At a glance
The public website includes marketing pages and interactive demonstrations. Creating an account stores identity and account-preference data, but dashboard, coach, workout, progress, and AI examples still use sample data and do not create a member health record.
The browser receives HttpOnly, SameSite session cookies from the private HealthFit API. Administrator roles are stored and enforced on the server; changing browser data cannot grant privileged access.
Information collected today
How the information is used
- Create, verify, recover, secure, and administer HealthFit accounts.
- Apply the selected plan and authorized role.
- Protect authentication and administrative services from abuse.
- Manage editorial publishing and documented platform settings.
- Respond to questions, diagnose failures, meet legal obligations, and enforce the Terms.
HealthFit does not sell account information or personal health data for advertising.
Storage, service providers, and retention
Account identity is processed through the private HealthFit API and self-hosted Supabase Auth/PostgreSQL. Browser roles have no direct access to profile, content-control, platform-setting, or audit tables. Privileged credentials remain in the server container.
A final retention schedule, processor list, hosting region, deletion SLA, backup-retention period, and international-transfer position must be approved before broad paid release. Historical pre-account registration data remains private and must be migrated or deleted under that approved schedule.
Your choices
- Do not create an account if you do not want to provide the required identity information.
- Use password recovery when you lose access; responses do not reveal whether an email is registered.
- Email privacy@healthfit.ai to request access, correction, export, or deletion.
- Sign out to clear the HealthFit session cookies from the current browser.
Identity verification or recent reauthentication may be required before acting on a request involving stored personal information.
Future health product
Future account features may process check-ins, goals, constraints, workouts, meal patterns, recovery signals, connected-device data, and coach relationships. Those health-data flows are not implemented by the current account and administration release. They require additional reviewed purposes, consent controls, authorization rules, retention, export/deletion tooling, and security evidence before activation.
Questions or concerns
Contact privacy@healthfit.ai. For security concerns, use security@healthfit.ai. Do not use either address for emergencies or urgent medical help.