Legal

Privacy Notice

What we collect, what we don't, why, and the strict limits we put on it.

Version
v0.4
Effective
2026-09-18
Last updated
2026-08-19

This Privacy Notice explains howFIT TRAINR LLC ("FitTrainr", "we", "us", or "our") collects, uses, discloses, and protects information about you when you use the FitTrainr coaching platform (the "Service"), including the website at https://app.fittrainr.com, the web application at https://fittrainr.com, and our mobile apps.

We have three things we want you to take away from this document:

  • Your wellness and fitness data is never shared with advertisers. Workouts, nutrition logs, body weight and measurements, progress photos, coaching messages, client records — none of it is sold, rented, shared with, or used to build audiences for advertisers. Ever.
  • We access only what is required to operate the platform you are paying for.
  • Our public marketing website uses one optional advertising pixel — and only if you opt in. Nothing advertising-related loads until you say yes, and you can change your mind at any time on Your Privacy Choices. Section 7 has the full story.

This version of the Notice was published on 2026-08-19 and takes effect on 2026-09-18. The one change it announces — the optional, opt-in advertising pixel on our marketing website — stays switched off until this version takes effect, at the earliest.

1. Information We Collect

1.1 Account information

When you sign up — as a coach, sub-coach, or client — we collect your name, email address, role, and authentication identifiers (such as the unique ID returned by your single sign-on provider). If you set a password, it is hashed before being stored; we never see or store your plaintext password.

1.2 Profile information

Optional profile fields you choose to add: a profile photo, biography, timezone, preferred units, contact preferences, and (for coaches) professional details such as certifications and specialties.

1.3 Wellness and fitness data

For clients, the Service stores the wellness data you log: body weight, body fat percentage, body measurements, progress photos, nutrition entries, workout completions, and similar metrics. Coaches store the plans and content they create for their clients.

These records are wellness data, not medical records. FitTrainr is not a HIPAA-covered entity and does not collect Protected Health Information (PHI). See our Wellness Disclaimer for the full statement.

1.4 Coaching messages and content

Messages exchanged between coaches and clients (including 1-1 chats, group chats, file attachments, and voice notes if/when introduced) are stored to deliver the Service. We do not review, screen, or index the contents of these messages for any purpose other than operating the platform, complying with law, or responding to abuse reports.

1.5 Payment information

Payments are handled by Stripe. Card numbers and bank details never touch our servers. We store the limited tokens Stripe returns to us (such as a customer ID and the last four digits of the card) so we can show your billing history and invoices.

1.6 Ambassador and affiliate information

If you participate in the FitTrainr Ambassador Program, we collect additional information related to your role as an ambassador, including: your public display name, social media handle and platform, referral link activity (clicks, sign-ups, and conversions attributed to your links), commission earnings, and tax-related information (such as the data collected via Stripe for 1099-NEC reporting if your earnings exceed applicable thresholds).

Certain ambassador profile information — your display name, handle, and platform — is published on our marketing website to identify you as an active program participant. Referral performance metrics are shared with FitTrainr administrators for program management. For details on the program, see our Affiliate & Ambassador Disclosure.

1.7 Technical and usage data

When you use the Service we collect standard server logs (IP address, user agent, request path, response status, timestamp). We also collect minimal product analytics — events like "user signed in", "coach created plan" — without third-party trackers or advertising IDs. Inside the app there are no third-party analytics, advertising pixels, or social-media tracking scripts. On the public marketing website — and only there — we use a single optional advertising pixel (the Meta Pixel) that stays off unless you opt in through the cookie banner. Section 7 describes exactly what it shares and how to switch it off.

1.8 AI abuse and security monitoring

To keep AI features safe and to enforce our Terms, the Platform automatically records each AI interaction: the date and time, the feature and model used, token counts, response latency, a truncated preview of the prompt you submitted (after sanitization), and security signals such as detected prompt-injection patterns, model safety blocks, and rate-limit denials. Where an interaction is flagged or blocked by these security controls, the AI-generated response text is also retained.

These records are used solely to detect, investigate, and prevent abuse, fraud, and misuse of AI features. They are not used for advertising, are not sold or shared for marketing, and are not used to train AI models. Access is restricted to authorized platform administrators. AI interaction records are retained for 90 days and then automatically deleted, or earlier if your account is deleted. Repeated abuse signals may result in AI features being automatically suspended for your account pending administrator review.

2. How We Use Information

  • To provide, maintain, and improve the Service.
  • To authenticate you and protect your account.
  • To deliver coach-to-client communications and store the records of those communications on behalf of the parties involved.
  • To bill you (for coaches) and to power admin/support tooling.
  • To detect, prevent, and respond to fraud, abuse, and security incidents.
  • To operate the Ambassador Program — tracking referral activity, calculating commissions, publishing ambassador profiles on the marketing website, and fulfilling tax reporting obligations.
  • To comply with legal obligations.

3. How We Share Information

We share information only in the limited circumstances below.

3.1 Between coaches and their clients

The Service exists to enable coaching. By signing up as a client and accepting a coach's invitation, you authorise us to share the wellness data you log with that coach (and, where applicable, the coach's organisation and any sub-coach delegated to your account).

3.2 Ambassador profiles on the marketing website

If you are an active ambassador, limited profile information (display name, social media handle, and platform) is published on our marketing website at https://app.fittrainr.com/ambassadors to identify you as a program participant. This information is stored in a separate analytics system (Google BigQuery) that is isolated from the main application database. The marketing website has read-only access to this data and cannot access any other user information.

3.3 Service providers (subprocessors)

We use a small set of vetted third parties to operate the Service. See our subprocessors list for the current set, including the data each one processes and the regions where they operate.

3.4 Legal and safety

We may disclose information if required by law, by valid legal process, or where we have a good-faith belief that disclosure is necessary to prevent harm or to protect the rights, property, or safety of FitTrainr, our users, or the public.

3.5 Business transfers

If FitTrainr is acquired, merged, or undergoes a similar transaction, information may transfer to the successor entity. We will notify affected users in advance and ensure the successor is bound by terms no less protective than those in this Notice.

3.6 Advertising partner (marketing website only, opt-in)

If — and only if — you opt in on our public marketing website, that website shares limited technical data with Meta Platforms, Inc. so we can measure our ads and reach people who visited the site. Meta uses this data for its own purposes under its own privacy policy as an independent controller; it is not one of our subprocessors and does not process it on our instructions. Section 7 lists exactly what is shared, for what purposes, and how to opt out — and your wellness and fitness data is never part of it.

4. Data Retention

The simple version:

  • Account and profile data: retained while your account is active, plus 30 days after deletion (so we can recover from accidental deletions and process disputes).
  • Wellness logs and messages: retained for the life of the account, except that check-ins, forms, and other records created within a coaching relationship are cleared when you change coaches. Deleted on the same 30-day cycle as account data.
  • Server logs: retained for 365 days for security, debugging, and compliance.
  • Backups: retained for 30 days, after which they are overwritten.
  • Financial records: retained as required by tax and accounting law (typically 7 years), even after account deletion. These records are kept in restricted-access systems.
  • Ambassador data: referral activity, commission records, and tax-related information are retained for the duration of your participation and for 7 years after termination for tax compliance. Your public ambassador profile is removed from the marketing website within 24 hours of termination.

5. Your Rights

You have the right to access, correct, export, and delete your personal data. Most of these are self-service from inside the app.

  • Access: see all of your data from your profile and history pages.
  • Correct: update profile fields, logs, and content directly in the app.
  • Export: request a structured export of your data via support@fittrainr.com.
  • Delete: see Account Deletion. This page is publicly accessible without signing in, as required by mobile app store policies.

Residents of jurisdictions with additional rights — including the EU/EEA (GDPR), the United Kingdom (UK GDPR), California (CCPA/CPRA), and other US state privacy laws — may have further rights such as the right to object to processing, to lodge a complaint with a supervisory authority, or to opt out of certain processing activities. The right to opt out of "sharing" for cross-context behavioral advertising (California) is self-service: use Your Privacy Choices, or simply browse with Global Privacy Control enabled — we honor the signal automatically. To exercise any other right, contact support@fittrainr.com.

6. Children

FitTrainr is not intended for, and we do not knowingly collect data from, anyone under 16 years old. If you believe a child under 16 has provided us with personal information, please contact support@fittrainr.com and we will delete the information promptly.

7. Cookies, Advertising, and Similar Technologies

7.1 Cookies

We use the cookies necessary to keep you signed in, to remember your preferences, and to protect against cross-site request forgery. These are essential, they are the only cookies used inside the app, and they need no consent. See our Cookie Policy for the complete list.

7.2 Advertising on our marketing website (opt-in only)

Our public marketing website at https://app.fittrainr.com uses one advertising tool: the Meta Pixel, provided by Meta Platforms, Inc. It is off by default. The pixel script does not load — not even silently — unless you opt in through the cookie banner, and it never runs inside the app or anywhere you are signed in.

If you opt in, the pixel shares with Meta:

  • Identifiers — a random cookie ID (the _fbp cookie), your IP address, and browser and device information.
  • Internet activity — which public marketing pages you view, the referring page, and ad-click identifiers (such as the fbclid URL parameter) when you arrive from a Meta ad.

We use this for two purposes only: ad measurement (did our ads actually bring people here) and retargeting (showing FitTrainr ads on Meta's platforms to people who visited this site). We send Meta no names, no email addresses, no account data, and no wellness data — the pixel is limited to standard page-view and content-view events with no added parameters.

Meta processes this data for its own purposes as an independent controller under the Meta Privacy Policy; it is not one of our subprocessors and does not act on our instructions.

7.3 California "sharing" disclosure and how to opt out

California law (CCPA/CPRA) calls the disclosure described above "sharing" personal information for cross-context behavioral advertising, and gives you the right to opt out of it. We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. You can opt out of sharing three ways — no account required:

  • Do nothing. Sharing is off by default and stays off unless you opt in.
  • Use the switch. Your Privacy Choices shows your current setting and lets you change it at any time. Turning it off stops the pixel and deletes its cookies.
  • Turn on Global Privacy Control. If your browser sends the GPC signal, advertising stays off on this site automatically — no banner interaction needed, and it overrides any earlier opt-in.

7.4 What is never shared with advertisers

Your wellness and fitness data — workouts, nutrition entries, body weight and measurements, progress photos, coaching messages, and your clients' data — is never shared with Meta or any other advertiser, and is never used to build advertising audiences. The pixel exists only on the public marketing pages of this website. There is no version of the opt-in above that changes any of this.

8. International Transfers

FitTrainr's primary infrastructure is hosted in the United States, in the Google Cloud Platform us-central1 region (Iowa). If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

For users in the EU/EEA and the UK: this transfer relies on the applicable Standard Contractual Clauses with our subprocessors and on supplementary safeguards (encryption in transit and at rest, access controls, audit logging). You may request a copy of the applicable SCCs by emailing support@fittrainr.com.

9. Security

We protect your data with the controls described on our security page: encryption in transit, encryption at rest, IAM-based database authentication, dependency scanning, audit logging, two-factor authentication for admins, and regular backups. No security program is perfect; if you believe your account has been compromised, please email support@fittrainr.com immediately.

10. SMS/Text Messaging

Coaches on FitTrainr can send text messages through the Service to prospective and current clients who have opted in. If you check the SMS consent box on a coach's lead-capture or booking form, we collect your mobile phone number together with a record of your consent: the date and time, your IP address, and the exact consent text you were shown.

We use this information solely to send you text messages related to that coach's services — such as appointment reminders and confirmations, follow-ups to inquiries you submitted, and promotional offers from that coach. Message frequency varies based on your interactions with your coach. Message and data rates may apply.

You can opt out at any time by replying STOP to any message, and get help by replying HELP or emailing support@fittrainr.com. Consent to receive text messages is never a condition of purchasing any good or service.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent records are not shared with, sold to, or rented to any third party, except as necessary to deliver the messages you have requested (i.e., our SMS delivery provider, listed on our subprocessors page).

11. Google Account Data (Drive, Calendar, and Ads)

Coaches can optionally connect a Google account to FitTrainr. Nothing below happens unless you choose to connect, and each service is granted separately — connecting Drive does not grant access to your Calendar or your Google Ads account. This section describes how we access, use, store, share, and delete Google user data.

11.1 What we access, and why

  • Google Drive (drive.file): we can only see the individual files and folders you explicitly pick through Google's file picker. We use them so you can attach documents — programs, contracts, spreadsheets — to a client record and import contract documents. We cannot see, list, or search the rest of your Drive.
  • Google Calendar (calendar.readonly): read-only access to your calendar events, used for one purpose: to display your existing commitments alongside your FitTrainr client appointments on your schedule so you do not double-book. We do not create, modify, or delete calendar events with this access.
  • Google Ads (adwords): for coaches who advertise their own business, we read campaign performance data to show spend and results inside FitTrainr, and create or update campaigns when you ask us to.
  • Account email (userinfo.email): the email address of the connected Google account, so you can see which account is linked.

11.2 How it is stored

Google access and refresh tokens are encrypted at rest (AES-256-GCM) before being written to our database, are decrypted only in memory to serve your own requests, and are never logged, never sent to your browser, and never exposed to any other user. Google user data itself is fetched on demand to render the feature you are using; we do not build a mirrored copy of your Drive or your calendar.

11.3 Limited Use — what we will never do

FitTrainr's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is not sold, not shared with data brokers or advertisers, not used for advertising or personalised ad targeting, not used for credit assessment, and not used to develop, improve, or train generalised artificial intelligence or machine learning models. No FitTrainr employee reads your Google user data except with your explicit consent (for example, if you ask support to investigate a problem), where required for security or to comply with law, or on aggregated, anonymised data used for internal operations.

11.4 Disconnecting and deletion

You can disconnect a Google account at any time from Settings → Integrations → Google in the coach portal. Disconnecting deletes our stored tokens immediately, and our access ends at that moment. You can also revoke access directly from your Google account at myaccount.google.com/permissions. Deleting your FitTrainr account deletes the tokens on the same 30-day cycle described in section 4. Files in your Drive, events in your Calendar, and your Google Ads campaigns are yours and are unaffected — we never delete them.

12. Changes to this Notice

We may update this Notice from time to time. Material changes will be communicated by email to your account address at least 30 days before they take effect, and the version and effective date in the header above will be updated. The full version history lives in our legal changelog.

13. How to Contact Us

For privacy questions, requests, or complaints, email support@fittrainr.com or support@fittrainr.com. Postal address available on request.