Privacy Policy

Effective date: October 6, 2026

This policy explains what personal information FitApp collects, why, who else handles it, how long we keep it, and the choices you have. FitApp is a fitness app with an AI coach. Some of what you tell the coach is health information, so we've tried to be especially clear about that.

The short version

Who we are

FitApp is run by Edibl AI LLC ("we", "us"). We decide how and why your personal information is used, which makes us the "controller" under data protection laws such as the GDPR. We're based in the United States and don't have an office in the European Union or the UK.

You can reach us at liamckoster@gmail.com or by post at 9552 Queensbury Ct, Windermere, FL 34786, USA.

What we collect and why

Your account and sign-in

Your date of birth

We ask for your date of birth when you sign up (or once, straight after your first Sign in with Apple). We use it to make sure you're at least 13, to keep advice suitable for your age, and to show supplement advice only to adults (18 and over). You can set it only once in the app; if it's wrong, contact support.

Your name and preferences

We store the first name you give at sign-up (or the name Apple shares) so the app can greet you, and your choice of metric or imperial units. You can change both in Settings > Profile. Your light or dark appearance choice is stored only on your device.

The app doesn't let you upload photos.

Your coach quiz answers (health information)

Before the quiz starts, the app asks you to agree to us processing your health information. If you agree, the coach asks about your sex, height and weight, goals, training experience, injuries, health conditions, medications, diet preferences, food allergies, equipment and schedule, plus a few safety questions (for example about pregnancy, heart problems, fainting and eating disorders). It also asks about your ethnicity; that one is optional, and you can say "prefer not to say".

We use these answers to build your plan and personalize the coach's answers, and to spot answers that mean you should see a health professional before starting a plan. Your answers are encrypted in our database with a key kept in a separate secure key store.

Your chat with the coach and your plans

We store your messages to the coach, the coach's answers (with the sources it cites) and the plans it builds for you, so you can come back to them. They are encrypted in our database in the same way as your quiz answers.

Your workout, weight, protein and water logs

If you log workouts (exercises, sets, weights and reps, and when you trained), your body weight, or how much protein and water you've had, we store those logs to show your progress and your daily targets. Logging needs the same health data agreement as the quiz. These logs are protected by access rules that let only your account read them, but they aren't encrypted with the separate key the way your quiz answers and chat are.

Readings from your phone's health app

If you choose to connect Apple Health (iPhone and iPad) or Health Connect (Android), see Apple Health and Health Connect below for exactly what is read and where it goes.

Reports about the coach

You can report any coach answer or any part of your plan. We store the reason you choose, any details you add, and which answer or plan item you reported. People on our team review open reports, and when they do they can read the answer or plan item you reported, to make the coach safer and more accurate.

Support messages

When you contact support in the app, we store the topic and your message, and reply to the email address on your account. If you choose "Something isn't working", the app also attaches a technical error reference: the identifier of an error report in Sentry (see Crash and error reports). Your message itself is never sent to Sentry.

Your subscription and purchases

Subscriptions are bought through the Apple App Store or Google Play. Apple or Google takes the payment; we never see your card or bank details. Our subscription provider, RevenueCat, receives the store's record of your purchase under your account identifier, and tells our server whether your subscription is active. We keep a copy of your subscription status (for example the product, which store, when it renews or ends, whether it's a trial, and whether there's a billing problem) so the app knows what you can use.

Crash and error reports

When the app or our server hits an unexpected error, a report goes to Sentry, our error-tracking provider, so we can fix it. App reports contain the error and where in the code it happened, the app version, your device model and operating system version, and the screens you moved between and the app's network requests just before it (which addresses it contacted, not what it sent). Before a report leaves your device, the app removes who you are, the contents of network requests, email addresses, sign-in tokens and account identifiers, and it doesn't record your taps. It never sends screenshots, screen recordings or a copy of what's on your screen. Reports from our server contain only the error, where it happened and which feature it was in, never anything you sent.

Crash reports aren't linked to your account, unless you choose "Something isn't working" when you contact support: then that one report is linked to your support message.

Bot protection when you sign in

The sign-up and sign-in screens (including Sign in with Apple) use Cloudflare Turnstile to check that a real person is using the app. Turnstile runs a check inside the app that sends technical information such as your IP address and information about your device's browser component to Cloudflare. Our sign-in provider then checks the result with Cloudflare. We don't link this information to your account.

Technical information when the app connects

Like any online service, our hosting provider receives your IP address and basic request information when the app talks to our servers, and keeps it in its own security and operations logs for a limited time.

What we don't collect

FitApp doesn't collect your location, contacts, photos, microphone or camera input, browsing history or advertising identifiers. It contains no advertising or analytics tools, and we don't track you across other companies' apps or websites.

Apple Health and Health Connect

Connecting Apple Health or Health Connect is optional. You can only connect after agreeing to the coach's health data terms, from Settings > Connected apps.

What we read. Sleep, resting heart rate, heart rate variability, steps, workouts recorded by other apps (such as Apple Watch runs), and weight. FitApp only reads. It never writes anything to Apple Health or Health Connect.

Where your readings go. Your readings stay on your device. FitApp works out averages there, such as last night's sleep, your 7-day averages and your usual resting heart rate. Only that summary leaves your device, and only when you send the coach a message or build a plan. Our server passes it to Anthropic, our AI provider, so the coach can take your sleep and recovery into account. We don't store the summary or write it to our logs.

What can end up saved. The coach's answers and your plans are saved like any other answer. When a reading explains the coach's advice (for example, suggesting an easier session after a short night's sleep), the answer may mention it. If you tap the option to use your latest weight from Apple Health or Health Connect when logging your weight, that weight is saved as one of your weight logs, like any weight you type in.

What we never do. We never use information from Apple Health or Health Connect for advertising or marketing, never sell it, and never share it with anyone except Anthropic, which processes the summary only to write the coach's answers for you. We don't use it for any purpose other than coaching you in the app.

FitApp's use of information received from Health Connect follows the Health Connect Permissions policy, including its Limited Use requirements.

How to stop. In FitApp, go to Settings > Connected apps, open Apple Health or Health Connect and tap Disconnect. To remove FitApp's access completely, use the Settings app on iPhone or iPad (under Health, then Data Access & Devices) or Health Connect on Android (under App permissions). "Delete my health data", signing out and deleting your account also stop FitApp reading your health data.

How the AI coach uses your information

The coach's answers and plans are written by an AI model from Anthropic. Each time you send the coach a message or build a plan, our server sends Anthropic:

We don't send your name, email address, date of birth or account identifier.

Research searches. After the quiz, to find current research for each question and each plan, our server searches PubMed, the research database run by the U.S. National Library of Medicine. A short AI step turns your question into a few general search words (for example "creatine" and "muscle strength"), and only those words go to PubMed: never your messages, your profile, your health information or anything that identifies you. PubMed sees the request as coming from our server. The coach may cite the reviews and guidelines it finds alongside our curated library, and the app marks them as found on PubMed.

Our server then checks the answer before you see it: every recommendation must cite at least two sources from our curated library or from those research searches, supplement advice is only given to adults, and answers that suggest you should see a health professional stop the coach from giving a plan or advice.

If you're in the European Economic Area, the UK or Switzerland, we rely on these legal bases:

Who else handles your information

We use these service providers to run FitApp. They process your information on our behalf and under contracts with us.

The U.S. National Library of Medicine's PubMed service receives only the general search words described in How the AI coach uses your information, from our server, with nothing that identifies you.

Apple and Google also handle information when you use their services with FitApp: Sign in with Apple, App Store and Google Play purchases, and Apple Health and Health Connect on your device. They do this under their own privacy policies, as independent companies, not on our behalf.

We may also disclose information if the law requires it, to protect people's safety or our legal rights, or as part of a sale or merger of FitApp's business, in which case we'd tell you first.

We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We don't use any of your information for advertising.

Where your information is stored

We're based in the United States, so if you use FitApp from another country, including the EEA, the UK or Switzerland, your information is handled in the United States. Our database and server code run on Supabase in the region we chose when setting up the service. Some of our providers, including Anthropic, RevenueCat, Sentry and Cloudflare, are based in the United States or process information in other countries. When our providers receive information about people in the EEA, the UK or Switzerland, we rely on safeguards the law recognizes, such as the European Commission's standard contractual clauses (and the UK's and Switzerland's equivalents), or the provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.

How long we keep your information

Your rights

Everyone

You can do these yourself in the app:

For anything else, email liamckoster@gmail.com. We'll need to confirm the request comes from the account holder before acting on it, usually by replying from or to the email address on the account.

EEA, UK and Switzerland

You have the right to access, correct, delete, restrict and port your personal information, to object to processing based on legitimate interests, and to withdraw consent at any time. You can also complain to your local data protection authority, though we'd appreciate the chance to help first. We answer requests within one month.

California and other US states

Depending on where you live, you may have the right to know what personal information we collect and how we use and disclose it, to get a copy of it, to correct it, to delete it, and to opt out of its sale or sharing. We don't sell or share personal information, so there's nothing to opt out of. We only use sensitive personal information (such as health information and ethnicity) to provide the app you asked for, so there's no further use to limit. We won't treat you differently for using your rights. You can use an authorized agent; we'll ask them for proof that you authorized them, and may ask you to confirm your identity.

Children

FitApp isn't for children under 13. We check your date of birth in the app and in our database: an email sign-up with a date of birth under 13 is refused. Sign in with Apple doesn't tell us your age, so the app asks for your date of birth before you can do anything else; if it's under 13, the app deletes your sign-in details straight away and tells you that you can't use FitApp. If an account still has no date of birth a day after it was created (for example because the app was closed at that step), we delete it automatically. Supplement advice is only shown to adults (18 and over). If you believe a child under 13 has an account, email liamckoster@gmail.com and we'll delete it.

How we protect your information

No system is perfectly secure. If a security breach affects your personal information, we'll tell you and the authorities where the law requires it.

Changes to this policy

If we change this policy, we'll update the effective date at the top. If a change is significant, for example a new use of your health information, we'll tell you by email before it takes effect and, where the law requires it, ask for your consent again.

Contact us

Email liamckoster@gmail.com, write to Edibl AI LLC, 9552 Queensbury Ct, Windermere, FL 34786, USA, or use Settings > Contact support in the app.