← Home

Privacy Policy

Effective date: 28 August 2026

Vector Mesa LLC (“we”, “us”) operates the app “F/AI: AI Gym & Fitness Trainer” (“F/AI”, listed in some regions as “F/AI: AI Fitness & Gym Coach”). This policy describes what data the app handles, who else receives it and why, and what you can do about it. It reflects what the app actually does today, not what it might do.

1. Who is responsible

Vector Mesa LLC is the data controller for the processing described here. Contact: help@fitgpt.pro.

2. What we collect

Account. Email address; first and last name. When you sign in with Apple or Google, the name and email come from that account — the app never asks you to type them again. With Sign in with Apple you may choose to hide your email; we then receive Apple’s relay address and nothing else.

What you tell the coach. Your goal, training experience, sex, age, height, weight, available equipment, schedule, sleep and stress answers, injuries and health limitations, and any free-text notes you write. Injuries and limitations are health data, and we treat them as such.

Body data. Body photos you take or upload for body analysis, and the results derived from them (body-fat estimate, somatotype, measurements), plus measurements you enter by hand.

Training data. Workouts, exercises, sets, weights, repetitions, completion times, and the plans generated for you.

Chat. Message text, photos you attach, and voice recordings you dictate.

Purchases. Subscription status, purchase and renewal events, and the store transaction identifiers needed to grant access and to handle refunds.

Technical data. Device model and OS version, app version, language and region, device and installation identifiers, IP address, crash reports and diagnostic logs, and the screens and actions you use inside the app.

Apple Health. If you grant access, the app reads steps, active energy, exercise minutes, heart rate and sleep. This data stays on your device. It is never sent to our servers, to AI providers, or to any analytics service. Apple’s App Review Guideline 5.1.3 forbids sharing HealthKit data with third parties, and we do not.

3. Why we use it

  • To create and maintain your account, and to sign you in.
  • To generate training plans, analyse body photos, answer you in chat, transcribe your voice, and suggest exercise replacements — the core function of the app.
  • To show your progress, statistics and history.
  • To sell and manage subscriptions, and to process refunds.
  • To send push notifications you asked for.
  • To find and fix crashes and defects.
  • To measure how the app is used, and to measure advertising that brought people to it.

4. AI processing: who sees your data and when

The app’s coaching features run on large language models operated by third parties. Nothing is sent to them until you give explicit consent in the app; the consent screen names the providers and the data before the first transmission, and you can withdraw it at any time in Settings → AI data processing. Withdrawing it turns those features off; it does not delete data already sent.

OpenAI receives, depending on the feature you use:

  • chat messages and attached photos, together with the profile facts the coach needs to answer (goal, level, limitations);
  • your questionnaire when a training plan is generated;
  • the exercise being replaced and your equipment and limitations;
  • body photos and your height, weight and age for body analysis;
  • voice recordings, for transcription into text;
  • attached photos, for content moderation before they reach the model.

Google (Gemini) receives your body photo when a transformation image is generated as part of body analysis. No other feature sends data to Google’s AI.

Neither provider receives your name, email, payment details or Apple Health data. We do not use your data to train models, and both providers state that data sent through their business APIs is not used to train theirs.

5. Who else receives data

RecipientWhat it receivesWhy
Supabaseaccount record, questionnaire, plans, workouts, chat history, body-analysis resultsstorage and authentication
Our API serverseverything the app sendsrunning the service
RevenueCatpurchase events, subscription status, an app-specific user identifiersubscription management
Firebase (Google) — Analytics, Crashlytics, Cloud Messagingusage events, crash reports, push token, device identifiersanalytics, crash reporting, push delivery
PostHogusage events and session recordings (see below)product analytics
AppMetrica (Yandex)usage events, device identifiers, install attributionanalytics and attribution
TikTokinstall and purchase events, advertising identifiersadvertising measurement
Apple, Googlesign-in identity when you use their buttonsauthentication

We do not sell your data, and we do not share it with data brokers.

6. Session recordings

PostHog records the screen of a sample of app sessions, linked to your account identifier. Screens carrying personal data — your name, weight, measurements, body-fat estimate, injuries and free text, body photos, chat, and Apple Health figures — are masked, so those pixels are never captured. Masking is verified against real recorded frames and by automated tests. We use recordings to find where people get stuck, and for nothing else.

7. Advertising and tracking

On first launch iOS asks whether the app may track you across other companies’ apps and websites (App Tracking Transparency). If you decline, we do not use the advertising identifier for AppMetrica, and Apple withholds it from the other SDKs. Declining does not switch off product analytics or crash reporting, which we rely on to run the app. We do not show ads inside the app.

8. How long we keep it

Account data, questionnaire, plans, workouts, chat history and body-analysis results are kept while your account exists. Delete the account in Settings → Delete account and they are removed from our systems, except where we must retain records to meet a legal obligation (for example, tax records of a purchase). Analytics events and session recordings expire on the providers’ retention schedules and are not restored by deleting your account. Crash reports are kept up to 90 days.

9. Your rights

Depending on where you live, you may request access to your data, correction, deletion, restriction of processing, portability, and withdrawal of consent. You can delete your account yourself in the app; for anything else write to help@fitgpt.pro and we will answer within 30 days. You may also complain to your local data protection authority.

10. International transfers

Our recipients operate in the European Union, the United States and Russia, so your data may be processed outside your country. Where required, transfers rely on the European Commission’s standard contractual clauses.

11. Children

The app is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.

12. Security

Data travels over encrypted connections. Access tokens are held in the iOS Keychain; the app never stores backend service keys. Access to production data is limited to people who need it.

13. Changes

We update this policy when the app changes. Material changes are announced in the app; the effective date at the top always shows the current version.

14. Contact

help@fitgpt.pro