FitVoya logoFitVoya
Back

FitVoya · Legal & privacy center

Privacy policy

Draft version · 11 October 2026

1. Scope and responsible party

This draft explains FitVoya’s current data flows and separates planned features from existing ones. Information about fitness, body composition and diet can be sensitive health information. The legal controller/operator name, postal address and privacy contact are missing; this policy cannot serve as a complete statutory collection notice until those details and the remaining arrangements are supplied.

2. Information you provide

Account information includes email, authentication identifiers and display name; email/password sign-up uses an authentication service. Optional profile fields include date of birth, sex, height, goal and activity preferences. Records may include weight, body fat, strength exercises, sets/reps/weights, dates, notes, goals, food names and calories, logged activity/calorie burn, steps and progress photos. Coach relationships, permissions, workout plans, completion checks, reminder messages and notifications are also stored. Avoid adding unnecessary sensitive details or other people’s information to free text or photos. Core account information is needed to sign in; optional health fields can be left blank, but related calculations and features will then be unavailable.

3. Information from devices and sign-in

Google sign-in supplies the identity information authorized in Google’s sign-in flow, such as account ID, email and profile information; it does not authorize access to your mailbox. In the browser, motion access can be used to estimate steps while the page is open. The native app integration, when available and authorized, reads daily steps from Apple Health or Health Connect and saves daily totals in your account, making them subject to the coach/friend access described below. It does not currently request all health-store records. Health permissions can be revoked in device settings. Denying access disables the related feature. Device sensors and health-store results can be incomplete or inaccurate.

4. Purposes and legal basis

Data is used to authenticate accounts, save and display records, calculate estimates, implement chosen sharing and coach links, send scheduled in-app reminders, protect the service and understand feature usage. Depending on applicable law, ordinary account processing may rely on providing the requested service and security processing on a documented legitimate interest. Health data may require explicit consent or another valid special-category condition; guardian consent may also be required. These legal bases and separate consent mechanisms must be validated and implemented before this policy is finalized. Publishing this policy or signing in is not itself explicit health-data consent. Future marketing or AI processing cannot rely on a blanket acceptance of this draft.

5. Friends, coaches and downloaded copies

Records are private from other users by default. Approved friends can read only enabled shared metrics, photos and notes. An approved active coach can read all trainee health/fitness records, including photos, nutrition and step totals, regardless of friend-sharing switches; coaches may edit permitted fields and see group averages. Requests can be declined and links removed. Disconnecting prevents further linked access but does not erase lawful records, notes or downloads the recipient already holds. A coach may have independent privacy obligations; ask how they handle your information. Before/after downloads and other external sharing are controlled by the recipient’s service, not by FitVoya.

6. Service providers and technical records

External cloud infrastructure providers support accounts, databases and photo storage. An external identity provider participates when you choose social sign-in; an external font service is loaded for typography and can receive connection information such as IP address. Hosting, authentication and error-monitoring systems may process request/device metadata, timestamps and diagnostic information. FitVoya’s usage analytics record account-linked event names and activity timestamps, not health values; administrator screens show account information and aggregates rather than individual health diaries. Service-provider access remains possible for authorized operation and support and is not ruled out by “private by default.” A definitive processor list, contracts, hosting locations and diagnostic-retention schedule still need verification. No advertising trackers or payments/AI providers are currently integrated into these described features.

7. International transfers and security

Cloud providers may process information outside your country. Actual locations, subprocessors and the safeguards required for transfers, including EU transfer mechanisms where applicable, must be confirmed and disclosed; this draft does not claim that data stays in Israel or that standard contractual clauses already exist. Access controls restrict account data and approved sharing, but no system can guarantee absolute security. Authorized operational access, incident procedures and compliance with applicable Israeli information-security rules must be maintained. Where required, breaches must be notified to the authority and affected people under the applicable deadlines.

8. Retention and deletion

Journal, profile, photo, relationship and plan data are retained to provide the service; a complete retention schedule and deletion procedure, including backups and orphaned files, have not yet been finalized. A 13-month usage-analytics retention limit is planned but automatic enforcement was not verified; in-app notifications are deleted by the scheduled reminder process after 90 days. These are feature-specific settings, not a promise that every copy disappears at once. Signing out, hiding photos or disconnecting a coach does not delete your account. You can remove supported individual records in the app, but no complete self-service account deletion or export tool is currently provided. A verified request channel and a process for handling access, export and deletion must be made available before finalization. Any legally necessary retention must be limited and explained.

9. Your rights and young users

Depending on applicable law, you may request access, correction, erasure, restriction, portability, object to certain processing or withdraw consent, and complain to the relevant privacy authority. Israeli law provides rights including inspection and correction subject to its conditions; EU/UK rights apply where those laws govern. Withdrawal does not make earlier lawful processing unlawful, but may make optional features unavailable. Requests require proportionate identity verification, not unnecessary identity documents. Teenagers are part of the intended audience, but minimum age, age checks, guardian authority and consent records are not implemented as a completed process. In the EU the online-consent threshold varies by country between 13 and 16; it is not a universal minimum age. Minors should not rely on adult calorie/BMI guidance.

10. Future development and updates

Planned AI meal scans, premium trend analysis, reports, subscriptions and phone push notifications will require purpose-specific disclosures of new data, providers, retention, permissions and charges before launch. This draft is not advance permission to train AI, sell health data, target ads with health-store data or disclose photos for marketing. New uses must have a valid legal basis and fresh consent where required. Updated versions should be dated and material changes brought to users’ attention. The missing operator and contact information must be completed so privacy and safety requests can actually be received.