Privacy Policy
Draft — pending legal review.
For the short version of what we do and don't do with your data, see our commitment to you. The Terms govern where any of these differ.
What we collect
Only what the app needs to work. There is no tracking SDK, no analytics service and no advertising network in Fitoria, so nothing is collected in the background.
- Account details — handled by our authentication provider: your email address and, if you set one, a display name. We store an internal id, your handle and your preferences (time zone, units, privacy toggles).
- Health data you log — weight, food and drink, workouts, and the profile you set at onboarding: age, height, activity level, goals, experience, equipment and any injuries or limitations you choose to describe.
- Substance-use data, if you use that part of the app — smoking and alcohol habits, quit dates, daily check-ins and relapses. This is the most sensitive category we hold and we treat it accordingly: it feeds no XP, no streak, no quest and no avatar, it is never shown to anyone else, and the wellness page carries no advertising at any tier.
- Content you create — routines, movements, meals, meal plans, recipes, comments and shopping lists. Private until you publish it.
- Billing state — whether you have an active subscription, and the customer and subscription identifiers our payments provider issues. Card numbers never reach Fitoria.
- Safety records — reports you make or that are made about your content, and a log of any action our staff take on your account, with the reason. An enforcement decision with no record is not one anybody can appeal.
- Messages you send us — anything you write in the contact form, plus the page you were on and any reply address you chose to give. We store it rather than only emailing it, so a message can't be lost between us. Sent while signed in, it is part of your account: it is in your export and it is deleted with your account. Sent signed out, it is attached to no account at all — which also means deleting an account can't reach it, so tell us if you want it removed.
How it's used
Your data powers your own charts, progress, streaks, quests, avatar and plans. That is the whole of it — Fitoria has no second purpose that your logs serve.
On AI: plans and coaching check-ins are generated by templates and heuristics that run on our own servers. Nothing you log is sent to an AI provider today, because no model is called at all. When that changes we will say what is sent and this page will change before it does, not after.
On advertising: free accounts see sponsored placements, always labelled. They are not targeted — everyone sees the same rotating pool, and no third-party ad network is loaded, so no advertiser receives anything about you.
Who else sees it
We do not sell, rent or otherwise distribute your personal information. The outside services involved in running Fitoria are a short enough list to simply state:
- Authentication — holds your sign-in credentials and session. We never see your password.
- Payments — processes subscriptions. Card details go to them directly and are never stored by us.
- Food databases (USDA FoodData Central and Open Food Facts) — searched from our servers when you look up an ingredient or scan a barcode. They receive a search term or a barcode and nothing else: no account id, no session, no identity. They cannot tell one user from another, or a user from us.
Our hosting and database providers necessarily store the data in order to serve it. They process it on our instructions and for no purpose of their own; we will name them specifically here as Fitoria leaves beta, because that list is changing while infrastructure is still being chosen.
Barcode scanning happens on your device. Camera frames are read in the page and discarded — only the decoded digits are sent to us, and no image ever leaves your phone.
What other members see
Your logs, weights, goals and wellness entries are private and are never shown to anyone else. What is public is what you choose to publish, plus a profile at your handle showing your level, streak and the date you joined. Making your profile private hides that page; published items stay published and stay attributed, because withdrawing something other people saved is a different decision, and unpublishing it is the control for that one.
How long we keep it
Deleting your account hides it immediately and permanently erases your data after a 30-day grace period, during which you can restore it yourself with no email and no support ticket. After that, logs, weights, progress, saved meals, unpublished routines and recipes, wellness entries and shopping lists are gone.
Three things survive that, and you should know which before you decide. Everything else goes, including your consent record and any staff notes about your account.
- Content you published to the community. Publishing grants us a licence to keep carrying it — stated in the Terms and shown to you at the moment you publish, not only here. It stays at the same link with your name, handle and profile removed, shown as Anonymous, and our team then decides whether to keep it or delete it. Unpublishing an item before you leave removes it in the ordinary way. Anything you never published is deleted with the account.
- Copies other members saved. A saved routine, meal or recipe is a self-contained copy in someone else's library — deliberately, so that saving something does not leave you dependent on another account continuing to exist. Those copies are theirs and stay with them.
- Payment records held by our payments provider. They keep transaction history under their own retention rules for tax and accounting, and that is theirs rather than ours to erase. Our own copy — which is only whether a subscription was active, and the identifiers linking to theirs — goes with the account.
Your controls
- Export your data as a file, from settings. It covers everything you created or logged. The one thing it gives as a number rather than a list is who follows you — who you chose to follow is yours, but the roster of people who chose you is theirs.
- Delete your account from settings — self-serve, with the 30-day window above.
- Reset your progress without deleting the account, choosing what goes.
- Make your profile private, unpublish anything you shared, and switch off activity events — one toggle each.
All of it is in settings. None of it requires contacting us.
Cookies
Fitoria sets a session cookie so you stay signed in. That is the only cookie we set. Subscribing sends you to our payments provider's own checkout page, which sets its own cookies under its own policy — on their site, not ours.
There are no advertising cookies and no tracking pixels, which is why there is no consent banner to dismiss: there is nothing to consent to.
Questions and requests
Write to support@fitoriafit.com for anything this page doesn't answer, including access, correction or erasure requests that the self-serve tools above don't cover.
This page will get more specific as Fitoria leaves beta. It will not get broader — anything new we collect gets added here before it is collected, not after.