Privacy
Last updated: 6 August 2026
This Privacy Policy explains how GHSTSOFT (“we”, “us”) collects, uses, and protects your personal data when you use Fitivo, our AI fitness coaching website and app. We are the controller responsible for your data under the EU General Data Protection Regulation (GDPR). For any privacy question or request, contact us at privacy@fitivo.dev.
1. Data we collect
Account data: your name, email address, and login credentials (passwords are stored only in hashed form) when you create an account or sign in.
Profile and fitness data: the information you provide to personalize your coaching, such as age, gender, height, weight, goals, activity level, workouts, nutrition, and progress. If you connect Apple Health or Withings, we process only the health and activity metrics you choose to share.
AI coach conversations: the messages you send to, and receive from, your AI coach.
Payment data: if you subscribe, payments are handled by our payment provider (Stripe). We do not store your full card details.
Usage and technical data: device and browser information, IP address, and log data generated when you use the service.
2. How we use your data
We use your data to provide and personalize the coaching service, generate AI responses and recommendations, manage your account and authenticate you, process subscriptions and payments, send you service-related emails, keep the service secure and prevent abuse, improve our features, and comply with our legal obligations.
3. Legal bases for processing
We process your data on the following legal bases under the GDPR: performance of a contract (Art. 6(1)(b)) to provide the service you signed up for; your consent (Art. 6(1)(a)) for optional data such as Apple Health or Withings, which you can withdraw at any time; our legitimate interests (Art. 6(1)(f)) in securing and improving the service; and legal obligations (Art. 6(1)(c)), for example for tax and accounting.
Health and fitness data is a special category of data under Art. 9 GDPR. We process it only on the basis of your explicit consent, which you give by choosing to enter it or connect Apple Health or Withings, and which you can withdraw at any time.
4. Service providers and where your data is stored
We rely on a small number of service providers that process data on our behalf as processors under data-processing agreements:
Neon: your account, profile, fitness, and conversation data is stored in a managed PostgreSQL database provided by Neon.
Cloudflare: our website and app are hosted on Cloudflare’s global network, and our transactional emails are sent through Cloudflare.
OpenRouter: the messages you exchange with the AI coach are routed through OpenRouter, which forwards them to the AI model that generates the response.
Stripe: subscription payments are processed by Stripe.
Withings: if you connect your Withings account, we receive from Withings the health and activity measurements you authorize.
Apple Health data stays on your device; we receive only the metrics you explicitly choose to share.
5. AI processing
To answer you, your conversations are sent through OpenRouter to third-party AI models solely to generate a response. We do not use your conversations to train our own models, and where our providers offer such controls we request that your data not be used to train theirs. Please avoid sharing sensitive information you would not want processed by an AI model.
6. International data transfers
Some of our providers may process data outside the EU/EEA, for example in the United States. Where that happens, the transfer is safeguarded by the European Commission’s Standard Contractual Clauses or an adequacy decision.
7. Data retention
We keep your personal data for as long as your account is active. When you delete your account, we delete or anonymize your data within a reasonable period, except where we are required to retain certain records to meet legal obligations.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw any consent at any time. To exercise these rights, contact us at privacy@fitivo.dev.
You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
9. Data security
We protect your data with encryption in transit, hashed password storage, and access controls that limit who can reach your data. No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organizational measures.
10. Children
Fitivo is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us at privacy@fitivo.dev and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where changes are significant, notify you within the app.