FitAI Trainer ("we", "us") operates the FitAI Trainer app and the fitaitrainer.com website. This policy explains what data we collect, why we collect it, who processes it, and the rights you have over it. Because FitAI Trainer builds training programs around your health and fitness profile, we handle health-related information — and we want you to know exactly how.
1. What we collect
- Account data. Your email address and password (passwords are handled by our authentication provider and are never visible to us in plain text), and your date of birth to confirm you are 18 or older.
- Profile data. Your goals, training experience, available equipment, and schedule — the inputs your program is built from.
- Health screening data. Your answers to the pre-exercise health screening (a standard PAR-Q-style questionnaire) and any pain or injury information you report while training. This is health-related data and we treat it accordingly: it is used to shape and validate your program for safety, never for advertising.
- Workout data. Your training plans, generated workouts, completed sessions, and the feedback you give.
- Trainer chat. Your conversations with the AI trainer, which the trainer uses to adapt your program.
- Subscription status. Your membership tier, renewal state, and usage allowances (video minutes, media credits).
- Diagnostics. Crash reports and performance data — technical details about failures in the app or on our servers, used only to find and fix problems. Error reporting is configured not to send personal identifiers by default, and our server-side error reports drop request bodies and scrub health-related text before they are sent.
- Product usage. Coarse product events our servers record as the service operates (for example "onboarding completed" or "workout completed"), restricted to an approved event list with health-sensitive values redacted. In-app analytics from your device is separate: it is off by default and runs only if you opt in (you can change your choice any time in Settings).
- Connected health data (optional). If you turn on Connected health data, per-workout heart-rate and active-energy summaries read from your phone's health store — described in full in section 2. If you never turn it on, none of this data is read or collected.
We do not collect your precise location, your contacts, or advertising identifiers.
2. Connected health data (optional)
FitAI Trainer can include heart rate and energy readings — for example the ones your watch records — in your workout summaries. This is off unless you turn it on, and it works like this:
- Opt-in only. Nothing is read unless you enable Connected health data in the app's Settings for your account and grant read access in Apple HealthKit (iOS) or Android Health Connect. You can turn it off in Settings at any time, and you can also revoke the app's access at the operating-system level — in the iOS Health app or in Health Connect on Android.
- What we read. Heart rate and active energy from the health store on your phone, only for the time window of your own completed workout sessions — never continuously, and never for other parts of your day.
- What we store. Per-workout aggregates — average, maximum, and minimum heart rate, and active energy — plus a downsampled heart-rate series of at most 120 points per workout. We never store the raw sample stream.
- How it is used. Solely to show these metrics in your own workout summaries and history. Connected health data is never used for advertising and is never sold.
- Where it is stored. Alongside the rest of your workout data, on the infrastructure described in section 5. It is not sent to the AI providers described in section 4.
- Retention and deletion. Kept for the life of your account, like your other workout data. Deleting your account deletes it, and a data export includes it (section 6).
- Watches. The app reads from your phone's health store, not from the watch itself. An Apple Watch or Wear OS watch syncs its readings there automatically; third-party watches such as Garmin, Fitbit, or Samsung appear only if you enable their vendor app's sync with Health Connect.
3. How we use your data
- To build, validate, and adapt your personal training program.
- To generate your workout media — video demonstrations and trainer-voice narration.
- To run health and safety checks: screening before you start, pain check-ins while you train, and automatic validation of every generated workout.
- To show your heart rate and energy in your workout summaries and history, if you turn on Connected health data (section 2).
- To operate your account, membership, and allowances.
- To respond when you contact support.
4. AI processing
FitAI Trainer is built on generative AI. To provide the service, relevant parts of your profile, health screening, workout history, and chat messages are sent to OpenAI, whose language models build and safety-check your program and power your coaching conversations, and whose speech models synthesize trainer-voice narration. Workout demonstration video is generated by Runway from exercise descriptions and a stock trainer appearance — those prompts describe the movement, not you, and health-related terms are blocked from them. This processing exists solely to produce your program, coaching responses, and media. See the AI-Coaching Disclosure for a plain-language description of what the AI does and where its limits are.
5. Who processes your data
We use a small set of service providers to run FitAI Trainer. Each receives only what its role requires:
- OpenAI — runs the language models that generate, adapt, and safety-check your program and power your coaching conversations, and the speech models that synthesize trainer-voice narration. Receives the relevant parts of your profile, health screening, workout history, and chat described in section 4.
- Runway — generates workout demonstration video clips. Receives exercise and movement descriptions and a stock trainer appearance, never your health information.
- Supabase — authentication, database, and file storage. Your account and application data, including generated media, are stored here.
- Railway — cloud hosting for our API, background workers, and website. Your data is processed on infrastructure it hosts.
- Sentry — crash and error reporting for the app and our servers. Receives the technical diagnostics described in section 1: personal identifiers are not sent by default, and our server-side reports drop request bodies and scrub health-related text.
- PostHog — product analytics. Receives the approved-list, health-redacted product events described in section 1; in-app analytics from your device additionally runs only if you opt in.
- Apple App Store / Google Play and RevenueCat — payments and subscription management. Purchases are made through the app stores; we never see or store your card number. RevenueCat processes subscription state on our behalf.
Two additions are planned and are not in use today; each will begin only with its feature launch, with this policy updated first:
- Stripe — card payments, when checkout on our website launches. Card details would go directly to Stripe; we would still never see or store your card number.
- Meta advertising attribution — if and when we begin advertising, to measure whether our ads led to installs.
We do not sell your personal data, and we do not share it with advertisers.
6. Your rights
- Export. You can request a copy of your data from the app's Data & Privacy settings or by emailing support@fitaitrainer.com from your account email.
- Deletion. You can request deletion of your account and data the same way. Deletion removes your profile, health screening, workout history, connected health data, chat, and generated media, subject to records we must keep for legal or accounting reasons. See Delete Your Account for the exact steps and what is removed.
- Correction. You can update your profile and health information at any time in the app ("Update My Health Info" in settings).
7. Retention
We keep your data while your account is active. When your account is deleted, we delete or de-identify your personal data except where a legal, security, or accounting obligation requires a limited record.
Acceptance of a deletion request, removal of your account, and completion of checks for data held by service providers are separate stages. Provider checks may remain pending after your sign-in identity and application data have been removed. We do not infer that a provider erased data from the age of your request alone or from a general description of that provider's retention policy.
Completion requires evidence covering the relevant service and account settings, historical submissions, and when further submissions stopped. Depending on the service, that can be verified deletion or the expiry of a verified, applicable maximum retention period measured from the last possible submission. When that evidence is unavailable or the scope is uncertain, the check stays pending for review. We retain a limited record of the request and the evidence used to assess it. Contact us for the status of a pending request; see Delete Your Account for details.
8. Security
Data is encrypted in transit, access is authenticated and scoped per user, and payment card details never touch our systems. No internet service can promise perfect security, but we design so that a failure is loud and contained rather than silent.
9. Age requirement
FitAI Trainer is for adults: you must be 18 or older to use it. Creating an account requires only an email address and password. Your date of birth is collected during the onboarding conversation, and the age check runs when you complete onboarding — and again any time you update your date of birth. While you answer the setup questions, your answers (including your date of birth and health-screening responses) are saved as an in-progress onboarding draft so you can resume where you left off. If the age check shows you are under 18, we refuse to set up coaching and delete that onboarding draft — the date of birth, screening answers, and profile details collected during setup. If that deletion cannot be completed, we tell you so instead of claiming it happened.
10. Changes to this policy
When this policy changes, we publish the new version here with a new version number and date. Completing onboarding always requires accepting the exact current version — the app verifies this document's version and content digest against the server before your consent is recorded.
11. Contact
Privacy questions or requests: support@fitaitrainer.com. General questions: info@fitaitrainer.com.