Privacy Policy
1. Who we are
Fittest Tech Ltd ("Fittest", "we", "us", "our") is a company registered in England and Wales, company number 16306185, with its registered office at Flat 112 Alington House, 1 Mary Neuner Road, London, England, N8 0ES.
We are the data controller for the personal data described in this policy. We are registered with the Information Commissioner's Office under registration reference ZB887278.
This policy explains how we handle personal data when you use the Fittest mobile applications, website at fittestapp.co.uk and related services (the "Service").
For any privacy question, contact pd@fittestapp.co.uk.
2. Who controls your data
There are two ways to use Fittest, and which one applies to you decides who is accountable for your data.
2.1 If you signed up yourself
You found Fittest, downloaded it and created your own account. Fittest Tech Ltd is the data controller. We decide the purposes and means of processing and are directly accountable to you. This whole policy applies to you.
If you later choose to share your data with a gym, studio or coach, that sharing is under your control. You decide whether to connect, you can disconnect at any time in your account settings, and your account stays yours if you leave that gym. Once you share data with them, they become an independent controller for what they do with it and their own privacy policy applies.
2.2 If your gym or studio brought you to Fittest
Your gym, studio or coach asked you to download Fittest, pays for your subscription, and uses their Fittest dashboard to coach you. In that case your gym or studio is the data controller for your training and health data, and we act as their data processor — we handle that data on their instructions, under a written data processing agreement that meets Article 28 UK GDPR.
If this is you, ask your gym or studio first about why your data is held, how long they keep it, or to access, correct or delete it. They decide those things; we carry out their instructions. We will help them respond to any request you make, and we will not use your data for our own purposes beyond what section 2.3 describes.
Your gym or studio is responsible for obtaining your explicit consent to process your health data, and for telling you how they use it. Sections 3, 7, 9, 10 and 11 of this policy still describe accurately how that data is handled technically while it is in our systems.
2.3 Where we are always the controller
However you signed up, we are the controller for:
- your account credentials and login records;
- billing and subscription records, including where a gym pays on your behalf;
- correspondence you send us directly, including support requests;
- security, access and API logs used to detect abuse and unauthorised access;
- aggregated and anonymised usage statistics used to improve the Service.
For those categories you can contact us directly and this policy applies in full.
2.4 If you leave your gym
Your account does not close and you do not lose your history. It converts to a direct Fittest account and you can keep using the app on your own.
When that happens, we become the data controller for your data in place of your gym, and section 2.1 applies to you from then on. Because the explicit consent you gave your gym does not transfer to us, we will ask you separately for consent to continue processing your health data. If you do not give it, we will delete that data and your account will continue without the features that rely on it.
Your gym loses access to your data through their dashboard from that point. They may keep their own records of your time with them, as an independent controller — ask them directly what they retain.
If your gym was paying your subscription, that ends, and we will tell you what plan you move onto. You can also simply ask us to close the account and delete everything.
3. What we collect
3.1 Information you give us
- Account details — name, email address, password (stored hashed), and where you provide them, date of birth or age, sex, height and weight.
- Profile and goals — training experience, objectives, availability, equipment access, and any preferences you set.
- Training data — workouts logged, sets, reps, loads, durations, perceived exertion, and notes you write.
- Nutrition data — food and drink logged, macronutrient and calorie records, dietary preferences and restrictions.
- Body measurements — where you choose to record them, including weight, body composition and circumference measurements, and any progress photos you upload.
- Support and correspondence — messages you send us and the contents of support tickets.
3.2 Information from your device and connected services
Where you grant permission, we receive data from your phone and from third-party health platforms and wearables you connect, including Apple Health, Google Fit and Health Connect, Garmin, Whoop, Fitbit, Oura and Strava. This may include:
- resting heart rate and heart rate during activity;
- heart rate variability;
- sleep duration, timing and stages;
- estimated VO2max;
- steps, distance, active energy and workout records;
- Bluetooth connections to fitness sensors you pair with the app.
You control these permissions in your device settings and can withdraw them at any time. Doing so will reduce or disable parts of the Service, including readiness scoring.
3.3 Information collected automatically
- Device and log data — IP address, device model and identifiers, operating system and version, app version, language, crash reports and diagnostic data.
- Usage data — which features you use, when, and for how long.
- Security data — authentication events, API request patterns and rate limiting records, used to detect abuse and unauthorised access.
3.4 Information from other sources
- Your gym or studio, where they create or manage your account or record sessions on your behalf.
- Payment providers, who confirm the status of a transaction. We do not receive or store your full card number.
- App stores, which confirm subscription and renewal status.
4. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (UK GDPR Art. 6) |
|---|---|---|
| Creating and managing your account, authenticating you | Account details, device data | Performance of a contract |
| Delivering training programmes, logging, and progress tracking | Training, nutrition, body measurement data | Performance of a contract |
| Calculating readiness and recovery scores | Resting heart rate, HRV, sleep, VO2max | Performance of a contract, plus explicit consent for the health data itself (see section 5) |
| Generating AI-assisted guidance and summaries | Pseudonymised training and health metrics | Performance of a contract, plus explicit consent for the health data itself |
| Taking payment and managing subscriptions | Billing records, transaction status | Performance of a contract; legal obligation for tax records |
| Providing support | Correspondence, account and usage data | Performance of a contract; legitimate interests in running a supported service |
| Securing the Service, preventing fraud, scraping and abuse | Security and log data | Legitimate interests in protecting the Service and its users |
| Understanding how the Service is used, fixing bugs, improving features | Aggregated and pseudonymised usage data | Legitimate interests in improving our product |
| Marketing emails about our products | Name, email | Consent, which you can withdraw at any time |
| Complying with legal obligations and responding to lawful requests | Whatever is required | Legal obligation |
| Protecting someone's life in an emergency | Whatever is required | Vital interests |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights. You can ask us for a summary of that assessment, and you can object to the processing.
5. Health data
Much of what Fittest processes — heart rate, heart rate variability, sleep, VO2max, body composition, nutrition and training records — is data concerning health. Under Article 9 of the UK GDPR this is special category data and needs an additional condition beyond the legal bases in section 4.
We rely on your explicit consent under Article 9(2)(a). We ask for this separately from your acceptance of our Terms of Service, when you create your account and again before you connect a health platform or wearable.
You can withdraw that consent at any time in your account settings or by emailing pd@fittestapp.co.uk. Withdrawal does not affect processing that already took place, but it will stop future processing and will disable the parts of the Service that depend on health data, including readiness scoring and AI-assisted guidance.
We do not process data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, or data concerning sexual orientation or sex life.
We keep a record of when and how you gave your consent, so we can demonstrate it if asked.
6. Who we share it with
We do not sell your personal data. We do not share health data with advertisers, data brokers, or business partners for their own marketing.
We share data with the following categories of recipient:
6.1 Service providers (sub-processors)
We keep this list short deliberately. Our database is run by us on our own infrastructure, and our analytics and crash reporting are self-hosted, so that data is not passed to any third party.
| Provider | What they do | What they receive | Location |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting for our application and database | All data stored in the Service, held on servers we manage. Hetzner does not access it. | Falkenstein and Nuremberg (Germany); Helsinki (Finland) |
| OpenAI, L.L.C. | AI-assisted guidance and summaries | Pseudonymised training and health metrics only, as described in section 7. No names, email addresses, account identifiers, photos or payment data. | United States |
| Stripe | Subscription billing | Billing and transaction data for gyms and studios that pay us. No End User health or training data. | United Kingdom |
| Amazon Web Services (Amazon SES) | Sending transactional and account emails | Email address and the content of the message sent to you. No health or training data. | United States (us-east-1) |
Each acts on our instructions under a written contract meeting Article 28 UK GDPR. Analytics, crash reporting and database hosting are handled in-house and involve no third party.
If we add or replace a sub-processor we will update this policy and, where the change is material, notify you in advance as described in section 15.
6.2 A coach or studio you have chosen to share with
Where you connect your account to a gym, studio or coach, we disclose the data you have chosen to share so they can coach you. This happens only on your instruction and stops when you disconnect. They act as an independent controller for what they do with that data, and their own privacy policy applies.
6.3 Others
- Professional advisers — accountants, insurers and lawyers, where necessary.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, including reporting suspected unauthorised access under the Computer Misuse Act 1990.
- A buyer or successor — if we are involved in a merger, acquisition or sale of assets. We will notify you before your data becomes subject to a different privacy policy.
7. Artificial intelligence
Parts of the Service use AI to generate training suggestions, nutrition guidance, progress summaries and conversational responses.
7.1 Who processes it
We use OpenAI, L.L.C. (United States) as our AI provider, under OpenAI's API terms and Data Processing Addendum. Data sent through OpenAI's API is not used to train OpenAI's models. We operate under zero data retention, so the data we send is used to generate the response and is not stored by OpenAI afterwards.
7.2 What we send
We minimise what leaves our systems. Before sending data to OpenAI we remove direct identifiers — your name, email address and account identifier are not transmitted. What is sent is limited to the metrics and context needed to generate the response, for example age band, recent training load, sleep duration and readiness inputs.
We do not send progress photos, payment details, contact details or support correspondence to any AI provider.
7.3 Limits of AI output
AI-generated guidance may be inaccurate or unsuitable for you. It is not medical or clinical advice and is not a substitute for a qualified professional. Always use your own judgement, and seek professional advice before acting on it where your health is concerned.
7.4 Your choices
Where AI features are optional you can turn them off in your account settings. Some parts of the Service will be reduced or unavailable if you do.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | For as long as your account is active, then deleted 30 days after closure |
| Training, nutrition and health data | For as long as your account is active, then deleted 30 days after closure, or immediately on request |
| Progress photos | Until you delete them, or 30 days after account closure |
| Billing and transaction records | 6 years from the end of the relevant accounting period (UK tax law) |
| Support correspondence | 2 years from resolution |
| Security and access logs | 12 months |
| Marketing preferences and suppression lists | Until you object, and a record of your objection indefinitely so we do not contact you again |
| Backups | We keep the three most recent daily backups, so deleted data disappears from backups within three days |
We also delete the data in a dormant account after 10 years without a login. We will warn you before we do, so you have the chance to log in and keep your history.
We may keep anonymised and aggregated data indefinitely. Once anonymised it can no longer be linked to you and is no longer personal data.
9. International transfers
Your data is stored on servers we manage in Hetzner's data centres in Falkenstein and Nuremberg (Germany) and Helsinki (Finland). These are inside the EEA, which the United Kingdom recognises as providing an adequate level of protection, so no additional safeguard is needed for that storage.
Two providers process data in the United States:
- OpenAI receives only the pseudonymised metrics described in section 7.
- Amazon Web Services (Amazon SES) processes our outgoing account and transactional emails in its us-east-1 region. This means your email address and the content of those messages are processed in the United States. No health or training data is included.
Where data leaves the UK, we rely on one of the following safeguards under Chapter V of the UK GDPR:
- UK adequacy regulations, where the destination country has been recognised as providing adequate protection — this includes the EEA;
- the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, backed by a transfer risk assessment. This is the basis on which we transfer to OpenAI in the United States;
- the UK Extension to the EU–US Data Privacy Framework, where the receiving organisation is certified under it.
You can request a copy of the safeguards we rely on by emailing pd@fittestapp.co.uk.
10. Security
We take appropriate technical and organisational measures to protect your data, including:
- encryption in transit using TLS, and encryption at rest for our databases and backups;
- hashed and salted password storage;
- role-based access control, with access to production data limited to staff who need it;
- rate limiting, bot detection and monitoring for scraping and unauthorised API access;
- logging of access to personal data;
- regular dependency patching and monthly security review.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and will notify you directly where the risk is high.
If you believe you have found a vulnerability, please report it to pd@fittestapp.co.uk rather than exploiting or publicising it.
11. Automated decision-making
Readiness scores, training suggestions and AI-generated guidance are produced automatically from your data. They are advisory. They do not produce legal effects concerning you and do not similarly significantly affect you, so they are not automated decision-making within the meaning of Article 22 UK GDPR. You, and where relevant your coach, remain in control of what you actually do.
If you want to understand how a score was calculated, contact us and we will explain the inputs used.
12. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data, where we no longer have a valid reason to keep it;
- restrict processing in certain circumstances;
- data portability — receive data you gave us in a structured, machine-readable format, or have it sent to another provider;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, including your explicit consent to health data processing;
- not be subject to solely automated decisions with legal or similarly significant effects.
To exercise any of these, email pd@fittestapp.co.uk or use the in-app export and delete tools in your account settings. We respond within one month, which we may extend by two further months for complex requests, telling you if we do. There is no charge unless a request is manifestly unfounded or excessive.
We may ask you to verify your identity before acting on a request.
Because we are the controller, you can bring any request straight to us — you do not need to go through your gym, studio or coach. If you have shared data with them and want them to erase their own copy, you will need to ask them separately.
13. Children
Fittest is not intended for anyone under 16 and we do not knowingly collect data from under-16s. If you believe a child has given us personal data, contact pd@fittestapp.co.uk and we will delete it.
14. Cookies and similar technologies
Our website uses cookies and similar technologies. Strictly necessary cookies, which keep you logged in and keep the site secure, are set without consent because the Service cannot work without them. Analytics and any non-essential cookies are set only if you consent through our cookie banner, and you can change your choice at any time through the cookie banner on our website.
Our mobile apps use device identifiers and SDKs for crash reporting and analytics, described in section 3.3. You can limit tracking through your device's privacy settings.
We do not currently respond to browser Do Not Track signals, as no common standard has been agreed.
15. Changes to this policy
We may update this policy. The date at the top shows when it last changed. Where a change is material — for example a new purpose, a new category of data, or a new AI provider — we will notify you in the app, or on the dashboard if you are a gym or studio, at least 30 days before it takes effect, and where the change relies on consent we will ask for that consent again.
Previous versions are available on request.
16. Contact and complaints
Fittest Tech Ltd
Flat 112 Alington House, 1 Mary Neuner Road
London, England, N8 0ES
pd@fittestapp.co.uk
If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint