Working draft. Final policy will be reviewed by counsel for GDPR / CCPA compliance before public launch. Substance will stay; specific wording may change.
We’re a fitness app that needs some health-adjacent data to do its job. We hold the minimum necessary, never sell it, and give you clean controls to see, export, or delete everything.
Profile info you give us during onboarding (focus, fitness level, equipment, age, weight, height, optional injuries). Workout history (sets, reps, RIR, exercises performed). Wearable data, if you connect a device (sleep, HRV, RHR — read-only). Anonymized usage analytics for product improvement.
We do not collect precise location, contacts, photos, or browsing history outside the app. Wearable health data is read-only — we never write to Apple Health.
To generate your workouts, calibrate readiness, surface accurate nutrition targets, and improve the app. Aggregate, anonymized data may inform product decisions. We do not sell your personal data.
Service providers who help us operate the app (cloud hosting, video CDN, payment processors). They are bound by data-processing agreements. We also use Meta’s ad-measurement tools (Meta Pixel and Conversions API) to measure ad performance — on waitlist signup this shares a hashed email and technical data with Meta. No data brokers.
You can request a full data export at any time (we email you a zip). You can delete your account in-app — soft-deleted immediately, hard-deleted after 30 days. You can disconnect any wearable integration without deleting your account.
EU/UK (GDPR): right to access, rectify, erase, restrict, port, object. California (CCPA): right to know, delete, and opt-out of any sale (we do not sell — but the toggle exists). Other jurisdictions: contact info@itsyou.me for region-specific requests.
Privacy questions and data requests: info@itsyou.me.