1. TL;DR
- We collect the minimum needed to sign you in and run the app.
- We do not sell your data and we do not run advertising or third-party ad SDKs.
- You can delete your account and all associated data from inside the app at any time.
- Questions? Email nirv@fitfo.app.
2. Who we are
“Fitfo,” “we,” “us,” and “our” refer to Vaayu Athletics LLC, a US-based company that operates the Fitfo mobile app and the website at fitfo.app. You can reach us at nirv@fitfo.app.
3. What we collect
Fitfo collects only the information needed to authenticate you and operate the app. That includes:
- Account & contact info. Your phone number (if you sign in with SMS) or your name and email (if you use Sign in with Apple). If Apple relays a private email, that private relay is what we store.
- Profile & onboarding. Goals, training split, days per week, weight, height, experience level, and age that you enter during onboarding.
- Workout content. Workouts you save, schedule, or create; sessions you log (sets, reps, weights, durations, notes, completion timestamps); body-weight entries you record.
- Source URLs. TikTok and Instagram Reel URLs you share into the app for import, plus the extracted metadata and transcript we generate from them.
- Device identifiers.A user ID we assign to your account. We do not use Apple's advertising identifier (IDFA) and do not integrate any advertising SDKs.
- Apple Sign-In refresh token. If you signed in with Apple, we store the refresh token solely so we can revoke the token with Apple when you delete your account, as required by App Store Guideline 5.1.1(v).
What we do not collect
- We do not collect precise or coarse location, contacts, photos, videos, microphone audio, health data from HealthKit, or any sensitive personal information.
- We do not run advertising SDKs, analytics SDKs, crash reporters, or third-party tracking SDKs in the iOS app.
4. How we use your information
- Authenticate you via SMS one-time codes or Sign in with Apple.
- Store and display the workouts, sessions, and notes you create.
- Process the TikTok and Instagram URLs you submit by fetching public metadata, transcribing audio, and running OCR on a small number of frames so we can extract exercise data.
- Respond to support requests.
- Protect against abuse and comply with legal obligations.
We never use your data for advertising, profiling for third-party advertisers, or sale to data brokers.
5. Third-party services (sub-processors)
We use a small number of reputable vendors to run the app. Each processes only the data needed for its specific function:
- Supabase, database and file storage for profiles, workouts, and session logs (hosted on AWS in the United States).
- Twilio Verify, sending SMS one-time verification codes to your phone number.
- Apple, Sign in with Apple authentication and refresh-token revocation when you delete your account.
- Apify, fetching public metadata from TikTok and Instagram URLs you submit.
- OpenAI, running transcription, OCR, and language-model processing on the video, audio, and text extracted from videos you submit.
- DigitalOcean, hosting our API servers.
These providers are contractually required to handle data only on our behalf and in line with their own privacy terms. We do not sell data to any of them.
6. How long we keep data
We keep your data for as long as your account is active. When you delete your account (Profile → Delete Account inside the app) we immediately and permanently remove your profile, workouts, sessions, and body-weight entries from Supabase. Some server logs or backups may persist for up to 30 days before being fully expunged.
7. Your rights
You can, at any time:
- Accessor export your data. Email us and we'll send you a copy within 30 days.
- Correct inaccurate data. Most fields are editable directly inside the app.
- Delete your account and all associated data. Use Profile → Delete Account inside the app, or email us.
- Object to processing or withdraw consent. Simply stop using the app and request deletion.
Residents of California (CCPA/CPRA), the EEA / UK (GDPR), and other jurisdictions with equivalent laws are entitled to the same rights above without charge. We do not sell or share personal information for cross-context behavioral advertising.
8. Children
Fitfo is not directed to children under 13 and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us data, email us and we'll delete it.
9. International transfers
Our servers and sub-processors are primarily located in the United States. If you access Fitfo from outside the US, you consent to your data being transferred to and processed in the US under the safeguards described in this policy.
10. Security
All traffic between your device and our servers uses HTTPS/TLS. Stored data is encrypted at rest by our infrastructure providers. Access to production data is limited to a small number of engineers using least-privilege credentials. No method of transmission or storage is perfectly secure, but we work hard to treat your data with the same care we'd want for our own.
11. Third-party content (TikTok / Instagram videos)
Fitfo does not host or redistribute third-party video content. When you share a TikTok or Instagram video into Fitfo, we fetch public metadata, transcribe audio, and run OCR on frames to extract factual exercise information (names, sets, reps, rest). We always link back to the original post inside the app via the “View on TikTok” or “View on Instagram” button. Creators who want their content excluded from the service can email nirv@fitfo.appwith the URL and we'll remove it.
12. Subscriptions, billing, refunds, and App Store purchases
If Fitfo offers paid plans or trials, they are processed by Apple through In-App Purchase. Pricing, trial length, renewal, and cancellation are shown at checkout and in your Apple ID subscription settings. Refund requestsgenerally go through Apple’s support tools (for example “Report a Problem”), not by charging your card directly on our site. We do not receive or store your full card number.
If we materially change subscription benefits or pricing, we will describe the change in the app or on this site where practical, consistent with App Store guidelines.
13. Apple App Tracking Transparency (ATT) and advertising
Fitfo does not run third-party advertising SDKs or sell your personal information for cross-context behavioral advertising. We do not use the Identifier for Advertisers (IDFA) to track you across other companies’ apps or websites for ads. If we introduce optional analytics that could trigger an Apple privacy prompt in the future, we will describe it here and in the app before enabling it.
14. Changes to this policy
We'll update this page if our practices change. The effective date at the top reflects the latest version. Material changes will be communicated via the app or via email before they take effect.
15. Contact
Questions, requests, or concerns about your data? Email nirv@fitfo.app. We read every message and respond within one business day.
