FitCoach Privacy Policy
Effective date / last updated: 2026-08-31
Plain language, on purpose. FitCoach handles your training data, and training data is health data. Here is exactly what we collect, where it lives, and what you can do about it.
1. Who we are
FitCoach is a solo-operated product: an AI-chat fitness coach that stores your training history and builds weekly plans. It is a free experiment run by an individual — not a company, and not a paid service. The operator of FitCoach is the data controller for the personal data described below. Contact: support@usefitcoach.com.
Because it is an experiment, it may be discontinued. If that happens you will be told on the site and given at least 30 days in which export still works, so your training history does not disappear with it. The terms set that out in full.
2. What we collect
We collect only what coaching needs, and we name it specifically:
- Account identity — the user id issued by our authentication provider, plus a display name if you give us one. Your email address is not stored in FitCoach's database: it lives with the authentication provider (Supabase) so you can sign in. If you connect Whoop, its basic-profile response includes your Whoop account id, name, and email; FitCoach stores only the provider account id needed to route future syncs and discards the name and email.
- Training profile — experience level, training days per week, available equipment, preferred units, and your timezone if you tell us your city.
- Sex and age, only if you choose to give them — both are optional, and both are used for exactly one thing: estimating a sensible starting weight on your first session, before you have logged anything for us to measure. Published strength norms differ substantially by sex, so an estimate that ignored it would be badly wrong for a lot of people. Decline either and everything still works — your first plan simply gives you sets, reps and a target effort level instead of a weight. Nothing else in FitCoach reads these fields, they are never used to categorise you or to decide what you are capable of, and we treat them as sensitive health data.
- Height, only if you choose to give it — optional, and used for exactly one thing: a fallback input to your maintenance calorie/macro estimate when no body-fat percentage is on file. Log a body-fat check-in and this field becomes unnecessary. Decline it and the calorie estimate is simply unavailable until one of those two inputs exists — nothing else reads this field, and we treat it as sensitive health data.
- Injury and constraint notes — free-text notes like "left shoulder: avoid overhead pressing". We treat these as sensitive health data.
- Workout logs — exercises, sets, reps, weights, effort ratings (RPE), and timestamps, plus any runs or other cardio you log (distance, duration, pace, heart rate, and active energy burned when Apple Health or WHOOP reports it). Health-adjacent data.
- Food diary and nutrition targets — food or meal name, meal category, timestamp, calories, optional protein/carbohydrate/fat values and notes, plus a custom calorie/macro target if you set one. FitCoach stores only nutrition values you or your assistant submit; it does not infer them from a food name. We treat these as sensitive health-adjacent data.
- Body and recovery metrics — bodyweight and other measurements you log or choose to sync from Apple Health, and sleep, resting heart rate, HRV, or a recovery score when you log them or sync them from Apple Health or, if you connect it, Whoop. Sensitive health data.
- Subjective wellbeing notes — how a session felt, free-form session notes, and feedback entries. We treat these as sensitive: free-text fields can and do end up containing mood, sleep, pain, and life events, whether or not we invite it.
- Things you ask us to remember — free-text facts you tell FitCoach to keep, and training history you import from another app.
- Derived fitness state — estimated one-rep maxes, fitted coaching parameters, recovery score, adherence rate, flags such as a deload recommendation, and a maintenance calorie/macro estimate computed from your logged body metrics, training cadence, and available wearable workout-energy estimates (never a weight-loss or weight-gain target). These are inferences about your fitness and are treated as health-adjacent data.
- Goals — for example a target weight or a target date. Body-related goals are health-adjacent.
- Share links you create — the random token, which plan it points at, when it was created, when it expires, and whether you revoked it. See section 6.
- Legacy access records — historical account state retained only when an older installation created it.
- Usage events — which tools were called and when, kept for metering and service integrity.
3. Where it comes from
From you, via the AI assistant you connect through (Claude or ChatGPT). If you separately connect Apple Health to ChatGPT Health, ChatGPT can also send FitCoach a narrow snapshot of sleep, HRV, resting heart rate, body measurements, and completed workouts only when you ask it to. FitCoach first previews the record counts and saves nothing; the assistant must show you the extracted measurements and receive your explicit confirmation before a second, payload-bound call can save them. FitCoach never receives a raw Health export, routes, location, nutrition from Apple Health, diagnoses, medications, reproductive data, or medical records, and it cannot read or write Apple Health directly. Food-diary nutrition reaches FitCoach only when you explicitly ask your assistant to log values you provide or it obtains from a reliable nutrition source. Your conversation with the assistant itself is not stored by FitCoach — we only receive the structured tool inputs and outputs the assistant sends to our server. The assistant's own handling of your conversation and any connected Apple Health data is governed by its provider's privacy policy and your agreement with that provider: Anthropic (Claude), OpenAI (ChatGPT). FitCoach does not control the assistant's retention or training settings.
If you choose to, you can also connect Whoop directly from your account page. That flow sends you to Whoop's own authorization screen, which discloses exactly what you're granting before you approve it. FitCoach requests recovery, sleep, workout, basic-profile, and offline access: it stores your Whoop account id and encrypted access/refresh tokens; receives recovery score, HRV, resting heart rate, sleep duration, and completed workout duration, distance, heart rate, and WHOOP-estimated energy burn for coaching and maintenance-calorie calibration; and discards the name and email returned by the one-time basic-profile lookup. Offline access is what lets those syncs continue after the short-lived access token expires. You can disconnect at any time from the same page (section 8).
4. Why we use it
To build and adapt your training plans, operate your account, keep the calorie/macro diary and daily remaining-calorie calculation you request, and — unless you opt out — to compute population-wide statistics that tune the coaching engine for everyone. Nothing else. No advertising, no sale of your data, and no training of AI models on your data.
Population tuning, precisely
Each time we plan your week we archive a snapshot of the numbers the engine fitted to your log — never raw workouts, never your notes, never anything identifying. A background job reads those snapshots as aggregates only (counts, rates, and means across all users) and nudges a handful of hand-bounded engine constants; it can never see, or be reversed into, one person's training. It stays completely inert until the population passes a minimum size, and each constant may move by one small step inside a fixed envelope.
This is opt-out and it is a real switch: tell your assistant "don't use my data for research" and the snapshot is never written in the first place, so nothing of yours can reach the aggregate at all. Say "you can use my data" to opt back in. account_status tells you which way the setting is set.
5. Where it lives
Your data is stored in Supabase (hosted Postgres), region: United States. Row-level security is enabled and the database is accessed only by our application server using server-held credentials. The application server runs on Fly.io; your data lives in the database, not on the server's disk. All connections use TLS.
6. Who else touches it (subprocessors)
| Provider | Role | Data they touch |
|---|---|---|
| Supabase | Database and authentication | All categories listed in section 2 |
| Fly.io | Application hosting | Data in transit and in processing |
| Anthropic (Claude) / OpenAI (ChatGPT) | Conduit, not a subprocessor in the usual sense — you talk to FitCoach through your chosen AI assistant | Your messages to the assistant, under that provider's own privacy policy. FitCoach only receives what the assistant sends to its tools. |
| Whoop | Connected recovery and workout provider, only if you authorize it | Recovery score, HRV, resting heart rate, sleep duration, completed workout duration, distance, heart rate and estimated energy burn, plus the basic-profile response used once to link your Whoop account id; FitCoach discards the returned name and email |
We will update this list if it changes and aim to give notice of changes.
Links you publish yourself
Asking FitCoach to share your plan mints a public web page for one plan, at a secret random URL. Anyone holding that link sees the plan and your first name only — no email, no other plan, no logs, notes, metrics, or goals, and the plan's written rationale is filtered so health-related sentences are dropped rather than published. Links expire after 30 days by default (you can pick another window, or none), you can list every link you have made and whether it is still live, and you can revoke any single link or all of them at once. Deleting your account kills every link immediately. Nothing is ever published unless you ask for it.
7. How long we keep it
- While your account is active: account data and training history are retained — the product is your longitudinal training log, so keeping the history is the service.
- When you delete your account: your data is removed immediately, in one transaction, not on a 30-day schedule — see section 8. We keep no copy and cannot restore a deleted account, including from a backup. Copies inside our database provider's routine backups age out on that provider's cycle; we never restore your rows from one.
- Usage and metering events: kept while your account exists, for metering and service integrity, and deleted with it.
- Fitted-parameter snapshots (section 4): deleted 90 days after they are written, or sooner if you delete your account.
- Server request logs: see section 12 — they contain no personal data.
8. Your rights: export, correction, deletion
- Export — ask your assistant for your data and the
export_my_datatool returns everything we hold about you as structured JSON: profile, goals, sessions, sets, cardio, food diary and nutrition target, feedback, body and recovery metrics, remembered facts, plans, imports, experiments, fitted parameters and their snapshots, share-link records, connected-provider metadata, and usage events. It is self-serve and free. Working credentials are held back: share-link tokens and encrypted Whoop OAuth tokens are never placed in an export file, while their non-secret lifecycle and connection metadata are included. - Correction — you can correct your profile, goals, and logs through the product, or ask us at support@usefitcoach.com.
- Deletion — you can do this yourself, right now, in the chat. Tell your assistant "delete my account". FitCoach answers with an exact inventory of what would go and deletes nothing; to actually go through with it you must send back the exact phrase DELETE MY ACCOUNT. Anything else — including a typo — and nothing happens. On confirmation FitCoach first makes a best-effort request to revoke any connected Whoop authorization, then removes all application rows we hold for you in a single transaction: profile, goals, sessions, sets, cardio, food diary and nutrition target, feedback, body and recovery metrics, remembered facts, plans, imports, experiments, share links, connected-provider credentials, fitted parameters and snapshots, usage events, and any legacy access record. If Whoop is unavailable, deletion still proceeds: the local credentials are destroyed, so FitCoach can no longer call Whoop, and any later delivery is ignored. This is irreversible — no undo, no grace period, no copy of that application data kept on our side, and any share links you sent people stop working immediately. Export first if you want to keep your history. Your authentication-provider user id is queued before the application wipe and FitCoach then attempts the narrowly scoped sign-in-record deletion automatically. If that provider step cannot finish immediately, the durable queue remains visible to the operator until it is retried; you do not need to email us to start or finish it. We commit to clearing any such remainder within 30 days; contact support@usefitcoach.com if you want an update.
- Consent withdrawal — disconnect FitCoach from your assistant at any time, disconnect Apple Health from ChatGPT Health in ChatGPT settings, disconnect Whoop from your account page, turn off research contribution (section 4), or withdraw consent to collection entirely by deleting your account as above. Disconnecting stops future syncs but does not delete records already stored by FitCoach; export or delete them using the controls above.
9. No sale, no ads, no model training
FitCoach does not sell personal data, does not share it for advertising, and does not use it to train AI models. The population tuning in section 4 is not model training: it adjusts a handful of numeric constants from aggregate statistics, and never reads an individual's data. If any of this ever changed for consumer health data, Washington law would require your separate signed authorization first — practically: we just don't sell it.
10. Consumer Health Data Privacy Policy (Washington My Health My Data Act)
Washington's My Health My Data Act (MHMDA) protects "consumer health data" broadly — including physical fitness measurements, injuries, and inferences about health. Workout logs, effort ratings, recovery scores, wellbeing notes, and injury notes qualify. This section is our Consumer Health Data Privacy Policy for Washington residents; similar laws in Nevada and Connecticut are honored the same way.
Categories of consumer health data collected
Workout logs (exercises, sets, reps, weights, effort ratings), runs and other cardio, food-diary entries and nutrition targets, body measurements, recovery metrics you log or choose to sync (sleep, resting heart rate, HRV, recovery score), injury and constraint notes, subjective wellbeing and session notes, body-related goals, and derived fitness inferences (estimated one-rep maxes, recovery score, adherence, deload flags and calorie/macro guidance).
Sources and purposes
Collected from you through your AI assistant, including food nutrition values you explicitly ask it to log, a user-requested and user-confirmed narrow snapshot when you ask ChatGPT Health to bridge selected Apple Health data into FitCoach, or recovery, sleep, and completed workout metrics from Whoop if you connect it yourself from your account page, to provide the coaching service you asked for: building and adapting your training plans, keeping your calorie diary, and calibrating a maintenance-calorie estimate. Unless you opt out, statistics derived from your fitted numbers also feed the aggregate engine tuning in section 4, which never reads an individual's data. We collect nothing beyond what coaching needs, and we will ask for consent before collecting anything new.
Sharing and third parties
Consumer health data is shared only with the processors in section 6 (Supabase for storage, Fly.io for hosting), and reaches your AI assistant's provider only because you talk to FitCoach through it. The one other way any of it becomes visible is a share link you create yourself, which publishes one plan and your first name and which you can revoke at any time (section 6). We do not share consumer health data for advertising and do not sell it; a sale would require your separate signed authorization, which we will never ask for.
Your rights
You may access your consumer health data (self-serve export, section 8), withdraw consent, and have it deleted — deletion is self-serve, immediate, and irreversible (section 8), and no copy is retained by us. To exercise any right you cannot exercise in the product, email support@usefitcoach.com. If we deny a request, you may appeal by replying to our decision, and Washington residents may contact the Washington Attorney General.
Geofencing
Not applicable — FitCoach does not collect location data and does not geofence anything, health facilities included.
11. EU/UK (GDPR) and California (CCPA/CPRA)
If you are in the EU or UK: our legal bases are performance of contract (providing the coaching you signed up for), consent for health-adjacent data, and legitimate interests for the aggregate engine tuning in section 4 — which you can object to at any time by opting out, in which case nothing of yours is ever collected for it. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Exercise them via support@usefitcoach.com; export and deletion work as described in section 8.
If you are a California resident: you have the right to know, correct, and delete personal information, and the right to opt out of sale or sharing — moot here, because we do not sell or share personal information as defined by the CCPA/CPRA. We do not discriminate against you for exercising your rights.
12. What our servers log
Every request to our server writes one line to an operational log: a random request id, the HTTP method, the path, the response status, how long it took, and — for tool calls — the name of the tool. That is the whole line. Deliberately excluded: request bodies, access tokens, and user ids — no log line names you or carries anything you wrote. Share-link paths are redacted to /p/[redacted], because the token in such a URL is itself a working credential. The request id is returned to your assistant in a response header, so you can quote it when something breaks and we can find that request without having logged who made it.
13. Security
TLS everywhere; row-level security in the database; database credentials held server-side only; rate limiting on the API; no payment card data on our systems, because no payment provider is connected to FitCoach at all.
14. Children
FitCoach is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a child has an account, contact support@usefitcoach.com and we will delete it.
15. Not medical advice
FitCoach is a fitness coaching tool, not a medical service, and nothing it produces is medical advice, diagnosis, or treatment. Training plans are generated from the information you log and are no substitute for the judgment of a physician or qualified health professional. Consult a physician before starting a training program — especially if you have a medical condition or injury — and stop and seek medical advice if you experience pain, dizziness, or other concerning symptoms.
FitCoach does check what you write against a fixed list of red-flag phrasings and, when one matches, tells you to stop training and get medical help. That screen is a keyword check, not monitoring and not assessment: it misses things, it never decides you are fine, and saying nothing is never a sign that nothing is wrong. In the product's own words — FitCoach is a training tool, not medical care — stop and get checked out if anything feels wrong.
16. Changes to this policy
When this policy changes we update the date at the top, and a material change is announced at the top of this page before it takes effect. We do not hold your email address ourselves (section 2), so this page — not an email — is where changes are published.
17. Contact
support@usefitcoach.com