sourcesExplicit consentTransient

Progress photos are sent to none of these — measurements are derived on your own device. A non-owner account must accept the AI-processing consent before any of these run; without it the request is refused, not silently sent.

3. Analytics, crashes & connections your device makes

WhatGoes toWhyLegal basisKept
Page views (cookieless, aggregate)Vercel Web AnalyticsTraffic countsLegitimate interest — Art. 6(1)(f)Aggregate
First-party product analytics — semantic events (e.g. "a tab was opened") + a random device IDOur own endpoint → Supabase or the private repo (no third-party analytics company)Seeing which features helpLegitimate interest (opt-out)Aggregate; no PII, no message text
Crash reports — error name + code location (file:line), never the message or your contentSame first-party endpointCatching bugsLegitimate interest (opt-out)Aggregate
Marketing attribution — a channel slug like "tiktok" (from a utm link)Same first-party endpointWhich campaign brought youLegitimate interestAggregate, never joined to health data
Approximate location — coordinates rounded to ~1 km, on your explicit tapBigDataCloud (keyless)Auto-filling your city during setupConsent — your tapNot stored by us
Approximate coordinatesOpen-MeteoYour weather / UV / air-quality cardConsent — using the featureNot stored by us
Push subscription token + notification payloadYour browser's push service (Apple / Google / Mozilla)Delivering the coach nudges you enableConsent — enabling alertsUntil you turn alerts off
Marketing/ad measurement (GA4, Google Ads, Meta, TikTok)Those platforms — only if you press Accept on the consent barTelling which campaigns workConsent — Art. 6(1)(a)Per their terms; cookieless or off before consent

Your health logs are never sent to any analytics or ad platform — only anonymous usage events. The app's static assets (fonts, the sign-in SDK, 3D libraries) load from Google Fonts, esm.sh and jsDelivr, which see the request (including your IP) purely to deliver the file — no tracking.

4. Where it's stored, and for how long

5. The honest limits

Your account data is not end-to-end encrypted. FitMito is run by a small team, and to keep the service running and to help you when you write in, the operator can technically access the account data on our systems. We treat that as support-only, never as a data source to mine. One thing stays off our servers entirely: your progress photos (device-only).

Full detail, your rights and how to exercise them: Privacy Policy · Terms.