fiti.Open web app

Privacy

Updated 8 October 2026.

In short

Fiti keeps as little as it can: what you choose to log, and what it needs to sign you in.

Fiti does not sell your personal or health data, use it for advertising, or add advertising trackers. Service providers receive data as described below.

Who operates Fiti

Fiti is operated under the name Fiti Fitness. Contact: hey@fiti.fitness. This notice covers fiti.fitness, app.fiti.fitness and the Fiti mobile apps.

What Fiti keeps

Your account: a username, the name the app calls you, and an email address or phone number if you add one. Your password is kept only as a hash that cannot be read back.

Your journal: what you log. Meals, weight, height, age and sex, targets, medicines and supplements and the doses you took, GLP-1 doses with your notes, workouts, and what was said in voice chats.

From Apple Health or Health Connect, only if you connect it: steps, active calories and weigh-ins. Everything else on the Health data screen is shown and not kept.

A short record of each device you are signed in on, and counters that limit sign-in attempts and photo readings.

Where it is kept

Your journal is stored on this device and on the Fiti server under your account, so it follows you to another device.

The application server and its database backups are hosted in Canada. Fiti is initially offered in Canada and Brazil. Connections to the public website and app use HTTPS through Cloudflare; this does not mean that data is encrypted end to end against our service providers.

Who else receives it

Cloudflare provides HTTPS delivery, routing and security for the website and app. It processes requests passing through its network, including IP addresses and traffic information. This can involve processing outside Canada or Brazil.

PostHog, hosted in the European Union, measures visits to fiti.fitness: pages viewed, buttons clicked, referring site, browser, device type and approximate location derived from the network address. It sets no cookies on the website and records no screen sessions. It never receives what you log in your journal.

OpenAI, a company in the United States, receives data only when you use photo reading or the voice assistant. Reading a meal photo sends that photo and its meal category. Talking sends your voice, conversation and information needed to answer or perform the actions you request, including weight, food, movement, medicines or workouts.

Fiti does not automatically send OpenAI your account name, username, email address or phone number. Personal details may still be included in what you say, photograph, or save as free-text journal entries used by the assistant. Voice sessions use a one-way account code for abuse prevention. OpenAI sees your network address when your device connects directly for voice.

Under OpenAI’s standard API policy, submitted data is not used to train AI models unless the API customer opts in. OpenAI may keep it for up to 30 days for abuse monitoring; some safety or legal cases may be retained longer. Fiti does not store the original meal photo or voice recording. Saved voice conversations are kept as text in your journal.

Provider notices: Cloudflare Privacy, OpenAI API data controls and PostHog Privacy.

Cookies and local storage

The web app uses the fit_session sign-in cookie. It is HttpOnly, Secure on the public app and SameSite=Lax, and expires with its session after up to 90 days or is invalidated when you sign out. It is used for authentication, not advertising.

The journal, account/session record and preferences also use local storage on your device. Native builds use a bearer token for authentication. Signing out clears this app’s local journal and session record. Clearing browser storage can remove unsynced entries.

The marketing site has no account database or advertising scripts. It uses PostHog for cookie-free visit statistics, as described above. Its server can record access requests, and Cloudflare processes delivery and security traffic. The application records operational events such as account identifiers, AI model/usage counts and errors; it does not log photo contents or voice recordings.

Apple Health and Health Connect

Fiti reads your phone’s health data only after you allow it, and only the kinds you switch on. If you turn on sending, what you eat, your weight and your strength sessions are written there.

What Fiti reads there is used only to show it back to you. It is never used for advertising and never sold. A day’s steps and calories burned are part of what the voice assistant is given when you ask about that day.

You can stop at any time in Apps & devices, or in your phone’s own health settings.

Read the phone-health details.

Why Fiti may keep it

Fiti uses account information to sign you in and sync your journal, and health information to provide the journal, trends, estimates, reminders and optional features you request. Operational records help protect the service, investigate failures and control AI usage.

The app asks for agreement before opening your journal. Optional AI and phone-health features involve additional data flows described here. You can stop those features, revoke phone permissions, sign out or delete your account.

How long data stays

Account and journal data stay while you keep your account, until you delete or change them. There is no automatic inactivity-deletion period.

Database backups are scheduled daily in Canada. A successful backup run verifies a consistent snapshot before removing recognized backups outside the 30-day retention window. Deletions in the live database can remain in backups until they expire; outages or a failed backup job can delay expiry.

Sign-in sessions last up to 90 days unless revoked sooner. Operational logs and security records are kept separately from the journal; there is not yet a fixed published retention period for all of those records. Contact us about a deletion request and any necessary security or legal retention.

What you can do

Take a copy: Export on the You screen gives you your journal as a file.

Correct it: information you logged can be edited or removed.

Delete everything: clears the journal on this device and syncs that change to the server; your account stays.

Delete account: removes your account and ends its server sessions. A household owned only by that account and its journal are deleted. If other accounts share a household, its journal and profiles remain for those members.

Deleting an account cannot remotely erase an offline device’s cached copy, a file you exported, or records already written to Apple Health or Health Connect. Clear those copies on the device or in the receiving app. Database backups and service-provider retention have the limits below.

Children and young people

People of any age can create a Fiti account. There is no minimum signup age or age gate. The current release has no dedicated guardian-consent or child-account workflow, and its nutrition estimates and assistant instructions are designed around adults.

Email hey@fiti.fitness with questions about a child’s personal or health information, or to request review or deletion. Opening account creation to all ages does not mean that child-specific safeguards or consent mechanisms are implemented.

Contact and privacy requests

Email hey@fiti.fitness to ask about access, correction, deletion, consent, service providers or a privacy concern. We may need to verify that a request concerns your account before changing or disclosing its data.

People in Canada and Brazil can contact their relevant privacy authority about a concern, including the Office of the Privacy Commissioner of Canada or Brazil’s ANPD. Your applicable rights depend on where you live.

hey@fiti.fitness

If this changes

If what Fiti keeps or shares changes, this page changes with it and the app asks for your agreement again.