1. Who is the data controller
The controller of your personal data is FitDawg Ltd (“we”, “us”, “our”), a company registered in England and Wales, company number 17153572, registered office in Alton, Hampshire, United Kingdom.
Privacy contact: support@adai.systems
2. Scope
This policy explains how we collect, use, and protect your personal data when you use the FitDawg app (“the App”), and your rights under the UK GDPR, the EU GDPR, and — for US residents — the California Consumer Privacy Act (CCPA/CPRA).
3. What data we collect
The table below maps directly to what the App actually stores. Fields marked 🩺 are “special category” health data under UK/EU GDPR Article 9.
| Category | Specific data | Source |
|---|---|---|
| Account & identity | Email address, password (hashed), account creation date | You, at sign-up |
| Profile | Username, display name, short bio, avatar, theme preferences | You |
| 🩺 Body metrics | Weight, height, age, gender | You, in goals/profile |
| 🩺 Fitness goals | Calorie, protein, carb, fat, water, step, active-calorie, and sleep goals | You |
| 🩺 Workout data | Workout type, duration, calories burned, distance, speed, elevation, exercise breakdown, notes | You, during workouts |
| 🩺 Precise location | GPS route (latitude, longitude, timestamps) recorded during an active running/walking/cycling workout | Your device, only while a route workout is active — routes are stored locally on your device only and are not uploaded to our servers. We only receive workout summaries (distance, speed, calories) |
| 🩺 Nutrition data | Logged meals, meal names, calories, macros, meal photos | You / AI meal analysis |
| 🩺 Daily health summaries | Steps, distance, calories eaten/burned, macros, water, weight, workout minutes | Derived from your logs and connected integrations |
| 🩺 Imported third-party activity | Steps, weight, workouts, distance, and calories imported from Health Connect, Strava, Fitbit, or Withings | Only if you connect that service |
| Integration credentials | OAuth access/refresh tokens and provider account IDs for connected services, stored encrypted server-side and never on your device | The service you connect |
| Gamification & social | XP, streaks, gems, badges, trophies, cosmetics, daily quests, friendships, league memberships/history, in-app notifications | Generated by your use |
| Purchases & subscription | FitDawg Pro status and billing period, gem-pack purchase records (verified via Google Play, no card details touch our systems) | Your purchase activity via Google Play |
| Technical | App version and basic technical logs needed to run the App | Automatically |
We do not currently use third-party analytics or advertising SDKs, and we do not run advertising in the App.
4. Special category (health) data
Much of the data above is health and fitness data, which is “special category data” under UK/EU GDPR Article 9. We process it only on the basis of your explicit consent (Article 9(2)(a)), given by choosing to enter it, record a workout, log a meal, or connect a health integration. You can withdraw consent at any time by deleting the data, disconnecting an integration, or deleting your account. Withdrawing consent does not affect processing already carried out.
5. Legal bases for processing (UK/EU GDPR)
| Purpose | Legal basis |
|---|---|
| Creating and running your account; core features | Contract (Art. 6(1)(b)) |
| Processing health, fitness, location, and nutrition data | Explicit consent (Art. 9(2)(a)) |
| Sending your meal photo to our AI provider | Explicit consent (you initiate each scan) |
| Keeping the App secure, preventing abuse, fixing bugs | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations (e.g. tax records) | Legal obligation (Art. 6(1)(c)) |
6. How we use your data
- To provide and personalise your fitness tracking, gamification, and social features.
- To calculate XP, streaks, leagues, and leaderboards.
- To provide AI meal-photo nutrition estimates (Pro feature — see Section 8).
- To import and display activity from health integrations you connect.
- To operate FitDawg Pro subscriptions and gem purchases.
- To keep the App secure and to comply with law.
We do not sell your personal data, and we do not use it for third-party advertising or cross-app tracking.
7. Who we share data with
We use the following third parties to run the App. They act as our processors (or independent controllers where noted) so you know exactly where your data goes.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, storage, serverless functions | All account, profile, health, and app data |
| OpenAI | AI meal-photo nutrition analysis | The meal photo you scan, and your local time, per scan |
| Google Play | Subscription and gem-pack billing | Purchase tokens; no card details reach us |
| Expo / EAS | App builds and over-the-air updates | App/update delivery, basic technical data |
| Google Maps | Displaying maps of your workout routes | Map tile requests |
| Health Connect, Strava, Fitbit, Withings | Optional health/activity import you initiate | The scopes you approve |
We may also disclose data where required by law, to protect our rights, or as part of a business transfer (on notice).
8. AI meal analysis
If you use the Pro AI meal scan, the photo you capture and your device's local time are sent to OpenAI (in the United States) to estimate the meal's nutritional content. This estimate is approximate and is not nutritional or medical advice. Under OpenAI's API terms, data submitted via the API is not used to train OpenAI's models by default. The photo itself is not stored by our servers after the scan — only the resulting nutrition numbers you save are kept.
9. International data transfers
Some of our providers (OpenAI, Expo, Google) are located in the United States. Where we transfer personal data outside the UK/EU, we rely on appropriate safeguards such as the UK International Data Transfer Agreement/Addendum and the EU Standard Contractual Clauses, or an adequacy decision where one applies. You can request details of the safeguards at the privacy contact above.
10. How long we keep your data
- We keep your personal data for as long as your account is active.
- When you delete your account (Settings → Delete account), we permanently delete your account and associated personal data from our live systems. Encrypted backups are overwritten on our provider's normal backup-rotation cycle.
- We may retain limited records where required by law (for example, transaction records for tax purposes) for the statutory period.
- Aggregated or anonymised data that no longer identifies you may be retained.
11. Your rights
Under UK/EU GDPR you have the right to access your data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.
You can exercise many of these rights directly in the App (edit your profile, disconnect integrations, delete your account). For any other request, contact us at the privacy address above. We will respond within one month.
California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. You will not be discriminated against for exercising your rights.
12. Children's privacy
The App is for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, contact us and we will delete it.
13. Security
We use industry-standard measures to protect your data, including encryption in transit, access controls, and row-level security so users can only access their own data. OAuth tokens for integrations are stored encrypted server-side and are never exposed to the app client. No system is perfectly secure; we cannot guarantee absolute security.
Note: profile pictures are stored in a publicly readable storage bucket, meaning an avatar image URL is accessible without authentication — common practice for social avatars, and disclosed here for transparency.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will notify you through the App or by updating the “Last updated” date, and — where legally required — seek fresh consent.
15. Contact
For any privacy question or to exercise your rights, contact us at support@adai.systems. See also our Terms of Service.