Privacy Policy
What data Fitlyo uses, why, where it is stored, and how you stay in control.
In short
- Without an account, everything stays on your phone. With one, your data is backed up in Europe (Frankfurt).
- Your health data (weight, measurements, photos, food…) is processed only with your explicit consent.
- No targeted ads, no advertising trackers, no sale of data.
- You delete your account and online data right in the app.
Who is responsible for your data?
The data controller is [[COMPANY NAME]], a [[LEGAL FORM]] with share capital of €[[CAPITAL]], registered with the [[CITY]] Trade and Companies Register under number [[RCS NUMBER]], whose registered office is at [[REGISTERED OFFICE ADDRESS]] (“Fitlyo”).
Privacy contact: [[PRIVACY EMAIL]]. Data Protection Officer (DPO): [[DPO NAME OR FIRM, DPO EMAIL]].
This policy applies to the Fitlyo app for iOS and Android and related services. It is complemented by the “Health data and consent” text.
The principle: your phone first
Fitlyo is designed “local first”: everything you enter is first saved in the app’s private storage on your device. Without an account, nothing is sent to our servers.
If you create an account, your data is synced with our servers so it is backed up and available on your other devices. Your progress photos stay on your phone: only their details (date, pose, weight that day) are synced. An encrypted cloud backup of photos is planned; it will be optional and require your consent.
Apple Health and Health Connect
If you turn it on in Profile › Health, Fitlyo exchanges some data with Apple Health (iPhone) or Health Connect (Android). Every option is off by default and only asks for permission when you turn it on; you can withdraw it at any time in Fitlyo or in your phone’s settings.
- Write: your finished workouts (type, duration, estimated energy), weigh-ins entered in Fitlyo, and the calories and macronutrients of your food log.
- Read: your weight, steps, active energy for the last 7 days and last night’s sleep (to pre-fill the check-in).
Steps, active energy and sleep that are read stay only on your phone. Imported weigh-ins join your Fitlyo weigh-ins: with an account they are synced like the others (legal basis: your explicit consent to health data). Data from Apple Health and Health Connect is never used for advertising, sold or shared with third parties, and only powers the tracking features you see in the app.
The data we process
| Category | Examples | When |
|---|---|---|
| Account | First name, email address, password (stored irreversibly hashed), Apple or Google identifier if you use them, account ID | Account creation |
| Session and security | Session token, IP address and device type at sign-in, server technical logs | Use with an account |
| Training profile | Goal, level, training place and equipment, training days and session length, exercises to avoid, birth year, sex, height | Onboarding and profile |
| Training | Workouts, sets, loads, reps, records, programmes created or followed, favourites, notes | Use |
| Health data | Weight, body fat, measurements, sleep, energy, stress, fatigue, soreness, pain, readiness score, progress photos and their details | If you enter them |
| Nutrition | Meal diary, quantities, calories and nutrients, water, caffeine, supplements, fasting, Ramadan mode, preferences (vegetarian, gluten-free…), meal plans, shopping list | If you turn on nutrition |
| Meal analysis | Photo or description of a meal, corrections you make | If you use this feature |
| Purchases | Premium status, programmes bought, purchase identifier sent by the store (never your card details) | Purchase |
| Coaches | Public name, bio, specialties, qualification and its copy, professional status, sales; identity and IBAN are collected directly by Stripe | Coach application |
| Social | Friends, shared workouts, messages, reviews, reports | When these features become available |
| Support | Your exchanges with us | If you write to us |
We do not collect: your location, your contacts, your advertising identifier, or your biometric data (Face ID and fingerprint are handled by your phone; Fitlyo only receives “unlocked” or “refused”). The camera is used for barcode scanning and photos, only when you open it.
Why, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account, back up and sync your data, provide the features | Performance of the contract (Art. 6(1)(b)) |
| Process your health and nutrition data, including on our servers | Explicit consent (Art. 9(2)(a) and 6(1)(a)) |
| Progress photos and their cloud backup (when available) | Explicit consent (Art. 9(2)(a)) |
| Automatic analysis of a meal photo or description | Explicit consent to health data, with clear information before the first upload (Art. 9(2)(a)) |
| Improve our analysis models with your meal photos and corrections (optional) | Separate explicit consent (Art. 9(2)(a)) |
| Share your workouts, weight and measurements with your coach (optional) | Separate explicit consent (Art. 9(2)(a)) |
| Reminders and notifications | Consent (your phone’s permission), withdrawable at any time |
| Premium subscription, programme purchases, coach payouts | Performance of the contract (Art. 6(1)(b)) |
| Invoicing, accounting, platform tax reporting | Legal obligation (Art. 6(1)(c)) |
| Security, fraud and abuse prevention, moderation of social features | Legitimate interest (Art. 6(1)(f)): protecting the Service and its users |
| Coach verification | Performance of the contract and legitimate interest (user safety) |
| Support and answering your requests | Performance of the contract or legitimate interest |
| Defending our rights in a dispute | Legitimate interest |
We do not use your data for targeted advertising, we do not sell it, and we make no automated decisions with legal effects on you. Recommendations (loads, calories) are helper calculations you can always change.
Who has access
Only authorised Fitlyo staff access it, when needed (support, security). We use processors bound by contract (Article 28 GDPR) who do not use your data for their own purposes:
| Provider | Role | Data location |
|---|---|---|
| Vercel Inc. | Hosting of our API (Frankfurt servers) | EU (Germany); US company |
| Neon Inc. (Databricks) | Account and sync database | EU (Frankfurt, AWS eu-central-1); US company |
| Cloudflare Inc. | File storage (backed-up photos, coach documents) and delivery of exercise animations | [[EU (EU jurisdiction R2 bucket) TO CONFIRM]]; US company |
| Hugging Face Inc. | One-time download of the meal analysis model. Analysis then runs on your phone: no meal photo or description is ever sent; only your IP address is seen during the download | United States (download only) |
| RevenueCat Inc. (soon) | Subscription and in-app purchase management | United States |
| Stripe Payments Europe Ltd (soon) | Coach payouts, coach identity verification | Ireland / EU |
| OVH SAS | Sending account emails (verification, forgotten password, deletion confirmation) from fitlyo@rs-digital.fr | EU (France) |
Some recipients act as independent controllers, under their own policies:
- Apple and Google: app download, payments, “Sign in with Apple / Google” if you choose it;
- Open Food Facts (French non-profit): when you scan a barcode or search for a product, the request (barcode or search text) goes directly from your phone to their servers, with your IP address, without any account data;
- Your coach, only if you turned on sharing;
- Your friends, for what you choose to share in social features;
- administrative or judicial authorities, upon lawful request.
Transfers outside the European Union
Our data is stored in the European Union. Several providers are however US companies, which may access it for maintenance or be subject to US law. These transfers rely on the EU-US Data Privacy Framework adequacy decision of 10 July 2023 for certified companies and, failing that, on the European Commission’s Standard Contractual Clauses (Decision 2021/914), with additional security measures (encryption in transit and at rest, restricted access).
You can get a copy of these safeguards by writing to [[PRIVACY EMAIL]].
How long
| Data | Period |
|---|---|
| Data on your phone | Until you erase it (Profile › Reset) or delete the app |
| Account and synced data | While the account is active; erased immediately when the account is deleted, then removed from technical backups within [[7]] days |
| Inactive account | Deleted after [[3]] years without sign-in, after a notice email |
| Photos and descriptions sent for meal analysis | Processed on the fly and not kept by Fitlyo; [[RETENTION AT THE AI PROVIDER]]; daily usage counter kept [[90]] days |
| Model-improvement data (if you agreed) | Until you withdraw consent, at most [[3]] years |
| Technical and security logs | [[30]] days maximum, unless there is an incident |
| Proof of your consents | Duration of processing + 5 years |
| Invoices and transaction data | 10 years (accounting obligation, Article L123-22 of the French Commercial Code) |
| Coach file (qualification, status) | Duration of coach activity + 5 years |
| Support exchanges | 3 years after the last exchange |
Your rights
- Access: get a copy of your data.
- Rectification: correct your data, most of it directly in the app.
- Erasure: delete your account and all your online data from Profile › Account and backup › Delete my account, or ask us.
- Portability: receive your data in a structured, machine-readable format (JSON), directly from Profile › Account & backup › Export my data, or on request.
- Withdraw consent: at any time in Profile › Legal and privacy › My consents, without affecting past processing.
- Object to processing based on our legitimate interest, and restrict processing.
- Post-mortem instructions: decide what happens to your data after your death (Article 85 of the French Data Protection Act).
Write to [[PRIVACY EMAIL]] from your account’s email address. We reply within one month, extendable by two months for complex requests; we may ask you to confirm your identity.
Minors
Fitlyo is reserved for people aged 16 and over. We do not knowingly collect data about younger people. If you believe a child under 16 has given us data, write to [[PRIVACY EMAIL]]: we will delete it.
Security
- Encrypted connections (HTTPS/TLS) between the app and our servers; data encrypted at rest by our hosts.
- Passwords never stored in clear (irreversible hashing); session token kept in the phone’s secure storage (Keychain / Keystore).
- Each account only accesses its own data; files are stored per account and only open through temporary links.
- Progress photos stored in the app’s private space, with optional Face ID / fingerprint lock.
- Limited, logged internal access, and a procedure to notify the CNIL and the people concerned in case of a data breach.
Since no system is infallible, also protect your phone (passcode, updates) and choose a unique password.
Cookies and trackers
The app uses no advertising cookies, no audience-measurement tool and no third-party tracking SDK, and does not access your advertising identifier. The only “tracker” is the session token needed to keep you signed in, which is strictly necessary for the service and therefore exempt from consent.
If we ever add an audience-measurement or crash-reporting tool, we will update this policy and ask for your consent where the law requires it.
Changes
We may update this policy. The update date is shown at the top of the document. For a significant change (new purpose, new recipient), we inform you in the app before it applies and, where needed, ask for your consent again.