TRUST CENTER · PRIVACY

Your body. Your data.

This notice explains HealthFit accounts, the public website, protected administration, and the current product demonstrations. It separates implemented data flows from future health-product capabilities.

Version 1.0Updated 18 July 2026English
Legal review requiredThis factual notice reflects the implemented account architecture, but final controller details, launch geography, retention decisions, and counsel approval are still required before broad paid release.

At a glance

The public website includes marketing pages and interactive demonstrations. Creating an account stores identity and account-preference data, but dashboard, coach, workout, progress, and AI examples still use sample data and do not create a member health record.

Your session is protected.

The browser receives HttpOnly, SameSite session cookies from the private HealthFit API. Administrator roles are stored and enforced on the server; changing browser data cannot grant privileged access.

Information collected today

Website visitThe current build does not include advertising trackers or third-party product analytics. The hosting provider may process standard request information such as IP address, device information, requested path, and timestamp for delivery and security.
AccountName, email address, password verifier managed by Supabase Auth, selected plan, locale, consent-notice version, account role, status, and security timestamps. HealthFit does not store your plain-text password.
AdministrationInvitations, role and status changes, editorial actions, platform-setting changes, the acting administrator, affected record, and timestamp are written to a protected audit log.
MessagesInformation you choose to send to a HealthFit email address. Avoid sending medical records, emergency information, passwords, or highly sensitive health details by email.
Product demonstrationsInteractions with sample workouts, coach views, recommendations, and pricing are simulated and are not yet a persisted member health history.

How the information is used

  • Create, verify, recover, secure, and administer HealthFit accounts.
  • Apply the selected plan and authorized role.
  • Protect authentication and administrative services from abuse.
  • Manage editorial publishing and documented platform settings.
  • Respond to questions, diagnose failures, meet legal obligations, and enforce the Terms.

HealthFit does not sell account information or personal health data for advertising.

Storage, service providers, and retention

Account identity is processed through the private HealthFit API and self-hosted Supabase Auth/PostgreSQL. Browser roles have no direct access to profile, content-control, platform-setting, or audit tables. Privileged credentials remain in the server container.

A final retention schedule, processor list, hosting region, deletion SLA, backup-retention period, and international-transfer position must be approved before broad paid release. Historical pre-account registration data remains private and must be migrated or deleted under that approved schedule.

Your choices

  • Do not create an account if you do not want to provide the required identity information.
  • Use password recovery when you lose access; responses do not reveal whether an email is registered.
  • Email privacy@healthfit.ai to request access, correction, export, or deletion.
  • Sign out to clear the HealthFit session cookies from the current browser.

Identity verification or recent reauthentication may be required before acting on a request involving stored personal information.

Future health product

Future account features may process check-ins, goals, constraints, workouts, meal patterns, recovery signals, connected-device data, and coach relationships. Those health-data flows are not implemented by the current account and administration release. They require additional reviewed purposes, consent controls, authorization rules, retention, export/deletion tooling, and security evidence before activation.

Questions or concerns

Contact privacy@healthfit.ai. For security concerns, use security@healthfit.ai. Do not use either address for emergencies or urgent medical help.