Privacy Policy

Last updated: February 8, 2026

1. Introduction

FitTracker ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform.

2. Information We Collect

We collect the following types of information:

Account information: email address, name, and password (hashed). If you sign in with Google, we receive your Google profile name and email.

Training data: client names, session notes, exercises, weights, reps, and sets that you enter into the platform.

Payment information: processed and stored by Stripe. We do not store credit card numbers. We store your Stripe customer ID for subscription management.

Device fingerprint: a browser-generated identifier used solely to prevent abuse of the free trial system. It is not used for tracking or advertising.

Usage data: AI credit consumption and transaction history for billing purposes.

3. How We Use Your Information

We use your information to: provide and operate the Service; parse training notes using AI; generate metrics and analytics; process payments and manage subscriptions; prevent abuse and enforce our terms; send transactional emails (verification, password reset, receipts).

4. Third-Party Services

We share data with the following third parties, solely to provide the Service:

OpenAI: training notes and chat queries are sent to OpenAI's API (GPT-4o-mini) for parsing and answering questions. OpenAI's data usage policy applies to this processing.

Stripe: payment and billing information is processed by Stripe. See Stripe's privacy policy for details.

Resend: email addresses are shared with Resend for sending transactional emails (verification, password reset).

Google: if you use Google sign-in, authentication is handled by Google OAuth2. We receive only your name and email.

We do not sell your data. We do not use your data for advertising.

5. Data Processing Agreements

We have ensured that our third-party service providers process your data in compliance with applicable data protection laws. OpenAI processes data under their Data Processing Addendum (DPA). Stripe operates as a data processor under their DPA and is PCI DSS compliant. Resend processes email data under their terms of service. All data transfers to US-based providers are covered under applicable transfer mechanisms.

6. Data Storage & Security

Your data is stored in a PostgreSQL database on self-hosted infrastructure. Passwords are hashed using bcrypt. API keys are encrypted using Fernet symmetric encryption. All communications use HTTPS. Tenant isolation ensures no trainer can access another trainer's data.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, all associated data is permanently removed, including clients, sessions, exercises, files, fingerprints, and transaction history. Stripe may retain payment records independently per their own policies.

8. Your Rights

You have the right to: access your data through the platform; correct your information via your profile; delete your account and all data at any time; export is not currently available but is planned. If you are in the EU/EEA, you may have additional rights under GDPR. Contact us to exercise these rights.

9. Cookies

FitTracker uses localStorage to store authentication tokens and theme preferences. We do not use tracking cookies, analytics cookies, or any third-party cookies. No cookie consent banner is required.

10. Children's Privacy

The Service is not intended for users under 18. We do not knowingly collect data from minors. If we become aware that a minor has created an account, we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be indicated by updating the date at the top of this page. Continued use of the Service constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions, contact us at [email protected].