photofit is a workout-logging app that identifies gym equipment from your camera and generates training plans. This policy explains what we collect, why, and who we share it with. It describes the app's actual behaviour, not a generic template.
Controller under the GDPR:
Boris Kantorovich
Gritznerstraße 4
12163 Berlin
Germany
Email: hello@itsbor.is
When you create an account we store your email address and a securely hashed password, handled by our authentication provider (Supabase). We never see or store your password in readable form.
During onboarding and use of the app you may provide:
| Data | Why | Optional? |
|---|---|---|
| Training goal, experience level, sessions per week, gym type | To generate a training plan | Required to finish onboarding |
| Display name | Shown in the app | Optional |
| Sex | Tailors plan and exercise selection | Optional |
| Body weight | Progress tracking and plan calibration | Optional |
| Injuries and physical limitations (free text) | To avoid unsuitable exercises | Optional |
| Workouts, exercises, sets, repetitions, weights, dates | The core logging function | Created by using the app |
| Streaks, personal records, achievements | Progress features | Derived from your logs |
Health-related data. Body weight, sex and injury information are data concerning health under Article 9 GDPR. We process them only on the basis of your explicit consent, given when you choose to enter them. Every one of these fields is optional — the app works without them, and you may clear them at any time in your profile.
This is the part most people want to know about, so precisely:
We use PostHog to understand how the app is used. We record a fixed,
closed list of product events: machine_scanned,
paywall_viewed, subscription_started,
onboarding_started, onboarding_blocker_selected,
plan_generated, account_created,
promo_applied. Once signed in, these events are linked to your
user ID and email address. PostHog additionally collects standard technical
information such as device model, operating system version, app version and
session timing. We do not use advertising identifiers, and we do not track
you across other apps or websites.
Paid subscriptions are processed by Apple. We never receive your payment card details. When subscriptions are enabled, we use RevenueCat to record subscription status against your user ID. During the current beta, subscriptions are disabled and no purchase data is collected.
| Purpose | Basis |
|---|---|
| Providing the account and core app features | Performance of a contract, Art. 6(1)(b) |
| Health-related profile fields (weight, sex, injuries) | Explicit consent, Art. 9(2)(a) |
| Equipment identification from photos | Performance of a contract, Art. 6(1)(b) |
| Storing a reported photo for accuracy improvement | Consent, Art. 6(1)(a) — given by the explicit attach action |
| Product analytics | Legitimate interest, Art. 6(1)(f), or consent where required |
| Subscription management | Performance of a contract, Art. 6(1)(b) |
We do not sell your data and we do not share it for advertising. We use the following processors:
| Processor | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, profile, workouts, reported photos |
| Anthropic | Vision model that identifies equipment | The scan photo, transiently, at request time |
| PostHog | Product analytics | Events, user ID, email, device metadata |
| Apple | App distribution, TestFlight, payments | Handled under Apple's own privacy policy |
Some of these providers process data outside the European Economic Area, primarily in the United States. Such transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Photos sent for identification are not used to train third-party models.
Account, profile and workout data are kept for as long as your account exists. Scan photos on your device are capped at the 50 most recent. Reported photos are kept until the underlying accuracy issue is resolved, and in any case are deleted with your account. Analytics events are retained according to PostHog's default retention period.
You can permanently delete your account from within the app, under Profile. This immediately deletes your authentication record, profile, plans, workouts, sets and any reported photos, and clears locally stored scan photos from your device. It cannot be undone, and no manual request or email is required.
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interest, and to withdraw consent at any time with effect for the future. Exercise any of these by emailing hello@itsbor.is. You also have the right to lodge a complaint with a supervisory authority in your country of residence.
photofit is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
Data is transmitted over TLS. Database access is restricted per user through row-level security, so one account cannot read another's data. Session tokens are held in the device's secure storage (iOS Keychain).
We will update this policy when the app's data handling changes, and will revise the date at the top. Material changes will be announced in the app.