What we collect, why, and what we never keep
Last updated 12 September 2026
This policy explains what Get Fit with me collects about you, what it does with it, who else sees it, how long it is kept, and the choices you have. It applies to the web, iOS and Android apps and to the website, and it is written under India's Digital Personal Data Protection Act, 2023 and the EU and UK GDPR.
Who we are
Get Fit with me is operated by [Company legal name], [Registered address]. We are the data fiduciary under the DPDP Act and the data controller under the GDPR for the personal data described here. Questions and requests go to privacy@getfitwithme.app. Our grievance officer is [Grievance officer name] ([Grievance officer email and postal address]). EU representative: [EU representative, if appointed].
The short version
- Every instructor in the app is AI. A single photo goes to the AI for a pose check only when you ask for one, and it is never stored.
- Health conditions are collected only with your explicit consent and used only to keep unsafe poses out of your plan.
- We never see your card number; payments are handled by Stripe, Razorpay, Apple and Google.
- We do not sell your data and we do not use advertising trackers.
- You can export or delete everything, and withdraw any consent, from Settings → Privacy & data.
What we collect
We collect only what the service needs to work. Each item below says whether it is required, or optional and switched on by you.
- Account data (required): email address, display name, country and timezone, sign-in events, and the versions of the terms and policies you accepted.
- Practice profile (required for a plan): goals, experience, preferred session length and times, the instructor and studio environment you picked, and your body-focus areas.
- Health conditions and notes (optional, explicit consent): conditions you choose to tell us, such as a back injury, pregnancy or high blood pressure, plus a free-text note. This is special category / sensitive personal data. It is used only to remove clashing poses from your plan and to show you the relevant safety reminders; notes are encrypted at the application level and are never shown to other members.
- Session data (required): which poses you did, for how long, which ones you skipped, and the pose-check scores and spoken cues from your AI instructor.
- Camera frames for AI pose review (only when you ask): when you say "check my pose", press the button, or allow the automatic mid-hold check, one downscaled photo from your camera is sent to our server and forwarded to our AI provider for that single review. The photo is not written to any database, storage or log and is discarded as soon as the review is returned; only the score and the cues are kept. The camera preview itself never leaves your device, and no video is ever streamed.
- Voice transcripts (optional, consent): what you said to your instructor and what we understood. Audio is transcribed and the recording is discarded. Turn off "Keep voice logs" and transcripts are not stored at all.
- Progress photos and reels (optional, explicit consent): private by default, encrypted at rest, viewable only by you through short-lived links; no member of staff can open them.
- Payment data: a payment token, card brand and last four digits, invoices and subscription status. Full card and UPI details go directly to the payment processor and never reach us. For App Store and Google Play purchases we receive only a receipt and subscription status.
- Community content: posts, comments, group membership, reports and blocks.
- Shop activity: which affiliate links you clicked, from which placement and in which region; orders for products we sell ourselves.
- Device and usage data: app version, platform, coarse device type, screen sizes, crash reports, feature usage and performance timings, tied to your account, so we can fix what breaks and see which features are used.
- Notification preferences and delivery logs: what you turned on, and whether each message was delivered or opened.
- Support correspondence: emails and bug reports you send us.
What we do not collect
- Your full card number, CVV or bank credentials.
- Video from your camera, or any photo you did not deliberately trigger or upload.
- Audio recordings: speech is transcribed, then the audio is gone.
- Precise location. We use only the country and timezone you give us.
- Data from anyone under 18. The service is for adults only.
- Data from advertising networks, and we do not build advertising profiles or sell data to anyone.
Why we use it, and on what legal basis
Under the GDPR every use needs a lawful basis; under the DPDP Act we process personal data either for the purpose you consented to or for a legitimate use recognised by the Act. In plain terms:
- To provide the service you signed up for (contract; DPDP: the purpose you consented to when you created the account): create and secure your account, build and adapt your plan, run sessions, keep your history, take payment and unlock what you have paid for, run the community and the shop, and send service messages such as sign-in links, receipts and reminders you have turned on.
- With your explicit consent (consent, which you can withdraw at any time): health conditions and notes, voice transcripts, progress photos and reels, marketing email, and analytics cookies on the website.
- For our legitimate interests, balanced against yours (legitimate interests; DPDP: legitimate uses): keeping the service secure and preventing fraud and abuse, understanding how features are used in aggregate so we can improve them, and defending legal claims.
- To meet legal obligations (legal obligation): tax and accounting records, responding to lawful requests from authorities, and honouring your rights requests.
- We do not use your personal data to train AI models, and we do not make decisions with legal or similarly significant effects on you solely by automated means. Plan adaptation and pose filtering are automated, but they act only on what you told us and you can change or override them at any time.
AI processing
Get Fit with me uses artificial intelligence throughout, and the AI Disclosure explains it in full. For your data, this is what happens:
- Pose review: the single photo you trigger is sent, together with the pose's reference photo and notes, to Anthropic's Claude vision model, which returns a score and one or two cues. Anthropic processes it as our processor under a contract that does not permit training on it. When no AI key is configured the review is simulated locally on our server and no photo leaves it.
- Spoken guidance and conversation: what you say and what the instructor replies are generated by a language model (Anthropic Claude) from the current pose, your plan and your recent commands. Health notes are summarised into safety instructions for the model; the model never receives your name, email or contact details.
- Speech to text: your voice commands are transcribed either on your device or by a speech provider (Deepgram when configured); only the transcript is retained, and only with your consent.
- Community moderation: reports and new posts may be screened by an AI model for the rules in the Terms of Use, with a human reviewing anything it flags before an account is muted or banned.
- Instructor personas, voices and videos are synthetic and licensed; they are not real people and no real person's likeness is used without a licence.
How long we keep it
We keep personal data only as long as it is needed for the purpose it was collected for, then delete or anonymise it. The schedule:
- Account and practice profile: until you delete your account.
- Health conditions and notes: until you remove them or delete your account; withdrawn consent removes them within 24 hours.
- Session records, scores and cues: until you delete them or your account (you can clear history in Settings).
- Camera frames for pose review: not stored; discarded within seconds of the review.
- Voice transcripts: 90 days, or not stored at all if you turn off voice logs.
- Progress photos and reels: until you delete them; auto-deleted 24 months after your last upload, with 30 days' notice.
- Payment tokens and subscription status: while the subscription is active plus 90 days; invoices for the period tax law requires (currently 8 years in India).
- Payment webhook payloads: 90 days.
- Notification delivery logs: 180 days.
- Community content: until you delete it or your account; reports and moderation records for 12 months.
- Server and security logs: 30 days.
- Deleted accounts: soft-deleted for 30 days so you can change your mind, then purged, with backups rolling off within a further 30 days.
Who we share it with
We do not sell personal data. We share it only with service providers who process it for us under written contracts, with your consent, or when the law requires. Our processors, by purpose:
- Payments: Stripe and Razorpay (web), Apple App Store and Google Play with RevenueCat for receipt validation (mobile in-app purchases), Shopify (our own products).
- Email and notifications: Resend for email; Apple Push Notification service and Google Firebase Cloud Messaging for push, which receive a device token and the message text, never your health data.
- AI: Anthropic (pose review, spoken guidance, moderation), Deepgram (speech to text, when configured).
- Hosting, storage and delivery: our cloud hosting provider, an S3-compatible object store for photos and media, and a content delivery network for static files.
- Analytics and crash reporting: a privacy-focused analytics service that receives event names and coarse device data, never health data, transcripts or photos.
- Affiliate partners receive only the fact that a link was clicked, never who you are.
- Authorities and courts: only where we are legally required to, after checking the request is valid, and we log every such disclosure.
- A successor business: if we merge, are acquired or sell the service, your data passes to the successor under this policy and we will tell you before it happens.
International transfers
Your data is stored in India and in the European Union. Some processors listed above operate elsewhere, including the United States. Where personal data leaves the EU or UK we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. Where data leaves India we transfer only to countries that the Central Government has not restricted under section 16 of the DPDP Act, and under the same contractual safeguards.
Your rights and how to use them
You can do all of the following from Settings → Privacy & data, or by emailing privacy@getfitwithme.app. We answer within 30 days, or sooner where the law requires, and we may ask you to confirm your identity first.
- Access and export: "Export my data" gives you everything we hold about you as a JSON file, immediately.
- Correction: edit your profile and conditions in the app, or ask us.
- Deletion: "Delete account" removes everything, with a 30-day grace period. You can also delete individual photos, transcripts, posts and session history.
- Withdraw consent: every optional item (health conditions, voice logs, progress photos, marketing) is a separate toggle. Withdrawing is as easy as giving consent, and it does not affect what was done lawfully before.
- Object or restrict (GDPR): you can object to processing based on legitimate interests, and ask us to restrict processing while a dispute is resolved.
- Portability (GDPR): the export is in a machine-readable format you can take elsewhere.
- Nominate (DPDP): you can name a person who may exercise these rights on your behalf if you die or become incapacitated; email us to record a nominee.
- Complain: to our grievance officer first, and if you are not satisfied, to the Data Protection Board of India, or in the EU/UK to your local supervisory authority.
India: Digital Personal Data Protection Act, 2023
[Company legal name] is a data fiduciary under the DPDP Act. Before or when we collect personal data we give you this notice, in English and (on request) in any language listed in the Eighth Schedule to the Constitution, describing the data, the purpose and how to exercise your rights. Optional processing happens only on your free, specific, informed and unambiguous consent, given by a clear affirmative action in the app, and withdrawable just as easily.
Our grievance officer, [Grievance officer name] ([Grievance officer email and postal address]), acknowledges complaints within 24 hours and resolves them within 15 days. If you are not satisfied you may approach the Data Protection Board of India. We do not knowingly process the personal data of children and do not track or target advertising at anyone.
EU and UK: GDPR
For people in the European Economic Area and the United Kingdom, [Company legal name] is the controller and the lawful bases are those set out above. Health data is processed under Article 9(2)(a), your explicit consent. Our EU representative under Article 27 is [EU representative, if appointed]. You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or where an alleged infringement took place.
Children
Get Fit with me is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, email privacy@getfitwithme.app and we will delete it and its data.
Security
Everything is encrypted in transit and at rest. Health notes are encrypted at the application level with keys that staff cannot use; photos are held in a private store and served through owner-bound links that expire within minutes. Sign-in is passwordless with short-lived tokens that can be revoked from every device at once. Access by staff is role-based and audit-logged, and any staff view of health data is recorded. We review our processors and dependencies regularly. If a breach affects you we will tell you and, where required, the authorities, without undue delay.
Cookies and local storage
The website uses only essential cookies: one flag that remembers you are signed in so the home page can send you to Today. The apps keep your sign-in tokens in your browser's local storage or, on mobile, in the device keychain. Analytics on the website runs only after you consent, and there are no advertising cookies anywhere in Get Fit with me. Affiliate retailers may set cookies on their own sites after you click out; none are set inside the app.
Notifications and marketing
Practice reminders, streak nudges and account emails (sign-in links, receipts, security notices) are part of the service. You can tune or switch off every reminder category in Settings → Notifications. Marketing email is off unless you turn it on, every message has an unsubscribe link, and we never send marketing by push or SMS. Notifications never contain the name of a health condition.
Changes to this policy
We will tell you in the app and by email at least 14 days before a material change to this policy takes effect, and we will ask for fresh consent where a change would use your data for a new purpose. The date at the top tells you when it last changed.
Contact and grievance officer
Privacy questions and rights requests: privacy@getfitwithme.app. Grievance officer: [Grievance officer name], [Grievance officer email and postal address]. Post: [Company legal name], [Registered address]. EU representative: [EU representative, if appointed].