Fit Assist is published by John Abish, an individual developer operating as a sole proprietor in Ontario, Canada, who is the data controller (in Canadian terms, the organization accountable) for the personal information described here. For any privacy question or request, contact support@giftsonx.com.
During setup and while using the app: your email address (when you create an account); your sex, age, height, weight, and optionally body-fat percentage; your goal, target weight, target date, and pace; the body shape you choose as your target; activity level and training experience; diet preference, meal pattern, allergens, and food dislikes; training availability, environment, and equipment; the health-screening answers described in section 5; any measurement you enter by hand to correct a scan result (a tape measurement, for example); and the short note you can add to a meal scan.
For a body scan: two photos of you — front and side — taken with the camera or chosen from your photo library, plus, during guided capture, a short burst of framing-check frames. For a meal scan: one photo of your food, taken or chosen. Sections 3 and 4 say exactly what happens to each; the short version is that they are analyzed and immediately discarded, and a photo is never stored on our servers.
Weigh-ins you log, foods you log (including custom foods you create), workout sets and completions, routines you build, the plans we generate for you, weekly and daily adaptation decisions, and a closed set of first-party product-analytics events (for example "plan revealed", "food logged", "body scan captured"). Analytics events use a fixed vocabulary and carry no free-text content and no photos.
From the body scan: your estimated measurements with their uncertainty ranges, the shape values of your 3D model, the decisions you make when the app asks you to check a reading (keep it, measure with a tape, redo, or discard), and a body-fat estimate that is computed from your stored measurements each time you view it. From the meal scan: the list of foods and portions the analysis suggested, which you then edit before anything is logged. From barcode lookups: the product you scanned.
If you sign in with Google, Google shares your email address and basic profile with our sign-in provider, Clerk, to create your account, under Google's own privacy policy. From Google Play via RevenueCat we receive your subscription entitlement state and purchase events. We never receive or store your payment card or billing details — Google is the merchant of record.
The body scan estimates tape-style body measurements — neck, chest, waist, hips, thighs, arms and similar sites — and builds a 3D model of your body shape, from two photos and your height (plus your most recent logged weight, if it is recent). Here is the full picture.
Before your first scan the app shows a dedicated consent screen explaining what the scan looks at, what happens to the photos, and what the numbers can and cannot tell you. Each scan records the version of that screen you accepted. If the wording changes in a way that matters, you are asked again before the next scan.
Two downscaled JPEG copies of your photos; a cryptographic fingerprint (SHA-256) of each; your height and, if recent, your latest weight; and, during guided capture, a few framing-check frames so the app can tell you to step back or straighten up before the real shot.
Photos are processed by our own measurement model, on our own server. No third-party AI service ever sees a body-scan photo. The photos are held in memory only for the seconds the analysis takes and are then discarded: they are never written to disk or a database, never logged, and never attached to error reports. Framing-check frames are handled the same way and produce no stored record at all.
For each completed scan: the estimated measurements with their uncertainty ranges; the shape values that define your 3D model (a handful of numbers, not a photo); the fingerprint of each photo, which cannot be turned back into the image and exists so we can prove a result came from a given photo and reject mismatches; the height and weight the scan used; the model and consent versions; the time of the scan; and any coach-check decision or tape measurement you entered. Your body-fat estimate is recalculated from those stored measurements whenever you view it and is not itself stored.
We do not use your photos or your measurements to identify you. The scan performs no facial recognition and builds no biometric template. Your 3D model is a generic body shape fitted to your measurements, not a likeness of you.
Measurements are estimates, produced by software that is in beta calibration. Every value is shown with its uncertainty range, and at some sites the typical difference from a real tape measure is several centimetres. They are not medical measurements, they are not a diagnosis of anything, and they must not be used to make medical decisions. If you need a number you can rely on, use a tape — the app lets you enter one in place of any estimate.
The first body scan can happen during setup, before you create an account. That scan is anonymous: its results are keyed to a session identifier, not to a person, and are kept for 48 hours. If you create an account within that time, the scan becomes the first scan on your account; if you do not, it is deleted automatically. You can also skip the photos and get a statistical preview from your height, weight and sex alone — no photo is involved in that path.
The originals and the upload copies stay in the app's private storage on your phone — not in your gallery, unless you chose them from there. You can delete them from the scan itself at any time, and uninstalling the app removes them.
You can delete any individual scan from within the app. That permanently erases its measurements, model and fingerprints — this is a true deletion, not de-identification. Deleting your account erases every scan, onboarding preview and body target at once (section 11).
When you scan a meal, the photo, your optional note, and the meal slot are sent to our server and from there to Anthropic, PBC (United States), the company that makes the Claude AI models, acting as our service provider. Anthropic returns a suggested list of foods and portions, which the app shows you as an editable draft; nothing is logged until you confirm it. The same path handles a typed description without a photo.
Anthropic processes your photo and note only to return that result. Under its commercial terms it does not use your inputs to train its models, and it deletes inputs and outputs within 30 days, except where it must keep them longer to enforce its usage policies or comply with law. We do not store the photo at all — it is held in our server's memory for the request and discarded; we store only the structured result and a record that a scan happened, which is how the free tier's daily scan allowance is counted.
Photograph the food, not people. If a photo does include a person, it is processed in exactly the same way — for the food only — and is never stored.
When you scan a product barcode, our server looks the number up in Open Food Facts, a non-profit open food database based in France. Only the barcode number is sent, from our server: Open Food Facts does not receive your account, your device identifier or your IP address. We cache product information (name, brand, nutrition per 100 g) on our server for up to 30 days so repeated lookups are fast. That cache holds product information, not personal information. Product data is used under the Open Database License, with attribution shown in the app.
To keep plans safe, setup asks about health matters: injuries, disclosed medical conditions, pregnancy status, and screening for active eating disorders. Together with your body measurements — stated, logged, or estimated by the body scan — your body-scan photos, your body-fat estimate, and the foods you log or photograph, this is health information, a sensitive category of personal data.
We process it only with your explicit consent, which the app asks for as its own step during setup, separately from your acceptance of the Terms, and — for the body scan — on a separate consent screen before your first scan. We use it solely to run safety screening, generate your plan, adapt it over time, and show you your own measurements and trends. It is never used for advertising and never sold. If you withdraw consent, the app cannot function, and the way to withdraw is to delete your account (section 11).
| Purpose | Basis |
|---|---|
| Generating your meal and workout plan | Performing our contract with you |
| Weekly and daily plan adaptation from your logs | Performing our contract with you |
| Estimating body measurements and building your 3D model from your photos; showing your trends | Your explicit consent (the scan consent screen) and performing our contract with you |
| Analyzing a meal photo into a draft food log | Performing our contract with you |
| Safety screening, calorie floors, and the disclaimer audit trail | Legal obligation / legitimate interest in a tamper-evident safety record |
| Product analytics on a closed, first-party event set | Legitimate interest in improving the app |
| Server error monitoring | Legitimate interest in keeping the service working |
| Managing your subscription entitlement | Performing our contract with you |
| Local reminders | Your consent (opt-in) |
We do not send marketing email, and we make no decisions about you by automated means that have legal or similarly significant effects.
We share personal information only with the service providers below, only so they can provide their service to us, and never for their own advertising. We do not sell your personal information, we do not share it for advertising, and the app contains no advertising or third-party analytics SDKs. (Error monitoring runs on our server, not in the app.)
| Provider | Role | Data it receives | Location |
|---|---|---|---|
| Clerk, Inc. (privacy) | Sign-in and accounts | Email address, sign-in metadata, session tokens | United States |
| Google LLC — Sign in with Google (privacy) | Optional sign-in method | Only if you choose it: your sign-in request, under Google's policy | Global |
| RevenueCat, Inc. (privacy) | Subscription management | A pseudonymous user ID and purchase/entitlement events | United States |
| Google LLC — Google Play Billing (privacy) | Payment processing (merchant of record) | Your payment details go to Google directly; we receive only entitlement state | Global |
| Google — Health Connect | On-device health data store | Weight records are read on your device with your permission (section 9) | On your device |
| Anthropic, PBC (privacy) | Meal photo analysis (AI service provider) | Meal photos, your meal-scan note and meal slot — nothing else; never body-scan photos (section 4) | United States |
| Open Food Facts (privacy) | Product database for barcode lookup | The barcode number only, sent from our server — no account, device or IP data | France (EU) |
| Functional Software, Inc. — Sentry (privacy) | Server error monitoring | Technical details of server errors: endpoint, time, error type and request metadata, which may include a pseudonymous user or scan ID. Never photos, never request bodies, never your email | United States |
| Railway Corp. (privacy) | Application hosting and database | All server-side data described in this policy, encrypted in transit | United States |
Fonts and all app assets are bundled into the app at build time — the app makes no runtime requests to font or asset services that could expose your IP address to them.
Our servers and database are hosted by Railway in the United States, and Anthropic and Sentry process data there too; Open Food Facts is in France. If you use Fit Assist from Canada, the EEA, the UK, or elsewhere, your information is transferred to and processed in the United States, where laws may differ from those of your home jurisdiction. For EEA/UK users, transfers rely on appropriate safeguards such as Standard Contractual Clauses maintained by our providers. For Canadian users: comparable protection is required of our providers by contract, and this policy is your notice of processing outside Canada.
On Android, Fit Assist can read your weight from Health Connect. In full:
| Category | How long |
|---|---|
| Photos — body scan, meal scan, framing-check frames | Not stored on our servers. Processed in memory and discarded within the request. Meal photos sent to Anthropic are deleted by Anthropic within 30 days (section 4). Copies stay on your phone until you delete them or uninstall the app |
| Body scans: measurements, 3D-model shape values, photo fingerprints, coach-check decisions, tape entries, body target | Until you delete the scan or your account — then erased, not de-identified |
| Anonymous onboarding scan preview | 48 hours, then automatically deleted — or converted into your first scan if you create an account in that time |
| Meal-scan results (foods and portions — no image) | While your account is active; after deletion, retained only in de-identified form (section 11) |
| Barcode product cache | Product information only, not personal information; refreshed at least every 30 days |
| Account identifiers (email, sign-in identity, device ID) | Until you delete your account — then erased immediately and permanently |
| Plans, logs, screening answers, adaptation records | While your account is active; after deletion, retained only in de-identified form (section 11) |
| Safety-screening and disclaimer acceptance audit trail | Retained as a tamper-evident record for legal-protection purposes; de-identified after account deletion |
| Purchase/entitlement records | Retained for tax and accounting purposes; de-identified after account deletion |
| Server error reports (Sentry) | Up to 90 days |
| Server access logs | Approximately 30 days |
Depending on where you live, you have rights to access, correct, export, and delete your personal information, to object to or restrict certain processing, to withdraw consent, and to complain to your privacy regulator (in Canada, the Office of the Privacy Commissioner of Canada; in the EEA/UK, your supervisory authority; in California, the Attorney General or CPPA). To exercise any of these rights, email support@giftsonx.com — we respond within 30 days. You can request a copy of your data by email; we provide it in a portable electronic format.
Deleting one body scan (in the app, from the scan itself) permanently erases that scan's measurements, model and fingerprints.
What account deletion actually does. When you delete your account (in the app: your profile → Account → Delete account, or via our deletion page), we immediately and permanently erase everything that identifies you — your email address, your sign-in identity, your device identifier, and the link between your account and your subscription — and every body scan, onboarding scan preview, and body target, because a measurement series should not outlive the person it describes, even anonymously. Some other records — the weights you logged, the plans we generated, the food and portion lists from meal scans, and our safety-screening audit trail — are held in a tamper-evident, append-only store that we cannot edit after the fact; this is a deliberate safety and integrity design and, for the safety audit trail, a legal record-keeping measure. Those records survive deletion, but they are stripped of every identifier and are no longer associated with you or any account. We cannot re-link them to you, and neither can anyone else.
Fit Assist is for adults 18 and over. Setup asks your age and exits for anyone under 18. Do not scan or photograph anyone other than yourself. We do not knowingly collect personal information from minors; if we learn that we have, we will delete it.
All data is encrypted in transit (HTTPS). Your sign-in token is stored on your device in the platform's secure storage. Server credentials and secrets are kept in a secrets manager, never in source code. Photos are never written to disk, to a database, to logs, or to error reports — the analysis path is designed so there is nothing to breach. Safety-critical records are protected by database-level append-only enforcement, and account deletion uses a cryptographic-shredding design so identifier removal is immediate and irreversible. No system is perfectly secure, and we do not claim to be unbreachable — but we designed for containment.
Canada (PIPEDA): John Abish is the individual accountable for compliance; direct requests and challenges to support@giftsonx.com. You may contact the Office of the Privacy Commissioner of Canada if unsatisfied. EEA/UK (GDPR): the legal bases for processing are listed in section 6; the basis for health data, including body-scan photos and measurements, is your explicit consent (Art. 9(2)(a)), given at setup and again on the scan consent screen. Photos and measurements are not used to uniquely identify you and are not processed as biometric data. California (CCPA/CPRA): we do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months; we use sensitive personal information only to provide the service you requested.
If we change this policy, we update the version date above and give notice in the app. A material change to how health data is handled will ask for your consent again before it applies to you.
John Abish · Ontario, Canada · support@giftsonx.com