FitStreak — Privacy Policy
Last updated: September 2026
1. Information We Collect
FitStreak stores your workout data, preferences, and profile information locally on your device. If you sign in with Apple, we also store your data on our cloud servers to enable cross-device sync.
The information we handle includes:
- Your display name and avatar selection
- Workout completion history
- Fitness goals and level preferences
- App settings (reminders, sound, haptics)
- Achievement progress and XP
- Food and nutrition entries you log (item names, calories, and macros)
- Body weight readings you enter or import from Apple Health, and the daily water count you log
- Progress photos you choose to add. These never leave your device: they are not uploaded, not included in cloud sync, and not visible to anyone else. Deleting the app, resetting your progress, or deleting your account removes them permanently
- Apple Sign-In user ID (if signed in)
- Your email address, or the private relay address Apple provides if you choose Hide My Email (if signed in)
If you use the meal photo scanner, the photo you choose is sent to our AI provider to estimate the food and its nutrition. We do not store the photo: only the resulting item names, calories, and macros are saved to your food log. If you use the AI workout or program generator, the preferences you pick (duration, focus, difficulty, and available equipment) are sent to the same provider. Neither feature sends your name, email, or account ID.
2. How We Use Your Information
All data is used solely to provide you with a personalized fitness experience. Your workout history powers streak tracking, XP calculations, and achievement unlocks. If you sign in with Apple, your data is synced to our servers so you can access it across devices.
3. Data Storage
Data is always stored locally on your device. If you sign in with Apple, your data is also stored on Supabase (our cloud provider, hosted in the United States). Data is encrypted in transit (TLS) and at rest. If you do not sign in, no data leaves your device.
4. Third-Party Services
We use the following third-party services:
- Supabase — Cloud database and authentication (only if you sign in with Apple)
- RevenueCat — Subscription management (uses an anonymous ID; linked to your account if signed in)
- Apple HealthKit — If you enable it, we save your completed workouts to Apple Health, and we can read two things at your request: workouts logged by other apps, so you can import them, and your most recent body weight, only when you tap to import it. We write body weight back to Apple Health only if you turn on the separate “Write weight to Health” setting, which is off unless you turn it on, and even then only weights you typed yourself are written, never a value we imported or estimated. Nothing read from Health leaves your device except through the same cloud sync as the rest of your data if you are signed in. If you turn on “Gentle days”, we also check whether your period is logged in Apple Health for the current day, so we can offer an easier session. That check happens entirely on your device: we do not store it, we do not sync it, we do not include it in analytics, and it never reaches our servers or anyone else. The setting itself is kept only on this device, and is cleared if you reset your data or sign out.
- Your device calendar — If you turn on “Add to calendar”, we create a calendar named FitStreak on your device and write one repeating event for each of your training days. Granting calendar access on iOS and Android also technically grants the ability to read your calendar, and there is no narrower permission available to us. We do not use it: FitStreak only ever creates, updates and deletes events in the FitStreak calendar it made, and never reads, stores or sends anywhere the events in your other calendars. Nothing about your calendar is sent to us or to anyone else, and turning the setting off deletes the FitStreak calendar.
- Rork AI Toolkit (Google Gemini) — Powers the meal photo scanner and the AI workout/program generator. It receives the meal photo or the workout preferences you submit, and returns the analysis. It is only contacted when you actively use one of those features.
- Open Food Facts — Powers the barcode scanner. When you scan a product barcode we send that barcode number to Open Food Facts (world.openfoodfacts.org), a free public food database, and it returns the product name and nutrition values. Only the barcode is sent, no photo, no account information, nothing about you, and it is only contacted when you actively scan a code.
- Sentry — Crash and error reporting. If the app crashes or hits an error, Sentry receives the error details, a stack trace, and your device model and OS version so we can fix the problem. It is not configured to attach your name, email, or account ID.
- Google Analytics for Firebase — Product analytics. We log a small set of app-usage events (for example: sign-up, workout started/completed, streak milestones reached, paywall viewed, purchase completed) so we can understand how the app is used and improve it. These events include only IDs, counts, and category or plan labels, never your name, email, or account ID.
- AppsFlyer — Install attribution and ad-campaign measurement. It receives your install and a small set of in-app events: finishing onboarding (with the fitness goal you picked), starting a free trial (the plan and currency), and completing a purchase (the plan, price and currency). These events never include your name, email, or account ID. The App Tracking Transparency prompt you see decides what else happens. If you tap Allow, AppsFlyer also collects your device's advertising identifier (IDFA) and shares install and in-app event data with the ad network whose campaign led to your install (currently AppLovin), so we can measure which ads are working. If you tap Ask App Not to Track, no advertising identifier is collected, and AppsFlyer receives the same events tied only to an identifier that is unique to FitStreak on your device and cannot be used to follow you across other companies' apps.
Other than AppsFlyer as described above, we do not use advertising networks or data brokers, and we do not sell your data. Payment processing is handled entirely by Apple through the App Store.
5. What Other Users Can See
Your profile is private by default. Nothing you do is visible to other users unless you turn on Public Profile in Profile > Settings.
While Public Profile is on, other signed-in users can see your display name, avatar (including any equipped avatar frame), level, XP, current streak, and any commitment challenge you currently have active, on the leaderboard, in the weekly league, in your friends list, and in friend search results. Your workout history, food log, personal details, and settings are never shared. Turning Public Profile back off removes you from the leaderboard and from search.
Once someone becomes your friend (accepted request), they can see those same profile stats even if you later turn Public Profile off. A pending, not-yet-accepted request also shows those stats to the other person, but only while your profile is public.
If you and a friend agree to be streak buddies, each of you can see whether the other has completed a workout on a given day, and the shared streak that builds from it. Neither of you sees the other's workouts, food log, or body measurements. Either of you can end it at any time from the Friends tab.
6. Children's Privacy
FitStreak is not directed at children under 13. We do not knowingly collect information from children under 13 years of age.
7. Data Deletion
If you are not signed in, you can delete all local data by uninstalling the app. If you are signed in with Apple, you can delete your account and all server-side data from Profile > Delete Account. This permanently removes your data from our servers and cannot be undone.
You can also take a copy of everything the app holds about you at any time, signed in or not, from Profile > Export my data. The export is a JSON file built on your device and shared wherever you choose; it is not uploaded anywhere.
8. Marketing Communications
If you sign in with Apple, we may occasionally email you about product updates, new features, or special offers, using the email (or private relay) address Apple provides. You can unsubscribe at any time using the link in any marketing email, or by contacting us at isidora.tourni@hotmail.com. This does not affect account-related emails from Apple itself, which we do not control.
9. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be reflected in the app and on this page with an updated revision date.
10. Contact Us
If you have any questions about this privacy policy, please contact us at isidora.tourni@hotmail.com.