Privacy Policy
Last updated: January 2026
Introduction
Fitness Max is committed to protecting your privacy. This privacy policy explains how we collect, use and protect your personal data when you use our application.
Data Collected
We collect the following types of data:
- Account Data: Name, email address, password (encrypted)
- Profile Data: Date of birth, gender, height, target weight, activity level, fitness goal, diet type
- Fitness Data: Workout sessions, exercises, sets, reps, weights lifted, body weight history
- Technical Data: IP address, browser type, session data
Data Use
Your data is used to:
- Provide and improve our services
- Calculate your BMI, TDEE and track your progress
- Improve user experience
- Send you important notifications about your account
Data Storage
Your data is securely stored on servers hosted by Neon (PostgreSQL database).
Important note: Our database servers are located in the United States. By using our service, you consent to the transfer of your data outside the European Union. Neon complies with security standards and has Standard Contractual Clauses (SCCs) for international transfers.
Data Sharing
We never sell your personal data. We only share your data with:
- Hosting Provider (Vercel): For application hosting
- Authentication Services (Google OAuth): If you choose to sign in via Google
Cookies
We use cookies for:
- Essential Cookies: Necessary for application functionality (session, language preferences)
- Analytics Cookies: To understand how you use our application (with your consent)
Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Portability: Receive your data in a structured format
- Right to Object: Object to the processing of your data
To exercise these rights, contact us at the address below or use the features available in your Settings section.
Data Retention
Your data is retained as long as your account is active. Upon deletion request, your data will be permanently deleted within 30 days.
Security
We implement appropriate technical and organizational security measures to protect your data: password encryption, HTTPS connections, input validation, access control.
Minors
Our service is not intended for persons under 16 years of age. We do not knowingly collect data from minors.
Changes
We may update this privacy policy. Significant changes will be notified to you by email or through the application.
Contact
For any questions about this policy or your personal data, contact us:
Email: contact@fitnessmax.app