Privacy Policy

Last updated: August 25, 2026

The short version

This is a simplified summary - the full policy below is what actually applies.

Fitly AI ("Fitly," "we," "us," or "our") operates the Fitly AI mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, and a securely hashed password. We never store your password in plain text.

Profile & Health Data

To provide personalized guidance, you may choose to provide health and fitness information including: date of birth, gender, height, weight, fitness goals, dietary preferences, food allergies, supplements you tell us you take, injuries, and training experience. We use this information to provide personalized guidance, track your progress, and for the other purposes described in this Policy.

Fitness, Wellness & Nutrition Data

We store data you log through the Service, including meals (descriptions, macronutrients, photos), workouts (exercises, sets, reps, weights), body weight entries, water intake, daily check-ins (energy, soreness, mood, stress, hunger, sleep, sore areas, and journal entries), body measurements, body-fat estimates, and progress photos. Progress photos may include the date and time recorded by the image, a pose label, and notes you add. Logged data includes a date or timestamp and a source indicator where applicable.

Apple Health (HealthKit) Data

On iOS, you may optionally connect Apple Health. If you do, we read only the categories you approve in the iOS permission sheet - sleep, steps, active energy, body weight, and workouts - and store daily summaries alongside your fitness data, marked with Apple Health as the source. Access is read-only: Fitly never writes to Apple Health. We use this data solely to provide the Service (filling in your daily check-in, dashboards, weight trend, and the agent's guidance). We never use Apple Health data for advertising or marketing, never sell it or share it with third parties for their purposes, and exclude it from the model-training uses described in Section 2. You can disconnect at any time in iOS Settings > Privacy & Security > Health; values already synced remain in your account until you edit or delete them, or delete your account.

Conversation Data

Your chat conversations with the AI agent are stored to provide continuity, improve the quality of guidance, and enable you to review your history. Conversations may include text messages and photo uploads.

Payment Information

Subscription payments are processed by Apple for in-app purchases on iOS and by Stripe, Inc. for supported web purchases. We never receive, store, or process your credit card number or full payment details. We store subscription and purchase information such as the payment provider, customer or transaction identifier, product purchased, subscription status, and relevant purchase or renewal dates.

Usage & Analytics Data

We collect product analytics such as screen and feature usage, actions taken in the app, subscription events, and AI response quality ratings (thumbs up/down feedback you provide). Brain-game analytics may include the game played, score, outcome, hints used, and whether a new record was achieved. After you sign in, analytics events may be associated with your Fitly account identifier. We use PostHog to process these events. Session replay is disabled.

Signup Attribution

When you arrive on our website we store a first-party cookie recording how you got here: any campaign tags on the link you followed (source, medium, campaign, creative), advertising click identifiers appended by Google, Meta or TikTok, the page you landed on, the referring website, and, if you came through another user's share card or invite link, that share or referral code. If you create an account, that record is saved to your account so we can tell which campaigns and which member referrals bring people to Fitly. The cookie expires after 90 days. We also run Google Analytics on our marketing website. This information is used for our own reporting and to measure advertising; we do not sell it.

Brain Games & Rewards

Brain-game runs and best scores are primarily stored on your device. We collect the completion analytics described above, and our servers store mystery boxes, unlocked games, themes, plans, voices, and other collectible rewards associated with your account.

Notifications & Device Tokens

Your agent can reach out to you between sessions - a check-in after a meal you have not logged, an evening question, a weekly summary. This is off by default: nothing is sent until you choose a frequency in the app, and you can set it back to Never at any time. To deliver notifications we store a push token issued by Apple for your device, the platform it belongs to, and whether you have granted or declined notification permission, associated with your account so we know where to send and when to stop. The token identifies a device installation, not you personally, and is replaced when you reinstall the app. If you choose email instead, we send to your account address; every agent email carries a link that changes the setting without signing in. We use these notifications only to deliver your own coaching messages about your own logged data - never for advertising, marketing, or promotion of other products - and we never sell or share them. Turning notifications off in iOS Settings, or setting the frequency to Never, stops them; we delete a stored token once it is rejected as invalid or you disable notifications.

Device, Security & Diagnostic Data

We collect limited technical information needed to operate, secure, and troubleshoot the Service, including device platform, app version and build, analytics identifiers, IP address, user agent, request and audit-log details, and application error or diagnostic information. We do not use this information for cross-app advertising or advertising measurement.

2. How We Use Your Information

3. AI & Data Processing

Your conversations are processed by third-party AI providers (currently Anthropic Claude; we may use other providers such as OpenAI in the future) to generate guidance responses. When you send a message, relevant context - including your profile, today's logged data, check-in responses, measurements, and recent conversation history - may be sent to the AI provider to generate a personalized response.

Progress-photo images saved in your private gallery are not automatically sent to an AI provider. An image is sent for AI processing when you choose to submit it in chat. If you then ask Fitly AI to save that chat image as a progress photo, a private copy is added to your progress-photo gallery.

We do not sell your personal data to AI providers. AI providers process your data solely to generate responses and, per their data processing agreements, do not use your data to train their models.

Fitly AI model training: We may use your data - including conversations, logged meals and workouts, check-ins, measurements, photos, feedback, and usage patterns - to train, fine-tune, and improve our own AI models and guidance algorithms. This may include using identifiable data in a secure, access-controlled training environment, as well as de-identified or aggregated data. The purpose of this training is to improve the accuracy, relevance, and quality of AI guidance across the Service.

You may opt out of having your data used for model training at any time by contacting us at privacy@fitly.chat. Opting out will not affect the core functionality of the Service. Data that has already been used for training prior to your opt-out cannot be retroactively removed from trained models, but we will exclude your data from future training runs.

4. Data Security

We implement security measures consistent with industry best practices for handling sensitive health data:

5. Data Storage & Retention

Your data is stored on servers located in the United States (AWS infrastructure). We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records, legal compliance).

Anonymized, aggregated data that cannot be used to identify you may be retained indefinitely for research, model training, and service improvement purposes. Data that has been incorporated into trained AI models cannot be individually extracted or deleted from those models.

International transfers. Your data is stored and processed in the United States. By using the Service, you consent to the transfer of your data to the United States, where data protection laws may differ from those in your country of residence. We implement appropriate safeguards, including contractual protections, to ensure your data is treated securely and in accordance with this Privacy Policy.

6. Data Sharing & Disclosure

We do not sell your personal information. We may share or disclose your data in the following circumstances:

7. Your Rights & Choices

You have the following rights regarding your data:

8. Your Privacy Rights by Region

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know - You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your data.
  • Right to delete - You may request deletion of your personal information, subject to certain exceptions (e.g., data needed to complete a transaction, comply with legal obligations, or data already de-identified or incorporated into trained models).
  • Right to opt out of "sale" or "sharing"- We do not sell your personal information as defined by the CCPA. We may share de-identified or aggregated data with third parties for analytics and research purposes; however, this data does not constitute a "sale" under the CCPA as it cannot reasonably identify you.
  • Right to non-discrimination - We will not discriminate against you for exercising any of your CCPA rights.
  • Right to correct - You may request correction of inaccurate personal information.
  • Right to limit use of sensitive personal information - Health and fitness data may be considered sensitive personal information under the CPRA. You may request that we limit its use to what is necessary to provide the Service.

To exercise these rights, contact us at privacy@fitly.chat. We will verify your identity before processing your request and respond within 45 days as required by law.

European Economic Area, UK & Switzerland (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent laws:

  • Legal basis for processing - We process your data based on: (a) your consent (e.g., when you create an account); (b) performance of our contract with you (i.e., these Terms of Service); (c) our legitimate interests (e.g., improving our Service, training AI models, fraud prevention); and (d) compliance with legal obligations.
  • Right of access - You may request a copy of the personal data we hold about you.
  • Right to rectification - You may request correction of inaccurate or incomplete data.
  • Right to erasure - You may request deletion of your personal data, subject to legal retention requirements and the limitations described in Section 5.
  • Right to restrict processing - You may request that we limit how we process your data in certain circumstances.
  • Right to data portability - You may request your data in a structured, commonly used, machine-readable format.
  • Right to object - You may object to processing based on our legitimate interests, including the use of your data for AI model training.
  • Right to withdraw consent - Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint - You have the right to lodge a complaint with your local data protection authority.

To exercise these rights, contact us at privacy@fitly.chat. We will respond within 30 days as required by law.

Canadian Residents (PIPEDA)

If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access, correct, and challenge the collection, use, and disclosure of your personal information. To exercise these rights, contact us at privacy@fitly.chat.

9. Children's Privacy

Fitly AI is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child under 16 has provided us with personal data, please contact us and we will promptly delete it.

10. Third-Party Links

The Service may contain links to third-party websites or services (e.g., Stripe for payments, exercise demonstration videos). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

privacy@fitly.chat