fitt
Back

Privacy Policy

Last updated: May 7, 2026

fitto Technologies S.L. ("fitto", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the fitto platform and related services. It applies to all users worldwide and is designed to comply with applicable data protection regulations, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and other applicable laws.

1. Data Controller

The data controller is: fitto Technologies S.L. Calle Serrano 41, 28001 Madrid, Spain Email: info@fitto.fitness For EU/EEA users, fitto Technologies S.L. acts as the data controller under the GDPR.

2. Data We Collect

We collect the following categories of personal data: • Identity & Contact Data: full name, email address, phone number. • Profile & Health Data: age, gender, height, weight, goal weight, health conditions, medications, dietary restrictions, food preferences, fitness level, physical limitations. This data may qualify as special category data under the GDPR (health data); we collect it only with your explicit consent. • Preferences & Goals: activity level, sleep habits, stress level, fitness goals, workout preferences. • Usage Data: log-in timestamps, pages visited, features used, interactions with AI-generated plans. • Technical Data: IP address, browser type and version, operating system, device identifiers, time zone. • Payment Data: payment method details (processed and stored by Stripe; we do not store full card numbers). • Communications: emails, support tickets, and other correspondence you send us.

3. How We Collect Data

We collect your data: • Directly from you: when you register, complete the onboarding questionnaire, update your profile, or contact support. • Automatically: through cookies, log files, and similar tracking technologies when you use the Service. • From third parties: from Stripe (payment confirmation), and from authentication providers if applicable.

4. Legal Bases for Processing (GDPR)

For users in the EU/EEA, we rely on the following legal bases: • Contract performance (Art. 6(1)(b)): to provide the Service, generate your plans, and manage your subscription. • Explicit consent (Art. 9(2)(a)): to process special category health data you provide in your profile and questionnaire. • Legitimate interests (Art. 6(1)(f)): for fraud prevention, security, product analytics, and improving the Service, where our interests do not override your rights. • Legal obligation (Art. 6(1)(c)): where processing is required by applicable law (e.g., tax records, regulatory compliance). • Consent (Art. 6(1)(a)): for marketing emails and non-essential cookies, where required. You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. How We Use Your Data

We use your personal data to: • Create and manage your account and subscription. • Generate personalised weekly meal and training plans via AI. • Process payments and send billing notifications. • Send service notifications, including plan readiness emails. • Respond to your support requests. • Improve and personalise the Service through analytics. • Comply with legal obligations. • Detect and prevent fraud and abuse. • Send marketing communications (only where you have consented or where permitted by law, and always with an easy opt-out).

6. Health & Special Category Data

Information about your health conditions, medications, dietary restrictions, and physical limitations is considered special category data under the GDPR. We collect and process this data only based on your explicit consent, which you provide when completing the onboarding questionnaire. This data is used exclusively to generate your personalised plans and is never shared with third parties for advertising purposes. You may withdraw your consent at any time by deleting your profile data.

7. AI-Generated Plans and Automated Decision-Making

fitto uses AI to generate personalised plans based on your profile data. This involves automated processing but does not produce legally significant decisions about you. Under the GDPR, you have the right not to be subject to solely automated decisions that produce significant effects; if you believe an automated decision has adversely affected you, you may contact info@fitto.fitness to request human review.

8. Data Sharing and Disclosure

We do not sell your personal data. We may share it with: • Service providers: Stripe (payments), Base44 (infrastructure and database), email delivery providers, analytics tools — all bound by data processing agreements. • Legal authorities: where required by law, court order, or to protect our legal rights. • Business transfers: in connection with a merger, acquisition, or sale of assets, in which case you will be notified. All data processors are required to process data only on our instructions, maintain appropriate security, and comply with applicable data protection laws. Where data is transferred outside the EU/EEA, we ensure adequate safeguards (Standard Contractual Clauses or equivalent).

9. International Data Transfers

Your data may be processed on servers located in the European Union or the United States. Where we transfer data outside the European Economic Area, we do so only where adequate protections are in place, such as the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms. You may request a copy of the applicable safeguards by contacting info@fitto.fitness.

10. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically: • Account and profile data: retained while your account is active and for up to 3 years thereafter for legal compliance. • Health/preference data: deleted or anonymised within 90 days of account deletion. • Payment records: retained for 7 years as required by Spanish and EU tax law. • Usage and analytics data: anonymised or deleted within 24 months. You may request earlier deletion at any time (see Your Rights below).

11. Cookies and Tracking

We use cookies and similar technologies for: • Essential cookies: required for the Service to function (authentication, session management). • Analytics cookies: to understand how users use the Service (e.g., page views, feature usage). We use privacy-respecting analytics tools. • Marketing cookies: only with your explicit consent. You can control cookies via your browser settings. Refusing non-essential cookies will not affect core functionality. We will present a cookie consent banner to users in jurisdictions that require it.

12. Your Rights

Depending on your location, you may have the following rights regarding your personal data: • Right of access: to obtain a copy of your personal data. • Right to rectification: to correct inaccurate data. • Right to erasure ("right to be forgotten"): to request deletion of your data. • Right to restriction: to restrict processing in certain circumstances. • Right to data portability: to receive your data in a structured, machine-readable format. • Right to object: to object to processing based on legitimate interests or for direct marketing. • Right to withdraw consent: at any time for consent-based processing. • Right not to be subject to automated decisions with significant effects. California residents have additional rights under CCPA/CPRA, including the right to know, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information. Brazilian users have rights under the LGPD including access, correction, deletion, anonymisation, data portability, and information about sharing. To exercise your rights, contact info@fitto.fitness. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

13. Data Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (TLS) and at rest, access controls, regular security assessments, and data minimisation practices. However, no method of transmission over the Internet or electronic storage is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay.

14. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided personal data without appropriate parental consent, we will delete that information promptly. If you believe we may have collected data from a child under 16, please contact info@fitto.fitness.

15. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policies of any third-party services you visit.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before the changes take effect. The "Last updated" date at the top indicates when the policy was last revised. Continued use of the Service after changes constitutes acceptance.

17. Supervisory Authority

EU/EEA users have the right to lodge a complaint with their national data protection supervisory authority. The lead supervisory authority for fitto is the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD): www.aepd.es. UK users may contact the Information Commissioner's Office (ICO): ico.org.uk.

18. Contact and DPO

For privacy-related questions, requests, or complaints: Email: info@fitto.fitness Postal address: fitto Technologies S.L., Calle Serrano 41, 28001 Madrid, Spain If required by applicable law, we will appoint a Data Protection Officer (DPO); their contact details will be published here.