Fitineary

Privacy policy

What Fitineary stores, why, who can see it, and how to get rid of it. This one policy covers the Fitineary app and the fitineary.com website.

Last updated 29 September 2026 · Fitineary is operated by 7th Pillar Infotech, India.

The short version. Your account is your email address, or your phone number if you sign in with that instead. Everything else is what you log — food, training, sleep, mood, weight, photographs — plus, if you choose to connect Apple Health or Health Connect, what your phone and watch recorded, and, if you have a coach, what you send them: messages, photographs and voice messages. It is stored so the app can show it back to you. It is not sold, and it is not used for advertising. A coach sees your diary only while you have connected to one, and only for as long as you stay connected; the messages the two of you sent each other stay with both of you afterwards. You can delete the account, and everything in it, from inside the app. If you only joined a list on the website, we hold your email address, the goal or details you gave, and the country you visited from, and nothing else.

1. Who we are

Fitineary is operated by 7th Pillar Infotech, which is the Data Fiduciary for your personal data under India’s Digital Personal Data Protection Act, 2023 (the DPDP Act), and the data controller under equivalent laws elsewhere.

Registered address1st Floor, Sree Vilas, Darshan Nagar Rd, near DLF, Kakkanad, Kochi, Kerala 682037, India
Company identifierGSTIN 32AAACZ7635B1ZL
Privacy contactprivacy@fitineary.com
Grievance OfficerRashin Pothan — grievance@fitineary.com, +91 98470 32301

2. What we collect

All of it comes from you. There is no tracking pixel, no advertising identifier and no analytics SDK in the app — nothing measures what you look at, how long you stay or what you tap. There is one third-party SDK, and it reports crashes: when the app fails it sends the programming error and the version of the app and phone it happened on, so that we find out without waiting for somebody to tell us. It carries nothing you logged and nothing that says who you are. It is described in full in section 5.

AccountYour email address or your phone number, whichever you sign in with, which is the account — there is no separate username or password. A display name, language, and your unit preferences (kg/lb, cm/ft). An optional profile photograph.
About youSex, date of birth, height, your goal and activity level. Used to compute a calorie and protein target and for nothing else.
Health & fitnessWhat you log each day: meals and their portions, water, sleep duration and quality, mood, body weight, exercises, sets, reps and loads, and completed routine sessions.
From Apple Health or Health ConnectOnly if you connect it, and only what you allow. Steps, active calories, workouts, sleep and weight, read from your phone's health store. Fitineary also writes back to it the water you log, a weight you typed yourself, and each day's food energy and macros. It reads no heart rate. It is stored with your account, and a coach you have connected to sees steps, active calories and workouts from it only while Share with my coach is on. See “Your phone’s health store” below.
Photographs, video & voice messagesMeal photographs you take or pick, a profile picture, demonstration videos a coach attaches to an exercise, and anything you attach to a message in a coach conversation — a photograph, or a voice message you record there. A meal photograph is sent for analysis when you log a meal from a picture, whether you take it or pick one you already had — see “Reading a meal photograph” below. An attachment sent to a coach is not sent for analysis and goes to no AI service at all; it is stored so the two of you can open it, and nothing else — see “Sending a photograph or a voice message to your coach” below.
What you describeIf you type or say what you did instead of filling in a form, the words you typed — or, if you spoke, a recording of what you said — are sent to be read. Recording starts only when you start it and stops when you stop it — two deliberate actions, one at each end, with nothing captured before the first or after the second, and thirty seconds is the cap whatever you do. The microphone is used in two other places — a voice message you record in a coach conversation, and the sound on a demonstration video if you are a coach filming one — and nowhere else: there is no listening in the background and no wake word. If you describe food, the food’s name is sent a second time to be given a calorie figure, without being asked for. See “Describing a log in words” below.
CoachingIf you connect to a coach: the connection itself, what they coach, the routines they assign you, and the messages between you — including any photograph or voice message either of you attaches to one. If you are a coach, your own coaching profile: your bio, what you coach, your certifications and a phone number, if you choose to publish one — leaving it blank is a complete answer, and the field says at the point of entry that your clients can see it and call you.
DeviceA push token, and only if you allow notifications. When you sign in, your phone's notification service issues an address for this app on this device; we store that address and whether the device is iOS or Android, so a message from your coach can reach your lock screen. Refuse the permission and nothing is stored. Signing out deletes it. It is not an advertising ID and it identifies no one but this installation. Delivering a notification necessarily hands that address to the push service that issued it — see “Where it lives” below.
SubscriptionOnly if you subscribe. Which plan you are on, whether it is a trial, when it started and when it renews or ends, whether it will renew, and the payment provider’s own reference for your subscription. We never see or store your card number or bank details — you enter those on the payment provider’s page, not ours. See “Paying for a subscription” below.

We do not collect location, contacts, your device's advertising ID, browsing activity or performance telemetry. The only data we take from another app is what you choose to bring in from Apple Health or Health Connect, described above.

The one exception is a crash, and it is an exception rather than a qualification: when the app fails it sends a report of that failure, carrying the programming error, the version of the app and the model and operating-system version of the phone — and nothing that identifies you or anything you logged. Nothing at all is sent while the app is working. Section 5 says exactly what a report holds.

On the website. fitineary.com collects only what you type into its two forms, plus three things about the visit:

Early access listYour email address, the goal you chose (“lose weight”, “build muscle” or “general fitness” — a broad interest, not a health record), your confirmation that you are 18 or over, and a record of your consent: which boxes you ticked, when, and the version of this policy in force at that moment. We keep that record because the law requires us to be able to show consent was given.
Coach listYour name, email address and the professional details you enter: what you coach, roughly how many clients you have, years coaching and any certifications you list.
The visitThe country your request came from, which our hosting provider derives from your IP address — we store the country, not the address — your browser’s user-agent string, and the page that referred you. Analytics events only if you consent; see section 11.

The website asks for no health information, no phone number, no postal address and no payment details. The calculator on its front page runs entirely in your browser; the numbers you type into it never leave your device.

3. Why we hold it

We do not profile you, sell data, share it with advertisers, or use it to train a model.

The legal basis is your consent, given when you create an account or join a list, for everything above; and legitimate use — keeping the service secure and working — for the country, user agent and referrer the website records. You can withdraw consent at any time; see section 8.

4. Who can see it

You can. Nobody else, with five exceptions you create yourself:

Access is enforced by the database itself, per row, rather than by the app asking politely — a request for data you may not see returns nothing, not a filtered version.

5. Where it lives

Records are held in a managed PostgreSQL database run by Supabase in Mumbai, India; photographs, video and the voice messages you send a coach are held as objects in Cloudflare R2, in its Asia-Pacific region. Both are held under 7th Pillar Infotech’s own accounts, and both are encrypted in transit (HTTPS/TLS) and at rest by the provider. An image, a video or a voice message is reached only through a short-lived signed link that is issued after your permission to see it has already been checked — the storage layer never decides who you are.

Six things leave this system by design. All six are described here in full; nothing else about you goes anywhere. Your phone’s health store, described after them, is the other direction: it puts data into this system, and what Fitineary writes back to it stays in your phone’s health store.

A sign-in code. To sign you in we send a one-time code. If you sign in with your email address, the address and the code go to Resend, an email delivery service, which sends the email. If you sign in with your phone number, the number, the code and your display name, if you have set one, go to AiSensy, which delivers the code as a WhatsApp message through Meta’s WhatsApp Business platform. Nothing else about you is included, and the code stops working once it is used, or an hour after it was sent at the latest.

Paying for a subscription. Nobody has to pay to use Fitineary; a subscription is an option. On Android the payment page is run by Dodo Payments, which sells the subscription to you as the merchant of record: you enter your payment details, your email address and your billing address on Dodo’s page, and Dodo handles them under its own privacy policy. We send Dodo only which plan you chose and a random identifier for your account, and Dodo tells us whether the payment succeeded, when the plan renews, and whether it was cancelled. On iPhone you pay Apple through the App Store, and RevenueCat checks the purchase with Apple for us; we give RevenueCat the same random account identifier, never your email address or phone number. Either way, your card number never reaches us, and neither provider is sent anything you logged.

Notifications. To put a message on your lock screen we pass your device's push token, and the notification's own wording, to Expo's push service and from there to Google’s Firebase Cloud Messaging on Android or Apple’s push service on iOS. The message body is written by our server, not copied from the conversation — a coach’s notification says that they sent you a message, and never what it said. Nothing else about you is included.

Reading a meal photograph. When you log a meal from a picture — taken now, or chosen from your photos — that picture is sent to an AI service to be read, and what comes back is a guess at what is on the plate and how much of it — a list of foods and gram estimates, which you then correct before anything is saved. The request is routed through our own server, which passes on the picture and a fixed instruction to read it — and nothing else. Not your name, not your email address, not your diary, not your targets, and nothing that identifies you or the account. If you then ask for a different food match, the food’s name and the portion in grams are sent the same way; still nothing about you. Our server instructs the AI service not to retain what it is sent — it will only route the request to providers that do not store it — and it is used to answer your request and for no other purpose. The same instruction is set on every request of this kind, a description and a recording included. Nothing you photograph, type or say is used to train anyone’s model, including ours.

You are never obliged to use it. Search for a food and enter the portion instead and no photograph leaves your phone at all. And the estimate is an estimate: it arrives with a match score precisely because it can be wrong, and every gram stays editable before you save it.

Describing a log in words. Instead of filling in a form you can type what you did, or say it. Typing and speaking are two separate screens and you choose between them before either one starts; the one you speak on records nothing until you start it, and stops the moment you stop it. Either way what you wrote, or a recording of what you said, is sent to the same AI service, through the same server of ours, with a fixed instruction to turn it into a list of things to log and nothing else attached. Not your name, not your email address, not your diary, not your targets, and nothing that identifies you or the account.

What comes back is a card of what was understood, one row per thing, and every row says what it would write before it writes anything. The rows are not tappable. Save on a row writes that row into your diary there and then; Adjust opens the ordinary screen for that kind of log, already filled in, for when you want to change something first. A row you did not mean can be removed, and closing the card without saving puts nothing in your diary. The rows you have not saved yet are kept on your phone, and only there, so that going back or closing the app does not lose them; they are deleted when you save or discard them, when you sign out, or a day after you last changed them.

A food row is sent a second time, and nobody asks you first. Food is the one thing you can describe with no number in it, so when a food row appears the food’s name — and only the name — goes back to the same service under a second fixed instruction: give this a calorie and macro figure. That happens once per food row, without being requested, because the figure is what the row has to show you before Save can mean anything. It travels the same way as everything else here, with nothing about you attached, and it is what Save writes.

A recording made to describe a log is never kept on our servers. On your phone the file is temporary, and lives only for as long as it takes to read it. There is no step in between: stopping the recording is what sends it, and Fitineary deletes the file as soon as the reading comes back or fails. It is also deleted if you leave the screen while a recording is still running. There are two cases we cannot cover for you: force-quitting the app while a recording is in progress or waiting to be read, and an operating system that refuses the deletion — Fitineary asks it to delete the file and cannot compel it. In either case the temporary file is the operating system’s to clear, and we have no way to know it is still there. No copy is stored in your account and it is not attached to anything you log.

The sound outlives the file by a little, in the app’s memory and nowhere else. The file has to be read before it can be sent, and what was read is kept in the app’s memory for as long as that voice screen stays open — so that if the reading fails, trying again does not mean saying the whole thing over. It is never written back to storage, never uploaded a second time on its own, and never attached to your account. It goes when you start another recording, and it goes when you close the screen. Recording never starts on its own. It begins when you start it and ends when you stop it, and it is always capped at thirty seconds.

What we do keep, for this and for a meal photograph alike, is a short record of what the model understood — kept with your account so we can see how often it reads people correctly, deleted with the account, and not used to train anyone’s model. For a photograph we also record whether you corrected the reading. For a description we do not: what you do with the card afterwards is not written back against the record, and it is stored saying exactly that.

You are never obliged to use this either. Every screen it can take you to is one you can reach by tapping, and refusing the microphone leaves everything except this, a voice message to a coach, and the sound on a demonstration video exactly as it was — the app says so plainly and offers you the typed box instead.

Sending a photograph or a voice message to your coach. This one is here for the opposite reason to the ones above: nothing about it leaves our system, and what makes it worth its own section is that it is kept. Attach a photograph to a message, or record a voice message in the conversation, and the file is stored the way a meal photograph's bytes are stored — a row in the database and an object in Cloudflare R2, reachable only through a short-lived signed link issued after your permission to see it has been checked. It is not sent to the AI service, or to anyone else. Nothing is read out of it, nothing is guessed from it, and it is not used to train anything. It is stored so that you and your coach can open it, and for nothing else.

Nothing is recorded until you deliberately start a recording, and nothing leaves your phone until you press Send: a recording waits in the conversation where you can play it back and throw it away, and a photograph you have attached can be removed before you send it. Once you do send it, Fitineary deletes the temporary recording from your phone; the copy that remains is the stored one. A sent message cannot be taken back — there is no delete for a single message, on either side, and saying otherwise would be describing a control that does not exist. It goes when the account goes.

A crash report. When the app fails — a screen that stops drawing, or the whole app closing on its own — a report of that failure is sent to Firebase Crashlytics, Google's crash-reporting service. It contains the programming error and the line of our own code it happened on, the version of Fitineary you are running, the model and operating-system version of the phone, and whether the app was in the foreground. It is sent because a crash you do not report is a crash we never learn about, and until this existed the only way we heard about one was somebody describing the screen to us.

What a crash report does not contain, and this is enforced in the code rather than promised here. No email address, no phone number, no name and no account identifier — the report is not tied to you, and we could not look up who sent one. Nothing you logged: no meal, no photograph, no weight, no message to a coach. Nothing you typed or said. The service records no list of what you tapped, and Fitineary writes no notes of its own into a report, which is what keeps that true. This is crash reporting and not analytics: nothing is sent while the app is working, Google Analytics for Firebase is switched off and is not even installed, and no measurement of your use of the app is collected at any time.

One identifier does exist, and it is not you. Crashlytics gives each installation a random identifier of its own so that two crashes from the same phone can be seen as the same phone. It is generated on the device, it is not the advertising identifier, it is not your account, and uninstalling the app ends it. We never send anything alongside it that would say whose phone it is.

Your phone’s health store. This one is here because it is the other way round: nothing about it leaves our system, but it brings data in. If you connect Apple Health on an iPhone or Health Connect on Android, Fitineary asks your phone for permission to read your steps, active calories, workouts, sleep and weight, and to write back the water you log, a weight you typed yourself, and each day’s food energy and macros. It does not read heart rate. On Android, workouts arrive without distance. You choose what to allow on your phone’s own permission screen and can change it there at any time. Nothing is read until you connect, and it is read while the app is open, not in the background.

What is read is stored with your account in the same database as the rest of it (Mumbai, section 5), and it goes when the account goes. It is never sent to the AI service, and never used for advertising. A coach you have connected to sees your steps, active calories and workouts from your watch only while Share with my coach is on, which it is until you turn it off; with it off they see none of those. Sleep and weight are the exception: they are part of your daily diary row, which a coach you are connected to already sees when you type them. If you type a sleep or weight yourself, your value is kept and an import never replaces it, and a workout you edit or delete stays as you left it. A workout you delete from your phone’s health store, and never edited here, is removed from Fitineary at the next sync. The connection is remembered for your account on that phone; another account on the same phone starts disconnected.

The website’s lists. The website is hosted by Cloudflare, which also stores what you submit to either list. A working copy of the lists is kept in Google Sheets: your email, goal and consent record, or a coach’s details. If you tick the analytics box on the sign-up form, PostHog receives analytics events about your visit; the website never sends it your email address, and without that tick it receives nothing. These three process data on our instructions only.

Leaving India. Your account and everything you log are stored in India. Some of the providers named in this section operate outside India, including in the United States, so what this section says each of them receives is transferred and processed outside India. The DPDP Act permits such transfers except to countries the Central Government restricts, and we use providers that make contractual data-protection commitments. We may also disclose personal data where the law requires us to, or to establish or defend a legal claim.

6. How long

Until you delete it. Individual entries go when you delete them. The whole account goes when you delete the account — see below — and that removes your profile, your logs, your photographs, your messages and your coaching connections. We keep no shadow copy for analytics.

When a coaching relationship ends, the routines that coach assigned you leave your library along with their access — they belong to the coach, who keeps them. Reconnecting is not an undo; they assign again. What stays is anything you built yourself.

A disconnected conversation keeps its words and loses its attachments, and that is a decision rather than a side-effect. The messages you exchanged stay readable to both of you. The photographs and voice messages do not: from the moment the connection ends, each of you can still open what you sent yourself, and neither of you can open what the other sent. Nothing is deleted — the files are still there, and reconnecting makes them open again — but while you are disconnected they are simply not yours to see, for the same reason the rest of the diary is not. The app says so on the bubble rather than showing a broken picture.

The website’s lists are kept until twelve months after the app’s launch in August 2026, or until you ask us to erase your entry, whichever comes first; after that an entry is deleted without you having to ask. A consent record is kept for as long as the entry it belongs to, plus the period in which a claim could be brought.

7. Your choices

8. Your rights, and how to complain

Under the DPDP Act you have the right to:

Write to privacy@fitineary.com and we will answer within 30 days; we may ask you to confirm the request comes from the email address or phone number we hold. If you are unhappy with how we have handled your data, contact our Grievance Officer (section 1) first. If you are not satisfied with the answer, you have the right to complain to the Data Protection Board of India.

9. Children

Fitineary is not for anyone under 18. The website asks you to confirm your age before you join a list. We do not knowingly collect personal data from a child, we do not track children, and we do not serve them behavioural advertising. If you believe a child has created an account or joined a list, email privacy@fitineary.com and we will delete it.

10. Security

Data is encrypted in transit and at rest, access is checked by the database on every request (section 4), and access to the website’s lists is restricted to the people who need it. No system is perfectly secure, and we do not claim otherwise; if a breach affects your personal data we will tell you and the Data Protection Board, as the DPDP Act requires.

11. Cookies and local storage

Neither the app nor the website sets an advertising cookie or a third-party tracking cookie. On the website, the analytics tool loads switched off, keeps anything it holds in memory only, sets no cookie and no lasting identifier, and records nothing — not even a page view — unless you tick the consent box on a sign-up form. If you consent and later change your mind, tell us and we will delete the events.

12. Changes

If this policy changes, the date at the top changes. If a change materially affects what we collect or who receives it, we also say so in the app’s release notes on the App Store and Google Play, and email the people it affects; where the law requires it, we ask for your consent again. We will not quietly widen what is collected.

13. Contact

Questions, corrections, or a data request: privacy@fitineary.com. We answer data requests within 30 days. Complaints go to the Grievance Officer named in section 1.