Privacy Policy
Last updated 11 August 2026
This policy explains what MyFitsy does with your personal data, why, and what you can do about it. It covers the MyFitsy app for clients, the MyFitsy Coach app for trainers, and this website.
Who is responsible for your data
The data controller is:
Hoovus Kinnisvara OÜ
Registry code 16775200 · VAT EE102736764
Viru väljak 6, Kesklinna linnaosa, Tallinn, Harju maakond, 10153, Estonia
support@myfitsy.com
Write to that address for anything in this policy, including to exercise your rights. A person reads it.
The short version. Your training data is yours and is never public. We do not sell data and never will. We do not run adverts or advertising trackers. We do not know your card number. A coach sees the data of clients connected to them, and a coach's own profile page is public because that is what it is for. Everything else below is the detail.
What we collect, and why
1. Account data
Your name, email address, role (coach or client), @handle, profile photo if you add one, unit preference, and a securely hashed password. We never store your password itself.
If you sign in with Apple or Google, we receive an account identifier and your email address from them — never your password. If you use Apple's Hide My Email, we only ever receive the relay address.
Why: to create and run your account. Legal basis: performance of our contract with you.
2. Health and fitness data — a special category
Body measurements (neck, shoulders, chest, waist, hips, arms, forearms, thighs, calves), weight, estimated body fat, height, date of birth, sex, training goals, logged workouts including weights lifted, reps completed, cardio time and distance, skipped sessions, and the programmes assigned to you or written by you.
Under the GDPR this is data concerning health, a special category needing stronger protection. Why: it is the service — recording it and charting it is what the app is for, and sharing it with your coach is what coaching requires. Legal basis: your explicit consent (Article 9(2)(a)), given when you create an account and confirm you have read this policy, and withdrawable at any time — see Your rights.
3. Coach profile data — public by design
For coaches only: biography, years of experience, certifications, specialisations, gyms, city and country, contact email and phone if you add them, social links, listed prices, portfolio photos with their titles and descriptions, and the ratings and reviews clients leave you.
This is published. It appears in the in-app coach directory, on your page at
myfitsy.com/@yourhandle, and can be read and indexed by anyone, including search
engines and AI crawlers. Your page also shows your average rating, review count, years of
experience and how many active clients you have. It is removed from public view if you clear
your biography.
Legal basis: performance of our contract, and your consent for the parts you choose to publish.
4. Messages and attachments
The text of messages between a coach and a connected client, and the photos and videos sent in them.
Attachments are held in private storage. There is no public link to them: the app requests a short-lived signed address each time it needs to display one, and that address expires. Nobody outside the two people in the conversation can retrieve them, and a leaked address stops working.
Legal basis: performance of our contract.
5. Appointments
Session times, notes a coach adds, group membership, attendance. Legal basis: contract.
6. Where you are — only if you allow it
Both apps can ask your device for your location. Neither needs it, both work fully without it, and nothing is withheld from you for refusing. We ask only when you press something that plainly needs it, never on opening the app, and if you have said no once we do not ask again.
| In the client app | In the coach app | |
|---|---|---|
| What it is for | Putting nearer coaches first when you search, and showing how far away one is | Filling in the city and country on your profile, so clients nearby can find you |
| What we store | Your most recent latitude and longitude, and when it was taken. Overwritten each time — there is no history and no trail of where you have been | One latitude and longitude for where you work, alongside the city and country you confirm |
| How precise | As precise as your device reports. We do not round it, so treat it as your actual position rather than an area | |
| Who can see it | Nobody. Coordinates are never shown to another user and never leave our database. A client is shown a distance — "2.4 km away" — which is calculated on the server; a coach's coordinates are never sent to the app that displays the result, and neither are yours | |
| If you refuse | Search still works, ordered by city and country instead | Type your city and country in yourself, as before |
We keep the last reading rather than asking every time so that a search still works when you are underground, on a plane, or have simply switched location services off since. You can clear it by revoking location access in your phone's settings, and it goes when your account does.
Legal basis: your consent, given through your device's permission prompt and withdrawable there at any time.
7. Subscription status
Whether you have an active subscription or trial, which plan, when the current period ends, and a transaction reference from Apple or Google.
We never receive your card, bank or PayPal details. Apple and Google are the sellers; we are told only whether you are entitled to the paid features.
Legal basis: contract, and legal obligation for accounting records.
8. Reports and moderation records
If you report someone: your identity, who you reported, the category, and the written reason you gave. If a decision is taken about an account: what was done, why, and when. The person reported is not told who reported them.
Why: to keep people safe and to stop repeated behaviour being treated as a first offence. Legal basis: our legitimate interest in a safe service, and legal obligation where we must act or report.
9. Some photos are screened automatically
Two kinds of picture are checked by Google Cloud Vision for adult, violent or otherwise unsafe content before they are published: your profile picture and a coach's portfolio photos — the pictures other people see. The image is sent to that service for analysis and a safety rating comes back; the rating is kept, the image is not kept by us for that purpose, and an image the check rejects is deleted rather than published. An image the check is unsure about is published and passed to a person here to look at.
Nothing else is screened, and nothing else is sent to Google. Photos and videos you send in a conversation go to our storage and to the person you sent them to, and no automated system inspects them. We would rather tell you that than let you assume a filter stands between you and what someone sends. If someone sends you something they should not, report it or block them — a person here reads every report.
Legal basis: our legitimate interest, and that of every other user, in not being sent abusive images. See Automated decisions for what this does and does not decide on its own.
10. Website analytics and your choice
This website sets no cookies at all — not for advertising, not for analytics, not for anything else. There are no third-party trackers, no social media pixels, no advertising networks and no cross-site profiling. Nothing on these pages reports your visit to another company.
The one measurement we would like to take is a count of which pages get read. The first time you arrive we ask you, in a banner at the bottom of the page, to choose between allowing that count and allowing only what is strictly necessary. Until you choose, nothing is counted. If you decline, nothing is counted at all, and every part of the site keeps working exactly as it did.
If you do allow it, each page view records the page path, the referring website's domain (never the full referring URL), a coarse device type (mobile, tablet or desktop), and the country the request came from. We do not store your IP address.
What we store on your device: two things, both in your browser's local storage, neither of them a cookie and neither ever sent to another company.
-
mf_consent— your answer to the banner: what you agreed to, the date you agreed, and which version of this policy you agreed against. It contains no identifier. It exists so we do not ask you the same question on every page, and so we can show that consent was actually given rather than assumed. If we later change what we would like to measure, the version changes and we ask you again — an old yes does not carry over to a new question. -
mf_vid— only if you allow counting. A random number generated in your browser, meaning nothing by itself. It is what lets us tell a returning visit from a first one, so we can see whether people find the site useful enough to come back. We never see the number itself: it is put through a one-way hash on our server, and only the result is stored.
We chose a random number over the more common alternative deliberately. The usual way to recognise a returning visitor without storing anything is to fingerprint their IP address and browser, which takes the decision away from them and is inaccurate as well — one phone changing from wifi to mobile data looks like two people, and an office behind a single address looks like one. A random number you consented to is both more honest and more accurate.
How long: visit-level detail — which pages one visitor read, and in what order — is deleted after 90 days. What remains after that is anonymous daily totals: how many visits, how many visitors, which pages, which countries. Those are kept so we can compare one month or year with another, and they cannot be traced back to anybody.
Changing your mind: select Privacy choices in the footer of any page. The
banner reopens, your previous answer is discarded and mf_vid is deleted, so nothing
can be joined to visits you made before. Withdrawing is exactly as easy as agreeing, and costs
you nothing. Clearing your browser data has the same effect, and we will ask again.
Legal basis: your consent (Article 6(1)(a)) for the page-view count and for the random number that distinguishes a returning visit, neither of which we collect without it. Remembering your answer is strictly necessary to respect the answer itself.
11. Notifications
In-app notifications about your coaching, messages and sessions. If you turn on push notifications, a device push token so they can reach your phone. You can turn them off in Settings or in your phone's settings.
A push notification leaves our servers, and this is worth understanding. To reach a locked phone, a notification has to travel through the companies that own the delivery networks. Ours go to Expo, which passes them to Apple on an iPhone or Google on an Android phone, and each of those sees what the notification says while it is in transit.
For a new message, what it says includes the first 100 characters of the message — because a notification reading only "new message" is not much use, and a preview is what people expect. So the opening of a message can be seen by those three companies, and by anyone looking at your lock screen. The rest of the conversation never leaves our storage.
Turning push off stops this entirely. Notifications still appear inside the app, where nothing is sent to anybody. Do that in Settings, or in your phone's notification settings for MyFitsy — and if you would rather keep push but hide the content, both iOS and Android can be set to hide notification previews on the lock screen.
Legal basis: contract for the notification itself, and your consent for push delivery.
12. Support correspondence
What you write to us, so we can answer and refer back to it. Legal basis: legitimate interest.
What we never do
- We do not sell personal data, and we do not share it for anyone else's advertising.
- We do not run adverts or advertising SDKs in the apps.
- We do not build advertising or marketing profiles from your health data.
- We do not make your training data, measurements, chats or photos public. The only public surface is a coach's own profile page.
- We do not read your chats routinely. A message is looked at when it is reported, or where the law requires.
Who else processes your data
We use a small number of suppliers, each under a contract that limits them to acting on our instructions:
| Who | What they do | What they actually receive | Where |
|---|---|---|---|
| Supabase (on Amazon Web Services) |
Database, sign-in, file storage | Everything described above. This is where your account lives | EU — Stockholm |
| Vercel | Hosting this website, the coach pages and our server code | Web requests, including your IP address at the moment of the request, and the country it came from | EU edge, global network |
| Expo | Sending push notifications | Your device's push token, and the title and text of each notification — including a message preview. See section 11 | United States |
| Apple | App distribution, Sign in with Apple, subscriptions, push delivery on iPhone | Sign-in identity; purchase and receipt data; notification content in transit | Global |
| App distribution, Google sign-in, subscriptions, push delivery on Android | Sign-in identity; purchase and receipt data; notification content in transit | Global | |
| Google Cloud Vision | Automated image safety screening | Only profile pictures and coach portfolio photos, as image data. Never a chat photo, never a video, never anything else | Global |
That is the complete list. There is no analytics company, no advertising network, no attribution or crash-reporting service, and no data broker — not because we removed them, but because they were never added. Nothing in either app sends your data to a company that is not in this table.
We may also disclose data where the law requires it — a court order, a lawful request from an authority, or to protect someone from serious harm. Where we are permitted to tell you, we will.
If MyFitsy were ever sold or reorganised, data could transfer to the acquirer, who would remain bound by this policy or give you notice of a replacement before anything changed.
Where your data is stored, and transfers
Your account, training data and file uploads are held in the European Union (Supabase, Stockholm region). Some suppliers above operate globally, so limited data may be processed outside the EEA — where that happens it relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
| What | Kept for |
|---|---|
| Account, measurements, workouts, goals, programmes | Until you delete your account |
| A deleted account | 30-day grace period, then permanently erased — files first, then the account |
| Messages and attachments | Until deleted with the account of either participant |
| Your last known location | Overwritten by the next reading; deleted with your account. No history is kept |
| An upload waiting on a safety check | Removed as soon as it is judged, and swept within 24 hours if it is abandoned |
| Reports and moderation records | Up to 3 years after the decision, so repeat behaviour is visible |
| Subscription and payment records | 7 years, as Estonian accounting law requires |
| Website visit detail — which pages one visitor read, and in what order | 90 days, then deleted automatically |
| Website daily totals — how many visits, visitors, pages, countries | Indefinitely. These are anonymous counts and cannot be traced to anybody |
| Support emails | 2 years |
Deleting your account is done in Settings or via this page. It takes effect after 30 days, which exists so a deletion by mistake can be undone: sign in during that window and confirm you wish to keep the account. After the 30 days it cannot be recovered.
Your rights
Under the GDPR you can:
- See what we hold about you, and get a copy of all of it;
- Correct anything wrong — most of it you can edit yourself in the app;
- Delete your data. Settings in either app, or this page if you cannot get into the app. Both do the same thing and both remove everything, including your uploaded files;
- Take it elsewhere — the copy we send is a single machine-readable file covering every category in this policy, which you are free to hand to anybody;
- Restrict or object to processing based on legitimate interests;
- Withdraw consent at any time. Because health data is processed on the basis of your explicit consent, withdrawing it means we can no longer run a training account for you — so withdrawing consent and deleting the account are effectively the same act, and we will tell you that before doing it rather than after.
Write to support@myfitsy.com from the address on your account. We answer within one month. We do not charge for this, and we will not make you justify the request.
One practical note: if you want a copy and you want the account gone, ask for the copy first. Deletion removes everything, and once the grace period has passed there is nothing left for us to send you.
If you are unhappy with how we handled it you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or to the supervisory authority where you live.
Automated decisions
The image screening in section 9 is automated, and it can block an upload on its own. It cannot suspend or close your account on its own — a warning or a ban is always decided by a person, and you can ask for that decision to be reviewed by writing to us. We do not carry out profiling that produces legal effects, and we do not use your data to make automated decisions about credit, insurance, employment or anything similar.
How we protect it
- Everything travels over encrypted connections.
- Passwords are stored only as salted hashes, never as text.
- Row-level security in the database means one account cannot read another's data even if a request tries to — the rule is enforced by the database, not only by the app.
- Chat photos and videos live in private storage reachable only through short-lived signed addresses.
- Administrative access is limited, password-protected and separate from the apps.
No system is perfectly secure. If a breach ever affects your data and creates a real risk to you, we will tell you and the Data Protection Inspectorate within the time the GDPR requires.
Children
MyFitsy is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we delete such accounts when we find them. If you believe a child has an account, write to support@myfitsy.com.
Changes to this policy
If we change something that matters — a new purpose, a new supplier, a different retention period — we will tell you in the app or by email before it takes effect, not quietly afterwards. The date at the top is always the current version.
Contact
Hoovus Kinnisvara OÜ
Registry code 16775200 · VAT EE102736764
Viru väljak 6, Kesklinna linnaosa, Tallinn, Harju maakond, 10153, Estonia
support@myfitsy.com
