FitCoach

FitCoach Privacy Policy

Effective date / last updated: 2026-08-21

Plain language, on purpose. FitCoach handles your training data, and training data is health data. Here is exactly what we collect, where it lives, and what you can do about it.

1. Who we are

FitCoach is a solo-operated product: an AI-chat fitness coach that stores your training history and builds weekly plans. It is a free experiment run by an individual — not a company, and not a paid service. The operator of FitCoach is the data controller for the personal data described below. Contact: henryfelella@gmail.com.

Because it is an experiment, it may be discontinued. If that happens you will be told on the site and given at least 30 days in which export still works, so your training history does not disappear with it. The terms set that out in full.

2. What we collect

We collect only what coaching needs, and we name it specifically:

3. Where it comes from

From you, via the AI assistant you connect through (Claude or ChatGPT). Your conversation with the assistant itself is not stored by FitCoach — we only receive the structured tool inputs and outputs the assistant sends to our server. The assistant's own handling of your conversation is governed by its provider's privacy policy and your agreement with that provider: Anthropic (Claude), OpenAI (ChatGPT). FitCoach does not control the assistant's retention or training settings.

4. Why we use it

To build and adapt your training plans, operate your account and trial or subscription, and — unless you opt out — to compute population-wide statistics that tune the coaching engine for everyone. Nothing else. No advertising, no sale of your data, and no training of AI models on your data.

Population tuning, precisely

Each time we plan your week we archive a snapshot of the numbers the engine fitted to your log — never raw workouts, never your notes, never anything identifying. A background job reads those snapshots as aggregates only (counts, rates, and means across all users) and nudges a handful of hand-bounded engine constants; it can never see, or be reversed into, one person's training. It stays completely inert until the population passes a minimum size, and each constant may move by one small step inside a fixed envelope.

This is opt-out and it is a real switch: tell your assistant "don't use my data for research" and the snapshot is never written in the first place, so nothing of yours can reach the aggregate at all. Say "you can use my data" to opt back in. account_status tells you which way the setting is set.

5. Where it lives

Your data is stored in Supabase (hosted Postgres), region: United States. Row-level security is enabled and the database is accessed only by our application server using server-held credentials. The application server runs on Fly.io; your data lives in the database, not on the server's disk. All connections use TLS.

6. Who else touches it (subprocessors)

ProviderRoleData they touch
SupabaseDatabase and authenticationAll categories listed in section 2
Fly.ioApplication hostingData in transit and in processing
Anthropic (Claude) / OpenAI (ChatGPT)Conduit, not a subprocessor in the usual sense — you talk to FitCoach through your chosen AI assistantYour messages to the assistant, under that provider's own privacy policy. FitCoach only receives what the assistant sends to its tools.

We will update this list if it changes and aim to give notice of changes.

Links you publish yourself

Asking FitCoach to share your plan mints a public web page for one plan, at a secret random URL. Anyone holding that link sees the plan and your first name only — no email, no other plan, no logs, notes, metrics, or goals, and the plan's written rationale is filtered so health-related sentences are dropped rather than published. Links expire after 30 days by default (you can pick another window, or none), you can list every link you have made and whether it is still live, and you can revoke any single link or all of them at once. Deleting your account kills every link immediately. Nothing is ever published unless you ask for it.

7. How long we keep it

8. Your rights: export, correction, deletion

9. No sale, no ads, no model training

FitCoach does not sell personal data, does not share it for advertising, and does not use it to train AI models. The population tuning in section 4 is not model training: it adjusts a handful of numeric constants from aggregate statistics, and never reads an individual's data. If any of this ever changed for consumer health data, Washington law would require your separate signed authorization first — practically: we just don't sell it.

10. Consumer Health Data Privacy Policy (Washington My Health My Data Act)

Washington's My Health My Data Act (MHMDA) protects "consumer health data" broadly — including physical fitness measurements, injuries, and inferences about health. Workout logs, effort ratings, recovery scores, wellbeing notes, and injury notes qualify. This section is our Consumer Health Data Privacy Policy for Washington residents; similar laws in Nevada and Connecticut are honored the same way.

Categories of consumer health data collected

Workout logs (exercises, sets, reps, weights, effort ratings), runs and other cardio, body measurements, recovery metrics you log (sleep, resting heart rate, HRV), injury and constraint notes, subjective wellbeing and session notes, body-related goals, and derived fitness inferences (estimated one-rep maxes, recovery score, adherence, deload flags).

Sources and purposes

Collected from you, through your AI assistant, to provide the coaching service you asked for: building and adapting your training plans. Unless you opt out, statistics derived from your fitted numbers also feed the aggregate engine tuning in section 4, which never reads an individual's data. We collect nothing beyond what coaching needs, and we will ask for consent before collecting anything new.

Sharing and third parties

Consumer health data is shared only with the processors in section 6 (Supabase for storage, Fly.io for hosting), and reaches your AI assistant's provider only because you talk to FitCoach through it. The one other way any of it becomes visible is a share link you create yourself, which publishes one plan and your first name and which you can revoke at any time (section 6). We do not share consumer health data for advertising and do not sell it; a sale would require your separate signed authorization, which we will never ask for.

Your rights

You may access your consumer health data (self-serve export, section 8), withdraw consent, and have it deleted — deletion is self-serve, immediate, and irreversible (section 8), and no copy is retained by us. To exercise any right you cannot exercise in the product, email henryfelella@gmail.com. If we deny a request, you may appeal by replying to our decision, and Washington residents may contact the Washington Attorney General.

Geofencing

Not applicable — FitCoach does not collect location data and does not geofence anything, health facilities included.

11. EU/UK (GDPR) and California (CCPA/CPRA)

If you are in the EU or UK: our legal bases are performance of contract (providing the coaching you signed up for), consent for health-adjacent data, and legitimate interests for the aggregate engine tuning in section 4 — which you can object to at any time by opting out, in which case nothing of yours is ever collected for it. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Exercise them via henryfelella@gmail.com; export and deletion work as described in section 8.

If you are a California resident: you have the right to know, correct, and delete personal information, and the right to opt out of sale or sharing — moot here, because we do not sell or share personal information as defined by the CCPA/CPRA. We do not discriminate against you for exercising your rights.

12. What our servers log

Every request to our server writes one line to an operational log: a random request id, the HTTP method, the path, the response status, how long it took, and — for tool calls — the name of the tool. That is the whole line. Deliberately excluded: request bodies, access tokens, and user ids — no log line names you or carries anything you wrote. Share-link paths are redacted to /p/[redacted], because the token in such a URL is itself a working credential. The request id is returned to your assistant in a response header, so you can quote it when something breaks and we can find that request without having logged who made it.

13. Security

TLS everywhere; row-level security in the database; database credentials held server-side only; rate limiting on the API; no payment card data on our systems, because no payment provider is connected to FitCoach at all.

14. Children

FitCoach is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has an account, contact henryfelella@gmail.com and we will delete it.

15. Not medical advice

FitCoach is a fitness coaching tool, not a medical service, and nothing it produces is medical advice, diagnosis, or treatment. Training plans are generated from the information you log and are no substitute for the judgment of a physician or qualified health professional. Consult a physician before starting a training program — especially if you have a medical condition or injury — and stop and seek medical advice if you experience pain, dizziness, or other concerning symptoms.

FitCoach does check what you write against a fixed list of red-flag phrasings and, when one matches, tells you to stop training and get medical help. That screen is a keyword check, not monitoring and not assessment: it misses things, it never decides you are fine, and saying nothing is never a sign that nothing is wrong. In the product's own words — FitCoach is a training tool, not medical care — stop and get checked out if anything feels wrong.

16. Changes to this policy

When this policy changes we update the date at the top, and a material change is announced at the top of this page before it takes effect. We do not hold your email address ourselves (section 2), so this page — not an email — is where changes are published.

17. Contact

henryfelella@gmail.com