This notice explains cookies, local/session storage, mobile SDKs, device identifiers, permissions and similar technologies used by the GRITFIT website and private-beta app.
Current website
The public information pages do not load advertising, behavioural analytics or push-notification technology. The beta application page offers two routes:
- an email link that loads no third-party form technology; or
- a Load application form choice. Only after that choice does the page load Brevo's embedded form script and Google reCAPTCHA. Those providers can receive IP/network, browser/device, form and anti-abuse information and may use cookies or storage needed for the form and security check.
Rejecting that optional route is no harder than loading it: use the email link instead. Reload the page without selecting the form to withdraw the website choice. Essential server, security or content-delivery logs may still be created when any website is requested.
Mobile app technologies
| Technology/category | Where | Purpose and information | Leaves device? | Current control |
|---|---|---|---|---|
| Firebase Core and Authentication | iOS/Android | App setup, sign-in, provider identifier, email/account and security metadata | Yes | Necessary for authenticated cloud use; account controls in app |
| Firebase Cloud Firestore/Storage | iOS/Android | Limited account cache, notification/device state and user media storage | Yes when cloud feature used | Feature choice; media and deletion controls |
| Firebase Cloud Messaging | iOS/Android | Push token and delivery metadata | Yes after enabled/registered | OS prompt plus in-app notification preferences; automatic initialisation is disabled |
| Firebase Analytics, Crashlytics and Performance components | iOS/Android | Analytics/crash/performance capability is included in the build | Not automatically under the current production configuration | Automatic collection is disabled; GRITFIT must make and record an appropriate choice before enabling non-essential collection |
| GRITFIT server product/security events | Backend | Sanitised feature event, result, timestamp, request/security and limited device/app metadata | Yes | Essential security/reliability events use legitimate operational purposes; no advertising profile |
| Apple Health / Health Connect | iOS/Android | Selected health/activity categories authorised in the OS | Yes to GRITFIT only for an enabled cloud use; some reading may remain on device | Separate GRITFIT health choice, category-level OS permission, disconnect/withdraw controls |
| Optional activity providers | iOS/Android/backend | Provider account token and activity summaries for a deliberately connected provider | Yes | Connect/disconnect; availability depends on provider approval/configuration |
| Precise location | iOS/Android | Route points for an actively recorded workout | Yes only after review/save | OS permission, explicit recording/save and delete controls; teen guardian category |
| Camera/photo/video/biometric SDKs | iOS/Android | Profile/progress/private media; biometric unlock result; optional adult failed-unlock image | Media leaves device only when uploaded to the chosen GRITFIT feature | OS permission and feature controls; failed-unlock photos off by default, adult-only, visible capture, maximum three |
| Secure/local storage | iOS/Android | Session secrets, settings, consent/version state, PIN/security configuration and offline/cache data | Usually no; synchronised records may also exist server-side | Sign out, reset and deletion controls; OS app-data controls |
| Device/package/connectivity information | iOS/Android | Capability, OS/app version, device/session compatibility and network status | Limited metadata may be sent | Used for service operation and support |
| App-store billing SDKs | iOS/Android | Product, transaction token/receipt, store account context and entitlement status | Yes to Apple/Google and GRITFIT verification backend | Purchase confirmation, store subscription management and restore controls |
The app also requests notification, camera, photo, health, location and biometric capabilities only at relevant feature points. An OS permission is not treated as consent for every GRITFIT purpose.
Consent and changes
GRITFIT does not currently enable mobile advertising identifiers or automatic non-essential Firebase analytics/crash/performance collection. If this changes, GRITFIT must update this notice and implement an appropriate, rejectable and withdrawable choice before non-essential collection begins where required.
For questions or to exercise privacy rights, see Account Deletion and Privacy Rights or email dpo@gritfit-ai.com. The backup privacy route is support@gritfit-ai.com.