Privacy Policy
FoFit collects the data needed to run a fitness app: account, workout, nutrition, community, media, AI coaching, permissions, diagnostics, and support data. We do not sell personal information or use it for cross-app advertising.
Last updated July 14, 2026
Who operates FoFit
FoFit is operated by Kenan Larry in St. Louis, Missouri, United States. Contact support@fofit.app for privacy, support, account, or deletion requests.
Information you provide
- Account information such as email, sign-in provider, display name, profile role, avatar, handle, sport, school, and onboarding answers.
- Workout data such as exercises, sets, reps, weight, RPE, notes, personal records, training plans, sessions, streaks, body metrics, and goals.
- Nutrition data such as meals, macros, hydration, logged foods, saved foods, recipe choices, barcode searches, product results, and meal-photo analysis results.
- Community data such as posts, comments, reactions, follows, blocks, mutes, reports, group memberships, reels, and media you choose to upload. Community post and reel media is stored as public media URLs, so do not upload private information or media you would not want copied.
- Cypher AI content such as chat messages, approved or declined plan actions, structured coach-memory notes, and context needed to answer your request.
Device permissions and media
- Apple Health / HealthKit: with permission, FoFit reads active energy, steps, and workout summaries on your device. Raw HealthKit queries stay on device. If you choose to import a workout, its normalized summary may be saved to your FoFit account for workout history and cross-device sync. Health data is not sold, used for ads, or shared for marketing.
- Camera and photo library: FoFit asks only when you use features such as meal photos, barcode scanning, profile photos, progress photos, reels, or Performance Lab capture. Uploaded media is stored only when you choose to save or publish it. Community uploads are public-facing; progress photos and other private media use separate private storage where applicable.
- Microphone: if you use voice input for Cypher, the audio is sent through FoFit's server proxy to OpenAI Whisper for transcription. FoFit uses the transcript as your message and does not keep the raw audio after transcription.
- Notifications: if you enable reminders or community notifications, FoFit stores your notification preferences and may use device notification tokens where push delivery is supported.
- Location: FoFit may use approximate location for nearby gyms, events, or food spots and rounds it before transmission. If you start an outdoor run or walk recording, FoFit can use precise/background location to record the route. When you are signed in, exact route points are uploaded to FoFit's Supabase backend for private history and cross-device sync; any public route representation is separately sanitized before sharing.
How we use information
- Operate FoFit, keep you signed in, sync account data, and render workouts, nutrition, progress, community, and profile features.
- Personalize coaching, training, nutrition, and Cypher recommendations using the context you give FoFit.
- Moderate community safety, process reports, enforce blocks/mutes, prevent abuse, and preserve App Review demo account integrity.
- Debug crashes, measure reliability, and improve the product without selling your data or using it for cross-app advertising.
- Respond to support, deletion, privacy, export, and legal requests.
AI and Cypher
Cypher is a general fitness assistant, not a medical provider. Messages and selected context are processed through FoFit's server-side proxy before reaching AI providers.
- Anthropic may process Cypher chat responses.
- Google may process Gemini classification/routing requests and Google Places searches.
- OpenAI may process fallback responses, meal-photo image analysis, and Whisper transcription.
- Do not send payment data, regulated medical records, or information you are not comfortable processing through third-party AI services.
Third-party services
FoFit uses service providers to run the app. They process data only as needed to provide their services to FoFit.
- Supabase for authentication, database, storage, edge functions, and account deletion.
- Apple and Google for sign-in, device permissions, App Store services, Apple Health, and Google Places.
- Anthropic, Google, and OpenAI for AI and transcription features described above.
- Sentry for crash diagnostics. FoFit strips email, IP address, and account user id before sending events.
- PostHog for opt-in product analytics; event content excludes workout, nutrition, and chat details.
- Expo/EAS for app builds and updates.
- RevenueCat and Apple may support purchases if paid features are enabled in a future build; FoFit does not receive full payment card numbers.
Account deletion and your rights
You can initiate account deletion in the app from Settings > Profile & Account > Delete account. You can also email support@fofit.app from the email tied to your FoFit account or visit https://fofit.app/delete-account.
Deletion removes your FoFit account row and user-scoped cloud data through the backend deletion flow. Uploaded media is purged from storage on a best-effort basis after the account row is deleted. Rolling backups may retain deleted data briefly before expiry.
- You may ask to access, correct, export, or delete personal information.
- You may opt out of analytics where the app offers that control.
- You can revoke Health, camera, photo, microphone, notification, and location permissions in iOS Settings.
Children and safety
FoFit is not directed to children under 13. Community features require age confirmation and may be unavailable to younger users. If you believe a child provided personal information, contact support and we will review and delete it where appropriate.
FoFit and Cypher provide general fitness and nutrition information. They do not provide medical, diagnostic, emergency, or therapeutic advice.
Contact
Questions about privacy, account deletion, support, or data rights: support@fofit.app. FoFit is operated from St. Louis, Missouri, United States.