FiTAi PRO

Privacy Policy

Last updated: 17 July 2026

RomânăEnglishDeutsch

1. Who is responsible

Data controller (Art. 4(7) GDPR): The FiTAi PRO Team Germany Email: [email protected] We have not appointed a data protection officer, as we do not meet the criteria of Art. 37 GDPR. For any matter concerning your data, write to the address above or use More → Contact & support.

2. What data we collect

Account data: email address, display name, password (stored only as a bcrypt hash, never in plain text) or your Google identifier if you use Sign in with Google. Profile data: age, sex, height, current and target weight, fitness goal, number of training days, training location and available equipment. Usage data: recorded workouts (exercises, sets, weights, durations), logged meals, water intake, your custom programmes. Photos: progress photos stay on your phone. Photos published in the community are uploaded to Cloudinary. Device identifier: a randomly generated code stored locally, used for rate limiting and abuse prevention. It is not an advertising identifier and does not allow identification of a person. We do not collect: location data, contacts, advertising identifiers, browsing history. We do not use tracking cookies and do not display ads.

3. Health data — special category

Your weight, height, fitness goals, food allergies and recorded workouts may constitute health data, i.e. a special category under Art. 9 GDPR. We process them solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by voluntarily completing your profile. You may withdraw consent at any time by deleting your account. This data is used only to generate your plans and is never sold, rented or used for advertising.

4. Why we process data and on what basis

Performance of contract (Art. 6(1)(b) GDPR): creating and managing your account, authentication, providing the App's features, saving your workouts and meals, activating Premium. Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR): processing health data from your profile to generate personalised plans; publishing in the community. Legitimate interest (Art. 6(1)(f) GDPR): abuse and fraud prevention, rate limiting, server security, fixing errors. Our interest is maintaining a functional and secure service. Legal obligation (Art. 6(1)(c) GDPR): retaining certain data where required by law.

5. Artificial intelligence and your data

When you generate a plan, ask the AI Coach a question, or scan food or equipment, we send the necessary data to Anthropic PBC (United States), the provider of the Claude model. Transmitted: relevant profile data (age, sex, height, weight, goal), food preferences and allergies, the text of your questions, and the photos you scan. We do NOT transmit: your name, email address or device identifier. Anthropic processes this data as a processor under a data processing agreement and does not use it to train its models. Details: anthropic.com/privacy

6. Who else receives the data

We use the following providers, each as a processor under data processing agreements pursuant to Art. 28 GDPR: • Railway Corp. (USA) — server and database hosting • Anthropic PBC (USA) — AI content generation • Cloudinary Ltd. (Israel/USA) — hosting of community images • Resend (USA) — sending emails (welcome, password reset, contact); processing region: Ireland • Google Ireland Ltd. — Google Sign-In authentication and distribution via Google Play We do not sell, rent or exchange personal data with anyone. We do not transmit data to data brokers or advertising networks.

7. Transfers outside the EU

Some providers are established in the United States. Transfers are based on the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, where applicable, on certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Please note that despite these safeguards, authorities in third countries may under certain conditions have rights of access to data, and the level of protection may not be identical to that in the EU.

8. How long we keep data

Account and profile data: for as long as your account exists. When you delete your account, it is permanently removed from our database, immediately. Data stored locally on your phone (workouts, meals, progress photos, plans): remain on the device until you delete them or uninstall the App. We cannot access or delete them remotely. Community posts: until you delete them or delete your account. Used promotional codes: we keep the code-account link even after account deletion, strictly to prevent reuse of the same code. They contain no profile data. Backups: overwritten in the normal cycle, within 30 days at most. Emails sent to support: maximum 12 months.

9. Your rights

Under the GDPR, you have the following rights: • Access (Art. 15) — to know what data we hold about you • Rectification (Art. 16) — to correct inaccurate data; you can edit your profile directly in the App • Erasure (Art. 17) — the "right to be forgotten"; you can delete your account under More → Delete account • Restriction (Art. 18) — to limit processing in certain situations • Portability (Art. 20) — to receive your data in a structured, machine-readable format • Objection (Art. 21) — to object to processing based on legitimate interest • Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of prior processing To exercise these rights, write to [email protected] or use More → Contact & support. We respond within one month at the latest.

10. Right to lodge a complaint

If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority — in particular in the Member State where you live, where you work, or where the alleged infringement took place (Art. 77 GDPR). The authority competent for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany www.lda.bayern.de

11. Data security

All communication between the App and our servers is encrypted via HTTPS/TLS. Passwords are stored solely as bcrypt hashes — not even we can read them. Database access is restricted and credential-protected. We apply request rate limiting and temporary account lockout after repeated failed login attempts. Nevertheless, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. If a breach occurs that puts your rights at risk, we will inform you in accordance with Art. 34 GDPR.

12. Children

The App is not directed at persons under 16 and we do not knowingly collect their data. If you become aware that a child under 16 has provided us with data, contact us and we will delete it without delay.

13. Automated decision-making

Workout and nutrition plans are generated automatically based on your profile data. These are informational recommendations and do not produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR. We do not carry out profiling for advertising purposes and do not make automated decisions with legal effect on you.

14. Changes to this policy

We may update this policy when the App's features or legal requirements change. The date of the last update appears at the top. Substantial changes will be communicated in the App or by email before taking effect.

15. Contact

For any question regarding your personal data: The FiTAi PRO Team Germany [email protected] or More → Contact & support in the App.