← FitJournal

Privacy Policy

Last updated 28 August 2026 · Effective 28 August 2026

This policy explains what FitJournal (iOS and Android) does with your data. It is written against what the app actually does, not against a template.

The app is published by Sultan Seidalin, an individual developer, who is the data controller. Contact: seidalins@gmail.com.

The short version

What we collect

Account

DataWhere it comes fromWhy
Firebase user IDCreated when you first sign inThe identifier that ties your data together
Email addressGoogle or Apple (an Apple private-relay address is fine)Identifying your account, support
Display nameYour provider, if supplied. Otherwise a default is used — we never ask you for itShowing your name in the app
Profile picture URLYour provider, if supplied. Stored as a link only; we never copy the imageShowing your avatar
Platform (iOS / Android), training goal, unit preferencesYou / your deviceRunning the app the way you set it up

We do not collect your date of birth, gender, address, phone number, or payment details. We never see your card. Purchases happen inside Apple's and Google's systems.

Training data (your content)

Everything you log, which is the point of the app:

Body measurements and progress photos are health-related data. Under EU law that is a special category, which is why we process it only on the basis of your explicit consent — given by choosing to enter it — and why you can delete any of it at any time.

Diagnostics and usage

What we do not collect

Stated plainly, because it is unusual enough to be worth saying:

Apple Health (iOS only)

If you allow it, FitJournal reads your step count and nothing else, to display it on the home screen. Access is read-only — the app never writes to Health. This data never leaves your device: it is not sent to our servers, our analytics, or any third party. Revoke it any time in iOS Settings → Privacy & Security → Health.

Photos

Two separate things, which behave differently:

Progress photos are deleted when you delete the photo itself, when you delete the journal it belongs to, and when you delete your account. Deleting a single body-measurement entry deliberately leaves its photos alone — they stay browsable in the photo gallery, and are yours to remove when you want to.

Reporting a problem

If you use the “report a problem” form in Settings, the app sends your message together with the email address you type in, your user ID, your platform and your app version to a private support channel we run on Telegram. Only send what you are comfortable sharing there — the message goes to Telegram's servers, not to our own, and Telegram's privacy policy applies to it. If you would rather not use Telegram, email us directly at seidalins@gmail.com instead.

The AI suggestion feature

The app can show an optional suggestion for your next set. When it does, it sends to Google's Gemini API, through the Firebase AI Logic SDK: the exercise name, the sets from your previous session of that exercise, and the sets you have logged today. That is all. It does not send your name, email, user ID, notes, body measurements, or photos. The response is shown on screen and is not stored anywhere.

This feature is disabled by default and only runs if we switch it on remotely. Google's handling of the request is governed by the Firebase privacy documentation.

Who else receives data

These are our processors. We do not sell data to anyone, and none of these are advertising networks.

WhoWhat they getWhat for
Amazon Web ServicesYour account record, training data, and progress photosHosting and sync (EU, Stockholm)
Google / FirebaseSign-in identity, crash reports, analytics events, performance data, push token, AI promptsAuthentication, diagnostics, notifications, AI suggestions
Apple / Google PlayPurchase and subscription recordsSelling and billing subscriptions
QonversionYour user ID and purchase receiptsChecking whether your subscription is active
RevenueCatYour user ID and purchase receiptsSubscription analytics
SuperwallYour user ID and paywall interactionsShowing and testing the paywall
TelegramOnly what you submit through “report a problem”: your message, the email you enter, your user ID, platform and app versionDelivering support reports to us

Where your data is stored, and transfers

Your training data and photos are stored in AWS in Stockholm, Sweden (eu-north-1) — inside the EU/EEA. Firebase and the subscription vendors are US-based companies and may process data in the United States or elsewhere; those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Legal bases (EU/EEA and UK users)

How long we keep it

We keep your data while your account exists. When you or the app delete something, it is marked deleted and stops appearing anywhere in the app on any of your devices.

Being straight with you: when you delete an individual item, most rows are tombstoned rather than erased in our database. That design lets sync work correctly across devices and lets us recover from a bad delete, but it means a deleted workout can persist in backend storage after it disappears from your app. Deleting an individual note, body measurement or photo erases it outright, and so does deleting your whole account. If you want everything about you erased rather than tombstoned, email us and we will do it manually.

Crash and analytics data is retained under Firebase's own retention periods (analytics events for up to 14 months by default; crash reports for up to 90 days).

Deleting your account

Settings → delete account, in the app. It deletes, on our servers and on the device:

The app waits for those deletions to be confirmed by the server before signing you out, and only then clears the local database.

One caveat, worth stating. If you delete your account while offline, the deletion completes on your device but we cannot reach the server to carry it out, and you are signed out before we get another chance. If that happens, email us with the address you signed in with and we will finish it by hand. Deleting while connected needs no follow-up.

Deleting your account does not cancel a subscription — cancel that in your Apple ID or Google Play settings.

Your rights

If you are in the EU/EEA or the UK you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. Similar rights apply in many other places, including under California law.

Deletion is built into the app. There is no self-service export yet, so for a copy of your data, or for anything else on this list, email seidalins@gmail.com and we will answer within 30 days. It is one person answering, so please be patient if it takes a few days.

You can also complain to your national data protection authority. If you are in the EU, that is the supervisory authority where you live or work.

Security

Data travels over encrypted connections (HTTPS/TLS) and is stored on managed AWS and Google infrastructure. Sign-in is handled by Firebase Authentication, so we never see or store a password.

The local database on your device is not separately encrypted beyond the encryption your phone already applies, and on iOS it may be included in your iCloud device backup. On Android, app data is excluded from Google backups.

No system is perfectly secure, and we will not pretend otherwise. If you discover a security problem in FitJournal, please report it to seidalins@gmail.com before disclosing it publicly, and we will fix it as fast as we can.

Children

FitJournal is not for children under 13, and we do not knowingly collect their data. If you believe a child under 13 has an account, email us and we will delete it. Where the age of digital consent is higher than 13 (16 in parts of the EU), users below it need a parent's or guardian's consent.

Changes

We will update this policy when the app changes. The date at the top always shows the current version, and material changes will be announced in the app before they take effect.

Contact

Sultan Seidalin — seidalins@gmail.com