Privacy policy
Version 1, last updated 23 August 2026.
The short version
Your training data is yours. We do not sell it, we do not advertise, we run no analytics and no tracking of any kind, and nobody at your gym sees more than your name until you say they can. You can download the lot, or delete it outright, yourself, at any time. Everything below is the detail behind those sentences.
Who we are
FitFinch is the data controller for the information described here — we decide what is collected and why.
- Data protection contact
- hello@fitfinch.com
A gym you join is a separate business, and a controller in its own right for what it records about you as its member: your membership, your bookings, your attendance and its own staff notes. We process that on the gym’s behalf. Everything else on this page is ours.
What we collect, why, and on what basis
Only what you type in, and what your own use of the app produces. There is no tracking, no advertising identifier, no profiling, and no decision about you is ever made automatically.
Your account
Your name, your email address, and an encrypted form of your password. Your email address is how you sign in and how we reach you about your account.
Lawful basis: Contract — we cannot give you an account without it.
What you tell us about yourself
Height, current weight, date of birth, an optional description of your gender, your goals, your experience and how often you train. Used to estimate calorie targets and to show your own progress back to you. You can skip every question; the app is less useful and still works.
Lawful basis: Contract, for the features you asked for.
What you log
Food and drink, workouts and the sets you did, body weight and measurements, and the dates of all of it. This is the product. It is never sold, and never shown to anybody else without your say-so.
Lawful basis: Contract.
Progress photographs
Only if you add them: photographs of yourself, and the date each one was taken. They are private to you unless you mark one as shared with a gym you belong to, and staff can only open a shared one if you have separately agreed to share photographs at all. Every time a member of staff opens one, it is written down where you can see it. They are stored on our own servers, never used for anything but showing them back to you, and deleted with your account.
Lawful basis: Consent — asked for separately from everything else, and withdrawable at any moment by making a photograph private or deleting it.
What you eat, and what you will not
Only if you tell us: which recipes you saved, the proteins, vegetables and cuisines you enjoy, any dietary requirements, and any foods you would rather not see. It is used for one thing — deciding which recipes the app shows you first. No gym can see any of it, and there is no screen anywhere that shows it to staff. It is deleted with your account.
Lawful basis: Consent — you are asked for it, nothing is required, and clearing a box removes it. Some of these answers say something about your health: “nut free” and “gluten free” are the shape of an allergy, so we treat this the way we treat health information rather than as an ordinary preference.
Health information
Only if you enter it: medical notes about injuries or conditions, and an emergency contact. Under UK GDPR this is special category data, so it rests on your explicit consent — asked for separately, withdrawable at any moment, and written down every time a member of gym staff reads it.
Lawful basis: Explicit consent, Article 9(2)(a). Nothing here is inferred from anything else you enter.
Sign-in and security records
Your IP address, a rough description of your browser and device, and the time — for every sign-in, sign-out, failed attempt and password reset. Kept so you can see for yourself whether somebody else has been in your account.
Lawful basis: Legitimate interests: keeping accounts secure, and being able to show you what happened to yours.
If you join a gym
Your membership and its dates, which plan you are on, the classes you booked, whether you attended, and any notes staff write about you. Those notes are personal data about you, so they are in your data export even though the app does not otherwise show them to you.
Lawful basis: Contract with you, and the gym’s legitimate interest in running its classes.
Consent records
What you agreed to, when, the version of this policy it was given against, and the address it came from. Deliberately thin: enough to show you were asked, not enough to build a picture of you.
Lawful basis: Legal obligation — UK GDPR requires us to be able to demonstrate consent.
Who can see it
By default: you, and nobody else.
- Staff at a gym you belong to can see your name and contact details, and whether you are a current member.
- They can see your goals, weight, measurements and food diary only if you have said yes to that. It is checked on the server every time, not hidden in the interface. Turning it off takes effect immediately.
- They can see your medical notes only if you have separately said yes to that, and only while you belong to that gym. Every read is logged, and shown to you.
- They can never see your workout history or your sign-in records.
- Leaving a gym ends all of it at once. Staff there can no longer see anything of yours.
- Other members see nothing about you.
- We do not sell data, and there is no advertising anywhere on this platform.
Our own administrator account is no exception. It can do most things the software allows; reading progress or medical notes you have not shared is deliberately not one of them, and that is enforced in the code rather than promised here.
Who else processes it
Two kinds of supplier, both under a written contract binding them to act only on our instructions: the company that hosts the servers and database, and the company that sends our email. That is the whole list. Nothing about you goes to an advertiser, a data broker, an analytics company, or another gym.
One more thing happens, and it is worth being exact about because it involves another organisation. When you scan a barcode we do not already hold, our server asks Open Food Facts — a public, collaborative food database — what that barcode is. What we send them is the number off the packet and nothing else: not your name, not your account, not that anybody in particular is asking. They cannot tell one of our members from another, or from us. The answer is then stored here, so the same packet is never asked about twice.
We would disclose data if the law required it — a court order, or a genuine risk to somebody’s life. We have not been asked.
Where it is kept
Your data is stored in the United Kingdom. Where a supplier processes anything outside the UK, it is done under the transfer terms UK law provides for — the UK Addendum to the standard contractual clauses, or an adequacy decision.
The website itself loads nothing from a third party — no external scripts, no external fonts, no embedded trackers. Opening a page here contacts our servers and nobody else’s. Your browser never talks to Open Food Facts; only our server does, and only about a barcode.
How long we keep it
- Your account and everything in it: until you delete it. We do not expire accounts for being quiet — a year out of the gym is exactly when your old history is worth having.
- Sign-in history, and the record of who looked at your data: twelve months, then deleted automatically.
- Consent records: while your account exists, because they are the evidence that we asked you properly.
- When you delete your account it is gone, including what gyms wrote about you, and including your bookings and attendance. A gym’s own past figures fall by one; it does not get to keep a record of you. Backups roll off within 30 days.
Your rights, and the buttons that exercise them
These are things you do, not requests you have to make of us. Sign in and open “Your data”.
- Get a copy — everything we hold about you, as one file, from the “Your data” page.
- Correct anything — every screen that shows a figure also edits it.
- Delete your account — a real deletion, done from the app or from https://www.fitfinch.com/delete-account, without asking us.
- Withdraw a consent — immediately, and without losing the rest of your account.
- Object to what we do with your data, or ask us to restrict it.
- Take it elsewhere — the export is a machine-readable file, which is what portability means.
- See who has looked at your record, and when.
If you would rather ask us, write to hello@fitfinch.com and we will answer within one month, free of charge. If we have got something wrong you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113 — you do not have to come to us first.
Children
This service is for people aged 16 and over, and is not directed at children. We do not knowingly hold data about anybody younger; if you believe we do, write to hello@fitfinch.com and we will delete it. A gym with junior members should hold their records through a parent’s or guardian’s account rather than the child’s own.
How it is protected
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form, and nobody here can read yours. Access is limited by role, so a trainer at one gym reaches nothing belonging to another. Deleting your account and exporting your data both require your current password, because being signed in proves you logged in once, not that you are the person holding the phone now.
No system is perfect. If there is ever a breach that puts you at risk, we will tell you and the ICO within 72 hours, as the law requires.
Changes to this policy
Every consent you give is stored against the version of this policy it was given under, so a change here can never quietly reinterpret something you agreed to before it. Material changes are announced in the app, and the version number above goes up.