Privacy Policy
Last updated: September 26, 2026
This Privacy Policy explains how Fitty Up collects, uses, stores, and shares personal information when you use the Fitty Up mobile application and related support services. By using Fitty Up, you agree to the practices described in this policy.
1. Who We Are
Fitty Up is operated by Chattrawut Phoolakorn ("Fitty Up," "we," "our," or "us"), an individual developer based in Thailand. If you have questions about this policy or your personal data, contact us at support@fittyup.app.
2. Information We Collect
2.1 Account and profile information
- Sign-in data: Your email address and basic profile details received from Apple Sign In, Google Sign In, or other authentication flows we support.
- Profile data: Information you choose to provide, such as display name, avatar, banner image, age or date of birth, sex, height, weight, activity level, goals, and preferences.
- Account settings: App language, notification preferences, theme settings, legal consent records, and similar configuration data.
2.2 Wellness, nutrition, and activity data
- Nutrition data: Meals, calories, macronutrients, custom foods, saved foods, grocery items, meal combos, fasting windows, nutrition goals, and related notes.
- Workout and body data: Workout logs, plans, exercises, sets, reps, route metrics, pace, steps, heart-rate-related workout metrics, personal records, body measurements, weight logs, and workout goals.
- Additional wellness records: Water intake, medications and medication logs, course enrollments and course progress, check-in responses, and body progress review data if you use those features.
- Health-context details: Information you choose to save about yourself, such as medical conditions, food allergies, dietary restrictions, injuries, and free-text health notes.
2.3 Media and files
- Photos and images: Meal and food photos, barcode scans, AI chat attachments, avatar images, banner images, medication photos, and body progress photos you upload or capture through the app.
- Generated or processed media: AI review outputs, nutrition analysis generated from images, and file metadata such as image size or upload path.
Photos are re-encoded before upload, which removes camera metadata such as GPS coordinates. Where the app reads image metadata at all, it reads only the orientation needed to display the photo the right way up. Images you upload are stored in access-controlled buckets and fetched through URLs signed for your session that expire, as described in section 7.1. Even so, an image you send to an AI feature is transmitted to our AI processors to be analyzed, and images can be recovered from backups for a period after you delete them, so do not upload confidential documents to features that do not need them.
2.4 AI interaction data
- AI prompts and replies: Messages you send to Fitty Up's AI features, selected model or mode, attachments you include, and the responses returned to you.
- AI usage data: Credit usage, model routing, safety filtering results, tool/action proposal metadata, and request metadata needed to operate, secure, and bill AI features.
- Queued AI job records: Job records that may include the prompt, message, attachment reference, generated result, or structured request/result payload needed for the job, plus job identifiers, status, lane, credit-hold or billing identifiers, retry, cancel, finalization, error, timing, ETA, and redacted worker-event metadata.
- Live workout coach snapshots: If you turn on the live workout coach, periodic snapshots of the activity in progress — such as elapsed time, distance, pace, speed, elevation gain, estimated calories, goal progress, language, and heart rate where a source is connected, including heart rate read from Apple Health — sent while the workout is running so the coach can generate cues.
- Health context in AI requests: Health-context details you have saved, where you have saved them, so AI responses can take them into account.
- Execution metadata: For queued AI requests, specialist agent routing decisions, tool invocation logs, streaming delivery metrics, error recovery paths, queue admission decisions, multi-round agentic loop state, and abuse-prevention signals such as prompt fingerprints and request patterns, used to improve reliability, prevent abuse, and reconcile billing.
2.5 Purchase, subscription, and support data
- Billing and entitlement data: Subscription status, product identifiers, top-up purchases, transaction identifiers, entitlement state, related records from Apple App Store and RevenueCat, and — for subscriptions purchased on fittyup.app — the associated Stripe customer id and invoice records.
- Support and feedback: Feedback tickets, subject lines, message content, reply preference, app version, device information, and admin support responses.
- Promotions and rewards: Referral, bonus credit, promo-code, rewarded-ad, refund, webhook, and anti-replay verification records where applicable.
- Invite and referral codes: Which code you entered, who it belongs to, and whether a reward was granted.
- Partner program records: If you take part in the partner program, earnings records, payout requests and their status, review notes, and any identifying or tax information needed to make a payout.
- Virtual items and minigames: Records of virtual items bought with credits and of optional in-app minigames, including their in-app economy and anti-abuse records.
- One-time reward fingerprint: A one-way, secret-salted fingerprint of your durable login identity, kept so that one-time signup and first-subscription rewards can be granted once per person. It contains no account identifier, email address, or provider name, and it cannot be reversed to identify you.
2.6 Device, diagnostics, and security data
- Device and app data: Device brand, model, operating system, app version, locale, time zone, and general network state.
- Diagnostics: Crash reports, error logs, performance diagnostics, and technical troubleshooting data, including client error reports you or the app submit with the error, app version, and device information.
- Website analytics: On selected public pages, we use Cloudflare Web Analytics to measure visits, page views and page performance without analytics cookies or individual visitor profiles. We exclude account, checkout and referral pages, and do not load the beacon when the URL contains query parameters or a fragment. Website visit counts are separate from app downloads.
- Product analytics: Where enabled, feature interactions, safety system activations, and in-app funnel events such as scan capture or widget enablement, used for product improvement and safety monitoring.
- Security and abuse-prevention data: Push token registration data, a device fingerprint derived from device characteristics, authentication events, admin/support access logs, role checks, abuse-prevention signals, and request identifiers used to reduce fraud, investigate incidents, or enforce limits.
- Device-integrity signals: On supported builds, whether the device appears to be jailbroken or modified, whether a debugger or instrumentation tool appears to be attached, whether the app binary appears altered, and whether screen recording or screen mirroring is active. These are recorded to our systems and our crash-diagnostics provider to protect accounts and detect abuse, and screen-recording state may also be used to show you an in-app warning.
2.7 Permission-based data
- Apple Health (HealthKit) on iOS: Fitty Up accesses Apple Health only after you start or enable an Apple Health feature and grant the requested permission. Access is optional and permission-based. A metric import you choose may read up to 16 categories: steps, walking/running distance, active energy, flights climbed, weight, body fat percentage, body mass index (BMI), waist circumference, resting heart rate, heart-rate variability (HRV), VO2 max, blood pressure, blood glucose, oxygen saturation, respiratory rate, and water intake. Where you separately allow writing, Fitty Up may save completed workouts (including duration, distance, active energy, a recorded GPS route, and heart-rate samples), sleep records you log, and the seven supported health values you create in Fitty Up: weight, water intake, body fat, HRV, VO2 max, blood pressure, and blood glucose. Imported and in-app records are stored locally and, while you are signed in, synced to your Fitty Up account so they can appear across devices, subject to the retention rules in section 8. If you use an AI feature that needs those records, selected imported or in-app values may be included in health context sent to the AI processors described in sections 5 and 6.1. Apple Health data is not used for advertising or tracking.
- Native iOS widget snapshots: While you use Fitty Up, the app prepares summarized nutrition, workout, wellness, reminder, or status snapshots for its native iOS widgets, including before a widget is added. These widget snapshots are stored locally on your device: the shared App Group container and, for values read by widgets, the encrypted keychain under a shared access group. Adding or removing a widget controls its visibility through iOS, not whether the app prepares these snapshots.
- Live Activity data: If an active workout is shown on your Lock Screen or in the Dynamic Island, that surface may display activity name and status, elapsed time, distance, pace, estimated calories, and heart rate where a source is connected. These updates are generated on your device rather than sent from our servers, and the activity ends when the workout does. Anyone who can see your locked screen may be able to read it.
- Location and motion: If you grant permission and the feature is enabled, Fitty Up may access location and motion activity to map outdoor workouts, calculate pace, and track route-based exercise. Starting an outdoor route-recorded workout requests foreground location first, then background access when needed. On iOS, route recording requires Precise and Always location access so it can continue while the app is in the background. If required location access is denied, the route-recorded workout cannot start. You can change or withdraw location permission at any time in iOS system settings.
- Shake and tilt gestures: Device-motion readings while the app is open are used outside workouts as well: to detect a deliberate shake that opens the in-app recovery and report sheet, and to tilt the animated food widget on the dashboard and nutrition screens so items settle with the angle of your device. These readings are evaluated on your device for those effects and are not stored or transmitted.
- Camera and photo library: If you grant permission, Fitty Up may capture or import photos for food logging, barcode scanning, avatars, and progress tracking.
- Audio session: While a workout is active and spoken coaching is enabled, Fitty Up holds an audio session so cues can be heard with the screen locked. The session is released when spoken coaching is off, and cues may be audible to people near you. Fitty Up does not record audio and does not request microphone access.
- Notifications: If you opt in, Fitty Up may schedule local reminders on your device and store remote push-token data to send announcements or account-related notifications. Reminder notifications are generated on your device and may include details you have chosen to show, such as a medication name. Medication names are hidden in notification text by default and can be shown or hidden in your reminder settings; anyone who can see your locked screen may be able to read whatever a notification displays.
3. How We Use Your Information
We use your information to operate, improve, and secure Fitty Up, including to:
- Create and maintain your account and synchronize your data across devices.
- Provide nutrition tracking, workout logging, progress history, reminders, courses, and other product features.
- Generate AI-powered analysis, coaching, summaries, and food-recognition results.
- Queue, retry, resume, cancel, finalize, and monitor asynchronous AI or background jobs, including credit holds, queue status, worker health, and result delivery.
- Prepare local native iOS widget summaries and refresh their timelines on your device.
- Process subscriptions, top-ups, promotional credits, and optional rewarded-ad credits.
- Verify purchases, refunds, referrals, rewarded-ad callbacks, and credit grants, and prevent replay or abuse of those flows.
- Run optional minigames and virtual items bought with credits, including their in-app economy and anti-abuse rules.
- Attribute invite and referral codes, calculate partner earnings, and review and settle payout requests.
- Personalize your targets, recommendations, dashboards, and in-app experience.
- Send service messages, reminders, and support replies.
- Send you offers about Fitty Up itself, including reminders about an expiring plan, a billing problem, or a discount to return after your subscription ends. These may arrive as push notifications if you have allowed notifications, and you can stop them by turning off notifications for Fitty Up in your device settings.
- Detect abuse, prevent fraud, monitor security, and enforce our Terms of Service.
- Debug crashes, investigate incidents, improve performance, and develop new features.
- Comply with legal obligations and resolve disputes.
4. Legal Bases for Processing
Where applicable data-protection law requires a legal basis, we generally process personal data under one or more of these bases: performance of our contract with you, your consent, our legitimate interests in operating and securing Fitty Up, and compliance with legal obligations.
5. How We Share Information
We do not sell your personal information. We share information only as reasonably necessary to operate Fitty Up, including with the following categories of recipients:
- Infrastructure, storage, and queue providers: Supabase (authentication, database, storage, server-side functions, durable AI queue records, and account deletion or storage cleanup jobs), Vultr (AI worker hosting), Cloudflare (CDN and TLS), Vercel (admin hosting), Expo (over-the-air updates and push notifications), and Redis/Valkey-compatible data stores used as AI queue transport to dispatch worker jobs.
- AI processors: For AI features, we send data needed for the requested feature directly to Anthropic or through OpenRouter. OpenRouter may pass a request to the serving endpoint for a selected model or embedding or image feature. Only Anthropic, OpenAI, DeepInfra, and Perplexity are permitted downstream serving operators. Chat may go to Anthropic, OpenAI, or DeepInfra; images to OpenAI; and search embeddings to Perplexity. A model's developer is not necessarily the operator of its serving endpoint. Depending on the feature and your data-access choices, the data may include prompts and relevant conversation history, attachments and photos, selected profile and goals, permitted nutrition, workout, medication, symptom, body, sleep, mood, and Apple Health-derived summaries, pseudonymous user-scoped and session-scoped identifiers that may persist across requests, request identifiers, and short report or chat extracts used for embeddings. Not every request contains every category; section 6.1 explains the separate choice in the updated app and why older versions cannot use external AI until they update.
- Payments and subscriptions: RevenueCat and Apple App Store to manage subscriptions, entitlements, one-time digital purchases, refunds, and related webhook verification. When a refund is requested, this may include sharing purchase-usage signals — such as how much of a billing period elapsed or how many included credits were used — with Apple through RevenueCat so the store can evaluate the request.
- Web payments: Stripe (Stripe, Inc.) processes payments for subscriptions purchased on fittyup.app. We share with Stripe the account email and a customer reference needed to create the checkout session, maintain the subscription, display invoices in your account page, and process refunds or disputes. Stripe stores your payment method details; Fitty Up never receives your full card number.
- Advertising partners: Google AdMob for free-tier ads, including rewarded-ad verification and nonce ownership checks. On iOS, Fitty Up may request App Tracking Transparency permission for the advertising identifier (IDFA), and AdMob measurement is delayed until runtime ATT handling. Ad requests are non-personalized while tracking is denied or consent is outstanding; where you have allowed tracking and, if a consent form applies in your region, given consent through Google's consent framework, requests may be personalized. On iOS, Fitty Up also declares Apple SKAdNetwork identifiers for Google's ad network and for additional ad networks that may serve ads through Google's mediation, so Apple may report privacy-preserving, aggregated install or conversion signals to those networks; this does not share your account, health, or nutrition data. Fitty Up may also show first-party Pro upgrade or house ads inside the app; those are not served by Google AdMob.
- Social sharing, at your request: If you choose to post a workout Moment to an Instagram or Facebook Story, the image you composed — which may include a route map, workout statistics, and a photo you selected — is handed to that app on your device and is then governed by that app's own terms and privacy policy. To offer those options, the app checks whether Instagram or Facebook is installed; the result of that check is used only on your device.
- The person whose invite or referral code you used: If you sign up with someone's code and later subscribe, that person's referral dashboard shows them that a referral converted, on what date, which plan it was, and what reward it earned them, identified by an internal account identifier. They do not receive your name, email address, sign-in identity, or any of your health, nutrition, workout, or AI data. If you did not enter a code, nothing about you is shown to anyone else.
- Diagnostics and support tools: Sentry for crash monitoring, error tracking, and stability improvements. Sentry receives crash reports, error logs, navigation breadcrumbs, user interaction events, component stack traces, and sanitized error context, with personal information redacted, to help us diagnose and fix issues.
- Notification delivery providers: Expo, Apple, and Google services to register and deliver push notifications.
- Legal or transactional disclosures: Authorities, advisors, counterparties, or successors where disclosure is required by law, necessary to protect rights or safety, or related to a merger, transfer, or restructuring.
6. AI and Advertising Disclosures
6.1 AI features
AI features in Fitty Up require us to send relevant prompts, attachments, and selected model settings to third-party AI processors. Those providers may process data in other countries and may retain limited request logs or safety-monitoring data under their own policies. Fitty Up does not use AI output as a substitute for professional medical, nutritional, or fitness advice.
In the updated app, before your first external AI action, we will ask for a separate, affirmative choice to share the data described in section 5 with these processors for AI replies, food or image analysis, coaching, and search embeddings. Accepting the Terms or this Privacy Policy, granting Apple Health access, or enabling an AI data-access switch does not itself grant this external-AI permission. If you decline, the updated app will not send that AI request or charge AI credits for it; non-AI tracking remains available. You can withdraw permission in Settings > AI Settings. Withdrawal stops new and not-yet-dispatched external AI work, including background embeddings, but cannot recall requests already processed or immediately erase copies retained under the limits below.
For this rollout, including while the updated app is in App Review, the server blocks external AI requests from older installed app versions until they update. Non-AI tracking remains available on those versions. The updated app asks for separate, affirmative consent before any external AI request.
For the updated consent flow, we require AI processors to provide the same or equivalent protection for your data as described in this policy before we enable a route: use limited to the requested feature and necessary safety, security, or legal purposes, restricted access, appropriate safeguards, and defined retention limits. We assess the applicable published API terms and endpoint data policies for direct and downstream model or embeddings operators. For direct Anthropic API use, Anthropic's published Commercial Terms treat customer content as confidential and prohibit model training; OpenRouter's published Terms make us responsible for reviewing each model's terms. For supported OpenRouter chat and embeddings requests, we will set provider.data_collection to deny to exclude endpoints OpenRouter identifies as collecting user data. Its dedicated image API does not support that per-request field, so we assess image operators' terms and any independently verified account-level controls separately. If comparable protection cannot be established for a route, we will not make it available for user data in the updated flow. This filter does not establish zero retention for any request.
Each external AI model is pinned to its named serving operator; unreviewed routes are blocked before data is sent. DeepInfra chat and Perplexity embeddings additionally require zero-data-retention routing. The OpenRouter image endpoint is limited to OpenAI.
Provider retention is separate from Fitty Up's own schedules in section 8. Anthropic's published standard API policy says inputs and outputs are normally deleted within 30 days, except where longer retention is needed for usage-policy enforcement, legal compliance, or a different agreement. OpenRouter's published default is to log basic request metadata but not prompts or completions; account settings and processing features can change that, and downstream providers' safety or legal retention may still apply. We do not promise that a withdrawal deletes data already sent to a provider.
Some AI requests may be admitted to a queue and processed asynchronously. Supabase stores durable request and result payloads, status, and related metadata so the app can resume progress, show status, retry, cancel, finalize credits, and deliver results. The worker transport is designed to carry job identity and bounded metadata rather than full prompts where possible; the provider execution path loads private payloads from Supabase only after authorized worker dispatch.
If you have saved health-context details such as medical conditions, allergies, or dietary restrictions, they may be included as context in AI requests so responses can take them into account, which means they are sent to our AI processors. The assistant may also propose adding to or changing those saved details; nothing is saved until you review and confirm the exact text shown to you.
So that your saved AI reports and past conversations can be searched by meaning rather than by exact words, Fitty Up may send short extracts of them to an embeddings model through OpenRouter — for a report, its title, the period it covers, its summary and its first few findings and recommendations; for a conversation, its title, its preview line and its stored summary — and keep the numeric representation that comes back alongside your own data. Those extracts are sent to produce that representation, not to generate a reply, and the resulting index is scoped to your account.
If you turn on the live workout coach, Fitty Up sends periodic snapshots of the workout in progress to our AI processors while the activity is running, and may read the reply aloud using your device's text-to-speech voice. The coach is off unless you enable it, you choose how often it may speak, and there is a limit on how many cues one session can generate.
6.2 Ads for free-tier users
Free-tier users may see Google AdMob banner ads, optional rewarded video ads, and full-screen ads shown at natural breaks or when returning to the app. Fitty Up may also show first-party Pro upgrade or house ads inside the app.
On iOS, if ATT permission is requested, you can allow or deny tracking in system settings; denying ATT does not block core app use. In regions where consent is required, Google's consent form may be shown before ads are loaded, and your choices are recorded by Google's consent framework. Where that form applies, an ad privacy options entry appears in Settings so you can review, change, or withdraw those choices at any time. Ad requests stay non-personalized while tracking is denied or consent is outstanding.
Rewarded ads may require server-side verification before bonus credits are added. Paid subscribers do not receive ads through the standard paid tier experience.
7. Data Storage and Security
We use reasonable technical and organizational safeguards designed to protect personal data, including encrypted transport, access controls, role-based administrative controls, secure authentication flows, and platform-specific secure or encrypted local storage for selected sensitive app data on supported devices. This may include authentication tokens, AI chat history, insight report history, signed media URL cache entries, push-token cache entries, and other sensitive local records.
Queued job records and worker status data are stored in Supabase and/or private worker transport systems with access controls. Operational logs and queue events are designed to be redacted or bounded so they can support reliability, billing reconciliation, abuse prevention, and debugging without exposing unnecessary prompt or provider payload detail.
Native iOS widget snapshots are stored locally in the app's shared App Group container and encrypted keychain access group so WidgetKit can display summaries while the main app is closed. They are prepared while you use Fitty Up, even if you have not added a widget. Settings > Advanced > iOS Widgets is a preview gallery with no per-widget privacy switches. Anyone who can see a widget on your Home Screen or Lock Screen may see its summary. Removing a widget stops its display but does not itself erase stored snapshots; iOS may retain a displayed summary until it refreshes or removes that surface. A workout Live Activity on the Lock Screen or Dynamic Island is separate and can be turned off in iOS Settings.
A small number of administrative accounts can read user records, including the text of AI conversations and the metadata of the requests behind them, where that is necessary to answer a support request, resolve a billing dispute, investigate abuse, or respond to a security incident. That access is restricted by role, is recorded in an audit log, and is not used for advertising, model training, or any unrelated purpose.
No system is perfectly secure. You are responsible for keeping your device, email account, and third-party sign-in credentials secure.
7.1 Storage bucket access controls
Storage is separated by what the files are:
- Your uploads are private. Avatars, body progress photos, AI chat attachments, meal and food images, and medication photos each live in an access-controlled bucket whose read rules allow only your own account, and the app reads them through URLs signed for your session that expire. Some of those signed URLs are cached briefly on your device so screens do not have to re-request them.
- App content is public, because it is the same for everyone and contains nothing about you: announcement images and theme artwork are served from public URLs. Listing the contents of those locations is not permitted, but an individual file can be fetched by anyone who has its exact URL.
Server-side jobs that maintain your data — cleanup, account deletion, AI processing — read your files through privileged credentials that are not available to the app or to other users.
8. Data Retention
- We keep personal data for as long as needed to provide Fitty Up, maintain account history, operate subscriptions and credits, resolve disputes, and comply with legal obligations.
- On the free tier and the lower paid tiers, some historical records — daily nutrition logs, workouts, medication logs, and body measurements — are subject to automatic cleanup after approximately 90 days. Higher tiers retain more history while the account remains active. Which tiers a cleanup covers can change as plans change, so treat 90 days as the shortest window rather than a promise about your specific plan.
- AI conversations are not kept indefinitely. A conversation you have not added to for approximately 30 days may be deleted along with its messages and image attachments, on every tier. There is currently no in-app export for AI conversations, so copy anything you want to keep out of the app before it ages out.
- Separately, on the free tier and the lower paid tiers, AI chat image attachments may be removed after approximately 14 days even while the conversation is still active. Both cleanups run as scheduled jobs and route file deletion through a queue, so removal can lag the cutoff.
- Queued AI job records, credit holds, queue events, ETA or statistical aggregates, worker validation evidence, and redacted logs may be retained as long as needed to deliver results, reconcile billing or credits, retry or cancel jobs, investigate abuse or security issues, and operate reliability metrics, then minimized or deleted according to cleanup processes.
- Data already sent to external AI processors remains subject to their applicable retention limits and safety or legal exceptions. Section 6.1 describes the published Anthropic API timeframe and OpenRouter's logging; withdrawing AI permission stops future sharing but cannot retract completed provider processing.
- AI queue execution logs, dynamic tool registry records, streaming event logs, and operational metadata are deleted according to internal schedules, typically 30 to 180 days. Client error reports and product analytics events are retained for approximately 180 days. User feedback and support tickets are retained for customer service purposes and may be kept longer to track recurring issues.
- Financial and administrative records are kept far longer than product data, because tax, accounting, chargeback, and dispute rules require it. Your credit and purchase ledger — the record of credits bought, granted, spent, held, refunded, or reversed — and our administrative audit log of privileged actions are retained for approximately 7 years. Those records are financial and security evidence and are not deleted when older product history is cleaned up.
- When you delete your account, we delete or de-link most account data and storage objects tied directly to your account, subject to technical limitations and legal requirements.
- We may retain limited financial, referral, anti-fraud, tax, or audit records after account deletion where reasonably necessary or legally required, and those records may be minimized or de-identified.
- We may retain limited webhook, rewarded-ad verification, security audit, and abuse-prevention records to prevent replay, fraud, or unauthorized access, even after related app content is deleted.
- Data exported or cached on your own device remains under your control until you delete it.
9. Your Rights and Choices
- Access and correction: You can review and update much of your profile and app data inside Fitty Up.
- Delete account: You can request deletion through the in-app Settings > Advanced > Delete Account flow, subject to limited record retention described above.
- Export: Fitty Up includes in-app export tools for certain categories of data, but AI conversations are not among them. You may contact us if you need additional help accessing your information.
- Permissions: You can disable camera, photo, HealthKit where available, location, motion, and notification permissions through your device settings at any time. Apple Health read and write access is managed in the Health app's own privacy settings.
- External AI: The updated app asks for a separate opt-in before external AI use. You can decline it or withdraw it later in Settings > AI Settings while continuing to use non-AI tracking. The individual AI data-access switches control which saved records may be used; they do not replace the external-AI choice. Section 6.1 explains that the server blocks external AI on older app versions until they update.
- Ads and tracking: On iOS you can allow or deny tracking in system settings. Where Google's consent form applies in your region, an ad privacy options entry appears in Settings so you can review, change, or withdraw those consent choices.
- Offers and reminders: Offers about Fitty Up, such as a discount to return after your subscription ends, are sent as push notifications where you have allowed them. There is no separate in-app switch for them: you can stop all Fitty Up notifications by turning them off for the app in your device settings, and you can contact us at support@fittyup.app if you want to be excluded from promotional messages while keeping service notifications.
- Regional rights: Depending on where you live, you may have additional rights such as data portability, restriction, objection, or complaint rights under local law.
To exercise privacy rights that are not available directly in the app, email support@fittyup.app.
10. International Transfers
Fitty Up and its processors may handle data in countries outside your own. When required, we rely on contractual, technical, and organizational safeguards designed to protect transferred data.
11. Children's Privacy
Fitty Up is not intended for children under 13. Users between 13 and the age of legal majority in their jurisdiction should use Fitty Up only with parent or guardian permission. Some sensitive features, such as certain body-progress or image-based features, may be restricted for younger users. If you believe a child under 13 has provided us with personal data, contact us so we can investigate and delete the information where appropriate.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect product, legal, or operational changes. If changes are material, we may provide notice inside the app or require renewed acceptance. The updated version becomes effective when posted with a new "Last updated" date.
13. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our handling of personal data, contact:
Email: support@fittyup.app
Operator: Chattrawut Phoolakorn