Updated September 30, 2026. This notice describes FitGod 2.0 and this website. FitGod 2.0 is being prepared for release; the App Store may still offer an earlier version.

FitGod's developer is Roman Ventskus. For privacy requests and support, contact roman.ventskus@gmail.com. Please do not send medical documents or your full training history when a short description is enough.

Your choices

You can record workouts without creating a cloud account. Signing in enables cloud synchronization. AI coaching, Apple Health permissions and advertising tracking are separate choices; enabling one does not enable all the others.

FitGod 2.0 is intended for people aged 16 and over. It is a fitness tool, not a medical service. If you believe a child has provided personal data, contact us so we can investigate and arrange deletion.

Data stored on your device and in your account

Depending on what you use and enter, FitGod stores your profile, training plans, exercises, sets, workout history, body measurements, nutrition entries, journal, health-related limitations, recovery information, coach conversations and coach memory. Optional entries can include sensitive information such as injuries or pregnancy-related circumstances.

Apple Health access is controlled by the permissions you grant in iOS. FitGod uses the authorized information for training, recovery and related features, not advertising. You can change those permissions in Apple's settings. Revoking access does not itself erase information already imported into FitGod.

Progress-photo image files are encrypted on your device; FitGod cloud sync transfers their record metadata, not the image files. Voice journaling uses on-device transcription; FitGod does not upload the recording as an audio file. The resulting text follows the same rules as other journal entries. Device backups are controlled separately by your operating-system settings.

When you sign in with Apple, the service receives an account identifier and authentication information. The sign-in flow does not request your name or email, but a profile or message you write can contain them. Device/session information, notification tokens, locale, time zone and a subscription identifier are also used to operate your account.

Cloud sync is separate from AI consent. Signing in synchronizes supported profile, workout, health, nutrition, journal, conversation, memory and consent records. Turning off an AI category does not stop that category's cloud storage. Use the account controls to sign out, export data or delete the cloud account.

AI coaching

AI requests are processed through FitGod's service using OpenAI or Anthropic. Requests can contain your message, conversation history, coach memory and relevant records. Your AI category choices limit the automatic retrieval of records; the exceptions for text you write and information already in conversations or coach memory are explained below. This processing lets the coach answer questions and generate training summaries. AI answers can be inaccurate and are not medical advice.

The consent screen names the providers and lets you choose data categories. You can decline AI or turn the coach off later. Disabling a category limits automatic retrieval for new AI requests; it does not rewrite earlier conversations or erase facts already saved in coach memory. Earlier conversations and coach memory can still be included in later AI requests. Text that you type into the chat is sent as written, including any personal information you include. You can review coach memory and use the available Edit or Forget controls for memory items. Contact support about existing conversation data; there is no separate conversation-deletion control in the current app.

With an eligible subscription and cloud account, the service can prepare scheduled summaries using the AI choices synchronized to your account. A change made while offline reaches the server only after synchronization. Disabling the coach prevents new eligible requests once the service has received the change, but does not recall requests already sent to a provider.

The providers' commercial API policies describe no model training on API content by default. FitGod does not promise zero provider retention: security monitoring and batch-processing storage can remain even when response storage is disabled. See OpenAI's data controls and Anthropic's retention policy. Standard API retention can be up to 30 days, with policy and legal exceptions; batch files have separate retention periods. Deleting your FitGod account does not automatically recall or erase those provider copies.

Purchases, analytics and diagnostics

Apple processes App Store payments. RevenueCat helps validate purchases and subscription access. FitGod receives purchase/subscription status and identifiers, not your payment-card details. Signing in links the subscription identifier to your FitGod account.

The PostHog usage-analytics and Sentry crash-reporting integrations are not configured in this release and do not send data to those services. This does not disable advertising measurement, account processing or the technical service records described below.

FitGod initializes the TikTok SDK only with Apple's tracking permission, to measure FitGod advertising. TikTok receives advertising/device identifiers, IP information, device model, operating-system and app information, installation, launch and retention events, and onboarding/trial/subscription events. Its privacy policy describes deriving approximate location, such as country or city, from IP information and matching advertiser events with TikTok accounts for advertising measurement and personalization. FitGod does not request GPS location for this integration. See TikTok's App Events SDK overview and TikTok's privacy policy.

This release uses a patched TikTok integration with SDK debug and crash-report collection disabled; it does not collect or transmit device boot-time history. Advertising measurement is separate from AI consent. FitGod does not intentionally send workout records, health records or coach messages to advertising services. You can revoke Apple's tracking permission in system settings to stop new TikTok requests; revocation does not erase information already sent.

Website and service providers

Cloudflare delivers and protects this website. Normal web requests expose an IP address, browser information and requested URL to the hosting service. The website itself does not set advertising cookies or embed an advertising tracker. Following an App Store or other external link takes you to that provider's service and privacy terms.

Railway hosts FitGod's cloud API, AI gateway and databases in Amsterdam, Netherlands. Other active providers include Apple, RevenueCat and the AI and advertising providers described above. A provider may process information outside your country or outside the European Economic Area; EU hosting of FitGod's own servers does not make all processing EU-only.

We use information to provide the features you request, manage subscriptions, protect the service, diagnose faults and, with the relevant choices, provide AI, usage analytics and advertising measurement. Depending on the processing and applicable law, the basis is providing the service, consent, legitimate interests in operating and protecting it, or a legal obligation. Consent can be withdrawn without making prior processing unlawful. We may disclose information when legally required or necessary to address fraud, security or safety issues.

Security and retention

Network connections use TLS. Selected text fields in the cloud use per-user encryption keys. This is not end-to-end encryption: the service must be able to process information for synchronization and AI. Not every numeric or technical field is individually encrypted. No security measure guarantees absolute protection.

Local records remain until you remove them or the app's local data. Cloud account records remain while your account is active. Deleting an individual synced item removes it from normal views but can leave a synchronization tombstone containing the previous record. Account-wide cloud deletion is the broader deletion mechanism.

Deleting your cloud account removes its active cloud records and queued work. It deliberately leaves your phone's local records in place. Some information can remain in backups until rotation, in restricted security/deletion-audit records, or with service providers under their own retention and legal requirements. Account deletion attempts to revoke the Apple sign-in grant but cannot guarantee that Apple's request succeeds. It does not cancel an Apple subscription or automatically delete a RevenueCat customer record.

The AI gateway's automated cleanup targets usage-accounting records older than 90 days and service batch/file metadata older than 29 days. Usage records include a hashed user identifier, model, token/cost totals and request status. Cleanup runs periodically, so these thresholds are not guarantees of deletion at an exact moment. These records are separate from the providers' copies and from cloud account records. Other technical records are retained according to operational, security and legal needs. We do not promise that account deletion immediately erases every backup or external record.

Access, export and deletion requests

Use the account controls for cloud-data export and account deletion. Export covers the supported account and synchronized records, not every security log or external provider record. Manage and cancel subscriptions through your Apple account separately.

For access, correction, deletion, portability, restriction, objection or consent questions, email roman.ventskus@gmail.com. Your rights depend on applicable law; we may need information to verify that the request concerns your account. Tell us when a request should also cover analytics, subscription-service or provider records so we can assess the relevant copies. You can also complain to your competent data-protection authority.

Material changes will be reflected here. Where a change requires renewed AI consent, the app will ask again before enabling that use.