1. Who we are and what this notice covers
GRITFIT.AI LIMITED (company number 17066827), 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ("GRITFIT") controls the personal information described in this notice. Our primary privacy contact is dpo@gritfit-ai.com; support@gritfit-ai.com is the backup route.
This notice applies to the English-language GRITFIT website and private-beta fitness application offered to people aged 16 or older in the United Kingdom, United States, Australia and New Zealand. It should be read with the Teen Privacy Notice, AI Transparency Notice, Cookies and App Technologies Notice, Consumer Health Data Privacy Policy and regional privacy supplements.
2. Information we handle
Depending on what you choose to use, GRITFIT may handle:
- Account and identity: name, email, authentication provider identifiers, account status, date of birth for age controls, territory, language, security and trusted-device information.
- Profile and training: fitness goals, preferences, experience, equipment, schedule, programmes, workouts, exercise history, sets, strength/performance records, achievements, body metrics and progress.
- Health and recovery: injuries, pain, symptoms or limitations you enter, fatigue, readiness, sleep or recovery information, health-related free text, and information imported from Apple Health, Health Connect or a supported activity provider when enabled.
- Coach and inferred information: Coach prompts and responses, feedback, bounded profile/training context, and training, recovery or progression outputs derived by GRITFIT systems.
- Media: profile images, progress photos and private Hidden Folder photos or videos. If an adult separately enables failed-unlock photos, the front camera may capture an image after repeated incorrect GRITFIT PIN attempts. This control is off by default, never runs from a failed biometric check, keeps at most three active security photos, and does not perform facial recognition.
- Location: approximate location from network/device context and precise workout route points only if you choose route recording and grant device permission.
- Device, app and diagnostics: IP/network information, operating system and app version, device capability, push token, app-security events, failed login/unlock information, server-side product events, request metadata, crash or error information where collection is enabled, and administrative audit records.
- Communications: beta application information, support emails, bug reports, service messages, survey/feedback answers and any marketing choice.
- Teen safeguards: guardian email and, after approval, name and relationship; requested and approved categories; declaration, token hashes, timestamps, withdrawal and age-transition records; and limited delivery/security metadata. A guardian does not receive the teen's Coach messages, health data, media, routes, notes or account content.
- Privacy administration: consent and legal-notice events, privacy/export/deletion requests, complaint correspondence and evidence needed to demonstrate or defend a request outcome.
- Payments: product and entitlement status, store transaction references and verification results. Apple or Google handles payment-card details; GRITFIT does not receive full card details from the app stores.
Information about injury, pain, health limitations, connected-health information and health-related inferences may be health information and, in the UK, special-category data.
3. Why we use information
We use information to create and secure accounts; provide training, progress, Coach and optional connected features; generate and validate workouts; remember relevant choices; respond to support and privacy requests; verify subscriptions; deliver requested notifications; investigate abuse, defects and security events; maintain the service; and comply with legal obligations.
GRITFIT does not sell personal information or consumer health data. We do not use health information, precise routes or progress media for targeted advertising.
4. UK lawful-basis and health-data mapping
For UK users, our principal Article 6 UK GDPR bases are:
- contract for account, requested fitness features, workouts, progress, subscription verification and service communications;
- consent for optional language-model sharing, optional health personalisation, connected-health/cloud sync, and marketing where used;
- legitimate interests for proportionate security, fraud prevention, service reliability, limited server-side product measurement and legal defence, balanced against user rights; and
- legal obligation where records or disclosures are required by law.
Where optional information is health-related special-category data, GRITFIT relies on explicit consent under Article 9(2)(a) for the relevant health personalisation or connection. Article 6 contract alone is not used as the special-category condition. The app presents separate affirmative choices, records the notice/version and choice, and provides withdrawal controls. Device permission is an additional platform control and is not treated as the whole legal consent.
Some essential safety handling of information a user has chosen to provide may be necessary to avoid returning an obviously unsuitable workout. GRITFIT does not use that limited safety handling to expand optional personalisation after consent is withdrawn.
5. Coach and external language-model processing
Coach is AI-generated, not a human coach or clinician, and may be wrong. Before Coach can send information to the external language-model provider, the app asks the user to choose Enable Coach or Continue without Coach. Without permission, non-AI core training remains available.
For an enabled request, GRITFIT assembles a limited context from the message and relevant profile/training information. Separately permitted health context may be included when relevant. Credentials, Hidden Folder media, private progress media and precise GPS route points are excluded from general Coach inference. See the AI Transparency Notice. GRITFIT does not make a public model-training or provider-log-retention promise that is broader than its confirmed provider arrangements.
6. Who receives information
Information may be processed by service providers supporting cloud hosting, authentication, database/storage, email, security, push delivery, store payments, connected-platform features, support, and protected language-model processing. Apple, Google or a connected activity provider also receives information when you deliberately use its platform or connection. See the Service Provider and Subprocessor List for current categories.
We may also disclose information when required by law, to protect a person or the service, in a corporate transaction subject to appropriate safeguards, or at your direction. We do not give guardians automatic access to a teen's account content.
7. International processing
GRITFIT is UK-based and some providers may process information outside your country, including in the United Kingdom, European Economic Area or United States depending on the service and provider configuration. Where transfer rules require a safeguard, GRITFIT will use an applicable adequacy decision or approved contractual safeguard and complete any required assessment. Provider countries and safeguards can change; contact us for the current transfer information relevant to your data.
Australian, New Zealand and US information may also be processed overseas. GRITFIT remains responsible for selecting and overseeing processors as required by applicable law.
8. Retention
We keep personal information only while it is reasonably needed for the purpose described, an active account, security, dispute handling or a legal requirement. Retention is based on the data and system rather than a universal period:
- active profile, training, health, routes, Coach history and media normally remain until the user deletes them, withdraws the applicable choice, resets training data or deletes the account;
- privacy exports expire from the active download service after 24 hours;
- guardian invitation links expire after seven days; active guardian authority ends when the user turns 18, when it is withdrawn, or when the account is deleted;
- failed-unlock security photos remain until deleted or replaced by the three-image limit, or until the feature/account is deleted;
- consent, security, transaction, complaint and deletion evidence may be retained after account deletion only where reasonably necessary for compliance, security, legal claims or store reconciliation;
- provider logs, support/email systems and backups follow provider or operational deletion cycles and may not disappear at the same moment as live application data.
We do not claim a fixed provider or backup deletion period unless it is confirmed for that system. Data kept beyond the active purpose is restricted, minimised or de-identified where appropriate.
9. Your choices and rights
Settings provides controls for Coach permission, optional health processing, connected-health/cloud sync, route and notification permissions, media security, data export, training-data reset and account deletion. Withdrawing health consent stops future optional health processing and removes identified health-personalisation records from active GRITFIT systems, including health context found in supported profile, check-in, Coach and workout fields. Ordinary workout records and media are not deleted merely because health consent is withdrawn; delete them separately or delete the account.
Depending on your location, you may request access, correction, deletion, portability, restriction, objection, consent withdrawal, health-data withdrawal, or review/appeal of a rejected request. See Account Deletion and Privacy Rights for working routes and response information.
10. Complaints
For a privacy question or rights request, email dpo@gritfit-ai.com. For a formal privacy complaint, use this complaint email route. If that route is unavailable, use support@gritfit-ai.com. Put the relevant wording in the subject so it is handled separately from ordinary support. We may need proportionate identity verification.
You may also complain to the regulator in your location, including the UK Information Commissioner's Office, the Office of the Australian Information Commissioner, the New Zealand Privacy Commissioner, or an applicable US state authority. Statutory request and complaint timeframes are not subject to GRITFIT's ordinary support-service disclaimer.
11. Changes
We will update the date and notice when practices materially change. Where a change affects an existing consent or required acknowledgement, the app can require the current choice before the affected processing continues.