
PRIVACY POLICY
Last updated: June 2026
What We Collect
- •Email address — account creation, login, and password reset
- •Workout logs — exercises, sets, reps, and weights
- •Video metadata — titles, tags, notes, and thumbnails for videos you add
- •Anonymous usage events — which screens you open, when you import a video, when you start and finish a workout. Helps us understand which features are useful. You can switch this off in Profile → Privacy.
- •Anonymous crash reports — when the app crashes or hits an unexpected error, we record the error type, message, and stack trace so we can fix it. No personal data is included. You can switch this off in Profile → Privacy.
- •Subscription & purchase data — if you subscribe, we process your purchase receipts, transaction history, and a pseudonymous purchase identifier to manage your subscription and unlock paid features. Payment itself is handled entirely by Apple or Google — we never see or store your card details.
What We Don't Collect
- ✕No location data
- ✕No cross-app or cross-site tracking
- ✕No third-party advertising, analytics, or crash-reporting trackers in the app (no Google Analytics, Firebase, Crashlytics, Sentry, Mixpanel, etc.). The website uses only cookieless page-view analytics — see Analytics below.
- ✕No IDFA, advertising ID, or device fingerprint
- ✕No contacts, phone, or health data
- ✕Locally recorded videos stay on your device — never uploaded to our servers
How Your Data Is Stored
- •Stored securely in Supabase (PostgreSQL with row-level security)
- •All data is isolated to your account — no other user can access it
- •Local video files are stored on your device only
- •Video thumbnails are in a private storage bucket accessible only to you
Analytics
- •We record anonymous events about how the app is used — for example, when you open a screen, import a video, or finish a workout — so we can fix friction and prioritise features people actually use.
- •Events never include the content of your videos, exercise notes, set logs, or tags. They include things like a screen name, a platform name (YouTube / Instagram / TikTok / Facebook / local), counts, and timestamps.
- •Events are stored on our own Supabase database under the same row-level security as the rest of your data — no third-party analytics provider receives them.
- •Opt out anytime in Profile → Privacy → "Share anonymous usage data". Off = no events recorded and any buffered events are deleted.
- •Legal basis under GDPR: legitimate interest in improving Fitness Vault (Article 6(1)(f)).
- •Website analytics. This site (fitnessvault.fit) uses privacy-friendly, cookieless analytics (Vercel Analytics and PostHog, the latter configured with in-memory persistence so it sets no cookies) to count aggregate page views and which pages convert. No cookies, no personal data, no cross-site tracking, and no Google Analytics — entirely separate from the in-app analytics described above.
Crash Reporting
- •When the app crashes or hits an unhandled error, we record the error type (e.g. "NetworkException"), a short message, the stack trace, the app version, and the platform (iOS / Android / web). This lets us fix bugs we'd otherwise never see.
- •Crash reports never include the content of your videos, exercise notes, set logs, tags, or any personal data. We do not capture screen contents, keystrokes, or user inputs.
- •Reports are stored on our own Supabase database under the same row-level security as the rest of your data — no Crashlytics, no Sentry, no third-party crash SDK.
- •Opt out anytime in Profile → Privacy. Off = no crashes recorded and any buffered reports are deleted.
- •Legal basis under GDPR: legitimate interest in keeping Fitness Vault reliable (Article 6(1)(f)).
Third-Party Services
| Service | Data Shared |
|---|---|
| Supabase | Email, workout data, video metadata |
| YouTube Data API | Video ID only (no personal data) |
| Google Gemini API | Video title/description only |
| Brevo | Email address only |
| RevenueCat | Purchase receipts, transaction data, and a pseudonymous app user ID (processed on servers in the United States). No card details. |
Most API calls go through our server. In-app purchases are handled on-device by Apple or Google and by RevenueCat, our subscription manager.
AI & Automated Processing
- •Exercise tagging. When you import a video, Google Gemini reads its title and description to suggest exercise tags (e.g. "squat", "push day"). This organises your library — it does not make any decision about your health, training, or account.
- •No automated decisions about you. We do not use AI for profiling or for any decision that produces legal or similarly significant effects.
- •AI-generated imagery. Some promotional images on our store listings, website, and social channels are created or edited using AI. Where used, they are labelled as such.
- •If we add features that generate training content (for example, an AI workout planner), that content will be clearly labelled as AI-generated, will carry a reminder that it is general information and not medical or professional training advice, and you will be asked to confirm you train at your own responsibility before using it.
Your Rights (GDPR / UK GDPR)
- •Access — all your data is visible in the app
- •Correct — edit exercises, notes, tags, and video details anytime
- •Delete — use "Delete Account" in Settings to permanently remove all data
- •Object — we don't do automated decision-making or profiling
To exercise any of these rights, email hello@fitnessvault.fit
Data Retention
- •Your data is kept for as long as you have an account
- •When you delete your account, all data is permanently removed immediately
- •We do not keep backups of deleted accounts
Children
Fitness Vault is not intended for children under 16. We do not knowingly collect data from anyone under 16.
Changes
If we make changes to this policy, we will update the "Last updated" date above and notify users in the app.
Contact
For privacy questions or data requests: hello@fitnessvault.fit