YOUR DATA, IN PLAIN LANGUAGE
Privacy Policy
Effective 15 September 2026
FitFight lets named participants compete on who records the most Steps during a private Fight. This policy explains the data used by the FitFight iPhone app and its support website.
Data we collect
- Account data: your Sign in with Apple identifier, email address (which may be an Apple private relay address), name when Apple supplies it, your FitFight username, chosen companion and optional custom description, and an encrypted server-only Apple credential used to disconnect Sign in with Apple when you delete your account.
- Referrals: a random sharing code and the accounts of the person referring and the person referred, with the time the referral was recorded. We use this to understand who brings friends to FitFight. These relationships stay private and are removed when either account is deleted.
- Fight data: the usernames invited to a Fight, its title, action and duration, membership status, aggregate scores, rank, and timestamps.
- Apple Health: with your permission, FitFight reads Step Count and other movement types (active and resting energy, distance, exercise, stand, flights, and workouts). Steps fights still send the merged step total for each exact Fight window plus the relevant daily step totals used by Fight charts. Other activity totals stay on your account and are not shown to other participants.
- Photos, videos, and posts: your optional profile photo, Fight posts, photos and videos, comments, and emoji reactions. Posts are shared with members of the Fights you select. The Public label on a post means all selected Fights, not an open internet page. Public Fights have join details visible to other signed-in users before they join.
- Bugs and feature requests: the title, details, votes, and comments, optional photos, videos, and files you post on the in-app board, shown to other signed-in FitFight Users with your username. Reports also include app and device information to help investigate a problem.
- Notifications: when you allow push notifications, an encrypted Apple push device token, language, permission status, and your notification preferences. Apple delivers enabled Fight reminders and post, comment, reaction, and daily-status alerts to your device.
- Support and operations: messages you send to support and limited server logs such as request time, IP address, device or browser information, and error details needed to keep the service secure and working. Private sync diagnostics also record how long Apple Health reads and network requests take, their success or failure, app version, and request sizes. These timing records contain no Steps values or raw Health samples and are not shared with other participants.
Apple Health
Apple Health access is read-only. FitFight does not write to Apple Health. The current app does not send raw Health samples, GPS routes, heart rate, or device and source metadata. It may send merged daily activity totals and workout summaries (type, time, optional active minutes, distance, energy, and effort) so FitFight can prepare later challenge types. Those extra readings are not used to score today's Steps fights and are not shown to other people.
Participants in the same private Fight can see each other's username, aggregate Steps total for the Fight, relevant daily Steps totals shown in the Fight chart, rank, Fight title, Fight action, and duration. They never receive another participant's raw Apple Health samples or unrelated Health history.
How we use data
We use the data above to:
- create and secure your account;
- create, invite participants to, score, and finish private Fights;
- show standings and shared Fight history;
- share posts and media with the selected Fight participants;
- deliver enabled notifications;
- run the in-app bugs and feature-request board;
- answer support requests; and
- detect errors, abuse, and security problems.
FitFight does not sell personal data, show advertising, or use account or Health data for advertising, cross-app tracking, or data brokerage.
Who processes data
FitFight uses Supabase for authentication, database, and uploaded-file storage, and Vercel to host server APIs and scheduled processing. These providers process data for FitFight under their service and security terms. We do not make private Fight or Health data public.
When configured, PostHog receives crash reports linked to your FitFight account identifier. FitFight disables session replay and screen and interaction capture; its crash integration sends crash reports and account identification. It does not intentionally include Health values in those reports.
When configured, bugs and feature requests are copied to our Notion backlog with your username, report text, and attachment links. The FitFight administrator can send a report, its comments, device information, and attachment links to Cursor to investigate and prepare a fix.
When daily-status generation is configured and enabled for your account, OpenRouter and its model provider receive a limited summary: whether you are ahead, behind, or tied, participant count, days remaining, whether a sync is needed, and language. This request does not include your account identifier, username, Fight title, exact Steps totals, or raw Health samples.
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Permissions, revocation, and retention
You choose whether to grant Apple Health access. You can remove FitFight's access at any time in Apple Health or iOS Settings. Revoking access stops future reads but does not change data already used to score a Fight.
You can manage notification categories under You → Settings → Notifications and remove push permission in iOS Settings.
We keep account, Fight, posts, media, bugs and feature-request, and uploaded Health data while your account exists. Support emails are kept only as long as needed to answer the request. Limited security and request logs follow Supabase's and Vercel's configured retention periods. Deleted data may remain temporarily in routine backups until those backups expire, or longer when required by law.
We keep at most the 100 most recent sync timing reports for your account. Reports older than seven days are removed the next time your app sends a diagnostic report. Deleting your account removes its timing history.
Account deletion
You can permanently delete your account under You → Settings → Delete account. You do not need to contact support. Deletion removes your profile, username, uploaded photos, videos, files, Fight posts and comments, uploaded Apple Health Fight, daily, and activity totals and workout summaries, legacy friendships, invitations, Fight memberships, scores, bugs and feature requests you posted, and every Fight you created. It also removes your participation from Fights created by someone else.
In-app deletion does not automatically remove report copies already sent to Notion or Cursor, or crash records already sent to PostHog. Contact marc@marclamy.com to request a review of those copies and their retention.
When FitFight has a revocable Sign in with Apple credential, it asks Apple to revoke that credential as part of deleting the FitFight login and signing you out. If automatic revocation is unavailable, the app tells you how to disconnect FitFight in Apple settings. Deletion does not remove information stored in Apple Health or delete your Apple ID.
Your choices
You may ask to access, correct, or delete information associated with your account. Email marc@marclamy.com from the address connected to your account so we can verify the request.
Changes and contact
We may update this policy when FitFight changes. The effective date above will identify the current version. Questions about privacy can be sent to marc@marclamy.com.