Fit Assist — Privacy Policy

Publisher: John Abish (sole proprietor), Ontario, Canada · Contact: support@giftsonx.com
Version: 2026-08-26 · Last updated: August 26, 2026 · Replaces the version dated July 27, 2026

Summary
What changed in this version. Fit Assist now includes a body scan, a meal photo scan, and a barcode lookup. This version adds sections 3 and 4 describing them, names the three new service providers involved (Anthropic, Open Food Facts, and Sentry — section 7), adds retention rows for photos and scans (section 10), and explains what deleting a scan or your account does to that data (section 11). Nothing about how your existing data is handled has changed.

1. Who we are

Fit Assist is published by John Abish, an individual developer operating as a sole proprietor in Ontario, Canada, who is the data controller (in Canadian terms, the organization accountable) for the personal information described here. For any privacy question or request, contact support@giftsonx.com.

2. What we collect

Information you give us

During setup and while using the app: your email address (when you create an account); your sex, age, height, weight, and optionally body-fat percentage; your goal, target weight, target date, and pace; the body shape you choose as your target; activity level and training experience; diet preference, meal pattern, allergens, and food dislikes; training availability, environment, and equipment; the health-screening answers described in section 5; any measurement you enter by hand to correct a scan result (a tape measurement, for example); and the short note you can add to a meal scan.

Photos you take or choose

For a body scan: two photos of you — front and side — taken with the camera or chosen from your photo library, plus, during guided capture, a short burst of framing-check frames. For a meal scan: one photo of your food, taken or chosen. Sections 3 and 4 say exactly what happens to each; the short version is that they are analyzed and immediately discarded, and a photo is never stored on our servers.

Generated by your use of the app

Weigh-ins you log, foods you log (including custom foods you create), workout sets and completions, routines you build, the plans we generate for you, weekly and daily adaptation decisions, and a closed set of first-party product-analytics events (for example "plan revealed", "food logged", "body scan captured"). Analytics events use a fixed vocabulary and carry no free-text content and no photos.

From the body scan: your estimated measurements with their uncertainty ranges, the shape values of your 3D model, the decisions you make when the app asks you to check a reading (keep it, measure with a tape, redo, or discard), and a body-fat estimate that is computed from your stored measurements each time you view it. From the meal scan: the list of foods and portions the analysis suggested, which you then edit before anything is logged. From barcode lookups: the product you scanned.

From your device, with your permission

From our sign-in and payment partners

If you sign in with Google, Google shares your email address and basic profile with our sign-in provider, Clerk, to create your account, under Google's own privacy policy. From Google Play via RevenueCat we receive your subscription entitlement state and purchase events. We never receive or store your payment card or billing details — Google is the merchant of record.

3. The body scan

The body scan estimates tape-style body measurements — neck, chest, waist, hips, thighs, arms and similar sites — and builds a 3D model of your body shape, from two photos and your height (plus your most recent logged weight, if it is recent). Here is the full picture.

Your consent

Before your first scan the app shows a dedicated consent screen explaining what the scan looks at, what happens to the photos, and what the numbers can and cannot tell you. Each scan records the version of that screen you accepted. If the wording changes in a way that matters, you are asked again before the next scan.

What leaves your phone

Two downscaled JPEG copies of your photos; a cryptographic fingerprint (SHA-256) of each; your height and, if recent, your latest weight; and, during guided capture, a few framing-check frames so the app can tell you to step back or straighten up before the real shot.

What happens on our server

Photos are processed by our own measurement model, on our own server. No third-party AI service ever sees a body-scan photo. The photos are held in memory only for the seconds the analysis takes and are then discarded: they are never written to disk or a database, never logged, and never attached to error reports. Framing-check frames are handled the same way and produce no stored record at all.

What we keep

For each completed scan: the estimated measurements with their uncertainty ranges; the shape values that define your 3D model (a handful of numbers, not a photo); the fingerprint of each photo, which cannot be turned back into the image and exists so we can prove a result came from a given photo and reject mismatches; the height and weight the scan used; the model and consent versions; the time of the scan; and any coach-check decision or tape measurement you entered. Your body-fat estimate is recalculated from those stored measurements whenever you view it and is not itself stored.

No identification

We do not use your photos or your measurements to identify you. The scan performs no facial recognition and builds no biometric template. Your 3D model is a generic body shape fitted to your measurements, not a likeness of you.

What the numbers are — and are not

Measurements are estimates, produced by software that is in beta calibration. Every value is shown with its uncertainty range, and at some sites the typical difference from a real tape measure is several centimetres. They are not medical measurements, they are not a diagnosis of anything, and they must not be used to make medical decisions. If you need a number you can rely on, use a tape — the app lets you enter one in place of any estimate.

Before you have an account

The first body scan can happen during setup, before you create an account. That scan is anonymous: its results are keyed to a session identifier, not to a person, and are kept for 48 hours. If you create an account within that time, the scan becomes the first scan on your account; if you do not, it is deleted automatically. You can also skip the photos and get a statistical preview from your height, weight and sex alone — no photo is involved in that path.

Your photos, on your phone

The originals and the upload copies stay in the app's private storage on your phone — not in your gallery, unless you chose them from there. You can delete them from the scan itself at any time, and uninstalling the app removes them.

Deleting a scan

You can delete any individual scan from within the app. That permanently erases its measurements, model and fingerprints — this is a true deletion, not de-identification. Deleting your account erases every scan, onboarding preview and body target at once (section 11).

4. Meal photo scan and barcode lookup

Meal photo scan

When you scan a meal, the photo, your optional note, and the meal slot are sent to our server and from there to Anthropic, PBC (United States), the company that makes the Claude AI models, acting as our service provider. Anthropic returns a suggested list of foods and portions, which the app shows you as an editable draft; nothing is logged until you confirm it. The same path handles a typed description without a photo.

Anthropic processes your photo and note only to return that result. Under its commercial terms it does not use your inputs to train its models, and it deletes inputs and outputs within 30 days, except where it must keep them longer to enforce its usage policies or comply with law. We do not store the photo at all — it is held in our server's memory for the request and discarded; we store only the structured result and a record that a scan happened, which is how the free tier's daily scan allowance is counted.

Photograph the food, not people. If a photo does include a person, it is processed in exactly the same way — for the food only — and is never stored.

Barcode lookup

When you scan a product barcode, our server looks the number up in Open Food Facts, a non-profit open food database based in France. Only the barcode number is sent, from our server: Open Food Facts does not receive your account, your device identifier or your IP address. We cache product information (name, brand, nutrition per 100 g) on our server for up to 30 days so repeated lookups are fast. That cache holds product information, not personal information. Product data is used under the Open Database License, with attribution shown in the app.

5. Health data

To keep plans safe, setup asks about health matters: injuries, disclosed medical conditions, pregnancy status, and screening for active eating disorders. Together with your body measurements — stated, logged, or estimated by the body scan — your body-scan photos, your body-fat estimate, and the foods you log or photograph, this is health information, a sensitive category of personal data.

We process it only with your explicit consent, which the app asks for as its own step during setup, separately from your acceptance of the Terms, and — for the body scan — on a separate consent screen before your first scan. We use it solely to run safety screening, generate your plan, adapt it over time, and show you your own measurements and trends. It is never used for advertising and never sold. If you withdraw consent, the app cannot function, and the way to withdraw is to delete your account (section 11).

6. Why we use your information

PurposeBasis
Generating your meal and workout planPerforming our contract with you
Weekly and daily plan adaptation from your logsPerforming our contract with you
Estimating body measurements and building your 3D model from your photos; showing your trendsYour explicit consent (the scan consent screen) and performing our contract with you
Analyzing a meal photo into a draft food logPerforming our contract with you
Safety screening, calorie floors, and the disclaimer audit trailLegal obligation / legitimate interest in a tamper-evident safety record
Product analytics on a closed, first-party event setLegitimate interest in improving the app
Server error monitoringLegitimate interest in keeping the service working
Managing your subscription entitlementPerforming our contract with you
Local remindersYour consent (opt-in)

We do not send marketing email, and we make no decisions about you by automated means that have legal or similarly significant effects.

7. Who we share with

We share personal information only with the service providers below, only so they can provide their service to us, and never for their own advertising. We do not sell your personal information, we do not share it for advertising, and the app contains no advertising or third-party analytics SDKs. (Error monitoring runs on our server, not in the app.)

ProviderRoleData it receivesLocation
Clerk, Inc. (privacy) Sign-in and accountsEmail address, sign-in metadata, session tokensUnited States
Google LLC — Sign in with Google (privacy) Optional sign-in methodOnly if you choose it: your sign-in request, under Google's policyGlobal
RevenueCat, Inc. (privacy) Subscription managementA pseudonymous user ID and purchase/entitlement eventsUnited States
Google LLC — Google Play Billing (privacy) Payment processing (merchant of record)Your payment details go to Google directly; we receive only entitlement stateGlobal
Google — Health Connect On-device health data storeWeight records are read on your device with your permission (section 9)On your device
Anthropic, PBC (privacy) Meal photo analysis (AI service provider)Meal photos, your meal-scan note and meal slot — nothing else; never body-scan photos (section 4)United States
Open Food Facts (privacy) Product database for barcode lookupThe barcode number only, sent from our server — no account, device or IP dataFrance (EU)
Functional Software, Inc. — Sentry (privacy) Server error monitoringTechnical details of server errors: endpoint, time, error type and request metadata, which may include a pseudonymous user or scan ID. Never photos, never request bodies, never your emailUnited States
Railway Corp. (privacy) Application hosting and databaseAll server-side data described in this policy, encrypted in transitUnited States

Fonts and all app assets are bundled into the app at build time — the app makes no runtime requests to font or asset services that could expose your IP address to them.

8. International transfers

Our servers and database are hosted by Railway in the United States, and Anthropic and Sentry process data there too; Open Food Facts is in France. If you use Fit Assist from Canada, the EEA, the UK, or elsewhere, your information is transferred to and processed in the United States, where laws may differ from those of your home jurisdiction. For EEA/UK users, transfers rely on appropriate safeguards such as Standard Contractual Clauses maintained by our providers. For Canadian users: comparable protection is required of our providers by contract, and this policy is your notice of processing outside Canada.

9. Health Connect

On Android, Fit Assist can read your weight from Health Connect. In full:

10. Retention

CategoryHow long
Photos — body scan, meal scan, framing-check framesNot stored on our servers. Processed in memory and discarded within the request. Meal photos sent to Anthropic are deleted by Anthropic within 30 days (section 4). Copies stay on your phone until you delete them or uninstall the app
Body scans: measurements, 3D-model shape values, photo fingerprints, coach-check decisions, tape entries, body targetUntil you delete the scan or your account — then erased, not de-identified
Anonymous onboarding scan preview48 hours, then automatically deleted — or converted into your first scan if you create an account in that time
Meal-scan results (foods and portions — no image)While your account is active; after deletion, retained only in de-identified form (section 11)
Barcode product cacheProduct information only, not personal information; refreshed at least every 30 days
Account identifiers (email, sign-in identity, device ID)Until you delete your account — then erased immediately and permanently
Plans, logs, screening answers, adaptation recordsWhile your account is active; after deletion, retained only in de-identified form (section 11)
Safety-screening and disclaimer acceptance audit trailRetained as a tamper-evident record for legal-protection purposes; de-identified after account deletion
Purchase/entitlement recordsRetained for tax and accounting purposes; de-identified after account deletion
Server error reports (Sentry)Up to 90 days
Server access logsApproximately 30 days

11. Your rights, and what deletion actually does

Depending on where you live, you have rights to access, correct, export, and delete your personal information, to object to or restrict certain processing, to withdraw consent, and to complain to your privacy regulator (in Canada, the Office of the Privacy Commissioner of Canada; in the EEA/UK, your supervisory authority; in California, the Attorney General or CPPA). To exercise any of these rights, email support@giftsonx.com — we respond within 30 days. You can request a copy of your data by email; we provide it in a portable electronic format.

Deleting one body scan (in the app, from the scan itself) permanently erases that scan's measurements, model and fingerprints.

What account deletion actually does. When you delete your account (in the app: your profile → Account → Delete account, or via our deletion page), we immediately and permanently erase everything that identifies you — your email address, your sign-in identity, your device identifier, and the link between your account and your subscription — and every body scan, onboarding scan preview, and body target, because a measurement series should not outlive the person it describes, even anonymously. Some other records — the weights you logged, the plans we generated, the food and portion lists from meal scans, and our safety-screening audit trail — are held in a tamper-evident, append-only store that we cannot edit after the fact; this is a deliberate safety and integrity design and, for the safety audit trail, a legal record-keeping measure. Those records survive deletion, but they are stripped of every identifier and are no longer associated with you or any account. We cannot re-link them to you, and neither can anyone else.

12. Children

Fit Assist is for adults 18 and over. Setup asks your age and exits for anyone under 18. Do not scan or photograph anyone other than yourself. We do not knowingly collect personal information from minors; if we learn that we have, we will delete it.

13. Security

All data is encrypted in transit (HTTPS). Your sign-in token is stored on your device in the platform's secure storage. Server credentials and secrets are kept in a secrets manager, never in source code. Photos are never written to disk, to a database, to logs, or to error reports — the analysis path is designed so there is nothing to breach. Safety-critical records are protected by database-level append-only enforcement, and account deletion uses a cryptographic-shredding design so identifier removal is immediate and irreversible. No system is perfectly secure, and we do not claim to be unbreachable — but we designed for containment.

14. Regional notes

Canada (PIPEDA): John Abish is the individual accountable for compliance; direct requests and challenges to support@giftsonx.com. You may contact the Office of the Privacy Commissioner of Canada if unsatisfied. EEA/UK (GDPR): the legal bases for processing are listed in section 6; the basis for health data, including body-scan photos and measurements, is your explicit consent (Art. 9(2)(a)), given at setup and again on the scan consent screen. Photos and measurements are not used to uniquely identify you and are not processed as biometric data. California (CCPA/CPRA): we do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months; we use sensitive personal information only to provide the service you requested.

15. Changes to this policy

If we change this policy, we update the version date above and give notice in the app. A material change to how health data is handled will ask for your consent again before it applies to you.

16. Contact

John Abish · Ontario, Canada · support@giftsonx.com