Privacy Policy

Last updated: January 2026

Introduction

Fitness Max is committed to protecting your privacy. This privacy policy explains how we collect, use and protect your personal data when you use our application.

Data Collected

We collect the following types of data:

  • Account Data: Name, email address, password (encrypted)
  • Profile Data: Date of birth, gender, height, target weight, activity level, fitness goal, diet type
  • Fitness Data: Workout sessions, exercises, sets, reps, weights lifted, body weight history
  • Technical Data: IP address, browser type, session data

Data Use

Your data is used to:

  • Provide and improve our services
  • Calculate your BMI, TDEE and track your progress
  • Improve user experience
  • Send you important notifications about your account

Data Storage

Your data is securely stored on servers hosted by Neon (PostgreSQL database).

Important note: Our database servers are located in the United States. By using our service, you consent to the transfer of your data outside the European Union. Neon complies with security standards and has Standard Contractual Clauses (SCCs) for international transfers.

Data Sharing

We never sell your personal data. We only share your data with:

  • Hosting Provider (Vercel): For application hosting
  • Authentication Services (Google OAuth): If you choose to sign in via Google

Cookies

We use cookies for:

  • Essential Cookies: Necessary for application functionality (session, language preferences)
  • Analytics Cookies: To understand how you use our application (with your consent)

Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Portability: Receive your data in a structured format
  • Right to Object: Object to the processing of your data

To exercise these rights, contact us at the address below or use the features available in your Settings section.

Data Retention

Your data is retained as long as your account is active. Upon deletion request, your data will be permanently deleted within 30 days.

Security

We implement appropriate technical and organizational security measures to protect your data: password encryption, HTTPS connections, input validation, access control.

Minors

Our service is not intended for persons under 16 years of age. We do not knowingly collect data from minors.

Changes

We may update this privacy policy. Significant changes will be notified to you by email or through the application.

Contact

For any questions about this policy or your personal data, contact us:

Email: contact@fitnessmax.app