Fitaio / Privacy
Your data, clearly explained.
This policy covers the Fitaio mobile app and fitaio.app. Contact the Fitaio developer at kakhagiorgashvili@gmail.com for privacy questions and requests.
Information you provide
- Account and profile: your email address, sign-in provider, account identifier and profile details you enter, such as your name, birth date, height, gender and fitness goal. Your sign-in provider may also supply your name, email and profile image. Firebase Authentication handles account credentials.
- Fitness and wellness records: workouts, sets, repetitions, weights, body measurements, body weight, body fat, nutrition logs, supplement schedules, goals, training plans, meal plans and saved routines.
- Photos: progress photos you choose or take, plus the date, pose and any body weight you associate with them. Your selected image may contain metadata; avoid uploading images containing information you do not want stored.
- AI requests: questions or instructions you send, and relevant fitness context if you choose to use AI features. Instructions and generated plans can be saved as part of your plan history.
- Support: the email address and information you include when contacting us.
Why we use it
We use your data to create and secure your account, sync your records, display your progress, provide the features you request and respond to support or deletion requests. Some information is also stored on your device to remember preferences and support the app experience.
Optional AI features
Before the first AI request for an account on a device, Fitaio asks for permission to send your prompt and relevant fitness context to Google Gemini through our Cloudflare service. Context can include your age, height, gender, goal, weight and body-fat trends, nutrition targets and totals, and workout history. Fitaio does not automatically include your name, email, full birth date or progress photos in the AI context. Anything you type into a prompt will be sent, so do not include unnecessary personal information.
You can decline and continue using tracking features. In Settings → Privacy & support, choose Reset AI sharing permission to make the next AI request ask again on this device. Declining that request prevents it from being sent. Resetting permission does not recall information already shared; previously transmitted requests remain subject to the provider's applicable processing and retention terms. Google processes requests under its Gemini API terms and privacy policy. Google's applicable unpaid-service terms permit use of inputs and outputs to improve its products and allow human review. Under its paid-service terms, Google does not use prompts or responses to improve its products, but may retain them for safety, security and legal purposes. Billing, regional conditions and account configuration determine which terms apply; using Fitaio is not a promise of zero provider retention. Do not use Fitaio to send confidential medical documents or information about other people.
Service providers and technical data
- Google Firebase: authentication, account records, fitness data and cloud photo storage. See Firebase privacy information.
- Cloudflare: website hosting and the authenticated AI gateway. Network requests include technical information such as IP addresses and request headers. The gateway uses account and network identifiers to check access and limit abuse; our gateway processes AI prompts and responses without storing them or logging their content or authentication tokens. Cloudflare may process separate network and security information under its own policies. See Cloudflare's privacy policy.
- App analytics: the mobile app uses Firebase Analytics for basic app interactions and technical usage information, including an app-instance identifier and approximate location derived from masked IP addresses. The app does not request precise device location. Our event payloads exclude health measurements, email addresses and account IDs; advertising-identifier collection is disabled. Earlier versions may have sent additional event details. Web analytics and PostHog are not enabled in this release. There is currently no in-app switch to turn off mobile usage analytics. See Google Analytics data handling.
- Exercise media: viewing externally hosted exercise images or videos connects to their providers, which receive normal network request information.
We do not sell your personal data or use your health records for advertising. Providers may process data in countries other than where you live.
Permissions
The camera is requested when you choose to take a progress photo. The system photo picker lets you select a photo. Denying these permissions does not prevent you from using the other tracking features. You can manage device permissions in system settings.
Retention and deletion
We keep your account records while your account is active, until you remove individual records or request account deletion. Deleting a progress photo removes its cloud image and associated record when the operation succeeds. Uninstalling the app does not delete a cloud account.
You can request deletion from Settings → Account deletion → Request account deletion, or use the public account-deletion page. Requests are handled manually after account ownership is verified. We confirm the processing timeframe with you and notify you when complete. Deletion covers your account, profile, linked fitness records, plans and stored progress photos. Limited support, security or legally required records may be retained when necessary; if an exception applies to your request, we explain the reason and retention period. Provider backups, security records and analytics that cannot be linked back to your account are subject to their respective retention processes.
Your choices
You can use the editing and deletion controls available for individual records, decline AI use and contact kakhagiorgashvili@gmail.com to request access, correction, a copy of your information or account deletion. Rights available to you depend on where you live. We may need to verify account ownership before acting on a request; never email your password.
Children
Fitaio is intended for adults and is not directed to children. Contact us if you believe a child has provided personal information so we can investigate and remove it as appropriate.
Security and changes
We use authentication and encrypted network connections to help protect information. No service can guarantee absolute security. This policy may change as features or practices change; the effective date above identifies the current version.