Fitlyo. Coming soon

Privacy Policy

What data Fitlyo uses, why, where it is stored, and how you stay in control.

Version 1.0Updated: 2 October 2026
Document being finalised: highlighted items [[…]] will be completed before the app is released.

In short

  • Without an account, everything stays on your phone. With one, your data is backed up in Europe (Frankfurt).
  • Your health data (weight, measurements, photos, food…) is processed only with your explicit consent.
  • No targeted ads, no advertising trackers, no sale of data.
  • You delete your account and online data right in the app.

Who is responsible for your data?

The data controller is [[COMPANY NAME]], a [[LEGAL FORM]] with share capital of €[[CAPITAL]], registered with the [[CITY]] Trade and Companies Register under number [[RCS NUMBER]], whose registered office is at [[REGISTERED OFFICE ADDRESS]] (“Fitlyo”).

Privacy contact: [[PRIVACY EMAIL]]. Data Protection Officer (DPO): [[DPO NAME OR FIRM, DPO EMAIL]].

This policy applies to the Fitlyo app for iOS and Android and related services. It is complemented by the “Health data and consent” text.

The principle: your phone first

Fitlyo is designed “local first”: everything you enter is first saved in the app’s private storage on your device. Without an account, nothing is sent to our servers.

If you create an account, your data is synced with our servers so it is backed up and available on your other devices. Your progress photos stay on your phone: only their details (date, pose, weight that day) are synced. An encrypted cloud backup of photos is planned; it will be optional and require your consent.

Apple Health and Health Connect

If you turn it on in Profile › Health, Fitlyo exchanges some data with Apple Health (iPhone) or Health Connect (Android). Every option is off by default and only asks for permission when you turn it on; you can withdraw it at any time in Fitlyo or in your phone’s settings.

  • Write: your finished workouts (type, duration, estimated energy), weigh-ins entered in Fitlyo, and the calories and macronutrients of your food log.
  • Read: your weight, steps, active energy for the last 7 days and last night’s sleep (to pre-fill the check-in).

Steps, active energy and sleep that are read stay only on your phone. Imported weigh-ins join your Fitlyo weigh-ins: with an account they are synced like the others (legal basis: your explicit consent to health data). Data from Apple Health and Health Connect is never used for advertising, sold or shared with third parties, and only powers the tracking features you see in the app.

The data we process

CategoryExamplesWhen
AccountFirst name, email address, password (stored irreversibly hashed), Apple or Google identifier if you use them, account IDAccount creation
Session and securitySession token, IP address and device type at sign-in, server technical logsUse with an account
Training profileGoal, level, training place and equipment, training days and session length, exercises to avoid, birth year, sex, heightOnboarding and profile
TrainingWorkouts, sets, loads, reps, records, programmes created or followed, favourites, notesUse
Health dataWeight, body fat, measurements, sleep, energy, stress, fatigue, soreness, pain, readiness score, progress photos and their detailsIf you enter them
NutritionMeal diary, quantities, calories and nutrients, water, caffeine, supplements, fasting, Ramadan mode, preferences (vegetarian, gluten-free…), meal plans, shopping listIf you turn on nutrition
Meal analysisPhoto or description of a meal, corrections you makeIf you use this feature
PurchasesPremium status, programmes bought, purchase identifier sent by the store (never your card details)Purchase
CoachesPublic name, bio, specialties, qualification and its copy, professional status, sales; identity and IBAN are collected directly by StripeCoach application
SocialFriends, shared workouts, messages, reviews, reportsWhen these features become available
SupportYour exchanges with usIf you write to us
Much of this data is health data under Article 9 GDPR. Some preferences (Ramadan mode, diet) may also reveal religious beliefs or a health condition. We treat them as sensitive data: only with your explicit consent, never for advertising.

We do not collect: your location, your contacts, your advertising identifier, or your biometric data (Face ID and fingerprint are handled by your phone; Fitlyo only receives “unlocked” or “refused”). The camera is used for barcode scanning and photos, only when you open it.

Why, and on what legal basis

PurposeLegal basis (GDPR)
Create and manage your account, back up and sync your data, provide the featuresPerformance of the contract (Art. 6(1)(b))
Process your health and nutrition data, including on our serversExplicit consent (Art. 9(2)(a) and 6(1)(a))
Progress photos and their cloud backup (when available)Explicit consent (Art. 9(2)(a))
Automatic analysis of a meal photo or descriptionExplicit consent to health data, with clear information before the first upload (Art. 9(2)(a))
Improve our analysis models with your meal photos and corrections (optional)Separate explicit consent (Art. 9(2)(a))
Share your workouts, weight and measurements with your coach (optional)Separate explicit consent (Art. 9(2)(a))
Reminders and notificationsConsent (your phone’s permission), withdrawable at any time
Premium subscription, programme purchases, coach payoutsPerformance of the contract (Art. 6(1)(b))
Invoicing, accounting, platform tax reportingLegal obligation (Art. 6(1)(c))
Security, fraud and abuse prevention, moderation of social featuresLegitimate interest (Art. 6(1)(f)): protecting the Service and its users
Coach verificationPerformance of the contract and legitimate interest (user safety)
Support and answering your requestsPerformance of the contract or legitimate interest
Defending our rights in a disputeLegitimate interest

We do not use your data for targeted advertising, we do not sell it, and we make no automated decisions with legal effects on you. Recommendations (loads, calories) are helper calculations you can always change.

Who has access

Only authorised Fitlyo staff access it, when needed (support, security). We use processors bound by contract (Article 28 GDPR) who do not use your data for their own purposes:

ProviderRoleData location
Vercel Inc.Hosting of our API (Frankfurt servers)EU (Germany); US company
Neon Inc. (Databricks)Account and sync databaseEU (Frankfurt, AWS eu-central-1); US company
Cloudflare Inc.File storage (backed-up photos, coach documents) and delivery of exercise animations[[EU (EU jurisdiction R2 bucket) TO CONFIRM]]; US company
Hugging Face Inc.One-time download of the meal analysis model. Analysis then runs on your phone: no meal photo or description is ever sent; only your IP address is seen during the downloadUnited States (download only)
RevenueCat Inc. (soon)Subscription and in-app purchase managementUnited States
Stripe Payments Europe Ltd (soon)Coach payouts, coach identity verificationIreland / EU
OVH SASSending account emails (verification, forgotten password, deletion confirmation) from fitlyo@rs-digital.frEU (France)

Some recipients act as independent controllers, under their own policies:

  • Apple and Google: app download, payments, “Sign in with Apple / Google” if you choose it;
  • Open Food Facts (French non-profit): when you scan a barcode or search for a product, the request (barcode or search text) goes directly from your phone to their servers, with your IP address, without any account data;
  • Your coach, only if you turned on sharing;
  • Your friends, for what you choose to share in social features;
  • administrative or judicial authorities, upon lawful request.

Transfers outside the European Union

Our data is stored in the European Union. Several providers are however US companies, which may access it for maintenance or be subject to US law. These transfers rely on the EU-US Data Privacy Framework adequacy decision of 10 July 2023 for certified companies and, failing that, on the European Commission’s Standard Contractual Clauses (Decision 2021/914), with additional security measures (encryption in transit and at rest, restricted access).

You can get a copy of these safeguards by writing to [[PRIVACY EMAIL]].

How long

DataPeriod
Data on your phoneUntil you erase it (Profile › Reset) or delete the app
Account and synced dataWhile the account is active; erased immediately when the account is deleted, then removed from technical backups within [[7]] days
Inactive accountDeleted after [[3]] years without sign-in, after a notice email
Photos and descriptions sent for meal analysisProcessed on the fly and not kept by Fitlyo; [[RETENTION AT THE AI PROVIDER]]; daily usage counter kept [[90]] days
Model-improvement data (if you agreed)Until you withdraw consent, at most [[3]] years
Technical and security logs[[30]] days maximum, unless there is an incident
Proof of your consentsDuration of processing + 5 years
Invoices and transaction data10 years (accounting obligation, Article L123-22 of the French Commercial Code)
Coach file (qualification, status)Duration of coach activity + 5 years
Support exchanges3 years after the last exchange

Your rights

  • Access: get a copy of your data.
  • Rectification: correct your data, most of it directly in the app.
  • Erasure: delete your account and all your online data from Profile › Account and backup › Delete my account, or ask us.
  • Portability: receive your data in a structured, machine-readable format (JSON), directly from Profile › Account & backup › Export my data, or on request.
  • Withdraw consent: at any time in Profile › Legal and privacy › My consents, without affecting past processing.
  • Object to processing based on our legitimate interest, and restrict processing.
  • Post-mortem instructions: decide what happens to your data after your death (Article 85 of the French Data Protection Act).

Write to [[PRIVACY EMAIL]] from your account’s email address. We reply within one month, extendable by two months for complex requests; we may ask you to confirm your identity.

You can lodge a complaint with the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France · https://www.cnil.fr) or with the data protection authority of your country of residence.

Minors

Fitlyo is reserved for people aged 16 and over. We do not knowingly collect data about younger people. If you believe a child under 16 has given us data, write to [[PRIVACY EMAIL]]: we will delete it.

Security

  • Encrypted connections (HTTPS/TLS) between the app and our servers; data encrypted at rest by our hosts.
  • Passwords never stored in clear (irreversible hashing); session token kept in the phone’s secure storage (Keychain / Keystore).
  • Each account only accesses its own data; files are stored per account and only open through temporary links.
  • Progress photos stored in the app’s private space, with optional Face ID / fingerprint lock.
  • Limited, logged internal access, and a procedure to notify the CNIL and the people concerned in case of a data breach.

Since no system is infallible, also protect your phone (passcode, updates) and choose a unique password.

Cookies and trackers

The app uses no advertising cookies, no audience-measurement tool and no third-party tracking SDK, and does not access your advertising identifier. The only “tracker” is the session token needed to keep you signed in, which is strictly necessary for the service and therefore exempt from consent.

If we ever add an audience-measurement or crash-reporting tool, we will update this policy and ask for your consent where the law requires it.

Changes

We may update this policy. The update date is shown at the top of the document. For a significant change (new purpose, new recipient), we inform you in the app before it applies and, where needed, ask for your consent again.