FitMito

Privacy Policy

Policy version 1 · Last updated: July 21, 2026 · Data controller: FitMito · hello@fitmito.com
When you create an account you accept this policy (version 1); a material change bumps the version and asks you to accept again.
🟢 The honest TL;DR

Our goal isn't data farming — it's to legally and fairly help you live better. Your health data exists to coach you, and for nothing else. No data sales, no model training on your data, ever. Your progress photos never leave your device. By default we run zero trackers; analytics and ad-measurement cookies exist but load only if you press Accept on the consent bar — press "Essential only" and the app works identically. Delete your account and your data goes with it.

1. What we collect

DataWhyWhere it lives
Account (email, name, Google ID)Sign-in, account securitySupabase (EU-compliant auth)
Health & habit logs (weight, meals, workouts, sleep, tape measurements, mood, habits)The entire product: coaching, trends, the gamePrivate, per-account, encrypted-at-rest repository (GitHub) + a cache in your browser (localStorage)
Progress photos / body-scan videos (optional)Your progress visualisation — measurements are derived on-device, then shown only to youYour device only. Photos and scan videos are stored in your browser (IndexedDB) and are never uploaded to our servers — they never leave the device you took them on
Chat messages with the coachGenerating replies; short history for continuityProcessed by the AI model you select (Google Gemini by default; OpenAI, Anthropic or DeepSeek if you choose them); stored in your private data space
Wearable feed (optional, e.g. heart rate, HRV, steps)Readiness and health trendsPrivate repository; you control the source
AI usage countersFair-use budgeting per planSupabase
Approximate location (optional)City auto-fill during setup, and the weather / UV / air-quality cardUsed live, not stored by us: on an explicit tap your coordinates are rounded (to ~1 km for the city lookup) and sent to a keyless service (BigDataCloud for the city name, Open-Meteo for weather) — never tied to your identity
Notification subscription (optional)Sending the coach nudges you turn onA push token from your browser's push service (Apple / Google / Mozilla), stored in your private data space so we can reach that device; removed when you turn alerts off
Anonymous product analytics & crash reportsSeeing which features get used, and catching bugsFirst-party only (our own endpoint → Supabase or your private repo). Semantic events (e.g. "a tab was opened") plus a random device ID — never your name, email, message text, or health values

2. What we deliberately do NOT do

3. Cookies, local storage & analytics

Essential (always): one authentication session (Supabase) so you stay signed in, plus device-local preferences in your browser's localStorage — they never leave your device. We also count page views with Vercel Web Analytics — cookieless, aggregate, no personal identifiers, no cross-site tracking, which is why it needs no consent.

Product analytics & crash reports (first-party, anonymous): to understand which features actually help and to catch bugs, the app sends its own usage events to our own endpoint (stored in Supabase or our private repo — never a third-party analytics company like Google Analytics, PostHog or Amplitude). These are semantic events only ("a chat message was sent", "the Lab was opened"), a random first-party device ID, and — for a crash — the error's name and a code location (file:line), never the error message and never any of your content. No personal data is included, and a server-side scrubber drops anything that looks personal even if a tampered client tried to send it. This runs on an opt-out basis: it's disabled automatically on data-saver / "reduce data" connections, and you can switch it off in your browser.

Connections your device makes: a few features reach third parties directly from your browser, only when you use them. If you tap "use my location" during setup, your coordinates are rounded to ~1 km and sent to BigDataCloud to name your city. The weather / UV / air card sends your approximate coordinates to Open-Meteo. If you enable coach nudges, your browser registers a push subscription with its own push service (Apple / Google / Mozilla). None of these are trackers, none receive your health data, and each is optional.

Optional (only with your consent): if you press Accept on the consent bar, we enable Google Analytics 4 (traffic measurement, IP anonymised) and ad-measurement tags (Google Ads, and where campaigns run, Meta/TikTok pixels) so we can tell which campaigns work. Consent Mode v2 applies: before or without consent these run cookieless or not at all. Your health logs are never sent to any of these platforms — only anonymous usage events like "a chat message was sent". Withdraw anytime by clearing site data or emailing us.

4. AI processing — what reaches the AI, and when

Powering the coaching means sending some of your data to an AI provider. This happens in three places, and only these:

We use API settings that do not permit these providers to train their models on your data. Consent to this AI processing is affirmative: you accept it when you create your account (and can withdraw it by deleting your account). The coach's write-actions (logging a meal, building a panel) act only on your data space. Your progress photos are never sent to any AI provider — measurements are derived on your own device.

5. Legal bases (GDPR)

6. Your rights

Access, rectification, erasure, portability, restriction, objection — all of them, free. The fastest erasure is built in: Account → Delete my account wipes your account, profile and Pro grant for good (you type DELETE to confirm; the server re-checks it). For anything else, email hello@fitmito.com. Data export is trivially real here: your data is a plain-text, per-account repository and you can have a full copy. You may also complain to your local supervisory authority (in Romania: ANSPDCP).

7. Retention

Your data is kept while your account exists. Delete your account and personal data is erased within 30 days (backups roll off within 90). AI usage counters are kept in aggregate, de-identified form.

8. Security — and the honest limits

Encryption in transit (TLS) and at rest (provider-side, on GitHub/Supabase), token-gated APIs with per-account isolation, least-privilege server keys, and a strict rule that non-owner accounts can never read another account's data — enforced in code at every endpoint.

What this is not: your account data is not end-to-end encrypted. FitMito is run by a small team, and to keep the service running and to help you when you write in, the operator can technically access the account data stored on our systems. We treat that access as support-only and never as a data source to mine. One thing stays off our servers entirely: your progress photos (device-only, see §1).

9. Subprocessors

The third parties that process data to run FitMito, each under their own GDPR-compliant terms and only as needed:

SubprocessorWhat it doesWhat it sees
VercelHosting & delivery of the app + APIsRequests/traffic; no health logs stored here
GitHubPrivate, per-account data storage (encrypted at rest)Your logs, profile, chat history
SupabaseSign-in / auth + AI usage countersEmail, account ID, aggregate usage counts
Google (Gemini API)The default AI: chat, meal-photo macros, care/evidence researchYour message + relevant data slices, or a meal photo, or a research topic
Anthropic (Claude API)AI replies — only when a Claude model is selectedThe same chat context, only for that turn
BigDataCloudTurns rounded coordinates into a city name (setup city auto-fill)Approximate coordinates (~1 km) — only on your explicit tap, no identity
Open-MeteoWeather, UV & air-quality for your outdoor cardApproximate coordinates — no identity, no health data
Browser push services (Apple / Google / Mozilla)Delivering the notifications you opt intoA push token + the notification payload — only if you enable alerts

Per each AI provider's API terms, they do not train their models on data sent through the API. Progress photos go to none of them — they never leave your device.

For a one-page map of every flow — what leaves your device, to whom, why, and for how long — see our data-flows sheet.

10. Children

FitMito is not for children under 16. We don't knowingly collect their data; if you believe a child is using the Service, email us and we'll remove the account.

11. Changes

Material changes to this policy are announced in-app or by email at least 14 days in advance. The "last updated" date at the top always tells the truth.

12. Contact

hello@fitmito.com — a human reads it.