Fitness Chief

Privacy Policy

Last updated: March 2026

We are committed to protecting your personal data and processing it transparently in compliance with India's Digital Personal Data Protection (DPDP) Act, 2026.

1Who We Are

Fitness Chief is an AI-powered fitness coaching application that generates personalised meal plans, workout routines, and nutrition guidance based on your health profile and goals.

Fitness Chief operates as a Data Fiduciary under India's Digital Personal Data Protection (DPDP) Act, 2026, and is responsible for determining the purpose and means of processing your personal data.

For all privacy-related inquiries, contact our Data Protection team at privacy@fitnesschief.app.

2Data We Collect

We collect only the data necessary to provide personalised coaching. This includes:

Account Data

  • Full name
  • Email address
  • Password (stored as a one-way bcrypt hash - never in plaintext)

Biometric Data

  • Age and gender
  • Height (cm) and weight (kg)
  • Activity level

Health & Fitness Data

  • Fitness goals and dietary preferences
  • Macro targets (protein and calories)
  • Health conditions (optional, provided voluntarily)
  • Daily food logs, step counts, and water intake

Usage Data

  • Chat history with the AI coach
  • App interactions and feature usage patterns

3How We Use Your Data

Your data is used solely for the following purposes, all of which you explicitly consent to:

  • To generate a personalised AI fitness plan tailored to your body, goals, and dietary preferences.
  • To provide daily nutrition and workout coaching through our AI assistant.
  • To track your daily progress - macros, steps, water intake, and supplement adherence.
  • To improve the accuracy and quality of our AI coaching over time.

4AI Processing & Third-Party Sharing

We use Google Gemini AI (operated by Google LLC) to power our coaching features. When you use the AI coach, your anonymised health profile is transmitted to Google's API to generate plans and responses. This profile includes: fitness goal, dietary preference, macro targets, and health conditions.

Your name and email address are never sent to the AI. Only anonymised health data is used.

Google processes this data as a data processor under a Data Processing Agreement (DPA) with us. Google's AI API data is not used to train their foundational models.

We do not sell, rent, or share your personal data with any third party for advertising or commercial purposes.

5Data Retention

Account data (name, email, biometrics, and fitness profile) is retained for as long as your account remains active.

Food logs and chat history are retained for 12 months from the date of creation, after which they are automatically deleted.

You may request deletion of all your personal data at any time by emailing privacy@fitnesschief.app. Account deletion is processed within 30 days.

6Your Rights (DPDP Act 2026)

As a Data Principal under the DPDP Act, 2026, you have the following rights with respect to your personal data:

Right to Access

Request a copy of the personal data we hold about you.

Right to Correction

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data (right to be forgotten).

Right to Withdraw Consent

Withdraw your consent at any time without affecting prior processing.

Right to Nominate

Nominate another person to exercise your rights on your behalf in the event of death or incapacity.

Right to Grievance Redressal

Lodge a complaint with us or the Data Protection Board of India.

To exercise any of the above rights, email privacy@fitnesschief.app. We will respond within 72 hours.

7Consent

By creating an account and completing the onboarding process, you provide explicit, informed consent to the processing of your health data as described in this policy. This consent is recorded at the time of registration.

You may withdraw consent at any time by deleting your account. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Fitness Chief does not process the personal data of minors under the age of 18 without verified parental consent, in accordance with the DPDP Act.

8Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit using HTTPS/TLS.
  • Passwords are hashed using bcrypt - never stored in plaintext.
  • Authentication uses short-lived JWT access tokens with HTTP-only refresh cookies.
  • No health data is stored in the browser beyond the active session.
  • Access to the production database is restricted to authorised backend services only.

9Contact & Grievance Officer

For any privacy-related queries, data subject requests, or complaints, please contact:

Grievance OfficerShrihari M (Founder & Data Controller)
Response TimeWithin 72 hours of receipt

If your grievance is not resolved to your satisfaction, you may escalate the matter to the Data Protection Board of India as established under the DPDP Act, 2026.

Last Updated

March 2026

We may update this policy from time to time. Significant changes will be notified via email or an in-app notice. Continued use of the app after such notice constitutes acceptance of the updated policy.