Privacy Policy
Effective date: October 6, 2026
This policy explains what personal information FitApp collects, why, who else handles it, how long we keep it, and the choices you have. FitApp is a fitness app with an AI coach. Some of what you tell the coach is health information, so we've tried to be especially clear about that.
The short version
- We collect what we need to run your account, coach you and keep the app working. We don't run ads, and we don't use advertising or analytics tools.
- Your coach quiz answers, your chat with the coach and your plans are encrypted in our database.
- Health information is only processed after you agree to it in the app, and you can withdraw that agreement at any time with "Delete my health data" in Settings.
- To write the coach's answers, we send your messages and the relevant parts of your profile to Anthropic, our AI provider. We don't send your name, email address or date of birth.
- To find current research, our server sends a few general search words, never anything about you, to PubMed, the U.S. National Library of Medicine's research database.
- If you connect Apple Health or Health Connect, your readings stay on your device. Only a short summary goes to the coach when you chat or build a plan, and we don't store that summary.
- We never sell your personal information, and we never use your health information for advertising.
- You can download everything we hold about you, or delete your account and all of it, from Settings in the app.
Who we are
FitApp is run by Edibl AI LLC ("we", "us"). We decide how and why your personal information is used, which makes us the "controller" under data protection laws such as the GDPR. We're based in the United States and don't have an office in the European Union or the UK.
You can reach us at liamckoster@gmail.com or by post at 9552 Queensbury Ct, Windermere, FL 34786, USA.
What we collect and why
Your account and sign-in
- Email address. You sign up with your email address, or with Sign in with Apple on iPhone and iPad. We use it to run your account, to send the confirmation link when you sign up and password reset links when you ask for one, and to reply to support messages. If you use Sign in with Apple and choose to hide your email, Apple gives us a private relay address that forwards to you, and we never see your real address.
- Password. If you sign up with email, your password is handled only by our sign-in provider (Supabase Auth), which stores it as a one-way hash. We never see it, store it ourselves or log it.
- Sign in with Apple. Apple tells us a unique identifier for your Apple sign-in, your email address (or relay address), and your name if you choose to share it. The app saves that name only after you've given a date of birth that lets you use FitApp.
- An account identifier. We give your account a random identifier. We use it to link your data to your account, and it's the identifier our subscription provider uses for your purchases.
Your date of birth
We ask for your date of birth when you sign up (or once, straight after your first Sign in with Apple). We use it to make sure you're at least 13, to keep advice suitable for your age, and to show supplement advice only to adults (18 and over). You can set it only once in the app; if it's wrong, contact support.
Your name and preferences
We store the first name you give at sign-up (or the name Apple shares) so the app can greet you, and your choice of metric or imperial units. You can change both in Settings > Profile. Your light or dark appearance choice is stored only on your device.
The app doesn't let you upload photos.
Your coach quiz answers (health information)
Before the quiz starts, the app asks you to agree to us processing your health information. If you agree, the coach asks about your sex, height and weight, goals, training experience, injuries, health conditions, medications, diet preferences, food allergies, equipment and schedule, plus a few safety questions (for example about pregnancy, heart problems, fainting and eating disorders). It also asks about your ethnicity; that one is optional, and you can say "prefer not to say".
We use these answers to build your plan and personalize the coach's answers, and to spot answers that mean you should see a health professional before starting a plan. Your answers are encrypted in our database with a key kept in a separate secure key store.
Your chat with the coach and your plans
We store your messages to the coach, the coach's answers (with the sources it cites) and the plans it builds for you, so you can come back to them. They are encrypted in our database in the same way as your quiz answers.
Your workout, weight, protein and water logs
If you log workouts (exercises, sets, weights and reps, and when you trained), your body weight, or how much protein and water you've had, we store those logs to show your progress and your daily targets. Logging needs the same health data agreement as the quiz. These logs are protected by access rules that let only your account read them, but they aren't encrypted with the separate key the way your quiz answers and chat are.
Readings from your phone's health app
If you choose to connect Apple Health (iPhone and iPad) or Health Connect (Android), see Apple Health and Health Connect below for exactly what is read and where it goes.
Reports about the coach
You can report any coach answer or any part of your plan. We store the reason you choose, any details you add, and which answer or plan item you reported. People on our team review open reports, and when they do they can read the answer or plan item you reported, to make the coach safer and more accurate.
Support messages
When you contact support in the app, we store the topic and your message, and reply to the email address on your account. If you choose "Something isn't working", the app also attaches a technical error reference: the identifier of an error report in Sentry (see Crash and error reports). Your message itself is never sent to Sentry.
Your subscription and purchases
Subscriptions are bought through the Apple App Store or Google Play. Apple or Google takes the payment; we never see your card or bank details. Our subscription provider, RevenueCat, receives the store's record of your purchase under your account identifier, and tells our server whether your subscription is active. We keep a copy of your subscription status (for example the product, which store, when it renews or ends, whether it's a trial, and whether there's a billing problem) so the app knows what you can use.
Crash and error reports
When the app or our server hits an unexpected error, a report goes to Sentry, our error-tracking provider, so we can fix it. App reports contain the error and where in the code it happened, the app version, your device model and operating system version, and the screens you moved between and the app's network requests just before it (which addresses it contacted, not what it sent). Before a report leaves your device, the app removes who you are, the contents of network requests, email addresses, sign-in tokens and account identifiers, and it doesn't record your taps. It never sends screenshots, screen recordings or a copy of what's on your screen. Reports from our server contain only the error, where it happened and which feature it was in, never anything you sent.
Crash reports aren't linked to your account, unless you choose "Something isn't working" when you contact support: then that one report is linked to your support message.
Bot protection when you sign in
The sign-up and sign-in screens (including Sign in with Apple) use Cloudflare Turnstile to check that a real person is using the app. Turnstile runs a check inside the app that sends technical information such as your IP address and information about your device's browser component to Cloudflare. Our sign-in provider then checks the result with Cloudflare. We don't link this information to your account.
Technical information when the app connects
Like any online service, our hosting provider receives your IP address and basic request information when the app talks to our servers, and keeps it in its own security and operations logs for a limited time.
What we don't collect
FitApp doesn't collect your location, contacts, photos, microphone or camera input, browsing history or advertising identifiers. It contains no advertising or analytics tools, and we don't track you across other companies' apps or websites.
Apple Health and Health Connect
Connecting Apple Health or Health Connect is optional. You can only connect after agreeing to the coach's health data terms, from Settings > Connected apps.
What we read. Sleep, resting heart rate, heart rate variability, steps, workouts recorded by other apps (such as Apple Watch runs), and weight. FitApp only reads. It never writes anything to Apple Health or Health Connect.
Where your readings go. Your readings stay on your device. FitApp works out averages there, such as last night's sleep, your 7-day averages and your usual resting heart rate. Only that summary leaves your device, and only when you send the coach a message or build a plan. Our server passes it to Anthropic, our AI provider, so the coach can take your sleep and recovery into account. We don't store the summary or write it to our logs.
What can end up saved. The coach's answers and your plans are saved like any other answer. When a reading explains the coach's advice (for example, suggesting an easier session after a short night's sleep), the answer may mention it. If you tap the option to use your latest weight from Apple Health or Health Connect when logging your weight, that weight is saved as one of your weight logs, like any weight you type in.
What we never do. We never use information from Apple Health or Health Connect for advertising or marketing, never sell it, and never share it with anyone except Anthropic, which processes the summary only to write the coach's answers for you. We don't use it for any purpose other than coaching you in the app.
FitApp's use of information received from Health Connect follows the Health Connect Permissions policy, including its Limited Use requirements.
How to stop. In FitApp, go to Settings > Connected apps, open Apple Health or Health Connect and tap Disconnect. To remove FitApp's access completely, use the Settings app on iPhone or iPad (under Health, then Data Access & Devices) or Health Connect on Android (under App permissions). "Delete my health data", signing out and deleting your account also stop FitApp reading your health data.
How the AI coach uses your information
The coach's answers and plans are written by an AI model from Anthropic. Each time you send the coach a message or build a plan, our server sends Anthropic:
- your recent messages with the coach (up to the last 40);
- your age in years and whether you're an adult;
- your quiz answers once you've finished the quiz, including any health conditions, medications and injuries, the safety answers, and your ethnicity if you shared it;
- a short summary of your current plan, when you have one;
- the Apple Health or Health Connect summary, if you've connected it.
We don't send your name, email address, date of birth or account identifier.
Research searches. After the quiz, to find current research for each question and each plan, our server searches PubMed, the research database run by the U.S. National Library of Medicine. A short AI step turns your question into a few general search words (for example "creatine" and "muscle strength"), and only those words go to PubMed: never your messages, your profile, your health information or anything that identifies you. PubMed sees the request as coming from our server. The coach may cite the reviews and guidelines it finds alongside our curated library, and the app marks them as found on PubMed.
Our server then checks the answer before you see it: every recommendation must cite at least two sources from our curated library or from those research searches, supplement advice is only given to adults, and answers that suggest you should see a health professional stop the coach from giving a plan or advice.
Our legal bases (EEA, UK and Switzerland)
If you're in the European Economic Area, the UK or Switzerland, we rely on these legal bases:
- To provide the app you asked for (performing our contract with you): your account, sign-in, name, units, subscription and purchase records, and replying to your support messages.
- Your explicit consent (GDPR Article 9(2)(a), and Article 6(1)(a)): your quiz answers, including health conditions, medications, safety answers and ethnicity; your chat with the coach and your plans; your workout, weight, protein and water logs; and your Apple Health or Health Connect summary. You give this consent on the coach's consent screen ("I agree, start the quiz"). You can withdraw it at any time in Settings > Your data > Delete my health data, which deletes this information and stops FitApp reading Apple Health or Health Connect. Withdrawing doesn't affect processing before you withdrew.
- Our legitimate interests in keeping FitApp safe, secure and working: checking your age at sign-up, bot protection, rate limits, error reports, and reviewing reports about the coach. We've balanced these against your rights, and you can object (see Your rights).
- Legal obligations: answering requests to exercise your rights, and keeping records the law requires.
Who else handles your information
We use these service providers to run FitApp. They process your information on our behalf and under contracts with us.
- Supabase hosts our database, sign-in system and server code. It stores everything described in this policy that we keep.
- Anthropic provides the AI model that writes the coach's answers and plans. It receives what's listed in How the AI coach uses your information.
- RevenueCat manages subscriptions. It receives your account identifier and your purchase records from Apple or Google, plus basic technical information from the app such as the platform and app version.
- Sentry receives crash and error reports, as described above.
- Cloudflare provides the Turnstile bot check on the sign-up and sign-in screens.
The U.S. National Library of Medicine's PubMed service receives only the general search words described in How the AI coach uses your information, from our server, with nothing that identifies you.
Apple and Google also handle information when you use their services with FitApp: Sign in with Apple, App Store and Google Play purchases, and Apple Health and Health Connect on your device. They do this under their own privacy policies, as independent companies, not on our behalf.
We may also disclose information if the law requires it, to protect people's safety or our legal rights, or as part of a sale or merger of FitApp's business, in which case we'd tell you first.
We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We don't use any of your information for advertising.
Where your information is stored
We're based in the United States, so if you use FitApp from another country, including the EEA, the UK or Switzerland, your information is handled in the United States. Our database and server code run on Supabase in the region we chose when setting up the service. Some of our providers, including Anthropic, RevenueCat, Sentry and Cloudflare, are based in the United States or process information in other countries. When our providers receive information about people in the EEA, the UK or Switzerland, we rely on safeguards the law recognizes, such as the European Commission's standard contractual clauses (and the UK's and Switzerland's equivalents), or the provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.
How long we keep your information
- While your account is open, we keep your account details, quiz answers, chat, plans, logs, reports, support messages and subscription status, so the app keeps working and you can see your history. You can delete individual weigh-ins in the Progress tab.
- "Delete my health data" (Settings > Your data) deletes your quiz answers, your chat with the coach, your plans and any reports about them, and all your workout, weight, protein and water logs, straight away. Your account stays open.
- "Delete account" (Settings > Account) deletes your account and everything we store about you straight away, and deletes your customer record at RevenueCat. If RevenueCat can't be reached at that moment, we keep only your account identifier until we finish deleting that record, then delete the identifier too. If you use Sign in with Apple on an iPhone or iPad, the app also asks Apple to stop FitApp's use of your Apple sign-in. See our account deletion page for the details.
- Download history: we keep a record of when you downloaded your data for one day, so we can limit how often downloads can be made (any record we still hold is included in the download).
- Coach usage counts: we keep a record of when you sent coach messages, built plans, reported content and started over, for one day, so we can limit how often these can be done. It holds the type and time of each action, not what you wrote.
- Backups: deleted information can remain in our hosting provider's backups until those backups expire.
- Our providers' copies: Sentry keeps error reports, and Anthropic keeps requests, only for a limited time under their own terms. Apple and Google keep their own records of your purchases.
Your rights
Everyone
You can do these yourself in the app:
- See and download your information: Settings > Your data > Download my data creates a file with everything we store about you.
- Correct it: change your name and units in Settings > Profile. To correct your date of birth, contact support.
- Delete your health information: Settings > Your data > Delete my health data.
- Delete everything: Settings > Account > Delete account, or follow the steps on our account deletion page if you can't use the app.
For anything else, email liamckoster@gmail.com. We'll need to confirm the request comes from the account holder before acting on it, usually by replying from or to the email address on the account.
EEA, UK and Switzerland
You have the right to access, correct, delete, restrict and port your personal information, to object to processing based on legitimate interests, and to withdraw consent at any time. You can also complain to your local data protection authority, though we'd appreciate the chance to help first. We answer requests within one month.
California and other US states
Depending on where you live, you may have the right to know what personal information we collect and how we use and disclose it, to get a copy of it, to correct it, to delete it, and to opt out of its sale or sharing. We don't sell or share personal information, so there's nothing to opt out of. We only use sensitive personal information (such as health information and ethnicity) to provide the app you asked for, so there's no further use to limit. We won't treat you differently for using your rights. You can use an authorized agent; we'll ask them for proof that you authorized them, and may ask you to confirm your identity.
Children
FitApp isn't for children under 13. We check your date of birth in the app and in our database: an email sign-up with a date of birth under 13 is refused. Sign in with Apple doesn't tell us your age, so the app asks for your date of birth before you can do anything else; if it's under 13, the app deletes your sign-in details straight away and tells you that you can't use FitApp. If an account still has no date of birth a day after it was created (for example because the app was closed at that step), we delete it automatically. Supplement advice is only shown to adults (18 and over). If you believe a child under 13 has an account, email liamckoster@gmail.com and we'll delete it.
How we protect your information
- Your quiz answers, chat with the coach and plans are encrypted in our database with a key kept in a separate secure key store, and the app can't read those tables directly; only our server code can.
- Every table that holds personal information has access rules so that each account can read only its own records, and our automated tests check that one person can't read or change another person's data.
- The app talks to our servers over encrypted connections, and keeps your sign-in session in your device's secure storage (the iOS Keychain or the Android Keystore).
- Sign-up and sign-in are protected against bots, and coach messages, plans, workouts, reports, support messages and data downloads have usage limits.
- Error reports are cleaned of personal details before they're sent.
No system is perfectly secure. If a security breach affects your personal information, we'll tell you and the authorities where the law requires it.
Changes to this policy
If we change this policy, we'll update the effective date at the top. If a change is significant, for example a new use of your health information, we'll tell you by email before it takes effect and, where the law requires it, ask for your consent again.
Contact us
Email liamckoster@gmail.com, write to Edibl AI LLC, 9552 Queensbury Ct, Windermere, FL 34786, USA, or use Settings > Contact support in the app.