# Fit# FitPulse — Privacy Policy
Effective Date: August 1, 2026
Last Updated: August 1, 2026
Application: FitPulse (iOS) — fitness, workout, and nutrition tracking
Privacy Contact: Services@fit-pulse.net
---
## 1. Introduction
This Privacy Policy ("Policy") explains how FitPulse ("FitPulse," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with the FitPulse mobile application for iOS (the "App") and any related services (collectively, the "Services").
FitPulse is a fitness and nutrition application that helps users log workouts and meals, track biometric and recovery trends, and receive on-device coaching feedback. Because the App processes health and fitness information, we treat that information as sensitive and apply heightened protections to it.
This Policy is designed to satisfy our obligations under the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other U.S. state privacy statutes, the Apple App Store Review Guidelines (including the HealthKit and Health & Fitness provisions), and the WHOOP Developer Platform Terms.
By downloading, installing, or using the App, you acknowledge that you have read and understood this Policy. Where consent is the legal basis for processing, we will request your consent separately and explicitly through the operating system or in-app prompts.
---
## 2. Summary of Our Core Privacy Commitments
The following commitments are binding statements of our practices and are described in greater detail throughout this Policy:
1. We never sell your personal information, and we never share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
2. We never use Apple HealthKit data for marketing, advertising, or any use-based data mining, and we never disclose HealthKit data to data brokers, advertising networks, or similar services.
3. Camera and computer-vision processing occurs entirely on your device. Video frames are never recorded, never stored, and never transmitted to our servers or to any third party.
4. Health, biometric, and recovery data are never used to serve or target advertisements. Our advertising partner receives no health, nutrition, biometric, or workout data.
5. You may request deletion of your account and associated data at any time by contacting Services@fit-pulse.net or by using the in-app account deletion control.
---
## 3. Data Controller and Contact Details
For the purposes of the GDPR, FitPulse is the data controller of personal data processed through the Services, except where the App merely facilitates local processing on your device.
| Purpose | Contact |
| --- | --- |
| Privacy inquiries | Services@fit-pulse.net |
| Data subject / consumer rights requests | Services@fit-pulse.net |
| Account and data deletion requests | Services@fit-pulse.net |
| Security disclosures | Services@fit-pulse.net |
Please include the email address associated with your FitPulse account and a description of your request so that we can verify your identity and respond accurately.
---
## 4. Categories of Information We Process
### 4.1 Account and Identity Information
Email address, hashed authentication credentials or third-party sign-in identifier (including Sign in with Apple), display name, and account creation timestamp.
### 4.2 Profile and Fitness Goal Information
Optionally provided attributes such as date of birth or age, biological sex, height, weight, activity level, training experience, dietary preferences, and calorie, macronutrient, or body-composition goals.
### 4.3 Health, Fitness, and Biometric Information
Data you log directly in the App and, where you grant permission, data read from Apple HealthKit and the WHOOP Developer API, as described in Sections 5 and 6.
### 4.4 Nutrition and Food Log Information
Foods and beverages logged, portion sizes, meal timing, barcode scan results, recipes, water intake, and derived calorie and macronutrient totals.
### 4.5 Workout and Exercise Information
Exercises performed, sets, repetitions, load, duration, perceived exertion, session notes, and — where you use camera-based tracking — the numeric rep counts and form-quality scores derived on your device.
### 4.6 Device and Technical Information
Device model, operating system version, App version, language and region settings, crash and diagnostic logs, and non-precise usage events such as screens viewed and features used.
### 4.7 Advertising Identifiers
Where permitted, the Apple Identifier for Advertisers (IDFA) or, on non-Apple platforms, the Google Advertising ID (GAID), together with ad interaction data collected by our advertising partner as described in Section 8.
### 4.8 Support Communications
The contents of messages you send to us, including email correspondence and attachments.
### 4.9 Purchase and Subscription Information
Subscription status, entitlement tier, renewal state, and transaction identifiers received from Apple. We do not receive or store your full payment card number, security code, or bank details; all payment processing is performed by Apple.
We do not intentionally collect precise geolocation data, contact lists, photo libraries, biometric identifiers used for authentication (such as Face ID templates, which remain under Apple's control), or government identification numbers.
---
## 5. Apple HealthKit Integration
### 5.1 Nature of the Integration
The App integrates with Apple HealthKit, the system framework that stores health and fitness data on your iOS device. HealthKit access is entirely optional and is never required to create an account or use the core features of the App. Access is granted only through Apple's native permission dialogs, which allow you to approve or deny each data type individually.
### 5.2 Data Types We Request Permission to Read
Where you grant permission, the App may read the following HealthKit data types:
- Heart Rate
- Resting Heart Rate
- Heart Rate Variability (HRV / SDNN)
- Respiratory Rate
- Blood Oxygen Saturation (SpO₂)
- Sleep Analysis
- Active Energy Burned
- Basal (Resting) Energy Burned
- Step Count
- Workouts (including type, duration, distance, and energy)
- Body Mass (Weight)
- Body Fat Percentage
- Dietary and Nutrition data (including energy consumed, protein, carbohydrates, total and saturated fat, fiber, sugar, sodium, cholesterol, water, and caffeine)
### 5.3 Data Types We Request Permission to Write
Where you grant permission, the App may write the following data types back to HealthKit so that your Apple Health record remains a complete and authoritative source:
- Dietary and Nutrition data corresponding to meals you log in the App
- Body Mass (Weight) and Body Fat Percentage you record in the App
- Workouts you complete or log in the App, including duration and Active Energy Burned
- Water intake
### 5.4 Purposes of HealthKit Processing
HealthKit data is used solely to provide health and fitness features that you have requested, specifically: displaying your metrics and trends; calculating daily calorie and macronutrient targets and remaining allowances; computing readiness, recovery, and training-load insights; generating on-device or user-requested coaching guidance; and synchronizing your logs so data is not duplicated across apps.
### 5.5 Binding HealthKit Restrictions
In strict compliance with the Apple App Store Review Guidelines and the HealthKit Developer Program requirements, we make the following binding commitments:
- We do NOT use HealthKit data for marketing.
- We do NOT use HealthKit data for advertising, ad targeting, ad measurement, or audience building.
- We do NOT sell HealthKit data, and we do NOT disclose or make HealthKit data available to data brokers, advertising networks, or similar services.
- We do NOT use HealthKit data for use-based data mining or for any purpose other than improving health, fitness, or medical-adherence outcomes, or for health research where you have provided separate, explicit, informed consent.
- We do NOT disclose HealthKit data to any third party except (a) to service providers strictly necessary to deliver the features you request, bound by contract to equivalent restrictions; or (b) where compelled by valid legal process.
- We do NOT use HealthKit data to make eligibility, insurance, credit, or employment determinations, and we do not provide it to parties who do.
### 5.6 Storage and Revocation
HealthKit data is read into the App for display and computation. Where you enable cloud sync or backup, health metrics are stored in encrypted form in our infrastructure solely to make your data available across your devices and to preserve your history; this storage is optional and can be disabled. You may revoke HealthKit permissions at any time in Settings → Privacy & Security → Health → FitPulse, or within the Apple Health app. Revocation stops all further reading and writing immediately. To delete previously synchronized copies held by us, use in-app account deletion or contact Services@fit-pulse.net. Data already written to HealthKit remains under your control in the Apple Health app, and deleting the App does not delete data from HealthKit.
---
## 6. WHOOP Developer API Integration
### 6.1 Nature of the Integration
FitPulse offers an optional integration with WHOOP via the WHOOP Developer API. This integration is disabled by default and is activated only when you explicitly choose to connect your WHOOP account.
### 6.2 Authorization via OAuth 2.0
Connection is established using the OAuth 2.0 authorization code flow. You are redirected to WHOOP's own authorization page, where you authenticate directly with WHOOP and review the scopes we request. FitPulse never receives, sees, or stores your WHOOP username, password, or WHOOP account credentials. WHOOP returns an access token and refresh token, which we store in encrypted form and use only to make authorized requests on your behalf.
### 6.3 Data Read from WHOOP
Subject to the scopes you approve, we read the following from WHOOP's servers:
- Recovery Score (daily recovery percentage)
- Daily Strain (cardiovascular load score)
- Sleep Performance (including sleep duration, efficiency, and stage summaries)
- Heart Rate Variability (HRV) and associated resting heart rate values
- Cycle and workout metadata necessary to align WHOOP metrics with the correct day and session
We request read-only scopes. We do not write data to your WHOOP account, and we do not access WHOOP data belonging to any person other than the account holder who authorized the connection.
### 6.4 Purposes of WHOOP Processing
WHOOP-derived metrics are used solely to display your recovery, strain, and sleep trends inside the App; to adjust recommended training intensity and nutritional targets based on recovery state; and to correlate recovery with your logged training and nutrition so you can understand your own patterns.
WHOOP data is never used for advertising, ad targeting, or marketing, is never sold, and is never disclosed to data brokers or advertising networks.
### 6.5 Storage, Retention, and Disconnection
WHOOP metrics are cached in encrypted form so the App can display history and trends without repeatedly querying WHOOP. You may disconnect at any time from within the App (Settings → Integrations → WHOOP) or by revoking FitPulse access in your WHOOP account settings. Upon disconnection we cease all further API requests, revoke and delete the stored tokens, and delete cached WHOOP data within thirty (30) days, subject to any narrower retention required by law.
### 6.6 Relationship with WHOOP
WHOOP is an independent third-party controller of the data it collects through its own devices and services. Our use of WHOOP data is governed by this Policy and the WHOOP Developer Platform Terms; WHOOP's own collection is governed by the [WHOOP Privacy Policy](https://www.whoop.com/privacy/). We encourage you to review it.
---
## 7. On-Device AI and Computer Vision (Camera)
### 7.1 Feature Description
FitPulse offers optional camera-based workout tracking that counts repetitions, estimates tempo and range of motion, and provides real-time form feedback. The feature operates only while you are actively in a camera-tracked workout session and only after you grant camera permission through the iOS system prompt.
### 7.2 100% On-Device Processing — Binding Statement
We make the following explicit and binding commitments regarding camera data:
- All video frames and camera data are processed 100% locally on your device, using on-device machine learning frameworks (including Apple Vision and Core ML) executing on your device's CPU, GPU, and Neural Engine.
- Video frames are NEVER recorded. The camera feed is held transiently in device memory only for the duration of the frame's analysis and is discarded immediately thereafter.
- Video frames, images, and body-pose data are NEVER stored to your camera roll, to App storage, or to any persistent medium.
- Video frames, images, and camera data are NEVER transmitted to our servers, to any cloud service, to any analytics provider, to our advertising partner, or to any other third party.
- No third party receives camera data of any kind, and camera data is never used for advertising, profiling, biometric identification, or facial recognition.
### 7.3 What Is Retained
Only the numeric outputs of the on-device analysis are retained, and only where you save the workout: repetition counts, set and tempo timings, estimated range of motion, and an aggregate form-quality score. These values are indistinguishable in kind from a manually logged workout and contain no imagery.
### 7.4 Control
You may deny or revoke camera permission at any time in Settings → Privacy & Security → Camera → FitPulse. Denying camera access disables only the camera-based tracking feature; all other App functionality remains available.
---
## 8. Advertising — Google AdMob
### 8.1 Nature of the Integration
The free tier of the App displays interstitial sponsor advertisements served through the Google Mobile Ads SDK (Google AdMob). Advertising is a separate processing activity from the health and fitness features described above.
### 8.2 Information Collected by AdMob
To serve, cap, measure, and prevent fraud in advertising, Google AdMob and its ad technology partners may collect and process:
- Device advertising identifiers — the Apple IDFA (only where you grant App Tracking Transparency permission) or the Google Advertising ID (GAID) on applicable platforms
- Device and network information, including device model, operating system version, screen characteristics, language, coarse location inferred from IP address, and IP address itself
- Ad interaction data, including ad impressions, views, clicks, and completion events
- Non-precise App usage and session signals relevant to ad delivery and frequency capping
Google acts as an independent controller or business for certain of these purposes. Its processing is governed by the [Google Privacy Policy](https://policies.google.com/privacy) and the [Google Business Data Responsibility disclosures for advertising](https://business.safety.google/privacy/).
### 8.3 Strict Data Separation — Binding Statement
- No Apple HealthKit data is shared with Google AdMob or any advertising partner.
- No WHOOP data is shared with Google AdMob or any advertising partner.
- No camera, video, or body-pose data is shared with Google AdMob or any advertising partner.
- No nutrition logs, body composition data, biometric values, or workout content are shared with Google AdMob or any advertising partner.
- We do not build advertising audiences or segments from health, fitness, or nutrition information, and we do not use such information to select or target the ads you see.
### 8.4 App Tracking Transparency and Consent
On iOS, tracking-based advertising requires your permission under Apple's App Tracking Transparency framework. If you decline, the IDFA is not made available and advertising is served on a non-personalized basis. In the European Economic Area, the United Kingdom, and Switzerland, we present a consent interface compliant with the ePrivacy Directive and the IAB Transparency & Consent Framework before any non-essential advertising or measurement identifiers are used; where you do not consent, only non-personalized advertising is served. You may withdraw consent at any time in the App's privacy settings.
### 8.5 Ad-Free Option
Purchasing a FitPulse premium subscription removes interstitial advertising and, with it, the associated advertising SDK data collection.
### 8.6 Opting Out at the Device Level
You may limit ad tracking through Settings → Privacy & Security → Tracking and Settings → Privacy & Security → Apple Advertising on iOS, or by resetting or deleting your advertising identifier on Android.
---
## 9. Other Third-Party Service Providers
In addition to Google AdMob, we rely on a limited set of processors, each bound by written agreements that restrict use of data to the purposes we specify:
| Category | Purpose | Health data access |
| --- | --- | --- |
| Cloud hosting and storage | Account hosting, encrypted data storage, backups | Encrypted at rest; no independent use |
| Authentication | Account sign-in, including Sign in with Apple | No |
| Crash and performance diagnostics | Stability and error monitoring | No |
| Product analytics | Aggregate feature usage and retention | No |
| Subscription management | Entitlement validation with Apple | No |
| Customer support tooling | Responding to your inquiries | Only what you voluntarily include |
| Nutrition database providers | Food and barcode lookup | Query terms only; not linked to identity for third-party use |
| Optional AI coaching services | Generating narrative guidance where you enable the feature | Only where you enable it, and only the minimum metrics necessary; providers are contractually prohibited from training models on your data |
We do not authorize any processor to sell your information, to use it for their own advertising, or to disclose it to data brokers.
---
## 10. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
| Processing activity | Legal basis |
| --- | --- |
| Creating and maintaining your account; delivering core App functionality | Contract — Art. 6(1)(b) |
| Processing health, biometric, nutrition, and recovery data (including HealthKit and WHOOP) | Explicit consent — Art. 9(2)(a), together with Art. 6(1)(a) |
| Camera-based on-device workout tracking | Explicit consent — Art. 9(2)(a) |
| Personalized advertising and associated identifiers | Consent — Art. 6(1)(a) |
| Non-personalized advertising, security, fraud prevention, and service integrity | Legitimate interests — Art. 6(1)(f) |
| Aggregated and de-identified product analytics and service improvement | Legitimate interests — Art. 6(1)(f) |
| Retaining transaction records; responding to legal process | Legal obligation — Art. 6(1)(c) |
Health-related data constitutes special category data under Article 9 GDPR. We process it only with your explicit consent, and you may withdraw that consent at any time without affecting the lawfulness of processing already carried out.
---
## 11. Your Rights
### 11.1 Rights Under the GDPR (EEA, UK, Switzerland)
You have the right to: access your personal data and obtain a copy; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests, including profiling; receive your data in a portable, machine-readable format (**data portability**); withdraw consent at any time; and lodge a complaint with your national supervisory authority. You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects — we do not engage in such decision-making. Coaching suggestions in the App are informational and never determine eligibility for any product, benefit, or service.
### 11.2 Rights Under the CCPA/CPRA (California)
You have the right to: know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; delete personal information we hold about you; correct inaccurate personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information; and be free from retaliation or discrimination for exercising these rights.
Notice regarding sale and sharing: In the preceding twelve (12) months, FitPulse has not sold personal information and has not shared personal information for cross-context behavioral advertising as those terms are defined by the CPRA. We do not sell or share the personal information of consumers we know to be under 16 years of age.
Sensitive personal information: Health, biometric, and precise-health-related data are treated as sensitive personal information. We use such information only for the purposes described in Section 5 and Section 6 — that is, to perform the services you request — which falls within the permitted uses under Cal. Civ. Code § 1798.121 and its implementing regulations. We do not use or disclose sensitive personal information to infer characteristics about you for advertising purposes.
### 11.3 Rights Under Other U.S. State Laws
Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have analogous rights of access, correction, deletion, portability, and opt-out of targeted advertising, and — where applicable — the right to appeal a denied request. Texas residents and others may also be protected by state laws governing consumer health data; we treat all health data as requiring affirmative consent.
### 11.4 How to Exercise Your Rights
Submit requests by emailing Services@fit-pulse.net, or use the in-app controls under Settings → Privacy, which include data export and account deletion. We will acknowledge your request promptly and respond within thirty (30) days (GDPR) or forty-five (45) days (CCPA/CPRA), with a single permitted extension where reasonably necessary and with notice to you. We may need to verify your identity by confirming control of the email address on your account. Authorized agents may submit requests on your behalf with written authorization. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
---
## 12. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy.
| Data category | Retention period |
| --- | --- |
| Account and profile data | For the life of the account, then deleted within 30 days of deletion request |
| Health, biometric, nutrition, and workout logs | For the life of the account, then deleted within 30 days |
| Cached WHOOP data and OAuth tokens | Deleted within 30 days of disconnection or account deletion |
| Camera / video frames | Not retained — discarded from memory in real time |
| Diagnostic and crash logs | Up to 90 days |
| Aggregated, de-identified analytics | Retained indefinitely in a form that cannot be re-identified |
| Support correspondence | Up to 24 months |
| Transaction and subscription records | As required by tax and accounting law, typically up to 7 years |
Following account deletion, residual copies may persist in encrypted backups for a limited period and are overwritten on the normal backup rotation cycle.
---
## 13. Security
We implement technical and organizational measures appropriate to the sensitivity of the data we process, including: TLS 1.2 or higher for all data in transit; AES-256 encryption for data at rest; encrypted storage of OAuth tokens in the iOS Keychain and in hardened server-side secret storage; role-based access control with least-privilege provisioning and multi-factor authentication for administrative access; audit logging of access to health data stores; periodic security review and dependency patching; and vendor due diligence before onboarding processors.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it as required by Article 33 GDPR, and will notify affected users without undue delay where required by applicable law.
---
## 14. International Data Transfers
We are based in the United States, and our infrastructure and certain processors are located in the United States and other jurisdictions. Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by technical measures such as encryption in transit and at rest, and by transfer impact assessments where required. You may request further information about these safeguards at Services@fit-pulse.net.
---
## 15. Children's Privacy
The App is not directed to children and is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children under 16. In the United States, consistent with the Children's Online Privacy Protection Act, we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. Parents or guardians who believe a child has provided information may contact Services@fit-pulse.net for immediate removal.
---
## 16. Health Disclaimer
FitPulse is a general wellness and fitness application. It is not a medical device, is not intended to diagnose, treat, cure, or prevent any disease or condition, and does not provide medical advice. Metrics such as HRV, blood oxygen, respiratory rate, recovery, and strain are provided for informational and self-tracking purposes only. Always consult a qualified healthcare professional before beginning or modifying any exercise, nutrition, or supplementation program, and seek immediate medical attention for any health concern.
---
## 17. Account and Data Deletion
You may delete your account and associated data at any time:
1. In-app: open Settings → Account → Delete Account and confirm.
2. By email: send a deletion request from your registered address to Services@fit-pulse.net.
Upon verified request we will delete your account, profile, health and nutrition logs, cached WHOOP data, and stored integration tokens within thirty (30) days, excluding records we are legally required to retain and de-identified aggregate data that can no longer be associated with you. Deleting your FitPulse account does not delete data stored in Apple Health or in your WHOOP account; those records remain under your control within Apple's and WHOOP's respective services.
---
## 18. Changes to This Policy
We may update this Policy to reflect changes in our practices, our integrations, or applicable law. When we do, we will revise the "Last Updated" date above and, for material changes, provide notice through the App or by email prior to the change taking effect. Where a material change affects processing that relies on your consent — including any change to how health, camera, or advertising data is handled — we will obtain your renewed consent before implementing it. Continued use of the App after the effective date of a non-material change constitutes acceptance of the revised Policy.
---
## 19. Contact Us
FitPulse — Privacy Team
Email: Services@fit-pulse.net
We aim to acknowledge all privacy inquiries within five (5) business days. If you are located in the EEA, the UK, or Switzerland and believe we have not adequately addressed your concern, you may lodge a complaint with your local data protection supervisory authority. California residents may also contact the California Privacy Protection Agency or the California Attorney General's office.
---
© 2026 FitPulse. All rights reserved.Pulse — Privacy Policy
Effective Date: August 1, 2026
Last Updated: August 1, 2026
Application: FitPulse (iOS) — fitness, workout, and nutrition tracking
Privacy Contact: Services@fit-pulse.net
---
## 1. Introduction
This Privacy Policy ("Policy") explains how FitPulse ("FitPulse," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with the FitPulse mobile application for iOS (the "App") and any related services (collectively, the "Services").
FitPulse is a fitness and nutrition application that helps users log workouts and meals, track biometric and recovery trends, and receive on-device coaching feedback. Because the App processes health and fitness information, we treat that information as sensitive and apply heightened protections to it.
This Policy is designed to satisfy our obligations under the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other U.S. state privacy statutes, the Apple App Store Review Guidelines (including the HealthKit and Health & Fitness provisions), and the WHOOP Developer Platform Terms.
By downloading, installing, or using the App, you acknowledge that you have read and understood this Policy. Where consent is the legal basis for processing, we will request your consent separately and explicitly through the operating system or in-app prompts.
---
## 2. Summary of Our Core Privacy Commitments
The following commitments are binding statements of our practices and are described in greater detail throughout this Policy:
1. We never sell your personal information, and we never share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
2. We never use Apple HealthKit data for marketing, advertising, or any use-based data mining, and we never disclose HealthKit data to data brokers, advertising networks, or similar services.
3. Camera and computer-vision processing occurs entirely on your device. Video frames are never recorded, never stored, and never transmitted to our servers or to any third party.
4. Health, biometric, and recovery data are never used to serve or target advertisements. Our advertising partner receives no health, nutrition, biometric, or workout data.
5. You may request deletion of your account and associated data at any time by contacting Services@fit-pulse.net or by using the in-app account deletion control.
---
## 3. Data Controller and Contact Details
For the purposes of the GDPR, FitPulse is the data controller of personal data processed through the Services, except where the App merely facilitates local processing on your device.
| Purpose | Contact |
| --- | --- |
| Privacy inquiries | Services@fit-pulse.net |
| Data subject / consumer rights requests | Services@fit-pulse.net |
| Account and data deletion requests | Services@fit-pulse.net |
| Security disclosures | Services@fit-pulse.net |
Please include the email address associated with your FitPulse account and a description of your request so that we can verify your identity and respond accurately.
---
## 4. Categories of Information We Process
### 4.1 Account and Identity Information
Email address, hashed authentication credentials or third-party sign-in identifier (including Sign in with Apple), display name, and account creation timestamp.
### 4.2 Profile and Fitness Goal Information
Optionally provided attributes such as date of birth or age, biological sex, height, weight, activity level, training experience, dietary preferences, and calorie, macronutrient, or body-composition goals.
### 4.3 Health, Fitness, and Biometric Information
Data you log directly in the App and, where you grant permission, data read from Apple HealthKit and the WHOOP Developer API, as described in Sections 5 and 6.
### 4.4 Nutrition and Food Log Information
Foods and beverages logged, portion sizes, meal timing, barcode scan results, recipes, water intake, and derived calorie and macronutrient totals.
### 4.5 Workout and Exercise Information
Exercises performed, sets, repetitions, load, duration, perceived exertion, session notes, and — where you use camera-based tracking — the numeric rep counts and form-quality scores derived on your device.
### 4.6 Device and Technical Information
Device model, operating system version, App version, language and region settings, crash and diagnostic logs, and non-precise usage events such as screens viewed and features used.
### 4.7 Advertising Identifiers
Where permitted, the Apple Identifier for Advertisers (IDFA) or, on non-Apple platforms, the Google Advertising ID (GAID), together with ad interaction data collected by our advertising partner as described in Section 8.
### 4.8 Support Communications
The contents of messages you send to us, including email correspondence and attachments.
### 4.9 Purchase and Subscription Information
Subscription status, entitlement tier, renewal state, and transaction identifiers received from Apple. We do not receive or store your full payment card number, security code, or bank details; all payment processing is performed by Apple.
We do not intentionally collect precise geolocation data, contact lists, photo libraries, biometric identifiers used for authentication (such as Face ID templates, which remain under Apple's control), or government identification numbers.
---
## 5. Apple HealthKit Integration
### 5.1 Nature of the Integration
The App integrates with Apple HealthKit, the system framework that stores health and fitness data on your iOS device. HealthKit access is entirely optional and is never required to create an account or use the core features of the App. Access is granted only through Apple's native permission dialogs, which allow you to approve or deny each data type individually.
### 5.2 Data Types We Request Permission to Read
Where you grant permission, the App may read the following HealthKit data types:
- Heart Rate
- Resting Heart Rate
- Heart Rate Variability (HRV / SDNN)
- Respiratory Rate
- Blood Oxygen Saturation (SpO₂)
- Sleep Analysis
- Active Energy Burned
- Basal (Resting) Energy Burned
- Step Count
- Workouts (including type, duration, distance, and energy)
- Body Mass (Weight)
- Body Fat Percentage
- Dietary and Nutrition data (including energy consumed, protein, carbohydrates, total and saturated fat, fiber, sugar, sodium, cholesterol, water, and caffeine)
### 5.3 Data Types We Request Permission to Write
Where you grant permission, the App may write the following data types back to HealthKit so that your Apple Health record remains a complete and authoritative source:
- Dietary and Nutrition data corresponding to meals you log in the App
- Body Mass (Weight) and Body Fat Percentage you record in the App
- Workouts you complete or log in the App, including duration and Active Energy Burned
- Water intake
### 5.4 Purposes of HealthKit Processing
HealthKit data is used solely to provide health and fitness features that you have requested, specifically: displaying your metrics and trends; calculating daily calorie and macronutrient targets and remaining allowances; computing readiness, recovery, and training-load insights; generating on-device or user-requested coaching guidance; and synchronizing your logs so data is not duplicated across apps.
### 5.5 Binding HealthKit Restrictions
In strict compliance with the Apple App Store Review Guidelines and the HealthKit Developer Program requirements, we make the following binding commitments:
- We do NOT use HealthKit data for marketing.
- We do NOT use HealthKit data for advertising, ad targeting, ad measurement, or audience building.
- We do NOT sell HealthKit data, and we do NOT disclose or make HealthKit data available to data brokers, advertising networks, or similar services.
- We do NOT use HealthKit data for use-based data mining or for any purpose other than improving health, fitness, or medical-adherence outcomes, or for health research where you have provided separate, explicit, informed consent.
- We do NOT disclose HealthKit data to any third party except (a) to service providers strictly necessary to deliver the features you request, bound by contract to equivalent restrictions; or (b) where compelled by valid legal process.
- We do NOT use HealthKit data to make eligibility, insurance, credit, or employment determinations, and we do not provide it to parties who do.
### 5.6 Storage and Revocation
HealthKit data is read into the App for display and computation. Where you enable cloud sync or backup, health metrics are stored in encrypted form in our infrastructure solely to make your data available across your devices and to preserve your history; this storage is optional and can be disabled. You may revoke HealthKit permissions at any time in Settings → Privacy & Security → Health → FitPulse, or within the Apple Health app. Revocation stops all further reading and writing immediately. To delete previously synchronized copies held by us, use in-app account deletion or contact Services@fit-pulse.net. Data already written to HealthKit remains under your control in the Apple Health app, and deleting the App does not delete data from HealthKit.
---
## 6. WHOOP Developer API Integration
### 6.1 Nature of the Integration
FitPulse offers an optional integration with WHOOP via the WHOOP Developer API. This integration is disabled by default and is activated only when you explicitly choose to connect your WHOOP account.
### 6.2 Authorization via OAuth 2.0
Connection is established using the OAuth 2.0 authorization code flow. You are redirected to WHOOP's own authorization page, where you authenticate directly with WHOOP and review the scopes we request. FitPulse never receives, sees, or stores your WHOOP username, password, or WHOOP account credentials. WHOOP returns an access token and refresh token, which we store in encrypted form and use only to make authorized requests on your behalf.
### 6.3 Data Read from WHOOP
Subject to the scopes you approve, we read the following from WHOOP's servers:
- Recovery Score (daily recovery percentage)
- Daily Strain (cardiovascular load score)
- Sleep Performance (including sleep duration, efficiency, and stage summaries)
- Heart Rate Variability (HRV) and associated resting heart rate values
- Cycle and workout metadata necessary to align WHOOP metrics with the correct day and session
We request read-only scopes. We do not write data to your WHOOP account, and we do not access WHOOP data belonging to any person other than the account holder who authorized the connection.
### 6.4 Purposes of WHOOP Processing
WHOOP-derived metrics are used solely to display your recovery, strain, and sleep trends inside the App; to adjust recommended training intensity and nutritional targets based on recovery state; and to correlate recovery with your logged training and nutrition so you can understand your own patterns.
WHOOP data is never used for advertising, ad targeting, or marketing, is never sold, and is never disclosed to data brokers or advertising networks.
### 6.5 Storage, Retention, and Disconnection
WHOOP metrics are cached in encrypted form so the App can display history and trends without repeatedly querying WHOOP. You may disconnect at any time from within the App (Settings → Integrations → WHOOP) or by revoking FitPulse access in your WHOOP account settings. Upon disconnection we cease all further API requests, revoke and delete the stored tokens, and delete cached WHOOP data within thirty (30) days, subject to any narrower retention required by law.
### 6.6 Relationship with WHOOP
WHOOP is an independent third-party controller of the data it collects through its own devices and services. Our use of WHOOP data is governed by this Policy and the WHOOP Developer Platform Terms; WHOOP's own collection is governed by the [WHOOP Privacy Policy](https://www.whoop.com/privacy/). We encourage you to review it.
---
## 7. On-Device AI and Computer Vision (Camera)
### 7.1 Feature Description
FitPulse offers optional camera-based workout tracking that counts repetitions, estimates tempo and range of motion, and provides real-time form feedback. The feature operates only while you are actively in a camera-tracked workout session and only after you grant camera permission through the iOS system prompt.
### 7.2 100% On-Device Processing — Binding Statement
We make the following explicit and binding commitments regarding camera data:
- All video frames and camera data are processed 100% locally on your device, using on-device machine learning frameworks (including Apple Vision and Core ML) executing on your device's CPU, GPU, and Neural Engine.
- Video frames are NEVER recorded. The camera feed is held transiently in device memory only for the duration of the frame's analysis and is discarded immediately thereafter.
- Video frames, images, and body-pose data are NEVER stored to your camera roll, to App storage, or to any persistent medium.
- Video frames, images, and camera data are NEVER transmitted to our servers, to any cloud service, to any analytics provider, to our advertising partner, or to any other third party.
- No third party receives camera data of any kind, and camera data is never used for advertising, profiling, biometric identification, or facial recognition.
### 7.3 What Is Retained
Only the numeric outputs of the on-device analysis are retained, and only where you save the workout: repetition counts, set and tempo timings, estimated range of motion, and an aggregate form-quality score. These values are indistinguishable in kind from a manually logged workout and contain no imagery.
### 7.4 Control
You may deny or revoke camera permission at any time in Settings → Privacy & Security → Camera → FitPulse. Denying camera access disables only the camera-based tracking feature; all other App functionality remains available.
---
## 8. Advertising — Google AdMob
### 8.1 Nature of the Integration
The free tier of the App displays interstitial sponsor advertisements served through the Google Mobile Ads SDK (Google AdMob). Advertising is a separate processing activity from the health and fitness features described above.
### 8.2 Information Collected by AdMob
To serve, cap, measure, and prevent fraud in advertising, Google AdMob and its ad technology partners may collect and process:
- Device advertising identifiers — the Apple IDFA (only where you grant App Tracking Transparency permission) or the Google Advertising ID (GAID) on applicable platforms
- Device and network information, including device model, operating system version, screen characteristics, language, coarse location inferred from IP address, and IP address itself
- Ad interaction data, including ad impressions, views, clicks, and completion events
- Non-precise App usage and session signals relevant to ad delivery and frequency capping
Google acts as an independent controller or business for certain of these purposes. Its processing is governed by the [Google Privacy Policy](https://policies.google.com/privacy) and the [Google Business Data Responsibility disclosures for advertising](https://business.safety.google/privacy/).
### 8.3 Strict Data Separation — Binding Statement
- No Apple HealthKit data is shared with Google AdMob or any advertising partner.
- No WHOOP data is shared with Google AdMob or any advertising partner.
- No camera, video, or body-pose data is shared with Google AdMob or any advertising partner.
- No nutrition logs, body composition data, biometric values, or workout content are shared with Google AdMob or any advertising partner.
- We do not build advertising audiences or segments from health, fitness, or nutrition information, and we do not use such information to select or target the ads you see.
### 8.4 App Tracking Transparency and Consent
On iOS, tracking-based advertising requires your permission under Apple's App Tracking Transparency framework. If you decline, the IDFA is not made available and advertising is served on a non-personalized basis. In the European Economic Area, the United Kingdom, and Switzerland, we present a consent interface compliant with the ePrivacy Directive and the IAB Transparency & Consent Framework before any non-essential advertising or measurement identifiers are used; where you do not consent, only non-personalized advertising is served. You may withdraw consent at any time in the App's privacy settings.
### 8.5 Ad-Free Option
Purchasing a FitPulse premium subscription removes interstitial advertising and, with it, the associated advertising SDK data collection.
### 8.6 Opting Out at the Device Level
You may limit ad tracking through Settings → Privacy & Security → Tracking and Settings → Privacy & Security → Apple Advertising on iOS, or by resetting or deleting your advertising identifier on Android.
---
## 9. Other Third-Party Service Providers
In addition to Google AdMob, we rely on a limited set of processors, each bound by written agreements that restrict use of data to the purposes we specify:
| Category | Purpose | Health data access |
| --- | --- | --- |
| Cloud hosting and storage | Account hosting, encrypted data storage, backups | Encrypted at rest; no independent use |
| Authentication | Account sign-in, including Sign in with Apple | No |
| Crash and performance diagnostics | Stability and error monitoring | No |
| Product analytics | Aggregate feature usage and retention | No |
| Subscription management | Entitlement validation with Apple | No |
| Customer support tooling | Responding to your inquiries | Only what you voluntarily include |
| Nutrition database providers | Food and barcode lookup | Query terms only; not linked to identity for third-party use |
| Optional AI coaching services | Generating narrative guidance where you enable the feature | Only where you enable it, and only the minimum metrics necessary; providers are contractually prohibited from training models on your data |
We do not authorize any processor to sell your information, to use it for their own advertising, or to disclose it to data brokers.
---
## 10. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
| Processing activity | Legal basis |
| --- | --- |
| Creating and maintaining your account; delivering core App functionality | Contract — Art. 6(1)(b) |
| Processing health, biometric, nutrition, and recovery data (including HealthKit and WHOOP) | Explicit consent — Art. 9(2)(a), together with Art. 6(1)(a) |
| Camera-based on-device workout tracking | Explicit consent — Art. 9(2)(a) |
| Personalized advertising and associated identifiers | Consent — Art. 6(1)(a) |
| Non-personalized advertising, security, fraud prevention, and service integrity | Legitimate interests — Art. 6(1)(f) |
| Aggregated and de-identified product analytics and service improvement | Legitimate interests — Art. 6(1)(f) |
| Retaining transaction records; responding to legal process | Legal obligation — Art. 6(1)(c) |
Health-related data constitutes special category data under Article 9 GDPR. We process it only with your explicit consent, and you may withdraw that consent at any time without affecting the lawfulness of processing already carried out.
---
## 11. Your Rights
### 11.1 Rights Under the GDPR (EEA, UK, Switzerland)
You have the right to: access your personal data and obtain a copy; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict processing; object to processing based on legitimate interests, including profiling; receive your data in a portable, machine-readable format (**data portability**); withdraw consent at any time; and lodge a complaint with your national supervisory authority. You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects — we do not engage in such decision-making. Coaching suggestions in the App are informational and never determine eligibility for any product, benefit, or service.
### 11.2 Rights Under the CCPA/CPRA (California)
You have the right to: know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; delete personal information we hold about you; correct inaccurate personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information; and be free from retaliation or discrimination for exercising these rights.
Notice regarding sale and sharing: In the preceding twelve (12) months, FitPulse has not sold personal information and has not shared personal information for cross-context behavioral advertising as those terms are defined by the CPRA. We do not sell or share the personal information of consumers we know to be under 16 years of age.
Sensitive personal information: Health, biometric, and precise-health-related data are treated as sensitive personal information. We use such information only for the purposes described in Section 5 and Section 6 — that is, to perform the services you request — which falls within the permitted uses under Cal. Civ. Code § 1798.121 and its implementing regulations. We do not use or disclose sensitive personal information to infer characteristics about you for advertising purposes.
### 11.3 Rights Under Other U.S. State Laws
Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have analogous rights of access, correction, deletion, portability, and opt-out of targeted advertising, and — where applicable — the right to appeal a denied request. Texas residents and others may also be protected by state laws governing consumer health data; we treat all health data as requiring affirmative consent.
### 11.4 How to Exercise Your Rights
Submit requests by emailing Services@fit-pulse.net, or use the in-app controls under Settings → Privacy, which include data export and account deletion. We will acknowledge your request promptly and respond within thirty (30) days (GDPR) or forty-five (45) days (CCPA/CPRA), with a single permitted extension where reasonably necessary and with notice to you. We may need to verify your identity by confirming control of the email address on your account. Authorized agents may submit requests on your behalf with written authorization. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
---
## 12. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy.
| Data category | Retention period |
| --- | --- |
| Account and profile data | For the life of the account, then deleted within 30 days of deletion request |
| Health, biometric, nutrition, and workout logs | For the life of the account, then deleted within 30 days |
| Cached WHOOP data and OAuth tokens | Deleted within 30 days of disconnection or account deletion |
| Camera / video frames | Not retained — discarded from memory in real time |
| Diagnostic and crash logs | Up to 90 days |
| Aggregated, de-identified analytics | Retained indefinitely in a form that cannot be re-identified |
| Support correspondence | Up to 24 months |
| Transaction and subscription records | As required by tax and accounting law, typically up to 7 years |
Following account deletion, residual copies may persist in encrypted backups for a limited period and are overwritten on the normal backup rotation cycle.
---
## 13. Security
We implement technical and organizational measures appropriate to the sensitivity of the data we process, including: TLS 1.2 or higher for all data in transit; AES-256 encryption for data at rest; encrypted storage of OAuth tokens in the iOS Keychain and in hardened server-side secret storage; role-based access control with least-privilege provisioning and multi-factor authentication for administrative access; audit logging of access to health data stores; periodic security review and dependency patching; and vendor due diligence before onboarding processors.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it as required by Article 33 GDPR, and will notify affected users without undue delay where required by applicable law.
---
## 14. International Data Transfers
We are based in the United States, and our infrastructure and certain processors are located in the United States and other jurisdictions. Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by technical measures such as encryption in transit and at rest, and by transfer impact assessments where required. You may request further information about these safeguards at Services@fit-pulse.net.
---
## 15. Children's Privacy
The App is not directed to children and is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children under 16. In the United States, consistent with the Children's Online Privacy Protection Act, we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. Parents or guardians who believe a child has provided information may contact Services@fit-pulse.net for immediate removal.
---
## 16. Health Disclaimer
FitPulse is a general wellness and fitness application. It is not a medical device, is not intended to diagnose, treat, cure, or prevent any disease or condition, and does not provide medical advice. Metrics such as HRV, blood oxygen, respiratory rate, recovery, and strain are provided for informational and self-tracking purposes only. Always consult a qualified healthcare professional before beginning or modifying any exercise, nutrition, or supplementation program, and seek immediate medical attention for any health concern.
---
## 17. Account and Data Deletion
You may delete your account and associated data at any time:
1. In-app: open Settings → Account → Delete Account and confirm.
2. By email: send a deletion request from your registered address to Services@fit-pulse.net.
Upon verified request we will delete your account, profile, health and nutrition logs, cached WHOOP data, and stored integration tokens within thirty (30) days, excluding records we are legally required to retain and de-identified aggregate data that can no longer be associated with you. Deleting your FitPulse account does not delete data stored in Apple Health or in your WHOOP account; those records remain under your control within Apple's and WHOOP's respective services.
---
## 18. Changes to This Policy
We may update this Policy to reflect changes in our practices, our integrations, or applicable law. When we do, we will revise the "Last Updated" date above and, for material changes, provide notice through the App or by email prior to the change taking effect. Where a material change affects processing that relies on your consent — including any change to how health, camera, or advertising data is handled — we will obtain your renewed consent before implementing it. Continued use of the App after the effective date of a non-material change constitutes acceptance of the revised Policy.
---
## 19. Contact Us
FitPulse — Privacy Team
Email: Services@fit-pulse.net
We aim to acknowledge all privacy inquiries within five (5) business days. If you are located in the EEA, the UK, or Switzerland and believe we have not adequately addressed your concern, you may lodge a complaint with your local data protection supervisory authority. California residents may also contact the California Privacy Protection Agency or the California Attorney General's office.
---
© 2026 FitPulse. All rights reserved.