Privacy Policy
When you create an account you accept this policy (version 1); a material change bumps the version and asks you to accept again.
Our goal isn't data farming — it's to legally and fairly help you live better. Your health data exists to coach you, and for nothing else. No data sales, no model training on your data, ever. Your progress photos never leave your device. By default we run zero trackers; analytics and ad-measurement cookies exist but load only if you press Accept on the consent bar — press "Essential only" and the app works identically. Delete your account and your data goes with it.
1. What we collect
| Data | Why | Where it lives |
|---|---|---|
| Account (email, name, Google ID) | Sign-in, account security | Supabase (EU-compliant auth) |
| Health & habit logs (weight, meals, workouts, sleep, tape measurements, mood, habits) | The entire product: coaching, trends, the game | Private, per-account, encrypted-at-rest repository (GitHub) + a cache in your browser (localStorage) |
| Progress photos / body-scan videos (optional) | Your progress visualisation — measurements are derived on-device, then shown only to you | Your device only. Photos and scan videos are stored in your browser (IndexedDB) and are never uploaded to our servers — they never leave the device you took them on |
| Chat messages with the coach | Generating replies; short history for continuity | Processed by the AI model you select (Google Gemini by default; OpenAI, Anthropic or DeepSeek if you choose them); stored in your private data space |
| Wearable feed (optional, e.g. heart rate, HRV, steps) | Readiness and health trends | Private repository; you control the source |
| AI usage counters | Fair-use budgeting per plan | Supabase |
| Approximate location (optional) | City auto-fill during setup, and the weather / UV / air-quality card | Used live, not stored by us: on an explicit tap your coordinates are rounded (to ~1 km for the city lookup) and sent to a keyless service (BigDataCloud for the city name, Open-Meteo for weather) — never tied to your identity |
| Notification subscription (optional) | Sending the coach nudges you turn on | A push token from your browser's push service (Apple / Google / Mozilla), stored in your private data space so we can reach that device; removed when you turn alerts off |
| Anonymous product analytics & crash reports | Seeing which features get used, and catching bugs | First-party only (our own endpoint → Supabase or your private repo). Semantic events (e.g. "a tab was opened") plus a random device ID — never your name, email, message text, or health values |
2. What we deliberately do NOT do
- No trackers of any kind without your explicit consent — and never any fingerprinting.
- No selling, renting or "sharing for value" of your data. Ever.
- No training of AI models on your personal data.
- No social features that expose your data to other users — your coach is yours alone; other accounts cannot see your data.
3. Cookies, local storage & analytics
Essential (always): one authentication session (Supabase) so you stay signed in, plus device-local preferences in your browser's localStorage — they never leave your device. We also count page views with Vercel Web Analytics — cookieless, aggregate, no personal identifiers, no cross-site tracking, which is why it needs no consent.
Product analytics & crash reports (first-party, anonymous): to understand which features actually help and to catch bugs, the app sends its own usage events to our own endpoint (stored in Supabase or our private repo — never a third-party analytics company like Google Analytics, PostHog or Amplitude). These are semantic events only ("a chat message was sent", "the Lab was opened"), a random first-party device ID, and — for a crash — the error's name and a code location (file:line), never the error message and never any of your content. No personal data is included, and a server-side scrubber drops anything that looks personal even if a tampered client tried to send it. This runs on an opt-out basis: it's disabled automatically on data-saver / "reduce data" connections, and you can switch it off in your browser.
Connections your device makes: a few features reach third parties directly from your browser, only when you use them. If you tap "use my location" during setup, your coordinates are rounded to ~1 km and sent to BigDataCloud to name your city. The weather / UV / air card sends your approximate coordinates to Open-Meteo. If you enable coach nudges, your browser registers a push subscription with its own push service (Apple / Google / Mozilla). None of these are trackers, none receive your health data, and each is optional.
Optional (only with your consent): if you press Accept on the consent bar, we enable Google Analytics 4 (traffic measurement, IP anonymised) and ad-measurement tags (Google Ads, and where campaigns run, Meta/TikTok pixels) so we can tell which campaigns work. Consent Mode v2 applies: before or without consent these run cookieless or not at all. Your health logs are never sent to any of these platforms — only anonymous usage events like "a chat message was sent". Withdraw anytime by clearing site data or emailing us.
4. AI processing — what reaches the AI, and when
Powering the coaching means sending some of your data to an AI provider. This happens in three places, and only these:
- Chat — your message plus the relevant slices of your own data (profile, recent logs, your health series, the life story you chose to write) are sent to the model behind your selection: Google's Gemini API.
- Meal photos — if you snap a plate, the image is sent to Google Gemini to estimate its calories and protein. It's used for that estimate, not stored by the provider for any other purpose.
- Care & evidence research — when you research a symptom or a self-experiment, the topic (not your identity) is sent to Google Gemini with a live web search so the answer is grounded in current, real sources.
We use API settings that do not permit these providers to train their models on your data. Consent to this AI processing is affirmative: you accept it when you create your account (and can withdraw it by deleting your account). The coach's write-actions (logging a meal, building a panel) act only on your data space. Your progress photos are never sent to any AI provider — measurements are derived on your own device.
5. Legal bases (GDPR)
- Contract — providing the Service you signed up for (Art. 6(1)(b)).
- Explicit consent — processing your health data, including sending the relevant slices to AI providers to coach you. You give this consent affirmatively when you create your account (and again if this policy materially changes), and can withdraw it by deleting your data or your account (Art. 9(2)(a)).
- Legitimate interest — fraud prevention and service security (Art. 6(1)(f)).
6. Your rights
Access, rectification, erasure, portability, restriction, objection — all of them, free. The fastest erasure is built in: Account → Delete my account wipes your account, profile and Pro grant for good (you type DELETE to confirm; the server re-checks it). For anything else, email hello@fitmito.com. Data export is trivially real here: your data is a plain-text, per-account repository and you can have a full copy. You may also complain to your local supervisory authority (in Romania: ANSPDCP).
7. Retention
Your data is kept while your account exists. Delete your account and personal data is erased within 30 days (backups roll off within 90). AI usage counters are kept in aggregate, de-identified form.
8. Security — and the honest limits
Encryption in transit (TLS) and at rest (provider-side, on GitHub/Supabase), token-gated APIs with per-account isolation, least-privilege server keys, and a strict rule that non-owner accounts can never read another account's data — enforced in code at every endpoint.
What this is not: your account data is not end-to-end encrypted. FitMito is run by a small team, and to keep the service running and to help you when you write in, the operator can technically access the account data stored on our systems. We treat that access as support-only and never as a data source to mine. One thing stays off our servers entirely: your progress photos (device-only, see §1).
9. Subprocessors
The third parties that process data to run FitMito, each under their own GDPR-compliant terms and only as needed:
| Subprocessor | What it does | What it sees |
|---|---|---|
| Vercel | Hosting & delivery of the app + APIs | Requests/traffic; no health logs stored here |
| GitHub | Private, per-account data storage (encrypted at rest) | Your logs, profile, chat history |
| Supabase | Sign-in / auth + AI usage counters | Email, account ID, aggregate usage counts |
| Google (Gemini API) | The default AI: chat, meal-photo macros, care/evidence research | Your message + relevant data slices, or a meal photo, or a research topic |
| Anthropic (Claude API) | AI replies — only when a Claude model is selected | The same chat context, only for that turn |
| BigDataCloud | Turns rounded coordinates into a city name (setup city auto-fill) | Approximate coordinates (~1 km) — only on your explicit tap, no identity |
| Open-Meteo | Weather, UV & air-quality for your outdoor card | Approximate coordinates — no identity, no health data |
| Browser push services (Apple / Google / Mozilla) | Delivering the notifications you opt into | A push token + the notification payload — only if you enable alerts |
Per each AI provider's API terms, they do not train their models on data sent through the API. Progress photos go to none of them — they never leave your device.
For a one-page map of every flow — what leaves your device, to whom, why, and for how long — see our data-flows sheet.
10. Children
FitMito is not for children under 16. We don't knowingly collect their data; if you believe a child is using the Service, email us and we'll remove the account.
11. Changes
Material changes to this policy are announced in-app or by email at least 14 days in advance. The "last updated" date at the top always tells the truth.
12. Contact
hello@fitmito.com — a human reads it.