1. TL;DR
- We collect the minimum needed to sign you in and run the app.
- We do not sell your data and we do not run advertising or third-party ad SDKs.
- You can delete your account and all associated data from inside the app at any time.
- Subscription payments are processed entirely by Apple. We never see or store your card details.
- Questions? Email nirv@fitfo.app.
2. Who we are
“Fitfo,” “we,” “us,” and “our” refer to Vaayu Athletics LLC, a US-based company that operates the Fitfo mobile app and the website at fitfo.app. You can reach us at nirv@fitfo.app.
3. What we collect
Fitfo collects only the information needed to authenticate you and operate the app. That includes:
- Account & contact info. Your phone number (if you sign in with SMS) or your name and email (if you use Sign in with Apple). If Apple relays a private email, that private relay is what we store.
- Profile & onboarding. Goals, training split, days per week, weight, height, experience level, and age that you enter during onboarding.
- Workout content. Workouts you save, schedule, or create; sessions you log (sets, reps, weights, durations, notes, completion timestamps); body-weight entries you record.
- Source URLs. TikTok and Instagram Reel URLs you share into the app for import, plus the extracted metadata and transcript we generate from them.
- Subscription status. Whether you have an active subscription or trial, which plan (monthly or annual), the start and renewal dates, and a unique anonymous identifier provided by Apple and RevenueCat to verify your subscription. We do NOT receive, see, or store your credit card number, billing address, or any payment method details. All payment data is handled exclusively by Apple.
- Device identifiers.A user ID we assign to your account, plus an anonymous identifier from RevenueCat used solely to track subscription entitlements. We do not use Apple's advertising identifier (IDFA) and do not integrate any advertising SDKs.
- Apple Sign-In refresh token. If you signed in with Apple, we store the refresh token solely so we can revoke the token with Apple when you delete your account, as required by App Store Guideline 5.1.1(v).
What we do not collect
- We do not collect precise or coarse location, contacts, photos, videos, microphone audio, health data from HealthKit, or any sensitive personal information.
- We do not collect or store any payment card numbers, CVV codes, expiration dates, billing addresses, or other financial information. All payment processing is handled by Apple's In-App Purchase system.
- We do not run advertising SDKs, analytics SDKs, crash reporters, or third-party tracking SDKs in the iOS app, with the limited exception of RevenueCat, which we use solely to validate subscription status (see Section 5).
4. How we use your information
- Authenticate you via SMS one-time codes or Sign in with Apple.
- Store and display the workouts, sessions, and notes you create.
- Process the TikTok and Instagram URLs you submit by fetching public metadata, transcribing audio, and running OCR on a small number of frames so we can extract exercise data.
- Validate and manage your subscription status (whether you have an active trial, monthly, or annual plan) so we can grant or restrict access to paid features.
- Respond to support requests.
- Protect against abuse and comply with legal obligations.
We never use your data for advertising, profiling for third-party advertisers, or sale to data brokers.
5. Third-party services (sub-processors)
We use a small number of reputable vendors to run the app. Each processes only the data needed for its specific function:
- Supabase, database and file storage for profiles, workouts, and session logs (hosted on AWS in the United States).
- Twilio Verify, sending SMS one-time verification codes to your phone number.
- Apple, Sign in with Apple authentication and refresh-token revocation when you delete your account. Apple also processes all subscription payments through In-App Purchase and handles all payment information directly.
- RevenueCat, validates your subscription status with Apple's servers and provides us with a simple yes/no signal about whether your subscription is active. RevenueCat receives an anonymous user identifier and your subscription transaction details from Apple, but does not receive or store your name, email, phone number, or payment card information. See RevenueCat's privacy policy at revenuecat.com/privacy for details.
- Apify, fetching public metadata from TikTok and Instagram URLs you submit.
- OpenAI, running transcription, OCR, and language-model processing on the video, audio, and text extracted from videos you submit.
- DigitalOcean, hosting our API servers.
These providers are contractually required to handle data only on our behalf and in line with their own privacy terms. We do not sell data to any of them.
6. How long we keep data
We keep your data for as long as your account is active. When you delete your account (Profile → Delete Account inside the app) we immediately and permanently remove your profile, workouts, sessions, and body-weight entries from Supabase. Some server logs or backups may persist for up to 30 days before being fully expunged.
Subscription transaction records held by Apple and RevenueCat may be retained for tax, accounting, and legal compliance purposes for up to 7 years, in accordance with applicable law. These records do not include identifying information beyond a transaction ID.
7. Your rights
You can, at any time:
- Accessor export your data. Email us and we'll send you a copy within 30 days.
- Correct inaccurate data. Most fields are editable directly inside the app.
- Delete your account and all associated data. Use Profile → Delete Account inside the app, or email us.
- Object to processing or withdraw consent. Simply stop using the app and request deletion.
- Manage your subscription. You can manage, cancel, or turn off auto-renewal of your Fitfo subscription at any time through your Apple ID settings (Settings → [Your Name] → Subscriptions on iPhone, or apps.apple.com/account/subscriptions on the web). Deleting the Fitfo app does not cancel your subscription.
Residents of California (CCPA/CPRA), the EEA / UK (GDPR), and other jurisdictions with equivalent laws are entitled to the same rights above without charge. We do not sell or share personal information for cross-context behavioral advertising.
8. Children
Fitfo is not directed to children under 13 and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us data, email us and we'll delete it.
9. International transfers
Our servers and sub-processors are primarily located in the United States. If you access Fitfo from outside the US, you consent to your data being transferred to and processed in the US under the safeguards described in this policy.
10. Security
All traffic between your device and our servers uses HTTPS/TLS. Stored data is encrypted at rest by our infrastructure providers. Access to production data is limited to a small number of engineers using least-privilege credentials. Payment data is never transmitted to or stored on our servers; it is handled exclusively by Apple's secure payment infrastructure. No method of transmission or storage is perfectly secure, but we work hard to treat your data with the same care we'd want for our own.
11. Third-party content (TikTok / Instagram videos)
Fitfo does not host or redistribute third-party video content. When you share a TikTok or Instagram video into Fitfo, we fetch public metadata, transcribe audio, and run OCR on frames to extract factual exercise information (names, sets, reps, rest). We always link back to the original post inside the app via the “View on TikTok” or “View on Instagram” button. Creators who want their content excluded from the service can email nirv@fitfo.appwith the URL and we'll remove it.
12. Subscriptions, billing, refunds, and App Store purchases
12.1 Payment processing.All Fitfo subscription payments are processed exclusively by Apple through In-App Purchase. We do not operate our own payment infrastructure and we do not collect, see, or store your credit card number, CVV, expiration date, billing address, or any other payment method details. Apple's privacy policy governs how Apple handles your payment information; see apple.com/legal/privacy.
12.2 Subscription plans. Fitfo currently offers two auto-renewable subscription plans: Monthly at $5.99 USD per month, and Annual at $39.99 USD per year. New subscribers may be eligible for a 7-day free trial. Pricing, trial length, renewal terms, and cancellation options are displayed at checkout and in your Apple ID subscription settings.
12.3 What we receive from Apple. When you start a subscription or trial, Apple provides us with a transaction identifier and a validation receipt confirming your purchase. RevenueCat, our subscription validation provider (see Section 5), uses this information to confirm your subscription status. We do not receive your card details, billing address, or any other payment information from Apple.
12.4 Refunds. Refund requests are handled by Apple, not by us. To request a refund, visit reportaproblem.apple.com or use the “Report a Problem” feature in your Apple ID settings. We do not have the ability to issue refunds directly because we do not process payments.
12.5 Subscription changes. If we materially change subscription pricing, plan features, or trial terms, we will describe the change in the app, on this site, or by email before it takes effect, consistent with App Store guidelines and applicable law. Apple may also notify you of material price changes and require your consent before continuing your subscription at a new price.
13. Apple App Tracking Transparency (ATT) and advertising
Fitfo does not run third-party advertising SDKs or sell your personal information for cross-context behavioral advertising. We do not use the Identifier for Advertisers (IDFA) to track you across other companies’ apps or websites for ads. If we introduce optional analytics that could trigger an Apple privacy prompt in the future, we will describe it here and in the app before enabling it.
Apple Search Ads.When you discover Fitfo through an Apple Ads campaign and install our iPhone app, Apple may provide attribution signals using Apple's AdServices framework (for example coarse campaign identifiers). Fitfo sends a one-time summarized conversion event to our product analytics so we can evaluate whether those visits lead to installs. This does not enable cross-app behavioral advertising beyond what Apple's own Apple Search Ads tooling provides for campaign reporting.
14. Changes to this policy
We'll update this page if our practices change. The effective date at the top reflects the latest version. Material changes, including changes to subscription billing, pricing, or data handling, will be communicated via the app or via email before they take effect.
15. Contact
Questions, requests, or concerns about your data? Email nirv@fitfo.app. We read every message and respond within one business day.
