Privacy Policy
Your data, your rules.
We believe privacy is a fundamental right, not a feature. Here's exactly how we collect, use, and protect your information.
Last updated: April 30, 2026
Information We Collect
- Account Information — When you sign up, we collect your name, email address, and password (securely hashed). You may optionally provide a profile photo, age, height, and weight to personalise your experience.
- Fitness & Health Data — Workout logs, nutrition entries, body metrics, and performance analytics that you input or sync from connected devices.
- Usage Data — Anonymised interaction patterns such as pages visited, features used, session duration, and device/browser type, collected automatically through cookies and similar technologies.
- Payment Information — If you subscribe to a paid plan, payment processing is handled by our third-party payment provider. We never store your full card details on our servers.
How We Use Your Data
- Delivering and improving the core fitness tracking experience, including personalised workout recommendations and progress analytics.
- Sending transactional emails (account verification, password resets, subscription confirmations) and, with your consent, occasional product updates.
- Aggregating anonymised data to identify trends and improve platform performance — individual users are never identifiable in aggregate datasets.
- Complying with legal obligations and protecting against fraudulent or unauthorised activity.
Data Protection & Security
- All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 across all storage layers.
- We conduct regular penetration testing and security audits with independent third-party firms.
- Access to user data is restricted to authorised personnel through role-based access controls with multi-factor authentication.
- We maintain a comprehensive incident response plan and will notify affected users within 72 hours in the event of a data breach, in compliance with GDPR requirements.
Your Rights & Controls
- Access & Portability — You can export all your data at any time from your account settings in a machine-readable format (JSON/CSV).
- Rectification — Update or correct any personal information directly from your profile dashboard.
- Erasure — Request complete deletion of your account and all associated data. We process deletion requests within 30 days.
- Opt-Out — Manage your communication preferences and withdraw consent for non-essential data processing at any time.
Cookies & Third Parties
- We use essential cookies to maintain your session and preferences. Analytics cookies (opt-in only) help us understand how the platform is used.
- We do not sell your personal data to third parties. Data is shared only with service providers who are contractually bound to protect it.
- Third-party integrations (e.g., wearable device syncs) process data according to their own privacy policies, which we encourage you to review.
Data Retention
- Active account data is retained for the duration of your account. Upon deletion, personal data is purged within 30 days, with anonymised analytics retained for up to 12 months.
- Backup copies are automatically purged within 90 days of account deletion.
- We may retain minimal data as required by law (e.g., transaction records for tax compliance).
Questions?
If you have any questions or concerns about our privacy practices, or if you'd like to exercise any of your data rights, reach out to us at:
privacy@relentless.fit