Skip to main content
FITBOUNDONLINE
How it worksFeaturesRoadmapAboutAccount
Get FitBound
YOUR DATA

Privacy Policy

Last updated: September 16, 2026

Development draftThis development draft must be reviewed by qualified privacy counsel and updated with the actual production processors, retention periods, business address, state-law applicability analysis, and deployed feature behavior before it is treated as final. Revised September 16, 2026 from the August 26, 2026 draft after a systematic verification pass against the app's actual, live behavior and production database.

This Policy explains how Sacro Media LLC (“FitBound,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in FitBound Online and related websites and services.

The initial beta is intended only for adults age 18 or older. FitBound is not offered to children, and we do not knowingly collect a child’s personal information.

1. Information we collect

Account and profile. Email address, authentication provider identifier, display name, username, birth date, age-gate acceptance, locale, region, time zone, avatar reference, and account timestamps; versions and timestamps for accepted Terms, EULA, Privacy Policy, health disclaimer, and AI disclosure; preferences such as units, goals, experience level, workout schedule, training split, exercise variability, and cardio choices.

Fitness and health-related information. Workout sessions, exercises, sets, repetitions, weight, duration, distance, rest, incline, resistance, notes, effort ratings, training location profile, and optional pain-check responses; body measurements and progress records you choose to enter; optional device health data, such as steps, workouts, active energy, heart rate, sleep, weight, and height, only after the relevant system permission; verification status, confidence signals, fraud-prevention events, and the rewardable portion of activity.

Nutrition. Food and meal names, serving information, calories, protein, carbohydrates, fat, fiber, sugar, sodium, water, meal time/type, recipes, notes, entry method, confirmation status, and AI confidence; barcode or nutrition-label information when those features are used.

Meal photos. If you choose photo analysis, the image is processed under a strict transient flow: the app captures or selects the image with your permission; the image is sent, encrypted in transit, to the processor named in Section 5; the processor uses it only to return an estimate; the remote image is deleted immediately after processing; FitBound’s backend does not store photo bytes or a remote photo URL; a local copy remains only if you choose to keep it on your device.

We store the resulting text/nutrient estimate, confirmation, and technical metadata needed for the entry. We also compute and store a short numeric fingerprint of the photo itself (a perceptual hash — a string of numbers derived from the image’s visual pattern, not the image), so that scanning the same meal again can reuse a prior estimate instead of sending a fresh image for analysis every time. This fingerprint cannot be used to reconstruct or view the photo. We keep up to 200 of these per account, automatically discarding the oldest once that limit is reached; there is currently no separate time-based expiration for this specific data. The first time you use photo or label scanning, FitBound shows a one-time notice confirming your photo is analyzed by an AI service, that the image itself is not kept, and that a fingerprint of it is stored to speed up repeat scans of the same meal.

Optional location. FitBound has two independent, optional uses of location, and they behave differently:

  • Training-location profile (no GPS). You may label a saved training location as Home, Gym, Outdoor, or Other purely to tell FitBound what equipment is available there for exercise recommendations. This profile is a name and an equipment list only — it never involves your device’s GPS and no coordinates are collected or stored for it, regardless of which label you choose. FitBound never asks for or stores your residential street address.
  • Gym verification (precise, while-in-use GPS). If you save a real gym (your own entry or one drawn from public map data) and use a feature that checks your presence there — starting a workout at that gym, a gym-boss encounter, or a gym-control/leaderboard action — FitBound reads your device’s precise while-in-use location at that moment and compares it to the gym’s known coordinates. We record a verification event containing the reported coordinates, the calculated distance to the gym, a pass/fail result, and a mock-location flag. This is precise geolocation, not approximate or rounded, for the moment of that specific check — we do not treat it as “coarse” and do not want to understate it.
  • Background location is never collected — FitBound only reads location while you are actively using the app for one of the actions above, and no background-location permission is requested on either platform.
  • Map display. When you open a map screen, your device loads map imagery directly from our map-tile provider (named in Section 5) so it can draw the map you see, including pins near your current position. That provider receives your device’s IP address and the map area being viewed as an ordinary part of loading those tiles — this is standard for how digital maps are drawn and is not routed through FitBound’s own servers.
  • Location is never used for advertising, and a verification event is never linked to anything other than confirming presence at a gym you chose to interact with.

Device, security, and diagnostics. App version, operating system, device class, language, crash diagnostics, network state, session identifiers, security events, and limited logs; IP address, specifically when you redeem a referral code, used only to detect obviously clustered/abusive redemption patterns (for example, many different codes or many redemptions of the same code from one address in a short window) — this is a soft, human-reviewed signal that never automatically blocks a redemption, and is not linked to any other feature; purchase product, store, transaction reference, entitlement state, and renewal/expiration status. Apple or Google processes payment credentials.

Game and social information. Character stats, verified progression, quests, achievements, currencies, inventory, loadout, consumable effects, battles, and anti-cheat signals; friends and social interactions if those features are enabled. Private custom exercises remain visible only to their creator.

2. Sources

We receive information directly from you; from your device and permissions; from Apple, Google, and connected health platforms; from authentication, database, security, purchase, and diagnostics providers; and from inferences needed to provide recommendations, verification, safety, and game progression.

3. How we use information

We use information to:

  • create and secure accounts;
  • provide workout, nutrition, progression, social, and game features;
  • personalize recommendations to goals, experience, equipment, history, and recovery;
  • synchronize offline entries and verify eligible rewards;
  • estimate nutrition and require user confirmation;
  • provide subscriptions, purchases, entitlement restoration, and support;
  • prevent fraud, tampering, unsafe behavior, and abuse;
  • debug, measure reliability, improve accessibility, and develop features;
  • comply with legal obligations, enforce agreements, and protect rights and safety.

We do not use HealthKit, Health Connect, meal-photo, workout, nutrition, or precise-location data for targeted advertising, marketing profiles, insurance, employment, credit, or unrelated data mining.

4. AI-assisted processing

FitBound uses AI-assisted development and uses AI services for food-image analysis and label reading (Section 5), and may use AI for text classification, recommendations, or support. AI output can be wrong. We identify estimates and require confirmation where appropriate.

Our current default meal-photo processor’s own commercial terms state it does not train general models on API content submitted through the service we use. We require every AI provider we use to be limited to providing the requested service, to not train on FitBound user content unless a user separately opts in, and to follow the retention/deletion promises in this Policy. Formally executing a data-processing agreement memorializing these terms with our current processor is in progress — counsel should confirm its status before relying on this section as complete.

5. Disclosure of information

We may disclose information:

  • to the processors named in the register below, each providing hosting, authentication, databases, subscription management, image analysis, or app-delivery infrastructure;
  • to Apple and Google for authentication, health permissions, purchases, subscriptions, fraud prevention, and store compliance;
  • at your direction, such as an export or future game-account connection;
  • in a corporate transaction, with appropriate confidentiality and notice;
  • to comply with law or protect users, rights, safety, and service security.

We do not sell personal data or share it for cross-context behavioral advertising. We do not permit processors to independently advertise from sensitive health, fitness, nutrition, or location data.

Production processor register

This table lists FitBound’s actual processors as of the date above. We will update it when a processor changes rather than leaving a placeholder.

PurposeProviderDataRetention/control
Database, authentication, and backend logicSupabaseAccount and app records, run through row-level securityRetained per Section 7; Supabase’s own infrastructure/subprocessor terms govern hosting
Apple platform servicesAppleSign-in, purchase, optional HealthKitApple terms and user permissions
Google platform servicesGoogleSign-in, purchase. Health Connect integration is planned but not yet implemented — Android does not currently read any device health/fitness data through this app.Google terms and user permissions
Subscription and purchase managementRevenueCatYour FitBound account identifier, purchased product IDs, and entitlement/renewal status. RevenueCat does not receive your card number or other raw payment credentials — Apple or Google handle those directly.Retained per RevenueCat’s own terms to maintain your active entitlement
Meal-photo and label AI analysisCurrently an OpenRouter-hosted open-weights vision model, Qwen3-VL-30B-A3B-Instruct, reached through FitBound’s own “FitBound Vision” backend gateway (confirmed by our own usage records as the processor actually handling scans). Our backend also supports routing directly to Anthropic (Claude) as an alternate/fallback path; whichever is actually configured live is the one in effect, and we will keep this row current as that changes.A transiently resized copy of the photo, plus the analysis requestThe processor receives the image only to return an estimate; the copy sent for analysis is discarded immediately after the response, by design — see “Meal photos” above
Food-scanning backend hosting (when the gateway path above is active)RailwayHosts the FitBound Vision gateway service that relays a meal photo to the AI processor aboveNo image is retained at this hop; see “Meal photos” above
Repeat-meal scan recognitionHandled entirely on FitBound’s own backend (Supabase) — not a separate third partyA short numeric fingerprint (perceptual hash) of each analyzed photo, used only to recognize a repeat scan of the same mealCapped at 200 entries per account, oldest discarded first; no separate time-based expiration today — see “Meal photos” above and Section 7
Map displayOpenFreeMap (map tiles for the Gym Map screens)Device IP address and the map area being viewed, as an ordinary part of loading map imageryGoverned by OpenFreeMap’s own hosting; not routed through FitBound’s servers — see “Optional location” above
App build delivery and over-the-air updatesExpo/EASApp binaries and code updates delivered to your deviceNot user personal data; delivery infrastructure only
Crash monitoringNone integratedNot applicable — FitBound does not currently use a crash-reporting providerNot applicable
Product analyticsNone integratedNot applicable — FitBound does not currently use a product-analytics providerNot applicable

If we add crash monitoring or product analytics in the future, we will name the provider here, describe what it collects, and follow the same no-advertising, no-sensitive-data-mining commitments as every other processor in this table.

6. Legal bases and consent

Where applicable, we process information to perform our contract, with consent, for legitimate interests such as security and service improvement, and to comply with law. You can withdraw optional permission through FitBound or system settings. Withdrawal does not affect prior lawful processing.

Health, camera, motion, location, microphone, and photo-library permissions are requested only in context. A permission is not treated as consent for an unrelated use.

7. Retention and deletion

We retain account and user-entered data while the account is active and for a limited period afterward to provide deletion recovery, resolve disputes, prevent fraud, satisfy financial/legal obligations, and maintain backups.

The items below marked (enforced) are independently verified to actually work as described, today. The items marked (policy commitment — technical enforcement pending) are our stated intent and the ceiling we are designing to, but do not yet have an automated mechanism that deletes or reduces the data at the stated time — until that mechanism exists, the data may persist longer than the stated window. We are disclosing this distinction directly rather than presenting every line as equally implemented.

  • meal photo sent for analysis: remote deletion immediately after response (enforced — no image, URL, or unrelated-reuse embedding is stored in our systems at all);
  • local meal photo: until the user deletes it, clears app data, or uninstalls (enforced — this is entirely on-device and outside our control);
  • meal-photo fingerprint (Section 1, “Meal photos”): up to 200 most recent per account, oldest discarded first (enforced); no separate time-based expiration (policy commitment — technical enforcement pending);
  • active account records: while the account is active (enforced);
  • deleted account primary records: delete or de-identify within 30 days (enforced — in practice this happens within seconds of a deletion request, not up to 30 days). One record is a deliberate exception: we keep a minimal log of the fact that a deletion occurred (the account identifier and the email on file at the time) to support fraud prevention and dispute handling after the account is gone; this log does not currently have its own expiration date;
  • encrypted backup remnants: age out within 90 days (policy commitment — we have not yet independently confirmed our current hosting plan’s backup behavior matches this number; being verified);
  • gym-verification location events (the precise coordinates described in Section 1, “Optional location”): 90 days from the event, then deleted or reduced to a pass/fail result with coordinates removed (policy commitment — technical enforcement pending; today these records persist past 90 days until that job is built);
  • referral-redemption fraud-detection signals (the IP address described above in “Device, security, and diagnostics”): up to 12 months (policy commitment — technical enforcement pending, same as the line above);
  • security and anti-fraud logs generally: up to 12 months unless needed for an incident (policy commitment — technical enforcement pending);
  • store transaction/financial records: as required by tax, accounting, store, and consumer-protection law (enforced by those third parties’ own systems — Apple/Google/RevenueCat — rather than a FitBound-side job);
  • legal acceptance records: retained as necessary to document the agreement (enforced).

We will build and independently verify the technical enforcement for every “policy commitment” line above; this Policy will be updated to move each one to “enforced” as that happens, not left indefinitely as an unimplemented promise. We may retain de-identified data that cannot reasonably be linked back to a person.

8. Security and breach response

We use measures appropriate to the sensitivity of the data, including encrypted transport, managed authentication, least-privilege access, row-level database security (independently verified as enabled on every exposed data table), separation of user-editable data from server-authoritative rewards, audit logging, dependency review, secrets management, and tested account-deletion procedures.

A formal written incident-response and breach-notification plan is in development and has not yet been finalized. No system is completely secure. If an incident triggers the FTC Health Breach Notification Rule or another notification law, we will provide required notices to affected individuals, regulators, and others within the required time.

To report a security vulnerability, contact security@fitboundonline.com.

9. Your choices and rights

You can review and edit profile, plan, workout, nutrition, and permission settings; disconnect health access in system settings; and decline optional location or meal photos.

You can delete your account at any time from within FitBound (Settings > Delete account); this is an automated, self-service action that removes or de-identifies your data as described in Section 7, typically within seconds.

You can export a copy of your data at any time from within FitBound (Profile > Nutrition & Body Report > Export all my data), covering your workouts, nutrition entries, body measurements, currency and progression history, inventory, achievements, guild membership, and other account records, as a self-service action requiring no wait or request. A small number of records are intentionally excluded from this export — content authored by other people about you (such as a moderation report someone else filed) and internal rate-limiting bookkeeping — because they are not solely your own data to export. For anything not covered by the in-app export, email privacy@fitboundonline.com and we will fulfill an access or portability request manually within the time required by applicable law.

Depending on where you live and whether an applicable law’s thresholds or exemptions are met, you may have rights to confirm processing, access, correct, delete, obtain a portable copy, opt out of certain profiling or targeted advertising, withdraw consent, and appeal a denied request. We will not discriminate against you for exercising a right.

Submit a request to privacy@fitboundonline.com. We may reasonably verify your identity. Authorized-agent requests require proof of authority. We will provide an appeal route when required.

10. State-specific disclosures

FitBound is based in New Jersey. The New Jersey Data Privacy Act, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other state consumer privacy laws may apply depending on statutory thresholds, exemptions, residency, and processing. Regardless of threshold, FitBound’s design avoids the sale of personal data and targeted advertising based on health data.

Before release, counsel must review and finalize this section, including confirming statutory thresholds actually apply, adding any additional state supplements (for example Virginia, Colorado, Connecticut, Utah), and completing appeals, data-protection-assessment, and processor-contract requirements.

California (CCPA/CPRA)

The table below identifies the categories of personal information FitBound actually collects, mapped to the categories defined in Cal. Civ. Code § 1798.140, and the categories of third parties each category is disclosed to for a business purpose (see Section 5 for the specific companies). FitBound does not sell personal information and does not share personal information for cross-context behavioral advertising, so no category below is disclosed for those purposes.

Category (Cal. Civ. Code § 1798.140)Examples of what FitBound collectsDisclosed to
IdentifiersName, email, account ID, IP address (see below)Service providers (hosting/auth); Apple/Google (sign-in)
Customer records (§ 1798.80(e))Height, weight, body measurementsService providers only
Protected classification characteristicsBirth date/age (18+ gate); gender, where providedService providers only
Commercial informationSubscription/purchase entitlement statusApple/Google (payment processing); RevenueCat (entitlement management, Section 5)
Internet or network activityIP address collected specifically when you redeem a referral code, for fraud-clustering detection (Section 1); map-tile requests when you open a map screen (Section 1, “Map display”). We do not integrate an analytics or crash-reporting provider (see Section 5), so no general app-interaction-event or crash-diagnostic collection exists beyond these specific, named uses.Service providers only (Section 5); OpenFreeMap for map-tile requests; never used for advertising
Geolocation dataPrecise device coordinates, but only for the moment of a gym-verification check you trigger (starting a workout at a saved gym, a boss encounter, a gym-control action) — never collected in the backgroundService providers only (Section 5); never used for advertising; retention described in Section 7
Sensory dataMeal photo, only if you use photo-based food logging; a numeric fingerprint of that photo is retained (Section 1, “Meal photos”)The AI image-analysis processor named in Section 5; image itself is transient and not retained by FitBound
InferencesRecovery status, workout/nutrition recommendations derived from your activityService providers only; not sold or shared for advertising

Sensitive personal information. Several of the categories above — health, fitness, and nutrition data, and precise geolocation in particular — also qualify as “sensitive personal information” under CPRA. FitBound only uses sensitive personal information to provide the features you use it for (workout tracking, nutrition estimates, recovery/progression, gym verification) and does not use it to infer characteristics about you for advertising or any purpose beyond providing the service. This means FitBound’s processing already falls within the CCPA/CPRA exemption for sensitive personal information used solely to provide the requested service, but you may still contact us using Section 9 to ask us to limit any use you believe falls outside that exemption.

Do Not Track. FitBound’s app does not currently respond to browser “Do Not Track” signals. Our support/marketing web pages, if they set any cookies, are covered by Section 1’s device/diagnostics disclosures; we do not use those cookies for cross-context advertising.

No discrimination. We will not deny goods or services, charge different prices, or provide a different level of service because you exercised a CCPA/CPRA right.

11. Health platforms

HealthKit (iOS) access is optional and granular, and is the only device-health-platform integration currently shipped — Android Health Connect access is planned but not yet implemented; FitBound does not currently read any device health/fitness data on Android. This section will be updated, and Health Connect access will follow these same commitments, if and when that integration ships. FitBound must:

  • request only data needed for a user-visible feature and only when relevant;
  • explain each requested category;
  • never use health-platform data for advertising or unrelated profiling;
  • never write false or misleading health data;
  • honor platform deletion, permission, and security requirements;
  • avoid storing HealthKit personal health information in iCloud.

12. International use

The initial release is designed for the United States. Do not market or enable additional jurisdictions until required notices, legal bases, representative appointments, transfer mechanisms, and rights workflows are evaluated.

13. Changes

We may update this Policy. We will post a version and effective date and provide additional notice or obtain renewed consent where required. Materially different uses of sensitive data require appropriate notice and choice before the new use.

14. Contact

Sacro Media LLC
Operating as FitBound Online
Email: privacy@fitboundonline.com

FITBOUNDONLINE

Real effort. Persistent progress.

ContactGeneral: hello@fitboundonline.comSupport: support@fitboundonline.comPrivacy: privacy@fitboundonline.comSecurity: security@fitboundonline.comLegal: legal@fitboundonline.com
ProductHow it worksFeaturesRoadmapWorkoutsProgressionMuscle recoveryNutritionGame systems
CompanyAboutBlogYour Account
HelpFAQSupportSecurityFeature RequestsReport a Bug
LegalPrivacy PolicyTerms of ServiceEnd User License AgreementHealth & Fitness DisclaimerAccount DeletionRequest Data DeletionAge Suitability
VisionFuture World — future vision

© 2026 Sacro Media LLC. FitBound Online is developed and operated by Sacro Media LLC.