Privacy Policy

Fitener — last updated 25 July 2026

This policy explains what personal data Fitener ("the app", "we") collects, why, and what rights you have. We keep data collection to what the app actually needs to build your training and nutrition plans and to show your progress.

1. Who is responsible

The data controller is Wouter Vanmaercke, established in Belgium. For any privacy question or to exercise your rights, contact info@woutervanmaercke.be.

2. What we collect

CategoryExamplesSource
AccountName and email addressYour Google sign-in
WaitlistEmail address, so we can tell you once when Fitener launchesYou (landing-page waitlist)
ProfileSex, year of birth, height, goal, training days and time, equipment, dietary preferences and allergiesYou (intake)
Health & body dataWeight, body-fat, lean mass, workouts (sets, reps, weights), nutrition and food logs, cardio, steps, sleep, resting heart rate, VO₂max, HRVYou, and connected services you choose
TechnicalA secure session token; basic request data needed to run the serviceAutomatic

3. Health data — special category

Body-composition, workout, nutrition and wearable data are "special category" data under Article 9 GDPR. We only process it on the basis of your explicit consent, which you give with the checkbox in the app and can withdraw at any time. Withdrawing consent or deleting your account removes this data (see sections 6 and 7).

4. Why we use it (legal basis)

We do not use your data for advertising, and we do not sell it.

5. Services that process data for us

We use a small number of providers, only to run the app:

ProviderPurpose
CloudflareHosting, database and storage of your data
GoogleSign-in (we receive your name and email; we never see your Google password)
WithingsIf you connect it, to import your weight and body-composition measurements
GarminIf you connect it, to import your activity and recovery metrics
StravaIf you connect it, to import your rides and activities
Apple HealthIf you allow it in the iOS app, health data stays on your device and is read only with your permission

Connecting any of these is optional and under your control; you can disconnect them at any time in the app, which deletes the stored connection.

6. Your rights

Under the GDPR you can, at any time:

7. How long we keep it

We keep your data while your account is active. When you delete your account, your personal data is removed. Connected-service keys are deleted as soon as you disconnect that service.

8. Security

Connection tokens (such as your Withings or Strava token) are encrypted before storage and are left out of your data export. Access to the app requires your account sign-in or, on the iOS app, a device key that is stored only on your phone.

9. Children

The app is not intended for children under 16. Do not use it if you are under that age.

10. Changes

If this policy changes we will update the date above and, for material changes, notify you in the app.