Legal

Privacy Policy

This policy explains what personal data Fithab collects, why we collect it, how long we keep it, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

Last updated: 5 August 2026

1. Who is responsible for your data

Fithab ("the app") is developed and operated by Ruben Tiso, an individual developer based in Switzerland. Ruben Tiso is the data controller for the personal data processed in the app.

Contact for any privacy matter, including requests to access or delete your data: ruben.tiso@gmail.com.

2. What data we collect

We only collect data needed to run the app. Specifically:

  • Account data: your email address, a password managed by our authentication provider (we never see or store your password in plain text), an optional display name and avatar, and your account creation date.
  • Health and fitness data you enter or authorise: body weight, calorie and nutrition entries, workouts (exercises, sets, reps, weights, duration), habit check-ins, and step count. Heart rate data is not collected today; support for it is planned and, when added, it will be strictly opt-in.
  • Progress data: XP, levels, streaks and achievements generated from your activity in the app.
  • Social data: friend connections, challenges and messages of encouragement you send or receive, if you choose to use these features.
  • Technical data: basic device and app information (such as app version, device type and error diagnostics) needed to keep the app working and fix crashes.
  • Device-local data: preferences such as units and reminder times, and cached daily progress, stored on your device.

We do not collect your precise location, contacts, microphone audio, or advertising identifiers, and we do not use third-party advertising or cross-app tracking.

3. Why we process your data and on what legal basis

  • To provide the app — creating your account, saving your workouts, nutrition, weight, steps and habits, and syncing them across your devices. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • To process health-related data — weight, nutrition, workouts, steps and (in future) heart rate are health data. We process them only with your explicit consent, which you give by entering the data or enabling the relevant feature (Art. 9(2)(a) GDPR). You can withdraw consent at any time by deleting the data or your account.
  • To generate AI coaching — when you use the AI coach or ask for a plan, the relevant context (for example recent workouts, nutrition totals and your prompt) is sent to an AI model provider to produce a reply. Legal basis: your consent and performance of a contract.
  • To send reminders and notifications — only if you enable them. Legal basis: consent.
  • To keep the app secure and stable — abuse prevention, crash and error diagnostics. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
  • To process payments — if you buy a premium subscription, our reseller and Merchant of Record Paddle.com handles the transaction, billing and tax, and we store only the subscription status. Legal basis: performance of a contract.

4. Automated processing and AI

The AI coach produces training and nutrition suggestions automatically. These suggestions are informational only, are not medical advice, and have no legal effect on you. Your data is not used to train third-party AI models. Always consult a qualified professional before starting a new diet or training programme, especially if you have a medical condition.

5. Who we share data with

We never sell your personal data. We share it only with service providers ("processors") that are contractually bound to process it on our instructions:

  • Supabase — authentication, database and file storage hosting.
  • Hosting and delivery providers — serving the app and its API.
  • AI model providers — processing coaching prompts and food-photo recognition requests.
  • Paddle.com (payment provider and Merchant of Record) — Paddle.com is the Merchant of Record for all our orders. If you subscribe, Paddle handles the checkout, payment, billing, tax and invoicing, provides customer service inquiries for orders and handles returns. Paddle collects your payment and billing details directly as its own controller under its privacy notice; we receive only your subscription status and basic order references — never your full card details.
  • Nutrition data source — public food database lookups when you search for a food or scan a barcode.

We may also disclose data where legally required, or to protect the rights, safety and security of users and the app.

6. International transfers

Some providers may process data outside Switzerland and the European Economic Area. Where that happens, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. You can request details of these safeguards by email.

7. How long we keep your data

  • Account and activity data (weight, calories, workouts, steps, habits) are kept while your account is active, so your history and progress remain available to you.
  • When you delete your account, your personal data is deleted from our live systems within 30 days and from backups within 90 days.
  • Limited records may be kept longer where legally required (for example payment records for accounting purposes).
  • Device-local data is removed when you sign out or uninstall the app.

8. Your rights

Under the GDPR and the Swiss FADP you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or your local EU/EEA data protection authority.

You can export your data and delete your account from inside the app, or email ruben.tiso@gmail.com. We respond to requests within 30 days.

9. Security

Data is transmitted over encrypted connections (TLS) and stored on managed infrastructure with encryption at rest. Database access is restricted with row-level security rules so that each account can only read and write its own records. No system is perfectly secure, but we work to protect your data and will inform you and the competent authority of any breach affecting your rights as required by law.

10. Children

Fithab is not intended for children under 16. We do not knowingly collect data from children under 16. If you believe a child has created an account, contact us and we will delete it.

11. Cookies and local storage

We use only essential storage: a session token to keep you signed in and local preferences such as units and reminder times. We do not use advertising or cross-site tracking cookies.

12. Changes to this policy

We may update this policy as the app evolves. The date at the top always reflects the current version, and material changes will be announced in the app before they take effect.

13. Contact

Ruben Tiso, Switzerland — ruben.tiso@gmail.com