iAM360

1. Introduction and Commitment to Privacy

FitnessTracker ("Company," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fitness tracking platform, mobile applications, and related services (collectively, the "Service").

We understand that your health and fitness data is particularly sensitive, and we take our responsibility to protect it seriously. By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.

1.1. Scope of This Policy

This Privacy Policy applies to all information collected through our Service, including our website, mobile applications, and any related services, sales, marketing, or events. It does not apply to information collected by third parties, including any third-party websites, services, or applications that may be accessible through links on our Service.

1.2. Data Controller

FitnessTracker is the data controller responsible for your personal information. If you have questions or concerns about how we handle your data, please contact us using the information provided at the end of this policy.

2. Information We Collect

We collect various types of information to provide and improve our Service. This section explains what information we collect and how we collect it.

2.1. Account Information

When you create an account, we collect personal information including:

  • Email address
  • Name (first and last)
  • Password (stored in encrypted form)
  • Profile photo (optional)
  • Basic demographic information (age, gender, height, weight)

2.2. Health and Fitness Data

Through our integration with wearable devices such as Whoop and Oura Ring, we collect health and fitness data including:

  • Heart rate and heart rate variability (HRV)
  • Sleep duration, stages, and quality metrics
  • Activity levels and step counts
  • Calories burned and energy expenditure
  • Recovery scores and readiness indicators
  • Respiratory rate and blood oxygen levels
  • Strain scores and workout intensity metrics
  • Body temperature variations

This data is synchronized from your connected devices with your explicit authorization.

2.3. Meal and Nutrition Data

When you use our meal tracking features, we collect information about:

  • Foods and beverages consumed
  • Meal times and eating patterns
  • Caloric intake and macronutrient information
  • Dietary preferences and restrictions
  • Custom recipes and food entries

2.4. Workout Data

We collect workout and exercise data including:

  • Exercise type and duration
  • Workout intensity and heart rate zones
  • Repetitions, sets, and weights (for strength training)
  • Distance and pace (for cardio activities)
  • Personal records and performance metrics
  • Workout notes and custom entries

2.5. Journal Data

When you choose to use the Journal, we collect and store the free-form text you submit. When you describe your day to Coach AI, we may also store a journal entry created from the information you provide.

To organize your journal and personalize the Service, Coach AI may generate and store internal attributes, such as an approximate feeling score, descriptive tags, or an indication that an entry may reflect a difficult day. You do not enter these fields yourself, and these inferences may be incomplete or inaccurate.

Coach AI may use your journal entries and these inferred attributes alongside your fitness and wearable data to answer questions about your entries and personalize responses. These inferences are not medical or mental-health diagnoses.

2.6. Goals and Preferences

We collect information about your fitness goals including:

  • Weight and body composition goals
  • Activity and exercise targets
  • Nutritional and dietary objectives
  • Sleep and recovery goals
  • Custom milestones and achievements

2.7. Automatically Collected Information

When you access our Service, we automatically collect certain information:

  • Device information (type, operating system, unique IDs)
  • IP address and approximate location
  • Browser type and version
  • Usage patterns and feature interactions
  • App crashes and performance data
  • Cookies and similar tracking technologies

2.8. Trainer-Shared Information

If you choose to share your data with a personal trainer or coach, we facilitate the sharing of your selected data categories. We also collect records of which trainers have access to your data and the permissions you have granted.

3. How We Use Your Information

We use the information we collect for various purposes related to providing, maintaining, and improving our Service.

3.1. To Provide the Service

We use your information to:

  • Create and manage your account
  • Display your health and fitness data
  • Track your meals, workouts, and goals
  • Store and display your journal entries
  • Generate insights and personalized recommendations
  • Enable data sharing with authorized trainers
  • Sync data across your devices

3.2. To Improve the Service

We analyze usage data to:

  • Identify and fix technical issues
  • Develop new features and functionality
  • Understand user preferences and behavior
  • Optimize performance and user experience
  • Conduct research and analytics

3.3. Communications

We may use your contact information to:

  • Send service-related notifications and updates
  • Respond to your inquiries and support requests
  • Send promotional communications (with your consent, where required)
  • Notify you of changes to our policies or services

4. Data Sharing and Disclosure

We are committed to protecting your privacy and only share your information in the following circumstances:

4.1. Sharing with Trainers

When you authorize sharing with a personal trainer or coach:

  • Only the data categories you specifically authorize will be shared
  • Journal entries are not shared with trainers
  • You can revoke access at any time
  • Trainers are bound by confidentiality requirements in their agreements with us
  • We maintain logs of data access by trainers for your review

4.2. Third-Party Service Integrations

We share data with integrated third-party services:

  • Whoop: We receive health metrics from Whoop via their API with your authorization
  • Oura: We receive sleep and activity data from Oura with your authorization

Your use of these third-party services is governed by their respective privacy policies.

4.3. Service Providers

We may share your information with trusted service providers who assist us in operating the Service, such as cloud hosting providers, analytics services, and customer support platforms. These providers are contractually bound to protect your information and use it only for the purposes we specify.

4.4. We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Your health and fitness data is never sold or used for advertising targeting.

4.6. Business Transfers

If FitnessTracker is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

4.7. Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot be used to identify you for research, analytics, and business purposes. This data helps us understand trends in fitness and health without compromising individual privacy.

5. Data Storage and Security

We implement robust security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction.

5.1. Security Measures

Our security practices include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Employee security training and awareness programs
  • Incident response and breach notification procedures
  • Regular backups and disaster recovery planning

5.2. Data Location

Your data is primarily stored on secure servers located in the United States. If we transfer data internationally, we ensure appropriate safeguards are in place as described in Section 10.

5.3. Limitations

While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but will notify you of any breach affecting your personal information as required by law.

6. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information. We are committed to honoring these rights.

6.1. Right to Access

You have the right to request a copy of the personal information we hold about you. You can access most of your data directly through your account settings, or you can contact us for a comprehensive data export.

6.2. Right to Rectification

You have the right to correct any inaccurate or incomplete personal information. You can update most information through your account settings, or contact us for assistance.

6.3. Right to Deletion

You have the right to request deletion of your personal information. You can delete your account through your settings, or contact us. Note that we may retain certain information as required by law or for legitimate business purposes.

6.4. Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. We provide data export functionality in your account settings.

6.5. Right to Restrict Processing

In certain circumstances, you have the right to request that we restrict the processing of your personal information. Contact us to exercise this right.

6.6. Right to Object

You have the right to object to certain types of processing, including processing for direct marketing purposes. You can manage your communication preferences in your account settings.

6.7. Additional Rights for EEA Residents

If you are located in the European Economic Area, you have additional rights under GDPR, including the right to withdraw consent at any time and the right to lodge a complaint with your local data protection authority.

6.8. Additional Rights for California Residents

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know what personal information is collected
  • Right to know whether personal information is sold
  • Right to opt out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information

As stated above, we do not sell your personal information.

7. Children's Privacy

7.1. Age Restrictions

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

7.2. COPPA Compliance

We comply with the Children's Online Privacy Protection Act (COPPA). If we discover that we have collected personal information from a child under 13, we will delete that information as quickly as possible.

7.3. Parental Rights

Parents or guardians may contact us to review, delete, or stop the collection of their child's personal information. We will verify the identity of the requester before taking action.

9. Data Retention

9.1. Retention Periods

We retain your personal information for as long as necessary to:

  • Provide the Service to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Support business operations

Your health and fitness data is retained for the duration of your account and for a reasonable period afterward to allow for account reactivation or data export.

9.2. Deletion Process

When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes. Backup copies may take additional time to be fully purged from our systems.

10. International Data Transfers

10.1. Transfer Mechanisms

If we transfer your personal data outside of your country of residence, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or other legally recognized transfer mechanisms.

10.2. Safeguards

Regardless of where your data is processed, we apply the same protections described in this Privacy Policy. We require our service providers to maintain equivalent levels of data protection through contractual obligations.

11. Cookies and Tracking Technologies

11.3. Do Not Track

We currently do not respond to "Do Not Track" browser signals, as there is no industry-standard interpretation of this signal. However, you can manage your tracking preferences through your browser settings and our cookie preferences.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by posting the updated policy on our Service with a new "Last Updated" date. For significant changes, we may also notify you via email or through an in-app notification. We encourage you to review this Privacy Policy periodically.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: privacy@fitnesstracker.com
  • Data Protection Inquiries: dpo@fitnesstracker.com
  • Website: www.fitnesstracker.com/privacy

We will respond to your request within a reasonable timeframe and in accordance with applicable data protection laws.

14. Additional Disclosures

14.1. Sensitive Personal Data

Our Service processes health and fitness data and may process your journal entries and attributes inferred from them. This information may be considered sensitive personal data under privacy laws. We only collect and process this data with your explicit consent and implement additional safeguards to protect it, including enhanced encryption, access controls, and audit logging.

14.2. California-Specific Disclosures

For California residents, the following categories of personal information may be collected:

  • Identifiers (name, email, IP address)
  • Personal information categories (physical characteristics)
  • Internet or network activity information
  • Geolocation data (approximate)
  • Inferences drawn from the above to create a profile

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

14.3. HIPAA Notice

FitnessTracker is not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). While we implement strong security measures to protect your health information, HIPAA regulations do not apply to our Service. If you have specific healthcare-related privacy concerns, please consult with your healthcare provider.

Your Consent

By using FitnessTracker, you acknowledge that:

  • You have read and understood this Privacy Policy
  • You consent to the collection and use of your information as described
  • You understand your rights regarding your personal data
  • You can contact us at any time with questions or concerns about your privacy

This document was last updated on August 7, 2026. If you have any questions about this Privacy Policy, please contact us at privacy@fitnesstracker.com.