Privacy Policy

Last updated 11 August 2026

This policy explains what MyFitsy does with your personal data, why, and what you can do about it. It covers the MyFitsy app for clients, the MyFitsy Coach app for trainers, and this website.

Who is responsible for your data

The data controller is:

Hoovus Kinnisvara OÜ
Registry code 16775200 · VAT EE102736764
Viru väljak 6, Kesklinna linnaosa, Tallinn, Harju maakond, 10153, Estonia
support@myfitsy.com

Write to that address for anything in this policy, including to exercise your rights. A person reads it.

The short version. Your training data is yours and is never public. We do not sell data and never will. We do not run adverts or advertising trackers. We do not know your card number. A coach sees the data of clients connected to them, and a coach's own profile page is public because that is what it is for. Everything else below is the detail.

What we collect, and why

1. Account data

Your name, email address, role (coach or client), @handle, profile photo if you add one, unit preference, and a securely hashed password. We never store your password itself.

If you sign in with Apple or Google, we receive an account identifier and your email address from them — never your password. If you use Apple's Hide My Email, we only ever receive the relay address.

Why: to create and run your account. Legal basis: performance of our contract with you.

2. Health and fitness data — a special category

Body measurements (neck, shoulders, chest, waist, hips, arms, forearms, thighs, calves), weight, estimated body fat, height, date of birth, sex, training goals, logged workouts including weights lifted, reps completed, cardio time and distance, skipped sessions, and the programmes assigned to you or written by you.

Under the GDPR this is data concerning health, a special category needing stronger protection. Why: it is the service — recording it and charting it is what the app is for, and sharing it with your coach is what coaching requires. Legal basis: your explicit consent (Article 9(2)(a)), given when you create an account and confirm you have read this policy, and withdrawable at any time — see Your rights.

3. Coach profile data — public by design

For coaches only: biography, years of experience, certifications, specialisations, gyms, city and country, contact email and phone if you add them, social links, listed prices, portfolio photos with their titles and descriptions, and the ratings and reviews clients leave you.

This is published. It appears in the in-app coach directory, on your page at myfitsy.com/@yourhandle, and can be read and indexed by anyone, including search engines and AI crawlers. Your page also shows your average rating, review count, years of experience and how many active clients you have. It is removed from public view if you clear your biography.

Legal basis: performance of our contract, and your consent for the parts you choose to publish.

4. Messages and attachments

The text of messages between a coach and a connected client, and the photos and videos sent in them.

Attachments are held in private storage. There is no public link to them: the app requests a short-lived signed address each time it needs to display one, and that address expires. Nobody outside the two people in the conversation can retrieve them, and a leaked address stops working.

Legal basis: performance of our contract.

5. Appointments

Session times, notes a coach adds, group membership, attendance. Legal basis: contract.

6. Where you are — only if you allow it

Both apps can ask your device for your location. Neither needs it, both work fully without it, and nothing is withheld from you for refusing. We ask only when you press something that plainly needs it, never on opening the app, and if you have said no once we do not ask again.

 In the client appIn the coach app
What it is for Putting nearer coaches first when you search, and showing how far away one is Filling in the city and country on your profile, so clients nearby can find you
What we store Your most recent latitude and longitude, and when it was taken. Overwritten each time — there is no history and no trail of where you have been One latitude and longitude for where you work, alongside the city and country you confirm
How precise As precise as your device reports. We do not round it, so treat it as your actual position rather than an area
Who can see it Nobody. Coordinates are never shown to another user and never leave our database. A client is shown a distance — "2.4 km away" — which is calculated on the server; a coach's coordinates are never sent to the app that displays the result, and neither are yours
If you refuse Search still works, ordered by city and country instead Type your city and country in yourself, as before

We keep the last reading rather than asking every time so that a search still works when you are underground, on a plane, or have simply switched location services off since. You can clear it by revoking location access in your phone's settings, and it goes when your account does.

Legal basis: your consent, given through your device's permission prompt and withdrawable there at any time.

7. Subscription status

Whether you have an active subscription or trial, which plan, when the current period ends, and a transaction reference from Apple or Google.

We never receive your card, bank or PayPal details. Apple and Google are the sellers; we are told only whether you are entitled to the paid features.

Legal basis: contract, and legal obligation for accounting records.

8. Reports and moderation records

If you report someone: your identity, who you reported, the category, and the written reason you gave. If a decision is taken about an account: what was done, why, and when. The person reported is not told who reported them.

Why: to keep people safe and to stop repeated behaviour being treated as a first offence. Legal basis: our legitimate interest in a safe service, and legal obligation where we must act or report.

9. Some photos are screened automatically

Two kinds of picture are checked by Google Cloud Vision for adult, violent or otherwise unsafe content before they are published: your profile picture and a coach's portfolio photos — the pictures other people see. The image is sent to that service for analysis and a safety rating comes back; the rating is kept, the image is not kept by us for that purpose, and an image the check rejects is deleted rather than published. An image the check is unsure about is published and passed to a person here to look at.

Nothing else is screened, and nothing else is sent to Google. Photos and videos you send in a conversation go to our storage and to the person you sent them to, and no automated system inspects them. We would rather tell you that than let you assume a filter stands between you and what someone sends. If someone sends you something they should not, report it or block them — a person here reads every report.

Legal basis: our legitimate interest, and that of every other user, in not being sent abusive images. See Automated decisions for what this does and does not decide on its own.

10. Website analytics and your choice

This website sets no cookies at all — not for advertising, not for analytics, not for anything else. There are no third-party trackers, no social media pixels, no advertising networks and no cross-site profiling. Nothing on these pages reports your visit to another company.

The one measurement we would like to take is a count of which pages get read. The first time you arrive we ask you, in a banner at the bottom of the page, to choose between allowing that count and allowing only what is strictly necessary. Until you choose, nothing is counted. If you decline, nothing is counted at all, and every part of the site keeps working exactly as it did.

If you do allow it, each page view records the page path, the referring website's domain (never the full referring URL), a coarse device type (mobile, tablet or desktop), and the country the request came from. We do not store your IP address.

What we store on your device: two things, both in your browser's local storage, neither of them a cookie and neither ever sent to another company.

We chose a random number over the more common alternative deliberately. The usual way to recognise a returning visitor without storing anything is to fingerprint their IP address and browser, which takes the decision away from them and is inaccurate as well — one phone changing from wifi to mobile data looks like two people, and an office behind a single address looks like one. A random number you consented to is both more honest and more accurate.

How long: visit-level detail — which pages one visitor read, and in what order — is deleted after 90 days. What remains after that is anonymous daily totals: how many visits, how many visitors, which pages, which countries. Those are kept so we can compare one month or year with another, and they cannot be traced back to anybody.

Changing your mind: select Privacy choices in the footer of any page. The banner reopens, your previous answer is discarded and mf_vid is deleted, so nothing can be joined to visits you made before. Withdrawing is exactly as easy as agreeing, and costs you nothing. Clearing your browser data has the same effect, and we will ask again.

Legal basis: your consent (Article 6(1)(a)) for the page-view count and for the random number that distinguishes a returning visit, neither of which we collect without it. Remembering your answer is strictly necessary to respect the answer itself.

11. Notifications

In-app notifications about your coaching, messages and sessions. If you turn on push notifications, a device push token so they can reach your phone. You can turn them off in Settings or in your phone's settings.

A push notification leaves our servers, and this is worth understanding. To reach a locked phone, a notification has to travel through the companies that own the delivery networks. Ours go to Expo, which passes them to Apple on an iPhone or Google on an Android phone, and each of those sees what the notification says while it is in transit.

For a new message, what it says includes the first 100 characters of the message — because a notification reading only "new message" is not much use, and a preview is what people expect. So the opening of a message can be seen by those three companies, and by anyone looking at your lock screen. The rest of the conversation never leaves our storage.

Turning push off stops this entirely. Notifications still appear inside the app, where nothing is sent to anybody. Do that in Settings, or in your phone's notification settings for MyFitsy — and if you would rather keep push but hide the content, both iOS and Android can be set to hide notification previews on the lock screen.

Legal basis: contract for the notification itself, and your consent for push delivery.

12. Support correspondence

What you write to us, so we can answer and refer back to it. Legal basis: legitimate interest.

What we never do

Who else processes your data

We use a small number of suppliers, each under a contract that limits them to acting on our instructions:

WhoWhat they doWhat they actually receiveWhere
Supabase
(on Amazon Web Services)
Database, sign-in, file storage Everything described above. This is where your account lives EU — Stockholm
Vercel Hosting this website, the coach pages and our server code Web requests, including your IP address at the moment of the request, and the country it came from EU edge, global network
Expo Sending push notifications Your device's push token, and the title and text of each notification — including a message preview. See section 11 United States
Apple App distribution, Sign in with Apple, subscriptions, push delivery on iPhone Sign-in identity; purchase and receipt data; notification content in transit Global
Google App distribution, Google sign-in, subscriptions, push delivery on Android Sign-in identity; purchase and receipt data; notification content in transit Global
Google Cloud Vision Automated image safety screening Only profile pictures and coach portfolio photos, as image data. Never a chat photo, never a video, never anything else Global

That is the complete list. There is no analytics company, no advertising network, no attribution or crash-reporting service, and no data broker — not because we removed them, but because they were never added. Nothing in either app sends your data to a company that is not in this table.

We may also disclose data where the law requires it — a court order, a lawful request from an authority, or to protect someone from serious harm. Where we are permitted to tell you, we will.

If MyFitsy were ever sold or reorganised, data could transfer to the acquirer, who would remain bound by this policy or give you notice of a replacement before anything changed.

Where your data is stored, and transfers

Your account, training data and file uploads are held in the European Union (Supabase, Stockholm region). Some suppliers above operate globally, so limited data may be processed outside the EEA — where that happens it relies on the European Commission's Standard Contractual Clauses or an adequacy decision.

How long we keep it

WhatKept for
Account, measurements, workouts, goals, programmesUntil you delete your account
A deleted account30-day grace period, then permanently erased — files first, then the account
Messages and attachmentsUntil deleted with the account of either participant
Your last known locationOverwritten by the next reading; deleted with your account. No history is kept
An upload waiting on a safety checkRemoved as soon as it is judged, and swept within 24 hours if it is abandoned
Reports and moderation recordsUp to 3 years after the decision, so repeat behaviour is visible
Subscription and payment records7 years, as Estonian accounting law requires
Website visit detail — which pages one visitor read, and in what order90 days, then deleted automatically
Website daily totals — how many visits, visitors, pages, countriesIndefinitely. These are anonymous counts and cannot be traced to anybody
Support emails2 years

Deleting your account is done in Settings or via this page. It takes effect after 30 days, which exists so a deletion by mistake can be undone: sign in during that window and confirm you wish to keep the account. After the 30 days it cannot be recovered.

Your rights

Under the GDPR you can:

Write to support@myfitsy.com from the address on your account. We answer within one month. We do not charge for this, and we will not make you justify the request.

One practical note: if you want a copy and you want the account gone, ask for the copy first. Deletion removes everything, and once the grace period has passed there is nothing left for us to send you.

If you are unhappy with how we handled it you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or to the supervisory authority where you live.

Automated decisions

The image screening in section 9 is automated, and it can block an upload on its own. It cannot suspend or close your account on its own — a warning or a ban is always decided by a person, and you can ask for that decision to be reviewed by writing to us. We do not carry out profiling that produces legal effects, and we do not use your data to make automated decisions about credit, insurance, employment or anything similar.

How we protect it

No system is perfectly secure. If a breach ever affects your data and creates a real risk to you, we will tell you and the Data Protection Inspectorate within the time the GDPR requires.

Children

MyFitsy is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we delete such accounts when we find them. If you believe a child has an account, write to support@myfitsy.com.

Changes to this policy

If we change something that matters — a new purpose, a new supplier, a different retention period — we will tell you in the app or by email before it takes effect, not quietly afterwards. The date at the top is always the current version.

Contact

Hoovus Kinnisvara OÜ
Registry code 16775200 · VAT EE102736764
Viru väljak 6, Kesklinna linnaosa, Tallinn, Harju maakond, 10153, Estonia
support@myfitsy.com