Legal

Privacy Policy

Last updated: 9 September 2026

1. Who is responsible for your information

Appostafat GmbH, Rothusstrasse 23, 6331 Hünenberg, Switzerland, operates the Fitonomy mobile application and website and is responsible for the personal information described in this policy. We refer to the company as "Fitonomy," "we," or "us." Contact us at support@fitonomyapp.com.

This policy explains our processing of personal information. Reading it or using Fitonomy does not, by itself, constitute consent to optional processing. Device permissions, communication preferences, and other choices are separate from this notice. Fitonomy Mobility has its own privacy policy.

2. Information we collect

Account and fitness information

We process your account identifier, name, email address, and authentication information through Firebase Authentication. If you use Apple or Google sign-in, we receive the information that the sign-in provider makes available for your account. Your profile may include a photo, age, gender, height, weight, goals, preferences, body measurements, and health integration settings. We also process your workout history, personal records, achievements, activity, nutrition preferences, and meals you log so that you can use the related fitness features.

Photos, community, and support

We process images you select or take for a profile, meal scan, or support request, together with the content and details you submit. Community features use profile and activity information as explained below. Support requests can include your email, account identifier, device platform, app version, messages, and any image or video attachments you provide.

Usage and technical information

The app records feature interactions, session and event times, app version, and account identifiers for analytics. Service providers also process connection and device information needed to deliver their services, such as IP addresses, operating system details, notification identifiers, and crash diagnostics.

Purchases and subscriptions

Apple and Google process purchases made through their stores. RevenueCat helps us validate those purchases and manage access, using subscription and transaction information, your app account identifier, and account attributes such as email and name. For subscriptions purchased on the web through Stripe, Stripe processes billing and customer information and we use the resulting subscription status to provide access. Payment card details are handled by the payment provider rather than entered into your Fitonomy fitness profile.

3. Why we use information

We use information to authenticate accounts, deliver and personalize workouts and nutrition features, save progress, operate community features, manage subscriptions, answer support requests, send service communications, maintain security, diagnose errors, and understand how the Service is used. Optional marketing communications and advertising measurement are described in section 7.

Where data protection law requires a legal basis, providing the service you request and administering your purchase relate to our contract with you; keeping required financial records relates to legal obligations; and proportionate security, troubleshooting, and service administration relate to our legitimate interests, subject to your rights. Processing that requires consent, including where applicable to sensitive health information, requires a separate valid choice. This notice is not a substitute for that choice.

4. Meal photos and AI analysis

When you use the meal photo scanner, the selected image is uploaded to Google Firebase Storage. Our server retrieves that image and sends its image content to Anthropic's Claude API with a food analysis request. Anthropic processes the image to return estimated foods, portions, calories, and nutrients. This is cloud processing; the image is not analyzed solely on your device.

The analysis request sends the image and a food analysis prompt to Anthropic. Your Fitonomy name, email, and account identifier are not fields in that request. Nevertheless, an image can reveal personal information through its contents. Avoid including people, documents, or other information unrelated to the meal.

Fitonomy associates scan usage and results with your account to provide the feature and enforce scan limits. If you log the meal, its image and nutrition result can be saved with your meal history. The app attempts to remove images from scans that are discarded or fail; this cleanup is not a guarantee of immediate removal from every system. Provider processing is also subject to the relevant service arrangements and policies. Contact us for information about provider retention applicable to your scan.

AI nutrition results are estimates and can be wrong. You can review and edit the result before logging it. The scanner is not a medical or allergy assessment.

5. Apple Health, Health Connect, and Fitbit

Health integrations are optional. On supported devices, Fitonomy connects to Apple Health through HealthKit or to Health Connect on Android after you enable the integration and grant the relevant system permissions. Depending on the feature and permission, the app can read steps, heart rate, and distance, and write workouts, weight, body fat, energy intake, protein, carbohydrates, and fat. Availability differs by platform and the permissions you allow.

Fitbit is a separate account connection. After Fitbit authorization, our server stores connection tokens and makes Fitbit API requests for supported features, including steps and resting heart rate, and recording workouts, weight, or body fat. These requests pass through our server; the Fitbit integration is not entirely local to your device.

We use these connections for the fitness features you enable. Integration preferences are stored with your Fitonomy account, and fitness information you enter or save in Fitonomy can be stored with your account. You can change access in Apple Health or Health Connect settings and disconnect Fitbit through the app or Fitbit. Revoking access stops future authorized access; it does not itself delete information already saved in either service.

6. Community visibility

Community features make some information visible to other users. A public profile can include your display name, photo, level, streak, achievements, workout count, gender, and personal records. Choose a display name and image that you are comfortable sharing.

Activity sharing controls whether supported workout, achievement, streak, and tournament updates are published to everyone, friends, or nobody. When no activity sharing choice has been saved, the current default is everyone. Review the activity sharing control before participating. This setting controls activity publication; it does not make every public profile field private or necessarily remove information previously shared. Contact us if you need help removing community information.

7. Analytics, notifications, and marketing choices

App analytics and diagnostics

The app uses Google Firebase Analytics for usage events and account-linked analytics, Firestore for app event records, and Firebase Crashlytics for crash reporting in release builds. These services are separate from Meta advertising measurement. Declining Apple's tracking permission is not an app-wide switch that turns off all analytics or crash reporting.

Meta advertising measurement

The app includes Meta event measurement for interactions such as registration, onboarding, trial, checkout, and subscription events. Its mobile tracking permission flow starts disabled and enables tracking when Apple's App Tracking Transparency permission is authorized. Denied, unavailable, or unsupported authorization leaves this mobile tracking flow disabled. You can change an iOS tracking permission in your device settings.

Web subscription measurement is a separate flow. When the required checkout and account analytics consent is recorded, our server can send Stripe trial or purchase conversion events to Meta. These include hashed email and account identifiers, product, value, and currency, and, where provided in the consented checkout context, advertising identifiers, IP address, browser information, and the source page. Hashing an identifier does not make it anonymous. Web marketing choices are separate from the mobile device's tracking permission; contact us to withdraw a choice you cannot access in the interface.

Notifications and email

OneSignal helps deliver notifications and uses your app account identifier to associate the device with your account. Notification permissions can be managed in device settings. The app attaches your email address to OneSignal when you affirmatively choose marketing emails and removes that email association when that preference is disabled. Marketing email choice is separate from push notification and advertising tracking permissions. Use the available marketing preferences or unsubscribe instructions to stop marketing, or contact support@fitonomyapp.com. Essential account, security, purchase, and support messages may still be necessary.

Website storage

Your browser can control cookies and other website storage. Browser controls affect the website and do not control the mobile app's SDKs or device permissions.

8. Who receives information

Google Firebase provides authentication, cloud storage, databases, server processing, analytics, and crash reporting. Anthropic processes meal images for AI analysis. RevenueCat, Apple, Google, and Stripe receive the information relevant to purchases and subscriptions. OneSignal handles notification and permitted email delivery, and Meta receives permitted advertising measurement events. Connected health providers receive the requests and data involved in the integrations you enable. The information disclosed to each provider depends on the feature you use, as described above.

Other users receive community information according to section 6. We may also disclose information when required by law, to protect rights and address fraud or abuse, or in connection with a business transfer, subject to applicable data protection requirements. External services you visit or connect have their own terms and privacy policies. That does not remove our responsibility for our own processing and disclosures.

9. Retention and account deletion

Account, workout, meal, and related records are kept to provide your account and its features. You can request account deletion in the app or contact support@fitonomyapp.com for help or an external deletion request. Deleting the app from your device does not delete your account. Cancelling a subscription and deleting an account are separate actions; manage cancellation through the channel where you purchased it.

The account deletion workflow removes sign-in access, deletes or de-identifies supported account records and uploaded profile and meal images, and requests cleanup of connected OneSignal and Fitbit data. It removes account links from supported Stripe records rather than deleting all Stripe transaction or customer records. If a cleanup step fails, the workflow records it for retry. Deletion therefore does not mean that every copy in every service disappears immediately.

A limited deletion protection record uses a keyed, one-way identifier to prevent deleted account data from being recreated by delayed events. It is configured to expire after 30 days and is removed by scheduled cleanup. Deletion completion and retry records, minimized billing and event records, and records needed for financial obligations, security, or disputes can remain. Removing an account identifier from a record does not mean all other transaction information has been erased.

Support tickets and their attachments are managed separately from the account cleanup workflow. If you want these removed, include that request when contacting support. Third-party providers may retain records under their applicable obligations and service policies. Contact us for information about retained records or to request further deletion; applicable legal exceptions may limit what can be erased.

10. Your privacy rights and choices

Depending on the law that applies to you, you may request access to, correction of, deletion of, or a portable copy of your personal information, restrict processing, or object to processing based on legitimate interests or for direct marketing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also complain to the competent data protection authority, including your local EEA authority or the Swiss Federal Data Protection and Information Commissioner where applicable.

Where California privacy law applies, additional rights can include knowing the categories and specific information collected, correction, deletion, and opting out of sale or sharing for cross-context behavioral advertising. The legal meaning of sharing is broader than a payment for data. The advertising processing and permission controls described in section 7 remain relevant. You may exercise applicable rights without unlawful discrimination.

Contact support@fitonomyapp.com to exercise a right or ask about a choice that is not available in the app. We may need to verify your identity before acting on a request. We respond within the period required by applicable law and explain any applicable exception or extension.

11. Security and international processing

Fitonomy uses authenticated service requests, access controls, and encrypted network connections to protect information. No system or transmission method can guarantee absolute security. Please keep your account credentials secure and report suspected unauthorized access to us.

Our service providers may process information outside your country, including in the United States. Applicable data protection requirements continue to apply to those transfers. Contact us for details of the destinations and safeguards relevant to your information.

12. Children

Fitonomy is not directed at children under 13. Where a higher age or parental authorization is required for a particular processing purpose by local law, that requirement applies. Contact us if you believe a child has provided personal information without the required authorization so that we can investigate and address it.

13. Changes to this policy

We may update this policy as the Service or our practices change. The date above identifies this revision. Material changes will be brought to your attention where required by applicable law. Updating a notice does not by itself obtain consent for a new processing purpose.

14. Contact

For privacy questions, rights requests, or account deletion help:

Appostafat GmbH

Rothusstrasse 23, 6331 Hünenberg, Switzerland

Email: support@fitonomyapp.com