1. Scope and who we are
This Privacy Policy explains how FitSocial collects, uses, shares, stores, and protects personal information when you use the FitSocial mobile application, the website at fitsocial.net, and related services (collectively, the “Services”).
FitSocial is currently operated in India by its co-founders, Harshit Arora and Naman Sinha. In this Policy, “FitSocial,” “we,” “us,” and “our” refer to FitSocial and its operators. Questions and privacy requests may be sent to .
This Policy is effective on . It applies worldwide, subject to additional rights provided by the law where you live.
2. Information we collect
Depending on how you use the Services, we collect the following categories of information:
- Google account and authentication information: Google user ID, name, email address, profile image, authentication tokens, session records, and related account-security information. Google Sign-In is the supported sign-in method at launch.
- Age-eligibility information: your date of birth, which is kept private and used to determine whether you meet FitSocial's minimum age requirement.
- Profile information: required name and profile photo, and information you choose to add such as a bio, fitness interests, experience, Personal Bests, goals, and Journey prompt answers.
- Health and activity information: exercise-session details and workout-route data you authorize FitSocial to read from Android Health Connect. If we add a visible feature that requires another Health Connect data type, we will explain the feature and request the relevant granular permission before accessing it.
- Workout information: activity type, title, source, date, start and end time, duration, route coordinates, road-matched route geometry, and related performance information supported by the feature.
- Location information: precise or approximate foreground device coordinates, depending on your Android setting; an approximately one-kilometre location cell derived from those coordinates; location-update records; rounded distance labels; and location-related security records. Exact or approximate device coordinates may also be processed by platform location or mapping services when resolving an area name.
- Content and media: profile and Journey photos, captions, Stories, squad names and cover images, announcements, and other information you upload or publish.
- Social and communication information: follows, followers, friends, friend requests, blocks, squad membership, direct and squad messages, read receipts, reports, Story views, profile visits, and notification history.
- Device and technical information: device platform, app version, push-notification token, IP address or a pseudonymous derivative, request timestamps, security events, diagnostics, and service logs.
- Support, rights, and deletion requests: your email address, request details, correspondence, verification records, and information needed to respond.
- Website information: waitlist email, consent version and timestamp, unsubscribe and notification status, a keyed hash of the requesting IP address for abuse prevention, page and referral information, approximate region, browser/device information, interaction events, and website performance measurements.
3. Sources of information
We receive information directly from you, from your use of the Services, from Google Sign-In, from Health Connect when you grant access, from device services such as location and notifications, from other users who interact with or report content, and from service providers that operate our infrastructure. We do not access Health Connect records unless you grant the applicable permission.
4. How we use information
We use information to:
- create, authenticate, secure, and support accounts;
- confirm age eligibility and prevent access by people under 18;
- provide profiles, Personal Bests, Journeys, Stories, squads, messaging, notifications, search, social connections, and workout features;
- provide nearby discovery and broad distance labels without giving other users your device coordinates;
- import, road-match, visualize, retain, and, when you choose, share workouts;
- apply rule-based content checks, investigate reports, enforce our rules, prevent abuse, and protect users and the Services;
- respond to support, access, correction, export, and deletion requests;
- measure website use and performance, troubleshoot errors, and improve the Services;
- send service messages, requested push notifications, and the one-time launch email; and
- comply with law, protect legal rights, and complete a merger, financing, acquisition, or transfer of assets with legally required notice.
5. Health Connect limited use
Connecting Health Connect is optional. At launch, FitSocial requests read access to supported exercise sessions. Access to an individual workout route requires the separate Health Connect route-consent flow. FitSocial does not write data back to Health Connect.
Health Connect information is used only to provide or improve health and fitness features visible in FitSocial. It is not sold, transferred to advertising platforms, or used for advertising, creditworthiness, lending, insurance eligibility, employment decisions, unrelated profiling, or training artificial-intelligence or machine-learning models.
We request only Health Connect permissions needed by current features. You can deny or revoke access through Android's Health Connect settings. Revocation stops future access but does not automatically delete information already imported into FitSocial; you may delete your account or submit a deletion request to remove imported information, subject to the retention terms below.
6. Location and Discover
FitSocial is built around helping users find fitness-minded people nearby. With foreground location permission, the app processes the precise or approximate coordinate supplied by Android and converts it on the device into an approximately one-kilometre Discover cell. FitSocial's backend stores the cell rather than the original device coordinate for Discover. Other users receive only broad nearby results and rounded whole-kilometre distance labels, not your location cell or device coordinates.
Discover is enabled by default for new accounts once location permission is granted. You may pause Discover in Settings. Pausing removes you from nearby recommendations and prevents you from browsing nearby recommendations until you resume. It does not disable direct messages with friends or Stories, and your profile can remain available in search and to your FitFam network. The most recent coarse Discover cell remains stored while visibility is paused and is replaced when a newer cell is submitted or deleted with your account.
Location-change and discovery security logs are retained for 30 days. Blocking is applied to supported discovery and social results. No technical measure can prevent every inference about location, particularly where a user voluntarily shares a workout route or location-identifying content.
7. Workout routes and Mapbox
When you approve a Health Connect workout route, FitSocial sends sampled route coordinates to Mapbox to match the route to roads and paths. The request does not include your FitSocial name, email address, or profile ID, but Mapbox may receive the coordinates and ordinary request information such as an IP address and access token. The resulting road-matched geometry is stored with your workout.
Where workout sharing is available, you decide whether to publish a workout. A shared route may reveal places you visit, including a home, workplace, or regular routine, and may be visible to authenticated users. Review a workout before sharing it. Imported workouts and route geometry are automatically deleted within six months. Individual imported-workout deletion is not currently offered, but account deletion removes associated workouts.
8. Content and visibility
Your email address and date of birth are not displayed to other users. Your name, profile photo, profile, bio, Personal Bests, Journey content, squads, social connections, and content you publish may be visible to authenticated FitSocial users. Stories are available to their author and eligible friends or followers while active. Direct messages are limited to their participants, and squad messages are limited to eligible squad members.
Media links may be copied or retained by a person who can view them. Information you share outside FitSocial is governed by the receiving service. We cannot delete copies made by other users, search engines, or external services.
9. Communications and moderation
Messages are encrypted in transit and protected by access controls, but they are not end-to-end encrypted. FitSocial applies rule-based checks to certain message and squad content. We do not currently use an AI service to moderate content.
Authorized personnel may review content submitted with a report to investigate safety or policy concerns. Personnel may otherwise access personal information only where reasonably necessary for security, support, legal compliance, or protecting users and the Services. Access is limited to people who need it for those purposes.
10. Advertising, sponsorships, and AI
FitSocial does not currently serve targeted advertising. We may introduce sponsored squads, brand partnerships, paid promotions, or advertising. Before beginning materially different advertising processing, we will provide an updated notice and obtain consent where required. Subject to those requirements, advertising may use general profile interests, interactions, and an approximate area.
Health Connect information, workout-route geometry, and message content will not be used for advertising. We do not sell personal information, health information, or location information. We do not use personal information to train AI or machine-learning models. If this changes, we will explain the feature and its data use before it begins and request permission where required.
11. Future paid features
FitSocial may offer subscriptions, in-app purchases, or paid events. If introduced, payments will be processed by the applicable app store or payment provider, such as Google Play or Razorpay. The provider may collect payment credentials under its own policy. FitSocial would receive transaction information such as purchase type, amount, currency, status, and a transaction identifier, rather than full payment-card details. We will provide any additional disclosures required before launching a paid feature.
13. Service providers
FitSocial currently uses Supabase for authentication, databases, Realtime, Edge Functions, and scheduled jobs; Google for Sign-In, Gmail communications, Google Play, and Android Health Connect; Cloudflare for media storage and delivery, authenticated uploads, and rule-based content screening; Mapbox for maps and route matching; Expo for application infrastructure and push notifications; and Vercel for website hosting, Web Analytics, and Speed Insights.
Providers process information under their own terms and privacy policies. We require access to be limited to the services they provide and assess new providers before sending personal information to them.
14. Website, analytics, and waitlist
If you join the launch waitlist, we collect your email address, consent version and time, source, notification status, unsubscribe status, and creation time. We use a keyed hash of your IP address to prevent automated abuse. Rejoining reactivates a previously unsubscribed address. The one-time launch email will include an unsubscribe method.
Vercel Web Analytics and Speed Insights process page views, referral and route information, approximate location, browser/device information, website interaction events, and performance measurements. FitSocial does not place advertising cookies on the website. Vercel may process technical information according to its own documentation and configured retention terms.
If you use the website account-deletion form, we collect your account email, submission time, verification and completion status, related correspondence, and a keyed hash of your IP address for abuse prevention. A form submission does not itself delete an account. We contact you at the account email to verify the request before deletion.
15. Legal bases
Where applicable law requires a legal basis, we process information as necessary to perform our agreement with you and provide requested Services; with your consent, including for Health Connect, device permissions, optional notifications, and certain advertising; for legitimate interests such as security, support, service improvement, and preventing abuse, where those interests are not overridden by your rights; and to comply with legal obligations or protect vital interests.
You may withdraw consent at any time through the relevant app or device setting or by contacting us. Withdrawal does not affect processing already completed lawfully and may prevent a requested feature from working.
16. Retention
We retain information only for the purposes described above:
- imported workouts and route geometry: up to six months;
- direct and squad messages, announcements, read receipts, notification records, and conversation metadata: up to 180 days;
- reports and moderation records: up to six months;
- Stories and associated Story media: up to 24 hours;
- location-update and discovery IP/security logs: up to 30 days;
- the current coarse Discover cell: until replaced or account deletion, including while Discover is paused;
- profiles, Journeys, avatars, social relationships, squads, and squad covers: until removed or the relevant account or squad is deleted;
- waitlist information: until the launch message is sent, followed by deletion within 30 days, or earlier withdrawal;
- website rate-limit identifiers: up to 30 days; and
- backup copies: deleted or overwritten within 90 days after deletion from active systems.
We may retain limited records longer when reasonably necessary for law, fraud prevention, safety, disputes, or enforcing our agreements. Where possible, we restrict or de-identify information retained for these purposes.
17. Your rights and controls
Depending on where you live, you may have rights to access, correct, receive a portable JSON copy of, delete, restrict, or object to processing of personal information; withdraw consent; opt out of targeted advertising; and appeal or complain to a privacy regulator. We will not discriminate against you for exercising an applicable privacy right.
You can manage eligible profile and social information in the app, pause Discover, revoke Health Connect or location access through Android settings, disable notifications, block users, and leave squads. To make a rights request, contact . We may verify that you control the account and may request only the additional information reasonably necessary to do so.
18. Account deletion
You can request account deletion from the FitSocial app's Settings screen or through our account-deletion webpage. Website requests are verified through the email address associated with the account. We aim to complete verified deletion requests within 30 days.
Account deletion removes or de-identifies account authentication data, profile information, social relationships, workouts, coarse Discover location, messages and content controlled by FitSocial, uploaded media, push tokens, and account-scoped local caches. Backup cleanup may take up to 90 days. Limited information may be retained for the legal, fraud-prevention, safety, and dispute purposes described above. Copies already shared outside FitSocial must be removed through the receiving service.
19. International transfers
FitSocial is operated from India, while its providers currently host or process much of the Services in the United States and may use other countries. Your information may therefore be transferred outside your country. Where required, we use contractual and other recognized safeguards intended to protect information during international transfers.
20. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transmission, encryption at rest where supported by our providers, row-level database controls, restricted service credentials, authenticated upload paths, rate limits, block-aware queries, and access controls. No online service can guarantee absolute security. Contact us promptly if you believe your account or information is at risk.
21. Adults only
FitSocial is intended only for people aged 18 or older. We use date of birth to enforce this requirement and do not knowingly permit a person under 18 to create or maintain an account. If we learn that an account belongs to someone under 18, we will suspend access and delete the associated personal information, subject to any limited retention required for safety or law. Contact us if you believe a person under 18 is using FitSocial.
22. Regional information
India: Users in India may contact us to access, correct, erase, or withdraw consent for personal information and to raise a grievance. You may pursue an available complaint before the authority designated under applicable Indian data-protection law.
EEA and UK: You may have rights of access, rectification, erasure, portability, restriction, objection, and withdrawal of consent, and the right to complain to your local supervisory authority. Health information is processed with explicit consent where required. FitSocial and its operators act as the controller for the processing described in this Policy.
Certain US states: Subject to applicable law and exceptions, you may request access, correction, deletion, or a portable copy and may opt out of targeted advertising, sale, or qualifying sharing. FitSocial does not sell personal information. If targeted advertising is introduced, an applicable opt-out method will be provided before that processing begins.
23. Changes to this Policy
We may update this Policy as the Services or law changes. We will post the revised Policy and effective date. For material changes, we will provide notice by email, in the app, and on the website where reasonably available, and request consent when required. Continued use does not replace consent where law requires an affirmative choice.