Privacy Policy

Fitener · last updated 17 September 2026

This policy explains what personal data Fitener ("the app", "we") collects, why, and what rights you have. We keep data collection to what the app actually needs to build your training and nutrition plans and to show your progress.

1. Who is responsible

The data controller is Vanmaercke Wouter CommV, Tiegemberg 48, 8573 Tiegem, Belgium, company number BE 0726.677.280. For any privacy question or to exercise your rights, contact hello@fitener.com.

2. What we collect

CategoryExamplesSource
AccountName and email addressYour Google or Apple sign-in, or the email address you sign in with
WaitlistEmail address, so we can tell you once when Fitener launchesYou (landing-page waitlist)
FeedbackWhatever you write in the feedback form, the screen you were on, the app version, your platform, and the last few error messages the app recorded in that session (technical text only, never your health data)You (feedback form)
ProfileSex, year of birth, height, goal, training days and time, equipment, dietary preferences and allergiesYou (intake)
Health & body dataWeight, body-fat, lean mass, workouts (sets, reps, weights), how recovered you feel at the start of a workout (optional, one answer per session, which you can skip), how hard a session felt when you finish it (optional, one 0–10 answer per session, which you can skip), nutrition and food logsYou, and connected services you choose
TechnicalA secure session token; basic request data needed to run the service; a hashed (one-way, not reversible) form of your IP address that we keep for up to 90 days to limit sign-in attempts and error reports per address; and, if the app hits a bug, an error report with the error message, the screen and the app version, with no name, no email and no health dataAutomatic

3. Health data: special category

Body-composition, workout and nutrition data are "special category" data under Article 9 GDPR. We only process it on the basis of your explicit consent, which you give with the checkbox in the app and can withdraw at any time. Withdrawing consent stops all processing of this data: the app no longer reads, writes or uses it, and you can only continue after giving consent again. The data itself is removed when you delete your account (section 7), which you can do at any time from Account.

4. Why we use it (legal basis)

We do not use your data for advertising, and we do not sell it.

5. Services that process data for us

We use a small number of providers, only to run the app:

ProviderPurpose
CloudflareHosting, database and storage of your data
GoogleSign-in (we receive your name and email; we never see your Google password)
AppleSign-in in the iPhone app (we receive your name and email; we never see your Apple password). If you choose to hide your email address, Apple sends us a relay address instead of your real one, and that is what we store
WithingsIf you connect it, to import your weight and body-composition measurements
Apple HealthIf you allow it in the iOS app, we read your weight and body fat from Apple Health on your iPhone. If you separately allow it, the app also writes your logged workouts and your estimated energy and macros to Apple Health; you can switch that off at any time in Account. Nothing else is read or written
StravaIf you connect it and press Send to Strava, to place that one session on your own Strava account
ResendSending email on our behalf: the one-time code when you sign in with your email address, and the copy of your feedback that goes to us. Resend sees your email address and the content of that message, nothing else
OpenAIOnly when you use Describe with AI to log food: the text you typed is sent to OpenAI to be turned into food items. See the section below for exactly what is and is not sent

Connecting any of these is optional and under your control; you can disconnect them at any time in the app, which deletes the stored connection.

One more third party is involved, but not as a processor: it never receives your personal data, so it is not in the table above.

OpenAI, for "Describe with AI"

When you type a meal in your own words ("300 g quark, granola, a banana"), Fitener sends that text to OpenAI (the gpt-4o-mini model) together with a compact list of the ingredients in our library, and asks it to turn your sentence into items from that list. This only happens when you use Describe with AI; searching, scanning a barcode and picking from your recents never involve OpenAI.

What is sent: the words you typed, and our ingredient list. What is not sent: your name, your email address, your account identifier, your profile, your weight, your goals, your history, or anything else about you. OpenAI cannot link a request to you. Do keep in mind that whatever you choose to type is sent as-is. If you describe a meal in a way that says something about your health, that sentence travels with it.

According to OpenAI's own API data-usage policy, requests sent through the API are not used to train its models and may be kept for up to 30 days to monitor for abuse, after which they are deleted; OpenAI's policy, not ours, governs that part. On our side, the model's answer for a given sentence is kept for 7 days so the same sentence does not have to be sent twice; that cached answer is stored under a one-way hash of the sentence and is not linked to your account.

The result is a suggestion, marked ESTIMATE. Nothing is added to your log until you review it and confirm.

Open Food Facts

When you look up a packaged product, Fitener asks Open Food Facts, a European non-profit food database.

A barcode scan always goes through our server: we send the barcode and nothing that identifies you. When you search by product name in the iOS app, your phone contacts Open Food Facts directly, so they see your IP address and the words you typed, and nothing else. In the web version that search goes through our server instead. Your name, your email address and your account identifier are never sent, and Open Food Facts cannot link a lookup to your account.

Products we have looked up once are stored on our own servers, so the same product is not requested again.

Product data from Open Food Facts is used under the Open Database License (ODbL) v1.0; the full attribution is on the credits page.

Strava

Strava is not one of the providers in the table above in the usual sense: it does not process data on our behalf. It is a service you have your own account with, and it decides for itself what happens to what is on that account.

Nothing reaches Strava unless you do two things yourself: connect your Strava account, and then press Send to Strava on a session you have just saved. There is no automatic transfer. Each session is a separate decision.

What we send is that one session: the exercises you did, the number of reps, the weight you lifted, when the session started and how long it lasted. Nothing else: no food, no body weight, no measurements, no personal details, and none of your other sessions. Because this is health data, we send it only on your explicit instruction, one session at a time.

Fitener never reads anything back from Strava. Nothing from your Strava account comes into this app.

Disconnecting stops Fitener from sending anything further. Sessions already on Strava stay there: we cannot remove them, you can, in Strava. You can also revoke Fitener’s access from your Strava account settings. Once a session is on Strava it is covered by Strava’s own privacy policy.

6. Your rights

Under the GDPR you can, at any time:

7. How long we keep it

We keep your data for as long as your account exists. We do not delete accounts on our own initiative. When you delete your account, your personal data is removed from our database straight away. Encrypted database backups, which exist so we can recover from a failure, are deleted 90 days after they are made; they are never used for anything else. Connected-service keys are deleted as soon as you disconnect that service.

8. Security

Connection tokens (such as your Withings token) are encrypted before storage and are never shown to you or included in any copy of your data. Access to the app requires your account sign-in or, on the iOS app, a device key that is stored only on your phone.

9. Children

The app is not intended for children under 16. Do not use it if you are under that age. The app asks for your year of birth and does not accept one that would make you younger than 16. If we find that an account belongs to someone younger, we will close it and delete the data.

10. Changes

If this policy changes we will update the date above and, for material changes, notify you in the app.

11. Cookies and website measurement

On this website (fitener.com) we use Google Tag Manager and Google Analytics to measure how the site is used. They set cookies and are non-essential, so they are not loaded at all until you press "Accept" in the cookie banner: before you choose, and if you press "Decline", no script is loaded from Google and no request is sent to Google. Your choice is stored on your device and applies to your next visits; you can change it at any time through "Cookie settings" in the footer. The app itself does not use these measurement tools; essential cookies needed to run the page and keep you signed in are always active.