FitNice Privacy Policy
At FitNice, we value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use the FitNice mobile application.
1. Information We Collect
We collect information to provide a better, more personalized fitness experience. The data we collect includes:
- Personal Information: Name, email, age, height, weight, and fitness goals.
- Health Data: Workout logs, meal preferences, and progress tracking.
- Health & Fitness API Data: With your explicit consent, physical activity data (such as step counts, active calories, and distance) from Google Play Services Health Connect and/or Apple HealthKit.
- Usage Data: App interactions, feature usage, and crash reports.
- Device Information: Device type, operating system, and app version.
- Local Storage: Chat history with the Nori AI coach and personalized plans stored locally on your device.
- Supabase Data: Account credentials and sync data secured through our cloud storage.
2. Health Connect & Health API Data
FitNice accesses, collects, and processes physical activity data from Google Play Services Health Connect and/or Apple HealthKit with your explicit consent.
Access and Collection
- Data Accessed: Step counts, active calories, and distance.
- Consent: We only access, collect, or read this data if you explicitly grant permission within the app. You can revoke this permission at any time in your device settings.
How We Use this Data
- To track your daily steps, calculate active calories, and monitor fitness progress in real-time.
- To display activity history and update your goals.
Limited Use Policy
- Our use of information received from Health Connect will adhere to the Health Connect Permissions Policy, including the Limited Use requirements.
- We do not share, sell, or transfer Health Connect data to third-party advertising networks, data brokers, or marketing platforms.
3. Data Storage & Technology
FitNice uses a hybrid data management approach to balance privacy and convenience:
Local Storage
- Chat history with the Nori AI coach is stored directly on your device.
- Meal and workout plans are cached for offline access.
- Personal preferences, settings, and progress tracking data are maintained locally.
Supabase Integration
- Secure user authentication and account management.
- Real-time data synchronization across multiple devices.
- Encrypted cloud backups for account recovery.
- Industry-standard security protocols (OAuth 2.0, JWT).
All data handling complies with Indian data protection regulations and international security standards.
4. How We Use Your Information
We use the collected information for the following purposes:
- To provide personalized fitness and nutrition recommendations.
- To track your progress and generate insights through AI coaching.
- To process physical activity data from Health Connect or Health APIs to display steps, calories, and goals.
- To securely sync data across your devices via Supabase.
- To improve our AI coaching algorithms and overall app functionality.
- To send important updates and notifications.
- To ensure app security and prevent fraud.
- To provide offline access to your data through local storage.
5. Data Security & Protection
We implement robust security measures to protect your data:
Local Security
- All local data is encrypted using device-level security.
- No sensitive data is transmitted without encryption.
- Secure file storage with restricted access.
Cloud Security (Supabase)
- End-to-end encryption for all data transmission.
- Row-level security (RLS) policies implemented on databases.
- Regular security audits and penetration testing.
- ISO 27001 and SOC 2 Type II compliance.
- Data is hosted in secure, geographically distributed data centers.
Indian Regulatory Compliance
- Strict adherence to the Information Technology Act, 2000 & IT Rules, 2011.
- Full compliance with the Digital Personal Data Protection (DPDP) Act, 2023.
- Strict adherence to data localization and cross-border transfer requirements under Indian regulations.
6. Your Rights & Data Control
You have full control over your data:
Data Access Rights
- View all personal data we store (both local and cloud).
- Request data export in a machine-readable format.
- Access real-time sync logs and activity history.
Data Control Options
- Revoke Health Connect and/or Apple HealthKit permissions at any time via device settings.
- Delete local chat history and cached plans at any time.
- Clear cloud-synced data through account deletion.
- Opt-out of data synchronization while keeping local data on your device.
- Control which data types sync across devices.
Indian Data Principal Rights (DPDP Act, 2023)
- Right to Access: Request a summary of personal data processed and details of third-party sharing.
- Right to Correction & Erasure: Request rectification, completion, or deletion of your personal data.
- Right to Grievance Redressal: Access to a grievance redressal mechanism for quick dispute resolution.
- Right to Nominate: Nominate another individual to exercise rights on your behalf in case of death or incapacity.
- Right to Withdraw Consent: Withdraw consent easily at any time, halting further data processing.
7. Data Sharing & Third Parties
We do not sell or rent your personal data to third parties.
Limited Data Sharing
- Supabase: Our cloud infrastructure provider for secure data storage and syncing.
- Analytics Services: Anonymized usage data only to help improve the app.
- Indian Law Enforcement: Only when legally required.
Service Providers
- All third-party services undergo strict security assessments.
- Data Processing Agreements (DPAs) are in place with all vendors.
- Regular audits of third-party security practices.
- Immediate notification of any data breaches.
Your data remains primarily on your device and under your control.
8. Contact & Support
For privacy-related questions, concerns, or to exercise your rights:
Primary Contact
- Email: tectra.ai@gmail.com
- Subject: Privacy Policy Inquiry
Designated Grievance Officer (India)
- Name: Grievance Officer - FitNice
- Designation: Data Protection & Grievance Officer
- Address: AI Tectra, Kerala, India
- Email: tectra.ai@gmail.com
- Subject: Grievance Redressal / DPDP Request
Indian Legal Compliance
- Mandated Grievance Officer redressal mechanism under the DPDP Act, 2023.
- Grievance acknowledgement within 24 hours and resolution within 48–72 hours.
- Escalation process for unresolved issues directly to the Data Protection Board of India (DPBI).
Response Times
- Privacy questions: Within 24 hours.
- Data access requests: Within 48 hours.
- Data deletion / Consent withdrawal requests: Within 72 hours.
- Legal compliance matters: Immediate attention.