Privacy Policy
Last updated: September 17, 2026
This policy explains what personal data the Fitgamma iPhone app and its server process, why, who else receives it and what you can do about it. It also covers this website and emails you send us. It describes how the app works today; when that changes, we update this page.
Who is responsible
Fitgamma is provided by Maksimilian Spiridonov, an individual developer based in the United Arab Emirates ("we"). We are responsible for the personal data described in this policy. Questions and requests: .
Data on your device and in your iCloud
Most of your data lives on your iPhone and, if iCloud is turned on, in your private iCloud database (Apple CloudKit). We have no access to it:
- your profile: gender, date of birth, height, weight, goal, experience, schedule and limitations
- workout places and equipment
- workouts, exercises and sets, including changes you make to a plan
- your conversation with the AI trainer
Your account
You sign in with Apple. We store the identifier Apple creates for Fitgamma and the email address Apple shares with us when you sign in — your own address, or a relay address if you choose Hide My Email. We use it only to contact you about your account, subscription and support requests; we do not send newsletters. We do not store your name. Sessions use short-lived access tokens (15 minutes) and a refresh token (30 days) that our server keeps only in hashed form.
Data stored on our server
Our server is located in Kazakhstan. It receives and stores:
- For generating workouts: gender, age (calculated on your device — your date of birth is not sent), height, weight, training experience, recent training frequency, confidence, goal, workout split, the limitations and injuries you selected, sessions per week, session length, workout place and equipment. A snapshot of these settings is stored with every generated workout; the server also uses your completed workouts listed below.
- Completed workouts: title, start and finish time, duration, exercises, sets (reps, weight or time), changes you made to the plan and the app version.
- Subscription: the signed App Store transaction the app sends after a purchase. We keep the original transaction ID, the product and the expiry date, and receive subscription status notifications from Apple.
- Counters of AI requests, used to apply daily limits.
AI trainer
When you use the trainer chat, your recent messages (up to 50), your training profile (goal, experience, limitations, schedule, equipment, and your weight when it changes) and your current and last 12 workouts are sent through our server to OpenRouter (USA), which passes them to a Google Gemini language model to generate the reply.
We do not store the text of your conversation on our server; it is kept on your device and in your iCloud. Please do not share anything in the chat that you do not want processed this way.
By sending a message to the trainer you agree that its text and the data listed above are processed by OpenRouter and Google to generate the reply.
Analytics
We use Amplitude (USA) to understand how the app is used. Amplitude receives your account ID and:
- profile properties: goal and fitness level
- your answers in the onboarding questionnaire — goal, experience, workout places and schedule; the limitations and injuries you select are not sent
- events such as generating, starting, completing or discarding a workout, opening the trainer chat, viewing the subscription screen, purchases (product ID) and reaching the free limit
- technical data the Amplitude SDK collects by default: IP address, device model, iOS version, identifier for vendor (IDFV) and session information
Analytics data is not deleted when you sign out or delete your account in the app (see "Retention and deletion"). We do not use the advertising identifier (IDFA), do not track you across other companies' apps and do not show ads.
Diagnostics
When the app hits an error, it may send a short diagnostic message (up to 2,000 characters, with access tokens and email addresses removed) together with your account ID and Support ID. Our server writes these messages to its operational log. Operational logs are kept in our log system for up to 7 days (container log files rotate by size), aggregated metrics for up to 90 days.
Apple Health
With your permission, Fitgamma reads your sex, date of birth, height and weight to fill in your profile, and reads and writes workouts, heart rate and active energy; finished workouts can be saved to Apple Health.
Raw Health data is not sent to our server. Values derived from it — gender, age, height and weight — can be sent as part of your profile as described above; none of them go to analytics. Health data is never used for advertising. You can change Health permissions at any time in the Health app or in iOS Settings.
This website and email
fitgamma.com uses no cookies, analytics or trackers and loads nothing from other services. Like any website, it receives your IP address and browser details with each request, but we don't keep a log of visits. Your theme and language choice are saved in your browser (localStorage) and never sent to us.
The support form on this website sends what you enter — your email address, your message, your Support ID and the files you attach, and, if you open the form from the app, the app version, iOS version and iPhone model — to our server, which forwards it as an email to our mailbox and does not keep it.
If you write to us through the form or to , your message, your email address and anything you include — such as your Support ID — are stored in our mailbox at Yandex 360 (Yandex, Russia). We use them only to answer you and to keep a history of your requests; we keep the correspondence while it is needed for that and delete it at your request.
Who receives your data
We do not sell your personal data. It is processed by:
- Apple — Sign in with Apple, iCloud (CloudKit), App Store purchases and Apple Health
- OpenRouter and Google (USA) — generating AI trainer replies
- Amplitude (USA) — product analytics
- Yandex (Russia) — our email service, Yandex 360: it stores the emails you send to or through the support form and our replies
- our hosting provider in Kazakhstan — the server that stores the data listed above
We may disclose data where the law requires it. We do not send marketing emails or push notifications.
International transfers
Our server is in Kazakhstan, the AI and analytics providers are in the United States, and our email is hosted by Yandex in Russia. These countries may not offer the same level of data protection as the country where you live.
Retention and deletion
Data on our server is kept while your account exists.
- Deleting your account in the app (Profile tab → Delete Account) erases your data on the device and in your iCloud, deactivates your account and your Sign in with Apple link on our server, erases the email address we stored and ends all sessions.
- Training profile snapshots, workout history, subscription records and AI request counters that the server has already received are not deleted automatically — they stay stored, linked to the deactivated account.
- To have them erased completely, email with your Support ID (Profile tab → Support). We will also ask Amplitude to delete the analytics data linked to your account.
- Workouts saved to Apple Health stay there until you delete them in the Health app.
- Backups of the server database are kept for up to 3 months.
Signing out keeps your data on the device; you can sign back in with the same Apple ID.
Legal bases
Where the GDPR or similar laws apply, we rely on: the performance of our contract with you (account, workout generation, AI trainer, sync and subscription); our legitimate interests (security, diagnostics, understanding how the app is used and answering your emails); and your consent where iOS asks for it (Apple Health), which you can withdraw in Settings at any time.
Security
Data travels over encrypted connections (HTTPS). Session tokens are stored in the iOS Keychain, and the server keeps refresh tokens only as hashes. No system is perfectly secure, so we limit what we collect.
Your rights
Depending on where you live (for example, under the GDPR in the EU and the UK, the UAE Federal Decree-Law No. 45 of 2021 on personal data protection or Russian Federal Law No. 152-FZ), you may have the right to:
- access the personal data we hold about you
- correct inaccurate data
- have your data erased
- receive your data in a portable format
- object to or restrict processing
- withdraw your consent
- lodge a complaint with a data protection authority
To exercise these rights, email with your Support ID. We reply within 30 days.
For residents of the United States
We do not sell your personal data and do not share it for cross-context behavioral advertising: there are no advertising SDKs in the app and no trackers on this website. Because the website sets no cookies and does not track visitors, it does not respond to browser "Do Not Track" signals — there is nothing to switch off.
Fitgamma processes data about your body and training, which some states treat as consumer health data. How we handle it, and how to withdraw consent or delete it, is described in our Consumer Health Data Privacy Policy.
To exercise any privacy right, email with your Support ID; we do not treat you differently for doing so.
Children
Fitgamma is for people aged 16 and over, or older if the minimum age for digital consent in your country is higher. The app asks your date of birth, and workouts are not generated for anyone younger. If you believe a younger person has given us personal data, contact us and we will delete it.
Changes to this policy
When the app starts handling data differently, we update this policy and the date at the top of the page.