← FitJournal
Privacy Policy
Last updated 28 August 2026 · Effective 28 August 2026
This policy explains what FitJournal (iOS and Android) does with your data. It is written
against what the app actually does, not against a template.
The app is published by Sultan Seidalin, an individual developer, who is the data
controller. Contact: seidalins@gmail.com.
The short version
- You sign in with Google or Apple. We get your email address, and a display name and profile picture URL if your provider supplies one. There is no password to lose, because we never handle one.
- Your training data lives on your device first, in a local database. The app works fully offline.
- In the background it syncs to our servers in the EU (Stockholm, eu-north-1), so you can change phones without losing your log.
- We use no advertising SDKs, no ad identifier (IDFA/GAID), no tracking or attribution SDKs, and we do not sell or share your data with data brokers.
- Your step count from Apple Health is read on your device and never uploaded.
- We do not use your workouts, notes or photos to train AI models.
What we collect
Account
| Data | Where it comes from | Why |
| Firebase user ID | Created when you first sign in | The identifier that ties your data together |
| Email address | Google or Apple (an Apple private-relay address is fine) | Identifying your account, support |
| Display name | Your provider, if supplied. Otherwise a default is used — we never ask you for it | Showing your name in the app |
| Profile picture URL | Your provider, if supplied. Stored as a link only; we never copy the image | Showing your avatar |
| Platform (iOS / Android), training goal, unit preferences | You / your device | Running the app the way you set it up |
We do not collect your date of birth, gender, address, phone number, or payment details. We never see
your card. Purchases happen inside Apple's and Google's systems.
Training data (your content)
Everything you log, which is the point of the app:
- Journals — name, comments, whether personal, training goal
- Workouts — date, workout number, start time, duration, your comment, and every exercise and set in it: weight, reps, distance, duration, completion
- Workout sessions (start and end times) and per-workout notes
- Free-text notes, including pinned ones
- Body measurements — type, value, your comment, and date
- Custom exercises you create
- Progress photos, if you add them (see below)
Body measurements and progress photos are health-related data. Under EU law that is a
special category, which is why we process it only on the basis of your explicit consent — given by choosing to
enter it — and why you can delete any of it at any time.
Diagnostics and usage
- Crash reports (Firebase Crashlytics) — stack traces, device model, OS version, and app state breadcrumbs, tagged with your user ID so we can tell whether a crash hit one person or everyone.
- Analytics (Firebase Analytics) — around thirty structural events: app opened, signed in with Google or Apple, journal created, workout added, paywall shown, purchase made, account deleted. The parameters are things like
method: "google", never the contents of your notes or measurements. One event does include the names of exercises you added to a workout.
- Performance (Firebase Performance) — app start and network timings.
- Push token (Firebase Cloud Messaging) — a device token, held on your device.
What we do not collect
Stated plainly, because it is unusual enough to be worth saying:
- No advertising identifier, no ad SDK, no App Tracking Transparency prompt — we do not track you across other companies' apps or websites.
- No location. (Older builds shipped an unused location permission string inherited from a since-removed SDK; nothing in the app has ever requested or read your location.)
- No camera, microphone, contacts, or calendar access.
- No health data beyond the step count described below.
- No session recording, heatmaps, or screen replay.
Apple Health (iOS only)
If you allow it, FitJournal reads your step count and nothing else, to display it on the
home screen. Access is read-only — the app never writes to Health. This data never leaves your
device: it is not sent to our servers, our analytics, or any third party. Revoke it any time in
iOS Settings → Privacy & Security → Health.
Photos
Two separate things, which behave differently:
- Progress photos that you attach to body measurements are uploaded to our storage in the EU, so they sync across your devices. They are shown through short-lived signed links.
- Workout share cards. If you pick a photo as the background of a post-workout card, that photo is used on your device only, to render the image. It is never uploaded. Saving the card to your photo library or sharing it is your choice, and it goes wherever you send it.
Progress photos are deleted when you delete the photo itself, when you delete the journal it belongs to, and
when you delete your account. Deleting a single body-measurement entry deliberately leaves its photos alone —
they stay browsable in the photo gallery, and are yours to remove when you want to.
Reporting a problem
If you use the “report a problem” form in Settings, the app sends your message together with
the email address you type in, your user ID, your platform and your app version to a private
support channel we run on Telegram. Only send what you are comfortable sharing there —
the message goes to Telegram's servers, not to our own, and Telegram's
privacy policy applies to it. If you would rather not use Telegram,
email us directly at seidalins@gmail.com instead.
The AI suggestion feature
The app can show an optional suggestion for your next set. When it does, it sends to Google's Gemini API,
through the Firebase AI Logic SDK: the exercise name, the sets from your previous session of that
exercise, and the sets you have logged today. That is all. It does not send your name, email, user ID,
notes, body measurements, or photos. The response is shown on screen and is not stored anywhere.
This feature is disabled by default and only runs if we switch it on remotely. Google's handling of the
request is governed by the Firebase privacy
documentation.
Who else receives data
These are our processors. We do not sell data to anyone, and none of these are advertising networks.
| Who | What they get | What for |
| Amazon Web Services | Your account record, training data, and progress photos | Hosting and sync (EU, Stockholm) |
| Google / Firebase | Sign-in identity, crash reports, analytics events, performance data, push token, AI prompts | Authentication, diagnostics, notifications, AI suggestions |
| Apple / Google Play | Purchase and subscription records | Selling and billing subscriptions |
| Qonversion | Your user ID and purchase receipts | Checking whether your subscription is active |
| RevenueCat | Your user ID and purchase receipts | Subscription analytics |
| Superwall | Your user ID and paywall interactions | Showing and testing the paywall |
| Telegram | Only what you submit through “report a problem”: your message, the email you enter, your user ID, platform and app version | Delivering support reports to us |
Where your data is stored, and transfers
Your training data and photos are stored in AWS in Stockholm, Sweden (eu-north-1) — inside
the EU/EEA. Firebase and the subscription vendors are US-based companies and may process data in the United
States or elsewhere; those transfers rely on the European Commission's Standard Contractual Clauses and, where
applicable, the EU–US Data Privacy Framework.
Legal bases (EU/EEA and UK users)
- Performance of a contract — running your account, storing and syncing what you log, managing your subscription.
- Explicit consent — health-related data (body measurements, progress photos), Apple Health access, and the AI suggestion feature. You can withdraw consent by deleting the data or turning the permission off; withdrawal does not affect processing already carried out.
- Legitimate interests — crash reporting, analytics and performance monitoring, to keep the app working and to understand which features are used. You can object; email us.
- Legal obligation — keeping transaction records where tax or consumer law requires it.
How long we keep it
We keep your data while your account exists. When you or the app delete something, it is marked deleted and
stops appearing anywhere in the app on any of your devices.
Being straight with you: when you delete an individual item, most rows are tombstoned rather than
erased in our database.
That design lets sync work correctly across devices and lets us recover from a bad delete, but it means a
deleted workout can persist in backend storage after it disappears from your app. Deleting an individual note,
body measurement or photo erases it outright, and so does deleting your whole account. If you want everything
about you erased rather than tombstoned, email us and we will do it manually.
Crash and analytics data is retained under Firebase's own retention periods (analytics events for up to
14 months by default; crash reports for up to 90 days).
Deleting your account
Settings → delete account, in the app. It deletes, on our servers and on the device:
- your workouts, sets, sessions and per-workout notes,
- your journals, notes and body measurements,
- every custom exercise you created,
- every progress photo you uploaded, and
- your profile record and your Firebase sign-in account — so signing in again with the same Google or Apple account creates a genuinely new, empty account.
The app waits for those deletions to be confirmed by the server before signing you out, and only then clears
the local database.
One caveat, worth stating. If you delete your account while offline, the deletion completes on
your device but we cannot reach the server to carry it out, and you are signed out before we get another
chance. If that happens,
email us with the address you signed in with
and we will finish it by hand. Deleting while connected needs no follow-up.
Deleting your account does not cancel a subscription — cancel that in your Apple ID or Google Play settings.
Your rights
If you are in the EU/EEA or the UK you have the right to access your data, correct it, delete it, restrict or
object to processing, and receive a copy in a portable format. Similar rights apply in many other places,
including under California law.
Deletion is built into the app. There is no self-service export yet, so for a copy of your
data, or for anything else on this list, email
seidalins@gmail.com and we will answer within 30 days. It is one
person answering, so please be patient if it takes a few days.
You can also complain to your national data protection authority. If you are in the EU, that is the
supervisory authority where you live or work.
Security
Data travels over encrypted connections (HTTPS/TLS) and is stored on managed AWS and Google infrastructure.
Sign-in is handled by Firebase Authentication, so we never see or store a password.
The local database on your device is not separately encrypted beyond the encryption your phone already
applies, and on iOS it may be included in your iCloud device backup. On Android, app data is excluded from
Google backups.
No system is perfectly secure, and we will not pretend otherwise. If you discover a security problem in
FitJournal, please report it to seidalins@gmail.com before disclosing
it publicly, and we will fix it as fast as we can.
Children
FitJournal is not for children under 13, and we do not knowingly collect their data. If you believe a child
under 13 has an account, email us and we will delete it. Where the age of digital consent is higher than 13
(16 in parts of the EU), users below it need a parent's or guardian's consent.
Changes
We will update this policy when the app changes. The date at the top always shows the current version, and
material changes will be announced in the app before they take effect.
Contact
Sultan Seidalin — seidalins@gmail.com