Fitineary

Privacy policy

What Fitineary stores, why, who can see it, and how to get rid of it.

Last updated 8 September 2026 · Fitineary is operated by 7th Pillar Infotech, India.

The short version. Your account is your email address. Everything else is what you log — food, training, sleep, mood, weight, photographs — and, if you have a coach, what you send them: messages, photographs and voice messages. It is stored so the app can show it back to you. It is not sold, and it is not used for advertising. A coach sees your diary only while you have connected to one, and only for as long as you stay connected; the messages the two of you sent each other stay with both of you afterwards. You can delete the account, and everything in it, from inside the app.

1. What we collect

All of it comes from you. There is no tracking pixel, no advertising identifier and no analytics SDK in the app — nothing measures what you look at, how long you stay or what you tap. There is one third-party SDK, and it reports crashes: when the app fails it sends the programming error and the version of the app and phone it happened on, so that we find out without waiting for somebody to tell us. It carries nothing you logged and nothing that says who you are. It is described in full in section 4.

AccountYour email address, which is the account — there is no separate username or password. A display name, language, and your unit preferences (kg/lb, cm/ft). An optional profile photograph.
About youSex, date of birth, height, your goal and activity level. Used to compute a calorie and protein target and for nothing else.
Health & fitnessWhat you log each day: meals and their portions, water, sleep duration and quality, mood, body weight, exercises, sets, reps and loads, and completed routine sessions.
Photographs, video & voice messagesMeal photographs you take or pick, a profile picture, demonstration videos a coach attaches to an exercise, and anything you attach to a message in a coach conversation — a photograph, or a voice message you record there. A meal photograph is sent for analysis when you log a meal from a picture, whether you take it or pick one you already had — see “Reading a meal photograph” below. An attachment sent to a coach is not sent for analysis and goes to no AI service at all; it is stored so the two of you can open it, and nothing else — see “Sending a photograph or a voice message to your coach” below.
What you describeIf you type or say what you did instead of filling in a form, the words you typed — or, if you spoke, a recording of what you said — are sent to be read. Recording starts only when you start it and stops when you stop it — two deliberate actions, one at each end, with nothing captured before the first or after the second, and thirty seconds is the cap whatever you do. The microphone is used in two other places — a voice message you record in a coach conversation, and the sound on a demonstration video if you are a coach filming one — and nowhere else: there is no listening in the background and no wake word. If you describe food, the food’s name is sent a second time to be given a calorie figure, without being asked for. See “Describing a log in words” below.
CoachingIf you connect to a coach: the connection itself, what they coach, the routines they assign you, and the messages between you — including any photograph or voice message either of you attaches to one. If you are a coach, your own coaching profile: your bio, what you coach, your certifications and a phone number, if you choose to publish one — leaving it blank is a complete answer, and the field says at the point of entry that your clients can see it and call you.
DeviceA push token, and only if you allow notifications. When you sign in, your phone's notification service issues an address for this app on this device; we store that address and whether the device is iOS or Android, so a message from your coach can reach your lock screen. Refuse the permission and nothing is stored. Signing out deletes it. It is not an advertising ID and it identifies no one but this installation. Delivering a notification necessarily hands that address to the push service that issued it — see “Where it lives” below.

We do not collect location, contacts, your device's advertising ID, browsing activity, performance telemetry, or anything from other apps.

The one exception is a crash, and it is an exception rather than a qualification: when the app fails it sends a report of that failure, carrying the programming error, the version of the app and the model and operating-system version of the phone — and nothing that identifies you or anything you logged. Nothing at all is sent while the app is working. Section 4 says exactly what a report holds.

2. Why we hold it

We do not profile you, sell data, share it with advertisers, or use it to train a model.

3. Who can see it

You can. Nobody else, with four exceptions you create yourself:

Access is enforced by the database itself, per row, rather than by the app asking politely — a request for data you may not see returns nothing, not a filtered version.

4. Where it lives

Records are held in a managed PostgreSQL database; photographs, video and the voice messages you send a coach are held as objects in Cloudflare R2. Both are encrypted in transit (HTTPS/TLS) and at rest by the provider. An image, a video or a voice message is reached only through a short-lived signed link that is issued after your permission to see it has already been checked — the storage layer never decides who you are.

Four things leave this system by design. All four are described here in full; nothing else about you goes anywhere.

Notifications. To put a message on your lock screen we pass your device's push token, and the notification's own wording, to Expo's push service and from there to Google’s Firebase Cloud Messaging on Android or Apple’s push service on iOS. The message body is written by our server, not copied from the conversation — a coach’s notification says that they sent you a message, and never what it said. Nothing else about you is included.

Reading a meal photograph. When you log a meal from a picture — taken now, or chosen from your photos — that picture is sent to an AI service to be read, and what comes back is a guess at what is on the plate and how much of it — a list of foods and gram estimates, which you then correct before anything is saved. The request is routed through our own server, which passes on the picture and a fixed instruction to read it — and nothing else. Not your name, not your email address, not your diary, not your targets, and nothing that identifies you or the account. If you then ask for a different food match, the food’s name and the portion in grams are sent the same way; still nothing about you. Our server instructs the AI service not to retain what it is sent — it will only route the request to providers that do not store it — and it is used to answer your request and for no other purpose. The same instruction is set on every request of this kind, a description and a recording included. Nothing you photograph, type or say is used to train anyone’s model, including ours.

You are never obliged to use it. Search for a food and enter the portion instead and no photograph leaves your phone at all. And the estimate is an estimate: it arrives with a match score precisely because it can be wrong, and every gram stays editable before you save it.

Describing a log in words. Instead of filling in a form you can type what you did, or say it. Typing and speaking are two separate screens and you choose between them before either one starts; the one you speak on records nothing until you start it, and stops the moment you stop it. Either way what you wrote, or a recording of what you said, is sent to the same AI service, through the same server of ours, with a fixed instruction to turn it into a list of things to log and nothing else attached. Not your name, not your email address, not your diary, not your targets, and nothing that identifies you or the account.

What comes back is a card of what was understood, one row per thing, and every row says what it would write before it writes anything. The rows are not tappable. Save on a row writes that row into your diary there and then; Adjust opens the ordinary screen for that kind of log, already filled in, for when you want to change something first. A row you did not mean can be removed, and closing the card without saving puts nothing in your diary. The rows you have not saved yet are kept on your phone, and only there, so that going back or closing the app does not lose them; they are deleted when you save or discard them, when you sign out, or a day after you last changed them.

A food row is sent a second time, and nobody asks you first. Food is the one thing you can describe with no number in it, so when a food row appears the food’s name — and only the name — goes back to the same service under a second fixed instruction: give this a calorie and macro figure. That happens once per food row, without being requested, because the figure is what the row has to show you before Save can mean anything. It travels the same way as everything else here, with nothing about you attached, and it is what Save writes.

A recording made to describe a log is never kept on our servers. On your phone the file is temporary, and lives only for as long as it takes to read it. There is no step in between: stopping the recording is what sends it, and Fitineary deletes the file as soon as the reading comes back or fails. It is also deleted if you leave the screen while a recording is still running. There are two cases we cannot cover for you: force-quitting the app while a recording is in progress or waiting to be read, and an operating system that refuses the deletion — Fitineary asks it to delete the file and cannot compel it. In either case the temporary file is the operating system’s to clear, and we have no way to know it is still there. No copy is stored in your account and it is not attached to anything you log.

The sound outlives the file by a little, in the app’s memory and nowhere else. The file has to be read before it can be sent, and what was read is kept in the app’s memory for as long as that voice screen stays open — so that if the reading fails, trying again does not mean saying the whole thing over. It is never written back to storage, never uploaded a second time on its own, and never attached to your account. It goes when you start another recording, and it goes when you close the screen. Recording never starts on its own. It begins when you start it and ends when you stop it, and it is always capped at thirty seconds.

What we do keep, for this and for a meal photograph alike, is a short record of what the model understood — kept with your account so we can see how often it reads people correctly, deleted with the account, and not used to train anyone’s model. For a photograph we also record whether you corrected the reading. For a description we do not: what you do with the card afterwards is not written back against the record, and it is stored saying exactly that.

You are never obliged to use this either. Every screen it can take you to is one you can reach by tapping, and refusing the microphone leaves everything except this, a voice message to a coach, and the sound on a demonstration video exactly as it was — the app says so plainly and offers you the typed box instead.

Sending a photograph or a voice message to your coach. This one is here for the opposite reason to the three above: nothing about it leaves our system, and what makes it worth its own section is that it is kept. Attach a photograph to a message, or record a voice message in the conversation, and the file is stored the way a meal photograph's bytes are stored — a row in the database and an object in Cloudflare R2, reachable only through a short-lived signed link issued after your permission to see it has been checked. It is not sent to the AI service, or to anyone else. Nothing is read out of it, nothing is guessed from it, and it is not used to train anything. It is stored so that you and your coach can open it, and for nothing else.

Nothing is recorded until you deliberately start a recording, and nothing leaves your phone until you press Send: a recording waits in the conversation where you can play it back and throw it away, and a photograph you have attached can be removed before you send it. Once you do send it, Fitineary deletes the temporary recording from your phone; the copy that remains is the stored one. A sent message cannot be taken back — there is no delete for a single message, on either side, and saying otherwise would be describing a control that does not exist. It goes when the account goes.

A crash report. When the app fails — a screen that stops drawing, or the whole app closing on its own — a report of that failure is sent to Firebase Crashlytics, Google's crash-reporting service. It contains the programming error and the line of our own code it happened on, the version of Fitineary you are running, the model and operating-system version of the phone, and whether the app was in the foreground. It is sent because a crash you do not report is a crash we never learn about, and until this existed the only way we heard about one was somebody describing the screen to us.

What a crash report does not contain, and this is enforced in the code rather than promised here. No email address, no phone number, no name and no account identifier — the report is not tied to you, and we could not look up who sent one. Nothing you logged: no meal, no photograph, no weight, no message to a coach. Nothing you typed or said. The service records no list of what you tapped, and Fitineary writes no notes of its own into a report, which is what keeps that true. This is crash reporting and not analytics: nothing is sent while the app is working, Google Analytics for Firebase is switched off and is not even installed, and no measurement of your use of the app is collected at any time.

One identifier does exist, and it is not you. Crashlytics gives each installation a random identifier of its own so that two crashes from the same phone can be seen as the same phone. It is generated on the device, it is not the advertising identifier, it is not your account, and uninstalling the app ends it. We never send anything alongside it that would say whose phone it is.

5. How long

Until you delete it. Individual entries go when you delete them. The whole account goes when you delete the account — see below — and that removes your profile, your logs, your photographs, your messages and your coaching connections. We keep no shadow copy for analytics.

When a coaching relationship ends, the routines that coach assigned you leave your library along with their access — they belong to the coach, who keeps them. Reconnecting is not an undo; they assign again. What stays is anything you built yourself.

A disconnected conversation keeps its words and loses its attachments, and that is a decision rather than a side-effect. The messages you exchanged stay readable to both of you. The photographs and voice messages do not: from the moment the connection ends, each of you can still open what you sent yourself, and neither of you can open what the other sent. Nothing is deleted — the files are still there, and reconnecting makes them open again — but while you are disconnected they are simply not yours to see, for the same reason the rest of the diary is not. The app says so on the bubble rather than showing a broken picture.

6. Your choices

7. Children

Fitineary is not intended for anyone under 16, and we do not knowingly hold data from a child. If you believe a child has created an account, write to us and we will remove it.

8. Changes

If this policy changes materially, the date at the top changes and the app tells you the next time you open it. We will not quietly widen what is collected.

9. Contact

Questions, corrections, or a data request: support@7thpillar.com. We answer data requests within 30 days.